Splunking with Sysmon Part 3: Detecting PsExec in your Environment

PsExec is another powerful tool created by Windows Sysinternal. It was created to allow Administrators to remotely connect to and manage Windows systems. Because of the power of PsExec, many different malware actors have used it in various forms of mal… Continue reading Splunking with Sysmon Part 3: Detecting PsExec in your Environment

Using Splunk Enterprise Security to Look for Zerologon Exploit Attempts

A while back, Zerologon came along and helped everyone look really hard at the effectiveness of their operating system (OS) patching strategy.  If you’re looking for more information on the exploit, there’s an excellent write-up by Lares Labs on the na… Continue reading Using Splunk Enterprise Security to Look for Zerologon Exploit Attempts

Your In-Depth Guide to Collecting Google Drive Activity Logs in Splunk

One of great things about Splunk is that if there’s a data source you want to capture, there’s probably a way to do it. I recently needed to configure Google Drive audit logging to track student activity in an international security competition. For ma… Continue reading Your In-Depth Guide to Collecting Google Drive Activity Logs in Splunk