Splunk Tech Talks
Deep-dives for technical practitioners.

Detecting Trickbot with Splunk

melissap
Splunk Employee
Splunk Employee

View our Tech Talk: Security Edition, Detecting Trickbot with Splunk 

(view in My Videos)

Trickbot is a very popular crimeware carrier associated with recent ransomware campaigns. It is a trojan that has gained popularity from being effective at infecting and propagating botnets – one of the main financial drivers of cyber criminal groups.

The effectiveness of trickbot crimeware comes from its stealthiness and versatility in installing payloads for further lateral movement and post-exploitation profit-driven activities such as cryptocurrency, ransomware, or banking fraud. But don’t worry! The Splunk Security Research team has developed an analytic story targeting Trickbot TTPs to help you detect them in your environment and respond immediately. 

Tune in to learn

  • How Trickbots, botnets, and webinjects work together in a malicious cyber campaign 
  • How to utilize pre-built searches to detect Trickbots in your environment
  • How to utilize pre-built automated playbooks to respond to Trickbots

 

Contributors
Get Updates on the Splunk Community!

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...

SplunkTrust Application Period is Officially OPEN!

It's that time, folks! The application/nomination period for the 2026-2027 SplunkTrust is officially open. If ...