Product News & Announcements
All the latest news and announcements about Splunk products. Subscribe and never miss an update!

Enterprise Security Content Update (ESCU) | New Releases

OliviaHenderson
Splunk Employee
Splunk Employee

In the last month, the Splunk Threat Research Team (STRT) has had 2 releases of new security content via the Enterprise Security Content Update (ESCU) app (v4.13.0, v4.14.0.). With these releases, there are 22 new detections and 6 new analytic stories, and 3 updated analytic stories now available in Splunk Enterprise Security via the ESCU application update process.

Content highlights include:

  • An analytic story for a previously unknown vulnerability in the Cisco IOS XE software's Web User Interface (Web UI) feature that is currently being exploited and effectively grants full control of the compromised device. 
  • An analytic story focused on Windows SIP WinVerifyTrust subversion and an analytic story for Microsoft SharePoint Server to detect a flaw in handling authentication tokens, which allows an attacker to escalate privileges and gain unauthorized access to the SharePoint environment. 
  • A NjRat analytic story that contains 7 detections to detect attack techniques relating to NjRat, a notorious remote access trojan (RAT). The detections include tracking file write operations for dropped files, scrutinizing registry modifications to provide persistence mechanisms, monitoring suspicious processes, self-deletion behaviors, browser credential parsing, firewall configuration alterations, spreading itself via removable drive, and other potentially malicious actions.
  • Additionally, we released new analytics to address Splunk CVEs that focus on attacker behavior targeting Splunk environments, along with 2 new analytics for CVEs related to Remote Code Execution (RCE) in WS_FTP and TeamCity On-Premises. 

New Analytics (22)

New Analytic Stories (6)

Updated Analytics (3)

For all our tools and security content, please visit research.splunk.com

— The Splunk Threat Research Team

Get Updates on the Splunk Community!

CX Day is Coming!

Customer Experience (CX) Day is on October 7th!! We're so excited to bring back another day full of wonderful ...

Strengthen Your Future: A Look Back at Splunk 10 Innovations and .conf25 Highlights!

The Big One: Splunk 10 is Here!  The moment many of you have been waiting for has arrived! We are thrilled to ...

Now Offering the AI Assistant Usage Dashboard in Cloud Monitoring Console

Today, we’re excited to announce the release of a brand new AI assistant usage dashboard in Cloud Monitoring ...