Splunk® Enterprise Security Content Update

Release Notes

What's new

Enterprise Security Content Updates v4.44.0 was released on December 4, 2024 and includes the following enhancements:

Key highlights

  • Windows Defender: Two new analytics now surface and summarize alerts from Microsoft Defender Advanced Threat Protection (ATP) as well as Microsoft Defender O365 Incidents.
  • BitLockerToGo Abuse: Two new analytics search for use of the legitimate BitLockerToGo.exe Windows utility. This application has been abused by the Lumma Stealer malware to manipulate registry keys, search for cryptocurrency wallets or credentials, and exfiltrate sensitive data.
  • VaultCLI Usage: One new analytic flags suspicious usage of the VaultCLI.dll, a technique observed by Information-Stealing Malware such as Meduza. This DLL allows processes to extract sensitive credentials from the Windows Credential Vault.
  • Windows RDP Activities: Two new analytics look for potentially suspicious Windows RDP activities.
  • Windows RunMRU Modifications: One analytic monitors changes to the RunMRU registry key. This key, which stores a history of commands executed via the windows Run dialog box, may capture commands run by malware attempting to appear legitimate.
  • Analytic Stories: Three new Analytic Stories have been introduced targeting Lumma Stealer, Meduza Stealer, and PXA Stealer

New analytic story

New analytics

Macros added

  • ms365_defender_incident_alerts
  • ms_defender_atp_alerts
  • wineventlog_rdp

Updated analytics

A number of analytics have been updated to address minor typos in the description field, make use of macros, or capture equivalent variants of commands.

Last modified on 05 December, 2024
 

This documentation applies to the following versions of Splunk® Enterprise Security Content Update: 4.44.0


Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters