Product News & Announcements
All the latest news and announcements about Splunk products. Subscribe and never miss an update!

Enterprise Security Content Update (ESCU) | New Releases

cwopat
Splunk Employee
Splunk Employee

In the last month, the Splunk Threat Research Team (STRT) has had 3 releases of new security content via the Enterprise Security Content Update (ESCU) app (v4.3.0, v4.4.0, and v4.5.0). With these releases, there are 27 new detections and 2 new analytic stories, and 1 updated analytic story now available in Splunk Enterprise Security via the ESCU application update process or via Splunk Security Essentials (SSE).

Content highlights include: 

  • Detections to help address the vulnerability in MOVEit Transfer software that is being actively exploited in the wild 
  • An advanced pre-trained deep learning model specifically engineered to discern and pinpoint instances of DNS-based exfiltration to accurately detect and flag potential data breaches or unauthorized information transfers
  • New and updated searches to detect living-off-the-land techniques being utilized by the threat actor group Volt Typhoon 

New Analytic Stories: 

New Detections: 

Updated Analytic Story: Splunk Vulnerabilities

For all our tools and security content, please visit research.splunk.com

The team has also published the following blogs in the last month:

— The Splunk Threat Research Team

Get Updates on the Splunk Community!

Index This | When is October more than just the tenth month?

October 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What’s New & Next in Splunk SOAR

 Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us for an ...