🚀 Key Highlights
⭐ Starland RAT Campaign (UAT-11795) ⭐
Expanded detection coverage for the Starland RAT campaign attributed to UAT-11795, a financially motivated threat actor leveraging ClickFix social engineering and trojanized installers to deploy Starland RAT, the WLDR Agent PowerShell memory implant, and supporting malware including CastleStealer and Remcos RAT. This release tags a broad set of existing analytics covering PowerShell abuse, malicious script execution, persistence, reconnaissance, suspicious downloads, registry modifications, and Telegram-based C2 communications, improving visibility into the multi-stage infection chain, in-memory execution, credential theft, and resilient command-and-control techniques used throughout the campaign.
👀 Linux Exploitation Detection Expansion 👀
Expanded Linux detection coverage with new analytics focused on local privilege escalation, defense evasion, and kernel-level exploitation techniques, improving visibility into attempts to bypass security controls, abuse elevated execution paths, and exploit low-level system components commonly targeted by advanced adversaries.
New Analytic Story - [1]
New Analytics - [4]
- Linux Apparmor Bypass Via Aaexec
- Linux Auditd Possible Setuid Execve Privesc
- Linux Pedit Offset Out Of Bounds
- Windows AppCertDLL Modification Via Registry
Updated Analytics - [67]
- AWS Bedrock Claude Unusually Large Prompts
- Attacker Tools On Endpoint
- Batch File Write to System32
- Cisco NVM - Curl Execution With Insecure Flags
- Cisco NVM - Installation of Typosquatted Python Package
- Cisco NVM - MSHTML or MSHTA Network Execution Without URL in CLI
- Cisco NVM - Non-Network Binary Making Network Connection
- Cisco NVM - Outbound Connection to Suspicious Port
- Cisco NVM - Rclone Execution With Network Activity
- Cisco NVM - Rundll32 Abuse of MSHTML.DLL for Payload Download
- Cisco NVM - Susp Script From Archive Triggering Network Activity
- Cisco NVM - Suspicious Download From File Sharing Website
- Cisco NVM - Suspicious File Download via Headless Browser
- Cisco NVM - Suspicious Network Connection From Process With No Args
- Cisco NVM - Suspicious Network Connection Initiated via MsXsl
- Cisco NVM - Suspicious Network Connection to IP Lookup Service API
- Cisco NVM - Webserver Download From File Sharing Website
- Common Ransomware Extensions
- Common Ransomware Notes
- Detect HTML Help URL in Command Line
- Detect MSHTA Url in Command Line
- Detect RClone Command-Line Usage
- Domain Controller Discovery with Nltest
- Email files written outside of the Outlook directory
- Executables Or Script Creation In Suspicious Path
- LLM Model File Creation
- Linux Binary Launched Process with Null Argv
- Linux PF_ALG Registration Outside of Boot Window
- Local LLM Framework DNS Query
- Malicious PowerShell Process - Execution Policy Bypass
- PowerShell 4104 Hunting
- Recon AVProduct Through Pwh or WMI
- Registry Keys Used For Persistence
- Set Default PowerShell Execution Policy To Unrestricted or Bypass
- Short Lived Scheduled Task (External Contributor: @AndreiBanaru)
- Suspicious Process Executed From Container File
- Svchost LOLBAS Execution Process Spawn
- Time Provider Persistence Registry
- WMIC XSL Execution via URL
- Windows AppCertDLL Modification Via Command Line
- Windows Boot or Logon Autostart Execution In Startup Folder
- Windows Curl Download to Suspicious Path
- Windows Curl Upload to Remote Destination
- Windows DNS Query Request by Telegram Bot API
- Windows File Download Via CertUtil
- Windows File Download Via PowerShell
- Windows File Without Extension In Critical Folder
- Windows Gather Victim Network Info Through Ip Check Web Services
- Windows HTTP Network Communication From MSIExec
- Windows InstallUtil Remote Network Connection
- Windows InstallUtil URL in Command Line
- Windows Kerberos Local Successful Logon
- Windows Large Number of Computer Service Tickets Requested (External Contributor: @munzzyy)
- Windows Local LLM Framework Execution
- Windows MSI Rollback Script Deleted By Non-Msiexec Process
- Windows MSIExec Remote Download
- Windows Mark Of The Web Bypass
- Windows Mshta Execution In Registry
- Windows PowerShell FakeCAPTCHA Clipboard Execution
- Windows PowerShell ScheduleTask
- Windows Process With NamedPipe CommandLine
- Windows RDP Cache File Deletion
- Windows Rdp AutomaticDestinations Deletion
- Windows Suspicious Defender Update Activity in INetCache
- Windows Suspicious Process File Path
- Windows WinSCP Configuration Security Access
- Wscript Or Cscript Suspicious Child Process
Other Updates
A special thanks to @thegreatmhn and @tid3na from the Security Content community for reporting bugs and proposing fixes that improved the quality and reliability of the security content.
We have also removed the Threat Activity by Snort IDs dashboard as it has been found to have a vulnerability and the searches in dashboard do not work due to issues with the Cisco Security Cloud TA. We will consider adding this dashboard in a future release when the TA can parse the data correctly.
The beta for Onboarding Assistant experience will conclude in the upcoming ESCU v6.4 release. The feedback we received during the beta has been invaluable, and we plan to bring this capability into Detection Studio later this year as a productized, more fully integrated experience.
Content Scheduled for Removal in Future Releases
| Content | Content Type | Removed in Version | Reason | Replacement Content |
|---|---|---|---|---|
| PowerShell - Connect To Internet With Hidden Window | Detection | 6.4.0 | Detection has been deprecated due to incorrect logic and bad performance. | None |
| Regsvr32 with Known Silent Switch Cmdline | Detection | 6.4.0 | Detection has been deprecated since its logic is already covered by another more improved detection. | Regsvr32 Silent and Install Param Dll Loading |
| Rundll32 CreateRemoteThread In Browser | Detection | 6.4.0 | Detection has been deprecated. The search is being replaced with a more generic detection that captures the behavior instead of relying on specific source processes. | Windows Uncommon Remote Thread Creation In Browser Process |
| Splunk App for Lookup File Editing RCE via User XSLT | Detection | 6.4.0 | Detection has been deprecated because it's too generic and does not provide the ability to detect the payload executed via this exploit. | None |
| Splunk Code Injection via custom dashboard leading to RCE | Detection | 6.4.0 | Detection has been deprecated. The affected Splunk software versions (8.1.12, 8.2.9, and 9.0.2) are no longer supported, having reached End of Life (EOL) between 2023 and 2024. Also, the logic is not perfectly capturing the malicious activity. | None |
| Splunk Enterprise KV Store Incorrect Authorization | Detection | 6.4.0 | Detection has been deprecated. The affected Splunk software versions (below 9.0.8 and 9.1.3)are no longer supported, having reached End of Life (EOL), and the logic is not accurately detecting the malicious activity. | None |
| Splunk Information Disclosure on Account Login | Detection | 6.4.0 | Detection has been deprecated. The logic is not accurately detecting the malicious activity. | None |
| Splunk Path Traversal In Splunk App For Lookup File Edit | Detection | 6.4.0 | Detection has been deprecated. The logic is not accurately detecting the malicious activity. | None |
| Splunk RCE PDFgen Render | Detection | 6.4.0 | Detection has been deprecated. The metadata along with the search are not accurately capturing the malicious activity. | None |
| Windows Process Injection Of Wermgr to Known Browser | Detection | 6.4.0 | Detection has been deprecated. The search is being replaced with a more generic detection that captures the behavior instead of relying on specific source processes. | Windows Uncommon Remote Thread Creation In Browser Process |
| Windows Process Injection With Public Source Path | Detection | 6.4.0 | Detection has been deprecated. The search is not helpful for the user to implement nor use, as it will generate too many false positives. | None |