- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

It's impossible to detect WannaCry by app ES Content Updates?
Someone have experience in this?
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content


If you haven't looked at the Splunk Security Essentials for Ransomware app, it has some useful reference searches.
There is also a Security Investigation online demo that might give you some pointers.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content


If you haven't looked at the Splunk Security Essentials for Ransomware app, it has some useful reference searches.
There is also a Security Investigation online demo that might give you some pointers.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

Hello test_qweqwe
These links might help by blocking the domains that could host ransomware using Splunk ES.
Official Documentation:
http://docs.splunk.com/Documentation/ES/4.6.0/User/Configureblocklists#Add_a_ransomware_threat_feed_...
Splunk Blog:
https://www.splunk.com/blog/2017/01/24/enhancing-enterprise-security-for-ransomware-detection.html
Hope it helps!
Thanks!
