Files
splunk-security_content/docs/_stories/network_discovery.md
T
2022-03-10 10:27:29 +01:00

2.0 KiB

title, last_modified_at, toc, toc_label, tags
title last_modified_at toc toc_label tags
Network Discovery 2022-02-14 true
Splunk Enterprise
Splunk Enterprise Security
Splunk Cloud
Endpoint
Reconnaissance

Try in Splunk Security Cloud{: .btn .btn--success}

Description

Leverage searches that allow you to detect and investigate unusual activities that might relate to the network discovery, including looking for network configuration, settings such as IP, MAC address, firewall settings and many more.

  • Product: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud
  • Datamodel: Endpoint
  • Last Updated: 2022-02-14
  • Author: Teoderick Contreras, Splunk
  • ID: af228995-f182-49d7-90b3-2a732944f00f

Narrative

Adversaries may use the information from System Network Configuration Discovery during automated discovery to shape follow-on behaviors, including determining certain access within the target network and what actions to do next.

Detections

Name Technique Type
Linux System Network Discovery System Network Configuration Discovery Anomaly

Reference

source | version: 1