Skip to content

Conversation

@nasbench
Copy link
Contributor

@nasbench nasbench commented Mar 3, 2025

The following PR introduces the following updates

Deprecated Analytics

  • CertUtil Download With URLCache and Split Arguments
  • CertUtil Download With VerifyCtl and Split Arguments
  • Windows CertUtil Download With URL Argument

New Analytics

  • Windows File Download Via CertUtil - This new analytic merges the 3 deprecated.

Updated Analytics

  • CHCP Command Execution - Removed the CommandLine condition to make it more generic. Also switched it to an Anomaly.
  • Check Elevated CMD using whoami - Updated FP section
  • Detection of tools built by NirSoft - Updated to an Anomaly
  • System Processes Run From Unexpected Locations - Added new locations to tune FP

Updated Lookups

  • is_nirsoft_software - Added additional nirsoft tooling

@patel-bhavin
Copy link
Contributor

Since this has new deprecated content : Lets make sure this PR passes the new validation check : splunk/contentctl#355

@patel-bhavin patel-bhavin added the Deprecated PRs where content is moved to deprecated label Mar 25, 2025
@patel-bhavin patel-bhavin modified the milestone: v5.5.0 Apr 17, 2025
@nasbench nasbench added this to the v5.5.0 milestone Apr 24, 2025
@nasbench nasbench marked this pull request as ready for review April 24, 2025 19:34
@patel-bhavin patel-bhavin merged commit a26bfc0 into develop May 1, 2025
4 checks passed
@patel-bhavin patel-bhavin deleted the small-tuning branch May 1, 2025 18:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Deprecated PRs where content is moved to deprecated Detections Lookups

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants