mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
21 lines
1.2 KiB
YAML
21 lines
1.2 KiB
YAML
name: Data Protection
|
|
id: 91c676cf-0b23-438d-abee-f6335e1fce33
|
|
version: 2
|
|
creation_date: '2019-10-16'
|
|
modification_date: '2026-05-13'
|
|
author: Bhavin Patel, Splunk
|
|
status: production
|
|
description: Fortify your data-protection arsenal--while continuing to ensure data confidentiality and integrity--with searches that monitor for and help you investigate possible signs of data exfiltration.
|
|
narrative: Attackers can leverage a variety of resources to compromise or exfiltrate enterprise data. Common exfiltration techniques include remote-access channels via low-risk, high-payoff active-collections operations and close-access operations using insiders and removable media. While this Analytic Story is not a comprehensive listing of all the methods by which attackers can exfiltrate data, it provides a useful starting point.
|
|
references:
|
|
- https://www.cisecurity.org/controls/data-protection/
|
|
- https://www.sans.org/reading-room/whitepapers/dns/splunk-detect-dns-tunneling-37022
|
|
- https://umbrella.cisco.com/blog/2013/04/15/on-the-trail-of-malicious-dynamic-dns-domains/
|
|
category:
|
|
- Abuse
|
|
product:
|
|
- Splunk Enterprise
|
|
- Splunk Enterprise Security
|
|
- Splunk Cloud
|
|
usecase: Security Monitoring
|