Security Jiujitsu
conf2015_DVeuve_Splunk_SecurityCompliance_SecurityJiujitsuBuildingCorrelation
conf2015_DVeuve_Splunk_SecurityCompliance_SecurityJiujitsuBuildingCorrelation
- No tags were found...
Create successful ePaper yourself
Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.
Analysis Technique – Combine MulEple Vectors <br />
If you have a number of correlaEon searches firing, you can track the <br />
output of those searches and do a meta analysis. <br />
If you use Enterprise <strong>Security</strong>, use index=notable. If you use a <br />
EckeEng system, query that. If you use the alert manager, use | rest <br />
“/services/alerts/fired_alerts” <br />
CraR a search that looks for mulEple event endpoint alerts, and then <br />
create a high confidence high severity event based on that. <br />
46