Getting Data In

How to create a search that will identify when a user has downloaded hacking domain tools?

Ghanayem1974
Path Finder

I don't have proxy logs, but I do have ids/firewalls etc and I want to create a search that will identify when a user has downloaded tools such as nmap, kali etc. any ideas?

0 Karma

elliotproebstel
Champion

Some IDS tools have options for alerting on such downloads. What IDS tools are you using, and are they deployed in a location to view users' web traffic?

0 Karma

Ghanayem1974
Path Finder

cisco firesight i am able to see that urls are being captured just not many.

0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...