mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
32 lines
1.3 KiB
YAML
32 lines
1.3 KiB
YAML
name: Monitor for Updates
|
|
id: 9ef8d677-7b52-4213-a038-99cfc7acc2d8
|
|
version: 1
|
|
date: '2017-09-15'
|
|
author: Rico Valdez, Splunk
|
|
description: Monitor your enterprise to ensure that your endpoints are being patched
|
|
and updated. Adversaries notoriously exploit known vulnerabilities that could be
|
|
mitigated by applying routine security patches.
|
|
narrative: 'It is a common best practice to ensure that endpoints are being patched
|
|
and updated in a timely manner, in order to reduce the risk of compromise via a
|
|
publicly disclosed vulnerability. Timely application of updates/patches is important
|
|
to eliminate known vulnerabilities that may be exploited by various threat actors.
|
|
|
|
Searches in this analytic story are designed to help analysts monitor endpoints
|
|
for system patches and/or updates. This helps analysts identify any systems that
|
|
are not successfully updated in a timely matter.
|
|
|
|
Microsoft releases updates for Windows systems on a monthly cadence. They should
|
|
be installed as soon as possible after following internal testing and validation
|
|
procedures. Patches and updates for other systems or applications are typically
|
|
released as needed.'
|
|
references:
|
|
- https://learn.cisecurity.org/20-controls-download
|
|
tags:
|
|
category:
|
|
- Best Practices
|
|
product:
|
|
- Splunk Enterprise
|
|
- Splunk Enterprise Security
|
|
- Splunk Cloud
|
|
usecase: Compliance
|