Splunk Security Content for Threat Detection & Response: August Recap

In August, the Splunk Threat Research Team had 3 releases of new security content via the Enterprise Security Content Update (ESCU) app (v5.11.0, v5.12.0, v5.13.0). With these releases, there are 8 new analytics and 32 new analytic stories now available in Splunk Enterprise Security via the ESCU application update process.

Content highlights include:

This demo video showcases Xworm attacks and Splunk detections finding the different ways it executes on an OS.

Related Articles

High(er) Fidelity Software Supply Chain Attack Detection
Security
4 Minute Read

High(er) Fidelity Software Supply Chain Attack Detection

Software supply chain attacks are not going away. As our network defenses improve, adversaries must move up the chain to stay a step ahead of our defenses.
Modifying the Incident Review Page
Security
5 Minute Read

Modifying the Incident Review Page

How to modify the Incident Review page and add information to Notable Events in Splunk Enterprise Security
SSO without an Active Directory or LDAP provider
Security
4 Minute Read

SSO without an Active Directory or LDAP provider