Free and Essential App for Splunk
Cyber Security Essentials is a must-have tool for Splunk users, designed to detect traces of advanced persistent threats (APTs), threat actors, state-sponsored attackers, malware, and exploits in your Splunk event logs. All detected malware, exploits, and threat actors are mapped to the MITRE ATT&CK framework, providing deep insight into potential risks.
Cyber Security Essentials identifies a wide range of malware, including:
1. Viruses.
2. Worms.
3. Ransomware.
4. Bots.
5. Trojan horses.
6. Keyloggers.
7. Rootkits.
8. Spyware.
9. Fileless malware.
10. Cryptojacking.
11. Wiper malware.
12. Adware.
14. Backdoor
15. P2P-Worm
16. Internet Worms
17. Net-worm
18. Clickjacking
19. Cryptominer
20. Fileless malware
You can easily configure the scan interval in the app’s settings. The real-time scan feature continuously monitors for threats in near real-time, as allowed by Splunk.
Information Use: Your email address is used to refine detection logic based on your feedback. Additionally, we may notify you about app upgrades, updates, or changes to features, user agreements, or the privacy policy.