Skip to content

Splunk security addon for lateral movement detection

License

Notifications You must be signed in to change notification settings

agiallombardo/TA-latmov

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

10 Commits
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

What

The technology addon "TA-latmov" was designed based off SANS' 2018 Hunt Evil Poster.

This poster focuses on lateral movement from forensic evidence found on the source/destination endpoint after the action has occurred. Based on this, I created a series of Windows-based inputs to capture the state for threat hunting and preservation.

How

Deploy the entire TA to the Windows universal forwarder, which already has the Splunk_TA_Windows on the local instance.

Enable the inputs and configure the intervals based on what makes sense for your environment. If not tuned correctly, there will be a ton of noise.

Deploy the entire TA to the searchheads and indexer tier (heavy forwarder, indexers) for index-time / search time operations.

Who

All credit of compiling the list of indicators goes to SANS: Rob Lee, and Mike Pilkington. I just splunkified it.

I am looking for additional volunteers to take this to the next level.

Disclaimer

Use this at your own risk, it's a proof-of-concept.

Lastly, this was created on my own and is not supported or endorsed by my employer.

About

Splunk security addon for lateral movement detection

Resources

License

Stars

Watchers

Forks

Releases

No releases published

Packages