Splunk Security Content for Threat Detection & Response: June Recap

Security Splunk Threat Research Team

In June, the Splunk Threat Research Team (STRT) had 1 release of new security content via the Enterprise Security Content Update (ESCU) app (v6.1.0). With this release, there are 5 analytic stories and 34 new analytics now available in Splunk Enterprise Security via the ESCU application update process.

Content highlights include:

For all our tools and security content, please visit research.splunk.com.

Related Articles

Splunk Enterprise Security 8.0 and Splunk SOAR 6.3 Unify and Automate TDIR Workflows within the Market-Leading SIEM
Security
4 Minute Read

Splunk Enterprise Security 8.0 and Splunk SOAR 6.3 Unify and Automate TDIR Workflows within the Market-Leading SIEM

Patriz Regalado explains how Splunk Enterprise Security is now natively integrated with automation capabilities from Splunk SOAR.
Hunting for Threats in VPCFlows
Security
7 Minute Read

Hunting for Threats in VPCFlows

This article will look at native AWS network telemetry — VPCFlows. We’ll explore what it is, how you can ingest it, and what value it provides from a security perspective.
Splunk SOAR Playbooks: Conducting an Azure New User Census
Security
3 Minute Read

Splunk SOAR Playbooks: Conducting an Azure New User Census

Learn how to use automated playbooks to monitor new user accounts to ensure that threat actors like Hafnium cannot leverage the Active Directory system to exploit vulnerabilities.