Splunk Security Content for Threat Detection & Response: August Recap

Security Splunk Threat Research Team

In August, the Splunk Threat Research Team (STRT) had 2 releases of new security content via the Enterprise Security Content Update (ESCU) app (v6.4.0 and v6.5.0) With these releases, there are 2 new analytic stories, 40 new analytics, and 52 updated analytics, now available in Splunk Enterprise Security via the ESCU application update process.

Content highlights include:

Related Articles

Not Just Annoying Ads: Adware Bundles Delivering Gh0st RAT
Security
8 Minute Read

Not Just Annoying Ads: Adware Bundles Delivering Gh0st RAT

Detect and defend against the Gh0st RAT and CloverPlus adware bundle – explore TTPs, persistence mechanisms, and actionable Splunk detection strategies.
Staff Picks for Splunk Security Reading June 2022
Security
2 Minute Read

Staff Picks for Splunk Security Reading June 2022

Hello, everyone! Welcome to the Splunk staff picks blog. Each month, Splunk security experts curate a list of presentations, whitepapers, and customer case studies that we feel are worth a read. To check out our previous staff security picks, take a peek here. We hope you enjoy.
Australia Is Investing in Resilience – Are Businesses Ready?
Security
3 Minute Read

Australia Is Investing in Resilience – Are Businesses Ready?

Splunker Craig Bates explains why the most immediate — and underestimated — consequence of disruption isn’t always data loss. It’s downtime.