Files
splunk-security_content/docs/_stories/data_protection.md
T
2021-10-11 18:18:23 -04:00

2.1 KiB

title, last_modified_at, toc, toc_label, tags
title last_modified_at toc toc_label tags
Data Protection 2017-09-14 true
Splunk Enterprise
Splunk Enterprise Security
Splunk Cloud
Network_Resolution

Try in Splunk Security Cloud{: .btn .btn--success}

Description

Fortify your data-protection arsenal--while continuing to ensure data confidentiality and integrity--with searches that monitor for and help you investigate possible signs of data exfiltration.

  • Product: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud
  • Datamodel: Network_Resolution
  • Last Updated: 2017-09-14
  • Author: Bhavin Patel, Splunk
  • ID: 91c676cf-0b23-438d-abee-f6335e1fce33

Narrative

Attackers can leverage a variety of resources to compromise or exfiltrate enterprise data. Common exfiltration techniques include remote-access channels via low-risk, high-payoff active-collections operations and close-access operations using insiders and removable media. While this Analytic Story is not a comprehensive listing of all the methods by which attackers can exfiltrate data, it provides a useful starting point.

Detections

Name Technique Type
Detect hosts connecting to dynamic domain providers Drive-by Compromise TTP

Reference

source | version: 1