Splunk Enterprise

Which product(s) would you use to detect, triage, and act on privilege escalation?

thos13
Explorer

Which product(s) would you use to detect, triage, and act on privilege escalation?

and how would you then proceed in doing so?

Labels (2)
0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

if this is your only issue to find then core splunk is enough. But I suppose that you will have some more issues in your mind or at least those will come later 😉

Personally I propose that you will contact some local Splunk Partners which can help you to look your needs and then select with you a correct product/apps for this. Here are some options which could fulfil your (future) needs:

  • Core Splunk
  • Core Splunk with TA's to collect events
    • Unix / Linux TA 
    • MS TA's based on products which you have in use
    • Some network gear TAs based on your used products 
  • Separate app over Core Splunk
    • InfoSec App for Splunk or
    • Splunk Security Essentials
    • Splunk Enterprise Serurity

Or something else based on your real needs which depends on your company needs.

r. Ismo

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...