ESCU 520: Splunk Threat Research Team’s Biggest Release of the Year

Listen to this Post

The Splunk Threat Research Team (STRT) has launched ESCU 5.2.0, packed with cutting-edge cybersecurity enhancements. This release introduces new detection capabilities, analytic stories, and optimizations for precision threat hunting.

Key Features:

🔐 GitHub Malicious Activity Detection

  • Monitor 2FA tampering, repo deletions, audit log changes, unauthorized runners, and more.

📧 O365 Email Threat Monitoring

  • Detect rule changes, email deletions, exfiltration patterns, and BEC (Business Email Compromise) behavior.

🧠 SQL Server Abuse Detection

  • Identify lateral movement and privilege escalation via `xp_cmdshell` abuse, malicious `SQLCMD` usage, and configuration hijacking.

New Analytic Stories:

  • GitHub Malicious Activity
  • SQL Server Abuse
  • O365 Email Threats
  • SnappyBee
  • SystemBC
  • Black Basta

⚙️ 43 New Detections

🧰 Enhanced Macros & Lookups

  • Legacy content cleanup for reduced noise.
  • Mapped to real-world threats for actionable intelligence.

🔗 Full Release Notes: https://lnkd.in/dWzipsAe
📥 Download Now: https://lnkd.in/gbs7DqZx

You Should Know:

1. GitHub Security Monitoring