Files
splunk-security_content/stories/data_protection.json
T
2019-09-04 12:20:27 -04:00

52 lines
1.9 KiB
JSON

{
"category": [
"Abuse"
],
"channel": "ESCU",
"creation_date": "2017-06-01",
"description": "Fortify your data-protection arsenal--while continuing to ensure data confidentiality and integrity--with searches that monitor for and help you investigate possible signs of data exfiltration.",
"detections": [
{
"detection_id": "104658f4-afdc-499f-9719-17a43f9826f4",
"name": "Detection of DNS Tunnels",
"type": "splunk"
},
{
"detection_id": "104658f4-afdc-499f-9719-17a43f9826f5",
"name": "Detect USB device insertion",
"type": "splunk"
},
{
"detection_id": "c77162d3-f93c-45cc-80c8-22f6v5464g9f",
"name": "Detect hosts connecting to dynamic domain providers",
"type": "splunk"
}
],
"id": "91c676cf-0b23-438d-abee-f6335e1fce33",
"maintainers": [
{
"company": "Splunk",
"email": "bpatel@splunk.com",
"name": "Bhavin Patel"
}
],
"modification_date": "2017-09-14",
"name": "Data Protection",
"narrative": "Attackers can leverage a variety of resources to compromise or exfiltrate enterprise data. Common exfiltration techniques include remote-access channels via low-risk, high-payoff active-collections operations and close-access operations using insiders and removable media. While this Analytic Story is not a comprehensive listing of all the methods by which attackers can exfiltrate data, it provides a useful starting point.",
"original_authors": [
{
"company": "Splunk",
"email": "bpatel@splunk.com",
"name": "Bhavin Patel"
}
],
"references": [
"https://www.cisecurity.org/controls/data-protection/",
"https://www.sans.org/reading-room/whitepapers/dns/splunk-detect-dns-tunneling-37022",
"https://umbrella.cisco.com/blog/2013/04/15/on-the-trail-of-malicious-dynamic-dns-domains/"
],
"spec_version": 2,
"usecase": "Security Monitoring",
"version": "1.0"
}