mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
ec5cf468e3
This PR introduces comprehensive updates to our detection analytics, focusing on tagging relevant detections with the new "Seashell Blizzard" analytic story. The changes include: Version and date updates across 20 detection files, with dates standardized to '2025-03-24' or '2025-03-25', and version numbers incremented appropriately. Analytics tagged with "Seashell Blizzard" include: ConnectWise ScreenConnect vulnerability detections (authentication bypass, path traversal) Exchange Server exploitation detections (ProxyShell, ProxyNotShell, web shell) Credential access monitoring (LSASS dumps via TaskMgr and ProcDump) Remote access software usage detections (file, process, registry) Scheduled task abuse detections SQL Server xp_cmdshell configuration changes Registry hive dumping detection Key updates: - Added "Seashell Blizzard" tag to 20 existing detections These changes enhance our ability to track and detect activities associated with the Seashell Blizzard threat actor.