What's new

ESCU version 6.3.0 was released on July 29, 2026.

Key highlights

ESCU 6.3.0 expands detection coverage for modern malware campaigns, Linux privilege escalation, and network-aware threat detection, helping security teams identify sophisticated attacks earlier in the intrusion lifecycle. New coverage for the Starland RAT campaign (UAT-11795) improves visibility into multi-stage attacks that combine ClickFix social engineering, trojanized installers, in-memory PowerShell implants, credential theft, and resilient command-and-control techniques. By correlating activity across the entire infection chain rather than isolated events, SOC teams can more quickly identify compromised systems, understand attacker progression, and accelerate containment before malware establishes long-term persistence.

This release also strengthens Linux security by introducing new analytics for privilege escalation, AppArmor bypass, and kernel-level exploitation techniques that help uncover attempts to evade security controls and gain elevated execution on Linux systems. In addition, ESCU 6.3.0 continues to advance the Splunk + Cisco Better Together strategy by expanding support for Cisco Network Visibility Module (NVM) telemetry across a broad set of existing ESCU detections, enabling them to take advantage of the latest NVM telemetry enhancements. Customers using Cisco NVM can now leverage existing detections for behaviors such as suspicious downloads, ransomware activity, malicious PowerShell execution, local LLM usage, file-sharing abuse, and command-and-control communications without requiring separate content, ensuring that the same high-fidelity ESCU analytics operate consistently across both endpoint and network telemetry. Together, these updates strengthen cross-layer visibility, improve detection fidelity, and help SOC teams investigate attacker activity across modern enterprise environments.

Here's a summary of the major changes:

  • Starland RAT Campaign (UAT-11795): Expanded detection coverage for the Starland RAT campaign attributed to UAT-11795, a financially motivated threat actor leveraging ClickFix social engineering and trojanized installers to deploy Starland RAT, the WLDR Agent PowerShell memory implant, and supporting malware including CastleStealer and Remcos RAT. This release tags a broad set of existing analytics covering PowerShell abuse, malicious script execution, persistence, reconnaissance, suspicious downloads, registry modifications, and Telegram-based C2 communications, improving visibility into the multi-stage infection chain, in-memory execution, credential theft, and resilient command-and-control techniques used throughout the campaign.
  • Linux Exploitation Detection Expansion Expanded Linux detection coverage with new analytics focused on local privilege escalation, defense evasion, and kernel-level exploitation techniques, improving visibility into attempts to bypass security controls, abuse elevated execution paths, and exploit low-level system components commonly targeted by advanced adversaries.

Updated analytics

Other updates

  • A special thanks to @thegreatmhn and @tid3na from the Security Content community for reporting bugs and proposing fixes that improved the quality and reliability of the security content.

  • We have also removed the Threat Activity by Snort IDs dashboard as it has been found to have a vulnerability and the searches in dashboard do not work due to issues with the Cisco Security Cloud TA. We will consider adding this dashboard in a future release when the TA can parse the data correctly.

  • The beta for Onboarding Assistant experience will conclude in the upcoming ESCU v6.4 release. The feedback we received during the beta has been invaluable, and we plan to bring this capability into Detection Studio later this year as a productized, more fully integrated experience.

Third party copyright credits

Some of the components included in Splunk Security Content are licensed under free or open source licenses. We wish to thank the contributors to those projects.

A complete listing of third-party software information for Splunk Security Content is available as a PDF file for download: Splunk Security Content version 6.3.0 third-party software credits.