Product News & Announcements
All the latest news and announcements about Splunk products. Subscribe and never miss an update!

Enterprise Security Content Update (ESCU) | New Releases

TyneDarke
Splunk Employee
Splunk Employee

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security Content Update (ESCU) app (v4.44.0). With this release, there are 8 new analytics, 3 new analytic stories, and 261 updated analytics now available in Splunk Enterprise Security via the ESCU application update process.

Content highlights include:

  • The new Lumma Stealer analytics story includes detections related to this information-stealing malware, which leverages several obfuscation techniques like base64 encoding and clipboard manipulation to evade detection.
  • The new Meduza Stealer analytics story includes detections designed to help identify activity related to this stealer, a relatively new threat that was first identified in 2023 and targets sensitive information like login credentials and financial details.
  • The new PAX Stealer analytics story features detections to help identify this data-stealing malware, which is especially stealthy as it’s able to evade antivirus software.

New Analytics (8)

New Analytic Stories (3)

Updated Analytics (261)

A number of analytics have been updated to address minor typos in the description field, make use of macros, or capture equivalent variants of commands.

For all our tools and security content, please visit research.splunk.com.

— The Splunk Threat Research Team

Contributors
Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...