github splunk/security_content v6.7.0

3 hours ago

🚀 Key Highlights

🍎 Expanded macOS AppleScript and osascript coverage 🍎

Added three new macOS analytics that identify osascript executing interactive shells, JavaScript for Automation code using the Objective-C bridge, and long-lived network connections. This improves visibility into script-based execution, remote access, command-and-control activity, and post-exploitation behavior on macOS endpoints.

🪟 Windows ClickFix and LOLBin detection coverage 🪟

Added four new Windows analytics covering remote connections through finger.exe, command execution through for /f loops, JavaScript execution by node.exe from unusual directories, and processes accessing the IronLanguages repository on GitHub. Together, these detections improve visibility into ClickFix-related execution chains, payload retrieval, scripting abuse, and the use of trusted utilities for malicious activity.

🔐 Improved credential-access and process-injection detection 🔐

Updated multiple detections leveraging the process access data source, covering LSASS access and termination, credential dumping, Winlogon token manipulation, Rubeus ticket export activity, handle duplication, and process injection. These changes improve analytic consistency, investigation context, and visibility into credential-access and defense-evasion techniques.

🛠️ Detection quality and metadata improvements 🛠️

Updated multiple analytics across application, endpoint, network, and web content. Changes include improved SPL logic, additional threat objects and references, better event context, and tuning intended to improve detection fidelity and reduce noise. Updates include coverage for ESXi tampering and VM termination, event-log clearing, Kerberos coercion, internal network scanning, and suspicious HTTP activity.

New Analytics - [7]

Updated Analytics - [30]

Other Updates

A special thanks to @0x4D6174696E from the Security Content community for reporting a bug in on piece of content that improved the quality and reliability of the security content.

Breaking Changes

List of detections scheduled for removal in ESCU version 6.10.0

Following is a list of detections scheduled for removal in ESCU version 6.10.0:

Content Content Type Removed in Version Reason Replacement Content
MacOS - Re-opened Applications Detection 6.10.0 Detection deprecated as it is targeting a method of persistence that has been disabled in MacOS for years. As well, as the fact that the detection has been set to experimental since 2020. None
Windows Process Injection into Notepad Detection 6.10.0 Detection deprecated as it is already covered by the" Windows Process Injection into Commonly Abused Processes" detection. Windows Process Injection into Commonly Abused Processes
XMRIG Driver Loaded Detection 6.10.0 Detection deprecated as it is inaccurate. WinRing0x64.sys is not related to XMRIG. It is a driver that is used to access the hardware ring0. Windows Vulnerable Driver Installed, Windows Vulnerable Driver Loaded

Don't miss a new security_content release

NewReleases is sending notifications on new releases.