Splunk® Security Content

Release Notes

This documentation does not apply to the most recent version of Splunk® Security Content. For documentation on the most recent version, go to the latest release.

What's new

Enterprise Security Content Updates v3.55.0 was released on December 13, 2022. It includes the following enhancements.

New analytic story

  • Prestige Ransomware
  • Windows Post-Exploitation

New analytics

  • Windows Modify Registry Reg Restore
  • Windows Query Registry Reg Save
  • Windows System User Discovery Via Quser
  • Windows WMI Process and Service List
  • Windows Cached Domain Credentials Reg Query
  • Windows ClipBoard Data via Get-ClipBoard
  • Windows Credentials from Password Stores Query
  • Windows Credentials in Registry Reg Query
  • Windows Indirect Command Execution Via Series of Forfiles
  • Windows Information Discovery Fsutil
  • Windows Password Managers Discovery
  • Windows Private Keys Discovery
  • Windows Security Support Provider Reg Query
  • Windows Steal or Forge Kerberos Tickets Klist
  • Windows System Network Config Discovery Display DNS
  • Windows System Network Connections Discovery Netsh
  • Windows Change Default File Association for No File Ext
  • Windows Service Stop Via Net and SC Application

Other updates

  • Added new Mitre MAP Coverage map json files to show the CISA 2021 Top Malware TTP coverage in docs/mitre-map.
  • Fixed a bug in contentctl to appropriate scheduling configuration in savedsearches.conf
Last modified on 15 December, 2022
  What's in Splunk Security Content

This documentation applies to the following versions of Splunk® Security Content: 3.55.0


Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters