Ryan Kovar's Blog Posts

NY. AZ. Navy. SOCA. KBMG. DARPA. Splunk.

Spotting the Adversary… with Splunk
Tips & Tricks
5 Minute Read

Spotting the Adversary… with Splunk

Wondering how to find the baddies in huge volumes of data? Work with Splunk & Windows event Log Monitoring – refer to table of event codes in NSA paper.
Random Words on Entropy and DNS
Security
4 Minute Read

Random Words on Entropy and DNS

Detecting dynamic DNS domains in Splunk
Security
3 Minute Read

Detecting dynamic DNS domains in Splunk

While useful legitimately, hackers can use dynamic DNS domains to change IP address rapidly & exploit via malware-evil.duckdns[.]org; how to protect against?