github splunk/security_content v6.5.0

4 hours ago

🚀 Key Highlights

🐍 Malicious Python Package Installation

Introduced a new analytic story with four detections focused on abuse of the Python package installation lifecycle. New coverage identifies unexpected network connections during package builds, creation of executable .pth configuration files and Python site hooks, and manipulation of the PYTHONPATH environment variable. These analytics help defenders uncover supply-chain compromises that execute code during installation or establish persistence across subsequent Python sessions, improving visibility into threats targeting developer workstations and build environments.

🕵️ Vidar Stealer Detection Coverage

Introduced a new analytic story for the Vidar information stealer, combining a new detection for uncommon processes reading sensitive cloud profile files with existing analytics covering unauthorized browser credential-store access and suspicious process behavior. This coverage helps identify attempts to collect saved credentials, cookies, Azure CLI profile metadata, and other information that could support account takeover, cloud reconnaissance, or data exfiltration, giving defenders an earlier opportunity to contain compromised Windows endpoints.

🪐 RoguePlanet and ShieldBreak Privilege Escalation

Expanded the RoguePlanet analytic story with six new detections targeting Windows Defender race-condition exploitation and related ShieldBreak techniques. The new analytics identify alternate data streams created through local shares, suspicious use of Defender components, threat events referencing kernel object paths, manually staged Windows Error Reports, phantom DLL creation, and Windows Error Reporting processes spawning SYSTEM-integrity children. This provides stronger visibility into Defender scanning abuse, DLL hijacking, and attempts to escalate from a low-privileged context to SYSTEM.

🛡️ EDR Defense Evasion Detection

Added two behavioral analytics for EDRSilencer-style tampering through the Windows Filtering Platform. The detections identify custom outbound filters and filtering rules designed to block security processes from communicating with their management infrastructure, helping defenders recognize attempts to suppress endpoint telemetry or disrupt response capabilities before attackers continue post-compromise activity.

🎯 Cross-Platform Detection Refinements

Updated 46 analytics across Windows, Linux, macOS, ESXi, and AWS Bedrock to improve detection fidelity and behavioral coverage. The refinements strengthen visibility into AI infrastructure abuse, credential access, browser data theft, process injection, persistence, privilege escalation, reconnaissance, security-tool tampering, and destructive activity, helping security teams investigate suspicious behavior across a broader range of endpoint, virtualization, and cloud telemetry.

🗓️ Legacy F5 Detection Retirement

Scheduled the experimental detection for F5 TMUI remote code execution (CVE-2020-5902) for removal in a future release. The analytic targets an older platform version that is no longer supported by F5 and has remained experimental since 2020, allowing the content library to prioritize relevant, supportable detection coverage.

New Analytic Story - [2]

Updated Analytic Story - [1]

New Analytics - [13]

Updated Analytics - [46]

Content Scheduled for Removal in Future Releases

Content Content Type Removed in Version Reason Replacement Content
Detect F5 TMUI RCE CVE-2020-5902 Detection 6.8.0 Detection deprecated as it is targeting a 6 years old CVE that is no longer relevant, since the OS version targeted is no longer supported by F5. As well, the fact that the detection has been set to experimental since 2020. None

Don't miss a new security_content release

NewReleases is sending notifications on new releases.