github splunk/security_content v4.38.0

latest releases: v4.42.0, v4.41.0, v4.40.0...
2 months ago

Key highlights

Enterprise Security Content Update version 4.38.0 introduces new detections focusing on Windows Endpoints and Office365 with specific attention to identity and access management vulnerabilities. This version also includes detections to identify unusual NTLM authentication patterns. A number of new detections are included for Crowdstrike environments to identify weak password policies, detect duplicate passwords among users and administrators, assess identity risk with various severity levels, and detect privilege escalation attempts in non-administrative accounts. For Office 365 environments, this update includes detections to monitor cross-tenant access changes, external guest invitations, changes in external identity policies, and privileged role assignments. Finally, two new analytic stores are included for help detect Compromised Windows Hosts or activities linked to the Handala Wiper Malware.

New Analytic Story - [2]

Updated Analytic Story - [1]

New Analytics - [20]

Updated Analytics - [13]

Macros Added - [3]

  • crowdstrike_identities
  • crowdstrike_stream
  • ntlm_audit

Macros Updated - [1]

  • linux_hosts

Lookups Updated - [1]

  • privileged_azure_ad_roles

Other Updates

  • Added new data_source objects
  • Changes TA names in data sources to match the name in Splunk
  • Updated TA version to match the latest (new check in contentctl)
  • Add configuration file to Sysmon and Windows Event Code 4688
  • Update analytic story on detections for Handala Wiper

Don't miss a new security_content release

NewReleases is sending notifications on new releases.