Product News & Announcements
All the latest news and announcements about Splunk products. Subscribe and never miss an update!

Enterprise Security Content Update (ESCU) | New Releases

TyneDarke
Splunk Employee
Splunk Employee

In November, the Splunk Threat Research Team had one release of new security content via the Enterprise Security Content Update (ESCU) app (v4.43.0). With this release, there are 2 new analytic stories and 9 new analytics now available in Splunk Enterprise Security via the ESCU application update process.

Content highlights include:

  • Braodo Stealer analytics story: This includes detections to help identify the Braodo Stealer malware, which is designed to steal sensitive information like credentials, cookies, and system data. To learn more about Braodo Stealer and the detections included in this analytics story, check out the team’s blog ”Cracking Braodo Stealer: Analyzing Python Malware and Its Obfuscated Loader.”
  • Enhanced drilldowns: In addition, all TTP or Anomaly and Correlation type detections have had two drilldowns added to their yaml files. The drilldowns let users view detection results for specific risk objects and access risk events from the past 7 days.

New Analytic Stories (2)

New Analytics (9)

The team also published the following 4 blogs:

For all our tools and security content, please visit research.splunk.com.

— The Splunk Threat Research Team

Get Updates on the Splunk Community!

Video | Welcome Back to Smartness, Pedro

Remember Splunk Community member, Pedro Borges? If you tuned into Episode 2 of our Smartness interview series, ...

Detector Best Practices: Static Thresholds

Introduction In observability monitoring, static thresholds are used to monitor fixed, known values within ...

Expert Tips from Splunk Education, Observability in Action, Plus More New Articles on ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...