Product News & Announcements
All the latest news and announcements about Splunk products. Subscribe and never miss an update!

Enterprise Security Content Update (ESCU) | New Releases

OliviaHenderson
Splunk Employee
Splunk Employee

In the last month, the Splunk Threat Research Team (STRT) has had 1 release of new security content via the Enterprise Security Content Update (ESCU) app (v4.12.0.). With this release, there are 8 new detections and 1 new analytic story now available in Splunk Enterprise Security via the ESCU application update process.

Content highlights include:

  • A Forest Blizzard analytic story that contains detections to detect “Living Off The Land” attack techniques using headless web browsers to exfiltrate data files through legitimate platforms like Mockbin via ZIP archives containing LNK files. These techniques were observed in the cyberattack on Ukraine’s energy infrastructure, orchestrated via deceptive emails to steal NTLMv2 hashes by various advanced persistent threat (APT) groups.
  • Six new detections related to Windows Active Directory enumeration, specifically to detect activity related to the usage of a popular red team tool such as Powerview, which are typically used for reconnaissance by attackers. 

New Analytic Story: 

New Detections:

The team has also published the following blogs:

For all our tools and security content, please visit research.splunk.com

— The Splunk Threat Research Team

Get Updates on the Splunk Community!

Index This | I’m short for "configuration file.” What am I?

May 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with a Special ...

New Articles from Academic Learning Partners, Help Expand Lantern’s Use Case Library, ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Your Guide to SPL2 at .conf24!

So, you’re headed to .conf24? You’re in for a good time. Las Vegas weather is just *chef’s kiss* beautiful in ...