Splunk Security Content for Threat Detection & Response: July Recap

Security Splunk Threat Research Team

In July, the Splunk Threat Research Team (STRT) had 2 releases of new security content via the Enterprise Security Content Update (ESCU) app (v6.2.0 and v6.3.0.) With this release, there are 3 analytic stories and 14 new analytics now available in Splunk Enterprise Security via the ESCU application update process.

Related Articles

7 questions all CxOs should ask to increase cyber resilience before buying more software
Security
7 Minute Read

7 questions all CxOs should ask to increase cyber resilience before buying more software

Here are 7 questions you should always ask to help your organisation to make the best possible purchase and increase its cyber resilience at the same time.
Splunk SOAR Playbooks: Suspicious Email Domain Enrichment
Security
2 Minute Read

Splunk SOAR Playbooks: Suspicious Email Domain Enrichment

This playbook focuses specifically on domain names contained in the ingested email, and it uses Cisco Umbrella Investigate to add the risk score, risk status, and domain category to the event in Splunk SOAR.
Macro-ATT&CK 2024: A Five-Year Perspective
Security
6 Minute Read

Macro-ATT&CK 2024: A Five-Year Perspective

Splunk’s Ryan Fetterman and Tamara Chacon dive into attacker techniques, trends, and blue team tips for analyzing and visualizing data from the past year.