Splunk Security Content for Threat Detection & Response: February Recap

Security Splunk Threat Research Team

In February, the Splunk Threat Research Team (STRT) had 2 releases of new security content via the Enterprise Security Content Update (ESCU) app (v5.21 and v5.22). With this release, there are 9 new analytic stories and 14 new analytics now available in Splunk Enterprise Security via the ESCU application update process.

Content Highlights Include:

For all our tools and security content, please visit research.splunk.com.

Related Articles

Detecting Ryuk Using Splunk Attack Range
Security
6 Minute Read

Detecting Ryuk Using Splunk Attack Range

A new alert, Ransomware Activity Targeting the Healthcare and Public Health Sector, issued by the CISA poses ongoing and possible imminent attacks against the healthcare sector. Learn how you can detect the Ryuk ransomware as payload with Splunk Attack Range.
Advanced Link Analysis: Part 2 - Implementing Link Analysis
Security
4 Minute Read

Advanced Link Analysis: Part 2 - Implementing Link Analysis

Learn how to step-by-step process to building the dashboard with Sigbay Link Analysis visualization app from scratch.
Process Hunting with PSTree
Security
5 Minute Read

Process Hunting with PSTree

This tutorial shows how to use the pstree command & app to help you look through all the processes you have to investigate.