Skip to main content
false

Tag: Splunk Enterprise Security

Latest Articles

Security 7 Min Read

Detecting Supernova Malware: SolarWinds Continued

Supernova exposes SolarWinds Orion to attack via an in-memory web shell. It needs to be patched and detections below can help identify adversary actions.
.conf & .conf Go 1 Min Read

The Best of .conf20: Security Sessions

We’ve rounded up the top security sessions, all available for easy online viewing, from .conf20 so you can keep up with the latest tools to address alert fatigue, anomaly detection and more.
Security 8 Min Read

Using Splunk to Detect Sunburst Backdoor

The Sunburst Backdoor threat truly burst on the scene as a send off for 2020. The good news is that the Splunk Security team has produced detections you can run in Splunk Enterprise Security to help you protect your environment from this sophisticated threat.
Security 3 Min Read

Gaining Control Over Medical and IoT Devices

It's important for health systems to protect all the devices within their operations to ensure patient data and, ultimately, care remains safe and reliable. Learn how with Medigate and Splunk.
Security 4 Min Read

Better Detections and Cloud Coverage with Splunk Enterprise Security 6.4

New features in Splunk Enterprise Security help you improve your detections and secure your multicloud and hybrid environments.
Tips & Tricks 1 Min Read

Extra, Extra, Tech Talk About It

Our Tech Talks series features technical deep dives into Splunk’s capabilities for Platform, Security, IT Operations and DevOps. Read more here!
Security 2 Min Read

Detecting Data Exfiltration Via the Use of SNICat

TLS SNI extension can now be used to exfiltrate data. Learn how you can add the SNI detection for use in Splunk Enterprise Security.
Security 6 Min Read

Detecting Ryuk Using Splunk Attack Range

A new alert, Ransomware Activity Targeting the Healthcare and Public Health Sector, issued by the CISA poses ongoing and possible imminent attacks against the healthcare sector. Learn how you can detect the Ryuk ransomware as payload with Splunk Attack Range.
Security 3 Min Read

What Do Splunk, Google Cloud, and Australian Cane Toads Have in Common?

Coming soon to a work monitor near you — brand new game scenarios for Boss of the SOC featuring Google Cloud Platform and Google Workspace launching at .conf20.