mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
23 lines
1.4 KiB
YAML
23 lines
1.4 KiB
YAML
name: Monitor for Updates
|
|
id: 9ef8d677-7b52-4213-a038-99cfc7acc2d8
|
|
version: 2
|
|
creation_date: '2019-10-16'
|
|
modification_date: '2026-05-13'
|
|
author: Rico Valdez, Splunk
|
|
status: production
|
|
description: Monitor your enterprise to ensure that your endpoints are being patched and updated. Adversaries notoriously exploit known vulnerabilities that could be mitigated by applying routine security patches.
|
|
narrative: 'It is a common best practice to ensure that endpoints are being patched and updated in a timely manner, in order to reduce the risk of compromise via a publicly disclosed vulnerability. Timely application of updates/patches is important to eliminate known vulnerabilities that may be exploited by various threat actors.
|
|
|
|
Searches in this analytic story are designed to help analysts monitor endpoints for system patches and/or updates. This helps analysts identify any systems that are not successfully updated in a timely matter.
|
|
|
|
Microsoft releases updates for Windows systems on a monthly cadence. They should be installed as soon as possible after following internal testing and validation procedures. Patches and updates for other systems or applications are typically released as needed.'
|
|
references:
|
|
- https://learn.cisecurity.org/20-controls-download
|
|
category:
|
|
- Best Practices
|
|
product:
|
|
- Splunk Enterprise
|
|
- Splunk Enterprise Security
|
|
- Splunk Cloud
|
|
usecase: Compliance
|