github splunk/security_content v4.33.0

latest releases: v4.41.0, v4.40.0, v4.39.1...
3 months ago

Key highlights

Enterprise Security Content Updates version 4.33.0 adds a new detection, CrushFTP Server Side Template Injection. This detection highlights any attempts to exploit CVE-2024-4040, a critical vulnerability that allows unauthenticated remote attackers to run arbitrary code and bypass authentication in CrushFTP versions before 10.7.1 and 11.1.0.

Additionally, this release includes updates to the detection logic of some analytics that use lookups. This includes changing the order of operations in the SPL so that the lookup command is run after the stats command. Thus, in a distributed environment, lookups don't need to be replicated and the search performance improves slightly in all environments because it involves looking up values for fewer events.

New Analytic Story - [1]

New Analytics - [1]

Updated Analytics - [12]

Other Updates

  • Updated descriptions for 80+ analytics to have a consistent standard and formatting.

Don't miss a new security_content release

NewReleases is sending notifications on new releases.