Staff Picks for Splunk Security Reading January 2022

Welcome to the Splunk staff picks blog. Each month, Splunk security experts select presentations, white papers, and customer case studies that we feel are worth a read. Check out our monthly staff security picks and our all-time best picks for security books and articles. We hope you enjoy.

John Stoner

@stonerpsu

Cobalt Strike, a Defender’s Guide – Part 2 by The DFIR Report

"Back in our August Staff Picks, I shared the article Cobalt Strike, a Defender’s Guide. This month, we are fortunate to have part two published by The DFIR Report! This article goes into the various communication profiles that can be created in Cobalt Strike, the malleable C2 configuration and different methods that can be used to detect them. This guide addresses domain fronting, JARM, C2 traffic including DNS and SMB and much much more! It is important to point out that while looking for the low hanging fruit of default configs and known configurations of adversaries is a good place to start, it isn’t the finish line. However, the information provided can serve as a starting point to hypothesize and conduct your own hunts. The article does call out some nice signatures to get started with if you are looking to tackle this and there are a number of different techniques to use depending on the technologies you have deployed in your environment!"

Tamara Chacon

@holly1g0lightly

Space Security in 2022: Expect a Hacked Satellite by Vilius Petkauskas

"We are entering a new age of space commercialization, so what does this mean for security? Will 2022 see the first cyberattack on a space system disclosed publicly? The article written by Vilius Petkauskas of Cybernews talks about just this. Petkauskas speaks with some of leading space security experts and insiders about what they see happening in space cyber security for the year 2022. They briefly touch on encryption, software protections, unwanted attention, and critical infrastructure of thousands of satellites currently orbiting the planet."

Haylee Mills

@7thdrxn

Secrets of Successful Security Programs - Part 1 by Phil Venables

"Phil is incredible at alchemizing insight out of his experience and deciphering trends in the industry, and this is just a whole gold mine. Alternates between a mixture of distilling what security has learned in the past 20 years of coming into being, as well as what the past few years is telling us about the immediate future. Excited for part two!"

Audra Streetman

@audrastreetman

Should Insurance Companies Pay Out for Damage Caused by State-Sponsored Cyberattacks? By Josephine Wolff for Slate

“The Superior Court of New Jersey recently ruled in favor of pharmaceutical company Merck in a lawsuit against its insurer, Ace American. The dispute involved $1.4 billion in losses caused by the NotPetya ransomware attack. Ace American denied the claim and a lengthy legal battle ensued. This ruling is significant because it sets a legal precedent for whether a company’s cyber insurance covers the damage caused by state-sponsored attacks. The court ruled that the “hostile or warlike action” exemption clause in Merck’s property policy does not apply to NotPetya. Insurers will likely respond to this ruling by updating the language in their exclusions to include cyberattacks.”

Related Articles

Predicting Cyber Fraud Through Real-World Events: Insights from Domain Registration Trends
Security
12 Minute Read

Predicting Cyber Fraud Through Real-World Events: Insights from Domain Registration Trends

By analyzing new domain registrations around major real-world events, researchers show how fraud campaigns take shape early, helping defenders spot threats before scams surface.
When Your Fraud Detection Tool Doubles as a Wellness Check: The Unexpected Intersection of Security and HR
Security
4 Minute Read

When Your Fraud Detection Tool Doubles as a Wellness Check: The Unexpected Intersection of Security and HR

Behavioral analytics can spot fraud and burnout. With UEBA built into Splunk ES Premier, one data set helps security and HR reduce risk, retain talent, faster.
Splunk Security Content for Threat Detection & Response: November Recap
Security
1 Minute Read

Splunk Security Content for Threat Detection & Response: November Recap

Discover Splunk's November security content updates, featuring enhanced Castle RAT threat detection, UAC bypass analytics, and deeper insights for validating detections on research.splunk.com.
Security Staff Picks To Read This Month, Handpicked by Splunk Experts
Security
2 Minute Read

Security Staff Picks To Read This Month, Handpicked by Splunk Experts

Our Splunk security experts share their favorite reads of the month so you can follow the most interesting, news-worthy, and innovative stories coming from the wide world of cybersecurity.
Behind the Walls: Techniques and Tactics in Castle RAT Client Malware
Security
10 Minute Read

Behind the Walls: Techniques and Tactics in Castle RAT Client Malware

Uncover CastleRAT malware's techniques (TTPs) and learn how to build Splunk detections using MITRE ATT&CK. Protect your network from this advanced RAT.
AI for Humans: A Beginner’s Field Guide
Security
12 Minute Read

AI for Humans: A Beginner’s Field Guide

Unlock AI with the our beginner's field guide. Demystify LLMs, Generative AI, and Agentic AI, exploring their evolution and critical cybersecurity applications.
Splunk Security Content for Threat Detection & Response: November 2025 Update
Security
5 Minute Read

Splunk Security Content for Threat Detection & Response: November 2025 Update

Learn about the latest security content from Splunk.
Operation Defend the North: What High-Pressure Cyber Exercises Teach Us About Resilience and How OneCisco Elevates It
Security
3 Minute Read

Operation Defend the North: What High-Pressure Cyber Exercises Teach Us About Resilience and How OneCisco Elevates It

The OneCisco approach is not about any single platform or toolset; it's about fusing visibility, analytics, and automation into a shared source of operational truth so that teams can act decisively, even in the fog of crisis.
Data Fit for a Sovereign: How to Consider Sovereignty in Your Digital Resilience Strategy
Security
5 Minute Read

Data Fit for a Sovereign: How to Consider Sovereignty in Your Digital Resilience Strategy

Explore how digital sovereignty shapes resilient strategies for European organisations. Learn how to balance control, compliance, and agility in your data infrastructure with Cisco and Splunk’s flexible, secure solutions for the AI era.