MSSP Elastic Security Query

MSSP Elastic Security Query

MSSP Elastic Security Query – it can be used to detect for known exploitable vulnerabilities and or malicious behavior. Check out the two examples below. MSSP Elastic Security Query to Detect Log4j Assuming that the network logs are being stored in an...
MSSP Elastic Security Query

MSSP Elastic Security Detections

MSSP Elastic Security Detections   Introduction Elastic Cloud is a cloud-based managed service that provides a scalable and secure way to deploy Elasticsearch, Kibana, and related technologies. One of Elastic Cloud’s key features is its built-in Elastic...
Managed Detection and Response Services – Do SMBs need it?

LockBit Ransomware

LockBit Ransomware A specific kind of ransomware called LockBit is made to encrypt the victim’s files and demand money in return for the decryption key. LockBit’s initial version was found in September 2019, and since then, it has developed into...
Installing Splunk on Standalone server

Installing Splunk on Standalone server

    Installing Splunk Enterprise : Standalone Linux Server Prerequisites: A Linux server with root access. A Splunk Enterprise installation package. Step 1: Install the Required LibrariesIn order to install Splunk Enterprise, we need to install the necessary...