Skip to main content
false

Security Blogs

Security
3 Min Read
Announcing the availability of Cisco Talos Incident Response services to Splunk customers.

Latest Articles

Security 5 Min Read

How Do I Add COVID (or Any) Threat Intelligence From the Internet to Splunk Enterprise Security?

This is another installment of the "Dear Buttercup..." series. Many organizations struggle with buying or affording threat intelligence to plug into Enterprise Security.
Security 2 Min Read

Asset & Identity for Splunk Enterprise Security - Part 3: Empowering Analysts with More Attributes in Notables

This is part three in a three part series on the Asset & Identity framework in Splunk Enterprise Security, focusing providing additional visibility and context to analysts with a notable event.
Security 3 Min Read

Top 10 Things Keeping CISOs Up at Night in 2020 | Splunk

CISOs face no shortage of challenges. Expanding attack surfaces and complex cloud security environments have given rise to new advanced threats.
Security 4 Min Read

Asset & Identity for Splunk Enterprise Security - Part 2: Adding Additional Attributes to Assets

This is part two in a three part series on the Asset & Identity framework in Splunk Enterprise Security, focusing on adding additional field or attributes to further contextualize systems being monitored.
Security 3 Min Read

Between Two Alerts: Easy VPN Security Monitoring with Splunk Enterprise Security

It’s a whole new world we’re living in, at least for now. This little tutorial will help you stay on top of your security game while in the world of Enterprise Security.
Security 1 Min Read

Introducing: Between Two Alerts

Splunk Security is excited to introduce a new series, Between Two Alerts, an ongoing digital gateway into various aspects of security.
Security 3 Min Read

Top 5 Cybersecurity Threats to Watch in 2020

To prepare for what’s ahead, we've compiled five of the top cybersecurity threats you might encounter in 2020.
Security 4 Min Read

Asset & Identity for Splunk Enterprise Security - Part 1: Contextualizing Systems

This is part one in a three part series on the Asset & Identity framework in Splunk Enterprise Security, focusing on gaining context on systems being monitored.
Security 7 Min Read

Use Cloud Infrastructure Data Model to Detect Container Implantation (MITRE T1525)

Using cloud infrastructure data model to detect possible container implantation (Mitre Cloud Matrix technique T1525)
Security 2 Min Read

WFH: Welcome to the New Normal

What happens when your entire workforce goes remote? We're here to help give you some answers.
Security 2 Min Read

Boss of the SOC v3 Dataset Released!

The tradition continues! We are happy to announce that the Boss of the SOC (BOTS) v3 dataset has been released under an open-source license and is available for download.
Security 2 Min Read

Securing a New Way of Working: You Gotta Love the CVEs

We're breaking down how to manage all the inbound VPN connections from people working from home, and what other vulnerabilities you should be monitoring for
Security 1 Min Read

Securing a New Way of Working: Wait, What’s This Thing Running on Your Machine?

Identify and investigate prohibited or unauthorized software or processes that may be concealing malicious behavior within your environment
Security 1 Min Read

Securing a New Way of Working: Monitoring Those Endpoints

Increase the monitoring of remote endpoints with Splunk Security Essentials, aimed at making security simpler
Security 1 Min Read

Securing a New Way of Working: Who Let the Data Out?

We break down the approach of implementing relevant threat detections through the lens of cybersecurity frameworks
Security 1 Min Read

Securing a New Way of Working

Practical advice and best practice guides to help you better protect your organization and infrastructure to manage remote worker security better
Security 4 Min Read

Staff Picks for Splunk Security Reading March 2020

These monthly postings will feature the favorite security-centric presentations, white papers and customer case studies from various peeps in the Splunk (or not) security world that WE think everyone should read. If you would like to read other months, please take a peek at previous posts in the "Staff Picks" series!
Security 2 Min Read

The CISO Says So: A Fireside Chat with Yassir Abousselham

Splunker Meera Shankar recaps the highlights of her fireside chat with Splunk CISO, Yassir Abousselham, at RSA Conference 2020.