Product News & Announcements
All the latest news and announcements about Splunk products. Subscribe and never miss an update!

Enterprise Security Content Update (ESCU) | New Releases

TyneDarke
Splunk Employee
Splunk Employee

In June, the Splunk Threat Research Team had 2 releases of new security content via the Enterprise Security Content Update (ESCU) app (v4.33.0 and v4.34.0). With these releases, there are 3 new analytics, 2 new analytic stories, and 10 updated analytics now available in Splunk Enterprise Security via the ESCU application update process.

Content highlights include:

  • The new CrushFTP Vulnerabilities analytic story includes content to help identify indicators of CVE-2024-4040 exploitation. To learn more about this vulnerability and how to use Splunk to identify and investigate CVE-2024-4040, check out this blog.
  • The new Gomir analytic story includes detections that help security analysts identify and investigate unusual activities associated with the Gomir backdoor malware.
  • The team also updated over 1,200 analytics descriptions for stylistic changes and improved readability.

New Analytics (3)

New Analytic Stories (2)

Updated Analytics (10)

The team also published the following 4 blogs:

For all our tools and security content, please visit research.splunk.com.

— The Splunk Threat Research Team

Get Updates on the Splunk Community!

Developer Spotlight with Brett Adams

In our third Spotlight feature, we're excited to shine a light on Brett—a Splunk consultant, innovative ...

Index This | What can you do to make 55,555 equal 500?

April 2025 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...

Say goodbye to manually analyzing phishing and malware threats with Splunk Attack ...

In today’s evolving threat landscape, we understand you’re constantly bombarded with phishing and malware ...