Skip to main content
false

Splunk Enterprise Security Blogs

Latest Articles

Security 6 Min Read

Defending Against Common Phishing Frameworks Kits with Splunk Enterprise Security Content Update

Discover how Splunk Enterprise Security Content Update (ESCU) can help you protect your network.
Security 4 Min Read

Monitor for, Investigate, and Respond to Phishing Payloads with Splunk Enterprise Security Content Update

Detect, investigate, and defend signs of phishing payloads in your environment with Splunk Enterprise Security Content Update (ESCU)
Security 6 Min Read

Defending Against Phishing Frameworks with Splunk Enterprise Security Content Updates

Attackers often use phishing framework kits to generate faux websites to trick unwitting users into visiting and/or giving up sensitive information.
Security 3 Min Read

Boss of the SOC (BOTS) Advanced APT Hunting Companion App: Now Available on Splunkbase

If you want to learn more about threat hunting with Splunk, this app in conjunction with the BOTSv2 data set is just the answer!
Security 4 Min Read

Threat Intel and Splunk Enterprise Security Part 2 - Adding Local Intel to Enterprise Security

Splunker John Stoner shares a walkthrough for how to add local threat intelligence into Splunk Enterprise Security
Security 6 Min Read

Service Providers Need More Than a SIEM

If you're a security-focused service provider, we've got good news for you – Splunk is more than just a SIEM solution.
Security 3 Min Read

Threat Intel and Splunk Enterprise Security Part 1 - What’s The Point of Threat Intel in ES?

Find out how threat intelligence works with Splunk Enterprise Security
Security 2 Min Read

Catching the Coldroot RAT

Detect signs of the Mac Coldroot RAT malware in your environment with Splunk Enterprise Security Content Update (ESCU)
Security 2 Min Read

Dear Buttercup: The Security Letters

A blog series answering the questions of customers around the world about Splunk security products like Splunk Enterprise Security, Splunk Phantom, Splunk ESCU, Spunk UBA and more