Status of detection analytics

The following table displays the various statuses of detection analytics:

Status Explanation
Production Fully tested detections in the Splunk Enterprise Security environment with the latest Splunk TAs installed against the associated attack data.
Experimental No associated attack data available because it was not possible to simulate the attack, or the attack data contains sensitive information that could not be published to our attack data repository.
Deprecated Deprecated detections that Splunk no longer supports or maintains. Usually, the description of a deprecated detection has a note explaining the reason for the deprecation of the detection and information on a replacement detection, if available.