Splunk Security Content for Threat Detection & Response: September Recap
Security Splunk Threat Research TeamIn September, the Splunk Threat Research Team (STRT) had 2 releases of new security content via the Enterprise Security Content Update (ESCU) app (v6.6.0 and v6.7.0) With these releases, there are 19 new analytics, and 48 updated analytics, now available in Splunk Enterprise Security via the ESCU application update process.
Content highlights include:
- Detection and AI Risk Classification: New NIST AI RMF Control Coverage dashboard (Alpha) gives security teams an operational view of how shadow AI detections and activity from common GenAI platforms align with the NIST AI Risk Management Framework’s Govern, Map, Measure, and Manage functions.
- Suspicious Network and Shell Activity Detections: New analytics for browser-spawned Unix shells with external connections, uncommon and rare network connections from LOLBAS binaries, and suspicious Socat listener and remote TCP activity.
- New macOS AppleScript and Osascript Detections: Introduced MacOS AppleScript Shell Execution and Compilation, MacOS Osascript Displaying Suspicious User Prompt, MacOS Osascript Executing Interactive Shell and MacOS Osascript Executing JavaScript Code With ObjC analytics covering AppleScript shell execution and compilation, as well as suspicious user prompts displayed through osascript. These detections improve visibility into script-based execution and potentially deceptive user interaction used to facilitate malicious activity on macOS endpoints.
- Added SCCM Abuse Coverage: Introduced two analytics (Windows SCCM Adsource DLL Was Planted In SMS Provider Directory and Windows SCCM Smsexec Spawned a Suspicious Child Process) focused on suspicious SCCM activity: DLL planting in the SMS Provider directory and abnormal child-process execution spawned by smsexec. This provides stronger visibility into potential abuse of SCCM components for execution, persistence, or lateral movement.
- Improved Windows ClickFix and LOLBin coverage: Added (Windows Finger.exe Connecting to a Remote Host, Windows For Loop Usage Within Cmd.exe To Execute Commands, Windows Node.exe Executing JS Script In Immediate Folder, and Windows Process Accessing IronLanguages Repository On GitHub) covering remote connections through finger.exe, command execution through for /f loops, JavaScript execution by node.exe from unusual directories, and processes accessing the IronLanguages repository on GitHub. These detections improve visibility into ClickFix-related execution chains, payload retrieval, scripting abuse, and the use of trusted utilities for malicious activity.
- Improved credential-access and process-injection detections: Updated detections leveraging the process access data source, covering LSASS access and termination, credential dumping, Winlogon token manipulation, Rubeus ticket export activity, handle duplication, and process injection. These changes improve analytic consistency, investigation context, and visibility into credential-access and defense-evasion techniques.
- Cross-Platform Detection Refinements: Updated analytics across Windows, Linux, and macOS environments. The refinements improve coverage and detection fidelity for Citrix ADC exploitation, pipe-based execution, file and process activity, data destruction, Ghostscript exploitation, account creation, data chunking, network discovery, PowerShell, event-log manipulation, user and private-key discovery, credential access, and execution from suspicious paths.
- Detection quality and metadata improvements: Updated analytics across application, endpoint, network, and web content. Changes include improved SPL logic, additional threat objects and references, better event context, and tuning intended to improve detection fidelity and reduce noise.
Title
Related Articles
Filter
Category
Blog Limit
3
Category
security
Sort Category Shuffle Order
true
Related Articles

The Agentic SOC Workforce: Defending at Machine Speed in the AI Era
Why trusted autonomy is becoming the operating model for modern security operations.

Detecting Copy Fail (CVE-2026-31431)– Phenomenal Power, Ity Bity Script
The Splunk Threat Research Team analyzes the VIP Keylogger malware to help improve your detection and threat-hunting strategies.
