Splunk Tech Talks
Deep-dives for technical practitioners.

ML in Security: Suspiciously Named Processes

WhitneySink
Splunk Employee
Splunk Employee

Screenshot 2023-05-08 at 8.49.44 PM.png

Kumar Sharad, Sr. Threat Researcher, and Abhinav Mishra, Principal Applied Scientist, explain the motivation and goals for ML based detection in ESCU, highlighting the benefits of using pre-trained models over live-trained models. Then they dive into a specific example of how Splunk is using Deep Learning to detect suspiciously named processes and how to deploy it using the Splunk App for Data Science and Deep Learning (DSDL). Finally, they touch on how this comes together in ESCU and discuss additional resources.

Watch this tech talk to learn:

  • How to leverage Deep Learning models to detect suspiciously named processes
  • The design of a RNN based character-level model at the heart of the detection
  • How to use the pre-trained model via the DSDL app

Tech Talk part I:

(view in My Videos)

Tech Talk part II:

(view in My Videos)

Contributors
Get Updates on the Splunk Community!

Automated Threat Analysis: Available in ES Premier

Automated Threat Analysis: Centralize and Accelerate Phishing Investigations in Splunk Enterprise ...

What’s New in Splunk AI: Volume 02

Welcome to the second edition of “What’s New in Splunk AI” where we look at the latest and greatest updates, ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...