Ryan Kovar's Blog Posts
NY. AZ. Navy. SOCA. KBMG. DARPA. Splunk.
Display Mode
Paginated
Filter
Author
Author URL
Limit
6

Spotting the Adversary… with Splunk
Wondering how to find the baddies in huge volumes of data? Work with Splunk & Windows event Log Monitoring – refer to table of event codes in NSA paper.

Detecting dynamic DNS domains in Splunk
While useful legitimately, hackers can use dynamic DNS domains to change IP address rapidly & exploit via malware-evil.duckdns[.]org; how to protect against?
