github splunk/security_content v5.24.0

17 hours ago

🚀 Key Highlights

  • Cisco SD-WAN Analytics: Expanded coverage for Cisco SD-WAN environments with new analytics targeting exploitation and anomalous traffic patterns, including detections for Cisco SD-WAN Arbitrary File Overwrite Exploitation Activity and Cisco SD-WAN Uncommon User-Agent Multi-URI Activity, improving visibility into potential exploitation attempts and suspicious HTTP behaviors indicative of adversary interaction with SD-WAN infrastructure.
  • BlankGrabber Stealer and Muddy Water Analytics: Expanded detection coverage for BlankGrabber, a Windows-based information stealer used to harvest browser credentials, cryptocurrency wallets, and authentication tokens, by tagging existing analytics and introducing new detections focused on browser data access, suspicious registry queries, WMI reconnaissance, and defense evasion behaviors such as PowerShell exclusion tampering. This update enhances visibility into credential harvesting, data staging, and stealthy exfiltration activity commonly associated with phishing-delivered stealers and cracked software infections, helping defenders detect and respond to early-stage compromise before widespread account takeover or financial theft occurs.
  • Lotus Blossom (Chrysalis Backdoor) Supply Chain Attack: Added new detection coverage for the Lotus Blossom (Billbug) APT group's Chrysalis backdoor campaign, which leveraged a Notepad++ supply chain compromise (June–December 2025) to target government, financial, and IT sectors. This release introduces detections for Bitdefender DLL sideloading abuse, BluetoothService-based persistence, and TinyCC shellcode execution, along with tagging existing analytics for system and user discovery behaviors observed across multiple infection chains. These updates improve visibility into stealthy execution, persistence mechanisms, and post-compromise reconnaissance associated with sophisticated supply chain intrusions and staged payload delivery.
  • Standardized Risk Scoring Across Detections: Implemented consistent risk scoring across all analytics by assigning a score of 50 for TTP detections and 20 for anomaly-based detections, improving prioritization, correlation, and alert triage across detection workflows.

New Analytic Story - [4]

Updated Analytic Story - [1]

New Analytics - [14]

Updated Analytics - [1655]

... truncated

Macros Added - [1]

  • cisco_sd_wan_service_proxy_access

Lookups Added - [1]

  • browser_process_and_path

Deprecated/removed detections tables

List of removed detections in ESCU version 5.24.0

Removed Detection Replacement Detection
Linux apt-get Privilege Escalation Linux APT Privilege Escalation

List of detections scheduled for removal in ESCU version 5.26.0

Deprecated Detection Replacement Detection
Abnormally High Number Of Cloud Infrastructure API Calls
Abnormally High Number Of Cloud Instances Destroyed
Abnormally High Number Of Cloud Instances Launched
Abnormally High Number Of Cloud Security Group API Calls
Detect DNS Data Exfiltration using pretrained model in DSDL
DNS Query Length Outliers - MLTK
SMB Traffic Spike - MLTK
Unusually Long Command Line - MLTK
Detect DGA domains using pretrained model in DSDL
Detect suspicious DNS TXT records using pretrained model in DSDL
Detect suspicious processnames using pretrained model in DSDL
Potentially malicious code on commandline
Linux Docker Privilege Escalation Linux Docker Root Directory Mount
Linux Docker Shell Execution
Windows Excel ActiveMicrosoftApp Child Process Windows Excel Spawning Microsoft Project Application

Don't miss a new security_content release

NewReleases is sending notifications on new releases.