Skip to main content
false

Security Blogs

Security
3 Min Read
Announcing the availability of Cisco Talos Incident Response services to Splunk customers.

Latest Articles

Security 2 Min Read

Fight Web Fraud with Splunk Enterprise Security Content Update's October Release

Use Splunk Enterprise Security Content Update (ESCU) searches to help you detect and prevent web fraud
Security 3 Min Read

Staff Picks for Splunk Security Reading October 2018

A selection of presentations, white papers and blog posts you might have missed in this month (or before), handpicked from the Splunk security world
Security 2 Min Read

“Are We Secure?” Lessons Learned From The CISO Of A Leading Saudi Bank

A Splunk customer's presentation at Gartner’s 2018 Security Risk and Management Summit
Security 2 Min Read

Splunk + Cisco = Endpoint Monitoring With No Added Installs

See how the Cisco AnyConnect Network Visibility Module delivers network flow data and execution data from all endpoints to Splunk
Security 1 Min Read

A Threat-Delivery Service for Slacking Hackers?

Once a mere trojan downloader, Emotet has evolved to become a threat-delivery service.
Security 6 Min Read

Go With the Flow - Network Telemetry (VPC Data) in AWS

This blog post describes how to use VPC data from AWS in Splunk to hunt hunt hunt!
Security 5 Min Read

CloudTrail - Digital Breadcrumbs for AWS

This blog post reviews AWS cloudtrail as a security logging source and how to hunt in it
Security 1 Min Read

Three Questions For Empowering Security: From Gartner’s Risk and Security Management Summit Europe

Key takeaways from this year's Gartner Risk and Security Management Summit Europe
Security 4 Min Read

November Spawned an Osquery

This blogs reviews how to hunt through osquery logs
Security 2 Min Read

Mount an Effective Defense Against Credential Dumping

Learn about the new Analytic Stories and searches in the August releases of Splunk's Enterprise Security Content Update
Security 3 Min Read

I Azure You, This Will Be Useful

This blog post describes how to use Azure Active directory for basic hunting and discovery
Security 3 Min Read

Staff Picks for Splunk Security Reading August 2018

A selection of presentations, white papers and blog posts you might have missed in this month (or before), handpicked from the Splunk security world
Security 3 Min Read

The Future is Cloudy with a Chance of Microsoft Office 365

This blog reviews the data that comes out of Office365 and how to use it to hunt in Splunk.
Security 2 Min Read

What Keeps the CISO Awake at Night? Four Dreaded Security Headlines

Would your organization's security team be prepared if these headlines appear in tomorrow's news?
Security 4 Min Read

Here's What's New in ESCU: July 2018

Find out what's new in the July 2018 releases of Splunk Enterprise Security Content Update (ESCU)!
Security 3 Min Read

Staff Picks for Splunk Security Reading July 2018

A selection of presentations, white papers and blog posts you might have missed in this month (or before), handpicked from the Splunk security world
Security 5 Min Read

I Have a Fever, and the Only Cure for It Is More Feedback

A how-to on providing feedback from hunting into security operations
Security 3 Min Read

Domestic Intelligence Service of the Federal Republic of Germany Warns About Cyber Attacks

What's happened, how to investigate if you've been affected and what you should do next.