Skip to content

Release history

Splunk Security Content releases

Splunk Security Content

All releases

24 shown

Review required
v6.0.0 Breaking risk
Breaking upgrade

Finding updates + date metadata + detection deprecations

v5.27.0 Security relevant
⚠ Upgrade required
  • Final release for ESCU v5.x; starting with ESCU v6.0, content will be validated, packaged, and published using new internal tooling instead of contentctl.
Security fixes
  • CVE-2026-31431 – Linux Auditd Copy Fail Privilege Escalation detection added to identify unprivileged users writing controlled data to page cache and escalating to root.
Notable features
  • Cisco Secure Access Analytics analytic story using firewall telemetry
  • Expanded Windows threat detection analytics covering PowerShell abuse, process injection, privilege escalation, cloud/Azure activity, RMM tools, and C2 frameworks
Full changelog

🚀 Key Highlights

  • 🚨 Linux Copy Fail Privilege Escalation (CVE-2026-31431): Added a new detection: Linux Auditd Copy Fail Privilege Escalation to identify exploitation of the Copy Fail vulnerability, a Linux kernel flaw that enables unprivileged users to perform controlled writes to file page cache and escalate privileges to root. This analytic leverages auditd telemetry to detect suspicious modification patterns targeting setuid binaries, providing early visibility into local privilege escalation attempts across affected Linux systems.

  • 🔐 Cisco Secure Access Analytics: Introduced a new analytic story for Cisco Secure Access, leveraging firewall telemetry to detect suspicious access patterns. This release includes updates to existing detections: Large ICMP Traffic, Outbound SMB Traffic, Outbound LDAP Traffic, and Windows RDP Network Brute Force Attempts enabling them to operate with Cisco Secure Access Firewall data, validated through simulated attack scenarios to improve visibility into adversary activity traversing modern cloud-delivered security controls.

  • 🪟 Windows Threat Detection Expansion: Significantly expanded coverage across multiple analytic stories with the addition of a broad set of new detections targeting modern Windows attack techniques, including PowerShell abuse, process injection, privilege escalation, registry manipulation, cloud and Azure activity, RMM tool usage, and C2 frameworks such as Cobalt Strike, Metasploit, and custom agents. These analytics enhance visibility into attacker behaviors like defense evasion (EDR bypass, obfuscation, EFI tampering), persistence (scheduled tasks, file association changes, GPO abuse), credential access (LAPS harvesting, keychain-like data access), and lateral movement and exfiltration, while also covering emerging tradecraft such as Cloudflared tunnels, Devtunnels, and supply chain tooling abuse—providing deeper detection across the Windows attack lifecycle.

  • ⌨️ VIP Keylogger (.NET Stealer) Detection Coverage: Introduced new analytics to strengthen detection of VIP Keylogger and related .NET-based infostealers by focusing on behavioral indicators of stealthy execution and persistence. New detections: PowerShell Environment Variable Execution, Windows Anomalous Registry Value Length in Environment Key, PowerShell PInvoke Process Injection API Chain, and Windows Proxy Execution of .NET Utilities via Scripts surface patterns such as encoded payload staging in registry keys, script-driven execution of trusted .NET binaries, and in-memory process injection techniques, improving visibility into credential theft operations, obfuscated execution chains, and defense evasion commonly used in modern phishing-delivered stealer campaigns.

New Analytic Story - [2]

New Analytics - [67]

Other Updates

  • Refined multiple detections using diverse telemetry sources to reduce false positives and enhance regex accuracy. (Pull Request)

  • Updated all detections to align with MITRE ATT&CK v19 technique IDs, ensuring consistency with the latest framework and improving mapping accuracy for threat coverage, reporting, and correlation.

Note: This is the final release for ESCU v5.x. Starting with ESCU v6.0, the STRT will use new internal tooling instead of contentctl to validate, package, and publish ESCU releases. For more information, see https://github.com/splunk/contentctl/blob/main/README.md

v5.26.0 Breaking risk
Breaking changes
  • Several detections removed; users must transition to replacements
Notable features
  • macOS Persistence, Post-Exploitation, Privilege Escalation stories
  • Axios supply chain post-compromise detection
Full changelog

🚀 Key Highlights

  • 🍎 macOS Detection Coverage Expansion: Expanded detection coverage for macOS environments with three new analytic stories - macOS Persistence Techniques, macOS Post-Exploitation, and macOS Privilege Escalation - delivering visibility across the full attack lifecycle. This release introduces detections for behaviors such as account creation, Gatekeeper bypass, keychain dumping, LoginHook persistence, kextload abuse, hidden files/directories, log removal, data chunking, network share discovery, and firewall rule enumeration, strengthening defense against stealthy macOS threats and improving monitoring of attacker activity on Apple endpoints.
  • ⛓️ Axios Supply Chain Post-Compromise Activity: Expanded detection coverage for Axios-related supply chain post-compromise scenarios by tagging existing analytics that capture behaviors associated with malicious package execution and downstream abuse. This update improves visibility into post-installation script execution, credential access, data exfiltration, and persistence mechanisms often triggered after a compromised dependency is introduced, helping defenders detect and respond to supply chain attacks impacting JavaScript and Node.js ecosystems.

New Analytic Story - [4]

New Analytics - [11]

Other Updates

  • Fixed a bug in the Onboarding Assistant that affected Splunk Cloud customers using instances configured on ports (other than 8000). In these cases, detections within an analytic story failed to enable correctly or behaved inconsistently. This issue has been resolved, and detections can now be enabled successfully.
  • Updated all View risk events for the last 7 days drilldown searches to reflect the correct earliest and latest time configuration.
  • Improved detection coverage and accuracy across multiple rules by fixing regex issues, refining conditions, adding macro usage, and reducing false positives. To view the detailed list of updates and the associated Github issues, please view the details in this pull request.
  • Removed missing fields from the Windows Event Log Cleared detection (External Contributor: AndreiBanaru).

Breaking Changes

As previously communicated in the ESCU v5.24.0 release, several detections have been removed. For a complete list of the detections removed in version v5.26.0, refer to the List of Removed Detections. Users are expected to transition to the recommended replacements where applicable. Additionally, a new set of detections has been deprecated. For details on detections scheduled for removal in ESCU version v6.1.0, see the List of Detections Scheduled for Removal.

v5.25.1 Mixed
Notable features
  • Ghost RAT threat detection with new analytic story
  • Void Manticore threat detection expansion
  • Improved detection accuracy and false positive reduction
v5.25.0 New feature
Notable features
  • Ghost RAT analytic story
  • Void Manticore destructive operations
  • Windows Rundll32 with Non-Standard File Extension
v5.24.0 New feature
Notable features
  • BlankGrabber Stealer coverage
  • Lotus Blossom Chrysalis backdoor detection
v5.23.0 New feature
Notable features
  • Cisco SD-WAN Low Frequency Rogue Peer detection
  • Cisco SD-WAN Peering Activity detection
v5.22.0 Security relevant
Breaking changes
  • Cobalt Strike Named Pipes replaced
  • HTTP Suspicious Tool User Agent replaced
Notable features
  • Suspicious MCP Activities story
  • DynoWiper and ZOVWiper coverage
v5.21.0 New feature
Breaking changes
  • Removed notable alert action from Process Creating LNK file in Suspicious Location
Security fixes
  • CVE-2026-24061 GNU Telnetd authentication bypass detection
Notable features
  • Finding-Based Detections for ES 8.4+
  • GNU Telnetd CVE-2026-24061 coverage
  • Windows Chromium browser hijacking
v5.20.0 New feature
Breaking changes
  • Windows Default RDP File Creation replaced
  • Windows Java Spawning Shells replaced
Notable features
  • Browser Hijacking analytics
  • Cisco Isovalent eBPF detections
  • HTTP suspicious user agent detection
v5.19.0 Security relevant
Security fixes
  • CVE-2025-55182 React Server Components RCE
  • CVE-2025-33073 Kerberos DNS coercion
Notable features
  • React2Shell RCE detection
  • Kerberos Coercion with DNS detection
  • NPM Supply Chain Compromise coverage
v5.18.0 New feature
Notable features
  • Castle RAT analytic story
  • Windows Browser Process Unusual Flags
  • Windows ComputerDefaults UAC bypass
v5.17.0 Security relevant
Security fixes
  • CVE-2025-59287 WSUS RCE detection
Notable features
  • WSUS CVE-2025-59287 detection
  • HTTP Request Smuggling detections
  • Scattered Lapsus$ Hunters coverage
v5.16.0 New feature
Breaking changes
  • Notable alert actions changed for specific detections
Notable features
  • Suspicious Ollama Activities story
  • M365 Copilot anomaly detection
  • PromptLock GenAI ransomware coverage
v5.15.2 Mixed

New analytic story for detecting suspicious Cisco Adaptive Security Appliance activity.

v5.15.0 Security relevant
Security fixes
  • CVE-2025-20333 detection
  • CVE-2025-20362 detection
Notable features
  • ArcaneDoor analytic story
  • Cisco ASA Core Syslog Message Volume Drop
  • Cisco ASA Logging Disabled via CLI
v5.14.0 New feature
Notable features
  • LAMEHUG AI-driven malware detection
  • NotDoor Outlook macro detection
  • Secret Blizzard certificate installation
v5.13.0 Security relevant
Security fixes
  • CVE-2018-0171 Cisco Smart Install RCE detection
Notable features
  • Cisco Smart Install detection
  • Static Tundra tradecraft detection
v5.12.0 New feature
Notable features
  • Medusa Rootkit detection
  • MSIX Package Abuse analytics
  • RDP Artifacts and Defense Evasion
v5.11.0 New feature

Adds detection coverage for Interlock Ransomware, NaiLaoLocker, Interlock RAT, and Scattered Spider threat actor.

v5.10.0 Security relevant
Security fixes
  • CVE-2025-5777 Citrix NetScaler detection
  • CVE-2025-53770 SharePoint detection
Notable features
  • Citrix NetScaler memory leak detection
  • SharePoint ToolPane exploitation
  • ESXi post-compromise 24 detections
v5.9.0 New feature

14 new Cisco Network Visibility Module analytics for detecting suspicious endpoint network behavior.

v5.8.0 New feature
Notable features
  • Remote Employment Fraud detection
  • Inno Setup malware coverage
  • Web Browser abuse analytics
v5.7.0 New feature
Notable features
  • Cisco Secure Firewall FTD integration
  • Remote Access Software Usage Traffic detection

Beta — feedback welcome: [email protected]