Splunk Security Content for Threat Detection & Response: May Recap

Security Splunk Threat Research Team

In May, the Splunk Threat Research Team (STRT) had 2 releases of new security content via the Enterprise Security Content Update (ESCU) app (v5.27 and v6.0.0). With this release, there are 2 analytic stories and 67 new analytics now available in Splunk Enterprise Security via the ESCU application update process.

We are excited to announce exciting updates on how we deliver security content. While much of the work is behind the scenes, the result is a more reliable ESCU experience and a stronger platform for STRT to deliver high-quality detection content faster and more consistently in future releases. In V6.0.0 we delivered the next generation of security content by establishing a stronger foundation for Enterprise Security 8.x workflows and improving how detections create actionable Findings.

Content Highlights Include:

Linux Copy Fail Privilege Escalation (CVE-2026-31431): Added a new detection: Linux Auditd Copy Fail Privilege Escalation to identify exploitation of the Copy Fail vulnerability, a Linux kernel flaw that enables unprivileged users to perform controlled writes to file page cache and escalate privileges to root.

Cisco Secure Access Analytics: Introduced a new analytic story for Cisco Secure Access, leveraging firewall telemetry to detect suspicious access patterns. This release includes updates to existing detections: Large ICMP Traffic, Outbound SMB Traffic, Outbound LDAP Traffic, and Windows RDP Network Brute Force Attempts enabling them to operate with Cisco Secure Access Firewall data, validated through simulated attack scenarios to improve visibility into adversary activity traversing modern cloud-delivered security controls.

• Windows Threat Detection Expansion: Expanded coverage across multiple analytic stories with the addition of a broad set of new detections targeting modern Windows attack techniques, including PowerShell abuse, process injection, privilege escalation, registry manipulation, cloud and Azure activity, RMM tool usage, and C2 frameworks such as Cobalt Strike, Metasploit, and custom agents. .

VIP Keylogger (.NET Stealer) Detection Coverage: Introduced new analytics to strengthen detection of VIP Keylogger and related .NET-based infostealers by focusing on behavioral indicators of stealthy execution and persistence.

For all our tools and security content, please visit research.splunk.com.

Related Articles

Visual Link Analysis with Splunk: Part 4 - How is this Pudding Connected?
Security
3 Minute Read

Visual Link Analysis with Splunk: Part 4 - How is this Pudding Connected?

Starting with a single piece of data, use Splunk link analysis functionality to find related links going multiple levels down.
Federated Analytics: Analyze Data Wherever It Resides for Rapid and Holistic Security Visibility
Security
6 Minute Read

Federated Analytics: Analyze Data Wherever It Resides for Rapid and Holistic Security Visibility

Federated Analytics is now generally available as a premium add-on feature for Splunk Cloud Platform and Splunk Enterprise Security.
Hypothesis-Driven Cryptominer Hunting with PEAK
Security
11 Minute Read

Hypothesis-Driven Cryptominer Hunting with PEAK

A sample hypothesis-driven hunt, using SURGe's PEAK threat hunting framework, looking for unauthorized cryptominers.