Security Blogs

Latest Articles

Detecting Active Directory Kerberos Attacks: Threat Research Release, March 2022
Security
14 Minute Read

Detecting Active Directory Kerberos Attacks: Threat Research Release, March 2022

Learn more about the Splunk Threat Research Team's new analytic story to help SOC analysts detect adversaries abusing the Kerberos protocol to attack Windows Active Directory environments
Splunk SOAR Recognized in Forrester Now Tech: SOAR, Q2 2022 Report
Security
3 Minute Read

Splunk SOAR Recognized in Forrester Now Tech: SOAR, Q2 2022 Report

Splunk SOAR recognized within Forrester’s report Now Tech: Security Orchestration, Automation, And Response (SOAR), Q2 2022.
Bringing Data-Centric Security to RSAC 2022
Security
3 Minute Read

Bringing Data-Centric Security to RSAC 2022

Check out what Splunk has in store at RSA Conference 2022, including theater sessions, demos and a keynote presentation from Splunk CEO Gary Steele.
Threat Update: Cyclops Blink
Security
6 Minute Read

Threat Update: Cyclops Blink

The Splunk Threat Research Team shares the latest on the payload named Cyclops Blink, which seems to target Customer Premise Equipment devices (CPE) generally prevalent in commercial and residential locations enabling internet connectivity.
CI/CD Detection Engineering: Dockerizing for Scale, Part 4
Security
9 Minute Read

CI/CD Detection Engineering: Dockerizing for Scale, Part 4

Get the latest from the Splunk Threat Research Team on CI/CD Detection Engineering.
Answered: Your Most Burning Questions About Planning And Operationalizing MITRE ATT&CK
Security
4 Minute Read

Answered: Your Most Burning Questions About Planning And Operationalizing MITRE ATT&CK

You asked, we answered. Splunker Matthias Maier compiled all of your most burning questions about planning and operationalizing MITRE ATT&CK in a blog post. Read all about it here.
Staff Picks for Splunk Security Reading April 2022
Security
2 Minute Read

Staff Picks for Splunk Security Reading April 2022

Check out our Splunk security experts' curated list of presentations, white papers, and customer case studies that we feel are worth a read in the month of April.
The Upsurge in Ransomware Attacks in Australia and Opportunities to Protect Data
Security
2 Minute Read

The Upsurge in Ransomware Attacks in Australia and Opportunities to Protect Data

Splunk's Mark Troselj explores the findings of Splunk SURGe's recent ransomware report and explains the importance of making risk mitigation a proactive and strategic focus.
STRT-TA03 CPE - Destructive Software
Security
5 Minute Read

STRT-TA03 CPE - Destructive Software

The Splunk Threat Research Team is monitoring several malicious payloads targeting Customer Premise Equipment (CPE) devices. These are defined as devices that are at customer (Commercial, Residential) premises and that provide connectivity and services to the internet backbone