Skip to content

Splunk Security Content

v6.1.0 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

βœ“ No known CVEs patched
Read the diff β†’ Tool health β†’ What is this tool? β†’
This release patches 1 known CVE

Topics

ci-cd security detection detection-engineering engineering responses
+1 more
splunk

Affected surfaces

auth rbac

Summary

AI summary

Broad release touches New Analytics - [34, πŸš€ Key Highlights, CVE-2026-31431, and PLM.

Full changelog

πŸš€ Key Highlights

πŸ”’ Cisco Secure Access Threat Detection πŸ”’

Introduced new analytics for Cisco Secure Access to identify access to anonymizer and privacy-focused services as well as automated web reconnaissance activity. New detections β€” Cisco Secure Access Access to Anonymizer Services and Cisco Secure Access Automated Web Reconnaissance via HTTP Access Errors β€” help uncover attempts to obscure attacker infrastructure, evade attribution, and perform large-scale web application discovery through patterns of abnormal HTTP error responses and suspicious outbound connectivity.

🟦 πŸ”¨ SUNBlueHammer & RedSun πŸ”¨ 🟦

Added new analytic stories and detections covering the BlueHammer and RedSun exploit families, which abuse Microsoft Defender functionality to achieve privilege escalation and credential access. New analytics detect suspicious Defender engine and signature update activity, non-administrative password changes, abnormal password reset bursts, unauthorized Defender file modifications, and processes interacting with Defender update components, while also introducing support for Windows Security Event ID 4723 (password change attempts) to improve visibility into credential theft and privilege escalation tradecraft associated with these emerging attack techniques.

πŸ”΄ Linux Copy Fail Analytics πŸ”΄

Expanded Linux detection coverage for Copy Fail (CVE-2026-31431) and related post-exploitation activity with new analytics targeting malformed authentication entries, PF_ALG registration outside normal boot windows, suspicious namespace creation, and process execution with null argv valuesβ€”behaviors associated with privilege escalation, stealthy execution, and kernel abuse. This release also introduces support for Linux kern.log telemetry through a new data source, providing deeper visibility into low-level system activity and emerging Linux exploitation techniques.

###πŸ§‚ Salt Typhoon Tradecraft on Cisco IOS XEπŸ§‚
Added a new set of analytics focused on Salt Typhoon-style activity targeting Cisco IOS XE devices, providing coverage for reconnaissance, persistence, defense evasion, and unauthorized remote access techniques observed in network infrastructure compromises. New detections identify behaviors such as Guestshell activation and destruction, log clearing sequences, VTY access control tampering, tunnel interface creation, WebUI abuse, remote access probing, and suspicious platform package shell interactions, helping defenders detect adversaries attempting to establish persistence, evade logging, and manipulate Cisco networking infrastructure.

πŸ›œ Cisco SD-WAN Authentication Analytics πŸ›œ

Added new analytics to identify suspicious authentication patterns in Cisco SD-WAN environments, including multiple source IPs authenticating to vManage via SSH and repeated SSH key-based authentications from a single source, helping detect potential credential sharing, unauthorized administrative access, and distributed brute-force or persistence activity targeting SD-WAN management infrastructure.

πŸ’¨ TC Windchill Exploitation Detection Coverage 🌬️

Added a new analytic story for PTC Windchill Exploitation along with detections for gateway command execution and GW READY/OK probing activity, providing visibility into exploitation attempts targeting Windchill environments. This release also introduces a new Windchill Log4j data source and supporting macro to help defenders identify reconnaissance, command execution, and post-exploitation behaviors against enterprise product lifecycle management (PLM) infrastructure.

New Analytic Story - [5]

New Analytics - [34]

Other Updates

Fixed several regex related bugs that were reported as Github Issues (External Contributor: @srkyn)

Breaking Changes

As previously communicated in the ESCU v5.26.0 release, several detections have been removed. For a complete list of the detections removed in version v6.1.0, refer to the List of Removed Detections. Users are expected to transition to the recommended replacements where applicable. Additionally, a new set of detections has been deprecated. For details on detections scheduled for removal in ESCU version v6.4.0, see the List of Detections Scheduled for Removal or see the notes below.

Detections Removed in Release v6.1.0

| Detection | Reason | Replacement Content |
| --- | --- | --- |
| Attempt To Add Certificate To Untrusted Store | Detection is deprecated as the usage of certutil and addstore by itself is not malicious. | None |
| CHCP Command Execution | Detection is deprecated as the usage of chcp.com by itself is not malicious. | None |
| Ivanti Sentry Authentication Bypass | Detection is deprecated since it is not specific enough to identify the intended malicious activity and might produce false positives. | None |
| Processes launching netsh | Detection is deprecated as the usage of netsh.exe by itself is often used for legitimate purposes. | None |
| Sc exe Manipulating Windows Services | Detection is deprecated as the usage of sc.exe by itself is often used for legitimate purposes. | None |

Detections Scheduled for Future Removal in Future Releases

| Detection | Removed in Version | Reason | Replacement Content |
| --- | --- | --- | --- |
| PowerShell - Connect To Internet With Hidden Window | 6.4.0 | Detection has been deprecated due to incorrect logic and bad performance. | None |
| Regsvr32 with Known Silent Switch Cmdline | 6.4.0 | Detection has been deprecated since its logic is already covered by another more improved detection. | Regsvr32 Silent and Install Param Dll Loading |

Breaking Changes

  • Removed detections: Attempt To Add Certificate To Untrusted Store, CHCP Command Execution, Ivanti Sentry Authentication Bypass, Processes launching netsh, Sc exe Manipulating Windows Services.
  • Detections scheduled for removal in ESCU v6.4.0: PowerShell - Connect To Internet With Hidden Window and Regsvr32 with Known Silent Switch Cmdline (replace with Regsvr32 Silent and Install Param Dll Loading).

Security Fixes

  • CVE-2026-31431: New Linux analytics targeting copy‑fail exploitation and related post‑exploitation behaviors.

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track Splunk Security Content

Get notified when new releases ship.

Sign up free

About Splunk Security Content

Splunk Security Content

All releases β†’

Related context

Related tools

Earlier breaking changes

  • v6.0.0 Removes Attempt To Add Certificate To Untrusted Store detection in ESCU v6.1.0.
  • v6.0.0 Removes Ivanti Sentry Authentication Bypass detection in ESCU v6.1.0.
  • v6.0.0 Removes Processes launching netsh detection in ESCU v6.1.0.
  • v6.0.0 Removes Sc exe Manipulating Windows Services detection in ESCU v6.1.0.
  • v6.0.0 Removes CHCP Command Execution detection in ESCU v6.1.0.

Beta — feedback welcome: [email protected]