feat: Dual-signal SnortML (GID 411) + signature/EVE corroboration analytics for Cisco Secure Firewall
Maintainers usually reply within 1 day
Nobody has claimed this yet.
Assessment
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Newbie friendliness
- 45/100
- Issue type
- Feature
- Clarity
- Mostly clear
- Activity status
- Quiet
- Tech stack
- python
- Domain
- analytics, backend-api-design, security
Research direction
The issue involves adding two new detections to the Cisco Secure Firewall Threat Defense analytics in the ESCU (Enterprise Security Content Updates) framework. Start by examining the existing detection YML files in the repository, likely under a directory like 'detections/'. Look for similar detections for Cisco Secure Firewall to understand the structure. The new detections require creating YML files for 'SnortML High Confidence ML-Only' and 'Signature Plus EVE Corroboration', and adding corresponding unit test data in the datasets/cisco_secure_firewall_threat_defense/ directories. Also, need to attach these detections to the existing analytic story. Review the sister PR in EvidenceForge for context on data formats. 'Done' means the YML detection files and test data are created and linked to the story, ready for PR.
Written by the indexing model from the issue text.
Description
Is your feature request related to a problem? Please describe.
Cisco Secure Firewall Threat Defense analytics in ESCU already cover:
- High EVE threat confidence (ML-ish encrypted path) as an intermediate finding
- High-priority classic Snort intrusion classifications as stronger findings
Missing: an explicit SnortML (GeneratorID / GID 411) path that encodes the hard rule ML probability ≠ signature true positive, plus a signature + EVE corroboration analytic for dual-signal FIX_NOW-class triage.
Without that split, agentic / automated response consumers over-trust ML-only highs and under-train corroboration — inflating false containment.
Describe the solution you'd like
- Detection:
Cisco Secure Firewall - SnortML High Confidence ML-OnlyEventType=IntrusionEvent GeneratorID=411(elevated Impact)- Type: Anomaly / intermediate finding (escalate/corroborate — not auto-contain)
- Detection:
Cisco Secure Firewall - Signature Plus EVE Corroboration- Classic Snort (
GeneratorID!=411) joined with ConnectionEventEVE_ThreatConfidencePct >= 80 - Type: TTP / higher finding score
- Classic Snort (
- Companion
attack_datasamples for unit tests under
datasets/cisco_secure_firewall_threat_defense/intrusion_event_snortml/and.../dual_signal_corroboration/ - Attach both detections to analytic story Cisco Secure Firewall Threat Defense Analytics
Describe alternatives you've considered
- Only tuning
known_false_positiveson High EVE — helpful but does not surface GID 411 as a first-class signal class. - Risk-rule-only correlation outside ESCU — weaker distribution to ES customers.
Additional context
- Draft detection YMLs + attack_data samples prepared locally; will open PRs after CLA + maintainer feedback.
- Sister labeled corpus: https://github.com/Cisco-Talos/EvidenceForge/pull/389
- I will sign the Splunk Contributor License Agreement before any mergeable PR: https://www.splunk.com/goto/individualcontributions
- Prefer discussing approach here before opening the PR (per CONTRIBUTING).
CLA status: pending signature (will confirm in thread once completed).
- Dominant language
- Python
- Stars
- 1.7k
- Forks
- 494
- Avg merge
- 2d 10h
- Merged PRs (30d)
- 31
Getting set up
- No Dockerfile or Docker Compose file
- Has a pull request template
- Read the contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from splunk/security_content
-
bug
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
splunk/security_content#4292 · 1 comment · 3 assignees ·
Maintainers usually reply within 1 day
-
Duplicate *http* Pattern in Windows Ngrok Reverse Proxy Usage DetectionPossibly taken @nasbench claimed this 1 day ago. Openbug
Difficulty 1/5 Under an hour Newbie friendliness 72/100
splunk/security_content#4275 · 1 comment · 2 assignees ·
Maintainers usually reply within 1 day
-
bug
Difficulty 3/5 1-2 days Newbie friendliness 72/100
splunk/security_content#4293 · 1 comment · 1 assignee ·
Maintainers usually reply within 1 day
-
Lookup replication issue with DA-ESS-ContentUpdate on distributed searchPossibly taken @nasbench claimed this 7 days ago. Open
Difficulty 4/5 3-5 days Newbie friendliness 35/100
splunk/security_content#4229 · 4 comments ·
Maintainers usually reply within 1 day
-
Suggested Enhancement for Detection: Windows AD Short Lived Domain Account ServicePrincipalNameMay be free again @patel-bhavin claimed this 197 days ago, and no pull request is open. Openenhancement
splunk/security_content#3941 · 1 assignee ·
Maintainers usually reply within 1 day
All issues in splunk/security_content
Similar issues
-
customer-reported
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
Azure/azure-cli#34150 · 1 comment ·
Maintainers usually reply within 1 day
-
community-request
Difficulty 1/5 Under an hour Newbie friendliness 95/100
NVIDIA-NeMo/Curator#2464 · 1 comment ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
WeblateOrg/translation-finder#1099 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
trezor/trezor-firmware#7997 ·
Maintainers usually reply within 2 days
-
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
Maintainers usually reply within 1 day