Splunk Threat Research has removed several endpoint analytics from its Security Content library, retiring detections for chcp.com execution, account discovery with the Windows net utility, and execution of files padded with spaces before the extension. Splunk said the CHCP Command Execution analytic was deprecated because chcp.com alone is not inherently malicious, while Account Discovery With Net App was withdrawn due to overlap with other detections and replaced by Windows Excessive Usage Of Net App. The filename-obfuscation analytic was also removed and superseded by Execution of File with Multiple Extensions.
The retired rules had mapped to MITRE ATT&CK techniques T1087.002 for domain account discovery and T1036.003 for masquerading through renamed or disguised utilities. Those ATT&CK entries describe common adversary tradecraft including use of net user /domain, net group "Domain Admins" /domain, PowerShell AD cmdlets, and tools such as AdFind and BloodHound to enumerate domain accounts, as well as renaming or disguising legitimate binaries like rundll32.exe, mshta.exe, cmd.exe, and wscript.exe to evade detection. Splunk noted the removed analytics depended on endpoint process telemetry such as EDR and Sysmon data, were disabled by default, and could generate false positives from legitimate administrative activity.

See real exploitation activity before you spend the cycle.
5 events from the most recent confirmed update back to the earliest known activity.
Splunk Threat Research removed the 'CHCP Command Execution' detection from its content library and said it was no longer maintained or supported. Splunk stated the analytic was deprecated because execution of chcp.com by itself is not inherently malicious.
Splunk Threat Research removed the 'Windows Service Stop Via Net and SC Application' analytic from its content library, saying it no longer effectively identified the intended malicious activity. Splunk said the detection is no longer maintained or supported and noted the removal in version 5.2.0.
Splunk Threat Research removed the 'Execution of File With Spaces Before Extension' detection from its content library and marked it no longer maintained or supported. The entry says it was updated to the replacement detection 'Execution of File with Multiple Extensions.'
Splunk Threat Research removed the 'Account Discovery With Net App' analytic from its content library, said it was no longer maintained or supported, and replaced it with 'Windows Excessive Usage Of Net App.' Splunk said the detection was deprecated because it covered unrelated behaviors and overlapped with other detections.
Microsoft published technical details on Prestige ransomware activity affecting organizations in Ukraine and Poland. The post disclosed a distinct ransomware campaign and identified impacted countries, adding a new incident not reflected in the existing timeline.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
7 references tracked. Mallory keeps watching after this page renders.
research.splunk.com
Open sourceresearch.splunk.com
Open sourceresearch.splunk.com
Open sourceresearch.splunk.com
Open sourceattack.mitre.org
Open sourcemicrosoft.com
Open sourceattack.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.