Introducing the Ransomware Content Browser

Splunk SURGe recently released a whitepaper, blog and video that outline the encryption speeds of 10 different ransomware families. The outcome of this research was that it is unlikely that a defender will be able to do anything once the encryption has started. Ransomware today is also mostly “human-operated” where many systems are sought out and compromised before any encryption activities occur and, once they do, the encryption is just too fast to meaningfully affect the damage done.

Depressing as this might sound, there are actions you as a defender can take to protect yourself. Defense activities should focus on prevention, detection and mitigation “left of boom” where boom refers to the encryption, exfiltration and destruction of data. There are plenty of attacker activities that need to happen long before the “boom” actually occurs. For instance, there is always a stage of consolidation and preparation where the attacker moves laterally via command and control activities to get access to as many systems as possible. Each one of those activities offers you, as a defender, an opportunity to disrupt the attack. Luckily, many of the defense activities are actions that you are probably already doing, or have the ability to do today.

What can we as a company do to help our customers and the wider cyber security community with these defense activities? Looking at the lifecycle of a ransomware attack, as presented beautifully by CERT NZ in this online guide, we see that many of the steps in a ransomware attack are similar to other types of intrusions and attacks. Hence, Splunk users already have the capability and the relevant security content to do something about this problem. We just need to make this content searchable and available as well as “framing” it in a ransomware context.

The outcome is an online environment where the user can interact with all the stages and phases of an attack and highlight existing security content that deal with this specifically. The idea is to provide help in the form of specific content dealing with practical things you can do as a defender to disrupt the attack. Instead of re-inventing the wheel, we used the great work done by CERT NZ to visualize the ransomware lifecycle. The types of content mapped out in this interactive environment includes, detections from our Splunk Threat Research Team (STRT), blog posts and .conf talks by Splunk experts and customers, video tutorials and more.

Screenshot from the Ransomware Content Browser dashboard in Security Essentials.

This interactive browser described above is now available in the latest release of Splunk Security Essentials 3.6.0 on Splunkbase. Get it while it’s hot!

Happy Hunting!

Johan

Authors and Contributors: As always, security at Splunk is a family business. Credit to authors and collaborators Johan Bjerke and Alex Salesi.

Related Articles

Predicting Cyber Fraud Through Real-World Events: Insights from Domain Registration Trends
Security
12 Minute Read

Predicting Cyber Fraud Through Real-World Events: Insights from Domain Registration Trends

By analyzing new domain registrations around major real-world events, researchers show how fraud campaigns take shape early, helping defenders spot threats before scams surface.
When Your Fraud Detection Tool Doubles as a Wellness Check: The Unexpected Intersection of Security and HR
Security
4 Minute Read

When Your Fraud Detection Tool Doubles as a Wellness Check: The Unexpected Intersection of Security and HR

Behavioral analytics can spot fraud and burnout. With UEBA built into Splunk ES Premier, one data set helps security and HR reduce risk, retain talent, faster.
Splunk Security Content for Threat Detection & Response: November Recap
Security
1 Minute Read

Splunk Security Content for Threat Detection & Response: November Recap

Discover Splunk's November security content updates, featuring enhanced Castle RAT threat detection, UAC bypass analytics, and deeper insights for validating detections on research.splunk.com.
Security Staff Picks To Read This Month, Handpicked by Splunk Experts
Security
2 Minute Read

Security Staff Picks To Read This Month, Handpicked by Splunk Experts

Our Splunk security experts share their favorite reads of the month so you can follow the most interesting, news-worthy, and innovative stories coming from the wide world of cybersecurity.
Behind the Walls: Techniques and Tactics in Castle RAT Client Malware
Security
10 Minute Read

Behind the Walls: Techniques and Tactics in Castle RAT Client Malware

Uncover CastleRAT malware's techniques (TTPs) and learn how to build Splunk detections using MITRE ATT&CK. Protect your network from this advanced RAT.
AI for Humans: A Beginner’s Field Guide
Security
12 Minute Read

AI for Humans: A Beginner’s Field Guide

Unlock AI with the our beginner's field guide. Demystify LLMs, Generative AI, and Agentic AI, exploring their evolution and critical cybersecurity applications.
Splunk Security Content for Threat Detection & Response: November 2025 Update
Security
5 Minute Read

Splunk Security Content for Threat Detection & Response: November 2025 Update

Learn about the latest security content from Splunk.
Operation Defend the North: What High-Pressure Cyber Exercises Teach Us About Resilience and How OneCisco Elevates It
Security
3 Minute Read

Operation Defend the North: What High-Pressure Cyber Exercises Teach Us About Resilience and How OneCisco Elevates It

The OneCisco approach is not about any single platform or toolset; it's about fusing visibility, analytics, and automation into a shared source of operational truth so that teams can act decisively, even in the fog of crisis.
Data Fit for a Sovereign: How to Consider Sovereignty in Your Digital Resilience Strategy
Security
5 Minute Read

Data Fit for a Sovereign: How to Consider Sovereignty in Your Digital Resilience Strategy

Explore how digital sovereignty shapes resilient strategies for European organisations. Learn how to balance control, compliance, and agility in your data infrastructure with Cisco and Splunk’s flexible, secure solutions for the AI era.