github splunk/security_content v5.9.0

latest releases: v5.13.0, v5.12.0, v5.11.0...
one month ago

Key Highlights

  • 🔍 Cisco Network Visibility Module Analytics: Introduced a new analytic story leveraging Cisco NVM telemetry to detect suspicious endpoint network behavior. This release includes 14 analytics covering threats such as insecure curl usage, typosquatted Python packages, abuse of native Windows tools like rundll32 and mshta, and anomalous network connections from uncommon or argument-less processes.

  • 💣 Disk Wiper: Released a new analytic story focused on identifying destructive malware that irreversibly erases disk data, with tagged detections targeting recursive file deletion and raw access to disk volumes and the primary boot record.

  • ⚙️ CrowdStrike EDR Playbook Pack for Splunk SOAR: Shipped a new playbook pack that enables automated investigation, enrichment, and response using CrowdStrike Falcon, helping security teams streamline endpoint operations with playbooks for actions like device isolation, process termination, file handling, and denylisting executables.

New Analytic Story - [2]

New Analytics - [19]

Updated Analytics - [2]

Macros Added - [1]

  • cisco_network_visibility_module_flowdata

Macros Updated - [0]

Lookups Added - [2]

  • suspicious_ports_list
  • typo_squatted_python_packages

Lookups Updated - [1]

  • attacker_tools

Other Updates

Playbooks Added - [9]

(Internal Contributor : @ccl0utier )

Don't miss a new security_content release

NewReleases is sending notifications on new releases.