Getting Data In

How to create a search that will identify when a user has downloaded hacking domain tools?

Ghanayem1974
Path Finder

I don't have proxy logs, but I do have ids/firewalls etc and I want to create a search that will identify when a user has downloaded tools such as nmap, kali etc. any ideas?

0 Karma

elliotproebstel
Champion

Some IDS tools have options for alerting on such downloads. What IDS tools are you using, and are they deployed in a location to view users' web traffic?

0 Karma

Ghanayem1974
Path Finder

cisco firesight i am able to see that urls are being captured just not many.

0 Karma
Get Updates on the Splunk Community!

Get Operational Insights Quickly with Natural Language on the Splunk Platform

In today’s fast-paced digital world, turning data into actionable insights is essential for success. With ...

What’s New in Splunk Observability Cloud – June 2025

What’s New in Splunk Observability Cloud – June 2025 We are excited to announce the latest enhancements to ...

Almost Too Eventful Assurance: Part 2

Work While You SleepBefore you can rely on any autonomous remediation measures, you need to close the loop ...