Product News & Announcements
All the latest news and announcements about Splunk products. Subscribe and never miss an update!

Enterprise Security Content Update (ESCU) | New Releases

cwopat
Splunk Employee
Splunk Employee

In the last month, the Splunk Threat Research Team (STRT) has had 3 releases of new security content via the Enterprise Security Content Update (ESCU) app (v4.3.0, v4.4.0, and v4.5.0). With these releases, there are 27 new detections and 2 new analytic stories, and 1 updated analytic story now available in Splunk Enterprise Security via the ESCU application update process or via Splunk Security Essentials (SSE).

Content highlights include: 

  • Detections to help address the vulnerability in MOVEit Transfer software that is being actively exploited in the wild 
  • An advanced pre-trained deep learning model specifically engineered to discern and pinpoint instances of DNS-based exfiltration to accurately detect and flag potential data breaches or unauthorized information transfers
  • New and updated searches to detect living-off-the-land techniques being utilized by the threat actor group Volt Typhoon 

New Analytic Stories: 

New Detections: 

Updated Analytic Story: Splunk Vulnerabilities

For all our tools and security content, please visit research.splunk.com

The team has also published the following blogs in the last month:

— The Splunk Threat Research Team

Get Updates on the Splunk Community!

Prove Your Splunk Prowess at .conf25—No Prereqs Required!

Your Next Big Security Credential: No Prerequisites Needed We know you’ve got the skills, and now, earning the ...

Splunk Observability Cloud's AI Assistant in Action Series: Observability as Code

This is the sixth post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how to ...

Splunk Answers Content Calendar, July Edition I

Hello Community! Welcome to another month of Community Content Calendar series! For the month of July, we will ...