Product News & Announcements
All the latest news and announcements about Splunk products. Subscribe and never miss an update!

Enterprise Security Content Update (ESCU) | New Releases

TyneDarke
Splunk Employee
Splunk Employee

In November, the Splunk Threat Research Team had one release of new security content via the Enterprise Security Content Update (ESCU) app (v4.43.0). With this release, there are 2 new analytic stories and 9 new analytics now available in Splunk Enterprise Security via the ESCU application update process.

Content highlights include:

  • Braodo Stealer analytics story: This includes detections to help identify the Braodo Stealer malware, which is designed to steal sensitive information like credentials, cookies, and system data. To learn more about Braodo Stealer and the detections included in this analytics story, check out the team’s blog ”Cracking Braodo Stealer: Analyzing Python Malware and Its Obfuscated Loader.”
  • Enhanced drilldowns: In addition, all TTP or Anomaly and Correlation type detections have had two drilldowns added to their yaml files. The drilldowns let users view detection results for specific risk objects and access risk events from the past 7 days.

New Analytic Stories (2)

New Analytics (9)

The team also published the following 4 blogs:

For all our tools and security content, please visit research.splunk.com.

— The Splunk Threat Research Team

Get Updates on the Splunk Community!

Developer Spotlight with Paul Stout

Welcome to our very first developer spotlight release series where we'll feature some awesome Splunk ...

State of Splunk Careers 2024: Maximizing Career Outcomes and the Continued Value of ...

For the past four years, Splunk has partnered with Enterprise Strategy Group to conduct a survey that gauges ...

Data-Driven Success: Splunk & Financial Services

Splunk streamlines the process of extracting insights from large volumes of data. In this fast-paced world, ...