Skip to content
-
Security You Can Trust, Expertise You Can Rely On. TekGenX Consulting
NetwerkLABS

Powered By TEKGENX CONSULTING

  • ATTACK
    • PenTest
    • Web Pentest
    • C2 Frameworks
    • VulnLAB
  • DETECT
    • Detection Engineering
    • DFIR
    • EDR | SIEM | SOAR
    • Purple Teaming
    • MITRE ATT&CK
  • DEFEND
    • CTEM
    • Attack Surface Management (ASM)
    • Network Infrastructure
    • Vulnerability Management
    • WAF | Firewalls | IDS/IPS
  • LEARNING PATHS
    • Wazuh SIEM & XDR
    • Attack & Defend AD
    • Cheat Sheets
  • GRC
    • ISO/IEC 27001
    • NIS2 | CyFUN
    • NIST
    • CIS Controls
  • CTI
    • Threat Intel
    • CyBER-NEWS
Subscribe

Intrusion Detection and Response

  • Home
  • BLUE TEAM
  • Intrusion Detection and Response
Data Manipulation in Splunk: PART II
Posted inSplunk CyBER Tools

Data Manipulation in Splunk: PART II

Event Boundaries Event breaking in Splunk refers to breaking raw data into individual events based on specified boundaries. Splunk uses event-breaking rules to identify where one event ends, and the next begins. In the PART I of this series, we…
Read More
Posted by Avatar photo Bharath Narayanasamy Tags: splunk
Data Manipulation in Splunk: PART I
Posted inSplunk CyBER Tools

Data Manipulation in Splunk: PART I

Splunk Log Parsing and Transformation Configuration Splunk needs to be properly configured to parse and transform the logs appropriately. Some of the issues being highlighted are: Event Breaking: Ensure Splunk correctly breaks events for proper indexing…
Read More
Posted by Avatar photo Bharath Narayanasamy Tags: splunk
Regular Expressions
Posted inSplunk CyBER Tools

Regular Expressions

Regular Expressions: Charsets Searching for Specific Strings Use grep 'string' <file> to search for an exact match. To find patterns rather than exact strings, Regular Expressions (regex) are used. Charsets in Regex Definition: Enclosed in […
Read More
Posted by Avatar photo Bharath Narayanasamy Tags: splunk
Splunk SIEM: Search Processing Language (SPL) Basics
Posted inSplunk CyBER Tools

Splunk SIEM: Search Processing Language (SPL) Basics

Splunk Search Processing Language comprises of multiple functions, operators and commands that are used together to form a simple to complex search and get the desired results from the ingested logs. Main components of SPL Search…
Read More
Posted by Avatar photo Bharath Narayanasamy
 Ship OPNSense Firewall Logs To Splunk SIEM
Posted inSplunk CyBER Tools

 Ship OPNSense Firewall Logs To Splunk SIEM

Shipping OPNsense firewall logs to Splunk centralizes log management, allowing for seamless consolidation with other network and system logs. This integration enhances visibility into network traffic, enabling the identification of threats like port scans, malware communication,…
Read More
Posted by Avatar photo Bharath Narayanasamy Tags: splink, OPNSense
Splunk SIEM: Exploring SPL
Posted inCyBER Tools Splunk

Splunk SIEM: Exploring SPL

Splunk Search & Reporting App Overview The Search & Reporting App is the primary interface on Splunk's Home page used for searching and analyzing data. This app provides several essential functionalities to enhance the search experience…
Read More
Posted by Avatar photo Bharath Narayanasamy Tags: splunk, SIEM
DFIR: Linux File System Analysis
Posted inSOC Analyst Threat Detection and Incident Response Intrusion Detection and Response

DFIR: Linux File System Analysis

Read More
Posted by Avatar photo Bharath Narayanasamy Tags: linux, incident response, detection, dfir
Posted inSplunk

Splunk SPL 101

Read More
Posted by Avatar photo Bharath Narayanasamy Tags: splunk, SPL
Practical Threat Hunting using Elastic SIEM: Hunting for Stuxbot
Posted inThreat Hunting Threat Detection and Incident Response Elastic SIEM

Practical Threat Hunting using Elastic SIEM: Hunting for Stuxbot

Based on the INTRODUCTION TO THREAT HUNTING & HUNTING WITH ELASTIC module from HTB-Academy Hunting for Stuxbot The Stuxbot cybercrime group operates with a broad scope, seizing upon opportunities as they arise, without any specific targeting…
Read More
Posted by Avatar photo Bharath Narayanasamy Tags: Elastic, Threat_hunting
Posted inDETECT Elastic SIEM

Elastic SIEM: Developing Dashboards & Visualization

Use case 1: Failed Logon Attempts (Disabled Users) https://youtu.be/7Uyqek-FdwI Use case 2: Failed Logon Attempts (using Admin Accounts) https://youtu.be/UGRmsoqk0EM Use case 3: Successful RDP Logon Related To Service Accounts https://youtu.be/eRjA6TpEryk Use case 4: Users Added Or…
Read More
Posted by Avatar photo Bharath Narayanasamy Tags: Threat_hunting, SIEM, Elastic

Posts pagination

1 2 Next page

Recent Posts

  • Using MITRE ATT&CK Navigator to Strengthen Threat Modelling [PART: II]
  • 8 LOLBins Every Threat Hunter Should Know
  • Living Off the Land (LOTL) Resources
  • Volatility3: Memory Forensics Cheatsheet
  • Misbehaving binaries: Hunting LOLBins 

Categories

AD AD attacks Atomic RED brute-force c2 caldera CISO dfir Elastic hydra linux NIST red-team SIEM splunk Threat Intel threat_detection vulnhub wazuh wireshark

Copyright 2026 — NetwerkLABS. Powered by TekGenX Consulting. All rights reserved.
Scroll to Top

Powered by
Necessary cookies enable essential site features like secure log-ins and consent preference adjustments. They do not store personal data.
None
Functional cookies support features like content sharing on social media, collecting feedback, and enabling third-party tools.
None
Analytical cookies track visitor interactions, providing insights on metrics like visitor count, bounce rate, and traffic sources.
None
Advertisement cookies deliver personalized ads based on your previous visits and analyze the effectiveness of ad campaigns.
None
Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
None
Powered by