Splunk Tech Talks
Deep-dives for technical practitioners.

Detecting Remote Code Executions With the Splunk Threat Research Team

WhitneySink
Splunk Employee
Splunk Employee

Remote code execution (RCE) vulnerabilities pose a significant risk to organizations. If exploited, they allow attackers to easily execute arbitrary code on affected systems without authentication — and open the door to use additional tactics and techniques to cause further harm.

To support defenders against these attacks, the Splunk Threat Research Team regularly creates new out-of-the-box security content for use in Splunk Enterprise Security. Join this Tech Talk to learn more from Michael Haag, Principal Threat Researcher, who will provide:

  • An overview of the latest security content the team has developed to defend against RCEs
  • Best practices for implementing and using this content
  • A walkthrough of the detection engineering process the Splunk Threat Research Team follows to create security content for defending against CVEs

Watch the full Tech Talk here:

(view in My Videos)

Tags (1)
Contributors
Get Updates on the Splunk Community!

A Four-Part Event Series: Full Stack Observability For the AI Era

As AI reshapes applications, infrastructure, and the way teams operate, the traditional boundaries of ...

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...