Skip to content

Splunk Security Content

SIEM & Threat Detection

A repository of Splunk analytic stories and security content mapped to MITRE ATT&CK, Cyber Kill Chain, and CIS Controls for threat detection, investigation, and response.

Python Latest v6.0.0 · 2d ago Security brief →

Features

  • Provides curated Analytic Stories with Splunk searches and Phantom playbooks
  • Maps detections to MITRE ATT&CK, Lockheed Martin Cyber Kill Chain, and CIS Controls
  • Includes machine‑learning algorithms for threat detection
  • Offers tooling (contentctl) for building, testing, and packaging security content

Recent releases

View all 24 releases →
Review required
v6.0.0 Breaking risk
Breaking upgrade

Finding updates + date metadata + detection deprecations

v5.27.0 Security relevant
⚠ Upgrade required
  • Final release for ESCU v5.x; starting with ESCU v6.0, content will be validated, packaged, and published using new internal tooling instead of contentctl.
Security fixes
  • CVE-2026-31431 – Linux Auditd Copy Fail Privilege Escalation detection added to identify unprivileged users writing controlled data to page cache and escalating to root.
Notable features
  • Cisco Secure Access Analytics analytic story using firewall telemetry
  • Expanded Windows threat detection analytics covering PowerShell abuse, process injection, privilege escalation, cloud/Azure activity, RMM tools, and C2 frameworks
Full changelog

🚀 Key Highlights

  • 🚨 Linux Copy Fail Privilege Escalation (CVE-2026-31431): Added a new detection: Linux Auditd Copy Fail Privilege Escalation to identify exploitation of the Copy Fail vulnerability, a Linux kernel flaw that enables unprivileged users to perform controlled writes to file page cache and escalate privileges to root. This analytic leverages auditd telemetry to detect suspicious modification patterns targeting setuid binaries, providing early visibility into local privilege escalation attempts across affected Linux systems.

  • 🔐 Cisco Secure Access Analytics: Introduced a new analytic story for Cisco Secure Access, leveraging firewall telemetry to detect suspicious access patterns. This release includes updates to existing detections: Large ICMP Traffic, Outbound SMB Traffic, Outbound LDAP Traffic, and Windows RDP Network Brute Force Attempts enabling them to operate with Cisco Secure Access Firewall data, validated through simulated attack scenarios to improve visibility into adversary activity traversing modern cloud-delivered security controls.

  • 🪟 Windows Threat Detection Expansion: Significantly expanded coverage across multiple analytic stories with the addition of a broad set of new detections targeting modern Windows attack techniques, including PowerShell abuse, process injection, privilege escalation, registry manipulation, cloud and Azure activity, RMM tool usage, and C2 frameworks such as Cobalt Strike, Metasploit, and custom agents. These analytics enhance visibility into attacker behaviors like defense evasion (EDR bypass, obfuscation, EFI tampering), persistence (scheduled tasks, file association changes, GPO abuse), credential access (LAPS harvesting, keychain-like data access), and lateral movement and exfiltration, while also covering emerging tradecraft such as Cloudflared tunnels, Devtunnels, and supply chain tooling abuse—providing deeper detection across the Windows attack lifecycle.

  • ⌨️ VIP Keylogger (.NET Stealer) Detection Coverage: Introduced new analytics to strengthen detection of VIP Keylogger and related .NET-based infostealers by focusing on behavioral indicators of stealthy execution and persistence. New detections: PowerShell Environment Variable Execution, Windows Anomalous Registry Value Length in Environment Key, PowerShell PInvoke Process Injection API Chain, and Windows Proxy Execution of .NET Utilities via Scripts surface patterns such as encoded payload staging in registry keys, script-driven execution of trusted .NET binaries, and in-memory process injection techniques, improving visibility into credential theft operations, obfuscated execution chains, and defense evasion commonly used in modern phishing-delivered stealer campaigns.

New Analytic Story - [2]

New Analytics - [67]

Other Updates

  • Refined multiple detections using diverse telemetry sources to reduce false positives and enhance regex accuracy. (Pull Request)

  • Updated all detections to align with MITRE ATT&CK v19 technique IDs, ensuring consistency with the latest framework and improving mapping accuracy for threat coverage, reporting, and correlation.

Note: This is the final release for ESCU v5.x. Starting with ESCU v6.0, the STRT will use new internal tooling instead of contentctl to validate, package, and publish ESCU releases. For more information, see https://github.com/splunk/contentctl/blob/main/README.md

v5.26.0 Breaking risk
Breaking changes
  • Several detections removed; users must transition to replacements
Notable features
  • macOS Persistence, Post-Exploitation, Privilege Escalation stories
  • Axios supply chain post-compromise detection
Full changelog

🚀 Key Highlights

  • 🍎 macOS Detection Coverage Expansion: Expanded detection coverage for macOS environments with three new analytic stories - macOS Persistence Techniques, macOS Post-Exploitation, and macOS Privilege Escalation - delivering visibility across the full attack lifecycle. This release introduces detections for behaviors such as account creation, Gatekeeper bypass, keychain dumping, LoginHook persistence, kextload abuse, hidden files/directories, log removal, data chunking, network share discovery, and firewall rule enumeration, strengthening defense against stealthy macOS threats and improving monitoring of attacker activity on Apple endpoints.
  • ⛓️ Axios Supply Chain Post-Compromise Activity: Expanded detection coverage for Axios-related supply chain post-compromise scenarios by tagging existing analytics that capture behaviors associated with malicious package execution and downstream abuse. This update improves visibility into post-installation script execution, credential access, data exfiltration, and persistence mechanisms often triggered after a compromised dependency is introduced, helping defenders detect and respond to supply chain attacks impacting JavaScript and Node.js ecosystems.

New Analytic Story - [4]

New Analytics - [11]

Other Updates

  • Fixed a bug in the Onboarding Assistant that affected Splunk Cloud customers using instances configured on ports (other than 8000). In these cases, detections within an analytic story failed to enable correctly or behaved inconsistently. This issue has been resolved, and detections can now be enabled successfully.
  • Updated all View risk events for the last 7 days drilldown searches to reflect the correct earliest and latest time configuration.
  • Improved detection coverage and accuracy across multiple rules by fixing regex issues, refining conditions, adding macro usage, and reducing false positives. To view the detailed list of updates and the associated Github issues, please view the details in this pull request.
  • Removed missing fields from the Windows Event Log Cleared detection (External Contributor: AndreiBanaru).

Breaking Changes

As previously communicated in the ESCU v5.24.0 release, several detections have been removed. For a complete list of the detections removed in version v5.26.0, refer to the List of Removed Detections. Users are expected to transition to the recommended replacements where applicable. Additionally, a new set of detections has been deprecated. For details on detections scheduled for removal in ESCU version v6.1.0, see the List of Detections Scheduled for Removal.

v5.25.1 Mixed
Notable features
  • Ghost RAT threat detection with new analytic story
  • Void Manticore threat detection expansion
  • Improved detection accuracy and false positive reduction
v5.25.0 New feature
Notable features
  • Ghost RAT analytic story
  • Void Manticore destructive operations
  • Windows Rundll32 with Non-Standard File Extension

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

About

Stars
1,634
Forks
458
Languages
Python Jupyter Notebook Shell

Install & Platforms

Install via
pip

Beta — feedback welcome: [email protected]