Skip to content

Releases: splunk/security_content

v5.4.0

Choose a tag to compare

@patel-bhavin patel-bhavin released this 23 Apr 22:01
de5542c

✨ Highlights

  • 🔥 Cisco Secure Firewall Threat Defense Analytics: We published a new analytic story and added new detections for Cisco Secure Firewall focusing on three primary event types—file events, network connections, and intrusion alerts. These detections identify activity such as malicious or uncommon file downloads, connections over suspicious ports or to file-sharing domains, and Snort rule-based intrusion events across multiple hosts. This enables broader visibility into network-based threats and host-level indicators of compromise.

  • 🤖 AWS Bedrock Security: Released a new analytic story to monitor for adversary techniques targeting AWS Bedrock, a managed service used to build and scale generative AI applications. This includes detections for the deletion of security guardrails, knowledge bases, and logging configurations, as well as high volumes of model invocation failures.

  • 🕵️ Mapping Threat Campaigns: Several detections have been mapped to known threat actors and malware campaigns, including Cactus Ransomware, Earth Alux, Storm-2460 CLFS Zero Day Exploitation and Water Gamayun, to improve attribution to TTPs and provide insights into observed behaviors.

  • 🆕 New Detections: Introduced additional detections for tactics such as directory path manipulation via MSC files, IP address collection using PowerShell Invoke-RestMethod, process spawning from CrushFTP, and deletion of Volume Shadow Copies via WMIC. These detections target adversary behavior related to discovery, lateral movement, and anti-forensics.


📚 New Analytic Stories – [6]


🧠 New Analytics – [27]


🛠 Other Updates

  • 🔄 Reverted several searches to use | join instead of prestats = t due to bugs encountered in the search logic.
  • ❌ Removed Detections – As notified in the ESCU v5.2.0 release, we have removed these detections. Please use replacements where appropriate.
  • 🗓️ Deprecated more detections now scheduled for removal in ESCU v5.6.0.
  • 📥 Updated deprecation_info lookup to reflect the latest list of deprecated and removed detections.

v5.3.0

Choose a tag to compare

@patel-bhavin patel-bhavin released this 09 Apr 17:11
31deacc

Key Highlights

  • ⚙️ Detection Output Standardization: Additionally, we’ve updated the majority of our detections to include a standardized set of output fields within each detection analytic and enhanced our tooling to consistently enforce this structure—improving usability, correlation, and integration across security workflows.

  • 🚨 Apache Tomcat Session Deserialization Attacks: CVE-2025-24813 is an unauthenticated remote code execution vulnerability in Apache Tomcat’s partial PUT feature disclosed on March 10, 2025. We introduced a new analytic story targeting potential exploitation of Apache Tomcat servers. This story includes detections for suspicious session deserialization attempts and file uploads—techniques commonly used by attackers to gain remote access or execute arbitrary code.

  • 🪟 Windows Shortcut Exploit Abuse: Released a new analytic story to detect emerging exploitation patterns involving Windows LNK files. This includes detections for abuse of SSH ProxyCommand, LNK files with abnormal padding, and Windows Explorer spawning suspicious processes like PowerShell or CMD. These analytics are designed to surface stealthy initial access and execution techniques leveraged in recent zero-day attacks. More details can be found here - (ZDI-CAN-25373)

  • 💥 New Ransomware Campaigns: We’ve expanded our ransomware mapping to include detection coverage for emerging threats such as Medusa Ransomware, Termite, Van Helsing, Salt Typhoon, and Sea Shell Blizzard. These mappings help contextualize detections within current threat actor TTPs and provide better visibility into campaign-specific behaviors.

  • 🔥 Windows Firewall Rule Monitoring: We also introduced new detections to monitor firewall-related security events on Windows systems, including: Windows Firewall Rule Added, Windows Firewall Rule Deletion, and Windows Firewall Rule Modification—helping security teams track unauthorized or suspicious changes to host-based firewall configurations.

New Analytic Stories - [8]

New Analytics - [15]

Other Updates

  • Updated ransomware_extensions and remote_access_software lookup with new values. (Contributor @sventec)
  • Updated a majority of detections to output improved field names, which should enhance how they appear in Enterprise Security. We also added output_fields to the data source objects to enforce output validation for detection analytics
  • Fixed a minor bug that prevented the deprecated and removed content warning banner from displaying correctly on the landing page

v5.2.0

Choose a tag to compare

@patel-bhavin patel-bhavin released this 24 Mar 18:41
4583864

Key highlights

We released new analytic stories and detections to enhance monitoring and security across GitHub, O365, and SQL Server environments. Here’s a summary of the latest updates:

  • 👨‍💻 GitHub Malicious Activity: A new analytic story focused on detecting potential security risks and policy violations in GitHub Enterprise and GitHub Organizations. This includes detections for disabling 2FA requirements, modifying or pausing audit log event streams, deleting repositories, disabling security features like Dependabot and branch protection rules, and registering unauthorized self-hosted runners—helping organizations prevent unauthorized changes and account takeovers.

  • 📧 O365 Email Threat Monitoring: Expanded coverage for malicious email activity in O365 environments. New detections focus on identifying inbox rule modifications, excessive email deletions, suspicious exfiltration behavior, and attempts to compromise payroll or password information. These detections help security teams track and mitigate email-based attacks, account takeovers, and data exfiltration tactics.

  • 🗒️ SQL Server Abuse: Introduced a new analytic story targeting SQL Server exploitation tactics. These detections cover malicious SQLCMD execution, abuse of xp_cmdshell, unauthorized configuration changes, and the loading of potentially dangerous extended procedures. This enhanced monitoring helps organizations detect lateral movement and privilege escalation attempts in Windows-based SQL environments.

  • 🔍 We have also mapped several of our existing detections to the Black Basta Ransomware, SnappyBee and SystemBC malware families as they continue to make headlines targeting various organizations.

  • 🎗️ As announced in ESCU v5.0.0 release, we are removing old and dated content from the app starting with ESCU v5.2.0, which includes several removal of detections in this release to improve quality of detections. Along with the deprecation assistant that is shipped in the application, you can also refer to this list of removed detections and replacements on Splunk docs.

New Analytic Story - [6]

New Analytics - [43]

Macros Added - [5]

  • github_enterprise
  • github_organizations
  • o365_messagetrace
  • o365_suspect_search_terms_regex
  • process_sqlcmd

Macros Updated - [1]

  • linux_auditd

Lookups Added - [2]

  • deprecation_info
  • windows_suspicious_tasks

Lookups Updated - [1]

  • ransomware_notes_lookup

Removed detections from v5.2.0

  • The list of removed detections and its potential replacements(where available)

Marked for Deprecation in v5.4.0

Read more

v5.1.1

Choose a tag to compare

@patel-bhavin patel-bhavin released this 04 Mar 18:21
3dbc72f

Release notes -v5.1.1 (Patch build)

  • Minor text update to malicious_powershell_strings.csv lookup file that caused MS Defender to falsely flag ESCU v5.1.0 as a malware.

v5.1.0

Choose a tag to compare

@patel-bhavin patel-bhavin released this 24 Feb 20:19
c795cda

Release notes - v5.1.0

Key highlights

We released 4 new analytic stories and added 41 new detection analytics. Some high level details of the new analytic stories in this release

  • 📡 Remote Monitoring and Management Software: Added a new story file to help users analyze unauthorized remote monitoring & management (RMM) tool usage, including detection of 3rd-party software installations like AnyDesk and TeamViewer through phishing/drive-by compromises.

  • ☁️ AWS S3 Bucket Security Monitoring: A new analytic story which addresses the risks associated with S3 bucket misconfigurations and potential hijacking of decommissioned buckets. This story includes baselines and detections that track public S3 buckets before deletion, monitor access attempts to these bucket names, and identify potential hijacking activities, leveraging AWS CloudTrail logs, DNS queries, and web proxy data to ensure robust monitoring and security.

  • 🛡️ Security Solution Tampering: A new analytic story, which includes new detections focused on identifying tampering activities with Cisco Secure Endpoint services. These detections cover techniques such as inhibiting system recovery and disabling or modifying security tools, enhancing our ability to detect and respond to potential security threats.

  • 📋 Windows Audit Policy Tampering: We also added detections for Windows audit policies, which are crucial for logging key system activities for monitoring and forensic analysis. This analytic story provides a framework to detect suspicious activities involving audit policy manipulation, such as the use of auditpol.exe with specific flags, helping to uncover potential malicious activity and maintain the integrity of security monitoring mechanisms.

  • In addition, external contributor @nterl0k has significantly enhanced our detection capabilities with six new Office 365 security detections and several other detections.. These include monitoring changes to email transport rules, various methods of data exfiltration, and suspicious authentication and search behaviors, providing robust protection against potential threats.

New Analytic Story - [4]

New Analytics - [41]

(Big thank you to @nterl0k from our Github Community for contributing several amazing tested detections, stories, lookups for this release! )

Macros Added - [4]

  • important_audit_policy_subcategory_guids
  • normalized_service_binary_field
  • process_auditpol
  • windows_exchange_iis

Macros Updated - [11]

  • ms_defender
  • powershell
  • printservice
  • remoteconnectionmanager
  • sysmon
  • wineventlog_application
  • wineventlog_rdp
  • wineventlog_security
  • wineventlog_system
  • wineventlog_task_scheduler
  • wmi

Lookups Added - [2]

  • malicious_powershell_strings
  • windows_suspicious_services

Lookups Updated - [5]

  • asr_rules
  • builtin_groups_lookup
  • dynamic_dns_providers_default
  • remote_access_software
  • security_services_lookup

Other updates

  • New baselines: Baseline Of Open S3 Bucket Decommissioning
  • Added a dropdown for dashboards to the navigation bar

v5.0.0

Choose a tag to compare

@patel-bhavin patel-bhavin released this 31 Jan 18:57
7712cd9

🌟 Github Community

🎉 The Splunk Threat Research Team is thrilled to announce Enterprise Security Content Update (ESCU) v5.0.0!

Key Highlights

  • (NEW) 🚨 Deprecation Assistant Dashboard: This release introduces a deprecation assistant dashboard for ESCU users to identify and manage deprecated detection analytics currently enabled in their Splunk Environment. These detections will be removed in ESCU v5.2.0 and could disrupt environments using them. For more in-depth information about which pieces of content will be removed and their replacements, please refer to the docs - 📄 Documentation.

  • (NEW) 🛠️ Analytic Story Onboarding Assistant: In this release, we've introduced a redesigned home page with an enhanced UI that offers direct access to release notes, analytics counts, and the latest version on Splunkbase, complemented by a detailed timeline of STRT blogs and updates. Additionally, we've launched the Analytic Story Onboarding Assistant, a new preview feature designed to streamline the process of enabling several detections from multiple analytics stories for which there is data available in your Splunk Environment.

  • 🔍 New Analytics: We have expanded our threat detection capabilities by mapping existing analytics and developing new detections for a range of threats, including Backdoor Pingpong, Cleo File Transfer Software, Crypto Stealer, SDDL Tampering Defense Evasion, Derusbi, Earth Estries, Nexus APT Threat Activity, WinDealer RAT, and XorDDos.

New Analytic Story - [9]

New Analytics - [52]

Other Updates

  • We've updated our YAML configurations by enhancing validation, improving accuracy and consistency, and replacing the 'observables' key with an 'RBA' key to better align with Enterprise Security standards and simplify risk attribution.

v4.44.0

Choose a tag to compare

@patel-bhavin patel-bhavin released this 05 Dec 22:31
300af51

STRT is excited to welcome @nasbench to the team! Congrats on your first of many PRs! #3213

Release notes - v4.44.0

Total New and Updated Content: [357]

Key highlights

  • Windows Defender: Two new analytics now surface and summarize alerts from Microsoft Defender Advanced Threat Protection (ATP) as well as Microsoft Defender O365 Incidents.
  • BitLockerToGo Abuse: Two new analytics search for use of the legitimate BitLockerToGo.exe Windows utility. This application has been abused by the Lumma Stealer malware to manipulate registry keys, search for cryptocurrency wallets or credentials, and exfiltrate sensitive data.
  • VaultCLI Usage: One new analytic flags suspicious usage of the VaultCLI.dll, a technique observed by Information-Stealing Malware such as Meduza. This DLL allows processes to extract sensitive credentials from the Windows Credential Vault.
  • Windows RDP Activities: Two new analytics look for potentially suspicious Windows RDP activities.
  • Windows RunMRU Modifications: One analytic monitors changes to the RunMRU registry key. This key, which stores a history of commands executed via the windows Run dialog box, may capture commands run by malware attempting to appear legitimate.

New Analytic Story - [3]

New Analytics - [8]

Updated Analytics - [261]

Read more

v4.43.0

Choose a tag to compare

@patel-bhavin patel-bhavin released this 14 Nov 01:21
738216a

Release notes - v4.43.0

Total New and Updated Content: [1645]

Key highlights

Detection Analytics Updates

  • Critical Alerts: Introduced a new analytic to detect critical alerts from multiple security tools, enhancing quick identification and response for high-priority threats. Tested with MS365 Defender and Windows Defender Alerts, compatible with any vendor alerts mapped to the Alerts data model.
  • Braodo Stealer: Added detections focused on identifying malicious behaviors associated with information-stealing malware.

Tooling Updates

We have released new version of contentctl (v4.4.5) that help with build and test ESCU content:

  • Enhanced Drilldowns: Added two default drilldowns for all notable detections, enabling users to view detection results for specific risk objects and access risk events from the past 7 days. This improves investigation workflows and response efficiency.
  • Version Enforcement & Datasource Testing: Enhanced version enforcement for detection content, automatically updating search versions when YAML changes. Added new datasource testing for detections, ensuring compatibility when new TAs are available.

Documentation Update

Additionally, the Splunk documentation and Github Wiki is also updated to include the latest features shipped in the Enterprise Security Content Update (ESCU). This update provides detailed guidance on using and testing these detections with Splunk Enterprise Security.

New Analytic Story - [2]

New Analytics - [9]

Updated Analytics - [1532]

  • All TTP/Anomaly and Correlation type detections now have two drilldowns added to their yaml files.

Huge thanks to @dluxtron for contributing new detections and enhancing existing ones!

v4.42.0

Choose a tag to compare

@patel-bhavin patel-bhavin released this 14 Oct 22:21
eb2e7d3

Total New and Updated Content: [18]

Key Highlights:

Splunk Vulnerabilities: This release introduces key detections for recently disclosed Splunk vulnerabilities, including issues like disabling KVStore via CSRF, image file disclosure in PDF exports, and persistent XSS attacks. It also covers critical vulnerabilities such as remote code execution through arbitrary file writes and sensitive information disclosure in low-privileged user sessions and DEBUG logs. These detections enhance monitoring for exploitation attempts, improving Splunk's defenses against potential attacks and data breaches.

CISA AA24-241A : This new analytic story delivers detections tailored to identify malicious usage of PowerShell Web Access (PSWA) in Windows environments. These new detections focus on monitoring PowerShell Web Access activity through the IIS application pool and web access logs, providing enhanced visibility into suspicious or unauthorized access. The story introduces two key detections: "Windows Identify PowerShell Web Access IIS Pool" and "Windows IIS Server PSWA Console Access," which track the creation and usage of PSWA sessions, anomalies in IIS pool configurations, and unusual patterns of console access. By improving detection of PowerShell Web Access exploitation, we can defenses against potential privilege escalation, lateral movement, and remote code execution attempts within Windows infrastructures.

In addition to these updates, the detection logic for "Windows AdFind Exe" and "Linux Auditd Change File Owner To Root" has been improved based on customer feedback. These enhancements provide more accurate identification of AdFind tool usage in Windows environments and better detection of unauthorized file ownership changes to root in Linux systems, further fortifying defenses against privilege abuse and lateral movement techniques across both platforms.

New Analytic Story - [0]

Updated Analytic Story - [1]

New Analytics - [10]

Updated Analytics - [15]

Other Updates

  • Updated README.md and WIKI on Github repository

v4.41.0

Choose a tag to compare

@patel-bhavin patel-bhavin released this 26 Sep 17:25
2e0a7c5

Key Highlights

ValleyRAT Analytic Story: This update introduces comprehensive detections tailored to the ValleyRAT malware, providing enhanced monitoring and threat-hunting capabilities for adversarial activity on Windows systems. The story includes new detections focusing on impairing defenses, modifying system registries, and exploiting privilege escalation mechanisms. Key detections cover tactics such as disabling antivirus via registry modifications, setting Windows Defender exclusions, and UAC bypass techniques like FodHelper and Eventvwr. These detections improve visibility into malicious registry changes, task scheduling anomalies, and suspicious executable behavior, fortifying defenses against ValleyRAT C2 activity and privilege abuse attempts.

Total New and Updated Content: [16]

New Analytic Story - [1]

ValleyRAT

Updated Analytic Story - [0]

New Analytics - [6]

Windows Impair Defenses Disable AV AutoStart via Registry
Windows Modify Registry Utilize ProgIDs
Windows Modify Registry ValleyRAT C2 Config
Windows Modify Registry ValleyRat PWN Reg Entry
Windows Schedule Task DLL Module Loaded
Windows Schedule Tasks for CompMgmtLauncher or Eventvwr

Updated Analytics - [9]

Add or Set Windows Defender Exclusion
CMLUA Or CMSTPLUA UAC Bypass
Eventvwr UAC Bypass
Executables Or Script Creation In Suspicious Path
FodHelper UAC Bypass
Suspicious Process File Path
WinEvent Windows Task Scheduler Event Action Started
Windows Access Token Manipulation SeDebugPrivilege
Windows Defender Exclusion Registry Entry