Skip to content

Add New Analytics - February Batch#3886

Open
nasbench wants to merge 11 commits intodevelopfrom
new_rules_feb
Open

Add New Analytics - February Batch#3886
nasbench wants to merge 11 commits intodevelopfrom
new_rules_feb

Conversation

@nasbench
Copy link
Contributor

@nasbench nasbench commented Feb 2, 2026

This PR introduces a couple new analytics as well as update/fixes. Below are some details

New Analytics [3]

  • Curl Execution with Percent Encoded URL
  • Cisco SD-WAN - Low Frequency Rogue Peer
  • Cisco SD-WAN - Peering Activity

Updated Analytics [7]

  • Cisco NVM - Non-Network Binary Making Network Connection - Add new entry for win32calc.exe
  • LOLBAS With Network Traffic - Fix an a big introduced in the previous release where the filter was missing the field name. So instead of using All_Traffic we now use All_Traffic.dest_ip (the reason for dest_ip is to ensure an IP is being used).
  • Windows DLL Side-Loading In Calc - Enhanced metadata to reflect the logic and reasoning behind the rule. This is also to address issue [BUG] Issue with calc.exe detections #3916. Also added an explicit WindowsCodecs.dll entry for the loaded DLL.
  • Windows DLL Side-Loading Process Child Of Calc - Enhanced metadata to reflect the logic and reasoning behind the rule. This is also to address issue [BUG] Issue with calc.exe detections #3916.
  • Windows Process Injection into Commonly Abused Processes - Add new entries for CalculatorApp.exe and win32calc.exe
  • Windows Process Injection Remote Thread - Add new entries for CalculatorApp.exe and win32calc.exe
  • Windows Suspicious React or Next.js Child Process - Add new entries for CalculatorApp.exe and win32calc.exe

New Macros [1]

  • cisco_sd_wan_syslog

New Analytic Stories [1]

  • Cisco Catalyst SD-WAN Analytics

@nasbench nasbench added this to the v5.22.0 milestone Feb 2, 2026
@nasbench nasbench modified the milestones: v5.22.0, v5.23.0 Feb 17, 2026
@nasbench nasbench linked an issue Feb 23, 2026 that may be closed by this pull request
@nasbench nasbench marked this pull request as ready for review March 2, 2026 03:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[BUG] Issue with calc.exe detections

1 participant