What's new
ESCU version 6.5.0 was released on August 27, 2026.
Key highlights
ESCU 6.5.0 introduces 13 new behavioral analytics and two new analytic stories focused on malicious Python package installation and Vidar Stealer. New Python coverage detects suspicious network activity during package builds and persistence through .pth files, site hooks, and PYTHONPATH manipulation, helping protect developer systems and build environments from software supply-chain threats. Vidar coverage improves visibility into browser credential theft, sensitive cloud profile access, and information-stealing activity that could lead to account takeover or data exfiltration.
The release also expands the RoguePlanet analytic story with detections for Windows Defender race-condition exploitation, alternate data stream abuse, suspicious Defender component activity, Windows Error Reporting manipulation, phantom DLL creation, and privilege escalation to SYSTEM. Additional analytics identify Windows Filtering Platform rules used to disrupt EDR communications, while 46 updated analytics strengthen coverage across Windows, Linux, macOS, ESXi, and AWS Bedrock environments. Together, these updates improve visibility into credential access, persistence, privilege escalation, defense evasion, reconnaissance, AI infrastructure abuse, and post-exploitation activity, while preparing legacy F5 TMUI detection content for retirement.
-
🐍 Malicious Python Package Installation: Introduced a new analytic story with four detections focused on abuse of the Python package installation lifecycle. New coverage identifies unexpected network connections during package builds, creation of executable .pth configuration files and Python site hooks, and manipulation of the PYTHONPATH environment variable. These analytics help defenders uncover supply-chain compromises that execute code during installation or establish persistence across subsequent Python sessions, improving visibility into threats targeting developer workstations and build environments.
-
🕵️ Vidar Stealer Detection Coverage: Introduced a new analytic story for the Vidar information stealer, combining a new detection for uncommon processes reading sensitive cloud profile files with existing analytics covering unauthorized browser credential-store access and suspicious process behavior. This coverage helps identify attempts to collect saved credentials, cookies, Azure CLI profile metadata, and other information that could support account takeover, cloud reconnaissance, or data exfiltration, giving defenders an earlier opportunity to contain compromised Windows endpoints.
-
🪐 RoguePlanet and ShieldBreak Privilege Escalation: Expanded the RoguePlanet analytic story with six new detections targeting Windows Defender race-condition exploitation and related ShieldBreak techniques. The new analytics identify alternate data streams created through local shares, suspicious use of Defender components, threat events referencing kernel object paths, manually staged Windows Error Reports, phantom DLL creation, and Windows Error Reporting processes spawning SYSTEM-integrity children. This provides stronger visibility into Defender scanning abuse, DLL hijacking, and attempts to escalate from a low-privileged context to SYSTEM.
-
🛡️ EDR Defense Evasion Detection: Added two behavioral analytics for EDRSilencer-style tampering through the Windows Filtering Platform. The detections identify custom outbound filters and filtering rules designed to block security processes from communicating with their management infrastructure, helping defenders recognize attempts to suppress endpoint telemetry or disrupt response capabilities before attackers continue post-compromise activity.
-
🎯 Cross-Platform Detection Refinements: Updated 46 analytics across Windows, Linux, macOS, ESXi, and AWS Bedrock to improve detection fidelity and behavioral coverage. The refinements strengthen visibility into AI infrastructure abuse, credential access, browser data theft, process injection, persistence, privilege escalation, reconnaissance, security-tool tampering, and destructive activity, helping security teams investigate suspicious behavior across a broader range of endpoint, virtualization, and cloud telemetry.
-
🗓️ Legacy F5 Detection Retirement: Scheduled the experimental detection for F5 TMUI remote code execution (CVE-2020-5902) for removal in a future release. The analytic targets an older platform version that is no longer supported by F5 and has remained experimental since 2020, allowing the content library to prioritize relevant, supportable detection coverage.
New analytic stories
New analytics
Updated analytics
Other updates
-
RoguePlanet story has been updated with refreshed content to improve detection and investigation context.
-
A special thanks to @ProfessorBrausewein, @Samuel25-hub, @fe-brain, and @thegreatmhn from the Security Content community for reporting bugs and proposing fixes that improved the quality and reliability of the security content.
List of detections scheduled for removal in ESCU version 6.8.0
Following is a list of detections removed from ESCU version 6.8.0:
| Deprecated Detection | Reason for deprecation | Replacement detection |
|---|---|---|
| Detection deprecated as it is targeting a 6 year old CVE that is no longer relevant, since the OS version targeted is no longer supported by F5. As well, the detection has been set to experimental since 2020. | None |
Third party copyright credits
Some of the components included in Splunk Security Content are licensed under free or open source licenses. We wish to thank the contributors to those projects.
A complete listing of third-party software information for Splunk Security Content is available as a PDF file for download: Splunk Security Content version 6.5.0 third-party software credits.