github splunk/security_content v3.17.0

latest releases: v4.41.0, v4.40.0, v4.39.1...
3 years ago

New Analytic Stories

  • Windows Discovery Techniques

New Detections

  • Detect Exchange Webshell

Updated Analytic Stories

  • Sunburst Malware ( now called NOBELIUM Group)

Updated Detections

  • Ryuk Wake On Lan Command
  • Any Powershell DownloadFile
  • Cobalt Strike Named Pipes
  • Suspicious Curl Network Connection
  • Detect Mimikatz Using Loaded Images
  • W3wp Spawning Shell

Don't miss a new security_content release

NewReleases is sending notifications on new releases.