Splunk Security Content for Threat Detection & Response: April Recap

Security Splunk Threat Research Team

In April, the Splunk Threat Research Team (STRT) had 2 releases of new security content via the Enterprise Security Content Update (ESCU) app (v5.25 and v5.26). With this release, there are new 6 analytic stories and 13 new analytics now available in Splunk Enterprise Security via the ESCU application update process.

Content Highlights Include:

For all our tools and security content, please visit research.splunk.com.

Related Articles

Built for Speed, Stuck in Neutral: Why Splunk ES Deployments Stall
Security
10 Minute Read

Built for Speed, Stuck in Neutral: Why Splunk ES Deployments Stall

Why do Splunk Enterprise Security deployments stall? A Security TAM outlines five common pitfalls and how to unlock better outcomes.
This Feels Scripted: Zeek Scripting and Splunk
Security
5 Minute Read

This Feels Scripted: Zeek Scripting and Splunk

Splunker Shannon Davis shares a closer look at updated searches for detecting SpookySSL.
Clop Ransomware Detection: Threat Research Release, April 2021
Security
4 Minute Read

Clop Ransomware Detection: Threat Research Release, April 2021

Discover how the Splunk Threat Research Team focused their research efforts on Clop Ransomware detections to help organizations detect abnormal behavior faster before it becomes detrimental.