Threat Hunting with Splunk: Hands-on Tutorials for the Active Hunter

At Splunk, you may hear us pontificating on our ponies about how awesome and easy it is to use Splunk to hunt for threats.

Why, all you need to do is use X and Y with Splunk to find a Z score (no zombies were injured) and BOOM! That baddie in your network is detected.

Going back to at least a decade, we’ve tried to make it easy — as you’ll see in the resources below — and yet threat hunting is about as easy as telling someone how easy it is to draw an owl. (Hint: it isn’t.) So, that’s why we started writing this series in 2017.

Today, we are doubling-down on our threat hunting capabilities. That's why we're updating this series, one article at a time, verifying that each tutorial is the best resource for some aspect of hunting, all using Splunk.

Show me the tutorials!

Want to learn more about threat hunting in general? Keep reading for more information about hunting and the team behind this series, SURGe.

Threat Hunting resources

So, let's make it clear, this entire series is about using Splunk for your threat hunting activities.

Here's some brand new and forever-favorite resources, too, that are about threat hunting with or without Splunk:

Meet the team

The team behind this series is SURGe, an in-house security research team at Splunk. The SURGe team focuses on in-depth analysis of the latest cybersecurity news and finding answers to security problems. All of this is delivered to you in a variety of forms:

Check out all these resources from SURGe and sign up for rapid response alerts.

And now, onto the hunting tutorials!

Tutorials for threat hunting with Splunk

This series will serve as your foundation for hunting with Splunk. (Brand new to Splunk? Explore our SIEM solution, Splunk Enterprise Security: Learn about Splunk ES | Tour Splunk ES)

Each of these articles take a single Splunk search command or hunting concept and break it down to its basic parts. We will help you create a solid base of Splunk knowledge that you can then use in your own environment to hunt for evil. We will cover everything from hypothesis generation to IDS. Splunk commands like stats, eval and lookups will be examined. And have we got queries for you!

As always, happy hunting!

Related Articles

Introducing Attack Range v3.0
Security
3 Minute Read

Introducing Attack Range v3.0

Explore the new features introduced in version 3.0 of the Splunk Attack Range, aimed at helping you build resilient, high-quality threat detections.
PCI Compliance Done Right with Splunk
Security
3 Minute Read

PCI Compliance Done Right with Splunk

Check out the added features to support PCI compliance in the latest Splunk App for PCI Compliance version 5.1, now generally available.
CISA Top Malware Summary
Security
8 Minute Read

CISA Top Malware Summary

This blog summarizes the Splunk Threat Research Team’s (STRT) recent review of the CISA Top 10 Malware strains for the year 2021 report.
Unknown and unseen, the cyberwar between Crimsonia and Berylia
Security
3 Minute Read

Unknown and unseen, the cyberwar between Crimsonia and Berylia

First week of December, unbeknown to many the island of Berylia engaged in cyberwarfare with their neighbors Crimsonia after a number of months of heightened tensions. The goal of the Berylian attackers was to disable as many critical infrastructure components of the Crimsonian Ministry of Defense in order to prevent the Crimsonian Navy from sailing. This would give the Berylian fleet the time to aid and protect critical locations and assets.
Splunk Named a Leader in The Forrester Wave™: Security Analytics Platforms, Q4 2022
Security
1 Minute Read

Splunk Named a Leader in The Forrester Wave™: Security Analytics Platforms, Q4 2022

We’re thrilled to share that Splunk has been named a Leader in The Forrester Wave™: Security Analytics Platforms, Q4 2022.
Staff Picks for Splunk Security Reading December 2022
Security
3 Minute Read

Staff Picks for Splunk Security Reading December 2022

Welcome to the Splunk staff picks blog. Each month, Splunk security experts curate a list of presentations, whitepapers, and customer case studies that we feel are worth a read.
Zoom. Enhance!: Finding Value in Macro-level ATT&CK Reporting
Security
8 Minute Read

Zoom. Enhance!: Finding Value in Macro-level ATT&CK Reporting

Blog description
Using Splunk to Secure Your Productivity and Team Collaboration Environment
Security
2 Minute Read

Using Splunk to Secure Your Productivity and Team Collaboration Environment

See how Splunk helps teams work and collaborate securely while using Google Chrome and Google Workspace.
Do More with Splunk Security Essentials 3.7.0
Security
2 Minute Read

Do More with Splunk Security Essentials 3.7.0

Check out some highlights of the new features available in Splunk Security Essentials 3.7.0.