Product News & Announcements
All the latest news and announcements about Splunk products. Subscribe and never miss an update!

Enterprise Security Content Update (ESCU) | New Releases

TyneDarke
Splunk Employee
Splunk Employee

In September, the Splunk Threat Research Team had two releases of new security content via the Enterprise Security Content Update (ESCU) app (v4.40.0 and v4.41.0). With these releases, there are 58 new analytics, 4 new analytic stories, and 81 updated analytics now available in Splunk Enterprise Security via the ESCU application update process.

Content highlights include:

  • The new analytic story “Compromised Linux Host” introduces a robust set of 50 detections for compromised Linux hosts, covering a wide range of activities such as unauthorized account creation, file ownership changes, kernel module modifications, privilege escalation, data destruction, and suspicious service stoppages, enhancing visibility into potential malicious actions and system tampering.
  • We have tagged existing analytics related to Black Suit ransomware TTPs into a new “BlackSuit Ransomware” analytic story, providing organizations with targeted threat detection capabilities to identify and mitigate ransomware attacks before they can cause significant damage.
  • The ValleyRAT analytic story includes new detections tailored to the ValleyRAT malware, providing enhanced monitoring and threat-hunting capabilities for adversarial activity on Windows systems. These detections improve visibility into malicious registry changes, task scheduling anomalies, and suspicious executable behavior.

New Analytics (58)

New Analytic Stories (4)

Updated Analytics (81)

The team also published the following 4 blogs:

For all our tools and security content, please visit research.splunk.com.

— The Splunk Threat Research Team

Get Updates on the Splunk Community!

SOCin’ it to you at Splunk University

Splunk University is expanding its instructor-led learning portfolio with dedicated Security tracks at .conf25 ...

Credit Card Data Protection & PCI Compliance with Splunk Edge Processor

Organizations handling credit card transactions know that PCI DSS compliance is both critical and complex. The ...

Stay Connected: Your Guide to July Tech Talks, Office Hours, and Webinars!

What are Community Office Hours?Community Office Hours is an interactive 60-minute Zoom series where ...