Splunk removed several Windows-focused detections from its Threat Research content library and Enterprise Security workflows, citing renamed analytics, overly broad logic, excessive noise, or reduced effectiveness against current attacker tradecraft. The retired content covered local administrator account creation with net.exe, domain and local account discovery, domain and privileged group enumeration, Excel spawning PowerShell, Mimikatz-related credential dumping, and an Investigation for pass-the-hash activity based on Windows Event ID 4624 with Logon_Type 9. Splunk said most of the detections were removed in content library version 5.2.0, while the pass-the-hash investigation was dropped because Enterprise Security 8.0 no longer supports Investigations.
The affected detections mapped to common ATT&CK behaviors including T1136.001 (local account creation), T1087.001 and T1087.002 (account discovery), T1069.002 (domain group discovery), T1003.001 (LSASS memory), and pass-the-hash activity involving dumped NTLM credentials. The changes reflect the difficulty of reliably detecting Windows credential access and reconnaissance techniques that remain widely used by threat actors, including SAM hive dumping (T1003.002) with tools such as Mimikatz, Impacket/SecretsDump, CrackMapExec, and Cobalt Strike, as documented by MITRE ATT&CK. Splunk directed users to newer replacements such as Windows Create Local Administrator Account Via Net, Windows User Discovery Via Net, Windows Group Discovery Via Net, Windows Sensitive Group Discovery With Net, and Windows Office Product Spawned Uncommon Process.

See real exploitation activity before you spend the cycle.
59 events from the most recent confirmed update back to the earliest known activity.
Splunk Threat Research removed the hunting detection 'Suspicious Rundll32 Rename' from its content library in version 5.2.0 because it no longer effectively identified the intended malicious activity. The removed-content page was updated on 2026-05-13 and documents the analytic's focus on detecting renamed rundll32.exe executions via PE metadata.
Splunk Threat Research removed the hunting detection 'Remote System Discovery with Net' from its content library in version 5.2.0 because it combined two separate and unrelated threat or action types. Splunk marked it as no longer maintained or supported and recommended replacement analytics including 'Windows Sensitive Group Discovery With Net.'
Splunk Threat Research removed the detection 'Windows connhost exe started forcefully' from its content library in version 5.2.0 because it no longer effectively identified the intended malicious activity. The removed-content page updated on 2026-05-13 says further testing showed the behavior was not specific to Ryuk and the detection was deprecated.
Splunk Threat Research removed the detection 'Processes created by netsh' from its content library in version 5.2.0 because it was updated to a new detection name. The removed-content page, updated on 2026-05-13, states the analytic is no longer maintained or supported.
Splunk Threat Research removed the detection 'Office Product Spawning BITSAdmin' from its content library in version 5.2.0 because it no longer effectively identified the intended malicious activity. Splunk listed 'Windows Office Product Spawned Uncommon Process' as the replacement detection, and the removed-content entry was updated on 2026-05-13.
Splunk Threat Research removed the detection 'Office Application Drop Executable' from its content library in version 5.2.0 because it was renamed and its logic was updated. Splunk listed 'Windows Office Product Dropped Uncommon File' as the replacement detection, and the removed-content page was updated on 2026-05-13.
Splunk Threat Research removed the detection 'Windows Office Product Spawning MSDT' from its content library in version 5.2.0 because it was renamed and its logic was updated. Splunk listed 'Windows Office Product Spawned MSDT' as the replacement detection, and the removed-content record was updated on 2026-05-13.
Splunk Threat Research removed the anomaly detection 'Windows Default RDP File Creation' from its content library in version 5.20.0 because detections were updated to use new search logic and field names. Splunk listed 'Windows Default RDP File Creation By Non MSTSC Process' as the replacement detection, and the removed-content entry was updated on 2026-05-13.
Splunk Threat Research removed the detection 'Windows Network Share Interaction With Net' from its content library because it was renamed and its logic was updated. Splunk listed 'Windows Network Share Interaction Via Net' as the replacement detection, and the removed-content entry was updated on 2026-05-13.
Splunk Threat Research removed the detection 'Windows MSIExec With Network Connections' from its content library in version 5.2.0 because it was renamed and its logic was updated. Splunk listed 'Windows HTTP Network Communication From MSIExec' as the replacement detection, and the removed-content entry was updated on 2026-05-13.
Splunk Threat Research removed the detection 'Windows Command Shell Fetch Env Variables' from its content library in version 5.2.0 because it was renamed and its logic was updated. Splunk listed 'Windows List ENV Variables Via SET Command From Uncommon Parent' as the replacement detection, and the removed-content entry was updated on 2026-05-13.
Splunk Threat Research removed the detection 'Reg exe used to hide files directories via registry keys' from its content library in version 5.2.0 because it no longer effectively identified the intended malicious activity. The removed-content entry was updated on 2026-05-13 and states the detection is no longer maintained or supported.
Splunk Threat Research removed the detection 'Windows Change Default File Association For No File Ext' from its content library in version 5.18.0 because it was deprecated and replaced with a better-named detection using more consistent logic. Splunk listed 'Windows Change File Association Command To Notepad' as the replacement detection, and the removed-content entry was updated on 2026-05-13.
Splunk Threat Research removed the anomaly detection 'Windows Set Private Network Profile via Registry' from its content library in version 5.18.0 because it was renamed for clarity and its logic was updated. Splunk listed 'Windows Set Network Profile Category to Private via Registry' as the replacement detection, and the removed-content page was updated on 2026-05-13.
Splunk Threat Research removed the detection 'Windows Java Spawning Shells' from its content library in version 5.20.0 and marked it as no longer maintained or supported. Splunk replaced it with the broader analytic 'Web or Application Server Spawning a Shell,' and the removed-content entry was updated on 2026-05-13.
Splunk Threat Research removed the detection 'Wmiprsve LOLBAS Execution Process Spawn' from its content library in version 5.20.0 because a typo in the title caused confusion. Splunk replaced it with the corrected detection name 'Wmiprvse LOLBAS Execution Process Spawn,' and the removed-content entry was updated on 2026-05-13.
Splunk Threat Research removed the anomaly detection 'Potentially malicious code on commandline' from its content library in version 5.26.0 because it no longer works with Splunk AI Toolkit 5.7.0 and Python for Scientific Computing for Linux 64-bit 4.3.0. The removed-content notice says the detection is no longer maintained or supported and was updated on 2026-05-13.
Splunk Threat Research removed the hunting detection 'Windows Remote Access Software Hunt' from its content library in version 5.8.0 and marked it as no longer maintained or supported. Splunk listed 'Detect Remote Access Software Usage Process' as the replacement analytic, and the removed-content page was updated on 2026-05-13.
Splunk Threat Research removed the detection 'Windows Service Created Within Public Path' from its content library in version 5.6.0 because it was replaced by a more specifically named analytic. Splunk listed 'Windows Service Created with Suspicious Service Path' as the replacement detection, and the removed-content page was updated on 2026-05-13.
Splunk Threat Research removed the detection 'Windows AD Suspicious GPO Modification' from its content library in version 5.10.0 because it was deprecated due to insufficient data quality and consistency. The removed-content record updated on 2026-05-13 says the detection is no longer maintained or supported and notes research is underway on a possible future replacement.
Splunk Threat Research removed the detection 'Office Product Spawning Rundll32 with no DLL' from its content library in version 5.2.0 because it was renamed and its logic was updated. Splunk listed 'Windows Office Product Spawned Rundll32 With No DLL' as the replacement detection, and the removed-content entry was updated on 2026-05-13.
Splunk Threat Research removed the detection 'Office Document Spawned Child Process To Download' from its content library in version 5.2.0 because it was renamed and its logic was updated. Splunk listed 'Windows Office Product Spawned Child Process For Download' as the replacement detection, and the removed-content entry was updated on 2026-05-13.
Splunk Threat Research removed the hunting detection 'Windows DLL Search Order Hijacking Hunt' from its content library in version 5.2.0 because the detection was updated to use new search logic and field names following a TA update. Splunk listed 'Windows DLL Search Order Hijacking Hunt with Sysmon' as the replacement detection, and the removed-content page was updated on 2026-05-13.
Splunk Threat Research removed the hunting detection 'Windows Modify Registry Reg Restore' from its content library in version 5.2.0 because it was renamed and its logic was updated. Splunk listed 'Windows Registry Entries Restored Via Reg' as the replacement detection, and the removed-content entry was updated on 2026-05-13.
Splunk Threat Research removed the hunting detection 'Windows Query Registry Reg Save' from its content library in version 5.2.0 because it was renamed and its logic was updated. Splunk listed 'Windows Registry Entries Exported Via Reg' as the replacement detection, and the removed-content entry was updated on 2026-05-13.
Splunk Threat Research removed the detection 'Windows Valid Account With Never Expires Password' from its content library in version 5.2.0 because it was renamed and its logic was updated. Splunk listed 'Windows Set Account Password Policy To Unlimited Via Net' as the replacement detection, and the removed-content entry was updated on 2026-05-13.
Splunk Threat Research removed the hunting detection 'Password Policy Discovery with Net' from its content library in version 5.2.0 because it was renamed and its logic was updated. Splunk listed 'Windows Password Policy Discovery with Net' as the replacement detection, and the removed-content page was updated on 2026-05-13.
Splunk Threat Research removed the detection 'Office Document Executing Macro Code' from its content library in version 5.2.0 because it was renamed and its logic was updated. Splunk listed 'Windows Office Product Loading VBE7 DLL' as the replacement detection, and the removed-content page was published on 2026-05-13.
Splunk Threat Research removed the detection 'Office Document Creating Schedule Task' from its content library in version 5.2.0 because it was renamed and its logic was updated. Splunk listed 'Windows Office Product Loading Taskschd DLL' as the replacement detection, and the removed-content page was published on 2026-05-13.
Splunk Threat Research removed the detection 'Scheduled tasks used in BadRabbit ransomware' from its content library in version 5.2.0 because it was updated to a new detection name. Splunk listed 'Scheduled Task Deleted Or Created via CMD' as the replacement detection, and the removed-content page was updated on 2026-05-13.
Splunk Threat Research removed the detection 'Remote Registry Key modifications' from its content library in version 5.2.0 because it no longer effectively identified the intended malicious activity. The removed-content page updated on 2026-05-13 says the logic was believed to be incorrect and notes the analytic could generate false positives from legitimate administrative activity.
Splunk Threat Research removed the detection 'Windows hosts file modification' from its content library in version 5.2.0 because it was deprecated and no longer effectively identified the intended malicious activity. The removed-content page was updated on 2026-05-13 and states the detection is no longer maintained or supported.
Splunk Threat Research removed the detection 'Remote Desktop Network Bruteforce' from its content library in version 5.4.0 because it no longer effectively identified the intended malicious activity. Splunk listed 'Windows Remote Desktop Network Bruteforce Attempt' as the replacement detection, and the removed-content page was published on 2026-05-13.
Splunk Threat Research removed the detection 'Suspicious Process File Path' from its content library in version 5.4.0 because it no longer effectively identified the intended malicious activity. Splunk listed 'Windows Suspicious Process File Path' as the replacement detection, and the removed-content entry was updated on 2026-05-13.
Splunk Threat Research removed the hunting detection 'Suspicious Event Log Service Behavior' from its content library in version 5.4.0 because it no longer effectively identified the intended malicious activity. Splunk listed 'Windows Event Logging Service Has Shutdown' as the replacement analytic.
Splunk Threat Research removed the detection 'Windows Lateral Tool Transfer RemCom' from its content library in version 5.2.0 because it was renamed. Splunk listed 'Windows Service Execution RemCom' as the replacement detection, and the removed-content page was updated on 2026-05-13.
Splunk Threat Research removed the detection 'Suspicious Changes to File Associations' from its content library in version 5.2.0 because it no longer effectively identified the intended malicious activity. The removed-content entry was updated on 2026-05-13 and documents the deprecation of this file-association persistence analytic.
Splunk Threat Research removed the hunting detection 'Suspicious File Write' from its content library in version 5.2.0 because it was deprecated and no longer effectively identified the intended malicious activity. The removed-content page was updated on 2026-05-13 and states the detection is no longer maintained or supported.
Splunk Threat Research removed the hunting detection 'Suspicious writes to System Volume Information' from its content library in version 5.2.0 because it was deprecated and no longer effectively identified the intended malicious activity. The removed-content record was updated on 2026-05-13 and states the detection is no longer maintained or supported.
Splunk Threat Research removed the hunting detection 'Prohibited Software On Endpoint' from its content library in version 5.2.0 because it no longer effectively identified the intended malicious activity. Splunk listed 'Attacker Tools On Endpoint' as the replacement detection, and the removed-content notice was updated on 2026-05-13.
Splunk Threat Research removed the hunting detection 'Uncommon Processes On Endpoint' from its content library in version 5.2.0 because it no longer effectively identified the intended malicious activity. Splunk listed 'Attacker Tools On Endpoint' as the replacement detection.
Splunk Threat Research removed the detection 'Office Application Spawn Regsvr32 process' from its content library in version 5.2.0 because it no longer effectively identified the intended malicious activity. Splunk listed 'Windows Office Product Spawned Uncommon Process' as the replacement detection, and the removed-content notice records the removal on 2026-05-13.
Splunk Threat Research removed the detection 'Office Product Spawning Windows Script Host' from its content library in version 5.2.0 because it no longer effectively identified the intended malicious activity. Splunk listed 'Windows Office Product Spawned Uncommon Process' as the replacement detection.
Splunk Threat Research removed the detection 'Office Product Spawning Wmic' from its content library in version 5.2.0 because it no longer effectively identified the intended malicious activity. Splunk listed 'Windows Office Product Spawned Uncommon Process' as the replacement detection, and the removed-content entry was updated on 2026-05-13.
Splunk Threat Research removed the detection 'Winword Spawning PowerShell' from its content library in version 5.2.0 because it no longer effectively identified the intended malicious activity. Splunk listed 'Windows Office Product Spawned Uncommon Process' as the replacement detection, and the removed-content entry was updated on 2026-05-13.
Splunk Threat Research removed the detection 'Winword Spawning Cmd' from its content library in version 5.2.0 because it no longer effectively identified the intended malicious activity. Splunk listed 'Windows Office Product Spawned Uncommon Process' as the replacement detection, and the removed-content entry was updated on 2026-05-13.
Splunk Threat Research removed the detection 'Office Product Spawn CMD Process' from its content library in version 5.2.0 because it no longer effectively identified the intended malicious activity. Splunk listed 'Windows Office Product Spawned Uncommon Process' as the replacement detection, and the removed-content entry was updated on 2026-05-13.
Splunk Threat Research removed the detection 'Office Application Spawn rundll32 process' from its content library in version 5.2.0 because it no longer effectively identified the intended malicious activity. Splunk listed 'Windows Office Product Spawned Uncommon Process' as the replacement detection, and the removed-content notice was updated on 2026-05-13.
Splunk Threat Research removed the detection 'Office Product Spawning MSHTA' from its content library in version 5.2.0 because it no longer effectively identified the intended malicious activity. Splunk listed 'Windows Office Product Spawned Uncommon Process' as the replacement detection.
On 2026-05-13, Splunk updated the removed-content pages for the deprecated detections and investigation. The pages document the removals, reasons such as renaming, logic updates, ineffective detection, or end of Investigation support in Splunk Enterprise Security 8.0, and list replacement analytics where applicable.
Horizon3.ai reported successfully reproducing exploitation of ManageEngine CVE-2022-47966 and published indicators of compromise and log-based detection guidance for affected products, including ServiceDesk Plus and Endpoint Central. The post highlighted that exploitation can yield pre-authentication RCE as NT AUTHORITY\SYSTEM when SAML had been enabled and urged immediate patching.
FortiGuard Labs reported a campaign leveraging Microsoft Office documents to deliver the Agent Tesla infostealer and njRat remote access trojan. The report adds technical details on a distinct malware delivery chain and victimization pattern separate from Fortinet's earlier Remcos RAT phishing analysis.
The DFIR Report published an incident analysis of threat actors exploiting Zoho ManageEngine CVE-2021-44077 from Tor exit nodes, deploying an fm2.jsp web shell and a malicious binary masquerading as msiexec.exe. The intrusion involved Plink-based RDP tunneling, credential-access activity, and exfiltration of confidential data before the actors were evicted, and the report released IOCs, Sigma rules, and YARA rules.
The DFIR Report analyzed a June 2022 intrusion in which a malspam-delivered LNK file launched PowerShell to install Emotet, which later dropped Cobalt Strike and enabled lateral movement, credential access, Tactical RMM and AnyDesk persistence, and Rclone exfiltration to Mega. After eight days of activity across the domain, the attackers deployed Quantum ransomware over SMB using locker.dll and a batch script, and the report published associated infrastructure, tooling, and file indicators.
DoublePulsar published reporting on the Follina Microsoft Office code execution vulnerability, adding technical details on a distinct Office exploitation issue. This is separate from the existing timeline's phishing and malware-delivery campaigns involving Office documents.
FortiGuard Labs reported a phishing campaign targeting Windows users with a password-protected Excel attachment masquerading as a bank payment notice, leading to multi-stage VBS and PowerShell execution and Remcos RAT deployment via process hollowing into RegAsm.exe. The report analyzed Remcos RAT 3.4.0 Pro and published technical details on its configuration, encryption, command set, C2 behavior, and indicators of compromise.
The DFIR Report analyzed an April 2022 intrusion in which attackers likely used a phishing-delivered ZIP/ISO/LNK chain to deploy the BumbleBee loader, followed by Cobalt Strike, RDP, and AnyDesk for access and persistence. Over an 11-day dwell period, the actors performed discovery, dumped LSASS, executed kerberoasting, and used a Domain Admin-capable service account to move laterally to a Domain Controller before defenders evicted them prior to ransomware deployment, exfiltration, or encryption.
Netlab 360 reported that ten families of malicious samples were actively spreading by exploiting the Log4j2 vulnerability. The report documented in-the-wild abuse of the flaw as attackers rapidly adopted it for malware delivery.
Splunk removed several Threat Research detections and one investigation from its content library in version 5.2.0. The affected items include detections for local admin creation, Mimikatz image loads, domain and local account/group discovery via net, Excel spawning PowerShell, and the "Investigate Pass the Hash Attempts" investigation.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 1,035 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
50 references tracked. Mallory keeps watching after this page renders.
research.splunk.com
Open sourceresearch.splunk.com
Open sourceresearch.splunk.com
Open sourceresearch.splunk.com
Open sourceattack.mitre.org
Open sourceattack.mitre.org
Open sourceattack.mitre.org
Open sourceattack.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.