Splunk Tech Talks
Deep-dives for technical practitioners.

ML in Security: Suspiciously Named Processes

WhitneySink
Splunk Employee
Splunk Employee

Screenshot 2023-05-08 at 8.49.44 PM.png

Kumar Sharad, Sr. Threat Researcher, and Abhinav Mishra, Principal Applied Scientist, explain the motivation and goals for ML based detection in ESCU, highlighting the benefits of using pre-trained models over live-trained models. Then they dive into a specific example of how Splunk is using Deep Learning to detect suspiciously named processes and how to deploy it using the Splunk App for Data Science and Deep Learning (DSDL). Finally, they touch on how this comes together in ESCU and discuss additional resources.

Watch this tech talk to learn:

  • How to leverage Deep Learning models to detect suspiciously named processes
  • The design of a RNN based character-level model at the heart of the detection
  • How to use the pre-trained model via the DSDL app

Tech Talk part I:

Video Player is loading.
Current Time 0:00
Duration 0:00
Loaded: 0%
Stream Type LIVE
Remaining Time 0:00
 
1x
    • Chapters
    • descriptions off, selected
    • captions off, selected
      (view in My Videos)

      Tech Talk part II:

      Video Player is loading.
      Current Time 0:00
      Duration 0:00
      Loaded: 0%
      Stream Type LIVE
      Remaining Time 0:00
       
      1x
        • Chapters
        • descriptions off, selected
        • captions off, selected
          (view in My Videos)

          Get Updates on the Splunk Community!

          .conf25 Registration is OPEN!

          Ready. Set. Splunk! Your favorite Splunk user event is back and better than ever. Get ready for more technical ...

          Detecting Cross-Channel Fraud with Splunk

          This article is the final installment in our three-part series exploring fraud detection techniques using ...

          Splunk at Cisco Live 2025: Learning, Innovation, and a Little Bit of Mr. Brightside

          Pack your bags (and maybe your dancing shoes)—Cisco Live is heading to San Diego, June 8–12, 2025, and Splunk ...