Splunk Security Content for Threat Detection & Response: March Recap

Security Splunk Threat Research Team

In March, the Splunk Threat Research Team (STRT) had 2 releases of new security content via the Enterprise Security Content Update (ESCU) app (v5.23 and v5.24). With this release, there are 5 new analytic stories and 17 new analytics now available in Splunk Enterprise Security via the ESCU application update process.

Content Highlights Include:

For all our tools and security content, please visit research.splunk.com.

Related Articles

Active Directory Lateral Movement Detection: Threat Research Release, November 2021
Security
12 Minute Read

Active Directory Lateral Movement Detection: Threat Research Release, November 2021

The Splunk Threat Research Team recently updated the Active Directory Lateral Movement analytic story to help security operations center (SOC) analysts detect adversaries executing these techniques within Windows Active Directory (AD) environments.
Introducing the PEAK Threat Hunting Framework
Security
4 Minute Read

Introducing the PEAK Threat Hunting Framework

Introducing the PEAK Threat Hunting Framework, bringing a fresh perspective to threat hunting and incorporating three distinct types of hunts.
Defending at Machine Speed: Splunk Advances the Agentic SOC
Security
5 Minute Read

Defending at Machine Speed: Splunk Advances the Agentic SOC

Splunk is extending agentic security capabilities across the SOC to help teams build detections, codify procedures, prioritize alerts, analyze threats, and scale response.