Product News & Announcements
All the latest news and announcements about Splunk products. Subscribe and never miss an update!

Enterprise Security Content Update (ESCU) | New Releases

TyneDarke
Splunk Employee
Splunk Employee

In the last month, the Splunk Threat Research Team has had 2 releases of new security content via the Enterprise Security Content Update (ESCU) app (v4.17.0 and v4.18.0). With these releases, there are 51 new analytics, 5 new analytic stories, 18 updated analytics, and 4 updated analytic stories now available in Splunk Enterprise Security via the ESCU application update process.

Content highlights include:

  • The "Office 365 Persistence Mechanisms" analytic story includes a group of detections that delve into attackers' tactics and techniques to maintain prolonged unauthorized access within the O365 environment. Persistence in this context refers to adversaries' methods to keep their foothold after an initial compromise.
  • The "Windows Attack Surface Reduction" analytic story includes a group of detections for Attack Surface Reduction (ASR) events. ASR is a feature of Windows Defender Exploit Guard that prevents actions and apps that are typically used by exploit-seeking malware to infect machines. When an action is blocked by an ASR rule, an event is generated.
  • The "Kubernetes Security" analytic story encompasses a range of detections that highlight the escalating challenges when securing containerized environments. Key detections include Kubernetes Abuse of Secret by Unusual Location, User Agent, User Group, and Username, which pinpoints attempts to exploit secrets via anomalous parameters.
  • Four new analytics delve into the intricacies of MFA security in the PingID environment. These detections, contributed by @nterl0k, cover scenarios like Mismatch Auth Source and Verification Response, Multiple Failed MFA Requests, New MFA Method Post-Credential Reset, and Registration of New MFA Methods, highlighting the evolving landscape of digital authentication security.

New Analytics (51)

New Analytic Stories (5)

Updated Analytics (18)

Updated Analytic Stories (4)

The team has also published the following blogs:

For all our tools and security content, please visit research.splunk.com

— The Splunk Threat Research Team

Get Updates on the Splunk Community!

.conf25 Registration is OPEN!

Ready. Set. Splunk! Your favorite Splunk user event is back and better than ever. Get ready for more technical ...

Detecting Cross-Channel Fraud with Splunk

This article is the final installment in our three-part series exploring fraud detection techniques using ...

Splunk at Cisco Live 2025: Learning, Innovation, and a Little Bit of Mr. Brightside

Pack your bags (and maybe your dancing shoes)—Cisco Live is heading to San Diego, June 8–12, 2025, and Splunk ...