Splunk for Incident Response: Practical Investigation Scenarios
Master Splunk for incident response: investigate, analyze, and mitigate security threats with practical scenarios and advanced techniques.
...
Share
Splunk Fundamentals for Incident Responders
Unit 1: Introduction to Splunk for Security
Splunk for Security
Navigating the Interface
Data Ingestion Basics
Indexes Explained
Searching 101
Unit 2: Search Processing Language (SPL) Fundamentals
The 'search' Command
Filtering with 'where'
Field Extractions
The Power of 'stats'
Transforming with 'eval'
Unit 3: Basic Reporting and Visualization
Creating Basic Reports
The 'table' Command
Visualizing with 'chart'
Dashboards 101
Saving Your Work
Investigating Common Security Incidents with Splunk
Unit 1: Malware Infection Investigations
Malware Event Basics
Hunting Malware Hashes
Process Behavior Analysis
Detecting Lateral Movement
Malware Alerting
Unit 2: Phishing Attack Investigations
Email Log Analysis 101
Spotting Suspicious Senders
Link & Attachment Analysis
User Behavior Analysis
Phishing Alerting
Unit 3: Brute-Force Attack Investigations
Auth Log Basics
Detecting Failed Logins
Successful Login Analysis
Account Lockout Analysis
Brute-Force Alerting
Advanced Splunk Techniques for Incident Response
Unit 1: Threat Intelligence Integration
Threat Intel Overview
Choosing Intel Feeds
Configuring Threat Intel
Intel Dashboards & Alerts
Testing Threat Intel
Unit 2: MITRE ATT&CK Framework
ATT&CK Framework Intro
Mapping Events to ATT&CK
ATT&CK Dashboards
ATT&CK for Prioritization
Simulating ATT&CK
Unit 3: Automating Incident Response
REST API Intro
Scripting with the API
Automated Enrichment
Automated Actions
API Security
Leveraging Splunk Enterprise Security (ES) and Machine Learning
Unit 1: Introduction to Splunk Enterprise Security (ES)
ES: What & Why?
ES Interface Overview
ES Data Models
Identity & Access in ES
Assets & Identities
Unit 2: Incident Investigation with Splunk ES
Incident Review Workflow
Notable Events Deep Dive
Correlation Searches
Risk Framework in ES
Visualizing Incident Data
Unit 3: Machine Learning for Security in Splunk
ML for Security: Intro
MLTK: First Look
Anomaly Detection
Predictive Analytics
Custom ML Models
Unit 4: Advanced Splunk ES Customization
Custom Dashboards
Custom Correlation Rules
Custom Alerts
Threat Intelligence Feeds
ES REST API