Security Blogs

Latest Articles

Splunk Security Content for Impact Assessment of CrowdStrike Windows Outage
Security
4 Minute Read

Splunk Security Content for Impact Assessment of CrowdStrike Windows Outage

This blog is intended to help existing Splunk customers who are also customers of CrowdStrike gain visibility into how the CrowdStrike outage may be impacting their organizations.
Splunk at Black Hat 2024: Strategic Transformations to Power the SOC of the Future
Security
3 Minute Read

Splunk at Black Hat 2024: Strategic Transformations to Power the SOC of the Future

At Black Hat 2024, Splunk will demonstrate how we’re empowering security teams to embrace strategic transformations and navigate the complex threat landscape.
Breaking Down Linux.Gomir: Understanding this Backdoor’s TTPs
Security
8 Minute Read

Breaking Down Linux.Gomir: Understanding this Backdoor’s TTPs

The Splunk Threat Research Team provides an analysis of Linux.Gomir to help security analysts, blue teamers and Splunk customers defend against this threat.
Woken by Ransomware, Are We Hypnotized by Tunnel Vision?
Security
4 Minute Read

Woken by Ransomware, Are We Hypnotized by Tunnel Vision?

Splunker Ronald Beiboer examines if ransomware has blinded us to the more invisible attacks and how cybersecurity can help.
Introducing ShellSweepPlus: Open-Source Web Shell Detection
Security
14 Minute Read

Introducing ShellSweepPlus: Open-Source Web Shell Detection

Detect web shells easily with ShellSweepPlus, an open-source tool for detecting potential web shells. Learn how ShellSweepPlus works and how to use it here.
regreSSHion: Uncovering CVE-2024-6387 in OpenSSH - A Critical Vulnerability
Security
9 Minute Read

regreSSHion: Uncovering CVE-2024-6387 in OpenSSH - A Critical Vulnerability

CVE-2024-6387, aka "regreSSHion", exposes Linux environments to remote unauthenticated code execution. Learn how to handle this CVE here.
Splunk Ranked Number 1 in the 2024 Gartner® Critical Capabilities for Security Information and Event Management
Security
1 Minute Read

Splunk Ranked Number 1 in the 2024 Gartner® Critical Capabilities for Security Information and Event Management

Splunk was ranked as the #1 SIEM solution in all three Use Cases in the 2024 Gartner® Critical Capabilities for Security Information and Event Management report.
Staff Picks for Splunk Security Reading June 2024
Security
2 Minute Read

Staff Picks for Splunk Security Reading June 2024

Welcome to the June Splunk staff picks blog, featuring a list of presentations, whitepapers, and customer case studies that our Splunk Security experts feel are worth a read.
The Geometry of Fraud Detection
Security
8 Minute Read

The Geometry of Fraud Detection

Splunker Nimish Doshi shares statistical ways to find outliers and visualizes what they would look like if using virtual area or virtual volume as geometric representations to find them.