Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

feat: Dual-signal SnortML (GID 411) + signature/EVE corroboration analytics for Cisco Secure Firewall

Open
#4,220 2 comments 0 reactions 0 assignees View on GitHub

Maintainers usually reply within 1 day

Nobody has claimed this yet.

Assessment

Difficulty
4/5
Estimated time
3-5 days
Newbie friendliness
45/100
Issue type
Feature
Clarity
Mostly clear
Activity status
Quiet
Tech stack
python

Research direction

The issue involves adding two new detections to the Cisco Secure Firewall Threat Defense analytics in the ESCU (Enterprise Security Content Updates) framework. Start by examining the existing detection YML files in the repository, likely under a directory like 'detections/'. Look for similar detections for Cisco Secure Firewall to understand the structure. The new detections require creating YML files for 'SnortML High Confidence ML-Only' and 'Signature Plus EVE Corroboration', and adding corresponding unit test data in the datasets/cisco_secure_firewall_threat_defense/ directories. Also, need to attach these detections to the existing analytic story. Review the sister PR in EvidenceForge for context on data formats. 'Done' means the YML detection files and test data are created and linked to the story, ready for PR.

Written by the indexing model from the issue text.

Description

Is your feature request related to a problem? Please describe.

Cisco Secure Firewall Threat Defense analytics in ESCU already cover:

  • High EVE threat confidence (ML-ish encrypted path) as an intermediate finding
  • High-priority classic Snort intrusion classifications as stronger findings

Missing: an explicit SnortML (GeneratorID / GID 411) path that encodes the hard rule ML probability ≠ signature true positive, plus a signature + EVE corroboration analytic for dual-signal FIX_NOW-class triage.

Without that split, agentic / automated response consumers over-trust ML-only highs and under-train corroboration — inflating false containment.

Describe the solution you'd like

  1. Detection: Cisco Secure Firewall - SnortML High Confidence ML-Only
    • EventType=IntrusionEvent GeneratorID=411 (elevated Impact)
    • Type: Anomaly / intermediate finding (escalate/corroborate — not auto-contain)
  2. Detection: Cisco Secure Firewall - Signature Plus EVE Corroboration
    • Classic Snort (GeneratorID!=411) joined with ConnectionEvent EVE_ThreatConfidencePct >= 80
    • Type: TTP / higher finding score
  3. Companion attack_data samples for unit tests under
    datasets/cisco_secure_firewall_threat_defense/intrusion_event_snortml/ and .../dual_signal_corroboration/
  4. Attach both detections to analytic story Cisco Secure Firewall Threat Defense Analytics

Describe alternatives you've considered

  • Only tuning known_false_positives on High EVE — helpful but does not surface GID 411 as a first-class signal class.
  • Risk-rule-only correlation outside ESCU — weaker distribution to ES customers.

Additional context

CLA status: pending signature (will confirm in thread once completed).

Dominant language
Python
Stars
1.7k
Forks
494
Avg merge
2d 10h
Merged PRs (30d)
31

Getting set up

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from splunk/security_content

All issues in splunk/security_content

Similar issues

More Python issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.