Splunk Security Content for Threat Detection & Response: December Recap

Security Splunk Threat Research Team

In December, the Splunk Threat Research Team had 1 release of new security contentvia the Enterprise Security Content Update (ESCU) app (v5.19). With this release, there are 6 new analytic stories and 31 new analytics now available in Splunk Enterprise Security via the ESCU application update process.

Content Highlights Include:

This release advances the Splunk + Cisco Better Together strategy with the largest expansion of Cisco ASA security analytics to date, exposing configuration tampering, logging suppression, packet capture abuse, identity manipulation, and reconnaissance activity on firewall infrastructure. Together, these updates help customers detect high-impact threats earlier, reduce blind spots across modern enterprise environments, and strengthen SOC effectiveness through unified, high-confidence detections. In addition, this release also adds the following coverage:

For all our tools and security content, please visit research.splunk.com.

Related Articles

Now Answering All Your Questions From a Single Search
Customers & Community
2 Minute Read

Now Answering All Your Questions From a Single Search

Splunker Jennifer Swallow announces a new federated search across Splunk knowledge sites, including Splunk Lantern, making it easier for customers to find answers in one place.
Honda Predicts Problems to Fuel Safety and Profitability
Customers & Community
2 Minute Read

Honda Predicts Problems to Fuel Safety and Profitability

Discover how Honda relies on the Splunk Data-to-Everything Platform to gain insight into parts, equipment and the plant’s more than 100 applications.
Asking Vendors to Create Usable Log Data
Customers & Community
4 Minute Read

Asking Vendors to Create Usable Log Data