Skip to content

Releases: splunk/attack_range

v4.0.0

01 Jul 19:47
Compare
Choose a tag to compare

Splunk Attack Range v4.0 Release Notes

The Splunk Threat Research Team (STRT) is happy to release v4.0 of the Splunk Attack Range.

Release Blog

Major Changes

  • SnapAttack CapAttack Integration - Added PowerShell capture agent that packages attacks with system logs, keystrokes, PCAP, and video for comprehensive attack analysis
  • GCP Support - Extended cloud platform support to include Google Cloud Platform alongside existing AWS and Azure deployments
  • Automated Splunk Apps Update Through CI/CD - Implemented automatic updates for all integrated Splunk Apps to ensure detection engineers work with current versions
  • Improved Caldera Integration - Enhanced deployment and configuration of MITRE's Caldera adversary emulation platform with better reliability and accessibility
  • Version-Tagged Docker Containers - Introduced specific version tags on DockerHub for greater stability and reproducibility in testing environments
  • Deprecate Splunk Attack Range Local - Discontinued local deployment support due to VirtualBox/Vagrant challenges; recommend Ludus for local range needs

Updates

  • Added CapAttack capture workflow to integrate with SnapAttack data collection
  • Improved Caldera interface reliability with port 8888 access
  • Updated Technical Add-ons (TAs) through automated CI/CD pipeline
  • Fixed various bugs in Caldera integration
  • Added replay file path functionality
  • Improved documentation and configuration guides

v3.3.0

09 Apr 13:16
d079c7f
Compare
Choose a tag to compare

Changes:

  • GCP support
  • deprecate local deployment of Attack Range

v3.2.0

06 Dec 15:27
Compare
Choose a tag to compare

Changes:

  • Add Mitre Caldera
  • bug fixes

v3.1.1

25 Sep 14:06
5d38462
Compare
Choose a tag to compare

Changes:

  • Improve Snort logging
  • Integrated Cisco Secure Endpoint

v3.1.0

26 Aug 14:12
Compare
Choose a tag to compare

Changes:

  • Remove packer to simplify usage
  • Build Snort server and get alarms to Splunk
  • Auditd logging for Linux server
  • better ansible variable handling
  • bug fixes

v3.0.0

18 Jan 18:55
29b3417
Compare
Choose a tag to compare

The Splunk Threat Research Team (STRT) is happy to release v3.0 of the Splunk Attack Range.

Release Blog

Check out the demo video!

Major Changes

Updates

  • Fixed CI jobs
  • Add support for terraforms remote backends

v2.0.0

01 Jul 22:08
e76c66f
Compare
Choose a tag to compare
Merge pull request #629 from splunk/haag_fixes

Spacing and Kali Update

v1.1.0

26 Aug 23:15
Compare
Choose a tag to compare
fixing minor bug with clipboard copy

v1.0.0

26 Jan 03:14
Compare
Choose a tag to compare
circlecci syntax error