updating lookups from latest mapping

This commit is contained in:
Bhavin Patel
2025-03-13 18:12:45 -07:00
parent 97395878e9
commit bebfe2e13e
2 changed files with 204 additions and 0 deletions
+195
View File
@@ -0,0 +1,195 @@
Name,Content Type,Deprecated in Version,Reason,Migration Guide,Replacement Content
ESCU - ASL AWS Excessive Security Scanning - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
ESCU - AWS Cloud Provisioning From Previously Unseen Region - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/5aba1860-9617-4af9-b19d-aecac16fe4f2
ESCU - First time seen command line argument - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
ESCU - Windows connhost exe started forcefully - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
ESCU - Detect Mimikatz Using Loaded Images - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
ESCU - Kubernetes Azure detect sensitive role access - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
ESCU - Web Fraud - Anomalous User Clickspeed - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
ESCU - EC2 Instance Started With Previously Unseen Instance Type - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/c6ddbf53-9715-49f3-bb4c-fb2e8a309cda
ESCU - EC2 Instance Started With Previously Unseen AMI - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/bc24922d-987c-4645-b288-f8c73ec194c4
ESCU - Domain Group Discovery With Net - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/c5c8e0f3-147a-43da-bf04-4cfaec27dc44
ESCU - Kubernetes AWS detect sensitive role access - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
ESCU - Winword Spawning Windows Script Host - Rule,Detection,5.2.0,"The following analytics was deprecated in favour of a more generic approach. Where instead of creating specific analytic for every potentially suspicious child of an office product. We group them by threat level.
This would ease management and false positives tuning.",https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/55d8741c-fa32-4692-8109-410304961eb8
ESCU - Winword Spawning PowerShell - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/55d8741c-fa32-4692-8109-410304961eb8
ESCU - Attempted Credential Dump From Registry via Reg exe - Rule,Detection,5.2.0,"This analytic had some overlap with another one, hence the deprecation. It was replaced by 8bbb7d58-b360-11eb-ba21-acde48001122 / Windows Sensitive Registry Hive Dump Via CommandLine",https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/5aaff29d-0cce-405b-9ee8-5d06b49d045e
ESCU - Detect processes used for System Network Configuration Discovery - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/3f0b95e3-3195-46ac-bea3-84fb59e7fac5
ESCU - Execution of File With Spaces Before Extension - Rule,Detection,5.2.0,Updated to a new detection name,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/b06a555e-dce0-417d-a2eb-28a5d8d66ef7
ESCU - EC2 Instance Started In Previously Unseen Region - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/fa4089e2-50e3-40f7-8469-d2cc1564ca59
ESCU - Office Document Spawned Child Process To Download - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/f02b64b8-cbea-4f75-bf77-7a05111566b1
ESCU - Detect new API calls from user roles - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/2181ad1f-1e73-4d0c-9780-e8880482a08f
ESCU - Cmdline Tool Not Executed In CMD Shell - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/2afa393f-b88d-41b7-9793-623c93a2dfde
ESCU - Linux Auditd Find Private Keys - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/892eb674-3344-4143-8e52-4775b1daf3f1
ESCU - Detect AWS API Activities From Unapproved Accounts - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
ESCU - Monitor DNS For Brand Abuse - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
ESCU - Kubernetes GCP detect sensitive object access - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
ESCU - Kubernetes Azure scan fingerprint - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
ESCU - ASL AWS Password Policy Changes - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
ESCU - O365 Suspicious Admin Email Forwarding - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/0b6bc75c-05d1-4101-9fc3-97e706168f24
ESCU - AWS Cloud Provisioning From Previously Unseen City - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/e7ecc5e0-88df-48b9-91af-51104c68f02f
ESCU - Kubernetes AWS detect service accounts forbidden failure access - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
ESCU - Osquery pack - ColdRoot detection - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
ESCU - Windows Modify Registry Reg Restore - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/a17af481-e2ad-494c-9da6-afb4d243a019
ESCU - Kubernetes GCP detect most active service accounts by pod - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
ESCU - Scheduled tasks used in BadRabbit ransomware - Rule,Detection,5.2.0,Updated to a new detection name,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/d5af132c-7c17-439c-9d31-13d55340f36c
ESCU - Suspicious Rundll32 Rename - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
ESCU - Remote System Discovery with Net - Rule,Detection,5.2.0,"This analytic was focusing on 2 separate and unrelated type of threats or actions. It was split into other analytics, namely:
Windows Network Share Interaction With Net / 4dc3951f-b3f8-4f46-b412-76a483f72277
Windows Sensitive Group Discovery With Net / a23a0e20-0b1b-4a07-82e5-ec5f70811e7a",https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/4dc3951f-b3f8-4f46-b412-76a483f72277
ESCU - Remote System Discovery with Net - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/d9eb7cda-5622-4722-bc88-7f2442f4b5af
ESCU - DNS Query Requests Resolved by Unauthorized DNS Servers - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
ESCU - Suspicious Changes to File Associations - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
ESCU - GCP Detect high risk permissions by resource and account - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
ESCU - Office Product Writing cab or inf - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/dbdd251e-dd45-4ec9-a555-f5e151391746
ESCU - Identify New User Accounts - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
ESCU - Office Product Spawn CMD Process - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/55d8741c-fa32-4692-8109-410304961eb8
ESCU - Windows DLL Search Order Hijacking Hunt - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/79c7d1fc-64c7-91be-a616-ccda752efe81
ESCU - ASL AWS CreateAccessKey - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/81a9f2fe-1697-473c-af1d-086b0d8b63c8
ESCU - Okta ThreatInsight Login Failure with High Unknown users - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
ESCU - Detect Spike in Security Group Activity - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/d4dfb7f3-7a37-498a-b5df-f19334e871af
ESCU - Office Product Spawning BITSAdmin - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/55d8741c-fa32-4692-8109-410304961eb8
ESCU - Create local admin accounts using net exe - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/2c568c34-bb57-4b43-9d75-19c605b98e70
ESCU - Abnormally High AWS Instances Terminated by User - MLTK - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
ESCU - Windows Office Product Spawning MSDT - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/a3148fad-3734-4b7f-9a71-62f08d39fab1
ESCU - Detect Spike in AWS API Activity - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
ESCU - Office Product Spawning Windows Script Host - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/55d8741c-fa32-4692-8109-410304961eb8
ESCU - Prohibited Software On Endpoint - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/a51bfe1a-94f0-48cc-b4e4-16a110145893
ESCU - AWS Cloud Provisioning From Previously Unseen Country - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/94994255-3acf-4213-9b3f-0494df03bb31
ESCU - Detect Critical Alerts from Security Tools - Rule,Detection,5.2.0,"As discussed internally, this analytic was too generic for an analyst to do anything with it. It was deprecated in favor of the more specific approach provided by analytics such as Microsoft Defender ATP Alerts and Microsoft Defender Incident Alerts. Going forward analytics from leveraging alerts from vendors will have their specific analytics.",https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/38f034ed-1598-46c8-95e8-14edf05fdf5d
ESCU - Detect Critical Alerts from Security Tools - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/13435b55-afd8-46d4-9045-7d5457f430a5
ESCU - Excel Spawning PowerShell - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/55d8741c-fa32-4692-8109-410304961eb8
ESCU - Office Application Spawn rundll32 process - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/55d8741c-fa32-4692-8109-410304961eb8
ESCU - Excessive Usage Of Net App - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/355ba810-0a20-4215-8485-9ce3f87f2e38
ESCU - Elevated Group Discovery With Net - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/d9eb7cda-5622-4722-bc88-7f2442f4b5af
ESCU - Local Account Discovery with Net - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/7742987e-88c1-476b-a626-a869e088ab72
ESCU - Windows Command Shell Fetch Env Variables - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/aec157f4-8783-4584-aca6-754c4dc7fba9
ESCU - Suspicious Email - UBA Anomaly - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
ESCU - Detect web traffic to dynamic domain providers - Rule,Detection,5.2.0,Updated to use a different log source,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/a1e761ac-1344-4dbd-88b2-3f34c912d359
ESCU - Okta Failed SSO Attempts - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/5f661629-9750-4cb9-897c-1f05d6db8727
ESCU - Kubernetes AWS detect RBAC authorization by account - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
ESCU - Kubernetes Azure detect service accounts forbidden failure access - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
ESCU - Remote Registry Key modifications - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
ESCU - O365 Suspicious User Email Forwarding - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/0b6bc75c-05d1-4101-9fc3-97e706168f24
ESCU - Office Product Spawning MSHTA - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/55d8741c-fa32-4692-8109-410304961eb8
ESCU - Kubernetes AWS detect most active service accounts by pod - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
ESCU - Correlation by Repository and Risk - Rule,Detection,5.2.0,Detections updated to use the datamodel,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/161bc0ca-4651-4c13-9c27-27770660cf67
ESCU - Kubernetes Azure detect RBAC authorization by account - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
ESCU - Clients Connecting to Multiple DNS Servers - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
ESCU - Excessive Service Stop Attempt - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/8f3a614f-6b98-4f7d-82dd-d0df38452a8b
ESCU - Multiple Okta Users With Invalid Credentials From The Same IP - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/de365ffa-42f5-46b5-b43f-fa72290b8218
ESCU - Suspicious writes to System Volume Information - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
ESCU - Detect new user AWS Console Login - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/bc91a8cd-35e7-4bb2-6140-e756cc46fd71
ESCU - Domain Account Discovery With Net App - Rule,Detection,5.2.0,"This analytic was a TTP that looked only for commands that tries to query info about the users via net user /do. This had a couple of issues, such as triggering on creation of users via the /add flag etc..
It was deprecated in favor of a more tighter approach in 5d0d4830-0133-11ec-bae3-acde48001122",https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/7742987e-88c1-476b-a626-a869e088ab72
ESCU - Detection of DNS Tunnels - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
ESCU - Detect DNS requests to Phishing Sites leveraging EvilGinx2 - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
ESCU - Office Document Creating Schedule Task - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/d7297cfa-1f04-4714-bfbe-3679e0666959
ESCU - Okta Account Locked Out - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/a511426e-184f-4de6-8711-cfd2af29d1e1
ESCU - Unsuccessful Netbackup backups - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
ESCU - Detect Mimikatz Via PowerShell And EventCode 4703 - Rule,Detection,5.2.0,Updated to a new detection name,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/8148c29c-c952-11eb-9255-acde48001122
ESCU - Winword Spawning Cmd - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/55d8741c-fa32-4692-8109-410304961eb8
ESCU - GCP Kubernetes cluster scan detection - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/f9cadf4e-df22-4f4e-a08f-9d3344c2165d
ESCU - Kubernetes GCP detect suspicious kubectl calls - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
ESCU - gcp detect oauth token abuse - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
ESCU - Correlation by User and Risk - Rule,Detection,5.2.0,Detections updated to use the datamodel,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/161bc0ca-4651-4c13-9c27-27770660cf67
ESCU - Processes created by netsh - Rule,Detection,5.2.0,Updated to a new detection name,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/b89919ed-fe5f-492c-b139-95dbb162040e
ESCU - Office Product Spawning Wmic - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/55d8741c-fa32-4692-8109-410304961eb8
ESCU - Extraction of Registry Hives - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/5aaff29d-0cce-405b-9ee8-5d06b49d045e
ESCU - Attempt To Stop Security Service - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/9ed27cea-4e27-4eff-b2c6-aac9e78a7517
ESCU - Windows MSIExec With Network Connections - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/b0fd38c7-f71a-43a2-870e-f3ca06bcdd99
ESCU - Windows Query Registry Reg Save - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/466379bc-0f47-476c-8202-16ef38112e0d
ESCU - Cloud Network Access Control List Deleted - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/ada0f478-84a8-4641-a3f1-d82362d6fd75
ESCU - O365 Suspicious Rights Delegation - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/2246c142-a678-45f8-8546-aaed7e0efd30
ESCU - Abnormally High AWS Instances Launched by User - MLTK - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
ESCU - Reg exe used to hide files directories via registry keys - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
ESCU - Detect Long DNS TXT Record Response - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
ESCU - Password Policy Discovery with Net - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/e52f7865-be78-46bf-b7ed-150fbe447613
ESCU - AWS Cloud Provisioning From Previously Unseen IP Address - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/f86a8ec9-b042-45eb-92f4-e9ed1d781078
ESCU - Network Connection Discovery With Net - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/86a5b949-679b-4197-8d4c-9c180a818c45
ESCU - Kubernetes Azure detect suspicious kubectl calls - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
ESCU - Kubernetes GCP detect sensitive role access - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
ESCU - Detect Webshell Exploit Behavior - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/2d4470ef-7158-4b47-b68b-1f7f16382156
ESCU - DNS record changed - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
ESCU - Unsigned Image Loaded by LSASS - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
ESCU - Detect USB device insertion - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
ESCU - Windows Network Share Interaction With Net - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/e51fbdb0-0be0-474f-92ea-d289f71a695e
ESCU - Account Discovery With Net App - Rule,Detection,5.2.0,"This analytic was a TTP that focused on unrelated things and called account discovery. Since there were other detection that overlapped with it. I choose to deprecate it, and replace it with an updated version of 339805ce-ac30-11eb-b87d-acde48001122 / Windows Excessive Usage Of Net App.",https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/355ba810-0a20-4215-8485-9ce3f87f2e38
ESCU - Change Default File Association - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/7d1f031f-f1c9-43be-8b0b-c4e3e8a8928a
ESCU - Windows Lateral Tool Transfer RemCom - Rule,Detection,5.2.0,Updated to a new detection name,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/7e3d68db-ea4d-419b-adbd-e14a525ecf09
ESCU - Office Document Executing Macro Code - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/7cfec906-2697-43f7-898b-83634a051d9a
ESCU - Okta Account Lockout Events - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/a511426e-184f-4de6-8711-cfd2af29d1e1
ESCU - Abnormally High AWS Instances Launched by User - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/f2361e9f-3928-496c-a556-120cd4223a65
ESCU - EC2 Instance Modified With Previously Unseen User - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/2181ad1f-1e73-4d0c-9780-e8880482a08f
ESCU - Windows Valid Account With Never Expires Password - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/11f93009-8083-43fd-82a7-821fcbdc8342
ESCU - Windows hosts file modification - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
ESCU - MSHTML Module Load in Office Product - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/4cc015c9-687c-40d2-adcc-46350f66e10c
ESCU - Abnormally High AWS Instances Terminated by User - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/ef629fc9-1583-4590-b62a-f2247fbf7bbf
ESCU - Web Fraud - Account Harvesting - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
ESCU - Office Spawning Control - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/081c485d-ac8d-4bee-ad4c-525772fead4d
ESCU - Detect Activity Related to Pass the Hash Attacks - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
ESCU - Deleting Of Net Users - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/b0b6fd2c-8953-4d1b-8f7b-56075ea6ab3e
ESCU - Suspicious File Write - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
ESCU - AWS EKS Kubernetes cluster sensitive object access - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/40a064c1-4ec1-4381-9e35-61192ba8ef82
ESCU - Spectre and Meltdown Vulnerable Systems - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
ESCU - EC2 Instance Started With Previously Unseen User - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/37a0ec8d-827e-4d6d-8025-cedf31f3a149
ESCU - Office Product Spawning CertUtil - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/55d8741c-fa32-4692-8109-410304961eb8
ESCU - Kubernetes GCP detect RBAC authorizations by account - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
ESCU - Office Application Drop Executable - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/7ac0fced-9eae-4381-a748-90dcd1aa9393
ESCU - Kubernetes Azure active service accounts by pod namespace - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
ESCU - Kubernetes Azure pod scan fingerprint - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
ESCU - Detect Spike in Network ACL Activity - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/0840ddf1-8c89-46ff-b730-c8d6722478c0
ESCU - Suspicious Powershell Command-Line Arguments - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/c4db14d9-7909-48b4-a054-aa14d89dbb19
ESCU - Office Application Spawn Regsvr32 process - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/55d8741c-fa32-4692-8109-410304961eb8
ESCU - Detect API activity from users without MFA - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/a520b1fe-cc9e-4f56-b762-18354594c52f
ESCU - Kubernetes Azure detect sensitive object access - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
ESCU - Web Fraud - Password Sharing Across Accounts - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
ESCU - Disabling Net User Account - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/b0359e05-c87b-4354-83d8-aee0d890243f
ESCU - GCP Detect accounts with high risk roles by project - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
ESCU - Kubernetes GCP detect service accounts forbidden failure access - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
ESCU - Extended Period Without Successful Netbackup Backups - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
ESCU - Office Product Spawning Rundll32 with no DLL - Rule,Detection,5.2.0,Renamed and updated logic,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/f28e787e-69ca-480e-9f98-ab970e6d4bcc
ESCU - Okta ThreatInsight Suspected PasswordSpray Attack - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/140504ae-5fe2-4d65-b2bc-a211813fbca6
ESCU - Net Localgroup Discovery - Rule,Detection,5.2.0,Both of these analytics were deprecated in favor of c5c8e0f3-147a-43da-bf04-4cfaec27dc44 / Windows Group Discovery Via Net,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/c5c8e0f3-147a-43da-bf04-4cfaec27dc44
ESCU - Uncommon Processes On Endpoint - Rule,Detection,5.2.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/a51bfe1a-94f0-48cc-b4e4-16a110145893
ESCU - Dump LSASS via procdump Rename - Rule,Detection,5.2.0,Updated to a new detection name,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/3742ebfe-64c2-11eb-ae93-0242ac130002
ESCU - Okta Two or More Rejected Okta Pushes - Rule,Detection,5.2.0,Detections updated to use the new search logic and field names due to the TA update,https://research.splunk.com/migration_guide/,https://research.splunk.com/detections/826dbaae-a1e6-4c8c-b384-d16898956e73
ESCU - Excel Spawning Windows Script Host - Rule,Detection,5.3.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
ESCU - GitHub Actions Disable Security Workflow - Rule,Detection,5.3.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
ESCU - Github Commit Changes In Master - Rule,Detection,5.3.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
ESCU - Github Commit In Develop - Rule,Detection,5.3.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
ESCU - GitHub Dependabot Alert - Rule,Detection,5.3.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
ESCU - GitHub Pull Request from Unknown User - Rule,Detection,5.3.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
ESCU - Known Services Killed by Ransomware - Rule,Detection,5.3.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
ESCU - Remote Desktop Network Bruteforce - Rule,Detection,5.3.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
ESCU - Suspicious Driver Loaded Path - Rule,Detection,5.3.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
ESCU - Suspicious Event Log Service Behavior - Rule,Detection,5.3.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
ESCU - Suspicious Process File Path - Rule,Detection,5.3.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
ESCU - Windows Service Stop Via Net and SC Application - Rule,Detection,5.3.0,Detection deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
ESCU - Add Prohibited Processes to Enterprise Security,Baseline,5.2.0,"All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.",https://research.splunk.com/migration_guide/,
ESCU - Baseline of API Calls per User ARN,Baseline,5.2.0,"All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.",https://research.splunk.com/migration_guide/,
ESCU - Baseline of Excessive AWS Instances Launched by User - MLTK,Baseline,5.2.0,"All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.",https://research.splunk.com/migration_guide/,
ESCU - Baseline of Excessive AWS Instances Terminated by User - MLTK,Baseline,5.2.0,"All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.",https://research.splunk.com/migration_guide/,
ESCU - Previously seen API call per user roles in CloudTrail,Baseline,5.2.0,"All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.",https://research.splunk.com/migration_guide/,
ESCU - Previously Seen AWS Provisioning Activity Sources,Baseline,5.2.0,"All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.",https://research.splunk.com/migration_guide/,
ESCU - Previously Seen EC2 AMIs,Baseline,5.2.0,"All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.",https://research.splunk.com/migration_guide/,
ESCU - Previously Seen EC2 Instance Types,Baseline,5.2.0,"All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.",https://research.splunk.com/migration_guide/,
ESCU - Previously Seen EC2 Launches By User,Baseline,5.2.0,"All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.",https://research.splunk.com/migration_guide/,
ESCU - Previously seen users in CloudTrail,Baseline,5.2.0,"All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.",https://research.splunk.com/migration_guide/,
ESCU - Update previously seen users in CloudTrail,Baseline,5.2.0,"All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.",https://research.splunk.com/migration_guide/,
AWS Cryptomining,Story,5.2.0,Analytic Story deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
AWS Suspicious Provisioning Activities,Story,5.2.0,Analytic Story deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
Common Phishing Frameworks,Story,5.2.0,Analytic Story deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
Container Implantation Monitoring and Investigation,Story,5.2.0,Analytic Story deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
Host Redirection,Story,5.2.0,Analytic Story deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
Kubernetes Sensitive Role Activity,Story,5.2.0,Analytic Story deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
Lateral Movement,Story,5.2.0,Analytic Story deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
Monitor Backup Solution,Story,5.2.0,Analytic Story deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
Monitor for Unauthorized Software,Story,5.2.0,Analytic Story deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
Office 365 Detections,Story,5.2.0,Analytic Story deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
Spectre And Meltdown Vulnerabilities,Story,5.2.0,Analytic Story deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
Suspicious AWS EC2 Activities,Story,5.2.0,Analytic Story deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
Unusual AWS EC2 Modifications,Story,5.2.0,Analytic Story deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
Web Fraud Detection,Story,5.2.0,Analytic Story deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
Nexus APT Threat Activity,Story,5.4.0,Analytic Story deprecated as it no longer effectively identifies the intended malicious activity,https://research.splunk.com/migration_guide/,
1 Name Content Type Deprecated in Version Reason Migration Guide Replacement Content
2 ESCU - ASL AWS Excessive Security Scanning - Rule Detection 5.2.0 Detection deprecated as it no longer effectively identifies the intended malicious activity https://research.splunk.com/migration_guide/
3 ESCU - AWS Cloud Provisioning From Previously Unseen Region - Rule Detection 5.2.0 Detections updated to use the new search logic and field names due to the TA update https://research.splunk.com/migration_guide/ https://research.splunk.com/detections/5aba1860-9617-4af9-b19d-aecac16fe4f2
4 ESCU - First time seen command line argument - Rule Detection 5.2.0 Detection deprecated as it no longer effectively identifies the intended malicious activity https://research.splunk.com/migration_guide/
5 ESCU - Windows connhost exe started forcefully - Rule Detection 5.2.0 Detection deprecated as it no longer effectively identifies the intended malicious activity https://research.splunk.com/migration_guide/
6 ESCU - Detect Mimikatz Using Loaded Images - Rule Detection 5.2.0 Detection deprecated as it no longer effectively identifies the intended malicious activity https://research.splunk.com/migration_guide/
7 ESCU - Kubernetes Azure detect sensitive role access - Rule Detection 5.2.0 Detection deprecated as it no longer effectively identifies the intended malicious activity https://research.splunk.com/migration_guide/
8 ESCU - Web Fraud - Anomalous User Clickspeed - Rule Detection 5.2.0 Detection deprecated as it no longer effectively identifies the intended malicious activity https://research.splunk.com/migration_guide/
9 ESCU - EC2 Instance Started With Previously Unseen Instance Type - Rule Detection 5.2.0 Detections updated to use the new search logic and field names due to the TA update https://research.splunk.com/migration_guide/ https://research.splunk.com/detections/c6ddbf53-9715-49f3-bb4c-fb2e8a309cda
10 ESCU - EC2 Instance Started With Previously Unseen AMI - Rule Detection 5.2.0 Detections updated to use the new search logic and field names due to the TA update https://research.splunk.com/migration_guide/ https://research.splunk.com/detections/bc24922d-987c-4645-b288-f8c73ec194c4
11 ESCU - Domain Group Discovery With Net - Rule Detection 5.2.0 Detection deprecated as it no longer effectively identifies the intended malicious activity https://research.splunk.com/migration_guide/ https://research.splunk.com/detections/c5c8e0f3-147a-43da-bf04-4cfaec27dc44
12 ESCU - Kubernetes AWS detect sensitive role access - Rule Detection 5.2.0 Detection deprecated as it no longer effectively identifies the intended malicious activity https://research.splunk.com/migration_guide/
13 ESCU - Winword Spawning Windows Script Host - Rule Detection 5.2.0 The following analytics was deprecated in favour of a more generic approach. Where instead of creating specific analytic for every potentially suspicious child of an office product. We group them by threat level. This would ease management and false positives tuning. https://research.splunk.com/migration_guide/ https://research.splunk.com/detections/55d8741c-fa32-4692-8109-410304961eb8
14 ESCU - Winword Spawning PowerShell - Rule Detection 5.2.0 Detection deprecated as it no longer effectively identifies the intended malicious activity https://research.splunk.com/migration_guide/ https://research.splunk.com/detections/55d8741c-fa32-4692-8109-410304961eb8
15 ESCU - Attempted Credential Dump From Registry via Reg exe - Rule Detection 5.2.0 This analytic had some overlap with another one, hence the deprecation. It was replaced by 8bbb7d58-b360-11eb-ba21-acde48001122 / Windows Sensitive Registry Hive Dump Via CommandLine https://research.splunk.com/migration_guide/ https://research.splunk.com/detections/5aaff29d-0cce-405b-9ee8-5d06b49d045e
16 ESCU - Detect processes used for System Network Configuration Discovery - Rule Detection 5.2.0 Renamed and updated logic https://research.splunk.com/migration_guide/ https://research.splunk.com/detections/3f0b95e3-3195-46ac-bea3-84fb59e7fac5
17 ESCU - Execution of File With Spaces Before Extension - Rule Detection 5.2.0 Updated to a new detection name https://research.splunk.com/migration_guide/ https://research.splunk.com/detections/b06a555e-dce0-417d-a2eb-28a5d8d66ef7
18 ESCU - EC2 Instance Started In Previously Unseen Region - Rule Detection 5.2.0 Detections updated to use the new search logic and field names due to the TA update https://research.splunk.com/migration_guide/ https://research.splunk.com/detections/fa4089e2-50e3-40f7-8469-d2cc1564ca59
19 ESCU - Office Document Spawned Child Process To Download - Rule Detection 5.2.0 Renamed and updated logic https://research.splunk.com/migration_guide/ https://research.splunk.com/detections/f02b64b8-cbea-4f75-bf77-7a05111566b1
20 ESCU - Detect new API calls from user roles - Rule Detection 5.2.0 Detections updated to use the new search logic and field names due to the TA update https://research.splunk.com/migration_guide/ https://research.splunk.com/detections/2181ad1f-1e73-4d0c-9780-e8880482a08f
21 ESCU - Cmdline Tool Not Executed In CMD Shell - Rule Detection 5.2.0 Renamed and updated logic https://research.splunk.com/migration_guide/ https://research.splunk.com/detections/2afa393f-b88d-41b7-9793-623c93a2dfde
22 ESCU - Linux Auditd Find Private Keys - Rule Detection 5.2.0 Renamed and updated logic https://research.splunk.com/migration_guide/ https://research.splunk.com/detections/892eb674-3344-4143-8e52-4775b1daf3f1
23 ESCU - Detect AWS API Activities From Unapproved Accounts - Rule Detection 5.2.0 Detection deprecated as it no longer effectively identifies the intended malicious activity https://research.splunk.com/migration_guide/
24 ESCU - Monitor DNS For Brand Abuse - Rule Detection 5.2.0 Detection deprecated as it no longer effectively identifies the intended malicious activity https://research.splunk.com/migration_guide/
25 ESCU - Kubernetes GCP detect sensitive object access - Rule Detection 5.2.0 Detection deprecated as it no longer effectively identifies the intended malicious activity https://research.splunk.com/migration_guide/
26 ESCU - Kubernetes Azure scan fingerprint - Rule Detection 5.2.0 Detection deprecated as it no longer effectively identifies the intended malicious activity https://research.splunk.com/migration_guide/
27 ESCU - ASL AWS Password Policy Changes - Rule Detection 5.2.0 Detection deprecated as it no longer effectively identifies the intended malicious activity https://research.splunk.com/migration_guide/
28 ESCU - O365 Suspicious Admin Email Forwarding - Rule Detection 5.2.0 Detections updated to use the new search logic and field names due to the TA update https://research.splunk.com/migration_guide/ https://research.splunk.com/detections/0b6bc75c-05d1-4101-9fc3-97e706168f24
29 ESCU - AWS Cloud Provisioning From Previously Unseen City - Rule Detection 5.2.0 Detections updated to use the new search logic and field names due to the TA update https://research.splunk.com/migration_guide/ https://research.splunk.com/detections/e7ecc5e0-88df-48b9-91af-51104c68f02f
30 ESCU - Kubernetes AWS detect service accounts forbidden failure access - Rule Detection 5.2.0 Detection deprecated as it no longer effectively identifies the intended malicious activity https://research.splunk.com/migration_guide/
31 ESCU - Osquery pack - ColdRoot detection - Rule Detection 5.2.0 Detection deprecated as it no longer effectively identifies the intended malicious activity https://research.splunk.com/migration_guide/
32 ESCU - Windows Modify Registry Reg Restore - Rule Detection 5.2.0 Renamed and updated logic https://research.splunk.com/migration_guide/ https://research.splunk.com/detections/a17af481-e2ad-494c-9da6-afb4d243a019
33 ESCU - Kubernetes GCP detect most active service accounts by pod - Rule Detection 5.2.0 Detection deprecated as it no longer effectively identifies the intended malicious activity https://research.splunk.com/migration_guide/
34 ESCU - Scheduled tasks used in BadRabbit ransomware - Rule Detection 5.2.0 Updated to a new detection name https://research.splunk.com/migration_guide/ https://research.splunk.com/detections/d5af132c-7c17-439c-9d31-13d55340f36c
35 ESCU - Suspicious Rundll32 Rename - Rule Detection 5.2.0 Detection deprecated as it no longer effectively identifies the intended malicious activity https://research.splunk.com/migration_guide/
36 ESCU - Remote System Discovery with Net - Rule Detection 5.2.0 This analytic was focusing on 2 separate and unrelated type of threats or actions. It was split into other analytics, namely: Windows Network Share Interaction With Net / 4dc3951f-b3f8-4f46-b412-76a483f72277 Windows Sensitive Group Discovery With Net / a23a0e20-0b1b-4a07-82e5-ec5f70811e7a https://research.splunk.com/migration_guide/ https://research.splunk.com/detections/4dc3951f-b3f8-4f46-b412-76a483f72277
37 ESCU - Remote System Discovery with Net - Rule Detection 5.2.0 Detection deprecated as it no longer effectively identifies the intended malicious activity https://research.splunk.com/migration_guide/ https://research.splunk.com/detections/d9eb7cda-5622-4722-bc88-7f2442f4b5af
38 ESCU - DNS Query Requests Resolved by Unauthorized DNS Servers - Rule Detection 5.2.0 Detection deprecated as it no longer effectively identifies the intended malicious activity https://research.splunk.com/migration_guide/
39 ESCU - Suspicious Changes to File Associations - Rule Detection 5.2.0 Detection deprecated as it no longer effectively identifies the intended malicious activity https://research.splunk.com/migration_guide/
40 ESCU - GCP Detect high risk permissions by resource and account - Rule Detection 5.2.0 Detection deprecated as it no longer effectively identifies the intended malicious activity https://research.splunk.com/migration_guide/
41 ESCU - Office Product Writing cab or inf - Rule Detection 5.2.0 Renamed and updated logic https://research.splunk.com/migration_guide/ https://research.splunk.com/detections/dbdd251e-dd45-4ec9-a555-f5e151391746
42 ESCU - Identify New User Accounts - Rule Detection 5.2.0 Detection deprecated as it no longer effectively identifies the intended malicious activity https://research.splunk.com/migration_guide/
43 ESCU - Office Product Spawn CMD Process - Rule Detection 5.2.0 Detection deprecated as it no longer effectively identifies the intended malicious activity https://research.splunk.com/migration_guide/ https://research.splunk.com/detections/55d8741c-fa32-4692-8109-410304961eb8
44 ESCU - Windows DLL Search Order Hijacking Hunt - Rule Detection 5.2.0 Detections updated to use the new search logic and field names due to the TA update https://research.splunk.com/migration_guide/ https://research.splunk.com/detections/79c7d1fc-64c7-91be-a616-ccda752efe81
45 ESCU - ASL AWS CreateAccessKey - Rule Detection 5.2.0 Detections updated to use the new search logic and field names due to the TA update https://research.splunk.com/migration_guide/ https://research.splunk.com/detections/81a9f2fe-1697-473c-af1d-086b0d8b63c8
46 ESCU - Okta ThreatInsight Login Failure with High Unknown users - Rule Detection 5.2.0 Detection deprecated as it no longer effectively identifies the intended malicious activity https://research.splunk.com/migration_guide/
47 ESCU - Detect Spike in Security Group Activity - Rule Detection 5.2.0 Detections updated to use the new search logic and field names due to the TA update https://research.splunk.com/migration_guide/ https://research.splunk.com/detections/d4dfb7f3-7a37-498a-b5df-f19334e871af
48 ESCU - Office Product Spawning BITSAdmin - Rule Detection 5.2.0 Detection deprecated as it no longer effectively identifies the intended malicious activity https://research.splunk.com/migration_guide/ https://research.splunk.com/detections/55d8741c-fa32-4692-8109-410304961eb8
49 ESCU - Create local admin accounts using net exe - Rule Detection 5.2.0 Renamed and updated logic https://research.splunk.com/migration_guide/ https://research.splunk.com/detections/2c568c34-bb57-4b43-9d75-19c605b98e70
50 ESCU - Abnormally High AWS Instances Terminated by User - MLTK - Rule Detection 5.2.0 Detection deprecated as it no longer effectively identifies the intended malicious activity https://research.splunk.com/migration_guide/
51 ESCU - Windows Office Product Spawning MSDT - Rule Detection 5.2.0 Renamed and updated logic https://research.splunk.com/migration_guide/ https://research.splunk.com/detections/a3148fad-3734-4b7f-9a71-62f08d39fab1
52 ESCU - Detect Spike in AWS API Activity - Rule Detection 5.2.0 Detection deprecated as it no longer effectively identifies the intended malicious activity https://research.splunk.com/migration_guide/
53 ESCU - Office Product Spawning Windows Script Host - Rule Detection 5.2.0 Detection deprecated as it no longer effectively identifies the intended malicious activity https://research.splunk.com/migration_guide/ https://research.splunk.com/detections/55d8741c-fa32-4692-8109-410304961eb8
54 ESCU - Prohibited Software On Endpoint - Rule Detection 5.2.0 Detection deprecated as it no longer effectively identifies the intended malicious activity https://research.splunk.com/migration_guide/ https://research.splunk.com/detections/a51bfe1a-94f0-48cc-b4e4-16a110145893
55 ESCU - AWS Cloud Provisioning From Previously Unseen Country - Rule Detection 5.2.0 Detections updated to use the new search logic and field names due to the TA update https://research.splunk.com/migration_guide/ https://research.splunk.com/detections/94994255-3acf-4213-9b3f-0494df03bb31
56 ESCU - Detect Critical Alerts from Security Tools - Rule Detection 5.2.0 As discussed internally, this analytic was too generic for an analyst to do anything with it. It was deprecated in favor of the more specific approach provided by analytics such as Microsoft Defender ATP Alerts and Microsoft Defender Incident Alerts. Going forward analytics from leveraging alerts from vendors will have their specific analytics. https://research.splunk.com/migration_guide/ https://research.splunk.com/detections/38f034ed-1598-46c8-95e8-14edf05fdf5d
57 ESCU - Detect Critical Alerts from Security Tools - Rule Detection 5.2.0 Detection deprecated as it no longer effectively identifies the intended malicious activity https://research.splunk.com/migration_guide/ https://research.splunk.com/detections/13435b55-afd8-46d4-9045-7d5457f430a5
58 ESCU - Excel Spawning PowerShell - Rule Detection 5.2.0 Detection deprecated as it no longer effectively identifies the intended malicious activity https://research.splunk.com/migration_guide/ https://research.splunk.com/detections/55d8741c-fa32-4692-8109-410304961eb8
59 ESCU - Office Application Spawn rundll32 process - Rule Detection 5.2.0 Detection deprecated as it no longer effectively identifies the intended malicious activity https://research.splunk.com/migration_guide/ https://research.splunk.com/detections/55d8741c-fa32-4692-8109-410304961eb8
60 ESCU - Excessive Usage Of Net App - Rule Detection 5.2.0 Renamed and updated logic https://research.splunk.com/migration_guide/ https://research.splunk.com/detections/355ba810-0a20-4215-8485-9ce3f87f2e38
61 ESCU - Elevated Group Discovery With Net - Rule Detection 5.2.0 Renamed and updated logic https://research.splunk.com/migration_guide/ https://research.splunk.com/detections/d9eb7cda-5622-4722-bc88-7f2442f4b5af
62 ESCU - Local Account Discovery with Net - Rule Detection 5.2.0 Renamed and updated logic https://research.splunk.com/migration_guide/ https://research.splunk.com/detections/7742987e-88c1-476b-a626-a869e088ab72
63 ESCU - Windows Command Shell Fetch Env Variables - Rule Detection 5.2.0 Renamed and updated logic https://research.splunk.com/migration_guide/ https://research.splunk.com/detections/aec157f4-8783-4584-aca6-754c4dc7fba9
64 ESCU - Suspicious Email - UBA Anomaly - Rule Detection 5.2.0 Detection deprecated as it no longer effectively identifies the intended malicious activity https://research.splunk.com/migration_guide/
65 ESCU - Detect web traffic to dynamic domain providers - Rule Detection 5.2.0 Updated to use a different log source https://research.splunk.com/migration_guide/ https://research.splunk.com/detections/a1e761ac-1344-4dbd-88b2-3f34c912d359
66 ESCU - Okta Failed SSO Attempts - Rule Detection 5.2.0 Detections updated to use the new search logic and field names due to the TA update https://research.splunk.com/migration_guide/ https://research.splunk.com/detections/5f661629-9750-4cb9-897c-1f05d6db8727
67 ESCU - Kubernetes AWS detect RBAC authorization by account - Rule Detection 5.2.0 Detection deprecated as it no longer effectively identifies the intended malicious activity https://research.splunk.com/migration_guide/
68 ESCU - Kubernetes Azure detect service accounts forbidden failure access - Rule Detection 5.2.0 Detection deprecated as it no longer effectively identifies the intended malicious activity https://research.splunk.com/migration_guide/
69 ESCU - Remote Registry Key modifications - Rule Detection 5.2.0 Detection deprecated as it no longer effectively identifies the intended malicious activity https://research.splunk.com/migration_guide/
70 ESCU - O365 Suspicious User Email Forwarding - Rule Detection 5.2.0 Detections updated to use the new search logic and field names due to the TA update https://research.splunk.com/migration_guide/ https://research.splunk.com/detections/0b6bc75c-05d1-4101-9fc3-97e706168f24
71 ESCU - Office Product Spawning MSHTA - Rule Detection 5.2.0 Detection deprecated as it no longer effectively identifies the intended malicious activity https://research.splunk.com/migration_guide/ https://research.splunk.com/detections/55d8741c-fa32-4692-8109-410304961eb8
72 ESCU - Kubernetes AWS detect most active service accounts by pod - Rule Detection 5.2.0 Detection deprecated as it no longer effectively identifies the intended malicious activity https://research.splunk.com/migration_guide/
73 ESCU - Correlation by Repository and Risk - Rule Detection 5.2.0 Detections updated to use the datamodel https://research.splunk.com/migration_guide/ https://research.splunk.com/detections/161bc0ca-4651-4c13-9c27-27770660cf67
74 ESCU - Kubernetes Azure detect RBAC authorization by account - Rule Detection 5.2.0 Detection deprecated as it no longer effectively identifies the intended malicious activity https://research.splunk.com/migration_guide/
75 ESCU - Clients Connecting to Multiple DNS Servers - Rule Detection 5.2.0 Detection deprecated as it no longer effectively identifies the intended malicious activity https://research.splunk.com/migration_guide/
76 ESCU - Excessive Service Stop Attempt - Rule Detection 5.2.0 Renamed and updated logic https://research.splunk.com/migration_guide/ https://research.splunk.com/detections/8f3a614f-6b98-4f7d-82dd-d0df38452a8b
77 ESCU - Multiple Okta Users With Invalid Credentials From The Same IP - Rule Detection 5.2.0 Detections updated to use the new search logic and field names due to the TA update https://research.splunk.com/migration_guide/ https://research.splunk.com/detections/de365ffa-42f5-46b5-b43f-fa72290b8218
78 ESCU - Suspicious writes to System Volume Information - Rule Detection 5.2.0 Detection deprecated as it no longer effectively identifies the intended malicious activity https://research.splunk.com/migration_guide/
79 ESCU - Detect new user AWS Console Login - Rule Detection 5.2.0 Detections updated to use the new search logic and field names due to the TA update https://research.splunk.com/migration_guide/ https://research.splunk.com/detections/bc91a8cd-35e7-4bb2-6140-e756cc46fd71
80 ESCU - Domain Account Discovery With Net App - Rule Detection 5.2.0 This analytic was a TTP that looked only for commands that tries to query info about the users via net user /do. This had a couple of issues, such as triggering on creation of users via the /add flag etc.. It was deprecated in favor of a more tighter approach in 5d0d4830-0133-11ec-bae3-acde48001122 https://research.splunk.com/migration_guide/ https://research.splunk.com/detections/7742987e-88c1-476b-a626-a869e088ab72
81 ESCU - Detection of DNS Tunnels - Rule Detection 5.2.0 Detection deprecated as it no longer effectively identifies the intended malicious activity https://research.splunk.com/migration_guide/
82 ESCU - Detect DNS requests to Phishing Sites leveraging EvilGinx2 - Rule Detection 5.2.0 Detection deprecated as it no longer effectively identifies the intended malicious activity https://research.splunk.com/migration_guide/
83 ESCU - Office Document Creating Schedule Task - Rule Detection 5.2.0 Renamed and updated logic https://research.splunk.com/migration_guide/ https://research.splunk.com/detections/d7297cfa-1f04-4714-bfbe-3679e0666959
84 ESCU - Okta Account Locked Out - Rule Detection 5.2.0 Detections updated to use the new search logic and field names due to the TA update https://research.splunk.com/migration_guide/ https://research.splunk.com/detections/a511426e-184f-4de6-8711-cfd2af29d1e1
85 ESCU - Unsuccessful Netbackup backups - Rule Detection 5.2.0 Detection deprecated as it no longer effectively identifies the intended malicious activity https://research.splunk.com/migration_guide/
86 ESCU - Detect Mimikatz Via PowerShell And EventCode 4703 - Rule Detection 5.2.0 Updated to a new detection name https://research.splunk.com/migration_guide/ https://research.splunk.com/detections/8148c29c-c952-11eb-9255-acde48001122
87 ESCU - Winword Spawning Cmd - Rule Detection 5.2.0 Detection deprecated as it no longer effectively identifies the intended malicious activity https://research.splunk.com/migration_guide/ https://research.splunk.com/detections/55d8741c-fa32-4692-8109-410304961eb8
88 ESCU - GCP Kubernetes cluster scan detection - Rule Detection 5.2.0 Detections updated to use the new search logic and field names due to the TA update https://research.splunk.com/migration_guide/ https://research.splunk.com/detections/f9cadf4e-df22-4f4e-a08f-9d3344c2165d
89 ESCU - Kubernetes GCP detect suspicious kubectl calls - Rule Detection 5.2.0 Detection deprecated as it no longer effectively identifies the intended malicious activity https://research.splunk.com/migration_guide/
90 ESCU - gcp detect oauth token abuse - Rule Detection 5.2.0 Detection deprecated as it no longer effectively identifies the intended malicious activity https://research.splunk.com/migration_guide/
91 ESCU - Correlation by User and Risk - Rule Detection 5.2.0 Detections updated to use the datamodel https://research.splunk.com/migration_guide/ https://research.splunk.com/detections/161bc0ca-4651-4c13-9c27-27770660cf67
92 ESCU - Processes created by netsh - Rule Detection 5.2.0 Updated to a new detection name https://research.splunk.com/migration_guide/ https://research.splunk.com/detections/b89919ed-fe5f-492c-b139-95dbb162040e
93 ESCU - Office Product Spawning Wmic - Rule Detection 5.2.0 Detection deprecated as it no longer effectively identifies the intended malicious activity https://research.splunk.com/migration_guide/ https://research.splunk.com/detections/55d8741c-fa32-4692-8109-410304961eb8
94 ESCU - Extraction of Registry Hives - Rule Detection 5.2.0 Renamed and updated logic https://research.splunk.com/migration_guide/ https://research.splunk.com/detections/5aaff29d-0cce-405b-9ee8-5d06b49d045e
95 ESCU - Attempt To Stop Security Service - Rule Detection 5.2.0 Renamed and updated logic https://research.splunk.com/migration_guide/ https://research.splunk.com/detections/9ed27cea-4e27-4eff-b2c6-aac9e78a7517
96 ESCU - Windows MSIExec With Network Connections - Rule Detection 5.2.0 Renamed and updated logic https://research.splunk.com/migration_guide/ https://research.splunk.com/detections/b0fd38c7-f71a-43a2-870e-f3ca06bcdd99
97 ESCU - Windows Query Registry Reg Save - Rule Detection 5.2.0 Renamed and updated logic https://research.splunk.com/migration_guide/ https://research.splunk.com/detections/466379bc-0f47-476c-8202-16ef38112e0d
98 ESCU - Cloud Network Access Control List Deleted - Rule Detection 5.2.0 Detections updated to use the new search logic and field names due to the TA update https://research.splunk.com/migration_guide/ https://research.splunk.com/detections/ada0f478-84a8-4641-a3f1-d82362d6fd75
99 ESCU - O365 Suspicious Rights Delegation - Rule Detection 5.2.0 Detections updated to use the new search logic and field names due to the TA update https://research.splunk.com/migration_guide/ https://research.splunk.com/detections/2246c142-a678-45f8-8546-aaed7e0efd30
100 ESCU - Abnormally High AWS Instances Launched by User - MLTK - Rule Detection 5.2.0 Detection deprecated as it no longer effectively identifies the intended malicious activity https://research.splunk.com/migration_guide/
101 ESCU - Reg exe used to hide files directories via registry keys - Rule Detection 5.2.0 Detection deprecated as it no longer effectively identifies the intended malicious activity https://research.splunk.com/migration_guide/
102 ESCU - Detect Long DNS TXT Record Response - Rule Detection 5.2.0 Detection deprecated as it no longer effectively identifies the intended malicious activity https://research.splunk.com/migration_guide/
103 ESCU - Password Policy Discovery with Net - Rule Detection 5.2.0 Renamed and updated logic https://research.splunk.com/migration_guide/ https://research.splunk.com/detections/e52f7865-be78-46bf-b7ed-150fbe447613
104 ESCU - AWS Cloud Provisioning From Previously Unseen IP Address - Rule Detection 5.2.0 Detections updated to use the new search logic and field names due to the TA update https://research.splunk.com/migration_guide/ https://research.splunk.com/detections/f86a8ec9-b042-45eb-92f4-e9ed1d781078
105 ESCU - Network Connection Discovery With Net - Rule Detection 5.2.0 Renamed and updated logic https://research.splunk.com/migration_guide/ https://research.splunk.com/detections/86a5b949-679b-4197-8d4c-9c180a818c45
106 ESCU - Kubernetes Azure detect suspicious kubectl calls - Rule Detection 5.2.0 Detection deprecated as it no longer effectively identifies the intended malicious activity https://research.splunk.com/migration_guide/
107 ESCU - Kubernetes GCP detect sensitive role access - Rule Detection 5.2.0 Detection deprecated as it no longer effectively identifies the intended malicious activity https://research.splunk.com/migration_guide/
108 ESCU - Detect Webshell Exploit Behavior - Rule Detection 5.2.0 Renamed and updated logic https://research.splunk.com/migration_guide/ https://research.splunk.com/detections/2d4470ef-7158-4b47-b68b-1f7f16382156
109 ESCU - DNS record changed - Rule Detection 5.2.0 Detection deprecated as it no longer effectively identifies the intended malicious activity https://research.splunk.com/migration_guide/
110 ESCU - Unsigned Image Loaded by LSASS - Rule Detection 5.2.0 Detection deprecated as it no longer effectively identifies the intended malicious activity https://research.splunk.com/migration_guide/
111 ESCU - Detect USB device insertion - Rule Detection 5.2.0 Detection deprecated as it no longer effectively identifies the intended malicious activity https://research.splunk.com/migration_guide/
112 ESCU - Windows Network Share Interaction With Net - Rule Detection 5.2.0 Renamed and updated logic https://research.splunk.com/migration_guide/ https://research.splunk.com/detections/e51fbdb0-0be0-474f-92ea-d289f71a695e
113 ESCU - Account Discovery With Net App - Rule Detection 5.2.0 This analytic was a TTP that focused on unrelated things and called account discovery. Since there were other detection that overlapped with it. I choose to deprecate it, and replace it with an updated version of 339805ce-ac30-11eb-b87d-acde48001122 / Windows Excessive Usage Of Net App. https://research.splunk.com/migration_guide/ https://research.splunk.com/detections/355ba810-0a20-4215-8485-9ce3f87f2e38
114 ESCU - Change Default File Association - Rule Detection 5.2.0 Renamed and updated logic https://research.splunk.com/migration_guide/ https://research.splunk.com/detections/7d1f031f-f1c9-43be-8b0b-c4e3e8a8928a
115 ESCU - Windows Lateral Tool Transfer RemCom - Rule Detection 5.2.0 Updated to a new detection name https://research.splunk.com/migration_guide/ https://research.splunk.com/detections/7e3d68db-ea4d-419b-adbd-e14a525ecf09
116 ESCU - Office Document Executing Macro Code - Rule Detection 5.2.0 Renamed and updated logic https://research.splunk.com/migration_guide/ https://research.splunk.com/detections/7cfec906-2697-43f7-898b-83634a051d9a
117 ESCU - Okta Account Lockout Events - Rule Detection 5.2.0 Detections updated to use the new search logic and field names due to the TA update https://research.splunk.com/migration_guide/ https://research.splunk.com/detections/a511426e-184f-4de6-8711-cfd2af29d1e1
118 ESCU - Abnormally High AWS Instances Launched by User - Rule Detection 5.2.0 Detections updated to use the new search logic and field names due to the TA update https://research.splunk.com/migration_guide/ https://research.splunk.com/detections/f2361e9f-3928-496c-a556-120cd4223a65
119 ESCU - EC2 Instance Modified With Previously Unseen User - Rule Detection 5.2.0 Detections updated to use the new search logic and field names due to the TA update https://research.splunk.com/migration_guide/ https://research.splunk.com/detections/2181ad1f-1e73-4d0c-9780-e8880482a08f
120 ESCU - Windows Valid Account With Never Expires Password - Rule Detection 5.2.0 Renamed and updated logic https://research.splunk.com/migration_guide/ https://research.splunk.com/detections/11f93009-8083-43fd-82a7-821fcbdc8342
121 ESCU - Windows hosts file modification - Rule Detection 5.2.0 Detection deprecated as it no longer effectively identifies the intended malicious activity https://research.splunk.com/migration_guide/
122 ESCU - MSHTML Module Load in Office Product - Rule Detection 5.2.0 Renamed and updated logic https://research.splunk.com/migration_guide/ https://research.splunk.com/detections/4cc015c9-687c-40d2-adcc-46350f66e10c
123 ESCU - Abnormally High AWS Instances Terminated by User - Rule Detection 5.2.0 Detections updated to use the new search logic and field names due to the TA update https://research.splunk.com/migration_guide/ https://research.splunk.com/detections/ef629fc9-1583-4590-b62a-f2247fbf7bbf
124 ESCU - Web Fraud - Account Harvesting - Rule Detection 5.2.0 Detection deprecated as it no longer effectively identifies the intended malicious activity https://research.splunk.com/migration_guide/
125 ESCU - Office Spawning Control - Rule Detection 5.2.0 Renamed and updated logic https://research.splunk.com/migration_guide/ https://research.splunk.com/detections/081c485d-ac8d-4bee-ad4c-525772fead4d
126 ESCU - Detect Activity Related to Pass the Hash Attacks - Rule Detection 5.2.0 Detection deprecated as it no longer effectively identifies the intended malicious activity https://research.splunk.com/migration_guide/
127 ESCU - Deleting Of Net Users - Rule Detection 5.2.0 Renamed and updated logic https://research.splunk.com/migration_guide/ https://research.splunk.com/detections/b0b6fd2c-8953-4d1b-8f7b-56075ea6ab3e
128 ESCU - Suspicious File Write - Rule Detection 5.2.0 Detection deprecated as it no longer effectively identifies the intended malicious activity https://research.splunk.com/migration_guide/
129 ESCU - AWS EKS Kubernetes cluster sensitive object access - Rule Detection 5.2.0 Detections updated to use the new search logic and field names due to the TA update https://research.splunk.com/migration_guide/ https://research.splunk.com/detections/40a064c1-4ec1-4381-9e35-61192ba8ef82
130 ESCU - Spectre and Meltdown Vulnerable Systems - Rule Detection 5.2.0 Detection deprecated as it no longer effectively identifies the intended malicious activity https://research.splunk.com/migration_guide/
131 ESCU - EC2 Instance Started With Previously Unseen User - Rule Detection 5.2.0 Detections updated to use the new search logic and field names due to the TA update https://research.splunk.com/migration_guide/ https://research.splunk.com/detections/37a0ec8d-827e-4d6d-8025-cedf31f3a149
132 ESCU - Office Product Spawning CertUtil - Rule Detection 5.2.0 Detection deprecated as it no longer effectively identifies the intended malicious activity https://research.splunk.com/migration_guide/ https://research.splunk.com/detections/55d8741c-fa32-4692-8109-410304961eb8
133 ESCU - Kubernetes GCP detect RBAC authorizations by account - Rule Detection 5.2.0 Detection deprecated as it no longer effectively identifies the intended malicious activity https://research.splunk.com/migration_guide/
134 ESCU - Office Application Drop Executable - Rule Detection 5.2.0 Renamed and updated logic https://research.splunk.com/migration_guide/ https://research.splunk.com/detections/7ac0fced-9eae-4381-a748-90dcd1aa9393
135 ESCU - Kubernetes Azure active service accounts by pod namespace - Rule Detection 5.2.0 Detection deprecated as it no longer effectively identifies the intended malicious activity https://research.splunk.com/migration_guide/
136 ESCU - Kubernetes Azure pod scan fingerprint - Rule Detection 5.2.0 Detection deprecated as it no longer effectively identifies the intended malicious activity https://research.splunk.com/migration_guide/
137 ESCU - Detect Spike in Network ACL Activity - Rule Detection 5.2.0 Detections updated to use the new search logic and field names due to the TA update https://research.splunk.com/migration_guide/ https://research.splunk.com/detections/0840ddf1-8c89-46ff-b730-c8d6722478c0
138 ESCU - Suspicious Powershell Command-Line Arguments - Rule Detection 5.2.0 Detection deprecated as it no longer effectively identifies the intended malicious activity https://research.splunk.com/migration_guide/ https://research.splunk.com/detections/c4db14d9-7909-48b4-a054-aa14d89dbb19
139 ESCU - Office Application Spawn Regsvr32 process - Rule Detection 5.2.0 Detection deprecated as it no longer effectively identifies the intended malicious activity https://research.splunk.com/migration_guide/ https://research.splunk.com/detections/55d8741c-fa32-4692-8109-410304961eb8
140 ESCU - Detect API activity from users without MFA - Rule Detection 5.2.0 Detections updated to use the new search logic and field names due to the TA update https://research.splunk.com/migration_guide/ https://research.splunk.com/detections/a520b1fe-cc9e-4f56-b762-18354594c52f
141 ESCU - Kubernetes Azure detect sensitive object access - Rule Detection 5.2.0 Detection deprecated as it no longer effectively identifies the intended malicious activity https://research.splunk.com/migration_guide/
142 ESCU - Web Fraud - Password Sharing Across Accounts - Rule Detection 5.2.0 Detection deprecated as it no longer effectively identifies the intended malicious activity https://research.splunk.com/migration_guide/
143 ESCU - Disabling Net User Account - Rule Detection 5.2.0 Renamed and updated logic https://research.splunk.com/migration_guide/ https://research.splunk.com/detections/b0359e05-c87b-4354-83d8-aee0d890243f
144 ESCU - GCP Detect accounts with high risk roles by project - Rule Detection 5.2.0 Detection deprecated as it no longer effectively identifies the intended malicious activity https://research.splunk.com/migration_guide/
145 ESCU - Kubernetes GCP detect service accounts forbidden failure access - Rule Detection 5.2.0 Detection deprecated as it no longer effectively identifies the intended malicious activity https://research.splunk.com/migration_guide/
146 ESCU - Extended Period Without Successful Netbackup Backups - Rule Detection 5.2.0 Detection deprecated as it no longer effectively identifies the intended malicious activity https://research.splunk.com/migration_guide/
147 ESCU - Office Product Spawning Rundll32 with no DLL - Rule Detection 5.2.0 Renamed and updated logic https://research.splunk.com/migration_guide/ https://research.splunk.com/detections/f28e787e-69ca-480e-9f98-ab970e6d4bcc
148 ESCU - Okta ThreatInsight Suspected PasswordSpray Attack - Rule Detection 5.2.0 Detections updated to use the new search logic and field names due to the TA update https://research.splunk.com/migration_guide/ https://research.splunk.com/detections/140504ae-5fe2-4d65-b2bc-a211813fbca6
149 ESCU - Net Localgroup Discovery - Rule Detection 5.2.0 Both of these analytics were deprecated in favor of c5c8e0f3-147a-43da-bf04-4cfaec27dc44 / Windows Group Discovery Via Net https://research.splunk.com/migration_guide/ https://research.splunk.com/detections/c5c8e0f3-147a-43da-bf04-4cfaec27dc44
150 ESCU - Uncommon Processes On Endpoint - Rule Detection 5.2.0 Detection deprecated as it no longer effectively identifies the intended malicious activity https://research.splunk.com/migration_guide/ https://research.splunk.com/detections/a51bfe1a-94f0-48cc-b4e4-16a110145893
151 ESCU - Dump LSASS via procdump Rename - Rule Detection 5.2.0 Updated to a new detection name https://research.splunk.com/migration_guide/ https://research.splunk.com/detections/3742ebfe-64c2-11eb-ae93-0242ac130002
152 ESCU - Okta Two or More Rejected Okta Pushes - Rule Detection 5.2.0 Detections updated to use the new search logic and field names due to the TA update https://research.splunk.com/migration_guide/ https://research.splunk.com/detections/826dbaae-a1e6-4c8c-b384-d16898956e73
153 ESCU - Excel Spawning Windows Script Host - Rule Detection 5.3.0 Detection deprecated as it no longer effectively identifies the intended malicious activity https://research.splunk.com/migration_guide/
154 ESCU - GitHub Actions Disable Security Workflow - Rule Detection 5.3.0 Detection deprecated as it no longer effectively identifies the intended malicious activity https://research.splunk.com/migration_guide/
155 ESCU - Github Commit Changes In Master - Rule Detection 5.3.0 Detection deprecated as it no longer effectively identifies the intended malicious activity https://research.splunk.com/migration_guide/
156 ESCU - Github Commit In Develop - Rule Detection 5.3.0 Detection deprecated as it no longer effectively identifies the intended malicious activity https://research.splunk.com/migration_guide/
157 ESCU - GitHub Dependabot Alert - Rule Detection 5.3.0 Detection deprecated as it no longer effectively identifies the intended malicious activity https://research.splunk.com/migration_guide/
158 ESCU - GitHub Pull Request from Unknown User - Rule Detection 5.3.0 Detection deprecated as it no longer effectively identifies the intended malicious activity https://research.splunk.com/migration_guide/
159 ESCU - Known Services Killed by Ransomware - Rule Detection 5.3.0 Detection deprecated as it no longer effectively identifies the intended malicious activity https://research.splunk.com/migration_guide/
160 ESCU - Remote Desktop Network Bruteforce - Rule Detection 5.3.0 Detection deprecated as it no longer effectively identifies the intended malicious activity https://research.splunk.com/migration_guide/
161 ESCU - Suspicious Driver Loaded Path - Rule Detection 5.3.0 Detection deprecated as it no longer effectively identifies the intended malicious activity https://research.splunk.com/migration_guide/
162 ESCU - Suspicious Event Log Service Behavior - Rule Detection 5.3.0 Detection deprecated as it no longer effectively identifies the intended malicious activity https://research.splunk.com/migration_guide/
163 ESCU - Suspicious Process File Path - Rule Detection 5.3.0 Detection deprecated as it no longer effectively identifies the intended malicious activity https://research.splunk.com/migration_guide/
164 ESCU - Windows Service Stop Via Net and SC Application - Rule Detection 5.3.0 Detection deprecated as it no longer effectively identifies the intended malicious activity https://research.splunk.com/migration_guide/
165 ESCU - Add Prohibited Processes to Enterprise Security Baseline 5.2.0 All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well. https://research.splunk.com/migration_guide/
166 ESCU - Baseline of API Calls per User ARN Baseline 5.2.0 All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well. https://research.splunk.com/migration_guide/
167 ESCU - Baseline of Excessive AWS Instances Launched by User - MLTK Baseline 5.2.0 All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well. https://research.splunk.com/migration_guide/
168 ESCU - Baseline of Excessive AWS Instances Terminated by User - MLTK Baseline 5.2.0 All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well. https://research.splunk.com/migration_guide/
169 ESCU - Previously seen API call per user roles in CloudTrail Baseline 5.2.0 All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well. https://research.splunk.com/migration_guide/
170 ESCU - Previously Seen AWS Provisioning Activity Sources Baseline 5.2.0 All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well. https://research.splunk.com/migration_guide/
171 ESCU - Previously Seen EC2 AMIs Baseline 5.2.0 All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well. https://research.splunk.com/migration_guide/
172 ESCU - Previously Seen EC2 Instance Types Baseline 5.2.0 All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well. https://research.splunk.com/migration_guide/
173 ESCU - Previously Seen EC2 Launches By User Baseline 5.2.0 All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well. https://research.splunk.com/migration_guide/
174 ESCU - Previously seen users in CloudTrail Baseline 5.2.0 All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well. https://research.splunk.com/migration_guide/
175 ESCU - Update previously seen users in CloudTrail Baseline 5.2.0 All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well. https://research.splunk.com/migration_guide/
176 AWS Cryptomining Story 5.2.0 Analytic Story deprecated as it no longer effectively identifies the intended malicious activity https://research.splunk.com/migration_guide/
177 AWS Suspicious Provisioning Activities Story 5.2.0 Analytic Story deprecated as it no longer effectively identifies the intended malicious activity https://research.splunk.com/migration_guide/
178 Common Phishing Frameworks Story 5.2.0 Analytic Story deprecated as it no longer effectively identifies the intended malicious activity https://research.splunk.com/migration_guide/
179 Container Implantation Monitoring and Investigation Story 5.2.0 Analytic Story deprecated as it no longer effectively identifies the intended malicious activity https://research.splunk.com/migration_guide/
180 Host Redirection Story 5.2.0 Analytic Story deprecated as it no longer effectively identifies the intended malicious activity https://research.splunk.com/migration_guide/
181 Kubernetes Sensitive Role Activity Story 5.2.0 Analytic Story deprecated as it no longer effectively identifies the intended malicious activity https://research.splunk.com/migration_guide/
182 Lateral Movement Story 5.2.0 Analytic Story deprecated as it no longer effectively identifies the intended malicious activity https://research.splunk.com/migration_guide/
183 Monitor Backup Solution Story 5.2.0 Analytic Story deprecated as it no longer effectively identifies the intended malicious activity https://research.splunk.com/migration_guide/
184 Monitor for Unauthorized Software Story 5.2.0 Analytic Story deprecated as it no longer effectively identifies the intended malicious activity https://research.splunk.com/migration_guide/
185 Office 365 Detections Story 5.2.0 Analytic Story deprecated as it no longer effectively identifies the intended malicious activity https://research.splunk.com/migration_guide/
186 Spectre And Meltdown Vulnerabilities Story 5.2.0 Analytic Story deprecated as it no longer effectively identifies the intended malicious activity https://research.splunk.com/migration_guide/
187 Suspicious AWS EC2 Activities Story 5.2.0 Analytic Story deprecated as it no longer effectively identifies the intended malicious activity https://research.splunk.com/migration_guide/
188 Unusual AWS EC2 Modifications Story 5.2.0 Analytic Story deprecated as it no longer effectively identifies the intended malicious activity https://research.splunk.com/migration_guide/
189 Web Fraud Detection Story 5.2.0 Analytic Story deprecated as it no longer effectively identifies the intended malicious activity https://research.splunk.com/migration_guide/
190 Nexus APT Threat Activity Story 5.4.0 Analytic Story deprecated as it no longer effectively identifies the intended malicious activity https://research.splunk.com/migration_guide/
+9
View File
@@ -0,0 +1,9 @@
name: deprecation_info
date: 2025-03-14
version: 1
id: d83dad4f-7bce-4979-bf07-a88c610da5f6
author: Splunk Threat Research Team
lookup_type: csv
default_match: false
description: A lookup file for deprecation information
min_matches: 1