github splunk/security_content v5.4.0

latest releases: v5.19.0, v5.18.0, v5.17.0...
7 months ago

✨ Highlights

  • 🔥 Cisco Secure Firewall Threat Defense Analytics: We published a new analytic story and added new detections for Cisco Secure Firewall focusing on three primary event types—file events, network connections, and intrusion alerts. These detections identify activity such as malicious or uncommon file downloads, connections over suspicious ports or to file-sharing domains, and Snort rule-based intrusion events across multiple hosts. This enables broader visibility into network-based threats and host-level indicators of compromise.

  • 🤖 AWS Bedrock Security: Released a new analytic story to monitor for adversary techniques targeting AWS Bedrock, a managed service used to build and scale generative AI applications. This includes detections for the deletion of security guardrails, knowledge bases, and logging configurations, as well as high volumes of model invocation failures.

  • 🕵️ Mapping Threat Campaigns: Several detections have been mapped to known threat actors and malware campaigns, including Cactus Ransomware, Earth Alux, Storm-2460 CLFS Zero Day Exploitation and Water Gamayun, to improve attribution to TTPs and provide insights into observed behaviors.

  • 🆕 New Detections: Introduced additional detections for tactics such as directory path manipulation via MSC files, IP address collection using PowerShell Invoke-RestMethod, process spawning from CrushFTP, and deletion of Volume Shadow Copies via WMIC. These detections target adversary behavior related to discovery, lateral movement, and anti-forensics.


📚 New Analytic Stories – [6]


🧠 New Analytics – [27]


🛠 Other Updates

  • 🔄 Reverted several searches to use | join instead of prestats = t due to bugs encountered in the search logic.
  • ❌ Removed Detections – As notified in the ESCU v5.2.0 release, we have removed these detections. Please use replacements where appropriate.
  • 🗓️ Deprecated more detections now scheduled for removal in ESCU v5.6.0.
  • 📥 Updated deprecation_info lookup to reflect the latest list of deprecated and removed detections.

Don't miss a new security_content release

NewReleases is sending notifications on new releases.