Splunk> Knowledge Base
Open in Telegram
2 306
Subscribers
No data24 hours
+17 days
-330 days
Posts Archive
Repost from PCSG • Girls in Cybersecurity
درود🪷
در این مقاله سعی کردیم با استفاده از منابع معتبر، دو محصول معروف رو با هم مقایسه کنیم و جنبههای مختلف اونهارو بررسی کنیم، امید داریم زمانی که برای مطالعه این فایل میگذارید براتون مفید باشه.
مثل همیشه از همراهیتون ممنونیم.
⚠️ این سند هر چندماه بروزرسانی خواهد شد ⚠️
Hi 🪷
in this paper we analyse the diffrence between two famous product and talk about diffrent aspects of them, we hope u read and grow.
thanks for your suppurts as always.
-------------------------
📌 Splunk vs. ELK (Version 1.9.2)
✨ Marjan Kamran
🔖 #Paper / #English
🌍 Website • Links • Boost
📑 #PCSGCommunity #SIEM #ELK #Splunk #Elasticsearch #ElasticStack #Hadoop
Repost from Hypersec
🚨 Alert - A critical vulnerability in PuTTY versions 0.68 to 0.80 could lead to private key compromises.
هشدار - یک آسیب پذیری حیاتی در PuTTY نسخه های 0.68 تا 0.80 می تواند منجر به به خطر افتادن کلید خصوصی شود.
➡️ https://thehackernews.com/2024/04/widely-used-putty-ssh-client-found.html
➡️https://www.chiark.greenend.org.uk/~sgtatham/putty/wishlist/vuln-p521-bias.html
Don't let hackers take control—update immediately.
#CVE
تیم سورین
🟡How to Map Splunk to CIS 20 Security Controls?
🟢Mapping Splunk Software to the CIS 20 CSC Version 6.0
Repost from Hypersec
💻💻معرفی دوره جامع اسپلانک (Analyst , Adminitration , ES )💬🛡 :
✅امروزه، استفاده از نرمافزار اسپلانک در SOCها به طور فزایندهای رواج یافته است. کارشناسان مانیتورینگ از این ابزار قدرتمند برای تحلیل حملات سایبری و ارتقای امنیت شبکه سازمان خود بهره میبرند.
✈️این دوره آموزشی با تمرکز بر سه بخش اصلی طراحی شده است:
1️⃣ کار با اسپلانک:
- آشنایی با محیط کاربری اسپلانک
- جستجو و تحلیل دادهها با زبان اختصاصی اسپلانک (SPL)
- ساخت ريپورت ها، داشبوردها و الرت ها
2️⃣ مديريت اسپلانک:
- شناخت كامپوننت هاي اسپلانك
- پيكربندي كامپوننت هاي كلاستر شده
- مديريت ساختار كلاسترينگ اسپلانك
3️⃣ کار با Splunk Enterprise Security :
- نصب و پیکربندی ES
- مدیریت و بهینهسازی ES
- استفاده از ES در تحلیل و شناسایی حملات سایبری
این دوره با ارائه مثالهای عملی و تمرینهای متعدد، به دانشپذیران در یادگیری و تسلط بر مفاهیم تئوری کمک میکند و شامل محتوای زیر میباشد :
🟩Intro To Splunk
🟩 Using Splunk
🟩Using Search
🟩Exploring Events
🟩Search Processing Language
🟩What are Commands
*️⃣Understand the anatomy of Splunk’s Search language:
1️⃣ Search term
2️⃣ Commands
3️⃣ Functions
4️⃣ Arguments
5️⃣ Cluses
🟩What are knowledge Objects
➕Identify the five categories of knowledge object:
1️⃣Data Interpretation
2️⃣Data Classification
3️⃣Data Enrichment
4️⃣Data Normalization
5️⃣Data Models
🟩 Creating Reports and Dashboards
🟩Deploying Splunk
🟩Monitoring Splunk
🟩Licensing Splunk
🟩Using Configuration Files
🟩Creating Indexes
🟩Managing Index
🟩Managing Users
🟩Configuring Basic Forwarding
🟩Configuring Distributed Search
🟩Getting Started with ES
🟩Security Monitoring and Incident Investigation
🟩Risk-Based Alerting
🟩Incident Investigation
🟩Installation
🟩Security Domain Dashboards
🟩security threats
🟩User Intelligence
🟩Web Intelligence
🟩Threat Intelligence
🟩 threat intel is configured in ES
🟩 interacting with your environment
🟩Protocol Intelligence
🟩Creating Correlation Searches
🟩Asset & Identity Management
🧠 مدرس : مهندس احمدرضا نوروزی
🌟برگزار کننده : سورین
⏳مدت دوره : 70 ساعت
🎓 نوع برگزاری: حضوری / آنلاین
🏪ساعات برگزاری: شنبه و چهارشنبه – ساعت17:30 الی 20:30
⏲زمان شروع : 29 اردیبهشت
💰شهریه : شش میلیون تومان
👩💻 پیش نیازها
• آشنایی با شبکه و سیستم عامل لینوکس
• آشنایی اولیه با حملات شبکه و میزبان
• آشنایی نسبی با لاگ و سنسورهای امنیتی
🔗 نحوه ثبت نام:
📬 برقراری ارتباط با ادمین در صفحات اجتماعی ( تلگرام ، اینستاگرام ، لینکدین)
☎️ شماره تماس : 09102144597
#اسپلانک #دوره_اسپلانک #Splunk #امنیت_سایبری
تیم سورین
Repost from Hypersec
💻💻معرفی دوره جامع اسپلانک (Analyst , Adminitration , ES )💬🛡 :
✅امروزه، استفاده از نرمافزار اسپلانک در SOCها به طور فزایندهای رواج یافته است. کارشناسان مانیتورینگ از این ابزار قدرتمند برای تحلیل حملات سایبری و ارتقای امنیت شبکه سازمان خود بهره میبرند.
✈️این دوره آموزشی با تمرکز بر سه بخش اصلی طراحی شده است:
1️⃣ کار با اسپلانک:
- آشنایی با محیط کاربری اسپلانک
- جستجو و تحلیل دادهها با زبان اختصاصی اسپلانک (SPL)
- ساخت ريپورت ها، داشبوردها و الرت ها
2️⃣ مديريت اسپلانک:
- شناخت كامپوننت هاي اسپلانك
- پيكربندي كامپوننت هاي كلاستر شده
- مديريت ساختار كلاسترينگ اسپلانك
3️⃣ کار با Splunk Enterprise Security :
- نصب و پیکربندی ES
- مدیریت و بهینهسازی ES
- استفاده از ES در تحلیل و شناسایی حملات سایبری
این دوره با ارائه مثالهای عملی و تمرینهای متعدد، به دانشپذیران در یادگیری و تسلط بر مفاهیم تئوری کمک میکند و شامل محتوای زیر میباشد :
🟩Intro To Splunk
🟩 Using Splunk
🟩Using Search
🟩Exploring Events
🟩Search Processing Language
🟩What are Commands
*️⃣Understand the anatomy of Splunk’s Search language:
1️⃣ Search term
2️⃣ Commands
3️⃣ Functions
4️⃣ Arguments
5️⃣ Cluses
🟩What are knowledge Objects
➕Identify the five categories of knowledge object:
1️⃣Data Interpretation
2️⃣Data Classification
3️⃣Data Enrichment
4️⃣Data Normalization
5️⃣Data Models
🟩 Creating Reports and Dashboards
🟩Deploying Splunk
🟩Monitoring Splunk
🟩Licensing Splunk
🟩Using Configuration Files
🟩Creating Indexes
🟩Managing Index
🟩Managing Users
🟩Configuring Basic Forwarding
🟩Configuring Distributed Search
🟩Getting Started with ES
🟩Security Monitoring and Incident Investigation
🟩Risk-Based Alerting
🟩Incident Investigation
🟩Installation
🟩Security Domain Dashboards
🟩security threats
🟩User Intelligence
🟩Web Intelligence
🟩Threat Intelligence
🟩 threat intel is configured in ES
🟩 interacting with your environment
🟩Protocol Intelligence
🟩Creating Correlation Searches
🟩Asset & Identity Management
🧠 مدرس : مهندس احمدرضا نوروزی
🌟برگزار کننده : سورین
⏳مدت دوره : 70 ساعت
🎓 نوع برگزاری: حضوری / آنلاین
🏪ساعات برگزاری: شنبه و چهارشنبه – ساعت17:30 الی 20:30
⏲زمان شروع : 29 اردیبهشت
💰شهریه : شش میلیون تومان
👩💻 پیش نیازها
• آشنایی با شبکه و سیستم عامل لینوکس
• آشنایی اولیه با حملات شبکه و میزبان
• آشنایی نسبی با لاگ و سنسورهای امنیتی
🔗 نحوه ثبت نام:
📬 برقراری ارتباط با ادمین در صفحات اجتماعی ( تلگرام ، اینستاگرام ، لینکدین)
☎️ شماره تماس : 09102144597
#اسپلانک #دوره_اسپلانک #Splunk #امنیت_سایبری
تیم سورین
Repost from Hypersec
🔓فورتی نت چندین آسیبپذیری حیاتی را که بر FortiClient، FortiSandbox، FortiOS و FortiProxy تأثیر میگذارند وصله میکند.
🛡https://securityonline.info/fortinet-patches-multiple-critical-vulnerabilities-affecting-forticlient-fortisandbox-fortios-and-fortiproxy/
#fortinet
تیم سورین
👩💻CVE-2024-3094 checker
xz Utils versions 5.6.0 and 5.6.1 appear to be compromised.
XZ Utils is data compression software and may be present in Linux distributions. The malicious code may allow unauthorized access to affected systems.
✅اگه Deployment Server دارین میتونین این اسکریپت رو به همه لینوکس ها ارسال کنین و لاگش رو بگیرین تا متوجه بشین که سرور آسیب پذیر دارین یا نه!
🌐https://github.com/FabioBaroni/CVE-2024-3094-checker
🟢Credits : Mohammad Mirasadollahi🟢
#CVE #XZ #linux
@splunk_kb
⚠️ Multiple Splunk Vulnerabilities Attackers Bypass SPL Safeguards : Patch Now‼️
CVE-2024-29945 (CVSS score: 7.2): This vulnerability could allow attackers to expose authentication tokens if Splunk Enterprise is running in debug mode or has specific logging configurations.
CVE-2024-29946 (CVSS score: 8.1): This vulnerability is more severe because it allows attackers to bypass safeguards for risky commands within the Dashboard Examples Hub of Splunk Enterprise. An attacker could potentially trick a user into initiating a malicious request.
🌐https://cybersecuritynews.com/splunk-vulnerabilities-spl-safeguards/
#CVE #splunk
@splunk_kb
💎Splunk advanced input configuration for Windows based on MITRE ATT&CK framework.
یکی از بهترین کانفیگهای فایل input.conf برای Universal Forwarder که بر روی فریمورک Mitre هم مپ شده 👌
💥https://github.com/mdecrevoisier/Splunk-input-windows-baseline
تیم سورین
✉️@splunk_kb
Repost from Hypersec
آسیب پذیری CVE-2024-26198 به آسیبپذیری Remote Code Execution در Microsoft Exchange Server اشاره دارد.
که در 12 مارس 2024 منتشر شد و دارای درجه شدت 8.8 (HIGH) است. این آسیبپذیری به مهاجم اجازه میدهد تا با ارسال یک درخواست طراحیشده خاص، کد دلخواه را روی یک سیستم آسیبدیده اجرا کند. حمله به تعامل کاربر نیاز دارد زیرا مهاجم باید کاربر را متقاعد کند که یک فایل مخرب را باز کند.
نسخه های آسیب دیده عبارتند از:
- Exchange Server 2019 CU13 و CU14
- Exchange Server 2016 CU23
مایکروسافت توصیه میکند فوراً بهروزرسانیهای امنیتی مارس 2024 را برای محافظت در برابر این آسیبپذیری نصب کنید.
اطلاعات تکمیلی در مورد این آسیب پذیری :
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-26198
دریافت بروزرسانی ها از طریق سایت رسمی مایکروسافت :
https://learn.microsoft.com/en-us/exchange/new-features/build-numbers-and-release-dates
تیم سورین
🔻Explore the World of Cybersecurity on @Hide_Club Telegram Channel:
🐞 Bug Bounty Tools & Techniques
💉 Exploit Vulnerabilities
💻 Web Application Security
🔐 Pentesting Insights
📚 Exclusive Bug Bounty Courses
Join for Cutting-Edge Cybersecurity Content👇🏻
https://t.me/+RgbzBK2_-Mo5MTE8
https://t.me/+RgbzBK2_-Mo5MTE8
https://t.me/+RgbzBK2_-Mo5MTE8
Repost from Bug Bounty Tools & Writeups | Hide Club
🔖Cloud Recon
This script is used to search for cloud certificate entities such as Amazon, Azure, and others that have been extracted by the kaeferjaeger[.]gay provider. It is useful for subdomain enumeration and finding additional apex domains during your reconnaissance processes.You can find it on my GitHub : https://github.com/0xSpidey/cloudrecon.git Please follow me on GitHub and don't forget to give a star to this repo. Thank you all!❤️ #BugBounty #bugbountyTools — Share & Support Us — ➯ Channel : @Hide_Club 🔒
