Skip to main content
false

Security Blogs

Security
3 Min Read
Announcing the availability of Cisco Talos Incident Response services to Splunk customers.

Latest Articles

Security 2 Min Read

Detect Ransomware in Your Data with the Machine Learning Cloud Service

Get your hands on the Machine Learning Cloud Service add-on for Splunk Enterprise Security to start detecting ransomware in your data.
Security 3 Min Read

Working in the SOC with Power Tools: Splunk and Polarity

Build a feedback loop with Splunk Phantom and Polarity by giving your security team context with their data.
Security 2 Min Read

Staff Picks for Splunk Security Reading September 2020

These monthly postings feature the favorite security-centric presentations, white papers and customer case studies from various folks throughout the Splunk security world that we think everyone should read.
Security 5 Min Read

Detecting CVE-2020-1472 (CISA ED 20-04) Using Splunk Attack Range

Microsoft's recent security disclosure of CVE-2020-1472 is extremely harmful to systems that have not been patched or lack mitigations in place. Learn how to prevent and detect CVE-2020-1472 using Splunk Attack Range.
Security 5 Min Read

Adaptable Incident Response With Splunk Phantom Modular Workbooks

Modular Workbooks allow you to effortlessly adapt your security operations workflow. Learn how Splunk Phantom SOAR can help divide tasks into phases, assign responsibilities to team members, and document your work.
Security 3 Min Read

The Business of Cybersecurity: How Security Programs Drive Business Results

Splunk's Brian Spanswick discusses defining, establishing and managing an organization's cybersecurity posture to deliver the results needed for the business to be successful.
Security 1 Min Read

How Ernst & Young Helps Security Analysts Connect the Dots with Splunk SOAR

Learn how Ernst & Young helps security analysts connect the dots with Splunk SOAR for their clients.
Security 2 Min Read

Splunk Named a 2020 Gartner Peer Insights Customers' Choice for Security Information Event Management (SIEM)

We’re honored that Splunk customers chose us as a 2020 Gartner Peer Insights Customers’ Choice for Security Information Event Management (SIEM).
Security 4 Min Read

Staff Picks for Splunk Security Reading August 2020

These monthly postings feature the favorite security-centric presentations, white papers and customer case studies from various folks throughout the Splunk security world that we think everyone should read.
Security 3 Min Read

Don't Let Security Go Up, Up and Away (in the Clouds), Start with Data

Learn how you can start identifying business-critical data, configuring your systems, and demonstrate how to onboard and normalize Windows, Linux and Cisco ASA data into Splunk Cloud so that you can start getting valuable insights today.
Security 2 Min Read

Introducing a New Splunk Add-On for OT Security

The Splunk Add-on for OT Security expands existing Splunk Enterprise Security frameworks to improve security visibility in OT environments for our customers, partners and community members.
Security 2 Min Read

Upping the Auditing Game for Correlation Searches Within Enterprise Security — Part 1: The Basics

We've compiled step-by-step instructions on how to get deeper insight and audit correlation searches running inside your enterprise security environment.
Security 4 Min Read

A Little Splunk MedicinalRub for Your Drovorub Rootkit Questions

Our Splunk Security experts provide some context, clarity and solutions for Splunk customers around the world following the cybersecurity advisory released by the FBI and NSA disclosing the details of a new Linux rootkit named Drovorub.
Security 3 Min Read

A Day in the Life: Secrets of a Top Splunk Security Analyst

From investigating security incidents to triaging alerts and identifying data threats, security analysts play a pivotal role in thwarting organizational cybersecurity threats.
Security 7 Min Read

Using Splunk to Detect Abuse of AWS Permanent and Temporary Credentials

In this blog, the Splunk threat research team shows how to detect suspicious activity and possible abuse of AWS Permanent and Temporary credentials.
Security 3 Min Read

Australia & New Zealand Boss of the SOC Day 2020

The best things come in threes and for the third year in a row, Splunkers down-under will take to the (virtual) thunderdome to battle it out for supreme bragging rights in the Australia & New Zealand Boss of the SOC (BOTS) Day held on August 20, 2020.
Security 7 Min Read

CI/CD Detection Engineering: Splunk's Attack Range, Part 2

In part 2 of our 3-part series, we walk you through how to use Splunk Security-Content, Attack Range and CircleCI to do detection development, continuous testing and deployment as a workflow in your SOC.
Security 4 Min Read

Staff Picks for Splunk Security Reading July 2020

These monthly postings will feature the favorite security-centric presentations, white papers and customer case studies from various peeps in the Splunk (or not) security world that we think everyone should read.