Splunk® Enterprise Security Content Update

Release Notes

What's new

Enterprise Security Content Updates version 5.0.0 was released on December 4, 2024 and includes the following enhancements:

Key highlights

  • A new Deprecation Assistant dashboard: This release introduces a Deprecation Assistant dashboard to identify and manage deprecated detection analytics that are enabled in your Splunk environment. Deprecated detections are marked for removal in ESCU version 5.2.0 and can disrupt your environment. For more information on the deprecated detections and their replacements, see [Documentation:ESCU:5.0.0:user:DeprecatedAnalytics Deprecated analytics].
  • Analytic Story Onboarding Assistant: A redesigned home page with an enhanced user interface that offers direct access to release notes, analytics counts, and the latest version on Splunkbase complemented by a detailed timeline of STRT blogs and updates. Additionally, the Analytic Story Onboarding Assistant, which is a new preview feature designed to streamline the process of enabling several detections from multiple analytics stories for which data is available in your Splunk Environment, is also available.
  • New analytics: Threat detection capabilities are now expanded by mapping existing analytics and creating new detections for a range of threats, including Backdoor Pingpong, Cleo File Transfer Software, Crypto Stealer, SDDL Tampering Defense Evasion, Derusbi, Earth Estries, Nexus APT Threat Activity, WinDealer RAT, and XorDDos. These detections are already available in Splunk Enterprise Security using an ESCU application update process built into the product and in Splunk Security Essentials (SSE) using an API update.

New analytic stories


New analytics


Other updates

Updates to YAML configurations by enhancing validation, improving accuracy and consistency, and replacing the observables key with an RBA key to better align with Splunk Enterprise Security standards and simplify risk attribution.

Last modified on 30 January, 2025
 

This documentation applies to the following versions of Splunk® Enterprise Security Content Update: 5.0.0


Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters