Files
splunk-security_content/removed/deprecation_mapping.YML
Nasreddine Bencherchali 21ee673940 Fix Issues & Updates (#3705)
* Fix Issues and Updates

* Update add_or_set_windows_defender_exclusion.yml

* Update windows_curl_download_to_suspicious_path.yml

* Fix more issues and bugs

* Update deprecation_mapping.YML

* Update windows_application_whitelisting_bypass_attempt_via_rundll32.yml

* More updates and fixes

* update `Windows Change Default File Association For No File Ext`

* A couple more updates for ya

* rename

* add / update rules

* Update windows_symlink_evaluation_change_via_fsutil.yml

* Update windows_symlink_evaluation_change_via_fsutil.yml

* Update linux_service_started_or_enabled.yml

* Update linux_service_started_or_enabled.yml

---------

Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
2025-10-13 09:18:21 -07:00

1102 lines
61 KiB
YAML

detections:
- content: Windows Change Default File Association For No File Ext
removed_in_version: 5.18.0
reason: Detection has been deprecated since it has been replaced with a better named detection that reflect a much better consistent logic
replacement_content:
- Windows Change File Association Command To Notepad
- content: Detect Rundll32 Application Control Bypass - setupapi
removed_in_version: 5.18.0
reason: Detection has been deprecated since it has been replaced with a better named detection that reflect a much better consistent logic
replacement_content:
- Windows Application Whitelisting Bypass Attempt via Rundll32
- content: Detect Rundll32 Application Control Bypass - syssetup
removed_in_version: 5.18.0
reason: Detection has been deprecated since it has been replaced with a better named detection that reflect a much better consistent logic
replacement_content:
- Windows Application Whitelisting Bypass Attempt via Rundll32
- content: Detect Rundll32 Application Control Bypass - advpack
removed_in_version: 5.18.0
reason: Detection has been deprecated since it has been replaced with a better named detection that reflect a much better consistent logic
replacement_content:
- Windows Application Whitelisting Bypass Attempt via Rundll32
- content: Windows Set Private Network Profile via Registry
removed_in_version: 5.18.0
reason: Renamed the detection for much clearer description with an updated detection logic.
replacement_content:
- Windows Set Network Profile Category to Private via Registry
- content: Cisco Secure Application Alerts
removed_in_version: 5.14.0
reason: Detection has been deprecated since it has been replaced with a better named detection to reflect the correct product
replacement_content:
- Splunk AppDynamics Secure Application Alerts
- content: Windows InstallUtil Uninstall Option with Network
removed_in_version: 5.12.0
reason: Detection has been deprecated as its scope is already covered by "Windows InstallUtil Remote Network Connection".
replacement_content:
- Windows InstallUtil Remote Network Connection
- content: Any Powershell DownloadString
removed_in_version: 5.12.0
reason: Detection has been replaced by a new detection with a better logic and grouping in order to ease its management.
replacement_content:
- Windows File Download Via PowerShell
- content: Any Powershell DownloadFile
removed_in_version: 5.12.0
reason: Detection has been replaced by a new detection with a better logic and grouping in order to ease its management.
replacement_content:
- Windows File Download Via PowerShell
- content: Windows AD Suspicious GPO Modification
removed_in_version: 5.10.0
reason: Detection deprecated due to lack of data and consistency. Research is being done to create potential replacement in a future release.
- content: Windows Remote Access Software Hunt
removed_in_version: 5.8.0
reason: Detection has been replaced by a new detection with a more specific name and logic
replacement_content:
- Detect Remote Access Software Usage Process
- content: CertUtil Download With URLCache and Split Arguments
removed_in_version: 5.8.0
reason: Detection deprecated in favor of "Windows File Download Via CertUtil", in order to provide a better experience of the alert
replacement_content:
- Windows File Download Via CertUtil
- content: Windows CertUtil Download With URL Argument
removed_in_version: 5.8.0
reason: Detection deprecated in favor of "Windows File Download Via CertUtil", in order to provide a better experience of the alert
replacement_content:
- Windows File Download Via CertUtil
- content: CertUtil Download With VerifyCtl and Split Arguments
removed_in_version: 5.8.0
reason: Detection deprecated in favor of "Windows File Download Via CertUtil", in order to provide a better experience of the alert
replacement_content:
- Windows File Download Via CertUtil
- content: Detect Large Outbound ICMP Packets
removed_in_version: 5.6.0
reason: Detection has been replaced by a new detection with a more specific name
replacement_content:
- Detect Large ICMP Traffic
- content: Windows Service Created Within Public Path
removed_in_version: 5.6.0
reason: Detection has been replaced by a new detection with a more specific name
replacement_content:
- Windows Service Created with Suspicious Service Path
- content: GitHub Actions Disable Security Workflow
removed_in_version: 5.4.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content:
- GitHub Organizations Disable Classic Branch Protection Rule
- content: Github Commit Changes In Master
removed_in_version: 5.4.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- content: Github Commit In Develop
removed_in_version: 5.4.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- content: GitHub Dependabot Alert
removed_in_version: 5.4.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content:
- GitHub Enterprise Disable Dependabot
- content: GitHub Pull Request from Unknown User
removed_in_version: 5.4.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- content: Known Services Killed by Ransomware
removed_in_version: 5.4.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content:
- Windows Security And Backup Services Stop
- content: Remote Desktop Network Bruteforce
removed_in_version: 5.4.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content:
- Windows Remote Desktop Network Bruteforce Attempt
- content: Suspicious Driver Loaded Path
removed_in_version: 5.4.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content:
- Windows Suspicious Driver Loaded Path
- content: Suspicious Event Log Service Behavior
removed_in_version: 5.4.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content:
- Windows Event Logging Service Has Shutdown
- content: Suspicious Process File Path
removed_in_version: 5.4.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content:
- Windows Suspicious Process File Path
- content: AWS Cross Account Activity From Previously Unseen Account
removed_in_version: 5.4.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- content: aws detect attach to role policy
removed_in_version: 5.4.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- content: aws detect permanent key creation
removed_in_version: 5.4.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- content: aws detect role creation
removed_in_version: 5.4.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- content: aws detect sts assume role abuse
removed_in_version: 5.4.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- content: aws detect sts get session token abuse
removed_in_version: 5.4.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- content: AWS SAML Access by Provider User and Principal
removed_in_version: 5.4.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- content: ASL AWS Excessive Security Scanning
removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- content: AWS Cloud Provisioning From Previously Unseen Region
removed_in_version: 5.2.0
reason: Detections updated to use the new search logic and field names due to the
TA update
replacement_content:
- Cloud Provisioning Activity From Previously Unseen Region
- content: First time seen command line argument
removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- content: Windows connhost exe started forcefully
removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- content: Detect Mimikatz Using Loaded Images
removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- content: Kubernetes Azure detect sensitive role access
removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- content: Web Fraud - Anomalous User Clickspeed
removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- content: EC2 Instance Started With Previously Unseen Instance Type
removed_in_version: 5.2.0
reason: Detections updated to use the new search logic and field names due to the
TA update
replacement_content:
- Cloud Compute Instance Created With Previously Unseen Instance Type
- content: EC2 Instance Started With Previously Unseen AMI
removed_in_version: 5.2.0
reason: Detections updated to use the new search logic and field names due to the
TA update
replacement_content:
- Cloud Compute Instance Created With Previously Unseen Image
- content: Domain Group Discovery With Net
removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content:
- Windows Group Discovery Via Net
- content: Kubernetes AWS detect sensitive role access
removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- content: Winword Spawning Windows Script Host
removed_in_version: 5.2.0
reason: "The following analytics was deprecated in favour of a more generic approach.
Where instead of creating specific analytic for every potentially suspicious child
of an office product. We group them by threat level.\nThis would ease management
and false positives tuning."
replacement_content:
- Windows Office Product Spawned Uncommon Process
- content: Winword Spawning PowerShell
removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content:
- Windows Office Product Spawned Uncommon Process
- content: Attempted Credential Dump From Registry via Reg exe
removed_in_version: 5.2.0
reason: This analytic had some overlap with another one, hence the deprecation.
It was replaced by 8bbb7d58-b360-11eb-ba21-acde48001122 / Windows Sensitive Registry
Hive Dump Via CommandLine
replacement_content:
- Windows Sensitive Registry Hive Dump Via CommandLine
- content: Detect processes used for System Network Configuration Discovery
removed_in_version: 5.2.0
reason: Renamed and updated logic
replacement_content:
- Potential System Network Configuration Discovery Activity
- content: Execution of File With Spaces Before Extension
removed_in_version: 5.2.0
reason: Updated to a new detection name
replacement_content:
- Execution of File with Multiple Extensions
- content: EC2 Instance Started In Previously Unseen Region
removed_in_version: 5.2.0
reason: Detections updated to use the new search logic and field names due to the
TA update
replacement_content:
- Cloud Compute Instance Created In Previously Unused Region
- content: Office Document Spawned Child Process To Download
removed_in_version: 5.2.0
reason: Renamed and updated logic
replacement_content:
- Windows Office Product Spawned Child Process For Download
- content: Detect new API calls from user roles
removed_in_version: 5.2.0
reason: Detections updated to use the new search logic and field names due to the
TA update
replacement_content:
- Cloud API Calls From Previously Unseen User Roles
- content: Cmdline Tool Not Executed In CMD Shell
removed_in_version: 5.2.0
reason: Renamed and updated logic
replacement_content:
- Windows Cmdline Tool Execution From Non-Shell Process
- content: Linux Auditd Find Private Keys
removed_in_version: 5.2.0
reason: Renamed and updated logic
replacement_content:
- Linux Auditd Private Keys and Certificate Enumeration
- content: Detect AWS API Activities From Unapproved Accounts
removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- content: Monitor DNS For Brand Abuse
removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- content: Kubernetes GCP detect sensitive object access
removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- content: Kubernetes Azure scan fingerprint
removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- content: ASL AWS Password Policy Changes
removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- content: O365 Suspicious Admin Email Forwarding
removed_in_version: 5.2.0
reason: Detections updated to use the new search logic and field names due to the
TA update
replacement_content:
- O365 Mailbox Email Forwarding Enabled
- content: AWS Cloud Provisioning From Previously Unseen City
removed_in_version: 5.2.0
reason: Detections updated to use the new search logic and field names due to the
TA update
replacement_content:
- Cloud Provisioning Activity From Previously Unseen City
- content: Kubernetes AWS detect service accounts forbidden failure access
removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- content: Osquery pack - ColdRoot detection
removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- content: Windows Modify Registry Reg Restore
removed_in_version: 5.2.0
reason: Renamed and updated logic
replacement_content:
- Windows Registry Entries Restored Via Reg
- content: Kubernetes GCP detect most active service accounts by pod
removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- content: Scheduled tasks used in BadRabbit ransomware
removed_in_version: 5.2.0
reason: Updated to a new detection name
replacement_content:
- Scheduled Task Deleted Or Created via CMD
- content: Suspicious Rundll32 Rename
removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- content: Remote System Discovery with Net
removed_in_version: 5.2.0
reason: "This analytic was focusing on 2 separate and unrelated type of threats
or actions. PLease use the replacement content"
replacement_content:
- Windows Sensitive Group Discovery With Net
- content: DNS Query Requests Resolved by Unauthorized DNS Servers
removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- content: Suspicious Changes to File Associations
removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- content: GCP Detect high risk permissions by resource and account
removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- content: Office Product Writing cab or inf
removed_in_version: 5.2.0
reason: Renamed and updated logic
replacement_content:
- Windows Office Product Dropped Cab or Inf File
- content: Identify New User Accounts
removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- content: Office Product Spawn CMD Process
removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content:
- Windows Office Product Spawned Uncommon Process
- content: Windows DLL Search Order Hijacking Hunt
removed_in_version: 5.2.0
reason: Detections updated to use the new search logic and field names due to the
TA update
replacement_content:
- Windows DLL Search Order Hijacking Hunt with Sysmon
- content: ASL AWS CreateAccessKey
removed_in_version: 5.2.0
reason: Detections updated to use the new search logic and field names due to the
TA update
replacement_content:
- ASL AWS Create Access Key
- content: Okta ThreatInsight Login Failure with High Unknown users
removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- content: Detect Spike in Security Group Activity
removed_in_version: 5.2.0
reason: Detections updated to use the new search logic and field names due to the
TA update
replacement_content:
- Abnormally High Number Of Cloud Security Group API Calls
- content: Office Product Spawning BITSAdmin
removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content:
- Windows Office Product Spawned Uncommon Process
- content: Create local admin accounts using net exe
removed_in_version: 5.2.0
reason: Renamed and updated logic
replacement_content:
- Windows Create Local Administrator Account Via Net
- content: Abnormally High AWS Instances Terminated by User - MLTK
removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- content: Windows Office Product Spawning MSDT
removed_in_version: 5.2.0
reason: Renamed and updated logic
replacement_content:
- Windows Office Product Spawned MSDT
- content: Detect Spike in AWS API Activity
removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- content: Office Product Spawning Windows Script Host
removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content:
- Windows Office Product Spawned Uncommon Process
- content: Prohibited Software On Endpoint
removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content:
- Attacker Tools On Endpoint
- content: AWS Cloud Provisioning From Previously Unseen Country
removed_in_version: 5.2.0
reason: Detections updated to use the new search logic and field names due to the
TA update
replacement_content:
- Cloud Provisioning Activity From Previously Unseen Country
- content: Detect Critical Alerts from Security Tools
removed_in_version: 5.2.0
reason: As discussed internally, this analytic was too generic for an analyst to
do anything with it. It was deprecated in favor of the more specific approach
provided by analytics such as Microsoft Defender ATP Alerts and Microsoft Defender
Incident Alerts. Going forward analytics from leveraging alerts from vendors will
have their specific analytics.
replacement_content:
- Microsoft Defender ATP Alerts
- Microsoft Defender Incident Alerts
- content: Excel Spawning PowerShell
removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content:
- Windows Office Product Spawned Uncommon Process
- content: Office Application Spawn rundll32 process
removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content:
- Windows Office Product Spawned Uncommon Process
- content: Excessive Usage Of Net App
removed_in_version: 5.2.0
reason: Renamed and updated logic
replacement_content:
- Windows Excessive Usage Of Net App
- content: Elevated Group Discovery With Net
removed_in_version: 5.2.0
reason: Renamed and updated logic
replacement_content:
- Windows Sensitive Group Discovery With Net
- content: Local Account Discovery with Net
removed_in_version: 5.2.0
reason: Renamed and updated logic
replacement_content:
- Windows User Discovery Via Net
- content: Windows Command Shell Fetch Env Variables
removed_in_version: 5.2.0
reason: Renamed and updated logic
replacement_content:
- Windows List ENV Variables Via SET Command From Uncommon Parent
- content: Suspicious Email - UBA Anomaly
removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- content: Detect web traffic to dynamic domain providers
removed_in_version: 5.2.0
reason: Updated to use a different log source
replacement_content:
- Detect hosts connecting to dynamic domain providers
- content: Okta Failed SSO Attempts
removed_in_version: 5.2.0
reason: Detections updated to use the new search logic and field names due to the
TA update
replacement_content:
- Okta Unauthorized Access to Application
- content: Kubernetes AWS detect RBAC authorization by account
removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- content: Kubernetes Azure detect service accounts forbidden failure access
removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- content: Remote Registry Key modifications
removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- content: O365 Suspicious User Email Forwarding
removed_in_version: 5.2.0
reason: Detections updated to use the new search logic and field names due to the
TA update
replacement_content:
- O365 Mailbox Email Forwarding Enabled
- content: Office Product Spawning MSHTA
removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content:
- Windows Office Product Spawned Uncommon Process
- content: Kubernetes AWS detect most active service accounts by pod
removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- content: Correlation by Repository and Risk
removed_in_version: 5.2.0
reason: Detections updated to use the datamodel
replacement_content:
- Risk Rule for Dev Sec Ops by Repository
- content: Kubernetes Azure detect RBAC authorization by account
removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- content: Clients Connecting to Multiple DNS Servers
removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- content: Excessive Service Stop Attempt
removed_in_version: 5.2.0
reason: Renamed and updated logic
replacement_content:
- Windows Excessive Service Stop Attempt
- content: Multiple Okta Users With Invalid Credentials From The Same IP
removed_in_version: 5.2.0
reason: Detections updated to use the new search logic and field names due to the
TA update
replacement_content:
- Okta Multiple Users Failing To Authenticate From Ip
- content: Suspicious writes to System Volume Information
removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- content: Detect new user AWS Console Login
removed_in_version: 5.2.0
reason: Detections updated to use the new search logic and field names due to the
TA update
replacement_content:
- Detect AWS Console Login by New User
- content: Domain Account Discovery With Net App
removed_in_version: 5.2.0
reason: "This analytic was a TTP that looked only for commands that tries to query
info about the users via net user /do. This had a couple of issues, such as triggering
on creation of users via the /add flag etc..\nIt was deprecated in favor of a
more tighter approach in 5d0d4830-0133-11ec-bae3-acde48001122"
replacement_content:
- Windows User Discovery Via Net
- content: Detection of DNS Tunnels
removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- content: Detect DNS requests to Phishing Sites leveraging EvilGinx2
removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- content: Office Document Creating Schedule Task
removed_in_version: 5.2.0
reason: Renamed and updated logic
replacement_content:
- Windows Office Product Loading Taskschd DLL
- content: Okta Account Locked Out
removed_in_version: 5.2.0
reason: Detections updated to use the new search logic and field names due to the
TA update
replacement_content:
- Okta Multiple Accounts Locked Out
- content: Unsuccessful Netbackup backups
removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- content: Detect Mimikatz Via PowerShell And EventCode 4703
removed_in_version: 5.2.0
reason: Updated to a new detection name
replacement_content:
- Detect Mimikatz With PowerShell Script Block Logging
- content: Winword Spawning Cmd
removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content:
- Windows Office Product Spawned Uncommon Process
- content: GCP Kubernetes cluster scan detection
removed_in_version: 5.2.0
reason: Detections updated to use the new search logic and field names due to the
TA update
replacement_content:
- Kubernetes Scanning by Unauthenticated IP Address
- content: Kubernetes GCP detect suspicious kubectl calls
removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- content: gcp detect oauth token abuse
removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- content: Correlation by User and Risk
removed_in_version: 5.2.0
reason: Detections updated to use the datamodel
replacement_content:
- Risk Rule for Dev Sec Ops by Repository
- content: Processes created by netsh
removed_in_version: 5.2.0
reason: Updated to a new detection name
replacement_content:
- Processes launching netsh
- content: Office Product Spawning Wmic
removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content:
- Windows Office Product Spawned Uncommon Process
- content: Extraction of Registry Hives
removed_in_version: 5.2.0
reason: Renamed and updated logic
replacement_content:
- Windows Sensitive Registry Hive Dump Via CommandLine
- content: Attempt To Stop Security Service
removed_in_version: 5.2.0
reason: Renamed and updated logic
replacement_content:
- Windows Attempt To Stop Security Service
- content: Windows MSIExec With Network Connections
removed_in_version: 5.2.0
reason: Renamed and updated logic
replacement_content:
- Windows HTTP Network Communication From MSIExec
- content: Windows Query Registry Reg Save
removed_in_version: 5.2.0
reason: Renamed and updated logic
replacement_content:
- Windows Registry Entries Exported Via Reg
- content: Cloud Network Access Control List Deleted
removed_in_version: 5.2.0
reason: Detections updated to use the new search logic and field names due to the
TA update
replacement_content:
- AWS Network Access Control List Deleted
- content: O365 Suspicious Rights Delegation
removed_in_version: 5.2.0
reason: Detections updated to use the new search logic and field names due to the
TA update
replacement_content:
- O365 Elevated Mailbox Permission Assigned
- content: Abnormally High AWS Instances Launched by User - MLTK
removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- content: Reg exe used to hide files directories via registry keys
removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- content: Detect Long DNS TXT Record Response
removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- content: Password Policy Discovery with Net
removed_in_version: 5.2.0
reason: Renamed and updated logic
replacement_content:
- Windows Password Policy Discovery with Net
- content: AWS Cloud Provisioning From Previously Unseen IP Address
removed_in_version: 5.2.0
reason: Detections updated to use the new search logic and field names due to the
TA update
replacement_content:
- Cloud Provisioning Activity From Previously Unseen IP Address
- content: Network Connection Discovery With Net
removed_in_version: 5.2.0
reason: Renamed and updated logic
replacement_content:
- Windows Network Connection Discovery Via Net
- content: Kubernetes Azure detect suspicious kubectl calls
removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- content: Kubernetes GCP detect sensitive role access
removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- content: Detect Webshell Exploit Behavior
removed_in_version: 5.2.0
reason: Renamed and updated logic
replacement_content:
- Windows Suspicious Child Process Spawned From WebServer
- content: DNS record changed
removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- content: Unsigned Image Loaded by LSASS
removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- content: Detect USB device insertion
removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- content: Windows Network Share Interaction With Net
removed_in_version: 5.2.0
reason: Renamed and updated logic
replacement_content:
- Windows Network Share Interaction Via Net
- content: Account Discovery With Net App
removed_in_version: 5.2.0
reason: This analytic was a TTP that focused on unrelated things and called account
discovery. Since there were other detection that overlapped with it. I choose
to deprecate it, and replace it with an updated version of 339805ce-ac30-11eb-b87d-acde48001122
/ Windows Excessive Usage Of Net App.
replacement_content:
- Windows Excessive Usage Of Net App
- content: Change Default File Association
removed_in_version: 5.2.0
reason: Renamed and updated logic
replacement_content:
- Windows New Default File Association Value Set
- content: Windows Lateral Tool Transfer RemCom
removed_in_version: 5.2.0
reason: Updated to a new detection name
replacement_content:
- Windows Service Execution RemCom
- content: Office Document Executing Macro Code
removed_in_version: 5.2.0
reason: Renamed and updated logic
replacement_content:
- Windows Office Product Loading VBE7 DLL
- content: Okta Account Lockout Events
removed_in_version: 5.2.0
reason: Detections updated to use the new search logic and field names due to the
TA update
replacement_content:
- Okta Multiple Accounts Locked Out
- content: Abnormally High AWS Instances Launched by User
removed_in_version: 5.2.0
reason: Detections updated to use the new search logic and field names due to the
TA update
replacement_content:
- Abnormally High Number Of Cloud Instances Launched
- content: EC2 Instance Modified With Previously Unseen User
removed_in_version: 5.2.0
reason: Detections updated to use the new search logic and field names due to the
TA update
replacement_content:
- Cloud API Calls From Previously Unseen User Roles
- content: Windows Valid Account With Never Expires Password
removed_in_version: 5.2.0
reason: Renamed and updated logic
replacement_content:
- Windows Set Account Password Policy To Unlimited Via Net
- content: Windows hosts file modification
removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- content: MSHTML Module Load in Office Product
removed_in_version: 5.2.0
reason: Renamed and updated logic
replacement_content:
- Windows Office Product Loaded MSHTML Module
- content: Abnormally High AWS Instances Terminated by User
removed_in_version: 5.2.0
reason: Detections updated to use the new search logic and field names due to the
TA update
replacement_content:
- Abnormally High Number Of Cloud Instances Destroyed
- content: Web Fraud - Account Harvesting
removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- content: Office Spawning Control
removed_in_version: 5.2.0
reason: Renamed and updated logic
replacement_content:
- Windows Office Product Spawned Control
- content: Detect Activity Related to Pass the Hash Attacks
removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- content: Deleting Of Net Users
removed_in_version: 5.2.0
reason: Renamed and updated logic
replacement_content:
- Windows User Deletion Via Net
- content: Suspicious File Write
removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- content: AWS EKS Kubernetes cluster sensitive object access
removed_in_version: 5.2.0
reason: Detections updated to use the new search logic and field names due to the
TA update
replacement_content:
- Kubernetes Abuse of Secret by Unusual Location
- content: Spectre and Meltdown Vulnerable Systems
removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- content: EC2 Instance Started With Previously Unseen User
removed_in_version: 5.2.0
reason: Detections updated to use the new search logic and field names due to the
TA update
replacement_content:
- Cloud Compute Instance Created By Previously Unseen User
- content: Office Product Spawning CertUtil
removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content:
- Windows Office Product Spawned Uncommon Process
- content: Kubernetes GCP detect RBAC authorizations by account
removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- content: Office Application Drop Executable
removed_in_version: 5.2.0
reason: Renamed and updated logic
replacement_content:
- Windows Office Product Dropped Uncommon File
- content: Kubernetes Azure active service accounts by pod namespace
removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- content: Kubernetes Azure pod scan fingerprint
removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- content: Detect Spike in Network ACL Activity
removed_in_version: 5.2.0
reason: Detections updated to use the new search logic and field names due to the
TA update
replacement_content:
- Abnormally High Number Of Cloud Infrastructure API Calls
- content: Suspicious Powershell Command-Line Arguments
removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content:
- Malicious PowerShell Process - Encoded Command
- content: Office Application Spawn Regsvr32 process
removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content:
- Windows Office Product Spawned Uncommon Process
- content: Detect API activity from users without MFA
removed_in_version: 5.2.0
reason: Detections updated to use the new search logic and field names due to the
TA update
replacement_content:
- AWS Successful Single-Factor Authentication
- content: Kubernetes Azure detect sensitive object access
removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- content: Web Fraud - Password Sharing Across Accounts
removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- content: Disabling Net User Account
removed_in_version: 5.2.0
reason: Renamed and updated logic
replacement_content:
- Windows User Disabled Via Net
- content: GCP Detect accounts with high risk roles by project
removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- content: Kubernetes GCP detect service accounts forbidden failure access
removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- content: Extended Period Without Successful Netbackup Backups
removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- content: Office Product Spawning Rundll32 with no DLL
removed_in_version: 5.2.0
reason: Renamed and updated logic
replacement_content:
- Windows Office Product Spawned Rundll32 With No DLL
- content: Okta ThreatInsight Suspected PasswordSpray Attack
removed_in_version: 5.2.0
reason: Detections updated to use the new search logic and field names due to the
TA update
replacement_content:
- Okta ThreatInsight Threat Detected
- content: Net Localgroup Discovery
removed_in_version: 5.2.0
reason: Both of these analytics were deprecated in favor of c5c8e0f3-147a-43da-bf04-4cfaec27dc44
/ Windows Group Discovery Via Net
replacement_content:
- Windows Group Discovery Via Net
- content: Uncommon Processes On Endpoint
removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
replacement_content:
- Attacker Tools On Endpoint
- content: Dump LSASS via procdump Rename
removed_in_version: 5.2.0
reason: Updated to a new detection name
replacement_content:
- Dump LSASS via procdump
- content: Okta Two or More Rejected Okta Pushes
removed_in_version: 5.2.0
reason: Detections updated to use the new search logic and field names due to the
TA update
replacement_content:
- Okta Multiple Failed MFA Requests For User
- content: Windows Service Stop Via Net and SC Application
removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
- content: Excel Spawning Windows Script Host
removed_in_version: 5.2.0
reason: Detection deprecated as it no longer effectively identifies the intended malicious activity
baselines:
- content: Previously Seen AWS Cross Account Activity
removed_in_version: 5.4.0
reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
- content: Previously Seen AWS Cross Account Activity - Initial
removed_in_version: 5.4.0
reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
- content: Previously Seen AWS Cross Account Activity - Update
removed_in_version: 5.4.0
reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
- content: Add Prohibited Processes to Enterprise Security
removed_in_version: 5.2.0
reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
- content: Baseline of API Calls per User ARN
removed_in_version: 5.2.0
reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
- content: Baseline of Excessive AWS Instances Launched by User - MLTK
removed_in_version: 5.2.0
reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
- content: Baseline of Excessive AWS Instances Terminated by User - MLTK
removed_in_version: 5.2.0
reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
- content: Previously seen API call per user roles in CloudTrail
removed_in_version: 5.2.0
reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
- content: Previously Seen AWS Provisioning Activity Sources
removed_in_version: 5.2.0
reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
- content: Previously Seen EC2 AMIs
removed_in_version: 5.2.0
reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
- content: Previously Seen EC2 Instance Types
removed_in_version: 5.2.0
reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
- content: Previously Seen EC2 Launches By User
removed_in_version: 5.2.0
reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
- content: Previously seen users in CloudTrail
removed_in_version: 5.2.0
reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
- content: Update previously seen users in CloudTrail
removed_in_version: 5.2.0
reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
- content: Monitor Successful Backups
removed_in_version: 5.2.0
reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
- content: Monitor Unsuccessful Backups
removed_in_version: 5.2.0
reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
- content: Previously Seen AWS Regions
removed_in_version: 5.2.0
reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
- content: Previously Seen EC2 Modifications By User
removed_in_version: 5.2.0
reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
- content: Systems Ready for Spectre-Meltdown Windows Patch
removed_in_version: 5.2.0
reason: 'All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.'
investigations:
- content: All backup logs for host
removed_in_version: 5.2.0
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- content: Amazon EKS Kubernetes activity by src ip
removed_in_version: 5.2.0
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- content: AWS Investigate Security Hub alerts by dest
removed_in_version: 5.2.0
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- content: AWS Investigate User Activities By AccessKeyId
removed_in_version: 5.2.0
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- content: AWS Investigate User Activities By ARN
removed_in_version: 5.2.0
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- content: AWS Network ACL Details from ID
removed_in_version: 5.2.0
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- content: AWS Network Interface details via resourceId
removed_in_version: 5.2.0
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- content: AWS S3 Bucket details via bucketName
removed_in_version: 5.2.0
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- content: GCP Kubernetes activity by src ip
removed_in_version: 5.2.0
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- content: Get All AWS Activity From City
removed_in_version: 5.2.0
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- content: Get All AWS Activity From Country
removed_in_version: 5.2.0
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- content: Get All AWS Activity From IP Address
removed_in_version: 5.2.0
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- content: Get All AWS Activity From Region
removed_in_version: 5.2.0
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- content: Get Backup Logs For Endpoint
removed_in_version: 5.2.0
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- content: Get Certificate logs for a domain
removed_in_version: 5.2.0
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- content: Get DNS Server History for a host
removed_in_version: 5.2.0
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- content: Get DNS traffic ratio
removed_in_version: 5.2.0
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- content: Get EC2 Instance Details by instanceId
removed_in_version: 5.2.0
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- content: Get EC2 Launch Details
removed_in_version: 5.2.0
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- content: Get Email Info
removed_in_version: 5.2.0
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- content: Get Emails From Specific Sender
removed_in_version: 5.2.0
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- content: Get First Occurrence and Last Occurrence of a MAC Address
removed_in_version: 5.2.0
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- content: Get History Of Email Sources
removed_in_version: 5.2.0
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- content: Get Logon Rights Modifications For Endpoint
removed_in_version: 5.2.0
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- content: Get Logon Rights Modifications For User
removed_in_version: 5.2.0
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- content: Get Notable History
removed_in_version: 5.2.0
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- content: Get Outbound Emails to Hidden Cobra Threat Actors
removed_in_version: 5.2.0
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- content: Get Parent Process Info
removed_in_version: 5.2.0
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- content: Get Process File Activity
removed_in_version: 5.2.0
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- content: Get Process Info
removed_in_version: 5.2.0
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- content: Get Process Information For Port Activity
removed_in_version: 5.2.0
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- content: Get Process Responsible For The DNS Traffic
removed_in_version: 5.2.0
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- content: Get Sysmon WMI Activity for Host
removed_in_version: 5.2.0
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- content: Get Web Session Information via session id
removed_in_version: 5.2.0
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- content: Investigate AWS activities via region name
removed_in_version: 5.2.0
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- content: Investigate AWS User Activities by user field
removed_in_version: 5.2.0
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- content: Investigate Failed Logins for Multiple Destinations
removed_in_version: 5.2.0
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- content: Investigate Network Traffic From src ip
removed_in_version: 5.2.0
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- content: Investigate Okta Activity by app
removed_in_version: 5.2.0
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- content: Investigate Okta Activity by IP Address
removed_in_version: 5.2.0
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- content: Investigate Pass the Hash Attempts
removed_in_version: 5.2.0
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- content: Investigate Pass the Ticket Attempts
removed_in_version: 5.2.0
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- content: Investigate Previous Unseen User
removed_in_version: 5.2.0
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- content: Investigate Successful Remote Desktop Authentications
removed_in_version: 5.2.0
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- content: Investigate Suspicious Strings in HTTP Header
removed_in_version: 5.2.0
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- content: Investigate User Activities In Okta
removed_in_version: 5.2.0
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
- content: Investigate Web POSTs From src
removed_in_version: 5.2.0
reason: 'As of Splunk Enterprise Security version 8.0, Splunk Enterprise Security no longer supports Investigations. As such, all Investigations have been deprecated in ES Content Update.'
stories:
- content: Nexus APT Threat Activity
removed_in_version: 5.4.0
reason: Analytic Story has been replaced by a new analytic story with a more specific name
replacement_content:
- China-Nexus Threat Activity
- content: Earth Estries
removed_in_version: 5.4.0
reason: Analytic Story has been replaced by a new analytic story with a more specific name
replacement_content:
- Salt Typhoon
- content: AWS Cross Account Activity
removed_in_version: 5.4.0
reason: All associated detections with this story have been deprecated
- content: AWS Cryptomining
removed_in_version: 5.2.0
reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
replacement_content:
- Cloud Cryptomining
- content: AWS Suspicious Provisioning Activities
removed_in_version: 5.2.0
reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
replacement_content:
- Suspicious Cloud Provisioning Activities
- content: Common Phishing Frameworks
removed_in_version: 5.2.0
reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
- content: Container Implantation Monitoring and Investigation
removed_in_version: 5.2.0
reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
replacement_content:
- Kubernetes Security
- content: Host Redirection
removed_in_version: 5.2.0
reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
- content: Kubernetes Sensitive Role Activity
removed_in_version: 5.2.0
reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
replacement_content:
- Kubernetes Security
- content: Lateral Movement
removed_in_version: 5.2.0
reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
replacement_content:
- Compromised User Account
- content: Monitor Backup Solution
removed_in_version: 5.2.0
reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
- content: Monitor for Unauthorized Software
removed_in_version: 5.2.0
reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
- content: Office 365 Detections
removed_in_version: 5.2.0
reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
replacement_content:
- Office 365 Account Takeover
- content: Spectre And Meltdown Vulnerabilities
removed_in_version: 5.2.0
reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
- content: Suspicious AWS EC2 Activities
removed_in_version: 5.2.0
reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
replacement_content:
- Suspicious Cloud Instance Activities
- content: Unusual AWS EC2 Modifications
removed_in_version: 5.2.0
reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
replacement_content:
- Suspicious Cloud Instance Activities
- content: Web Fraud Detection
removed_in_version: 5.2.0
reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity