Splunk Threat Research Team's Blog Posts

Splunk Threat Research Team

The Splunk Threat Research Team is an active part of a customer’s overall defense strategy by enhancing Splunk security offerings with verified research and security content such as use cases, detection searches, and playbooks. We help security teams around the globe strengthen operations by providing tactical guidance and insights to detect, investigate and respond against the latest threats. The Splunk Threat Research Team focuses on understanding how threats, actors, and vulnerabilities work, and the team replicates attacks which are stored as datasets in the Attack Data repository.

Our goal is to provide security teams with research they can leverage in their day to day operations and to become the industry standard for SIEM detections. We are a team of industry-recognized experts who are encouraged to improve the security industry by sharing our work with the community via conference talks, open-sourcing projects, and writing white papers or blogs. You will also find us presenting our research at conferences such as Defcon, Blackhat, RSA, and many more.

Read more Splunk Security Content.

Detecting Copy Fail (CVE-2026-31431)– Phenomenal Power, Ity Bity Script
Security
15 Minute Read

Detecting Copy Fail (CVE-2026-31431)– Phenomenal Power, Ity Bity Script

The Splunk Threat Research Team analyzes the VIP Keylogger malware to help improve your detection and threat-hunting strategies.
Behind the Code: The Layered Defense-Evasion of VIP Keylogger
Security
15 Minute Read

Behind the Code: The Layered Defense-Evasion of VIP Keylogger

The Splunk Threat Research Team analyzes the VIP Keylogger malware. Learn about its evasion tactics, including obfuscation and steganography, to improve your detection and threat-hunting strategies.
Splunk Security Content for Threat Detection & Response: May 2026 Update
Security
5 Minute Read

Splunk Security Content for Threat Detection & Response: May 2026 Update

Looking for the latest Splunk security content? This page is updated quarterly with all the latest security content details.
Splunk Security Content for Threat Detection & Response: April Recap
Security
5 Minute Read

Splunk Security Content for Threat Detection & Response: April Recap

In April, the Splunk Threat Research Team had 2 releases of new security content via the Enterprise Security Content Update app.
Splunk Security Content for Threat Detection & Response: March Recap
Security
5 Minute Read

Splunk Security Content for Threat Detection & Response: March Recap

In March, the Splunk Threat Research Team had two releases of new security content via the Enterprise Security Content Update app.
Top 50 Cybersecurity Threats
Security
5 Minute Read

Top 50 Cybersecurity Threats

Splunk's Top 50 Cybersecurity Threats is a practical field guide to the tactics and techniques shaping today’s threat landscape.