Security Blogs

Latest Articles

Integrating COVID (or Any) Threat Indicators with MISP and Splunk Enterprise Security
Security
5 Minute Read

Integrating COVID (or Any) Threat Indicators with MISP and Splunk Enterprise Security

Integrating MISP servers with Enterprise Security's Threat Intelligence framework
Asset & Identity for Splunk Enterprise Security - Part 3: Empowering Analysts with More Attributes in Notables
Security
2 Minute Read

Asset & Identity for Splunk Enterprise Security - Part 3: Empowering Analysts with More Attributes in Notables

This is part three in a three part series on the Asset & Identity framework in Splunk Enterprise Security, focusing providing additional visibility and context to analysts with a notable event.
Asset & Identity for Splunk Enterprise Security - Part 2: Adding Additional Attributes to Assets
Security
4 Minute Read

Asset & Identity for Splunk Enterprise Security - Part 2: Adding Additional Attributes to Assets

This is part two in a three part series on the Asset & Identity framework in Splunk Enterprise Security, focusing on adding additional field or attributes to further contextualize systems being monitored.
Between Two Alerts: Easy VPN Security Monitoring with Splunk Enterprise Security
Security
3 Minute Read

Between Two Alerts: Easy VPN Security Monitoring with Splunk Enterprise Security

It’s a whole new world we’re living in, at least for now. This little tutorial will help you stay on top of your security game while in the world of Enterprise Security.
Asset & Identity for Splunk Enterprise Security - Part 1: Contextualizing Systems
Security
4 Minute Read

Asset & Identity for Splunk Enterprise Security - Part 1: Contextualizing Systems

This is part one in a three part series on the Asset & Identity framework in Splunk Enterprise Security, focusing on gaining context on systems being monitored.
Use Cloud Infrastructure Data Model to Detect Container Implantation (MITRE T1525)
Security
7 Minute Read

Use Cloud Infrastructure Data Model to Detect Container Implantation (MITRE T1525)

Using cloud infrastructure data model to detect possible container implantation (Mitre Cloud Matrix technique T1525)
Boss of the SOC v3 Dataset Released!
Security
2 Minute Read

Boss of the SOC v3 Dataset Released!

The tradition continues! We are happy to announce that the Boss of the SOC (BOTS) v3 dataset has been released under an open-source license and is available for download.
World Economic Forum In Davos - Growth in Global Technology Risk
Security
2 Minute Read

World Economic Forum In Davos - Growth in Global Technology Risk

Taking a look at the World Economic Forum (WEF) in Davos 2020 from a cybersecurity angle. What technology risks should we be prepared for according to the WEF?
Detecting CVE-2020-0601 Exploitation Attempts With Wire & Log Data
Security
4 Minute Read

Detecting CVE-2020-0601 Exploitation Attempts With Wire & Log Data

Learn two simple techniques for detecting CVE-2020-0601 exploitation attempts using Splunk