Splunk [Security, Compliance and Fraud Track] 2019 .conf Videos w/ Slides

ATT&CK™ing Linux with SPL [Splunk Enterprise, Splunk Enterprise Security]


Listen Later

In this session we will discuss using Splunk to detect a range of Linux-based adversary techniques from MITRE’s ATT&CK™ framework. We will also demonstrate how event sequencing can be used to map a path through the ATT&CK™ matrix and improve overall detection fidelity. We will provide auditd configuration suggestions for Linux endpoints to support greater coverage.

Speaker(s)
Doug Brown, Senior Information Security Analyst, Red Hat

Slides PDF link - https://conf.splunk.com/files/2019/slides/SEC1156.pdf?podcast=1577146214

Product: Splunk Enterprise, Splunk Enterprise Security

Track: Security, Compliance and Fraud

Level: Advanced

...more
View all episodesView all episodes
Download on the App Store

Splunk [Security, Compliance and Fraud Track] 2019 .conf Videos w/ SlidesBy Splunk