Splunk® Enterprise Security Content Update

Release Notes

This documentation does not apply to the most recent version of Splunk® Enterprise Security Content Update. For documentation on the most recent version, go to the latest release.

What's new

Enterprise Security Content Updates v4.40.0 was released on September 11, 2024 and includes the following enhancements:

Key highlights

Compromised Linux Host: This update introduces a robust set of 50 detections for compromised Linux hosts, covering a wide range of activities such as unauthorized account creation, file ownership changes, kernel module modifications, privilege escalation, data destruction, and suspicious service stoppages, enhancing visibility into potential malicious actions and system tampering.

Black Suit Ransomware: We have tagged existing analytics, aligning with tactics, techniques, and procedures (TTPs) associated with the Black Suit ransomware, providing organizations with targeted threat detection capabilities to identify and mitigate ransomware attacks before they can cause significant damage.

CISA Alert (CISA AA24-241A): In response to a joint advisory regarding Iran-based cyber actors exploiting U.S. and foreign organizations, this update includes new detections for identifying PowerShell Web Access installations and enabling activities, strengthening defenses against ransomware and espionage activities linked to these threats.

New analytic story

New analytics

Updated analytics

Macros added

  • linux_auditd
  • linux_auditd_normalized_execve_process
  • linux_auditd_normalized_proctitle_process


Other updates

  • Updated text in feedback center dashboard
  • Added Splunk Enterprise 9.3 as a version compatible with ESCU when uploading to Splunkbase
Last modified on 26 September, 2024
 

This documentation applies to the following versions of Splunk® Enterprise Security Content Update: 4.40.0


Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters