Skip to content

v6.3.0

Latest

Choose a tag to compare

@patel-bhavin patel-bhavin released this 29 Jul 14:21
fed8170

🚀 Key Highlights

⭐ Starland RAT Campaign (UAT-11795) ⭐

Expanded detection coverage for the Starland RAT campaign attributed to UAT-11795, a financially motivated threat actor leveraging ClickFix social engineering and trojanized installers to deploy Starland RAT, the WLDR Agent PowerShell memory implant, and supporting malware including CastleStealer and Remcos RAT. This release tags a broad set of existing analytics covering PowerShell abuse, malicious script execution, persistence, reconnaissance, suspicious downloads, registry modifications, and Telegram-based C2 communications, improving visibility into the multi-stage infection chain, in-memory execution, credential theft, and resilient command-and-control techniques used throughout the campaign.

👀 Linux Exploitation Detection Expansion 👀

Expanded Linux detection coverage with new analytics focused on local privilege escalation, defense evasion, and kernel-level exploitation techniques, improving visibility into attempts to bypass security controls, abuse elevated execution paths, and exploit low-level system components commonly targeted by advanced adversaries.

New Analytic Story - [1]

New Analytics - [4]

Updated Analytics - [67]

Other Updates

A special thanks to @thegreatmhn and @tid3na from the Security Content community for reporting bugs and proposing fixes that improved the quality and reliability of the security content.

We have also removed the Threat Activity by Snort IDs dashboard as it has been found to have a vulnerability and the searches in dashboard do not work due to issues with the Cisco Security Cloud TA. We will consider adding this dashboard in a future release when the TA can parse the data correctly.

The beta for Onboarding Assistant experience will conclude in the upcoming ESCU v6.4 release. The feedback we received during the beta has been invaluable, and we plan to bring this capability into Detection Studio later this year as a productized, more fully integrated experience.

Content Scheduled for Removal in Future Releases

Content Content Type Removed in Version Reason Replacement Content
PowerShell - Connect To Internet With Hidden Window Detection 6.4.0 Detection has been deprecated due to incorrect logic and bad performance. None
Regsvr32 with Known Silent Switch Cmdline Detection 6.4.0 Detection has been deprecated since its logic is already covered by another more improved detection. Regsvr32 Silent and Install Param Dll Loading
Rundll32 CreateRemoteThread In Browser Detection 6.4.0 Detection has been deprecated. The search is being replaced with a more generic detection that captures the behavior instead of relying on specific source processes. Windows Uncommon Remote Thread Creation In Browser Process
Splunk App for Lookup File Editing RCE via User XSLT Detection 6.4.0 Detection has been deprecated because it's too generic and does not provide the ability to detect the payload executed via this exploit. None
Splunk Code Injection via custom dashboard leading to RCE Detection 6.4.0 Detection has been deprecated. The affected Splunk software versions (8.1.12, 8.2.9, and 9.0.2) are no longer supported, having reached End of Life (EOL) between 2023 and 2024. Also, the logic is not perfectly capturing the malicious activity. None
Splunk Enterprise KV Store Incorrect Authorization Detection 6.4.0 Detection has been deprecated. The affected Splunk software versions (below 9.0.8 and 9.1.3)are no longer supported, having reached End of Life (EOL), and the logic is not accurately detecting the malicious activity. None
Splunk Information Disclosure on Account Login Detection 6.4.0 Detection has been deprecated. The logic is not accurately detecting the malicious activity. None
Splunk Path Traversal In Splunk App For Lookup File Edit Detection 6.4.0 Detection has been deprecated. The logic is not accurately detecting the malicious activity. None
Splunk RCE PDFgen Render Detection 6.4.0 Detection has been deprecated. The metadata along with the search are not accurately capturing the malicious activity. None
Windows Process Injection Of Wermgr to Known Browser Detection 6.4.0 Detection has been deprecated. The search is being replaced with a more generic detection that captures the behavior instead of relying on specific source processes. Windows Uncommon Remote Thread Creation In Browser Process
Windows Process Injection With Public Source Path Detection 6.4.0 Detection has been deprecated. The search is not helpful for the user to implement nor use, as it will generate too many false positives. None