Getting Data In

How to create a search that will identify when a user has downloaded hacking domain tools?

Ghanayem1974
Path Finder

I don't have proxy logs, but I do have ids/firewalls etc and I want to create a search that will identify when a user has downloaded tools such as nmap, kali etc. any ideas?

0 Karma

elliotproebstel
Champion

Some IDS tools have options for alerting on such downloads. What IDS tools are you using, and are they deployed in a location to view users' web traffic?

0 Karma

Ghanayem1974
Path Finder

cisco firesight i am able to see that urls are being captured just not many.

0 Karma
Get Updates on the Splunk Community!

Application management with Targeted Application Install for Victoria Experience

  Experience a new era of flexibility in managing your Splunk Cloud Platform apps! With Targeted Application ...

Index This | What goes up and never comes down?

January 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Splunkers, Pack Your Bags: Why Cisco Live EMEA is Your Next Big Destination

The Power of Two: Splunk + Cisco at "Ludicrous Scale"   You know Splunk. You know Cisco. But have you seen ...