Product News & Announcements
All the latest news and announcements about Splunk products. Subscribe and never miss an update!

Enterprise Security Content Update (ESCU) | New Releases

TyneDarke
Splunk Employee
Splunk Employee

In January, the Splunk Threat Research Team had one release of new security content via the Splunk ES Content Update (ESCU) app (v5.0). With this release, there are 52 new analytics and 9 new analytic stories now available in Splunk Enterprise Security via the ESCU application update process — plus several new exciting enhancements.

Highlights include:

  • The team released new analytic stories designed to help identify activity related to various types of malware (i.e., Backdoor Pingpong, Crypto Stealer, Derusbi, WinDealer RAT, and XorDDos), specific threat actors (i.e., Earth Estries, Nexus), and other threats.
  • ESCU 5.0 introduces several enhancements designed to help further security operations. These include:
    • A revamped user interface and home page
    • A new Analytic Story Onboarding Assistant to help accelerate the enablement of detections
    • A new dashboard to help identify detections that are marked as Deprecated by the Splunk Threat Research Team that are currently enabled in your environment
    • And more!

Check out the blog “Now Available: Splunk Enterprise Security Content Update App 5.0” for more details.

New Analytics (52)

New Analytic Stories (9)

For all our tools and security content, please visit research.splunk.com.

— The Splunk Threat Research Team

Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...