github splunk/security_content v6.8.0

4 hours ago

🚀 Key Highlights

🔐 Expanded Active Directory and Windows threat coverage 🔐

Added four analytics for KerberLoss SPN manipulation, ResetNightmare-related UPN changes, and Windows Defender artifacts associated with ShieldCrash. These detections help identify suspicious account changes and exploitation activity.

🪟 Consolidated renamed-binary detection 🪟

Added four lookup-backed analytics covering renamed command interpreters, LOLBAS binaries, popular third-party software, and Python binaries. This replaces multiple separate searches with a smaller set of detections.

☁️ Improved support for current security data sources ☁️

Updated Office 365 message trace analytics to support the Microsoft 365 Graph sourcetype while retaining legacy support. Updates also improve CrowdStrike FDR compatibility and refine Azure AD consent and WMI event subscription detections.

🛠️ Detection quality and content improvements 🛠️

Updated 121 analytics and four macros, and added three lookup sets. Changes span Active Directory, cloud, endpoint, Cisco NVM, and Cisco Secure Firewall content, improving data handling, investigation context, and content maintainability.

New Analytics - [8]

Updated Analytics - [121]

Other Updates

Breaking Changes

Content Removed in Release v6.8.0

Content Content Type Reason Replacement Content
Detect F5 TMUI RCE CVE-2020-5902 Detection Detection deprecated as it is targeting a 6 years old CVE that is no longer relevant, since the OS version targeted is no longer supported by F5. As well, the fact that the detection has been set to experimental since 2020. None
LOLBAS With Network Traffic Detection Detection deprecated due to high false positive rates from certain LOLBAS binaries with common legitimate network behavior. This broad analytic is being split into more manageable anomaly analytics with separate process groups and common-port tuning. LOLBAS Network Connection On Uncommon Port, LOLBAS Rare Network Connection
Linux Adding Crontab Using List Parameter Detection Detection deprecated as its name and description are not matching the behavior of the search. The search is looking for crontab command with list parameter, not adding a new cron job. Linux Crontab Enumeration

List of detections scheduled for removal in ESCU version 6.10.0

Following is a list of detections scheduled for removal in ESCU version 6.10.0:

Content Content Type Removed in Version Reason Replacement Content
Child Processes of Spoolsv exe Detection 6.10.0 Deprecated because the broad parent-child logic generated substantial legitimate printer, driver, and print-management activity and did not directly detect the exploitation behavior associated with its CVE reference.
More specific Print Spooler behaviors are covered by existing production detections.
None
Detect HTML Help Renamed Detection 6.10.0 Detection deprecated due to having a duplicated content with another detection. Renaming of all LOLBAS binaries are covered in a single detection instead of having their separate searches, for performance related reasons. Windows Renamed LOLBAS Binary was Executed
Detect Renamed 7-Zip Detection 6.10.0 Detection deprecated due to having a duplicated content with another detection. Renaming of all popular 3rd party software binaries are covered in a single detection instead of having their separate searches, for performance related reasons. Windows Renamed Popular 3rd Party Software was Executed
Detect Renamed PSExec Detection 6.10.0 Detection deprecated due to having a duplicated content with another detection. Renaming of all command interpreter binaries are covered in a single detection instead of having their separate searches, for performance related reasons. Windows Renamed Command Interpreter was Executed
Detect Renamed RClone Detection 6.10.0 Detection deprecated due to having a duplicated content with another detection. Renaming of all popular 3rd party software binaries are covered in a single detection instead of having their separate searches, for performance related reasons. Windows Renamed Popular 3rd Party Software was Executed
Detect Renamed WinRAR Detection 6.10.0 Detection deprecated due to having a duplicated content with another detection. Renaming of all popular 3rd party software binaries are covered in a single detection instead of having their separate searches, for performance related reasons. Windows Renamed Popular 3rd Party Software was Executed
Detect WMI Event Subscription Persistence Detection 6.10.0 This rule uses only Sysmon EventID 20, which records creation of a WMI event consumer but does not confirm that a filter is bound to it. The Sysmon permanent subscription detection covers the binding with EventID 21. WMI Permanent Event Subscription - Sysmon
Detect mshta renamed Detection 6.10.0 Detection deprecated due to having a duplicated content with another detection. Renaming of all LOLBAS binaries are covered in a single detection instead of having their separate searches, for performance related reasons. Windows Renamed LOLBAS Binary was Executed
MacOS - Re-opened Applications Detection 6.10.0 Detection deprecated as it is targeting a method of persistence that has been disabled in MacOS for years. As well, as the fact that the detection has been set to experimental since 2020. None
Suspicious MSBuild Rename Detection 6.10.0 Detection deprecated due to having a duplicated content with another detection. Renaming of all LOLBAS binaries are covered in a single detection instead of having their separate searches, for performance related reasons. Windows Renamed LOLBAS Binary was Executed
Suspicious microsoft workflow compiler rename Detection 6.10.0 Detection deprecated due to having a duplicated content with another detection. Renaming of all LOLBAS binaries are covered in a single detection instead of having their separate searches, for performance related reasons. Windows Renamed LOLBAS Binary was Executed
WMI Temporary Event Subscription Detection 6.10.0 This rule is deprecated in its current form because EventID 5860 identifies temporary subscriptions rather than permanent persistence, and the broad match with exact query-string exceptions does not reliably distinguish malicious use from legitimate software.
Temporary WMI activity may warrant a separate behavior-focused detection.
None
Windows LOLBAS Executed As Renamed File Detection 6.10.0 Detection deprecated due to renaming of its newer version. Windows Renamed LOLBAS Binary was Executed
Windows Process Injection into Notepad Detection 6.10.0 Detection deprecated as it is already covered by the" Windows Process Injection into Commonly Abused Processes" detection. Windows Process Injection into Commonly Abused Processes
Windows Regsvr32 Renamed Binary Detection 6.10.0 Detection deprecated due to having a duplicated content with another detection. Renaming of all LOLBAS binaries are covered in a single detection instead of having their separate searches, for performance related reasons. Windows Renamed LOLBAS Binary was Executed
Windows Renamed Powershell Execution Detection 6.10.0 Detection deprecated due to having a duplicated content with another detection. Renaming of all command interpreter binaries are covered in a single detection instead of having their separate searches, for performance related reasons. Windows Renamed Command Interpreter was Executed
XMRIG Driver Loaded Detection 6.10.0 Detection deprecated as it is inaccurate. WinRing0x64.sys is not related to XMRIG. It is a driver that is used to access the hardware ring0. Windows Vulnerable Driver Installed, Windows Vulnerable Driver Loaded

Don't miss a new security_content release

NewReleases is sending notifications on new releases.