What's new

ESCU version 6.4.0 was released on August 12, 2026.

Key highlights

ESCU 6.4.0 expands behavioral detection coverage across Linux and Windows environments, with a strong focus on activity associated with privilege escalation, persistence, execution, defense evasion, reconnaissance, and post-exploitation. New Linux analytics help surface suspicious bootloader and system file modification, shared-memory execution, reverse shells, UDEV and XDG persistence, privileged container activity, PostgreSQL and Redis abuse, Ghostscript exploitation, and multiple potential privilege-escalation paths. Windows coverage now includes suspicious network sniffing, PowerShell commands retrieved through DNS TXT records, reconnaissance activity, and unusual child processes of Consent.exe. This release also refines existing analytics for administrative SMB shares, network-share activity, user discovery, and registry-based defense evasion, while updating attacker tool and malware user-agent lookups to strengthen investigation context. Together, these updates give security teams broader visibility into suspicious activity across the attack lifecycle and help identify high-risk Linux and Windows behaviors that can blend into legitimate administrative operations.

Here's a summary of the major changes:

  • Linux Detection Coverage Expansion: Added broad new Linux behavioral coverage targeting privilege escalation, persistence, execution, defense evasion, reverse shells, container abuse, and suspicious service activity. New analytics identify behaviors including bootloader and system file modification, shared-memory execution, UDEV and XDG persistence, privileged container execution, PostgreSQL and Redis abuse, Ghostscript exploitation, shell history access, and multiple potential privilege-escalation paths, giving defenders stronger visibility into suspicious activity that can blend with legitimate Linux administration.

  • Windows Detection Coverage: Expanded Windows detection coverage with new analytics for network reconnaissance, suspicious PowerShell execution, and abnormal process behavior. New detections identify network sniffing tools, PowerShell commands retrieved through DNS TXT records, directory output piped to Findstr, and suspicious child processes of Consent.exe, helping security teams surface discovery, command execution, defense evasion, and other potentially malicious endpoint activity.

  • Detection Updates and Fixes: Refined six existing analytics covering administrative SMB shares, high-frequency file copying, network-share discovery, user discovery, and registry-based defense evasion, improving existing detection coverage and fidelity. This release also updates the attacker_tools and malware_user_agents lookups, providing refreshed context to support threat detection and investigation workflows.

New analytics

Other updates

  • A special thanks to @munzzyy @tid3na and @thegreatmhn from the Security Content community for reporting bugs and proposing fixes that improved the quality and reliability of the security content.

Breaking changes

  • As previously communicated in ESCU v6.2.0, ESCU v6.4.0 removes several detections. See the list of removed detections below for affected detections and recommended replacements. If you are currently using any deprecated detections, review the deprecated analytics in ESCU documentation for guidance on identifying, reviewing, and preserving deprecated detections before upgrading.

  • As communicated in ESCU v6.3.0, the Onboarding Assistant beta has now concluded and is no longer available in ESCU as we prepare to bring this capability into Detection Studio for a more fully integrated experience.

List of removed detections

Following is a list of detections removed from ESCU version 6.4.0:

Deprecated Detection Reason for deprecation Replacement detection

PowerShell - Connect To Internet With Hidden Window

Detection has been deprecated due to incorrect logic and bad performance.

Regsvr32 with Known Silent Switch Cmdline

Detection has been deprecated since its logic is already covered by another more improved detection.

Regsvr32 Silent and Install Param Dll Loading

Rundll32 CreateRemoteThread In Browser

Detection has been deprecated. The search is being replaced with a more generic detection that captures the behavior instead of relying on specific source processes.

Windows Uncommon Remote Thread Creation In Browser Process

Splunk App for Lookup File Editing RCE via User XSLT

Detection has been deprecated because it's too generic and does not provide the ability to detect the payload executed via this exploit.

Splunk Code Injection via custom dashboard leading to RCE

Detection has been deprecated. The affected Splunk software versions (8.1.12, 8.2.9, and 9.0.2) are no longer supported, having reached End of Life (EOL) between 2023 and 2024. Also, the logic is not perfectly capturing the malicious activity.

Splunk Enterprise KV Store Incorrect Authorization

Detection has been deprecated. The affected Splunk software versions (below 9.0.8 and 9.1.3) are no longer supported, having reached End of Life (EOL), and the logic is not accurately detecting the malicious activity.

Splunk Information Disclosure on Account Login

Detection has been deprecated. The logic is not accurately detecting the malicious activity.

Splunk Path Traversal In Splunk App For Lookup File Edit

Detection has been deprecated. The logic is not accurately detecting the malicious activity.

Splunk RCE PDFgen Render

Detection has been deprecated. The metadata along with the search are not accurately capturing the malicious activity.

Windows Process Injection Of Wermgr to Known Browser

Detection has been deprecated. The search is being replaced with a more generic detection that captures the behavior instead of relying on specific source processes.

Windows Uncommon Remote Thread Creation In Browser Process

Windows Process Injection With Public Source Path

Detection has been deprecated. The search is not helpful for the user to implement nor use, as it will generate too many false positives.

Third party copyright credits

Some of the components included in Splunk Security Content are licensed under free or open source licenses. We wish to thank the contributors to those projects.

A complete listing of third-party software information for Splunk Security Content is available as a PDF file for download: Splunk Security Content version 6.4.0 third-party software credits.