๐ Key Highlights
๐ง Linux Detection Coverage Expansion:
Added broad new Linux behavioral coverage targeting privilege escalation, persistence, execution, defense evasion, reverse shells, container abuse, and suspicious service activity. New analytics identify behaviors including bootloader and system file modification, shared-memory execution, UDEV and XDG persistence, privileged container execution, PostgreSQL and Redis abuse, Ghostscript exploitation, shell history access, and multiple potential privilege-escalation paths, giving defenders stronger visibility into suspicious activity that can blend with legitimate Linux administration.
๐ช Windows Detection Coverage:
Expanded Windows detection coverage with new analytics for network reconnaissance, suspicious PowerShell execution, and abnormal process behavior. New detections identify network sniffing tools, PowerShell commands retrieved through DNS TXT records, directory output piped to Findstr, and suspicious child processes of Consent.exe, helping security teams surface discovery, command execution, defense evasion, and other potentially malicious endpoint activity.
๐ ๏ธ Detection Updates & Fixes:
Refined six existing analytics covering administrative SMB shares, high-frequency file copying, network-share discovery, user discovery, and registry-based defense evasion, improving existing detection coverage and fidelity. This release also updates the attacker_tools and malware_user_agents lookups, providing refreshed context to support threat detection and investigation workflows.
New Analytics - [27]
- Linux Binary Executed from Shared Memory Directory
- Linux EFI Bootloader File Deletion
- Linux File Creation In System Generator Directory
- Linux Ghostscript Exploitation
- Linux MOTD Script Added
- Linux Netcat Outbound Connection
- Linux Possible Bootloader Modification
- Linux Possible GSM Privilege Escalation
- Linux Possible Nimbuspwn Privilege Escalation
- Linux Possible Privilege Escalation via PYTHONPATH
- Linux Possible System Binary Backdoor
- Linux Root Execution of id
- Linux Shell History Access Via Command Line Utility
- Linux Shell Pseudo Device Reverse Shell
- Linux Suspicious Child Process of PostgreSQL
- Linux Suspicious Docker Build Command Execution
- Linux Suspicious GCC Invocation Building Init Shared Object
- Linux Suspicious Privileged Container Execution
- Linux Suspicious Redis Activity
- Linux Suspicious Staging of Alternate System Files
- Linux Suspicious XDG Autostart
- Linux UDEV Rule Created
- Linux Usermod Root UID Set
- Windows Dir Piped to Findstr Activity
- Windows Network Sniffing Tool Executed
- Windows Powershell Commands from DNS TXT
- Windows Suspicious Child Process of Consent.EXE
Updated Analytics - [6]
- Executable File Written in Administrative SMB Share
- High Frequency Copy Of Files In Network Share
- Network Share Discovery Via Dir Command
- Windows Disable Shutdown Button Through Registry
- Windows Registry Dotnet ETW Disabled Via ENV Variable
- Windows User Discovery Via Net
Other Updates
- Both the attacker_tools and malware_user_agents lookups have been updated with refreshed content to improve detection and investigation context.
- A special thanks to @munzzyy, @tid3na, and @thegreatmhn from the Security Content community for reporting bugs and proposing fixes that improved the quality and reliability of the security content.
Breaking Changes
- As communicated in ESCU v6.3.0, the Onboarding Assistant beta has now concluded and is no longer available in ESCU as we prepare to bring this capability into Detection Studio for a more fully integrated experience.
- As previously communicated in ESCU v6.2.0, ESCU v6.4.0 removes several detections. See the list of removed detections below for affected detections and recommended replacements. If you are currently using any deprecated detections, review the deprecated analytics in ESCU documentation for guidance on identifying, reviewing, and preserving deprecated detections before upgrading.
Content Removed in Release v6.4.0
| Content | Content Type | Reason | Replacement Content |
|---|---|---|---|
| PowerShell - Connect To Internet With Hidden Window | Detection | Detection has been deprecated due to incorrect logic and bad performance. | None |
| Regsvr32 with Known Silent Switch Cmdline | Detection | Detection has been deprecated since its logic is already covered by another more improved detection. | Regsvr32 Silent and Install Param Dll Loading |
| Rundll32 CreateRemoteThread In Browser | Detection | Detection has been deprecated. The search is being replaced with a more generic detection that captures the behavior instead of relying on specific source processes. | Windows Uncommon Remote Thread Creation In Browser Process |
| Splunk App for Lookup File Editing RCE via User XSLT | Detection | Detection has been deprecated because it's too generic and does not provide the ability to detect the payload executed via this exploit. | None |
| Splunk Code Injection via custom dashboard leading to RCE | Detection | Detection has been deprecated. The affected Splunk software versions (8.1.12, 8.2.9, and 9.0.2) are no longer supported, having reached End of Life (EOL) between 2023 and 2024. Also, the logic is not perfectly capturing the malicious activity. | None |
| Splunk Enterprise KV Store Incorrect Authorization | Detection | Detection has been deprecated. The affected Splunk software versions (below 9.0.8 and 9.1.3)are no longer supported, having reached End of Life (EOL), and the logic is not accurately detecting the malicious activity. | None |
| Splunk Information Disclosure on Account Login | Detection | Detection has been deprecated. The logic is not accurately detecting the malicious activity. | None |
| Splunk Path Traversal In Splunk App For Lookup File Edit | Detection | Detection has been deprecated. The logic is not accurately detecting the malicious activity. | None |
| Splunk RCE PDFgen Render | Detection | Detection has been deprecated. The metadata along with the search are not accurately capturing the malicious activity. | None |
| Windows Process Injection Of Wermgr to Known Browser | Detection | Detection has been deprecated. The search is being replaced with a more generic detection that captures the behavior instead of relying on specific source processes. | Windows Uncommon Remote Thread Creation In Browser Process |
| Windows Process Injection With Public Source Path | Detection | Detection has been deprecated. The search is not helpful for the user to implement nor use, as it will generate too many false positives. | None |