Splunk Enterprise Security

How do I search for rogue Server added to my environment including info about the Hacker(s)

SamHTexas
Builder

How do I search for rogue Server added to my environment including info about the Hacker(s)

Labels (1)
Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

That's what's called Hardware Asset Management (HWAM).  You have a list of devices that are allowed/expected on the on the network and a list of devices that ARE on the network then you compare them.  Any unexpected devices are considered rogue until they are discovered to be legitimate.

See https://us-cert.cisa.gov/cdm/capabilities/hwam and https://us-cert.cisa.gov/sites/default/files/cdm_files/HWAM_CapabilityDescription.pdf

Information about the "hacker" is harder to come by.  With luck, when you find the rogue machine you'll also find the person responsible (the user, most likely).

---
If this reply helps you, Karma would be appreciated.
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.


Introducing Unified TDIR with the New Enterprise Security 8.2

Read the blog
Get Updates on the Splunk Community!

Data Persistence in the OpenTelemetry Collector

This blog post is part of an ongoing series on OpenTelemetry. What happens if the OpenTelemetry collector ...

Introducing Splunk 10.0: Smarter, Faster, and More Powerful Than Ever

Now On Demand Whether you're managing complex deployments or looking to future-proof your data ...

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...