Have you ever had an idea that would improve incident response? I did. I knew I could save security analysts time by providing a tool that enabled analysts to determine if an endpoint had persistent malware present in seconds. However, it would need to integrate seamlessly into their incident response workflow and have a quality user interface. Frankly, that felt like an insurmountable hurdle for someone with little front-end development experience. I was pleasantly surprised to find that even as a solo developer, I was able to create a full-featured Splunk App with an interface that looks like it was designed by someone far more talented. Through a demonstration of my incident response app and a discussion of my experience building it, I’ll show you how Splunk makes it easier and, more importantly, realistic to bring your own ideas to life. I’ll also share a few pain-points I encountered so you can avoid some of the mistakes I made.
Slides PDF link - https://conf.splunk.com/files/2019/slides/DEV1308.pdf?podcast=1577146223