2026-04-13 09-26-14
Qof-dheer
Qodobbada
-
0:11
In this video, we're going to take a look at some of the more common types of queries that you may use in Splunk when performing threat hunting activities. So, first of all, let's remember what's important about threat hunting and the hypot…
-
5:11
We see the account was created by the sysadmin user and the account that was created is the shadow user right there so we can see we do have results from this query. So again a very useful query to run if we are looking for new user creatio…
-
10:13Qodobka 3: and more than one success. 300s · Speaker 2
and more than one success. Excuse me, more than zero successes, at least one success. However, I also need to spell success properly. So we want more than five failed logins and at least one successful login for these accounts. Now we could…
-
15:13Qodobka 4: And we're going to look at the destination host name as well, just if there is any. 202s · Speaker 2
And we're going to look at the destination host name as well, just if there is any. There may not be a destination host name if the network connection wasn't initiated using a domain name. And then we're going to look at the destination por…
-
18:36Qodobka 5: here. Yeah, so we can see some information here. 302s · Speaker 3
here. Yeah, so we can see some information here. We see a PowerShell script being executed. We see what looks like potentially malicious activity. This, I can tell you right here, looks to be evidence of Mimi Cats running. So you can see th…
-
23:38Qodobka 6: one. We're going to look for evidence of malicious services being created. 300s · Speaker 1
one. We're going to look for evidence of malicious services being created. Now, there's a few different ways you can do this. There's event IDs you can use, and there are also registry keys that can be created. We're going to use the regist…
-
28:39
more information, usually into some sort of a command. For example, the WHERE command. We saw that one being used when we were looking for brute force attacks. This will filter the information, filter the results based on whatever criteria …