Investigating an APT with Splunk (Boss of the SOC)
文章介绍如何利用Splunk SIEM解决方案深入调查真实APT场景案例。APT是一种复杂且持续的网络攻击行为,旨在长期潜伏以窃取敏感信息或破坏运营。通过MITRE ATT&CK框架和Splunk查询文档支持案例分析。 2025-9-9 06:46:13 Author: infosecwriteups.com(查看原文) 阅读量:4 收藏

whoami

Hey cybersecurity evangelist, hope this walk through article finds you all in a good spirit. Let’s do a deeper investigation, leveraging Splunk SIEM solution to investigate a real-word APT scenario case which is provided by Splunk Boss of the SOC.

Investigating an APT with Splunk

Knowledge Sharing — Advanced Persistent Threat (APT) refers to a highly sophisticated and sustained cyberattack where a threat actor. The goal is not quick financial gain, but long-term infiltration in order to steal sensitive information, conduct cyber espionage, carry out data exfiltration, or even disrupt operations.

The more APT Groups info can be found through MITRE ATT&CK®

Splunk SPL Query Documents

Scenario —


文章来源: https://infosecwriteups.com/investigating-an-apt-with-splunk-boss-of-the-soc-bbf7f35645af?source=rss----7b722bfd1b8d---4
如有侵权请联系:admin#unsafe.sh