Splunk has removed several Enterprise Security detections that were built to identify abuse of risky Search Processing Language (SPL) commands, including "Splunk Command and Scripting Interpreter Risky SPL MLTK", "Detect Risky SPL using Pretrained ML Model", and "Splunk risky Command Abuse disclosed february 2023". The analytics monitored Splunk_Audit.Search_Activity data for ad hoc searches using commands such as collect, delete, fit, outputcsv, outputlookup, run, script, sendalert, sendemail, and tscollect, which could be abused to bypass warnings, escalate privileges, delete data, exfiltrate information, or support arbitrary code execution and persistence. Splunk said the detections were disabled by default and mapped to ATT&CK techniques including T1059, T1202, and T1548.
The retired content relied on the Machine Learning Toolkit (MLTK) and, in some cases, pretrained models or per-user baselines to flag anomalous long-running risky searches or suspicious command text. Splunk originally promoted the approach as a way to complement rule-based detections for exploitation tied to CVE-2022-32154 and later risky-command vulnerabilities, but the company has since withdrawn the analytics from its Threat Research library because the affected flaws have been patched in current Splunk releases. Splunk also noted operational drawbacks, including false positives from legitimate long-running searches and added compute requirements for model training in larger environments.

See real exploitation activity before you spend the cycle.
4 events from the most recent confirmed update back to the earliest known activity.
Splunk Threat Research removed the detection "Detect Risky SPL using Pretrained ML Model" from its content library and said it was no longer maintained because the associated CVEs had been patched in the latest Splunk release. The analytic had used a pretrained text classifier to score ad hoc SPL activity for suspicious risky commands.
Splunk Threat Research removed the detection "Splunk Command and Scripting Interpreter Risky SPL MLTK" in content library version 5.12.0 and said it was no longer maintained or supported. Splunk explained the detection was deprecated because it monitored regular Splunk commands that are not recommended to be used as a detection search.
Splunk Threat Research removed the detection "Splunk risky Command Abuse disclosed february 2023" from its content library, stating the associated CVEs had been patched in the latest Splunk release. The removed hunting analytic had targeted execution of high-risk commands tied to multiple Splunk vulnerability disclosures.
Splunk described an anomaly-detection approach for identifying abuse of risky SPL commands using audit log data and the Machine Learning Toolkit's DensityFunction algorithm. The blog said the corresponding ESCU detection was named "Splunk Command and Scripting Interpreter Risky SPL MLTK" and reported successful testing with implanted anomalies.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
5 references tracked. Mallory keeps watching after this page renders.
splunkbase.splunk.com
Open sourceresearch.splunk.com
Open sourceresearch.splunk.com
Open sourceresearch.splunk.com
Open sourcesplunk.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.