Splunk Enterprise Security

Does Splunk ESS include correlation rules for malware activities?

Max
Engager

Does Splunk ESS include, out of the box - functionalities that do not require any additional installation, correlation rules and alert for malware (worm, virus, ecc...) activities?

Thanks in advance,

Max

0 Karma

hazekamp
Builder

maxlanzi,

We have several OOTB correlation searches that leverage data provided by your Antivirus/Malware solutions.

Endpoint - Host With Multiple Infections - Rule
Endpoint - Old Malware Infection - Rule
Endpoint - High Number of Hosts With Infection - Rule
Endpoint - High Number Of Infected Hosts - Rule
Endpoint - High Or Critical Priority Host With Malware - Rule
Endpoint - Recurring Malware Infection - Rule
Endpoint - Outbreak Observed - Rule

We also have a number of OOTB correlation searches that discover activity indicative of malware, but leverage other data sets such as Firewall/Proxy.

If you need a comprehensive list of correlation searches and descriptions, please contact Splunk Sales.

Get Updates on the Splunk Community!

Cloud Platform & Enterprise: Classic Dashboard Export Feature Deprecation

As of Splunk Cloud Platform 9.3.2408 and Splunk Enterprise 9.4, classic dashboard export features are now ...

Explore the Latest Educational Offerings from Splunk (November Releases)

At Splunk Education, we are committed to providing a robust learning experience for all users, regardless of ...

New This Month in Splunk Observability Cloud - Metrics Usage Analytics, Enhanced K8s ...

The latest enhancements across the Splunk Observability portfolio deliver greater flexibility, better data and ...