04.10.2015 Views

Security Jiujitsu

conf2015_DVeuve_Splunk_SecurityCompliance_SecurityJiujitsuBuildingCorrelation

conf2015_DVeuve_Splunk_SecurityCompliance_SecurityJiujitsuBuildingCorrelation

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Analysis Technique – Combine MulEple Vectors <br />

If you have a number of correlaEon searches firing, you can track the <br />

output of those searches and do a meta analysis. <br />

If you use Enterprise <strong>Security</strong>, use index=notable. If you use a <br />

EckeEng system, query that. If you use the alert manager, use | rest <br />

“/services/alerts/fired_alerts” <br />

CraR a search that looks for mulEple event endpoint alerts, and then <br />

create a high confidence high severity event based on that. <br />

46

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!