Product News & Announcements
All the latest news and announcements about Splunk products. Subscribe and never miss an update!

Enterprise Security Content Update (ESCU) | New Releases

TyneDarke
Splunk Employee
Splunk Employee

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security Content Update (ESCU) app (v4.44.0). With this release, there are 8 new analytics, 3 new analytic stories, and 261 updated analytics now available in Splunk Enterprise Security via the ESCU application update process.

Content highlights include:

  • The new Lumma Stealer analytics story includes detections related to this information-stealing malware, which leverages several obfuscation techniques like base64 encoding and clipboard manipulation to evade detection.
  • The new Meduza Stealer analytics story includes detections designed to help identify activity related to this stealer, a relatively new threat that was first identified in 2023 and targets sensitive information like login credentials and financial details.
  • The new PAX Stealer analytics story features detections to help identify this data-stealing malware, which is especially stealthy as it’s able to evade antivirus software.

New Analytics (8)

New Analytic Stories (3)

Updated Analytics (261)

A number of analytics have been updated to address minor typos in the description field, make use of macros, or capture equivalent variants of commands.

For all our tools and security content, please visit research.splunk.com.

— The Splunk Threat Research Team

Get Updates on the Splunk Community!

Splunk Observability Cloud's AI Assistant in Action Series: Auditing Compliance and ...

This is the third post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how to ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

What You Read The Most: Splunk Lantern’s Most Popular Articles!

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...