Splunk Enterprise Security

Does Splunk ESS include correlation rules for malware activities?

Max
Engager

Does Splunk ESS include, out of the box - functionalities that do not require any additional installation, correlation rules and alert for malware (worm, virus, ecc...) activities?

Thanks in advance,

Max

0 Karma

hazekamp
Builder

maxlanzi,

We have several OOTB correlation searches that leverage data provided by your Antivirus/Malware solutions.

Endpoint - Host With Multiple Infections - Rule
Endpoint - Old Malware Infection - Rule
Endpoint - High Number of Hosts With Infection - Rule
Endpoint - High Number Of Infected Hosts - Rule
Endpoint - High Or Critical Priority Host With Malware - Rule
Endpoint - Recurring Malware Infection - Rule
Endpoint - Outbreak Observed - Rule

We also have a number of OOTB correlation searches that discover activity indicative of malware, but leverage other data sets such as Firewall/Proxy.

If you need a comprehensive list of correlation searches and descriptions, please contact Splunk Sales.

Get Updates on the Splunk Community!

Index This | I’m short for "configuration file.” What am I?

May 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with a Special ...

New Articles from Academic Learning Partners, Help Expand Lantern’s Use Case Library, ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Your Guide to SPL2 at .conf24!

So, you’re headed to .conf24? You’re in for a good time. Las Vegas weather is just *chef’s kiss* beautiful in ...