Splunk Search

Reconnaissance of BOTSv3

splunkbegineer
New Member

Hello,

I have completed the BOTSv1 investigation. But when it comes to BOTSv3, it is about cloud. May I know on how to reconnaissance if no information provided?  I only found cloud source type such as aws*. Then after that I do not have any idea to continue the reconnaissance

https://www.youtube.com/watch?v=q4LmktgWsRE&t=230s

Please kindly help and advise.

 

Thank you

Labels (1)
Tags (1)
0 Karma
Get Updates on the Splunk Community!

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

New This Month - Observability Updates Give Extended Visibility and Improve User ...

This month is a collection of special news! From Magic Quadrant updates to AppDynamics integrations to ...

Intro to Splunk Synthetic Monitoring

In our last post, we mentioned that the 3 key pieces of observability – metrics, logs, and traces – provide ...