What's new
ESCU version 6.6.0 was released on September 10, 2026.
Key highlights
ESCU 6.6.0 introduces 12 new behavioral analytics and updates 18 existing analytics, expanding coverage across Linux, macOS, and Windows environments. New detections identify suspicious shell execution from browsers, uncommon and rare network connections from LOLBAS binaries, Linux crontab enumeration, macOS AppleScript and user-prompt activity, Socat listeners and remote connections, Windows account manipulation and browser-content execution, and potential SCCM DLL planting and abnormal child-process activity.
The release also strengthens existing coverage for exploitation, execution, defense evasion, discovery, credential access, data destruction, and network activity. Two new lookups improve detection categorization and introduce mappings aligned with the NIST AI Risk Management Framework. In addition, two more detections are scheduled for removal in ESCU version 6.8.0, including the broad LOLBAS network-traffic detection and a Linux crontab detection whose search behavior does not match its name and description.
Here's a summary of the major changes:
-
Suspicious Network and Shell Activity: Introduced new analytics for browser-spawned Unix shells with external connections, uncommon and rare network connections from LOLBAS binaries, and suspicious Socat listener and remote TCP activity. This coverage helps defenders identify potential command execution, network tunneling, proxying, and command-and-control behavior originating from browsers or trusted system utilities.
-
macOS AppleScript and User Interaction: Added two macOS analytics covering AppleScript shell execution and compilation, as well as suspicious user prompts displayed through osascript. These detections improve visibility into script-based execution and potentially deceptive user interaction used to facilitate malicious activity on macOS endpoints.
-
Windows Account and Browser Activity: Expanded Windows coverage with detections for changes to built-in account names and execution of content copied from a browser. These analytics help identify account manipulation and suspicious execution workflows that may involve commands or payloads copied from web content.
-
SCCM Abuse Detection: Introduced two analytics focused on suspicious SCCM activity: DLL planting in the SMS Provider directory and abnormal child-process execution spawned by smsexec. This provides stronger visibility into potential abuse of SCCM components for execution, persistence, or lateral movement.
-
Cross-Platform Detection Refinements: Updated 18 analytics across Citrix, Windows, Linux, and macOS environments. The refinements improve coverage and detection fidelity for Citrix ADC exploitation, pipe-based execution, file and process activity, data destruction, Ghostscript exploitation, account creation, data chunking, network discovery, PowerShell, event-log manipulation, user and private-key discovery, credential access, and execution from suspicious paths.
-
Detection and AI Risk Classification: Together with NIST AI RMF Control Coverage dashboard, we've added the detection_subcategory_map and nist_ai_rmf_subcategories lookups to improve analytic categorization, detection metadata, and alignment with NIST AI Risk Management Framework subcategories.
New analytics
Updated analytics
Other updates
-
A new NIST AI RMF Control Coverage dashboard, available in alpha, maps AI-related ESCU detections and activity to the framework's Govern, Map, Measure, and Manage functions. This helps security teams identify coverage gaps and turn technical telemetry into clearer risk and governance insights.
-
Two new lookups detection_subcategory_map, nist_ai_rmf_subcategories were added to support the NIST AI RMF Dashboard.
-
A special thanks to @thegreatmhn and @munzzyy from the Security Content community for reporting bugs and proposing fixes that improved the quality and reliability of the security content.
List of detections scheduled for removal in ESCU version 6.8.0
Following is a list of detections removed from ESCU version 6.8.0:
| Deprecated Detection | Reason for deprecation | Replacement detection |
|---|---|---|
| Detection deprecated due to high false positive rates from certain LOLBAS binaries with common legitimate network behavior. This broad analytic is being split into more manageable anomaly analytics with separate process groups and common-port tuning. | LOLBAS Network Connection On Uncommon Port, LOLBAS Rare Network Connection | |
| Detection deprecated as its name and description are not matching the behavior of the search. The search is looking for crontab command with list parameter, not adding a new cron job. | Linux Crontab Enumeration |
Third party copyright credits
Some of the components included in Splunk Security Content are licensed under free or open source licenses. We wish to thank the contributors to those projects.
A complete listing of third-party software information for Splunk Security Content is available as a PDF file for download: Splunk Security Content version 6.5.0 third-party software credits.