Community Blog
Get the latest updates on the Splunk Community, including member experiences, product education, events, and more!

Tech Talk Recap | Mastering Threat Hunting

DayaSCanales
Retired

Mastering Threat Hunting

Dive into the world of threat hunting, exploring the key differences between indicator-based and behavior-based approaches.

Watch this Tech Talk recap to learn:

  • Approaches to Threat Detection and Threat Hunting
  • How to identify potentially malicious activity in your own logs that you may have otherwise missed
  • How to mature your SOC practices

 

Understanding Indicator and Behavior based Threat Hunting:

(view in My Videos)

DayaSCanales_8-1758137852407.gifDayaSCanales_8-1758137852407.gif

Indicator Based:

  • Easier
  • Can be run off any log containing indicators
  • Relies heavily on external threat intelligence:
    TI collects the IOC's and associates them to relevant threat actors, campaigns, malware families, etc..

Behavior Based:

  • Harder
  • Generally relies on OS or cloud specific logs
  • Relies heavily on external threat intelligence:
    TI analyzes threat and malware behavior and produces hunt packages (Sigma, Yara, Snort, etc....)

 

Most organizations need to use thread intelligence to empower their tools and the people that doing the cyber thread operations

(view in My Videos)

 

Sigma:

Open source platform agnostic threat hunting package format.

  • There is NO official Sigma to Splunk decoder
  • Note that it requires adjustment and tuning
  • Allows organizations that may have different underlying log management and SIM providers to work together and build hunting packages that can be worked across the tooling

DayaSCanales_10-1758137852409.gifDayaSCanales_10-1758137852409.gif

(view in My Videos)

 

Recorded Future Intelligence:

The world's largest cyber threat intelligence organization now due to the way it collects data.

Takes a unified approach to deliver unbiased, comprehensive, and real-time threat intelligence.

DayaSCanales_11-1758137852409.gifDayaSCanales_11-1758137852409.gif

(view in My Videos)

 

Within Splunk Recorded Future has multiple integrations:

DayaSCanales_12-1758137852409.gifDayaSCanales_12-1758137852409.gif

(view in My Videos)

 

Demo:

DayaSCanales_13-1758137852410.gifDayaSCanales_13-1758137852410.gif

(view in My Videos)
 

(view in My Videos)
DayaSCanales_14-1758137852410.gifDayaSCanales_14-1758137852410.gif

If you are interested in watching the full recording, click here.

Contributors
Get Updates on the Splunk Community!

Developer Spotlight with Denis Gladkikh

From Splunk Engineer to Kubernetes App Builder Denis GladkikhWhat happens when a lifelong developer turns a ...

Governing Enterprise AI, Bringing Cisco Telemetry Home, and More from Splunk Lantern

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...