Skip to content

Releases: splunk/security_content

v4.31.0

08 May 17:23
59e85b0
Compare
Choose a tag to compare
New Analytic Story
Updated Analytic Story
New Analytics
Updated Analytics
Deprecated Analytics
Other Updates
  • Updated risk and threat related configurations for several detections
  • Added Victims to missing detections to create correct risk_objects
  • Converted 50+ Windows detections to leverage the XML log format

Upcoming Changes (ONLY INCLUDE IN announcements)

IMPORTANT NOTE : In the upcoming v4.34.0 release, changes will be made to the security_content_summariesonly macro. Its current definition will change to wrap the existing values into another set of macros. This will allow each environment to customize each setting without changing the base macro. If this macro has already been modified in your environment, it will not be affected.

v4.30.0

17 Apr 22:55
afe7cb8
Compare
Choose a tag to compare

Release notes

New Analytics Story

Updated Analytics Story

New Analytics

Updated Analytics

Macros Added

  • applocker
  • zscaler_proxy

Macros Updated

  • okta

Lookups Added

  • applockereventcodes

Other Updates

  • Added a new dashboard ESCU - AppLocker, Navigate to your Dashboards and search for "ESCU - AppLocker" to assist with auditing and monitoring Windows AppLocker events for your endpoints (Splunk Enterprise 9.x.x version and above only)

v4.29.0

04 Apr 19:21
69e8ca7
Compare
Choose a tag to compare

v4.28.0

v4.27.0

20 Mar 23:08
e4dd27c
Compare
Choose a tag to compare

v4.26.0

06 Mar 22:42
b32c1a6
Compare
Choose a tag to compare

New Analytics Story

Updated Analytics Story

New Analytics

Updated Analytics

Macros Added

  • nginx_access_logs
  • suricata

Macros Updated

Lookups Added

Lookups Updated

  • remote_access_software

Playbooks Added

Playbooks Updated

Other Updates

  • Added a new script and a CI job to automatically upload the package to Splunkbase using a service account
  • Create SSA-Content-latest.tar.gz in the generate_ba CI job

v4.25.0

22 Feb 19:58
bac4b5b
Compare
Choose a tag to compare

Release notes for ESCU v4.25.0

New Analytics Story

Updated Analytics Story

New Analytics

Updated Analytics

Other Updates

  • Updated contentctl to output accurate providing technologies in savedsearches.conf

v4.24.0

15 Feb 21:47
794904b
Compare
Choose a tag to compare

Release notes for ESCUv4.24.0

New Analytics Story

Updated Analytics Story

New Analytics

Updated Analytics

Read more

v4.23.0

30 Jan 22:17
50459e7
Compare
Choose a tag to compare

Release notes for ESCU v4.23.0

New Analytics Story

Updated Analytics Story

New Analytics

Updated Analytics

Other Updates

  • Added a new input macro sourcetype="kube:container:falco"

Playbook Updates

  • Splunk Attack Analyzer Dynamic Analysis
  • Splunk Automated Email Investigation
  • Splunk Identifier Activity Analysis
  • Splunk Message Identifier Activity Analysis

v4.22.0

24 Jan 22:16
fee6f11
Compare
Choose a tag to compare