Splunk Security Content for Threat Detection & Response: December Recap

Security Splunk Threat Research Team

In December, the Splunk Threat Research Team had 1 release of new security contentvia the Enterprise Security Content Update (ESCU) app (v5.19). With this release, there are 6 new analytic stories and 31 new analytics now available in Splunk Enterprise Security via the ESCU application update process.

Content Highlights Include:

This release advances the Splunk + Cisco Better Together strategy with the largest expansion of Cisco ASA security analytics to date, exposing configuration tampering, logging suppression, packet capture abuse, identity manipulation, and reconnaissance activity on firewall infrastructure. Together, these updates help customers detect high-impact threats earlier, reduce blind spots across modern enterprise environments, and strengthen SOC effectiveness through unified, high-confidence detections. In addition, this release also adds the following coverage:

For all our tools and security content, please visit research.splunk.com.

Related Articles

Harmonizing Digital Channels and Business Operations to Deliver a Good Customer Experience
Customers & Community
1 Minute Read

Harmonizing Digital Channels and Business Operations to Deliver a Good Customer Experience

In celebration of Customer Experience Day 2023, we share a closer look at how Splunk prioritizes simplifying digital experiences and operational efficiency.
Splunk Tops Award Season with 10 Customer Review Wins Across Security Portfolio From TrustRadius
Customers & Community
2 Minute Read

Splunk Tops Award Season with 10 Customer Review Wins Across Security Portfolio From TrustRadius

We’re thrilled to announce that TrustRadius has recognized two of our Splunk Security products — Splunk Enterprise Security and Splunk Security Orchestration, Automation and Response (SOAR) — with 10 Top Rated Awards for 2022.
Unlocking Your Full Splunk Potential with Splunk TAMs
Customers & Community
3 Minute Read

Unlocking Your Full Splunk Potential with Splunk TAMs

Splunk Technical Account Managers help customers accelerate time to value, reduce risk, and optimize Splunk deployments across Platform, Security, and Observability through expert, flexible guidance.