DiscoverSplunk [Phantom] 2019 .conf Videos w/ SlidesUse Splunk SIEMulator to Generate Data for Automated Detection, Investigation, and Response [Splunk Enterprise Security, Splunk User Behavior Analytics, Phantom]
Use Splunk SIEMulator to Generate Data for Automated Detection, Investigation, and Response  [Splunk Enterprise Security, Splunk User Behavior Analytics, Phantom]

Use Splunk SIEMulator to Generate Data for Automated Detection, Investigation, and Response [Splunk Enterprise Security, Splunk User Behavior Analytics, Phantom]

Update: 2019-12-24
Share

Description

Obtaining data to develop defenses against threats is a constant challenge for security analysts. To that end, Splunk's Security Research team developed the Splunk SIEMulator, a framework modeled after Chris Long's DetectionLab that allows a defender to replay attack scenarios using AttackIQ in a simulated environment. SIEMulator’s Attack Range environments are all configured with Splunk forwarders and the apps necessary to create and store data in CIM data models. We'll show you how to use the SIEMulator to produce shareable data that can help security analysts replicate scenarios and effectively detect, investigate, and respond to threats.


Speaker(s)
Phil Royer, Research Engineer, Splunk
Rod Soto, Principal Security Research Engineer, Splunk



Slides PDF link - https://conf.splunk.com/files/2019/slides/SEC1671.pdf?podcast=1577146239


Product: Splunk Enterprise Security, Splunk User Behavior Analytics, Phantom


Track: Security, Compliance and Fraud


Level: Advanced

Comments 
In Channel
loading
00:00
00:00
x

0.5x

0.8x

1.0x

1.25x

1.5x

2.0x

3.0x

Sleep Timer

Off

End of Episode

5 Minutes

10 Minutes

15 Minutes

30 Minutes

45 Minutes

60 Minutes

120 Minutes

Use Splunk SIEMulator to Generate Data for Automated Detection, Investigation, and Response  [Splunk Enterprise Security, Splunk User Behavior Analytics, Phantom]

Use Splunk SIEMulator to Generate Data for Automated Detection, Investigation, and Response [Splunk Enterprise Security, Splunk User Behavior Analytics, Phantom]

Splunk