github splunk/security_content v5.12.0

latest release: v5.13.0
15 days ago

๐Ÿš€ Key Highlights

๐Ÿ›ก๏ธ Medusa Rootkit (UNC3886): Introduced a new analytic story for Medusa Rootkit, a stealthy malware leveraged by UNC3886 to maintain persistence on Linux ๐Ÿง and Windows ๐ŸชŸ systems. This release adds detections for Linux GDrive Binary Activity, Linux Medusa Rootkit, Windows GDrive Binary Activity, and Windows Suspicious VMware Tools Child Process, while also mapping other existing detections to this threat actor.

๐Ÿ“ฆ MSIX Package Abuse: We added a new analytic story covering abuse of Microsoft MSIX application packages, leveraging telemetry from AppXDeploymentServer/Operational logs ๐Ÿ“‘. This story introduces detections for suspicious MSIX behaviors, including Windows Advanced Installer MSIX with AI_STUBS Execution, Unsigned Package Installation, PowerShell MSIX Package Installation, and interactions with Windows Apps directories ๐Ÿ“‚, providing visibility into application sideloading and potential malware delivery.

๐Ÿ–ฅ๏ธ Windows RDP Artifacts & Defense Evasion: A new analytic story focused on RDP activity ๐Ÿ’ป followed by artifact cleanup ๐Ÿงน or evasion techniques. Windows RDP usage generates forensic artifacts such as Default.rdp files ๐Ÿ“„ and bitmap caches ๐Ÿ–ผ๏ธ that can reveal details about accessed systems. This release adds detections for RDP file creation, deletion, and un-hiding events, bitmap cache file activity, RDP server registry entry creation/deletion, and RDP client launched with admin session, while tagging existing detections to ensure comprehensive monitoring of both RDP usage and evasion behavior.


๐Ÿ“š New Analytic Stories โ€“ [3]

โ™ป๏ธ Updated Analytic Story โ€“ [1]

๐Ÿ†• New Analytics โ€“ [22]


โš ๏ธ Other Updates

As previously communicated in the ESCU v5.10.0 release, several detections have been removed.
For a complete list of the detections removed in version v5.12.0, refer to the List of Removed Detections.

Additionally, a new set of detections has been deprecated.
For details on detections scheduled for removal in ESCU v5.14.0, see the List of Detections Scheduled for Removal.

Don't miss a new security_content release

NewReleases is sending notifications on new releases.