What's new
ESCU version 6.7.0 was released on September 23, 2026.
Key highlights
ESCU version 6.7.0 helps security teams identify post-exploitation activity that can be difficult to distinguish from legitimate administration on macOS and Windows. New analytics focus on suspicious osascript behavior, from interactive shell launches and JXA use of the Objective-C bridge to long-running network connections. Additional Windows coverage targets execution patterns linked to ClickFix and living-off-the-land techniques. Support for Cisco Network Visibility Module telemetry brings network activity into the investigation, helping analysts connect osascript processes with outbound communications when endpoint evidence alone does not tell the full story.
Alongside the new coverage, this release improves the investigative context provided by existing detections across endpoint, application, network, and web data. More consistent process-access handling, threat objects, references, and event details make it easier to understand and validate findings involving credential dumping, process injection, platform tampering, and exploitation. Together, these changes provide broader cross-platform visibility and clearer signals, helping analysts spend less time assembling context and more time deciding how to respond.
Here's a summary of the latest updates:
-
Expanded macOS AppleScript and osascript coverage: Added three new macOS analytics that identify osascript executing interactive shells, JavaScript for Automation code using the Objective-C bridge, and long-lived network connections. This improves visibility into script-based execution, remote access, command-and-control activity, and post-exploitation behavior on macOS endpoints.
-
Windows ClickFix and LOLBin detection coverage: Added four new Windows analytics covering remote connections through finger.exe, command execution through for /f loops, JavaScript execution by node.exe from unusual directories, and processes accessing the IronLanguages repository on GitHub. Together, these detections improve visibility into ClickFix-related execution chains, payload retrieval, scripting abuse, and the use of trusted utilities for malicious activity.
-
Improved credential-access and process-injection detection: Updated multiple detections leveraging the process access data source, covering LSASS access and termination, credential dumping, Winlogon token manipulation, Rubeus ticket export activity, handle duplication, and process injection. These changes improve analytic consistency, investigation context, and visibility into credential-access and defense-evasion techniques.
-
Detection quality and metadata improvements: Updated multiple analytics across application, endpoint, network, and web content. Changes include improved SPL logic, additional threat objects and references, better event context, and tuning intended to improve detection fidelity and reduce noise. Updates include coverage for ESXi tampering and VM termination, event-log clearing, Kerberos coercion, internal network scanning, and suspicious HTTP activity.
New analytics
Updated analytics
Other updates
A special thanks to @0x4D6174696E from the Security Content community for reporting a bug in on piece of content that improved the quality and reliability of the security content.
List of detections scheduled for removal in ESCU version 6.10.0
Following is a list of detections removed from ESCU version 6.10.0:
| Deprecated Detection | Reason for deprecation | Replacement detection |
|---|---|---|
| Detection is deprecated as it is targeting a method of persistence that has been disabled in MacOS for years. As well, the detection has been set to experimental since 2020. | None | |
| Detection is deprecated as it is already covered by the" Windows Process Injection into Commonly Abused Processes" detection. | ||
| Detection is deprecated as it is inaccurate. WinRing0x64.sys is not related to XMRIG. It is a driver that is used to access the hardware ring0. | , |
Third party copyright credits
Some of the components included in Splunk Security Content are licensed under free or open source licenses. We wish to thank the contributors to those projects.
A complete listing of third-party software information for Splunk Security Content is available as a PDF file for download: Splunk Security Content third-party software credits.