Splunk for InfoSec Professionals

No ratings

Presented at saintcon 2017 by

Help us protect EquilFacts! The imaginary company, a leading provider of facts, might have been breached. Use the power of Splunk to unveil suspicious events and protect the company from future incidents. We’ll use Splunk to help EquilFacts trace phishing emails and data exfiltration, service accounts takeover, suspicious encoded Powershell commands, new autoruns and mysterious creation of privileged accounts, C&C communications and more. This entry-level, hands-on training will introduce students to Splunk in the context of EquilFacts’ information-security tasks. We'll understand what Splunk is (and what it isn't), go over architecture and deployment scenarios, and take a bird eye's view of how Splunk works behind the scenes. We'll review the Search Processing Language and use it for basic querying of large datasets, as we investigate suspicious account and machine activities. We'll then dive into more complex searches and create interesting queries, reports, dashboards, and alerts, all applicable to monitoring, investigating, and incident response. Disclaimer: all log events appearing in this class are fictitious. Any resemblance to real log events, living or dead, is purely coincidental.