Files
splunk-security_content/stories/monitor_for_updates.yml
Patrick Bareiss 7cbc9a9ba6 WIP
2020-04-30 10:34:18 +02:00

30 lines
1.3 KiB
YAML

name: Monitor for Updates
id: 9ef8d677-7b52-4213-a038-99cfc7acc2d8
version: 1
date: '2017-09-15'
description: Monitor your enterprise to ensure that your endpoints are being patched
and updated. Adversaries notoriously exploit known vulnerabilities that could be
mitigated by applying routine security patches.
narrative: 'It is a common best practice to ensure that endpoints are being patched
and updated in a timely manner, in order to reduce the risk of compromise via a
publicly disclosed vulnerability. Timely application of updates/patches is important
to eliminate known vulnerabilities that may be exploited by various threat actors.\
Searches in this analytic story are designed to help analysts monitor endpoints
for system patches and/or updates. This helps analysts identify any systems that
are not successfully updated in a timely matter.\
Microsoft releases updates for Windows systems on a monthly cadence. They should
be installed as soon as possible after following internal testing and validation
procedures. Patches and updates for other systems or applications are typically
released as needed.'
author: Rico Valdez, Splunk
type: ESCU
references:
- https://learn.cisecurity.org/20-controls-download
tags:
analytics_story: Monitor for Updates
usecase: Compliance
category:
- Best Practices