Deprecated analytics in ESCU

Some detections and analytic stories from Splunk Enterprise Security Content Update (ESCU) versions 5.4.0 and higher are marked for deprecation and can be deleted from the ESCU app. Deprecating these detections might impact your environment if these detections are enabled in your environment.

Dashboard to assist tracking deprecated detections

Use the Deprecation Assistant dashboard for a comprehensive overview of all deprecated ESCU detections that are enabled within your Splunk environment. Monitoring this dashboard helps to ensure that your security posture is robust by identifying outdated content and making timely updates or replacements to maintain optimal threat detection capabilities.

Potential impact of deprecated detections

  • Deprecated detections can be removed from the following location: DA-ESS-ContentUpdate/default/savedsearches.conf.
  • Edited detections might stop functioning if the base detection is removed and if the search parameter was not modified or saved in your local configuration. Edited detections with saved search parameters can continue to function.
  • The Job Scheduler might display errors with the message: Alert is invalid
  • Detections might disappear from the Content Management page.
  • When a detection is removed from DA-ESS-ContentUpdate/default/savedsearches.conf, partial configurations in DA-ESS-ContentUpdate/local/savedsearches.conf might be orphaned.
  • The Correlation Search Editor might fail to load deprecated detections.
  • The Job Scheduler might report errors for deprecated detections even if they appear to be enabled in the user interface.

Required actions if you are using deprecated detections

If you are using deprecated detections, perform the following actions:

  • Review all the deprecated detections that are enabled in your environment using the Deprecation Assistant dashboard.
  • Ensure you have a full copy of the detection including all knowledge objects such as lookups and macros by cloning it in your Splunk environment before installing ESCU versions 5.2.0 and higher.

Risk mitigation: Clone and preserve deprecated detections

Follow these steps to clone deprecated detections before upgrading the app to avoid losing important updates and ensure the smooth management of deprecated detections:

  • Identify the deprecated detections by reviewing the release notes.
  • Identify the list of deprecated detections that are enabled in your environment using the Deprecation Assistant dashboard.
  • Create a clone of the deprecated detections under a new name and ensure that these cloned detections do not conflict with future updates of the ESCU app.
  • Modify the titles and other app metadata such as adding notes to the description to explain its history and the reason for retention.
  • Identify and create a backup of the lookups and macros that are used by the deprecated detection that is turned on. This applies especially for the filter macros that are denoted by the suffix of `_filter` and are typically used at the end of a search as missing macros prevent searches from running.
  • Adjust permissions if the deprecated detection is shared across the app or globally and ensure that the cloned search retains the appropriate sharing permissions.
  • Verify that the cloned searches work correctly before upgrading the app.

Note: Replacements for detections are provided as necessary. However, a replacement for every detection might not be available.

List of removed detections in ESCU version 6.2.0

No detections were removed from ESCU 6.2.0:

List of detections scheduled for removal in ESCU version 6.4.0

Following is a list of detections scheduled for removal in ESCU version 6.4.0:

Deprecated Detection Reason for deprecation Replacement detection

PowerShell - Connect To Internet With Hidden Window

Detection has been deprecated due to incorrect logic and bad performance.

Regsvr32 with Known Silent Switch Cmdline

Detection has been deprecated since its logic is already covered by another more improved detection.

Regsvr32 Silent and Install Param Dll Loading

Rundll32 CreateRemoteThread In Browser

Detection has been deprecated. The search is being replaced with a more generic detection that captures the behavior instead of relying on specific source processes.

Windows Uncommon Remote Thread Creation In Browser Process

Splunk App for Lookup File Editing RCE via User XSLT

Detection has been deprecated because it's too generic and does not provide the ability to detect the payload executed via this exploit.

Splunk Code Injection via custom dashboard leading to RCE

Detection has been deprecated. The affected Splunk software versions (8.1.12, 8.2.9, and 9.0.2) are no longer supported, having reached End of Life (EOL) between 2023 and 2024. Also, the logic is not perfectly capturing the malicious activity.

Splunk Enterprise KV Store Incorrect Authorization

Detection has been deprecated. The affected Splunk software versions (below 9.0.8 and 9.1.3) are no longer supported, having reached End of Life (EOL), and the logic is not accurately detecting the malicious activity.

Splunk Information Disclosure on Account Login

Detection has been deprecated. The logic is not accurately detecting the malicious activity.

Splunk Path Traversal In Splunk App For Lookup File Edit

Detection has been deprecated. The logic is not accurately detecting the malicious activity.

Splunk RCE PDFgen Render

Detection has been deprecated. The metadata along with the search are not accurately capturing the malicious activity.

Windows Process Injection Of Wermgr to Known Browser

Detection has been deprecated. The search is being replaced with a more generic detection that captures the behavior instead of relying on specific source processes.

Windows Uncommon Remote Thread Creation In Browser Process

Windows Process Injection With Public Source Path

Detection has been deprecated. The search is not helpful for the user to implement nor use, as it will generate too many false positives.