Splunk Security Content for Threat Detection & Response: May Recap

Security Splunk Threat Research Team

In May, the Splunk Threat Research Team had 2 releases of new security content via the Enterprise Security Content Update (ESCU) app (v5.5.0 and v5.6.0). With these releases, there are 13 new analytics and 4 new analytic stories now available in Splunk Enterprise Security via the ESCU application update process.

Content highlights include:

For all our tools and security content, please visit research.splunk.com.

Related Articles

My Username Fields Have Passwords in Them! What Do I Do?
Security
3 Minute Read

My Username Fields Have Passwords in Them! What Do I Do?

Sometimes, users put their password into a username field and it gets logged into Splunk – learn how to identify this behavior and remediate it with SOAR.
Linux Persistence and Privilege Escalation: Threat Research January 2022 Release
Security
6 Minute Read

Linux Persistence and Privilege Escalation: Threat Research January 2022 Release

In this January 2022 release, The Splunk Threat Research (STRT) team focused on the recently released Sysmon for Linux technology addition to Splunk.
Introducing: The Splunk App for Okta
Security
2 Minute Read

Introducing: The Splunk App for Okta