Product News & Announcements
All the latest news and announcements about Splunk products. Subscribe and never miss an update!

Enterprise Security Content Update (ESCU) | New Releases

cwopat
Splunk Employee
Splunk Employee

In the last month, the Splunk Threat Research Team (STRT) has had 3 releases of new security content via the Enterprise Security Content Update (ESCU) app (v4.3.0, v4.4.0, and v4.5.0). With these releases, there are 27 new detections and 2 new analytic stories, and 1 updated analytic story now available in Splunk Enterprise Security via the ESCU application update process or via Splunk Security Essentials (SSE).

Content highlights include: 

  • Detections to help address the vulnerability in MOVEit Transfer software that is being actively exploited in the wild 
  • An advanced pre-trained deep learning model specifically engineered to discern and pinpoint instances of DNS-based exfiltration to accurately detect and flag potential data breaches or unauthorized information transfers
  • New and updated searches to detect living-off-the-land techniques being utilized by the threat actor group Volt Typhoon 

New Analytic Stories: 

New Detections: 

Updated Analytic Story: Splunk Vulnerabilities

For all our tools and security content, please visit research.splunk.com

The team has also published the following blogs in the last month:

— The Splunk Threat Research Team

Get Updates on the Splunk Community!

Unlock New Opportunities with Splunk Education: Explore Our Latest Courses!

At Splunk Education, we’re dedicated to providing top-tier learning experiences that cater to every skill ...

Technical Workshop Series: Splunk Data Management and SPL2 | Register here!

Hey, Splunk Community! Ready to take your data management skills to the next level? Join us for a 3-part ...

Spotting Financial Fraud in the Haystack: A Guide to Behavioral Analytics with Splunk

In today's digital financial ecosystem, security teams face an unprecedented challenge. The sheer volume of ...