All Apps and Add-ons

How to create a detection rule on the LLMNR protocol knowing that I don't have Sysmon just with the logs?

Massin
Observer

Hello,
I wanted to create a detection rule on the LLMNR protocol knowing that I don't have Sysmon just with the logs.
Can you help me please?
thank you and have a great day

Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Please help us help you by telling us more about the use case.

What exactly are you trying to detect?  I presume the information needed usually is supplied by sysmon - have you verified the same information is available in your logs?

---
If this reply helps you, Karma would be appreciated.
0 Karma

Massin
Observer

I try to detect the LLMNR protocol if it is activated by a malicious user

0 Karma

richgalloway
SplunkTrust
SplunkTrust

We still need more information about the use case.  How do you determine the user is malicious?  Have you verified your logs contain the necessary information?

---
If this reply helps you, Karma would be appreciated.
0 Karma

Massin
Observer

Thank you,
we don't have a sysmon

0 Karma
Get Updates on the Splunk Community!

Buttercup Games: Further Dashboarding Techniques (Part 7)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...

Stay Connected: Your Guide to April Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...

Mastering Data Pipelines: Unlocking Value with Splunk

 In today's AI-driven world, organizations must balance the challenges of managing the explosion of data with ...