🚀 Key Highlights
🔐 Expanded Active Directory and Windows threat coverage 🔐
Added four analytics for KerberLoss SPN manipulation, ResetNightmare-related UPN changes, and Windows Defender artifacts associated with ShieldCrash. These detections help identify suspicious account changes and exploitation activity.
🪟 Consolidated renamed-binary detection 🪟
Added four lookup-backed analytics covering renamed command interpreters, LOLBAS binaries, popular third-party software, and Python binaries. This replaces multiple separate searches with a smaller set of detections.
☁️ Improved support for current security data sources ☁️
Updated Office 365 message trace analytics to support the Microsoft 365 Graph sourcetype while retaining legacy support. Updates also improve CrowdStrike FDR compatibility and refine Azure AD consent and WMI event subscription detections.
🛠️ Detection quality and content improvements 🛠️
Updated 121 analytics and four macros, and added three lookup sets. Changes span Active Directory, cloud, endpoint, Cisco NVM, and Cisco Secure Firewall content, improving data handling, investigation context, and content maintainability.
New Analytics - [8]
- Windows AD Computer SPN Modified By User Account
- Windows AD SPN Unicode Collision Injection
- Windows AD User Suspicious UPN Change
- Windows Defender Intermediary Artifact Was Observed
- Windows Renamed Command Interpreter was Executed
- Windows Renamed LOLBAS Binary was Executed
- Windows Renamed Popular 3rd Party Software was Executed
- Windows Renamed Python Binary was Executed
Updated Analytics - [121]
- 3CX Supply Chain Attack Network Indicators
- Attacker Tools On Endpoint
- Azure AD OAuth Application Consent Granted By User
- Azure AD Privileged Role Assigned to Service Principal
- Azure AD Privileged Role Assigned
- Azure AD User Consent Blocked for Risky Application
- Circle CI Disable Security Job
- Cisco NVM - Browser Spawned Unix Shell with External Connection
- Cisco NVM - Curl Execution With Insecure Flags
- Cisco NVM - Installation of Typosquatted Python Package
- Cisco NVM - MSHTML or MSHTA Network Execution Without URL in CLI
- Cisco NVM - Non-Network Binary Making Network Connection
- Cisco NVM - Osascript Network Connection for a Long Duration
- Cisco NVM - Outbound Connection to Suspicious Port
- Cisco NVM - Rclone Execution With Network Activity
- Cisco NVM - Rundll32 Abuse of MSHTML.DLL for Payload Download
- Cisco NVM - Susp Script From Archive Triggering Network Activity
- Cisco NVM - Suspicious Download From File Sharing Website
- Cisco NVM - Suspicious File Download via Headless Browser
- Cisco NVM - Suspicious Network Connection From Process With No Args
- Cisco NVM - Suspicious Network Connection Initiated via MsXsl
- Cisco NVM - Suspicious Network Connection to IP Lookup Service API
- Cisco NVM - Webserver Download From File Sharing Website
- Cisco Secure Firewall - Binary File Type Download
- Cisco Secure Firewall - Blacklisted SSL Certificate Fingerprint
- Cisco Secure Firewall - File Download Over Uncommon Port
- Cisco Secure Firewall - Intrusion Events by Threat Activity
- Cisco Secure Firewall - Malware File Downloaded
- Cisco Secure Firewall - Remote Access Software Usage Traffic
- Cisco Secure Firewall - Repeated Malware Downloads
- Cloud API Calls From Previously Unseen User Roles
- Cloud Compute Instance Created By Previously Unseen User
- Cloud Compute Instance Created In Previously Unused Region
- Cloud Compute Instance Created With Previously Unseen Image
- Cloud Compute Instance Created With Previously Unseen Instance Type
- Cloud Instance Modified By Previously Unseen User
- Cloud Provisioning Activity From Previously Unseen City
- Cloud Provisioning Activity From Previously Unseen Country
- Cloud Provisioning Activity From Previously Unseen IP Address
- Cloud Provisioning Activity From Previously Unseen Region
- Common Ransomware Extensions
- Detect Remote Access Software Usage DNS
- Detect Remote Access Software Usage FileInfo
- Detect Remote Access Software Usage File
- Detect Remote Access Software Usage Process
- Detect Remote Access Software Usage Registry
- Detect Remote Access Software Usage Traffic
- Detect Remote Access Software Usage URL
- Detect hosts connecting to dynamic domain providers
- First Time Seen Child Process of Zoom
- HTTP C2 Framework User Agent
- HTTP Malware User Agent
- HTTP PUA User Agent
- HTTP RMM User Agent
- HTTP Scripting Tool User Agent
- Kubernetes Nginx Ingress LFI
- LOLBAS Network Connection On Uncommon Port
- MacOS Osascript Executing Interactive Shell
- MacOS Osascript Executing JavaScript Code With ObjC
- O365 BEC Email Hiding Rule Created
- O365 Email Password and Payroll Compromise Behavior
- O365 Email Receive and Hard Delete Takeover Behavior
- O365 Email Send Attachments Excessive Volume
- O365 Email Send and Hard Delete Exfiltration Behavior
- O365 Privileged Role Assigned To Service Principal
- O365 Privileged Role Assigned
- Potential password in username
- Prohibited Network Traffic Allowed
- System Processes Run From Unexpected Locations
- WMI Permanent Event Subscription - Sysmon
- WMI Permanent Event Subscription
- Windows AD AdminSDHolder ACL Modified
- Windows AD DCShadow Privileges ACL Addition
- Windows AD Dangerous Deny ACL Modification
- Windows AD Dangerous Group ACL Modification
- Windows AD Dangerous User ACL Modification
- Windows AD Domain Controller Audit Policy Disabled
- Windows AD Domain Replication ACL Addition
- Windows AD Domain Root ACL Deletion
- Windows AD Domain Root ACL Modification
- Windows AD GPO New CSE Addition
- Windows AD Hidden OU Creation
- Windows AD Object Owner Updated
- Windows AD Privileged Account SID History Addition
- Windows AD Privileged Group Modification
- Windows AD Self DACL Assignment
- Windows AI Platform DNS Query
- Windows Admin Password Changed by Non-Admin
- Windows Alternate Data Stream Created Over Local Share
- Windows AppLocker Block Events
- Windows AppLocker Privilege Escalation via Unauthorized Bypass
- Windows Attempt To Stop Security Service
- Windows Credential Access From Browser Password Store
- Windows Crowdstrike RTR Script Execution
- Windows DLL Search Order Hijacking Hunt with Sysmon
- Windows Defender ASR Audit Events
- Windows Defender ASR Block Events
- Windows Defender ASR Registry Modification
- Windows Defender ASR Rule Disabled
- Windows Defender ASR Rules Stacking
- Windows Domain Admin Impersonation Indicator
- Windows DotNet Binary in Non Standard Path
- Windows Hosts File Access
- Windows Identify Protocol Handlers
- Windows Important Audit Policy Disabled
- Windows Kerberos Local Successful Logon
- Windows Known Abused DLL Created
- Windows Known Abused DLL Loaded Suspiciously
- Windows LOLBAS Executed Outside Expected Path
- Windows NirSoft Utilities
- Windows PUA Named Pipe
- Windows PowerShell Process With Malicious String
- Windows PowerShell Script Block With Malicious String
- Windows RMM Named Pipe
- Windows Scheduled Task with Suspicious Command
- Windows Scheduled Task with Suspicious Name
- Windows Service Created with Suspicious Service Name
- Windows Suspicious C2 Named Pipe
- Windows Suspicious Named Pipe
- Windows Vulnerable Driver Installed
- Windows Vulnerable Driver Loaded
Other Updates
-
A special thanks to @Masoud00013 and @sbaker-gre from the Security Content community for their contributions to this release, helping improve the quality and reliability of ESCU content.
-
This release also updates four macros: base64decode, o365_messagetrace, remote_access_software_usage_exceptions, and suspicious_writes, and adds three lookup sets for renamed LOLBAS binaries, popular third-party software, and Windows command interpreters.
Breaking Changes
Content Removed in Release v6.8.0
| Content | Content Type | Reason | Replacement Content |
|---|---|---|---|
| Detect F5 TMUI RCE CVE-2020-5902 | Detection | Detection deprecated as it is targeting a 6 years old CVE that is no longer relevant, since the OS version targeted is no longer supported by F5. As well, the fact that the detection has been set to experimental since 2020. | None |
| LOLBAS With Network Traffic | Detection | Detection deprecated due to high false positive rates from certain LOLBAS binaries with common legitimate network behavior. This broad analytic is being split into more manageable anomaly analytics with separate process groups and common-port tuning. | LOLBAS Network Connection On Uncommon Port, LOLBAS Rare Network Connection |
| Linux Adding Crontab Using List Parameter | Detection | Detection deprecated as its name and description are not matching the behavior of the search. The search is looking for crontab command with list parameter, not adding a new cron job. | Linux Crontab Enumeration |
List of detections scheduled for removal in ESCU version 6.10.0
Following is a list of detections scheduled for removal in ESCU version 6.10.0:
| Content | Content Type | Removed in Version | Reason | Replacement Content |
|---|---|---|---|---|
| Child Processes of Spoolsv exe | Detection | 6.10.0 | Deprecated because the broad parent-child logic generated substantial legitimate printer, driver, and print-management activity and did not directly detect the exploitation behavior associated with its CVE reference. More specific Print Spooler behaviors are covered by existing production detections. | None |
| Detect HTML Help Renamed | Detection | 6.10.0 | Detection deprecated due to having a duplicated content with another detection. Renaming of all LOLBAS binaries are covered in a single detection instead of having their separate searches, for performance related reasons. | Windows Renamed LOLBAS Binary was Executed |
| Detect Renamed 7-Zip | Detection | 6.10.0 | Detection deprecated due to having a duplicated content with another detection. Renaming of all popular 3rd party software binaries are covered in a single detection instead of having their separate searches, for performance related reasons. | Windows Renamed Popular 3rd Party Software was Executed |
| Detect Renamed PSExec | Detection | 6.10.0 | Detection deprecated due to having a duplicated content with another detection. Renaming of all command interpreter binaries are covered in a single detection instead of having their separate searches, for performance related reasons. | Windows Renamed Command Interpreter was Executed |
| Detect Renamed RClone | Detection | 6.10.0 | Detection deprecated due to having a duplicated content with another detection. Renaming of all popular 3rd party software binaries are covered in a single detection instead of having their separate searches, for performance related reasons. | Windows Renamed Popular 3rd Party Software was Executed |
| Detect Renamed WinRAR | Detection | 6.10.0 | Detection deprecated due to having a duplicated content with another detection. Renaming of all popular 3rd party software binaries are covered in a single detection instead of having their separate searches, for performance related reasons. | Windows Renamed Popular 3rd Party Software was Executed |
| Detect WMI Event Subscription Persistence | Detection | 6.10.0 | This rule uses only Sysmon EventID 20, which records creation of a WMI event consumer but does not confirm that a filter is bound to it. The Sysmon permanent subscription detection covers the binding with EventID 21. | WMI Permanent Event Subscription - Sysmon |
| Detect mshta renamed | Detection | 6.10.0 | Detection deprecated due to having a duplicated content with another detection. Renaming of all LOLBAS binaries are covered in a single detection instead of having their separate searches, for performance related reasons. | Windows Renamed LOLBAS Binary was Executed |
| MacOS - Re-opened Applications | Detection | 6.10.0 | Detection deprecated as it is targeting a method of persistence that has been disabled in MacOS for years. As well, as the fact that the detection has been set to experimental since 2020. | None |
| Suspicious MSBuild Rename | Detection | 6.10.0 | Detection deprecated due to having a duplicated content with another detection. Renaming of all LOLBAS binaries are covered in a single detection instead of having their separate searches, for performance related reasons. | Windows Renamed LOLBAS Binary was Executed |
| Suspicious microsoft workflow compiler rename | Detection | 6.10.0 | Detection deprecated due to having a duplicated content with another detection. Renaming of all LOLBAS binaries are covered in a single detection instead of having their separate searches, for performance related reasons. | Windows Renamed LOLBAS Binary was Executed |
| WMI Temporary Event Subscription | Detection | 6.10.0 | This rule is deprecated in its current form because EventID 5860 identifies temporary subscriptions rather than permanent persistence, and the broad match with exact query-string exceptions does not reliably distinguish malicious use from legitimate software. Temporary WMI activity may warrant a separate behavior-focused detection. | None |
| Windows LOLBAS Executed As Renamed File | Detection | 6.10.0 | Detection deprecated due to renaming of its newer version. | Windows Renamed LOLBAS Binary was Executed |
| Windows Process Injection into Notepad | Detection | 6.10.0 | Detection deprecated as it is already covered by the" Windows Process Injection into Commonly Abused Processes" detection. | Windows Process Injection into Commonly Abused Processes |
| Windows Regsvr32 Renamed Binary | Detection | 6.10.0 | Detection deprecated due to having a duplicated content with another detection. Renaming of all LOLBAS binaries are covered in a single detection instead of having their separate searches, for performance related reasons. | Windows Renamed LOLBAS Binary was Executed |
| Windows Renamed Powershell Execution | Detection | 6.10.0 | Detection deprecated due to having a duplicated content with another detection. Renaming of all command interpreter binaries are covered in a single detection instead of having their separate searches, for performance related reasons. | Windows Renamed Command Interpreter was Executed |
| XMRIG Driver Loaded | Detection | 6.10.0 | Detection deprecated as it is inaccurate. WinRing0x64.sys is not related to XMRIG. It is a driver that is used to access the hardware ring0. | Windows Vulnerable Driver Installed, Windows Vulnerable Driver Loaded |