Skip to content

v5.12.0

Choose a tag to compare

@patel-bhavin patel-bhavin released this 20 Aug 20:49
· 267 commits to develop since this release
6826018

πŸš€ Key Highlights

πŸ›‘οΈ Medusa Rootkit (UNC3886): Introduced a new analytic story for Medusa Rootkit, a stealthy malware leveraged by UNC3886 to maintain persistence on Linux 🐧 and Windows πŸͺŸ systems. This release adds detections for Linux GDrive Binary Activity, Linux Medusa Rootkit, Windows GDrive Binary Activity, and Windows Suspicious VMware Tools Child Process, while also mapping other existing detections to this threat actor.

πŸ“¦ MSIX Package Abuse: We added a new analytic story covering abuse of Microsoft MSIX application packages, leveraging telemetry from AppXDeploymentServer/Operational logs πŸ“‘. This story introduces detections for suspicious MSIX behaviors, including Windows Advanced Installer MSIX with AI_STUBS Execution, Unsigned Package Installation, PowerShell MSIX Package Installation, and interactions with Windows Apps directories πŸ“‚, providing visibility into application sideloading and potential malware delivery.

πŸ–₯️ Windows RDP Artifacts & Defense Evasion: A new analytic story focused on RDP activity πŸ’» followed by artifact cleanup 🧹 or evasion techniques. Windows RDP usage generates forensic artifacts such as Default.rdp files πŸ“„ and bitmap caches πŸ–ΌοΈ that can reveal details about accessed systems. This release adds detections for RDP file creation, deletion, and un-hiding events, bitmap cache file activity, RDP server registry entry creation/deletion, and RDP client launched with admin session, while tagging existing detections to ensure comprehensive monitoring of both RDP usage and evasion behavior.


πŸ“š New Analytic Stories – [3]

♻️ Updated Analytic Story – [1]

πŸ†• New Analytics – [22]


⚠️ Other Updates

As previously communicated in the ESCU v5.10.0 release, several detections have been removed.
For a complete list of the detections removed in version v5.12.0, refer to the List of Removed Detections.

Additionally, a new set of detections has been deprecated.
For details on detections scheduled for removal in ESCU v5.14.0, see the List of Detections Scheduled for Removal.