mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
24 lines
1.1 KiB
YAML
24 lines
1.1 KiB
YAML
name: Monitor Backup Solution
|
|
id: abe807c7-1eb6-4304-ac32-6e7aacdb891d
|
|
version: 1
|
|
date: '2017-09-12'
|
|
description: Address common concerns when monitoring your backup processes. These
|
|
searches can help you reduce risks from ransomware, device theft, or denial of physical
|
|
access to a host by backing up data on endpoints.
|
|
narrative: Having backups is a standard best practice that helps ensure continuity
|
|
of business operations. Having mature backup processes can also help you reduce
|
|
the risks of many security-related incidents and streamline your response processes.
|
|
The detection searches in this Analytic Story will help you identify systems that
|
|
have backup failures, as well as systems that have not been backed up for an extended
|
|
period of time. The story will also return the notable event history and all of
|
|
the backup logs for an endpoint.
|
|
author: David Dorsey, Splunk
|
|
type: ESCU
|
|
references:
|
|
- https://www.carbonblack.com/2016/03/04/tracking-locky-ransomware-using-carbon-black/
|
|
tags:
|
|
analytics_story: Monitor Backup Solution
|
|
usecase: Compliance
|
|
category:
|
|
- Best Practices
|