Product News & Announcements
All the latest news and announcements about Splunk products. Subscribe and never miss an update!

Enterprise Security Content Update (ESCU) | New Releases

cwopat
Splunk Employee
Splunk Employee

In the last month, the Splunk Threat Research Team (STRT) has had 2 releases of new security content via the Enterprise Security Content Update (ESCU) app (v4.1.0 and v4.2.0). With these releases, there are 61 new detections and 6 new analytic stories now available in Splunk Enterprise Security via the ESCU application update process or via Splunk Security Essentials (SSE).

Content highlights include: 

  • Azure Active Directory Privilege Escalation and AWS Exfiltration detections that help detect various new techniques used to gain higher-level permissions or exfiltrate data on systems
  • Detections to search for Snake Malware, a sophisticated espionage tool from Russia’s Federal Security Service (FSB), and its variants
  • Active Directory Privilege Escalations detections to detect techniques that adversaries use to gain higher-level permissions on a system or network that leverage Active Directory
  • Detections to search for adversaries leveraging RedLine Stealer malware
  • Windows Registry bootkit detections 
  • Remote Code Execution (RCE) detections in a commonly used printing software called PaperCut

New Analytic Stories: 

New Detections: 

The team has also published the following blogs in the last month:

For all our tools and security content, please visit research.splunk.com

— The Splunk Threat Research Team

Get Updates on the Splunk Community!

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...

Splunk App Developers | .conf25 Recap & What’s Next

If you stopped by the Builder Bar at .conf25 this year, thank you! The retro tech beer garden vibes were ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...