Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion build.yml
Original file line number Diff line number Diff line change
Expand Up @@ -9,7 +9,7 @@ author: Splunk Threat Research Team
author_email: research@splunk.com
content_prefix: ESCU
label: ES Content Updates
app_version: 6.3.0
app_version: 6.4.0
description: Explore the Analytic Stories included with ES Content Updates.
id: DA-ESS-ContentUpdate
external_app_content:
Expand Down
2 changes: 1 addition & 1 deletion contentctl.yml
Original file line number Diff line number Diff line change
Expand Up @@ -3,7 +3,7 @@ app:
uid: 3449
title: ES Content Updates
appid: DA-ESS-ContentUpdate
version: 6.3.0
version: 6.4.0
description: Explore the Analytic Stories included with ES Content Updates.
prefix: ESCU
label: ESCU
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -2,9 +2,9 @@ name: PowerShell - Connect To Internet With Hidden Window
id: ee18ed37-0802-4268-9435-b3b91aaa18db
version: 17
creation_date: '2020-04-29'
modification_date: '2026-06-04'
modification_date: '2026-07-29'
author: David Dorsey, Michael Haag Splunk
status: deprecated
status: removed
type: Hunting
description: The following analytic detects PowerShell commands using the WindowStyle parameter to hide the window while connecting to the Internet. This behavior is identified through Endpoint Detection and Response (EDR) telemetry, focusing on command-line executions that include variations of the WindowStyle parameter. This activity is significant because it attempts to bypass default PowerShell execution policies and conceal its actions, which is often indicative of malicious intent. If confirmed malicious, this could allow an attacker to execute commands stealthily, potentially leading to unauthorized data exfiltration or further compromise of the endpoint.
data_source:
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -2,9 +2,9 @@ name: Regsvr32 with Known Silent Switch Cmdline
id: c9ef7dc4-eeaf-11eb-b2b6-acde48001122
version: 15
creation_date: '2021-07-29'
modification_date: '2026-06-09'
modification_date: '2026-07-29'
author: Teoderick Contreras, Splunk
status: deprecated
status: removed
deprecation_info:
reason: Detection has been deprecated since its logic is already covered by another more improved detection.
removed_in_version: 6.4.0
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -2,9 +2,9 @@ name: Rundll32 CreateRemoteThread In Browser
id: f8a22586-ee2d-11eb-a193-acde48001122
version: 11
creation_date: '2021-07-29'
modification_date: '2026-06-29'
modification_date: '2026-07-29'
author: Teoderick Contreras, Splunk
status: deprecated
status: removed
type: TTP
description: |-
The following analytic detects the suspicious creation of a remote thread by rundll32.exe targeting browser processes such as firefox.exe, chrome.exe, iexplore.exe, and microsoftedgecp.exe.
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -2,9 +2,9 @@ name: Splunk App for Lookup File Editing RCE via User XSLT
id: a053e6a6-2146-483a-9798-2d43652f3299
version: 8
creation_date: '2023-11-16'
modification_date: '2026-06-24'
modification_date: '2026-07-29'
author: Rod Soto, Splunk
status: deprecated
status: removed
type: Hunting
description: The following analytic identifies the creation of lookup files in Splunk, which could indicate an attempt to exploit remote code execution via user-supplied XSLT. It leverages REST API queries to monitor the creation of these lookups, focusing on fields such as title, author, and access control lists. This activity is significant because it targets a known vulnerability in Splunk versions 9.1.x, potentially allowing attackers to execute arbitrary code. If confirmed malicious, this could lead to unauthorized code execution, compromising the integrity and security of the Splunk environment.
data_source: []
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -2,9 +2,9 @@ name: Splunk Code Injection via custom dashboard leading to RCE
id: b06b41d7-9570-4985-8137-0784f582a1b3
version: 8
creation_date: '2022-12-19'
modification_date: '2026-06-24'
modification_date: '2026-07-29'
author: Rod Soto
status: deprecated
status: removed
type: Hunting
description: The following analytic identifies attempts to exploit a vulnerability in Splunk Enterprise versions below 8.2.9, 8.1.12, and 9.0.2, where an authenticated user can execute arbitrary code via the dashboard PDF generation component. It detects this activity by analyzing events in the _internal index with the file=export parameter. This behavior is significant because it indicates a potential code injection attack, which could lead to remote code execution (RCE). If confirmed malicious, an attacker could gain unauthorized access, execute arbitrary commands, and potentially compromise the entire Splunk environment.
data_source: []
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -2,9 +2,9 @@ name: Splunk Enterprise KV Store Incorrect Authorization
id: 8f0e8380-a835-4f2b-b749-9ce119364df0
version: 9
creation_date: '2024-01-22'
modification_date: '2026-06-24'
modification_date: '2026-07-29'
author: Rod Soto, Eric McGinnis, Chase Franklin
status: deprecated
status: removed
type: Hunting
description: The following analytic detects unauthorized attempts to reload Splunk KV Store collections via the REST API. It leverages internal index logs to identify POST requests to the `/servicesNS/nobody/search/admin/collections-conf/_reload` endpoint, focusing on status codes starting with '2'. This activity is significant as it may indicate improper permission handling, potentially leading to unauthorized deletion of KV Store collections. If confirmed malicious, this could result in data loss or unauthorized data manipulation, impacting the integrity and availability of critical Splunk data.
data_source:
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -2,9 +2,9 @@ name: Splunk Information Disclosure on Account Login
id: 2bae5d19-6d1b-4db0-82ab-0af5ac5f836c
version: 8
creation_date: '2024-07-01'
modification_date: '2026-06-24'
modification_date: '2026-07-29'
author: Rod Soto
status: deprecated
status: removed
type: Hunting
description: This is a composed hunting search that looks for possible user enumeration attempts when SAML is enabled on a Splunk instance by capturing different responses from server.
data_source:
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -2,9 +2,9 @@ name: Splunk Path Traversal In Splunk App For Lookup File Edit
id: 8ed58987-738d-4917-9e44-b8ef6ab948a6
version: 9
creation_date: '2023-06-01'
modification_date: '2026-06-24'
modification_date: '2026-07-29'
author: Rod Soto, Eric McGinnis
status: deprecated
status: removed
type: Hunting
description: The following analytic identifies path traversal attempts in the Splunk App for Lookup File Editing. It detects specially crafted web requests targeting lookup files by analyzing the `uri_query` field in the `_internal` index. This activity is significant because it allows low-privilege users to read and write to restricted areas of the Splunk installation directory, potentially accessing sensitive files like password hashes. If confirmed malicious, this could lead to unauthorized access, data breaches, and further exploitation of the Splunk environment.
data_source:
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -2,9 +2,9 @@ name: Splunk RCE PDFgen Render
id: bc2b7437-0400-438b-9537-21ab5b7d2d53
version: 8
creation_date: '2024-07-01'
modification_date: '2026-06-24'
modification_date: '2026-07-29'
author: Rod Soto, Chase Franklin
status: deprecated
status: removed
type: TTP
description: This is a hunting search designed to find and discover exploitation attempts against Splunk pdfgen render endpoint which results in remote
data_source:
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -2,9 +2,9 @@ name: Windows Process Injection Of Wermgr to Known Browser
id: aec755a5-3a2c-4be0-ab34-6540e68644e9
version: 12
creation_date: '2022-10-28'
modification_date: '2026-06-29'
modification_date: '2026-07-29'
author: Teoderick Contreras, Splunk
status: deprecated
status: removed
type: TTP
description: The following analytic identifies the suspicious remote thread execution of the wermgr.exe process into known browsers such as firefox.exe, chrome.exe, and others. It leverages Sysmon EventCode 8 logs to detect this behavior by monitoring SourceImage and TargetImage fields. This activity is significant because it is indicative of Qakbot malware, which injects malicious code into legitimate processes to steal information. If confirmed malicious, this activity could allow attackers to execute arbitrary code, escalate privileges, and exfiltrate sensitive data from the compromised host.
data_source:
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -2,9 +2,9 @@ name: Windows Process Injection With Public Source Path
id: 492f09cf-5d60-4d87-99dd-0bc325532dda
version: 11
creation_date: '2022-09-05'
modification_date: '2026-06-29'
modification_date: '2026-07-29'
author: Teoderick Contreras, Splunk
status: deprecated
status: removed
type: Hunting
description: The following analytic detects a process from a non-standard file path on Windows attempting to create a remote thread in another process. This is identified using Sysmon EventCode 8, focusing on processes not originating from typical system directories. This behavior is significant as it often indicates process injection, a technique used by adversaries to evade detection or escalate privileges. If confirmed malicious, this activity could allow an attacker to execute arbitrary code within another process, potentially leading to unauthorized actions and further compromise of the system.
data_source:
Expand Down
Loading