What's new

ESCU version 6.2.0 was released on July 8, 2026.

Key highlights

ESCU version 6.2.0 significantly expands protection for enterprise generative AI with a new AWS Bedrock Claude analytic story and seven new detections. Customers gain visibility into prompt injection and jailbreak attempts, sensitive data exposure, hostile or unusually large prompts, excessive token consumption, cross-region inference abuse, and high-risk filesystem or execution-tool activity. This helps organizations adopt Claude-powered applications with stronger security oversight, detect attempts to bypass AI safety controls, protect sensitive information, and identify potentially costly or unauthorized use. Beyond AI, the release strengthens protection against Linux privilege escalation, Phantom Stealer credential theft, and stealthy Windows process injection. Improvements to Sysmon Event ID 8 mappings, noisy-rule consolidation, and PowerShell finding messages also increase signal quality and reduce triage friction, helping SOC teams investigate faster, prioritize meaningful threats, and expand coverage without adding equivalent analyst workload.

Here's a summary of the major changes:

  • Linux Dirty Frag Privilege Escalation (CVE-2026-43284 & CVE-2026-43500): Added a new detection for the Dirty Frag Linux kernel privilege escalation vulnerabilities, identifying the exploit's characteristic high-frequency splice() syscall activity followed by execution of a setuid binary within the same audit session. This analytic provides early visibility into attempts to corrupt the kernel page cache and escalate privileges to root through abuse of the IPsec ESP or RxRPC subsystems.

  • Phantom Stealer: Expanded detection coverage for this Windows information stealer that targets browser credentials, FTP/SSH clients, cryptocurrency wallets, and other sensitive application data. This release adds a new detection for unauthorized access to WinSCP security configuration folders while tagging and enhancing existing analytics covering browser credential theft, PowerShell abuse, process injection, persistence, suspicious browser behavior, and data exfiltration, improving visibility into credential harvesting and post-compromise activity commonly associated with modern infostealers.

  • Sysmon Event ID 8 Detection Improvements: Refined detection coverage built on Sysmon Event ID 8 (CreateRemoteThread) by aligning the data source with native Sysmon field mappings, updating analytics to use the correct raw field names, and reducing false positives through rule consolidation and deprecation of noisy content. This release also introduces a new detection — Windows Uncommon Remote Thread Creation in Browser Process — strengthening visibility into process injection techniques while improving the accuracy and maintainability of existing CreateRemoteThread analytics.

  • AWS Bedrock Claude AI Security Analytics: Introduced a new analytic story for AWS Bedrock Claude focused on detecting prompt injection, jailbreak attempts, and suspicious AI interactions targeting enterprise generative AI workloads. This release adds analytics to identify cross-region inference abuse, excessive token consumption, high-risk filesystem and execution tool invocation, hostile prompt sentiment, prompt injection attempts, sensitive data exposure in prompts, and unusually large prompt submissions, providing security teams with visibility into attempts to bypass AI safety controls, manipulate model behavior, or misuse Claude-powered applications.

New analytics

Other updates

PowerShell ScriptBlock Analytics Refinement: Updated the finding messages for detections leveraging the PowerShell ScriptBlock data source to improve readability by omitting oversized ScriptBlockText fields, while also converting these analytics to Anomaly detections and refining their descriptions for clearer triage.

Breaking changes

A new set of detections has been deprecated. For details on detections scheduled for removal in ESCU version v6.4.0, see the List of Detections Scheduled for Removal.

Third party copyright credits

Some of the components included in Splunk Security Content are licensed under free or open source licenses. We wish to thank the contributors to those projects.

A complete listing of third-party software information for Splunk Security Content is available as a PDF file for download: Splunk Security Content version 6.2.0 third-party software credits.