Skip to content

Commit 5fa7311

Browse files
authored
Merge pull request #3567 from splunk/bump_version_5_8_0
Bump ESCU to 5.8.0
2 parents 6ca51e1 + 81efb27 commit 5fa7311

5 files changed

+5
-5
lines changed

contentctl.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -3,7 +3,7 @@ app:
33
uid: 3449
44
title: ES Content Updates
55
appid: DA-ESS-ContentUpdate
6-
version: 5.7.0
6+
version: 5.8.0
77
description: Explore the Analytic Stories included with ES Content Updates.
88
prefix: ESCU
99
label: ESCU

detections/deprecated/certutil_download_with_urlcache_and_split_arguments.yml renamed to removed/detections/certutil_download_with_urlcache_and_split_arguments.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -3,7 +3,7 @@ id: 415b4306-8bfb-11eb-85c4-acde48001122
33
version: 13
44
date: '2025-05-02'
55
author: Michael Haag, Splunk
6-
status: deprecated
6+
status: removed
77
type: TTP
88
description: This analytic has been deprecated in favor of "Windows CertUtil Download".
99
The following analytic detects the use of certutil.exe to download files

detections/deprecated/certutil_download_with_verifyctl_and_split_arguments.yml renamed to removed/detections/certutil_download_with_verifyctl_and_split_arguments.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -3,7 +3,7 @@ id: 801ad9e4-8bfb-11eb-8b31-acde48001122
33
version: 13
44
date: '2025-05-02'
55
author: Michael Haag, Splunk
6-
status: deprecated
6+
status: removed
77
type: TTP
88
description: This analytic has been deprecated in favor of "Windows CertUtil Download".
99
The following analytic detects the use of `certutil.exe` to download

detections/deprecated/windows_certutil_download_with_url_argument.yml renamed to removed/detections/windows_certutil_download_with_url_argument.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -3,7 +3,7 @@ id: 4fc5ca00-4c7c-46b3-8772-c98a4b8bd944
33
version: 6
44
date: '2025-05-02'
55
author: Nasreddine Bencherchali, Splunk
6-
status: deprecated
6+
status: removed
77
type: TTP
88
description: This analytic has been deprecated in favor of "Windows CertUtil Download".
99
The following analytic detects the use of `certutil.exe` to download

detections/deprecated/windows_remote_access_software_hunt.yml renamed to removed/detections/windows_remote_access_software_hunt.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -3,7 +3,7 @@ id: 8bd22c9f-05a2-4db1-b131-29271f28cb0a
33
version: 8
44
date: '2025-05-02'
55
author: Michael Haag, Splunk
6-
status: deprecated
6+
status: removed
77
type: Hunting
88
description: This search is deprecated in favor of the new detection - Detect Remote Access Software Usage Process. The following analytic identifies the use of remote access software within
99
the environment. It leverages data from Endpoint Detection and Response (EDR) agents,

0 commit comments

Comments
 (0)