github splunk/security_content v6.0.0

6 hours ago

๐Ÿš€ Key Highlights

ESCU 6.0.0 is a major release that includes a number of changes for better alignment with Enterprise Security v8.x+ features.

Please note that all content has been updated in this release, resulting in cleaner, more readable .conf files.

๐Ÿ”Expanded Finding and Intermediate Finding Support ๐Ÿ”Ž

Detections that previously created Notable Events, and then Findings with a 0 score โ€œN/Aโ€ entity will now create a Finding with an appropriately tagged entity from the search results, with the score that previously would have been used for a risk event/Intermediate Finding for that entity.

Because of the shift to tagging entities to Findings, fewer total Intermediate Findings may be created for some detections, as we wonโ€™t be separately creating Intermediate Findings for every entity.

๐Ÿ—“๏ธ Increased Clarity on Content Creation Date vs Modification Date ๐Ÿ—“๏ธ

Detections, Analytic Stories, and other things, depending on where you view them now have both creation and modification dates indicating when we first created them and when weโ€™ve last modified them.

๐Ÿ› ๏ธ Repository Tooling Updates ๐Ÿ› ๏ธ

ESCU v6.0 marks the transition away from contentctl. We are shifting future investment from contentctl to Detection Studio as we work to bring this functionality into Splunk as an officially supported capability. The contentctl repository will remain publicly available for reference, forking, and customization, but continued use may require customer-managed customization. For more information, see https://github.com/splunk/contentctl/blob/main/README.md

Future Breaking Changes

As previously communicated in ESCU v5.27.0, a number of detections will be removed in v6.1.0. For details on detections scheduled for removal in ESCU version v6.1.0, see the List of Detections Scheduled for Removal.

List of detections scheduled for removal in ESCU version 6.1.0

Deprecated Detection Replacement Detection
CHCP Command Execution Not Available
Sc exe Manipulating Windows Services Not Available
Processes launching netsh Not Available
Ivanti Sentry Authentication Bypass Not Available
Attempt To Add Certificate To Untrusted Store Not Available

List of detections deprecated in ESCU version 6.0.0

Deprecated Detection Replacement Detection

Don't miss a new security_content release

NewReleases is sending notifications on new releases.