Splunk Security Content for Threat Detection & Response: December Recap

Security Splunk Threat Research Team

In December, the Splunk Threat Research Team had 1 release of new security contentvia the Enterprise Security Content Update (ESCU) app (v5.19). With this release, there are 6 new analytic stories and 31 new analytics now available in Splunk Enterprise Security via the ESCU application update process.

Content Highlights Include:

This release advances the Splunk + Cisco Better Together strategy with the largest expansion of Cisco ASA security analytics to date, exposing configuration tampering, logging suppression, packet capture abuse, identity manipulation, and reconnaissance activity on firewall infrastructure. Together, these updates help customers detect high-impact threats earlier, reduce blind spots across modern enterprise environments, and strengthen SOC effectiveness through unified, high-confidence detections. In addition, this release also adds the following coverage:

For all our tools and security content, please visit research.splunk.com.

Related Articles

Cybersecurity Awareness Month: Defend What Matters with Splunk Education
Customers & Community
2 Minute Read

Cybersecurity Awareness Month: Defend What Matters with Splunk Education

October is Cybersecurity Awareness Month – a reminder that protecting data and digital infrastructure isn’t just an IT responsibility; it’s everyone’s responsibility.
Operational resilience, as seen by our French customers
Customers & Community
3 Minute Read

Operational resilience, as seen by our French customers

On October 18th, .conf Go was held in Paris. It was an opportunity to finally meet in-person and discuss the latest developments in cybersecurity and observability. Operational resilience was high on the agenda. We were able to discuss it with two of Splunk’s customers: David Charpagne, Global SOC Manager at Carrefour, and Youssef Kilany, Director of Architecture and Production at Net-entreprises (GIP-MDS).
From Insight to Action: Transforming Customer Experience with Splunk
Customers & Community
1 Minute Read

From Insight to Action: Transforming Customer Experience with Splunk

With Splunk, teams can innovate, adapt faster, and grow their skills more rapidly to challenge the norm and enable them to quickly find solutions to customer problems through valuable data insights.