Product News & Announcements
All the latest news and announcements about Splunk products. Subscribe and never miss an update!

Enterprise Security Content Update (ESCU) | New Releases

cwopat
Splunk Employee
Splunk Employee

In the last month, the Splunk Threat Research Team (STRT) has had 3 releases of new security content via the Enterprise Security Content Update (ESCU) app (v4.3.0, v4.4.0, and v4.5.0). With these releases, there are 27 new detections and 2 new analytic stories, and 1 updated analytic story now available in Splunk Enterprise Security via the ESCU application update process or via Splunk Security Essentials (SSE).

Content highlights include: 

  • Detections to help address the vulnerability in MOVEit Transfer software that is being actively exploited in the wild 
  • An advanced pre-trained deep learning model specifically engineered to discern and pinpoint instances of DNS-based exfiltration to accurately detect and flag potential data breaches or unauthorized information transfers
  • New and updated searches to detect living-off-the-land techniques being utilized by the threat actor group Volt Typhoon 

New Analytic Stories: 

New Detections: 

Updated Analytic Story: Splunk Vulnerabilities

For all our tools and security content, please visit research.splunk.com

The team has also published the following blogs in the last month:

— The Splunk Threat Research Team

Get Updates on the Splunk Community!

AppDynamics Summer Webinars

This summer, our mighty AppDynamics team is cooking up some delicious content on YouTube Live to satiate your ...

SOCin’ it to you at Splunk University

Splunk University is expanding its instructor-led learning portfolio with dedicated Security tracks at .conf25 ...

Credit Card Data Protection & PCI Compliance with Splunk Edge Processor

Organizations handling credit card transactions know that PCI DSS compliance is both critical and complex. The ...