Splunk Security Content for Threat Detection & Response: May Recap

In May, the Splunk Threat Research Team had 2 releases of new security content via the Enterprise Security Content Update (ESCU) app (v5.5.0 and v5.6.0). With these releases, there are 13 new analytics and 4 new analytic stories now available in Splunk Enterprise Security via the ESCU application update process.

Content highlights include:

For all our tools and security content, please visit research.splunk.com.

Related Articles

Strengthen Digital Resilience with Unified Security Operations
Security
4 Minute Read

Strengthen Digital Resilience with Unified Security Operations

Splunk Mission Control offers a unified, simplified, and modernized security operations experience which reduces complexity and reduces risk.
Detecting SeriousSAM CVE-2021-36934 With Splunk
Security
4 Minute Read

Detecting SeriousSAM CVE-2021-36934 With Splunk

SeriousSAM or CVE-2021-36934 is a Privilege Escalation Vulnerability. The Splunk Threat Research team recommends performing an assessment to better understand the impact of this vulnerability in corporate environments.
Machine Learning in Security: Detect Suspicious TXT Records Using Deep Learning
Security
8 Minute Read

Machine Learning in Security: Detect Suspicious TXT Records Using Deep Learning

The Splunk Machine Learning for Security (SMLS) team introduces a new detection to detect DNS Tunneling using DNS TXT payloads.