Splunk Security Content for Threat Detection & Response: September Recap
Security Splunk Threat Research TeamIn September, the Splunk Threat Research Team (STRT) had 2 releases of new security content via the Enterprise Security Content Update (ESCU) app (v6.6.0 and v6.7.0) With these releases, there are 19 new analytics, and 48 updated analytics, now available in Splunk Enterprise Security via the ESCU application update process.
Content highlights include:
- Detection and AI Risk Classification: New NIST AI RMF Control Coverage dashboard (Alpha) gives security teams an operational view of how shadow AI detections and activity from common GenAI platforms align with the NIST AI Risk Management Frameworkâs Govern, Map, Measure, and Manage functions.
- Suspicious Network and Shell Activity Detections: New analytics for browser-spawned Unix shells with external connections, uncommon and rare network connections from LOLBAS binaries, and suspicious Socat listener and remote TCP activity.
- New macOS AppleScript and Osascript Detections: Introduced MacOS AppleScript Shell Execution and Compilation, MacOS Osascript Displaying Suspicious User Prompt, MacOS Osascript Executing Interactive Shell and MacOS Osascript Executing JavaScript Code With ObjC analytics covering AppleScript shell execution and compilation, as well as suspicious user prompts displayed through osascript. These detections improve visibility into script-based execution and potentially deceptive user interaction used to facilitate malicious activity on macOS endpoints.
- Added SCCM Abuse Coverage: Introduced two analytics (Windows SCCM Adsource DLL Was Planted In SMS Provider Directory and Windows SCCM Smsexec Spawned a Suspicious Child Process) focused on suspicious SCCM activity: DLL planting in the SMS Provider directory and abnormal child-process execution spawned by smsexec. This provides stronger visibility into potential abuse of SCCM components for execution, persistence, or lateral movement.
- Improved Windows ClickFix and LOLBin coverage: Added (Windows Finger.exe Connecting to a Remote Host, Windows For Loop Usage Within Cmd.exe To Execute Commands, Windows Node.exe Executing JS Script In Immediate Folder, and Windows Process Accessing IronLanguages Repository On GitHub) covering remote connections through finger.exe, command execution through for /f loops, JavaScript execution by node.exe from unusual directories, and processes accessing the IronLanguages repository on GitHub. These detections improve visibility into ClickFix-related execution chains, payload retrieval, scripting abuse, and the use of trusted utilities for malicious activity.
- Improved credential-access and process-injection detections: Updated detections leveraging the process access data source, covering LSASS access and termination, credential dumping, Winlogon token manipulation, Rubeus ticket export activity, handle duplication, and process injection. These changes improve analytic consistency, investigation context, and visibility into credential-access and defense-evasion techniques.
- Cross-Platform Detection Refinements: Updated analytics across Windows, Linux, and macOS environments. The refinements improve coverage and detection fidelity for Citrix ADC exploitation, pipe-based execution, file and process activity, data destruction, Ghostscript exploitation, account creation, data chunking, network discovery, PowerShell, event-log manipulation, user and private-key discovery, credential access, and execution from suspicious paths.
- Detection quality and metadata improvements: Updated analytics across application, endpoint, network, and web content. Changes include improved SPL logic, additional threat objects and references, better event context, and tuning intended to improve detection fidelity and reduce noise.
Title
Related Articles
Filter
Category
Blog Limit
3
Category
security
Sort Category Shuffle Order
true
Related Articles

Previous Security Content Roundups from the Splunk Threat Research Team (STRT)
Recap: Learn about the last four quarters of security content from the Splunk Threat Research Team.

Mockbin and the Art of Deception: Tracing Adversaries, Going Headless and Mocking APIs
Splunk's Threat Research Team delves into the attack's components, usage of tools like Mockbin and headless browsers, and provides guidance on detecting such activities.

Old School vs. New School
The Splunk SURGe team examines the claim that generative AI will empower threat actors to improve the scale and/or efficiency of their spear-phishing campaigns.