Splunk Enterprise

MITRE usecases

1ueshkil
Loves-to-Learn

Hi Team,

We are new to Splunk SIEM, Need to create real time use cases based on MITRE Framework for Linux and Palo Alto log sources in customer environment. Kindly help on this.

Labels (1)
0 Karma

1ueshkil
Loves-to-Learn

We have already integrated linux, palo alto,SAP log sources. Just looking to create Linux, Palo alto, SAP use cases which is based on MITRE framework or any attack pattern use cases, as we don't have that much knowledge to create SPL use cases.

0 Karma

1ueshkil
Loves-to-Learn

@inventsekar Could you please suggest on this.

We have already integrated linux, palo alto,SAP log sources. Just looking to create Linux, Palo alto, SAP use cases which is based on MITRE framework or any attack pattern use cases, as we don't have that much knowledge to create SPL use cases.

0 Karma

inventsekar
SplunkTrust
SplunkTrust

Hi @1ueshkil .. I did this UseCases bit long back.. so i got some confusions now. i am just giving you my educated guesses.. 

Let us know, if you have Security Essentials App - ( https://splunkbase.splunk.com/app/3435 )


>>> We have already integrated linux, palo alto,SAP log sources.
Nice. most of the problems solved. You no need to worry about data/logs required for the UseCase creation. Now you need to focus only on UseCase Creation

>>>Just looking to create Linux, Palo alto, SAP use cases which is based on MITRE framework or any attack pattern use cases, as we don't have that much knowledge to create SPL use cases.

Pls select a simple usecase to start with. Lets say DDOS attack on Linux systems. then we can try to work on the UseCase creation step by step. 

0 Karma

1ueshkil
Loves-to-Learn

Yes it was installed.

0 Karma

1ueshkil
Loves-to-Learn

@inventsekar Could you please suggest. Yes that app was installed. 

0 Karma

inventsekar
SplunkTrust
SplunkTrust

Hi @1ueshkil ... we may need more details from you.. 

Pls check this: https://www.splunk.com/en_us/blog/security/using-mitre-att-ck-in-splunk-security-essentials.html

Do you know on Linux and Palo Alto, which use-case you are exactly looking for.. 

0 Karma

1ueshkil
Loves-to-Learn

Hi,

Any kind of real time attacks - Unauthorized attacks, Malicious access attempts, Command and controller traffic, Inbound/outbound malicious traffic, port scanning, palo alto threat detected traffic etc....

0 Karma

inventsekar
SplunkTrust
SplunkTrust

may we know if you have a working splunk environment (splunk indexer(s), linux UF's already sending logs to indexer, required apps installed on SH, etc..) 

if yes, pls suggest us what things exactly you have.. 

OR

do you have nothing and you want to start from zero.. 

0 Karma
Get Updates on the Splunk Community!

Enter the Splunk Community Dashboard Challenge for Your Chance to Win!

The Splunk Community Dashboard Challenge is underway! This is your chance to showcase your skills in creating ...

.conf24 | Session Scheduler is Live!!

.conf24 is happening June 11 - 14 in Las Vegas, and we are thrilled to announce that the conference catalog ...

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...