Splunk Security Content for Threat Detection & Response: July Recap

Security Splunk Threat Research Team

In July, the Splunk Threat Research Team had 2 releases of new security content via the Enterprise Security Content Update (ESCU) app (v5.9.0 and v5.10). With these releases, there are 64 new analytics and 7 new analytic stories now available in Splunk Enterprise Security via the ESCU application update process.

Content highlights include:

For all our tools and security content, please visit research.splunk.com.

Related Articles

Security Insights: JetBrains TeamCity CVE-2024-27198 and CVE-2024-27199
Security
9 Minute Read

Security Insights: JetBrains TeamCity CVE-2024-27198 and CVE-2024-27199

The Splunk Threat Research Team examines exploit operations, analytics, hunting queries, and tips on capturing TeamCity logs.
Beyond Logs: Navigating Entity Behavior in Splunk Platform
Security
7 Minute Read

Beyond Logs: Navigating Entity Behavior in Splunk Platform

Master internal threat detection with Splunk's anomaly detection, finding events like unusual geolocations and spikes in activity, while optimizing security.
Phishing – What does it look like in machine data?
Security
2 Minute Read

Phishing – What does it look like in machine data?