Splunk Security Content for Threat Detection & Response: August 2026 Update

Security Splunk Threat Research Team

Looking for the latest Splunk security content? You’ve come to the right place! This page is updated quarterly with all the latest security content details.

This blog post covers security content developed May 2026 – July 2026. Jump straight to the updates below, or read on to learn more about:

See the latest Splunk Security Content

Splunk continuously monitors the threat landscape to develop, test, and deliver security content to help identify and respond to vulnerabilities and cyber attacks within your environment.

Types of Security Content

Splunk provides a variety of security content, all of which is designed to help you make the most of your Splunk environment. This includes:

Detections

Splunk’s out-of-the-box detection searches are created to help identify patterns and alert you to threats and anomalous behavior.

Analytic Stories

All detection searches relevant to a particular threat are packaged in the form of analytic stories (also known as use cases).

SOAR Playbook Packs

A collection of pre-built automation playbooks that are designed to help users tackle specific use cases.

How to get Security Content

Take advantage of security content in two ways:

Both apps allow you to deploy thousands of out-of-the-box searches to start detecting, investigating, and responding to threats. You can also view the full security content repository by visiting research.splunk.com.

And with that information, we can move onto the latest content. Let's take a look!

Splunk Security Content: May 2026 – July 2026

Below you will find a brief table of contents, followed by an overview of the security content developed from February 2026 - April 2026.

Table of Contents

Adversary Tradecraft Analytic Stories

Emerging Threats Analytic Stories

Overview: Adversary Tradecraft Analytic Stories

The Splunk Threat Research Team (STRT) created several new analytic stories to help identify activity related to various malware threats:

Cisco Secure Access Analytics provides a suite of detections built to analyze network and access logs from Cisco Secure Access. The included analytics focus on uncovering suspicious and potentially malicious behavior such as unauthorized access attempts, anomalous authentication patterns, policy violations, and indicators of compromised credentials.

Phantom Stealer is an information-stealing malware designed to covertly harvest sensitive data from compromised Windows endpoints. In observed Phantom Stealer campaigns, the malware is typically delivered through phishing lures or cracked software bundles targeting Windows users.

Upon initial execution from a user profile or temporary directory, the malware rapidly enumerates installed applications and begins accessing sensitive credential stores.

Salat Stealer surfaced as part of the UAC-0252 campaign, a threat cluster observed distributing multiple credential-harvesting tools targeting organizations primarily in Ukraine and surrounding regions.

VIP Keylogger contains detections that help security analysts identify endpoint activity that may be associated with VIP Keylogger, a .NET-based information stealer and keylogger spread through spear-phishing and impersonation-themed campaigns (for example lures that mimic trusted organizations or urgent business documents).

UAT-11795 is a Russian-speaking, financially motivated threat actor active since at least June 2025 that deploys a novel Python-based remote access trojan named Starland RAT alongside a bespoke PowerShell C2 memory implant called WLDR Agent. The campaign uses ClickFix social engineering and trojanized software installers mimicking popular tools such as MobaXterm, WebEx, Zoom, and DBeaverCommunity to deliver a multi-stage infection chain. Starland RAT provides persistent remote access, cryptocurrency wallet enumeration, screenshot capture, and shellcode injection capabilities, while the WLDR Agent provides an encrypted, memory-resident beaconing capability with multi-threaded PowerShell execution.

The team also published a new analytic story focused on Suspicious AWS Bedrock Claude Activities detection coverage for prompt injection, jailbreak attempts, and other suspicious activities targeting AWS Bedrock Claude AI services. It monitors user inputs to Claude models for known manipulation patterns such as instruction override phrases, persona hijacking, and safety bypass keywords. These techniques are commonly used by adversaries to circumvent AI safety controls, extract sensitive information, or repurpose the model for malicious tasks.

Overview: Emerging Threats Analytic Stories

The STRT also released multiple analytic stories for emerging threats in the past few months.

BlueHammer is a Windows local privilege escalation (LPE) exploit that allows a threat actor who already has a foothold on a system to elevate from a low-privileged user account to full SYSTEM-level control. It abuses the Windows Defender update process via Volume Shadow Copy, using Cloud Files callbacks and oplocks to pause Defender at a critical moment — exposing the SAM, SYSTEM, and SECURITY registry hives.

RedSun analytic story detects activity associated with RedSun exploit. Released by Nightmare-Eclipse on GitHub alongside BlueHammer and UnDefend, it is part of a set of attacks that abuse Windows Defender to disrupt the system or elevate privileges.

RoguePlanet is a publicly released proof-of-concept exploit targeting a race condition in Microsoft Windows Defender. The attack abuses Defender scanning behavior, NTFS alternate data streams, virtual ISO mounting, volume shadow copy paths, and opportunistic oplocks to achieve local privilege escalation to SYSTEM.

The PTC Windchill Exploitation story leverage searches that allow you to detect and investigate activity that may relate to exploitation of PTC Windchill and FlexPLM CVE-2026-4681. CVE-2026-4681 is a critical remote code execution vulnerability affecting PTC Windchill PDMLink and FlexPLM. PTC reports that the vulnerability may be exploited through deserialization of untrusted data and published urgent mitigation guidance for Windchill and FlexPLM environments.

The team also published the following blogs:

Previous Security Content Roundups

Looking for previous security content updates?

Check out the previous quarters of security content roundups from the Spunk Threat Research Team.

Related Articles

Introducing Splunk Attack Range v3.1
Security
3 Minute Read

Introducing Splunk Attack Range v3.1

The Splunk Threat Research Team is happy to release v3.1 of Splunk Attack Range.
Punycode phishers - All you need to know
Security
2 Minute Read

Punycode phishers - All you need to know

Unicode domains can be used for homograph attacks. Learn what they are and how users can be tricked.
Locating IP Addresses
Security
1 Minute Read

Locating IP Addresses