Product News & Announcements
All the latest news and announcements about Splunk products. Subscribe and never miss an update!

Enterprise Security Content Update (ESCU) | New Releases

TyneDarke
Splunk Employee
Splunk Employee

In October, the Splunk Threat Research Team had one release of new security content via the Enterprise Security Content Update (ESCU) app (v4.42.0). With this release, there are 10 new analytics, 15 updated analytics, and 1 updated analytic story now available in Splunk Enterprise Security via the ESCU application update process.

Content highlights include:

  • The CISA AA24-241A analytic story was updated with detections tailored to identify malicious usage of PowerShell Web Access in Windows environments. The new detections focus on monitoring PowerShell Web Access activity through the IIS application pool and web access logs, providing enhanced visibility into suspicious or unauthorized access.
  • The Splunk Threat Research Team also updated the security content repository on research.splunk.com to better help security teams find the most relevant content for their organizations, understand how individual detections operate, and stay up-to-date on the latest releases. For more details, check out this blog: Fueling the SOC of the Future with Built-in Threat Research and Detections in Splunk Enterprise Secu....

New Analytics (10)

Updated Analytics (15)

Updated Analytic Stories (1)

The team also published the following 4 blogs:

For all our tools and security content, please visit research.splunk.com.

— The Splunk Threat Research Team

Get Updates on the Splunk Community!

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...