Splunk Security Content for Threat Detection & Response: April Recap

Security Splunk Threat Research Team

In April, the Splunk Threat Research Team (STRT) had 2 releases of new security content via the Enterprise Security Content Update (ESCU) app (v5.25 and v5.26). With this release, there are new 6 analytic stories and 13 new analytics now available in Splunk Enterprise Security via the ESCU application update process.

Content Highlights Include:

For all our tools and security content, please visit research.splunk.com.

Related Articles

Phantom Stealer Unmasked: Shellcode, Steganography, and Credential Theft
Security
15 Minute Read

Phantom Stealer Unmasked: Shellcode, Steganography, and Credential Theft

Unmask Phantom Stealer, a .NET credential-stealing threat, and explore its steganography, shellcode injection, and evasion tactics with 32 actionable Splunk detections.
Logs Are For Campfires: Log Data, Big Data, and Splunk Asset & Risk Intelligence
Security
3 Minute Read

Logs Are For Campfires: Log Data, Big Data, and Splunk Asset & Risk Intelligence

Discover how Splunk Asset and Risk Intelligence (ARI) transforms log data into actionable insights. From automated asset discovery to risk and compliance management, ARI empowers organizations with real-time visibility, vulnerability tracking, and proactive threat mitigation. Elevate your security posture today.
Streamlining Vulnerability Management with Splunk Phantom
Security
2 Minute Read

Streamlining Vulnerability Management with Splunk Phantom

Manage the entire lifecycle of vulnerability management with automation and orchestration using Splunk’s SOAR technology, Splunk Phantom, to automate actions and reduce the time spent on patch management by 40%.