mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
24 lines
1.1 KiB
YAML
24 lines
1.1 KiB
YAML
name: Asset Tracking
|
|
id: 91c676cf-0b23-438d-abee-f6335e1fce77
|
|
version: 1
|
|
date: '2017-09-13'
|
|
description: Keep a careful inventory of every asset on your network to make it easier
|
|
to detect rogue devices. Unauthorized/unmanaged devices could be an indication of
|
|
malicious behavior that should be investigated further.
|
|
narrative: This Analytic Story is designed to help you develop a better understanding
|
|
of what authorized and unauthorized devices are part of your enterprise. This story
|
|
can help you better categorize and classify assets, providing critical business
|
|
context and awareness of their assets during an incident. Information derived from
|
|
this Analytic Story can be used to better inform and support other analytic stories.
|
|
For successful detection, you will need to leverage the Assets and Identity Framework
|
|
from Enterprise Security to populate your known assets.
|
|
author: Bhavin Patel, Splunk
|
|
type: ESCU
|
|
references:
|
|
- https://www.cisecurity.org/controls/inventory-of-authorized-and-unauthorized-devices/
|
|
tags:
|
|
analytics_story: Asset Tracking
|
|
usecase: Security Monitoring
|
|
category:
|
|
- Best Practices
|