github splunk/security_content v6.4.0

4 hours ago

🚀 Key Highlights

🐧 Linux Detection Coverage Expansion:

Added broad new Linux behavioral coverage targeting privilege escalation, persistence, execution, defense evasion, reverse shells, container abuse, and suspicious service activity. New analytics identify behaviors including bootloader and system file modification, shared-memory execution, UDEV and XDG persistence, privileged container execution, PostgreSQL and Redis abuse, Ghostscript exploitation, shell history access, and multiple potential privilege-escalation paths, giving defenders stronger visibility into suspicious activity that can blend with legitimate Linux administration.

🪟 Windows Detection Coverage:

Expanded Windows detection coverage with new analytics for network reconnaissance, suspicious PowerShell execution, and abnormal process behavior. New detections identify network sniffing tools, PowerShell commands retrieved through DNS TXT records, directory output piped to Findstr, and suspicious child processes of Consent.exe, helping security teams surface discovery, command execution, defense evasion, and other potentially malicious endpoint activity.

🛠️ Detection Updates & Fixes:

Refined six existing analytics covering administrative SMB shares, high-frequency file copying, network-share discovery, user discovery, and registry-based defense evasion, improving existing detection coverage and fidelity. This release also updates the attacker_tools and malware_user_agents lookups, providing refreshed context to support threat detection and investigation workflows.

New Analytics - [27]

Updated Analytics - [6]

Other Updates

  • Both the attacker_tools and malware_user_agents lookups have been updated with refreshed content to improve detection and investigation context.
  • A special thanks to @munzzyy, @tid3na, and @thegreatmhn from the Security Content community for reporting bugs and proposing fixes that improved the quality and reliability of the security content.

Breaking Changes

  • As communicated in ESCU v6.3.0, the Onboarding Assistant beta has now concluded and is no longer available in ESCU as we prepare to bring this capability into Detection Studio for a more fully integrated experience.
  • As previously communicated in ESCU v6.2.0, ESCU v6.4.0 removes several detections. See the list of removed detections below for affected detections and recommended replacements. If you are currently using any deprecated detections, review the deprecated analytics in ESCU documentation for guidance on identifying, reviewing, and preserving deprecated detections before upgrading.

Content Removed in Release v6.4.0

Content Content Type Reason Replacement Content
PowerShell - Connect To Internet With Hidden Window Detection Detection has been deprecated due to incorrect logic and bad performance. None
Regsvr32 with Known Silent Switch Cmdline Detection Detection has been deprecated since its logic is already covered by another more improved detection. Regsvr32 Silent and Install Param Dll Loading
Rundll32 CreateRemoteThread In Browser Detection Detection has been deprecated. The search is being replaced with a more generic detection that captures the behavior instead of relying on specific source processes. Windows Uncommon Remote Thread Creation In Browser Process
Splunk App for Lookup File Editing RCE via User XSLT Detection Detection has been deprecated because it's too generic and does not provide the ability to detect the payload executed via this exploit. None
Splunk Code Injection via custom dashboard leading to RCE Detection Detection has been deprecated. The affected Splunk software versions (8.1.12, 8.2.9, and 9.0.2) are no longer supported, having reached End of Life (EOL) between 2023 and 2024. Also, the logic is not perfectly capturing the malicious activity. None
Splunk Enterprise KV Store Incorrect Authorization Detection Detection has been deprecated. The affected Splunk software versions (below 9.0.8 and 9.1.3)are no longer supported, having reached End of Life (EOL), and the logic is not accurately detecting the malicious activity. None
Splunk Information Disclosure on Account Login Detection Detection has been deprecated. The logic is not accurately detecting the malicious activity. None
Splunk Path Traversal In Splunk App For Lookup File Edit Detection Detection has been deprecated. The logic is not accurately detecting the malicious activity. None
Splunk RCE PDFgen Render Detection Detection has been deprecated. The metadata along with the search are not accurately capturing the malicious activity. None
Windows Process Injection Of Wermgr to Known Browser Detection Detection has been deprecated. The search is being replaced with a more generic detection that captures the behavior instead of relying on specific source processes. Windows Uncommon Remote Thread Creation In Browser Process
Windows Process Injection With Public Source Path Detection Detection has been deprecated. The search is not helpful for the user to implement nor use, as it will generate too many false positives. None

Don't miss a new security_content release

NewReleases is sending notifications on new releases.