Splunk Tech Talks
Deep-dives for technical practitioners.

Using the Splunk Threat Research Team’s Latest Security Content

WhitneySink
Splunk Employee
Splunk Employee

Tech Talk | Security Edition

Did you know the Splunk Threat Research Team regularly releases new, pre-packaged security content? Just in the last few months, the team has released dozens of new and updated detections and analytics stories covering the latest threats, including malware campaigns, zero-day vulnerabilities, CVEs, and more.

(view in My Videos)

Join this Tech Talk to learn more from Michael Haag, Principal Threat Researcher, who will provide:

  • Best practices for accessing and using the team’s content in the Splunk ES Content Update (ESCU) app
  • An overview of the team’s content updates between November and January
  • Deeper dives into new content for detecting DarkGate malware, Office 365 account takeover, and Windows Attack Surface Reduction events

Event Page

Contributors
Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Rounding off the Splunk Dashboard Contest

What does a contest-winning Splunk dashboard look like? In this case, it isn't in a browser tab at all. It ...

A Four Part Event Series: AI + Observability: AI Agents, LLMs, Apps, & Infrastructure

AI + Observability: AI Agents, LLMs, Apps, & Infrastructure The rapid evolution of artificial intelligence ...