Splunk Security Content for Threat Detection & Response: December Recap

Security Splunk Threat Research Team

In December, the Splunk Threat Research Team had 1 release of new security contentvia the Enterprise Security Content Update (ESCU) app (v5.19). With this release, there are 6 new analytic stories and 31 new analytics now available in Splunk Enterprise Security via the ESCU application update process.

Content Highlights Include:

This release advances the Splunk + Cisco Better Together strategy with the largest expansion of Cisco ASA security analytics to date, exposing configuration tampering, logging suppression, packet capture abuse, identity manipulation, and reconnaissance activity on firewall infrastructure. Together, these updates help customers detect high-impact threats earlier, reduce blind spots across modern enterprise environments, and strengthen SOC effectiveness through unified, high-confidence detections. In addition, this release also adds the following coverage:

For all our tools and security content, please visit research.splunk.com.

Related Articles

High Five! Splunk Honored With Five TrustRadius Best Software Awards
Customers & Community
1 Minute Read

High Five! Splunk Honored With Five TrustRadius Best Software Awards

Customers have spoken, and we’re feeling the love – Splunk has been honored with no fewer than five 'Best Software' Awards from TrustRadius.
How Crowdsourcing is Shaping the Future of Splunk Best Practices
Customers & Community
2 Minute Read

How Crowdsourcing is Shaping the Future of Splunk Best Practices

Crowdsourcing is transforming the way we deliver best practices at scale
Splunk Customer Success at the Stevie Awards!
Customers & Community
3 Minute Read

Splunk Customer Success at the Stevie Awards!

Congratulations to Splunk Lantern and Dave Zimmerman – finalists for the 2024 Stevie Awards for Sales & Customer Service.