Product News & Announcements
All the latest news and announcements about Splunk products. Subscribe and never miss an update!

Enterprise Security Content Update (ESCU) | New Releases

TyneDarke
Splunk Employee
Splunk Employee

In November, the Splunk Threat Research Team had one release of new security content via the Enterprise Security Content Update (ESCU) app (v4.43.0). With this release, there are 2 new analytic stories and 9 new analytics now available in Splunk Enterprise Security via the ESCU application update process.

Content highlights include:

  • Braodo Stealer analytics story: This includes detections to help identify the Braodo Stealer malware, which is designed to steal sensitive information like credentials, cookies, and system data. To learn more about Braodo Stealer and the detections included in this analytics story, check out the team’s blog ”Cracking Braodo Stealer: Analyzing Python Malware and Its Obfuscated Loader.”
  • Enhanced drilldowns: In addition, all TTP or Anomaly and Correlation type detections have had two drilldowns added to their yaml files. The drilldowns let users view detection results for specific risk objects and access risk events from the past 7 days.

New Analytic Stories (2)

New Analytics (9)

The team also published the following 4 blogs:

For all our tools and security content, please visit research.splunk.com.

— The Splunk Threat Research Team

Contributors
Get Updates on the Splunk Community!

Splunk Enterprise Security: Your Command Center for PCI DSS Compliance

Every security professional knows the drill. The PCI DSS audit is approaching, and suddenly everyone's asking ...

Developer Spotlight with Guilhem Marchand

From Splunk Engineer to Founder: The Journey Behind TrackMe    After spending over 12 years working full time ...

Cisco Catalyst Center Meets Splunk ITSI: From 'Payments Are Down' to Root Cause in ...

The Problem: When Networks and Services Don't Talk Payment systems fail at a retail location. Customers are ...