Product News & Announcements
All the latest news and announcements about Splunk products. Subscribe and never miss an update!

Enterprise Security Content Update (ESCU) | New Releases

TyneDarke
Splunk Employee
Splunk Employee

In October, the Splunk Threat Research Team had one release of new security content via the Enterprise Security Content Update (ESCU) app (v4.42.0). With this release, there are 10 new analytics, 15 updated analytics, and 1 updated analytic story now available in Splunk Enterprise Security via the ESCU application update process.

Content highlights include:

  • The CISA AA24-241A analytic story was updated with detections tailored to identify malicious usage of PowerShell Web Access in Windows environments. The new detections focus on monitoring PowerShell Web Access activity through the IIS application pool and web access logs, providing enhanced visibility into suspicious or unauthorized access.
  • The Splunk Threat Research Team also updated the security content repository on research.splunk.com to better help security teams find the most relevant content for their organizations, understand how individual detections operate, and stay up-to-date on the latest releases. For more details, check out this blog: Fueling the SOC of the Future with Built-in Threat Research and Detections in Splunk Enterprise Secu....

New Analytics (10)

Updated Analytics (15)

Updated Analytic Stories (1)

The team also published the following 4 blogs:

For all our tools and security content, please visit research.splunk.com.

— The Splunk Threat Research Team

Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...