What's new
ESCU version 6.4.0 was released on August 12, 2026.
Key highlights
Here's a summary of the major changes:
-
Linux Detection Coverage Expansion: Added broad new Linux behavioral coverage targeting privilege escalation, persistence, execution, defense evasion, reverse shells, container abuse, and suspicious service activity. New analytics identify behaviors including bootloader and system file modification, shared-memory execution, UDEV and XDG persistence, privileged container execution, PostgreSQL and Redis abuse, Ghostscript exploitation, shell history access, and multiple potential privilege-escalation paths, giving defenders stronger visibility into suspicious activity that can blend with legitimate Linux administration.
-
Windows Detection Coverage: Expanded Windows detection coverage with new analytics for network reconnaissance, suspicious PowerShell execution, and abnormal process behavior. New detections identify network sniffing tools, PowerShell commands retrieved through DNS TXT records, directory output piped to Findstr, and suspicious child processes of Consent.exe, helping security teams surface discovery, command execution, defense evasion, and other potentially malicious endpoint activity.
-
Detection Updates and Fixes: Refined six existing analytics covering administrative SMB shares, high-frequency file copying, network-share discovery, user discovery, and registry-based defense evasion, improving existing detection coverage and fidelity. This release also updates the attacker_tools and malware_user_agents lookups, providing refreshed context to support threat detection and investigation workflows.
New analytics
Updated analytics
Other updates
-
Both the attacker_tools and malware_user_agents lookups have been updated with refreshed content to improve detection and investigation context.
-
A special thanks to @munzzyy @tid3na and @thegreatmhn from the Security Content community for reporting bugs and proposing fixes that improved the quality and reliability of the security content.
Breaking changes
-
As previously communicated in ESCU v6.2.0, ESCU v6.4.0 removes several detections. See the list of removed detections below for affected detections and recommended replacements. If you are currently using any deprecated detections, review the deprecated analytics in ESCU documentation for guidance on identifying, reviewing, and preserving deprecated detections before upgrading.
-
As communicated in ESCU v6.3.0, the Onboarding Assistant beta has now concluded and is no longer available in ESCU as we prepare to bring this capability into Detection Studio for a more fully integrated experience.
List of removed detections
Following is a list of detections removed from ESCU version 6.4.0:
| Deprecated Detection | Reason for deprecation | Replacement detection |
|---|---|---|
| Detection has been deprecated due to incorrect logic and bad performance. | ||
| Detection has been deprecated since its logic is already covered by another more improved detection. | ||
| Detection has been deprecated. The search is being replaced with a more generic detection that captures the behavior instead of relying on specific source processes. | ||
| Detection has been deprecated because it's too generic and does not provide the ability to detect the payload executed via this exploit. | ||
| Detection has been deprecated. The affected Splunk software versions (8.1.12, 8.2.9, and 9.0.2) are no longer supported, having reached End of Life (EOL) between 2023 and 2024. Also, the logic is not perfectly capturing the malicious activity. | ||
| Detection has been deprecated. The affected Splunk software versions (below 9.0.8 and 9.1.3) are no longer supported, having reached End of Life (EOL), and the logic is not accurately detecting the malicious activity. | ||
| Detection has been deprecated. The logic is not accurately detecting the malicious activity. | ||
| Detection has been deprecated. The logic is not accurately detecting the malicious activity. | ||
| Detection has been deprecated. The metadata along with the search are not accurately capturing the malicious activity. | ||
| Detection has been deprecated. The search is being replaced with a more generic detection that captures the behavior instead of relying on specific source processes. | ||
| Detection has been deprecated. The search is not helpful for the user to implement nor use, as it will generate too many false positives. |
Third party copyright credits
Some of the components included in Splunk Security Content are licensed under free or open source licenses. We wish to thank the contributors to those projects.
A complete listing of third-party software information for Splunk Security Content is available as a PDF file for download: Splunk Security Content version 6.4.0 third-party software credits.