Analytics Story: Splunk Vulnerabilities

Description

Keeping your Splunk Enterprise deployment up to date is critical and will help you reduce the risk associated with vulnerabilities in the product.

Why it matters

This analytic story includes detections that focus on attacker behavior targeted at your Splunk environment directly.

Detections

Name ▲▼ Technique ▲▼ Type ▲▼
Splunk RCE via User XSLT Exploitation of Remote Services Hunting
Splunk RCE Through Arbitrary File Write to Windows System Root Exploitation of Remote Services Hunting
Splunk Authentication Token Exposure in Debug Log Log Enumeration TTP
Splunk Sensitive Information Disclosure in DEBUG Logging Channels Unsecured Credentials Hunting
Splunk XSS Privilege Escalation via Custom Urls in Dashboard Drive-by Compromise Hunting
Splunk User Enumeration Attempt Valid Accounts TTP

Data Sources

Name ▲▼ Platform ▲▼ Sourcetype ▲▼ Source ▲▼
Splunk Splunk icon Splunk splunkd_ui_access splunkd_ui_access.log

References


Source: GitHub | Version: 3