Releases: splunk/security_content
Release list
v5.4.0
✨ Highlights
-
🔥 Cisco Secure Firewall Threat Defense Analytics: We published a new analytic story and added new detections for Cisco Secure Firewall focusing on three primary event types—file events, network connections, and intrusion alerts. These detections identify activity such as malicious or uncommon file downloads, connections over suspicious ports or to file-sharing domains, and Snort rule-based intrusion events across multiple hosts. This enables broader visibility into network-based threats and host-level indicators of compromise.
-
🤖 AWS Bedrock Security: Released a new analytic story to monitor for adversary techniques targeting AWS Bedrock, a managed service used to build and scale generative AI applications. This includes detections for the deletion of security guardrails, knowledge bases, and logging configurations, as well as high volumes of model invocation failures.
-
🕵️ Mapping Threat Campaigns: Several detections have been mapped to known threat actors and malware campaigns, including Cactus Ransomware, Earth Alux, Storm-2460 CLFS Zero Day Exploitation and Water Gamayun, to improve attribution to TTPs and provide insights into observed behaviors.
-
🆕 New Detections: Introduced additional detections for tactics such as directory path manipulation via MSC files, IP address collection using PowerShell Invoke-RestMethod, process spawning from CrushFTP, and deletion of Volume Shadow Copies via WMIC. These detections target adversary behavior related to discovery, lateral movement, and anti-forensics.
📚 New Analytic Stories – [6]
- AWS Bedrock Security
- Cactus Ransomware
- Cisco Secure Firewall Threat Defense Analytics
- Earth Alux
- Storm-2460 CLFS Zero Day Exploitation
- Water Gamayun
🧠 New Analytics – [27]
- AWS Bedrock Delete GuardRails
- AWS Bedrock Delete Knowledge Base
- AWS Bedrock Delete Model Invocation Logging Configuration
- AWS Bedrock High Number List Foundation Model Failures
- AWS Bedrock Invoke Model Access Denied
- Cisco Secure Firewall - Binary File Type Download
- Cisco Secure Firewall - Bits Network Activity
- Cisco Secure Firewall - Blacklisted SSL Certificate Fingerprint
- Cisco Secure Firewall - Blocked Connection
- Cisco Secure Firewall - Communication Over Suspicious Ports
- Cisco Secure Firewall - Connection to File Sharing Domain
- Cisco Secure Firewall - File Download Over Uncommon Port
- Cisco Secure Firewall - High EVE Threat Confidence
- Cisco Secure Firewall - High Volume of Intrusion Events Per Host
- Cisco Secure Firewall - Malware File Downloaded
- Cisco Secure Firewall - Potential Data Exfiltration
- Cisco Secure Firewall - Rare Snort Rule Triggered
- Cisco Secure Firewall - Repeated Blocked Connections
- Cisco Secure Firewall - Repeated Malware Downloads
- Cisco Secure Firewall - Snort Rule Triggered Across Multiple Hosts
- Cisco Secure Firewall - Wget or Curl Download
- CrushFTP Authentication Bypass Exploitation
- CrushFTP Max Simultaneous Users From IP
- Windows MSC EvilTwin Directory Path Manipulation
- Windows PowerShell Invoke-RestMethod IP Information Collection
- Windows Shell Process from CrushFTP
- Windows WMIC Shadowcopy Delete
🛠 Other Updates
- 🔄 Reverted several searches to use
| joininstead ofprestats = tdue to bugs encountered in the search logic. - ❌ Removed Detections – As notified in the ESCU v5.2.0 release, we have removed these detections. Please use replacements where appropriate.
- 🗓️ Deprecated more detections now scheduled for removal in ESCU v5.6.0.
- 📥 Updated
deprecation_infolookup to reflect the latest list of deprecated and removed detections.
v5.3.0
Key Highlights
-
⚙️ Detection Output Standardization: Additionally, we’ve updated the majority of our detections to include a standardized set of output fields within each detection analytic and enhanced our tooling to consistently enforce this structure—improving usability, correlation, and integration across security workflows.
-
🚨 Apache Tomcat Session Deserialization Attacks: CVE-2025-24813 is an unauthenticated remote code execution vulnerability in Apache Tomcat’s partial PUT feature disclosed on March 10, 2025. We introduced a new analytic story targeting potential exploitation of Apache Tomcat servers. This story includes detections for suspicious session deserialization attempts and file uploads—techniques commonly used by attackers to gain remote access or execute arbitrary code.
-
🪟 Windows Shortcut Exploit Abuse: Released a new analytic story to detect emerging exploitation patterns involving Windows LNK files. This includes detections for abuse of SSH ProxyCommand, LNK files with abnormal padding, and Windows Explorer spawning suspicious processes like PowerShell or CMD. These analytics are designed to surface stealthy initial access and execution techniques leveraged in recent zero-day attacks. More details can be found here - (ZDI-CAN-25373)
-
💥 New Ransomware Campaigns: We’ve expanded our ransomware mapping to include detection coverage for emerging threats such as Medusa Ransomware, Termite, Van Helsing, Salt Typhoon, and Sea Shell Blizzard. These mappings help contextualize detections within current threat actor TTPs and provide better visibility into campaign-specific behaviors.
-
🔥 Windows Firewall Rule Monitoring: We also introduced new detections to monitor firewall-related security events on Windows systems, including: Windows Firewall Rule Added, Windows Firewall Rule Deletion, and Windows Firewall Rule Modification—helping security teams track unauthorized or suspicious changes to host-based firewall configurations.
New Analytic Stories - [8]
- Apache Tomcat Session Deserialization Attacks
- Medusa Ransomware
- PHP-CGI RCE Attack on Japanese Organizations
- Salt Typhoon
- Seashell Blizzard
- Termite Ransomware
- VanHelsing Ransomware
- ZDI-CAN-25373 Windows Shortcut Exploit Abused as Zero-Day (Contributor: @ajkingio , @hunter-3)
New Analytics - [15]
- Detect Large ICMP Traffic
- Tomcat Session Deserialization Attempt
- Tomcat Session File Upload Attempt
- Windows AD Self DACL Assignment
- Windows ConsoleHost History File Deletion
- Windows Explorer LNK Exploit Process Launch With Padding (Contributor: @ajkingio, @hunter-3)
- Windows Explorer.exe Spawning PowerShell or Cmd (Contributor: @ajkingio, @hunter-3)
- Windows Firewall Rule Added
- Windows Firewall Rule Deletion
- Windows Firewall Rule Modification
- Windows MSTSC RDP Commandline
- Windows Powershell History File Deletion
- Windows Process Injection into Commonly Abused Processes (Contributor: @0xC0FFEEEE)
- Windows Remote Host Computer Management Access
- Windows SSH Proxy Command(Contributor: @ajkingio, @hunter-3)
Other Updates
- Updated
ransomware_extensionsandremote_access_softwarelookup with new values. (Contributor @sventec) - Updated a majority of detections to output improved field names, which should enhance how they appear in Enterprise Security. We also added output_fields to the data source objects to enforce output validation for detection analytics
- Fixed a minor bug that prevented the deprecated and removed content warning banner from displaying correctly on the landing page
v5.2.0
Key highlights
We released new analytic stories and detections to enhance monitoring and security across GitHub, O365, and SQL Server environments. Here’s a summary of the latest updates:
-
👨💻 GitHub Malicious Activity: A new analytic story focused on detecting potential security risks and policy violations in GitHub Enterprise and GitHub Organizations. This includes detections for disabling 2FA requirements, modifying or pausing audit log event streams, deleting repositories, disabling security features like Dependabot and branch protection rules, and registering unauthorized self-hosted runners—helping organizations prevent unauthorized changes and account takeovers.
-
📧 O365 Email Threat Monitoring: Expanded coverage for malicious email activity in O365 environments. New detections focus on identifying inbox rule modifications, excessive email deletions, suspicious exfiltration behavior, and attempts to compromise payroll or password information. These detections help security teams track and mitigate email-based attacks, account takeovers, and data exfiltration tactics.
-
🗒️ SQL Server Abuse: Introduced a new analytic story targeting SQL Server exploitation tactics. These detections cover malicious SQLCMD execution, abuse of xp_cmdshell, unauthorized configuration changes, and the loading of potentially dangerous extended procedures. This enhanced monitoring helps organizations detect lateral movement and privilege escalation attempts in Windows-based SQL environments.
-
🔍 We have also mapped several of our existing detections to the Black Basta Ransomware, SnappyBee and SystemBC malware families as they continue to make headlines targeting various organizations.
-
🎗️ As announced in ESCU v5.0.0 release, we are removing old and dated content from the app starting with ESCU v5.2.0, which includes several removal of detections in this release to improve quality of detections. Along with the deprecation assistant that is shipped in the application, you can also refer to this list of removed detections and replacements on Splunk docs.
New Analytic Story - [6]
- Black Basta Ransomware
- China-Nexus Threat Activity
- GitHub Malicious Activity
- SQL Server Abuse
- SnappyBee
- SystemBC
New Analytics - [43]
- Executables Or Script Creation In Temp Path
- GitHub Enterprise Delete Branch Ruleset
- GitHub Enterprise Disable 2FA Requirement
- GitHub Enterprise Disable Audit Log Event Stream
- GitHub Enterprise Disable Classic Branch Protection Rule
- GitHub Enterprise Disable Dependabot
- GitHub Enterprise Disable IP Allow List
- GitHub Enterprise Modify Audit Log Event Stream
- GitHub Enterprise Pause Audit Log Event Stream
- GitHub Enterprise Register Self Hosted Runner
- GitHub Enterprise Remove Organization
- GitHub Enterprise Repository Archived
- GitHub Enterprise Repository Deleted
- GitHub Organizations Delete Branch Ruleset
- GitHub Organizations Disable 2FA Requirement
- GitHub Organizations Disable Classic Branch Protection Rule
- GitHub Organizations Disable Dependabot
- GitHub Organizations Repository Archived
- GitHub Organizations Repository Deleted
- O365 BEC Email Hiding Rule Created (External Contributor: @0xC0FFEEEE )
- O365 Email Hard Delete Excessive Volume (External Contributor: @nterl0k)
- O365 Email New Inbox Rule Created (External Contributor: @nterl0k)
- O365 Email Password and Payroll Compromise Behavior (External Contributor: @nterl0k)
- O365 Email Receive and Hard Delete Takeover Behavior (External Contributor: @nterl0k)
- O365 Email Send Attachments Excessive Volume(External Contributor: @nterl0k)
- O365 Email Send and Hard Delete Exfiltration Behavior(External Contributor: @nterl0k)
- O365 Email Send and Hard Delete Suspicious Behavior(External Contributor: @nterl0k)
- O365 Email Suspicious Search Behavior(External Contributor: @nterl0k)
- Windows Anonymous Pipe Activity
- Windows PowerShell Invoke-Sqlcmd Execution
- Windows Process Execution From ProgramData
- Windows SQL Server Configuration Option Hunt
- Windows SQL Server Critical Procedures Enabled
- Windows SQL Server Extended Procedure DLL Loading Hunt
- Windows SQL Server Startup Procedure
- Windows SQL Server xp_cmdshell Config Change
- Windows SQLCMD Execution
- Windows Scheduled Task with Suspicious Command
- Windows Scheduled Task with Suspicious Name
- Windows SnappyBee Create Test Registry
- Windows Sqlservr Spawning Shell
- Windows Svchost.exe Parent Process Anomaly
- Windows Unusual SysWOW64 Process Run System32 Executable
Macros Added - [5]
- github_enterprise
- github_organizations
- o365_messagetrace
- o365_suspect_search_terms_regex
- process_sqlcmd
Macros Updated - [1]
- linux_auditd
Lookups Added - [2]
- deprecation_info
- windows_suspicious_tasks
Lookups Updated - [1]
- ransomware_notes_lookup
Removed detections from v5.2.0
- The list of removed detections and its potential replacements(where available)
Marked for Deprecation in v5.4.0
- AWS SAML Access by Provider User and Principal
- GitHub Actions Disable Security Workflow
- aws detect permanent key creation
- Github Commit In Develop
- Suspicious Driver Loaded Path
- Known Services Killed by Ransomware
- Github Commit Changes In Master
- GitHub Pull Request from Unknown User
- [Suspicious Event Log Service Behavior](https://research.splunk.com/deprecated/2b85aa3d-f5f6-4c2e-a081-a09f6e1c2e...
v5.1.1
Release notes -v5.1.1 (Patch build)
- Minor text update to
malicious_powershell_strings.csvlookup file that caused MS Defender to falsely flag ESCU v5.1.0 as a malware.
v5.1.0
Release notes - v5.1.0
Key highlights
We released 4 new analytic stories and added 41 new detection analytics. Some high level details of the new analytic stories in this release
-
📡 Remote Monitoring and Management Software: Added a new story file to help users analyze unauthorized remote monitoring & management (RMM) tool usage, including detection of 3rd-party software installations like AnyDesk and TeamViewer through phishing/drive-by compromises.
-
☁️ AWS S3 Bucket Security Monitoring: A new analytic story which addresses the risks associated with S3 bucket misconfigurations and potential hijacking of decommissioned buckets. This story includes baselines and detections that track public S3 buckets before deletion, monitor access attempts to these bucket names, and identify potential hijacking activities, leveraging AWS CloudTrail logs, DNS queries, and web proxy data to ensure robust monitoring and security.
-
🛡️ Security Solution Tampering: A new analytic story, which includes new detections focused on identifying tampering activities with Cisco Secure Endpoint services. These detections cover techniques such as inhibiting system recovery and disabling or modifying security tools, enhancing our ability to detect and respond to potential security threats.
-
📋 Windows Audit Policy Tampering: We also added detections for Windows audit policies, which are crucial for logging key system activities for monitoring and forensic analysis. This analytic story provides a framework to detect suspicious activities involving audit policy manipulation, such as the use of auditpol.exe with specific flags, helping to uncover potential malicious activity and maintain the integrity of security monitoring mechanisms.
-
In addition, external contributor @nterl0k has significantly enhanced our detection capabilities with six new Office 365 security detections and several other detections.. These include monitoring changes to email transport rules, various methods of data exfiltration, and suspicious authentication and search behaviors, providing robust protection against potential threats.
New Analytic Story - [4]
- AWS S3 Bucket Security Monitoring
- Remote Monitoring and Management Software (External Contributor: @nterl0k)
- Security Solution Tampering
- Windows Audit Policy Tampering
New Analytics - [41]
- Cisco Secure Application Alerts
- Cisco AI Defense Security Alerts by Application Name
- Detect Web Access to Decommissioned S3 Bucket
Detect DNS Query to Decommissioned S3 Bucket - O365 Email Transport Rule Changed (External Contributor: @nterl0k)
- O365 Exfiltration via File Access (External Contributor: @nterl0k)
- O365 Exfiltration via File Download (External Contributor: @nterl0k)
- O365 Exfiltration via File Sync Download (External Contributor: @nterl0k)
- O365 Multiple OS Vendors Authenticating From User (External Contributor: @nterl0k)
- O365 SharePoint Suspicious Search Behavior (External Contributor: @nterl0k)
- Potential Telegram API Request Via CommandLine (External Contributor: @zake1god)
- Windows Audit Policy Auditing Option Disabled via Auditpol
- Windows Audit Policy Auditing Option Modified - Registry
- Windows Audit Policy Cleared via Auditpol
- Windows Audit Policy Disabled via Auditpol
- Windows Audit Policy Disabled via Legacy Auditpol
- Windows Audit Policy Excluded Category via Auditpol
- Windows Audit Policy Restored via Auditpol
- Windows Audit Policy Security Descriptor Tampering via Auditpol
- Windows BitLocker Suspicious Command Usage (External Contributor: @nterl0k)
- Windows Cisco Secure Endpoint Related Service Stopped
- Windows Cisco Secure Endpoint Stop Immunet Service Via Sfc
- Windows Cisco Secure Endpoint Unblock File Via Sfc
- Windows Cisco Secure Endpoint Uninstall Immunet Service Via Sfc
- Windows Compatibility Telemetry Suspicious Child Process
- Windows Compatibility Telemetry Tampering Through Registry
- Windows Event Logging Service Has Shutdown
- Windows Global Object Access Audit List Cleared Via Auditpol
- Windows Important Audit Policy Disabled
- Windows PowerShell Process With Malicious String (External Contributor: @nterl0k)
- Windows PowerShell Script Block With Malicious String (External Contributor: @nterl0k)
- Windows Process Executed From Removable Media (External Contributor: @nterl0k)
- Windows Process Execution in Temp Dir
- Windows Remote Desktop Network Bruteforce Attempt
- Windows Security And Backup Services Stop
- Windows Service Created with Suspicious Service Name
- Windows Suspicious Driver Loaded Path
- Windows Suspicious Process File Path
- Windows System Remote Discovery With Query
- Windows USBSTOR Registry Key Modification (External Contributor: @nterl0k)
- Windows WPDBusEnum Registry Key Modification (External Contributor: @nterl0k)
(Big thank you to @nterl0k from our Github Community for contributing several amazing tested detections, stories, lookups for this release! )
Macros Added - [4]
- important_audit_policy_subcategory_guids
- normalized_service_binary_field
- process_auditpol
- windows_exchange_iis
Macros Updated - [11]
- ms_defender
- powershell
- printservice
- remoteconnectionmanager
- sysmon
- wineventlog_application
- wineventlog_rdp
- wineventlog_security
- wineventlog_system
- wineventlog_task_scheduler
- wmi
Lookups Added - [2]
- malicious_powershell_strings
- windows_suspicious_services
Lookups Updated - [5]
- asr_rules
- builtin_groups_lookup
- dynamic_dns_providers_default
- remote_access_software
- security_services_lookup
Other updates
- New baselines: Baseline Of Open S3 Bucket Decommissioning
- Added a dropdown for dashboards to the navigation bar
v5.0.0
🌟 Github Community
🎉 The Splunk Threat Research Team is thrilled to announce Enterprise Security Content Update (ESCU) v5.0.0!
Key Highlights
-
(NEW) 🚨 Deprecation Assistant Dashboard: This release introduces a deprecation assistant dashboard for ESCU users to identify and manage deprecated detection analytics currently enabled in their Splunk Environment. These detections will be removed in ESCU v5.2.0 and could disrupt environments using them. For more in-depth information about which pieces of content will be removed and their replacements, please refer to the docs - 📄 Documentation.
-
(NEW) 🛠️ Analytic Story Onboarding Assistant: In this release, we've introduced a redesigned home page with an enhanced UI that offers direct access to release notes, analytics counts, and the latest version on Splunkbase, complemented by a detailed timeline of STRT blogs and updates. Additionally, we've launched the Analytic Story Onboarding Assistant, a new preview feature designed to streamline the process of enabling several detections from multiple analytics stories for which there is data available in your Splunk Environment.
-
🔍 New Analytics: We have expanded our threat detection capabilities by mapping existing analytics and developing new detections for a range of threats, including Backdoor Pingpong, Cleo File Transfer Software, Crypto Stealer, SDDL Tampering Defense Evasion, Derusbi, Earth Estries, Nexus APT Threat Activity, WinDealer RAT, and XorDDos.
New Analytic Story - [9]
- Backdoor Pingpong
- Cleo File Transfer Software
- Crypto Stealer
- Defense Evasion or Unauthorized Access Via SDDL Tampering
- Derusbi
- Earth Estries
- Nexus APT Threat Activity
- WinDealer RAT
- XorDDos
New Analytics - [52]
- ASL AWS Create Access Key
- ASL AWS Create Policy Version to allow all resources
- ASL AWS Credential Access GetPasswordData
- ASL AWS Credential Access RDS Password reset
- ASL AWS Defense Evasion PutBucketLifecycle
- ASL AWS Detect Users creating keys with encrypt policy without MFA
- ASL AWS Disable Bucket Versioning
- ASL AWS EC2 Snapshot Shared Externally
- ASL AWS IAM AccessDenied Discovery Events
- ASL AWS IAM Assume Role Policy Brute Force
- ASL AWS Network Access Control List Created with All Open Ports
- ASL AWS Network Access Control List Deleted
- ASL AWS SAML Update identity provider
- ASL AWS UpdateLoginProfile
- Azure AD AzureHound UserAgent Detected
- Azure AD Service Principal Enumeration
- Azure AD Service Principal Privilege Escalation
- Detect Remote Access Software Usage Registry
- Microsoft Intune Device Health Scripts
- Microsoft Intune DeviceManagementConfigurationPolicies
- Microsoft Intune Manual Device Management
- O365 Service Principal Privilege Escalation
- Windows Account Access Removal via Logoff Exec
- Windows CertUtil Download With URL Argument
- Windows DNS Query Request by Telegram Bot API
- Windows Detect Network Scanner Behavior
- Windows File and Directory Enable ReadOnly Permissions
- Windows File and Directory Permissions Enable Inheritance
- Windows File and Directory Permissions Remove Inheritance
- Windows Impair Defenses Disable Auto Logger Session
- Windows New Custom Security Descriptor Set On EventLog Channel
- Windows New Deny Permission Set On Service SD Via Sc.EXE
- Windows New EventLog ChannelAccess Registry Value Set
- Windows New Service Security Descriptor Set Via Sc.EXE
- Windows Obfuscated Files or Information via RAR SFX
- Windows Office Product Dropped Cab or Inf File
- Windows Office Product Dropped Uncommon File
- Windows Office Product Spawned Control
- Windows Office Product Spawned MSDT
- Windows Office Product Spawned Rundll32 With No DLL
- Windows Office Product Spawned Uncommon Process
- Windows Powershell Logoff User via Quser
- Windows Process With NetExec Command Line Parameters
- Windows Registry Dotnet ETW Disabled Via ENV Variable
- Windows Remote Management Execute Shell
- Windows ScManager Security Descriptor Tampering Via Sc.EXE
- Windows Service Execution RemCom
- Windows Service Stop Attempt
- Windows Set Account Password Policy To Unlimited Via Net
- Windows SubInAcl Execution
- Windows Suspicious Child Process Spawned From WebServer
- Windows User Discovery Via Net
Other Updates
- We've updated our YAML configurations by enhancing validation, improving accuracy and consistency, and replacing the 'observables' key with an 'RBA' key to better align with Enterprise Security standards and simplify risk attribution.
v4.44.0
STRT is excited to welcome @nasbench to the team! Congrats on your first of many PRs! #3213
Release notes - v4.44.0
Total New and Updated Content: [357]
Key highlights
- Windows Defender: Two new analytics now surface and summarize alerts from Microsoft Defender Advanced Threat Protection (ATP) as well as Microsoft Defender O365 Incidents.
- BitLockerToGo Abuse: Two new analytics search for use of the legitimate BitLockerToGo.exe Windows utility. This application has been abused by the Lumma Stealer malware to manipulate registry keys, search for cryptocurrency wallets or credentials, and exfiltrate sensitive data.
- VaultCLI Usage: One new analytic flags suspicious usage of the VaultCLI.dll, a technique observed by Information-Stealing Malware such as Meduza. This DLL allows processes to extract sensitive credentials from the Windows Credential Vault.
- Windows RDP Activities: Two new analytics look for potentially suspicious Windows RDP activities.
- Windows RunMRU Modifications: One analytic monitors changes to the RunMRU registry key. This key, which stores a history of commands executed via the windows Run dialog box, may capture commands run by malware attempting to appear legitimate.
New Analytic Story - [3]
New Analytics - [8]
- Microsoft Defender ATP Alerts
- Microsoft Defender Incident Alerts
- Windows BitLockerToGo Process Execution
- Windows BitLockerToGo with Network Activity
- Windows Credentials Access via VaultCli Module
- Windows RDP File Execution
- Windows RDPClient Connection Sequence Events
- Windows RunMRU Command Execution
Updated Analytics - [261]
- 7zip CommandLine To SMB Share Path
- Active Setup Registry Autostart
- Add DefaultUser And Password In Registry
- Add or Set Windows Defender Exclusion
- Allow Inbound Traffic By Firewall Rule Registry
- Allow Operation with Consent Admin
- Any Powershell DownloadFile
- Attacker Tools On Endpoint
- Attempted Credential Dump From Registry via Reg exe
- Auto Admin Logon Registry Entry
- BCDEdit Failure Recovery Modification
- Batch File Write to System32
- CMD Echo Pipe - Escalation
- CertUtil Download With URLCache and Split Arguments
- CertUtil Download With VerifyCtl and Split Arguments
- Certutil exe certificate extraction
- Clear Unallocated Sector Using Cipher App
- Clop Common Exec Parameter
- Clop Ransomware Known Service Name
- ConnectWise ScreenConnect Path Traversal Windows SACL
- Conti Common Exec parameter
- Control Loading from World Writable Directory
- Create Remote Thread In Shell Application
- Create local admin accounts using net exe
- Creation of Shadow Copy with wmic and powershell
- Creation of Shadow Copy
- Credential Dumping via Copy Command from Shadow Copy
- Credential Dumping via Symlink to Shadow Copy
- Curl Download and Bash Execution
- DNS Exfiltration Using Nslookup App
- DSQuery Domain Discovery
- Deleting Shadow Copies
- Detect AzureHound Command-Line Arguments
- Detect Certify Command Line Arguments
- Detect Distributed Password Spray Attempts
- Detect Exchange Web Shell
- Detect HTML Help Spawn Child Process
- Detect HTML Help URL in Command Line
- Detect HTML Help Using InfoTech Storage Handlers
- Detect MSHTA Url in Command Line
- Detect Password Spray Attempts
- Detect Regasm Spawning a Process
- Detect Regsvcs Spawning a Process
- Detect Regsvr32 Application Control Bypass
- Detect Rundll32 Application Control Bypass - advpack
- Detect Rundll32 Application Control Bypass - setupapi
- Detect Rundll32 Application Control Bypass - syssetup
- Detect Webshell Exploit Behavior
- Detect mshta inline hta execution
- Disable AMSI Through Registry
- Disable Defender AntiVirus Registry
- Disable Defender BlockAtFirstSeen Feature
- Disable Defender Enhanced Notification
- Disable Defender MpEngine Registry
- Disable Defender Spynet Reporting
- Disable Defender Submit Samples Consent Feature
- Disable ETW Through Registry
- Disable Logs Using WevtUtil
- Disable Registry Tool
- Disable Security Logs Using MiniNt Registry
- Disable Show Hidden Files
- Disable UAC Remote Restriction
- Disable Windows App Hotkeys
- [Disable Windows Behavior Monitoring](htt...
v4.43.0
Release notes - v4.43.0
Total New and Updated Content: [1645]
Key highlights
Detection Analytics Updates
- Critical Alerts: Introduced a new analytic to detect critical alerts from multiple security tools, enhancing quick identification and response for high-priority threats. Tested with MS365 Defender and Windows Defender Alerts, compatible with any vendor alerts mapped to the Alerts data model.
- Braodo Stealer: Added detections focused on identifying malicious behaviors associated with information-stealing malware.
Tooling Updates
We have released new version of contentctl (v4.4.5) that help with build and test ESCU content:
- Enhanced Drilldowns: Added two default drilldowns for all notable detections, enabling users to view detection results for specific risk objects and access risk events from the past 7 days. This improves investigation workflows and response efficiency.
- Version Enforcement & Datasource Testing: Enhanced version enforcement for detection content, automatically updating search versions when YAML changes. Added new datasource testing for detections, ensuring compatibility when new TAs are available.
Documentation Update
Additionally, the Splunk documentation and Github Wiki is also updated to include the latest features shipped in the Enterprise Security Content Update (ESCU). This update provides detailed guidance on using and testing these detections with Splunk Enterprise Security.
New Analytic Story - [2]
New Analytics - [9]
- Detect Critical Alerts from Security Tools
- High Volume of Bytes Out to Url
- Internal Horizontal Port Scan NMAP Top 20
- Plain HTTP POST Exfiltrated Data
- Windows Archived Collected Data In TEMP Folder
- Windows Credentials from Password Stores Chrome Copied in TEMP Dir
- Windows Credentials from Web Browsers Saved in TEMP Folder
- Windows Disable or Stop Browser Process
- Windows Screen Capture in TEMP folder
Updated Analytics - [1532]
- All TTP/Anomaly and Correlation type detections now have two drilldowns added to their yaml files.
Huge thanks to @dluxtron for contributing new detections and enhancing existing ones!
v4.42.0
Total New and Updated Content: [18]
Key Highlights:
Splunk Vulnerabilities: This release introduces key detections for recently disclosed Splunk vulnerabilities, including issues like disabling KVStore via CSRF, image file disclosure in PDF exports, and persistent XSS attacks. It also covers critical vulnerabilities such as remote code execution through arbitrary file writes and sensitive information disclosure in low-privileged user sessions and DEBUG logs. These detections enhance monitoring for exploitation attempts, improving Splunk's defenses against potential attacks and data breaches.
CISA AA24-241A : This new analytic story delivers detections tailored to identify malicious usage of PowerShell Web Access (PSWA) in Windows environments. These new detections focus on monitoring PowerShell Web Access activity through the IIS application pool and web access logs, providing enhanced visibility into suspicious or unauthorized access. The story introduces two key detections: "Windows Identify PowerShell Web Access IIS Pool" and "Windows IIS Server PSWA Console Access," which track the creation and usage of PSWA sessions, anomalies in IIS pool configurations, and unusual patterns of console access. By improving detection of PowerShell Web Access exploitation, we can defenses against potential privilege escalation, lateral movement, and remote code execution attempts within Windows infrastructures.
In addition to these updates, the detection logic for "Windows AdFind Exe" and "Linux Auditd Change File Owner To Root" has been improved based on customer feedback. These enhancements provide more accurate identification of AdFind tool usage in Windows environments and better detection of unauthorized file ownership changes to root in Linux systems, further fortifying defenses against privilege abuse and lateral movement techniques across both platforms.
New Analytic Story - [0]
Updated Analytic Story - [1]
New Analytics - [10]
- Splunk Disable KVStore via CSRF Enabling Maintenance Mode
- Splunk Image File Disclosure via PDF Export in Classic Dashboard
- Splunk Low-Priv Search as nobody SplunkDeploymentServerConfig App
- Splunk Persistent XSS via Props Conf
- Splunk Persistent XSS via Scheduled Views
- Splunk RCE Through Arbitrary File Write to Windows System Root
- Splunk SG Information Disclosure for Low Privs User
- Splunk Sensitive Information Disclosure in DEBUG Logging Channels
- Windows IIS Server PSWA Console Access
- Windows Identify PowerShell Web Access IIS Pool
Updated Analytics - [15]
- Create Remote Thread into LSASS
- Detect Regsvcs with Network Connection
- Linux Auditd Change File Owner To Root
- Possible Lateral Movement PowerShell Spawn
- Suspicious Process DNS Query Known Abuse Web Services
- Windows AdFind Exe
- Windows DISM Install PowerShell Web Access
- Windows Enable PowerShell Web Access
- Windows Impair Defenses Disable AV AutoStart via Registry
- Windows Modify Registry Utilize ProgIDs
- Windows Modify Registry ValleyRAT C2 Config
- Windows Modify Registry ValleyRat PWN Reg Entry
- Windows Privileged Group Modification
- Windows Scheduled Task DLL Module Loaded
- Windows Scheduled Tasks for CompMgmtLauncher or Eventvwr
Other Updates
- Updated README.md and WIKI on Github repository
v4.41.0
Key Highlights
ValleyRAT Analytic Story: This update introduces comprehensive detections tailored to the ValleyRAT malware, providing enhanced monitoring and threat-hunting capabilities for adversarial activity on Windows systems. The story includes new detections focusing on impairing defenses, modifying system registries, and exploiting privilege escalation mechanisms. Key detections cover tactics such as disabling antivirus via registry modifications, setting Windows Defender exclusions, and UAC bypass techniques like FodHelper and Eventvwr. These detections improve visibility into malicious registry changes, task scheduling anomalies, and suspicious executable behavior, fortifying defenses against ValleyRAT C2 activity and privilege abuse attempts.
Total New and Updated Content: [16]
New Analytic Story - [1]
Updated Analytic Story - [0]
New Analytics - [6]
Windows Impair Defenses Disable AV AutoStart via Registry
Windows Modify Registry Utilize ProgIDs
Windows Modify Registry ValleyRAT C2 Config
Windows Modify Registry ValleyRat PWN Reg Entry
Windows Schedule Task DLL Module Loaded
Windows Schedule Tasks for CompMgmtLauncher or Eventvwr
Updated Analytics - [9]
Add or Set Windows Defender Exclusion
CMLUA Or CMSTPLUA UAC Bypass
Eventvwr UAC Bypass
Executables Or Script Creation In Suspicious Path
FodHelper UAC Bypass
Suspicious Process File Path
WinEvent Windows Task Scheduler Event Action Started
Windows Access Token Manipulation SeDebugPrivilege
Windows Defender Exclusion Registry Entry