The following attack data links were partially bad, but not totally wrong. - #4209
The following attack data links were partially bad, but not totally wrong.#4209pyth0n1c wants to merge 1 commit into
Conversation
…rong. Several of them had a path containing double backslash, like attack_data//T1003/file.log. This is resolvable by a redirect, but still wrong. A few others did not point to the prefix https://media.githubusercontent.com/media/splunk/attack_data/master/datasets and instead started with https://media.githubusercontent.com/media/splunk/attack_data/refs/head/master/datasets which, while it still resolved, was wrong
nasbench
left a comment
There was a problem hiding this comment.
Assuming this is targeting 6.5. So I will not merge for now
Correct. This also doesn't actually matter for releases, it is only relevant to validation/testing workflows which validate attack data links. Interesting enough, you will find both links to an attack_data file "work": It's just that the second is "silently" redirected. And I suppose different sites handle this differently. Both work, with the second one NOT being redirected. Interesting... |
Several of them had a path containing double backslash, like attack_data//T1003/file.log. This is resolvable by a redirect, but still wrong. A few others did not point to the prefix https://media.githubusercontent.com/media/splunk/attack_data/master/datasets and instead started with https://media.githubusercontent.com/media/splunk/attack_data/refs/head/master/datasets which, while it still resolved, was wrong
DETECTION VERSIONS ARE INTENTIONALLY NOT BUMPED BECAUSE THEY SHOULDN'T BE - ATTACK DATA LINKS ARE NOT SERIALIZED INTO SAVEDSEARCHES.CONF