Splunk Enterprise

Mapping to Mitre attack techniques

neerajs_81
Builder

HI All,  We have couple of searches as shown below 
1. User Login From Suspicious Countries

2. Multiple AWS Console Failed Login Attempts from Different Source IPs

3. High CPU or Memory Usage on a server 

Can someone pls advise which Mitre techniques can each one of these be mapped to?

Thanks

Tags (1)
0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...