Product News & Announcements
All the latest news and announcements about Splunk products. Subscribe and never miss an update!

Enterprise Security Content Update (ESCU) | New Releases

TyneDarke
Splunk Employee
Splunk Employee

In the last month, the Splunk Threat Research Team has had 2 releases of new security content via the Enterprise Security Content Update (ESCU) app (v4.17.0 and v4.18.0). With these releases, there are 51 new analytics, 5 new analytic stories, 18 updated analytics, and 4 updated analytic stories now available in Splunk Enterprise Security via the ESCU application update process.

Content highlights include:

  • The "Office 365 Persistence Mechanisms" analytic story includes a group of detections that delve into attackers' tactics and techniques to maintain prolonged unauthorized access within the O365 environment. Persistence in this context refers to adversaries' methods to keep their foothold after an initial compromise.
  • The "Windows Attack Surface Reduction" analytic story includes a group of detections for Attack Surface Reduction (ASR) events. ASR is a feature of Windows Defender Exploit Guard that prevents actions and apps that are typically used by exploit-seeking malware to infect machines. When an action is blocked by an ASR rule, an event is generated.
  • The "Kubernetes Security" analytic story encompasses a range of detections that highlight the escalating challenges when securing containerized environments. Key detections include Kubernetes Abuse of Secret by Unusual Location, User Agent, User Group, and Username, which pinpoints attempts to exploit secrets via anomalous parameters.
  • Four new analytics delve into the intricacies of MFA security in the PingID environment. These detections, contributed by @nterl0k, cover scenarios like Mismatch Auth Source and Verification Response, Multiple Failed MFA Requests, New MFA Method Post-Credential Reset, and Registration of New MFA Methods, highlighting the evolving landscape of digital authentication security.

New Analytics (51)

New Analytic Stories (5)

Updated Analytics (18)

Updated Analytic Stories (4)

The team has also published the following blogs:

For all our tools and security content, please visit research.splunk.com

— The Splunk Threat Research Team

Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...