Product News & Announcements
All the latest news and announcements about Splunk products. Subscribe and never miss an update!

Enterprise Security Content Update (ESCU) | New Releases

TyneDarke
Splunk Employee
Splunk Employee

In June, the Splunk Threat Research Team had 2 releases of new security content via the Enterprise Security Content Update (ESCU) app (v4.33.0 and v4.34.0). With these releases, there are 3 new analytics, 2 new analytic stories, and 10 updated analytics now available in Splunk Enterprise Security via the ESCU application update process.

Content highlights include:

  • The new CrushFTP Vulnerabilities analytic story includes content to help identify indicators of CVE-2024-4040 exploitation. To learn more about this vulnerability and how to use Splunk to identify and investigate CVE-2024-4040, check out this blog.
  • The new Gomir analytic story includes detections that help security analysts identify and investigate unusual activities associated with the Gomir backdoor malware.
  • The team also updated over 1,200 analytics descriptions for stylistic changes and improved readability.

New Analytics (3)

New Analytic Stories (2)

Updated Analytics (10)

The team also published the following 4 blogs:

For all our tools and security content, please visit research.splunk.com.

— The Splunk Threat Research Team

Contributors
Get Updates on the Splunk Community!

Your Guide to Splunk Digital Experience Monitoring

A flawless digital experience isn't just an advantage, it's key to customer loyalty and business success. But ...

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...