Skip to content
-
Security You Can Trust, Expertise You Can Rely On. TekGenX Consulting
NetwerkLABS

Powered By TEKGENX CONSULTING

  • ATTACK
    • PenTest
    • Web Pentest
    • C2 Frameworks
    • VulnLAB
  • DETECT
    • Detection Engineering
    • DFIR
    • EDR | SIEM | SOAR
    • Purple Teaming
    • MITRE ATT&CK
  • DEFEND
    • CTEM
    • Attack Surface Management (ASM)
    • Network Infrastructure
    • Vulnerability Management
    • WAF | Firewalls | IDS/IPS
  • LEARNING PATHS
    • Wazuh SIEM & XDR
    • Attack & Defend AD
    • Cheat Sheets
  • GRC
    • ISO/IEC 27001
    • NIS2 | CyFUN
    • NIST
    • CIS Controls
  • CTI
    • Threat Intel
    • CyBER-NEWS
Subscribe

splunk

  • Home
  • splunk
Atomic Red Team — Adversary Simulation and Detection
Posted inCyBER Tools Purple Teaming

Atomic Red Team — Adversary Simulation and Detection

Full Kill Chain Simulation + Splunk Detection Dashboard Operation Silent Ledger | Northbridge Financial APT SimulationPurple Team Playbook: ART Execution → Splunk Detection → Custom Dashboard 🗺️ Kill Chain Map — Techniques We'll Simulate Kill Chain…
Read More
Posted by Avatar photo Bharath Narayanasamy Tags: detection_engineering, Atomic RED, splunk
Data Manipulation in Splunk: PART II
Posted inSplunk CyBER Tools

Data Manipulation in Splunk: PART II

Event Boundaries Event breaking in Splunk refers to breaking raw data into individual events based on specified boundaries. Splunk uses event-breaking rules to identify where one event ends, and the next begins. In the PART I of this series, we…
Read More
Posted by Avatar photo Bharath Narayanasamy Tags: splunk
Data Manipulation in Splunk: PART I
Posted inSplunk CyBER Tools

Data Manipulation in Splunk: PART I

Splunk Log Parsing and Transformation Configuration Splunk needs to be properly configured to parse and transform the logs appropriately. Some of the issues being highlighted are: Event Breaking: Ensure Splunk correctly breaks events for proper indexing…
Read More
Posted by Avatar photo Bharath Narayanasamy Tags: splunk
Regular Expressions
Posted inCyBER Tools Splunk

Regular Expressions

Regular Expressions: Charsets Searching for Specific Strings Use grep 'string' <file> to search for an exact match. To find patterns rather than exact strings, Regular Expressions (regex) are used. Charsets in Regex Definition: Enclosed in […
Read More
Posted by Avatar photo Bharath Narayanasamy Tags: splunk
Splunk SIEM: Exploring SPL
Posted inSplunk CyBER Tools

Splunk SIEM: Exploring SPL

Splunk Search & Reporting App Overview The Search & Reporting App is the primary interface on Splunk's Home page used for searching and analyzing data. This app provides several essential functionalities to enhance the search experience…
Read More
Posted by Avatar photo Bharath Narayanasamy Tags: splunk, SIEM
Posted inSplunk

Splunk SPL 101

Read More
Posted by Avatar photo Bharath Narayanasamy Tags: SPL, splunk
Splunk: SPL Cheat Sheet for SOC Analysts
Posted inSplunk Splunk Basics Investigating with Splunk

Splunk: SPL Cheat Sheet for SOC Analysts

Splunk Cheat Sheet Query to identify failed login attempts: #Query to identify failed login attempts: sourcetype=auth* "authentication failure" | stats count by user | sort -count Query to identify privilege escalation attempts: #Query to identify privilege…
Read More
Posted by Avatar photo Bharath Narayanasamy Tags: splunk, SPL
Posted inThreat Intelligence

Investigate SQLi attacks using Splunk

Sure! Here are a few Splunk queries that can help detect web application attacks: Detecting SQL Injection Attacks: index=<your_index> sourcetype=<your_sourcetype> | search (request_uri=*' OR referer=*) AND (|inputlookup sql_injection_keywords.csv) Detecting Cross-Site Scripting (XSS) Attacks: index=<your_index> sourcetype=<your_sourcetype> |…
Read More
Posted by Avatar photo Bharath Narayanasamy Tags: splunk, SQLi
Posted inThreat Hunting Threat Detection and Incident Response

Splunk Threat Hunting – Windows Events

When performing threat hunting using Splunk on Windows systems, there are several important queries you can use to identify potential threats and security incidents. Here are some examples: Detecting Suspicious Processes: index=windows sourcetype="wineventlog:security" EventCode=4688 | where…
Read More
Posted by Avatar photo Bharath Narayanasamy Tags: splunk

Recent Posts

  • Testing Your Defences: Safe Technique Simulation with Atomic Red Team
  • Stakeholder-Specific Vulnerability Categorization
  • NIS2 to ISO 27001:2022 Mapping Table
  • NetBox Labs: Bringing Clarity and Control to Modern Network Infrastructure
  • CyFUN Implementation: A Practical Roadmap

Categories

AD AD attacks brute-force caldera CISO dfir Elastic hydra linux NIST red-team SIEM snort splunk Threat Intel threat_detection Threat_hunting vulnhub wazuh wireshark

Copyright 2026 — NetwerkLABS. Powered by TekGenX Consulting. All rights reserved.
Scroll to Top

Powered by
Necessary cookies enable essential site features like secure log-ins and consent preference adjustments. They do not store personal data.
None
Functional cookies support features like content sharing on social media, collecting feedback, and enabling third-party tools.
None
Analytical cookies track visitor interactions, providing insights on metrics like visitor count, bounce rate, and traffic sources.
None
Advertisement cookies deliver personalized ads based on your previous visits and analyze the effectiveness of ad campaigns.
None
Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
None
Powered by