Splunk Enterprise Security

Splunk Security Essentials : Data Exfiltration

mahe90
Explorer

Hi,

SSE use case maps to the MITRE ATT&CK tactics. As we can see from MITRE ATT&CK, each tactic has various techniques. For "Data Exfiltration" , the techniques are "Data Transfer Size Limits" , "Exfil over Alternate Protocol" etc.

For example: In SSE, the example "Sources Sending a High Volume of DNS Traffic" mapped to MITRE ATT&CK's DataExfiltration. Splunk reports outliers. How do I know which technique splunk used to determine the outlier? Or Splunk doesn't use any of these techniques , it just uses the total bytes transferred and looking for anomalies and deviations from normal traffic levels.?

Thanks,
Mahesh

Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...