๐ Key Highlights
ESCU 6.0.0 is a major release that includes a number of changes for better alignment with Enterprise Security v8.x+ features.
Please note that all content has been updated in this release, resulting in cleaner, more readable .conf files.
๐Expanded Finding and Intermediate Finding Support ๐
Detections that previously created Notable Events, and then Findings with a 0 score โN/Aโ entity will now create a Finding with an appropriately tagged entity from the search results, with the score that previously would have been used for a risk event/Intermediate Finding for that entity.
Because of the shift to tagging entities to Findings, fewer total Intermediate Findings may be created for some detections, as we wonโt be separately creating Intermediate Findings for every entity.
๐๏ธ Increased Clarity on Content Creation Date vs Modification Date ๐๏ธ
Detections, Analytic Stories, and other things, depending on where you view them now have both creation and modification dates indicating when we first created them and when weโve last modified them.
๐ ๏ธ Repository Tooling Updates ๐ ๏ธ
ESCU v6.0 marks the transition away from contentctl. We are shifting future investment from contentctl to Detection Studio as we work to bring this functionality into Splunk as an officially supported capability. The contentctl repository will remain publicly available for reference, forking, and customization, but continued use may require customer-managed customization. For more information, see https://github.com/splunk/contentctl/blob/main/README.md
Future Breaking Changes
As previously communicated in ESCU v5.27.0, a number of detections will be removed in v6.1.0. For details on detections scheduled for removal in ESCU version v6.1.0, see the List of Detections Scheduled for Removal.
List of detections scheduled for removal in ESCU version 6.1.0
| Deprecated Detection | Replacement Detection |
|---|---|
| CHCP Command Execution | Not Available |
| Sc exe Manipulating Windows Services | Not Available |
| Processes launching netsh | Not Available |
| Ivanti Sentry Authentication Bypass | Not Available |
| Attempt To Add Certificate To Untrusted Store | Not Available |
List of detections deprecated in ESCU version 6.0.0
| Deprecated Detection | Replacement Detection |
|---|