Latest Articles

Splunk Security Content for Threat Detection & Response: August 2026 Update
Security
5 Minute Read

Splunk Security Content for Threat Detection & Response: August 2026 Update

This blog post covers security content developed May 2026 – July 2026
Splunk Security Content for Threat Detection & Response: July Recap
Security
5 Minute Read

Splunk Security Content for Threat Detection & Response: July Recap

The Splunk Threat Research Team had two releases of new security content via the ESCU app.
From Discovery to Actionable Intelligence: Deeper Exposure Analytics in Splunk Enterprise Security 8.6
Security
5 Minute Read

From Discovery to Actionable Intelligence: Deeper Exposure Analytics in Splunk Enterprise Security 8.6

See how Exposure Analytics adds context to investigations.
Security for the Agentic Era: The Cisco + Splunk Guide to Black Hat 2026
Security
4 Minute Read

Security for the Agentic Era: The Cisco + Splunk Guide to Black Hat 2026

At Black Hat 2026, Cisco, Splunk, and Cisco Talos are joining forces to flip the script on attackers.
Stop Counting Alerts, Start Measuring Value
Security
8 Minute Read

Stop Counting Alerts, Start Measuring Value

Security teams can move beyond alert counts and MITRE coverage to measure real ROI from Splunk Enterprise Security.
Phantom Stealer Unmasked: Shellcode, Steganography, and Credential Theft
Security
15 Minute Read

Phantom Stealer Unmasked: Shellcode, Steganography, and Credential Theft

Unmask Phantom Stealer, a .NET credential-stealing threat, and explore its steganography, shellcode injection, and evasion tactics with 32 actionable Splunk detections.
Automated Threat Analysis: Centralize and Accelerate Phishing Investigations in Splunk Enterprise Security
Security
5 Minute Read

Automated Threat Analysis: Centralize and Accelerate Phishing Investigations in Splunk Enterprise Security

Splunk has introduced Automated Threat Analysis in Splunk Enterprise Security, incorporating many core capabilities that originated in Splunk Attack Analyzer directly into ES.
Bundled to Steal: The Salat Stealer Campaign
Security
12 Minute Read

Bundled to Steal: The Salat Stealer Campaign

Learn how the Salat Stealer campaign uses Go-based surveillance and data exfiltration, and explore its infection chain and how to hunt for this threat using Splunk.
Splunk Security Content for Threat Detection & Response: June Recap
Security
5 Minute Read

Splunk Security Content for Threat Detection & Response: June Recap

In June, the Splunk Threat Research Team (STRT) had 1 release of new security content via the Enterprise Security Content Update (ESCU) app (v6.1.0).