en
Feedback
Splunk> Knowledge Base

Splunk> Knowledge Base

Open in Telegram

تیم اسپلانک سورین 22021734

Show more
2 306
Subscribers
No data24 hours
+17 days
-330 days
Posts Archive
درود🪷 در این مقاله سعی کردیم با استفاده از منابع معتبر، دو محصول معروف رو با هم مقایسه کنیم و جنبه‌های مختلف اون‌هارو بررسی کنیم،‌ امید داریم زمانی که برای مطالعه این فایل می‌گذارید براتون مفید باشه. مثل همیشه از همراهیتون ممنونیم. ⚠️ این سند هر چندماه بروزرسانی خواهد شد ⚠️ Hi 🪷 in this paper we analyse the diffrence between two famous product and talk about diffrent aspects of them, we hope u read and grow. thanks for your suppurts as always. ------------------------- 📌 Splunk vs. ELK (Version 1.9.2) ✨ Marjan Kamran 🔖 #Paper / #English 🌍 WebsiteLinksBoost 📑 #PCSGCommunity #SIEM #ELK #Splunk #Elasticsearch #ElasticStack #Hadoop

Repost from Hypersec
🚨 Alert - A critical vulnerability in PuTTY versions 0.68 to 0.80 could lead to private key compromises. هشدار - یک آسیب پذیری حیاتی در PuTTY نسخه های 0.68 تا 0.80 می تواند منجر به به خطر افتادن کلید خصوصی شود. ➡️ https://thehackernews.com/2024/04/widely-used-putty-ssh-client-found.html ➡️https://www.chiark.greenend.org.uk/~sgtatham/putty/wishlist/vuln-p521-bias.html Don't let hackers take control—update immediately. #CVE تیم سورین

▶️How to Install and Configure Zeek to Ship Logs to Splunk💬

🟡How to Map Splunk to CIS 20 Security Controls? 🟢Mapping Splunk Software to the CIS 20 CSC Version 6.0

Repost from Hypersec
💻💻معرفی دوره جامع اسپلانک (Analyst , Adminitration , ES )💬🛡 : ✅امروزه، استفاده از نرم‌افزار اسپلانک در SOCها به طور فزاینده‌ای رواج یافته است. کارشناسان مانیتورینگ از این ابزار قدرتمند برای تحلیل حملات سایبری و ارتقای امنیت شبکه سازمان خود بهره می‌برند. ✈️این دوره آموزشی با تمرکز بر سه بخش اصلی طراحی شده است: 1️⃣ کار با اسپلانک: - آشنایی با محیط کاربری اسپلانک - جستجو و تحلیل داده‌ها با زبان اختصاصی اسپلانک (SPL) - ساخت ريپورت ها، داشبوردها و الرت ها 2️⃣ مديريت اسپلانک: - شناخت كامپوننت هاي اسپلانك - پيكربندي كامپوننت هاي كلاستر شده - مديريت ساختار كلاسترينگ اسپلانك 3️⃣ کار با Splunk Enterprise Security : - نصب و پیکربندی ES - مدیریت و بهینه‌سازی ES - استفاده از ES در تحلیل و شناسایی حملات سایبری این دوره با ارائه مثال‌های عملی و تمرین‌های متعدد، به دانش‌پذیران در یادگیری و تسلط بر مفاهیم تئوری کمک می‌کند و شامل محتوای زیر میباشد : 🟩Intro To Splunk 🟩 Using Splunk 🟩Using Search 🟩Exploring Events 🟩Search Processing Language 🟩What are Commands *️⃣Understand the anatomy of Splunk’s Search language: 1️⃣ Search term 2️⃣ Commands 3️⃣ Functions 4️⃣ Arguments 5️⃣ Cluses 🟩What are knowledge Objects ➕Identify the five categories of knowledge object: 1️⃣Data Interpretation 2️⃣Data Classification 3️⃣Data Enrichment 4️⃣Data Normalization 5️⃣Data Models 🟩 Creating Reports and Dashboards 🟩Deploying Splunk 🟩Monitoring Splunk 🟩Licensing Splunk 🟩Using Configuration Files 🟩Creating Indexes 🟩Managing Index 🟩Managing Users 🟩Configuring Basic Forwarding 🟩Configuring Distributed Search 🟩Getting Started with ES 🟩Security Monitoring and Incident Investigation 🟩Risk-Based Alerting 🟩Incident Investigation 🟩Installation 🟩Security Domain Dashboards 🟩security threats 🟩User Intelligence 🟩Web Intelligence 🟩Threat Intelligence 🟩 threat intel is configured in ES 🟩 interacting with your environment 🟩Protocol Intelligence 🟩Creating Correlation Searches 🟩Asset & Identity Management 🧠 مدرس : مهندس احمدرضا نوروزی 🌟برگزار کننده : سورین ⏳مدت دوره : 70 ساعت 🎓 نوع برگزاری:‌ حضوری / آنلاین 🏪ساعات برگزاری: شنبه و چهارشنبه – ساعت17:30 الی 20:30 ⏲زمان شروع : 29 اردیبهشت 💰شهریه : شش میلیون تومان 👩‍💻 پیش نیازها • آشنایی با شبکه و سیستم عامل لینوکس • آشنایی اولیه با حملات شبکه و میزبان • آشنایی نسبی با لاگ و سنسورهای امنیتی 🔗 نحوه ثبت نام: 📬 برقراری ارتباط با ادمین در صفحات اجتماعی ( تلگرام ، اینستاگرام ، لینکدین) ☎️ شماره تماس : 09102144597 #اسپلانک #دوره_اسپلانک #Splunk #امنیت_سایبری تیم سورین

Repost from Hypersec
💻💻معرفی دوره جامع اسپلانک (Analyst , Adminitration , ES )💬🛡 : ✅امروزه، استفاده از نرم‌افزار اسپلانک در SOCها به طور فزاینده‌ای رواج یافته است. کارشناسان مانیتورینگ از این ابزار قدرتمند برای تحلیل حملات سایبری و ارتقای امنیت شبکه سازمان خود بهره می‌برند. ✈️این دوره آموزشی با تمرکز بر سه بخش اصلی طراحی شده است: 1️⃣ کار با اسپلانک: - آشنایی با محیط کاربری اسپلانک - جستجو و تحلیل داده‌ها با زبان اختصاصی اسپلانک (SPL) - ساخت ريپورت ها، داشبوردها و الرت ها 2️⃣ مديريت اسپلانک: - شناخت كامپوننت هاي اسپلانك - پيكربندي كامپوننت هاي كلاستر شده - مديريت ساختار كلاسترينگ اسپلانك 3️⃣ کار با Splunk Enterprise Security : - نصب و پیکربندی ES - مدیریت و بهینه‌سازی ES - استفاده از ES در تحلیل و شناسایی حملات سایبری این دوره با ارائه مثال‌های عملی و تمرین‌های متعدد، به دانش‌پذیران در یادگیری و تسلط بر مفاهیم تئوری کمک می‌کند و شامل محتوای زیر میباشد : 🟩Intro To Splunk 🟩 Using Splunk 🟩Using Search 🟩Exploring Events 🟩Search Processing Language 🟩What are Commands *️⃣Understand the anatomy of Splunk’s Search language: 1️⃣ Search term 2️⃣ Commands 3️⃣ Functions 4️⃣ Arguments 5️⃣ Cluses 🟩What are knowledge Objects ➕Identify the five categories of knowledge object: 1️⃣Data Interpretation 2️⃣Data Classification 3️⃣Data Enrichment 4️⃣Data Normalization 5️⃣Data Models 🟩 Creating Reports and Dashboards 🟩Deploying Splunk 🟩Monitoring Splunk 🟩Licensing Splunk 🟩Using Configuration Files 🟩Creating Indexes 🟩Managing Index 🟩Managing Users 🟩Configuring Basic Forwarding 🟩Configuring Distributed Search 🟩Getting Started with ES 🟩Security Monitoring and Incident Investigation 🟩Risk-Based Alerting 🟩Incident Investigation 🟩Installation 🟩Security Domain Dashboards 🟩security threats 🟩User Intelligence 🟩Web Intelligence 🟩Threat Intelligence 🟩 threat intel is configured in ES 🟩 interacting with your environment 🟩Protocol Intelligence 🟩Creating Correlation Searches 🟩Asset & Identity Management 🧠 مدرس : مهندس احمدرضا نوروزی 🌟برگزار کننده : سورین ⏳مدت دوره : 70 ساعت 🎓 نوع برگزاری:‌ حضوری / آنلاین 🏪ساعات برگزاری: شنبه و چهارشنبه – ساعت17:30 الی 20:30 ⏲زمان شروع : 29 اردیبهشت 💰شهریه : شش میلیون تومان 👩‍💻 پیش نیازها • آشنایی با شبکه و سیستم عامل لینوکس • آشنایی اولیه با حملات شبکه و میزبان • آشنایی نسبی با لاگ و سنسورهای امنیتی 🔗 نحوه ثبت نام: 📬 برقراری ارتباط با ادمین در صفحات اجتماعی ( تلگرام ، اینستاگرام ، لینکدین) ☎️ شماره تماس : 09102144597 #اسپلانک #دوره_اسپلانک #Splunk #امنیت_سایبری تیم سورین

Repost from Hypersec
🔓فورتی نت چندین آسیب‌پذیری حیاتی را که بر FortiClient، FortiSandbox، FortiOS و FortiProxy تأثیر می‌گذارند وصله می‌کند. 🛡https://securityonline.info/fortinet-patches-multiple-critical-vulnerabilities-affecting-forticlient-fortisandbox-fortios-and-fortiproxy/ #fortinet تیم سورین

👩‍💻CVE-2024-3094 checker xz Utils versions 5.6.0 and 5.6.1 appear to be compromised. XZ Utils is data compression software and may be present in Linux distributions. The malicious code may allow unauthorized access to affected systems. ✅اگه Deployment Server دارین میتونین این اسکریپت رو به همه لینوکس ها ارسال کنین و لاگش رو بگیرین تا متوجه بشین که سرور آسیب پذیر دارین یا نه! 🌐https://github.com/FabioBaroni/CVE-2024-3094-checker 🟢Credits : Mohammad Mirasadollahi🟢 #CVE #XZ #linux @splunk_kb

Repost from Hypersec
تشریح بکدور XZ توسط جادی #linux #XZ #backdoor تیم سورین

Repost from Hypersec
+1
📃 MITRE ATTACKS DETECTION RULES 2 تیم سورین

⚠️ Multiple Splunk Vulnerabilities Attackers Bypass SPL Safeguards : Patch Now‼️ CVE-2024-29945 (CVSS score: 7.2): This vulnerability could allow attackers to expose authentication tokens if Splunk Enterprise is running in debug mode or has specific logging configurations. CVE-2024-29946 (CVSS score: 8.1): This vulnerability is more severe because it allows attackers to bypass safeguards for risky commands within the Dashboard Examples Hub of Splunk Enterprise. An attacker could potentially trick a user into initiating a malicious request. 🌐https://cybersecuritynews.com/splunk-vulnerabilities-spl-safeguards/ #CVE #splunk @splunk_kb

Repost from Hypersec
📎The Windows startup process sequence. #ThreatHunting #DFIR تیم سورین

💎Splunk advanced input configuration for Windows based on MITRE ATT&CK framework. یکی از بهترین کانفیگ‌های فایل input.conf برای Universal Forwarder که بر روی فریمورک Mitre هم مپ شده 👌 💥https://github.com/mdecrevoisier/Splunk-input-windows-baseline تیم سورین ✉️@splunk_kb

Repost from Hypersec
آسیب پذیری CVE-2024-26198 به آسیب‌پذیری Remote Code Execution در Microsoft Exchange Server اشاره دارد. که در 12 مارس 2024 منتشر شد و دارای درجه شدت 8.8 (HIGH) است. این آسیب‌پذیری به مهاجم اجازه می‌دهد تا با ارسال یک درخواست طراحی‌شده خاص، کد دلخواه را روی یک سیستم آسیب‌دیده اجرا کند. حمله به تعامل کاربر نیاز دارد زیرا مهاجم باید کاربر را متقاعد کند که یک فایل مخرب را باز کند. نسخه های آسیب دیده عبارتند از: - Exchange Server 2019 CU13 و CU14 - Exchange Server 2016 CU23 مایکروسافت توصیه می‌کند فوراً به‌روزرسانی‌های امنیتی مارس 2024 را برای محافظت در برابر این آسیب‌پذیری نصب کنید. اطلاعات تکمیلی در مورد این آسیب پذیری :‌ https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-26198 دریافت بروزرسانی ها از طریق سایت رسمی مایکروسافت : https://learn.microsoft.com/en-us/exchange/new-features/build-numbers-and-release-dates تیم سورین

#تبادل 👆

🔻Explore the World of Cybersecurity on @Hide_Club Telegram Channel: 🐞 Bug Bounty Tools & Techniques 💉 Exploit Vulnerabilit
🔻Explore the World of Cybersecurity on @Hide_Club Telegram Channel: 🐞 Bug Bounty Tools & Techniques 💉 Exploit Vulnerabilities 💻 Web Application Security 🔐 Pentesting Insights 📚 Exclusive Bug Bounty Courses Join for Cutting-Edge Cybersecurity Content👇🏻 https://t.me/+RgbzBK2_-Mo5MTE8 https://t.me/+RgbzBK2_-Mo5MTE8 https://t.me/+RgbzBK2_-Mo5MTE8

🔖Cloud Recon This script is used to search for cloud certificate entities such as Amazon, Azure, and others that have been e
🔖Cloud Recon
This script is used to search for cloud certificate entities such as Amazon, Azure, and others that have been extracted by the kaeferjaeger[.]gay provider. It is useful for subdomain enumeration and finding additional apex domains during your reconnaissance processes.
You can find it on my GitHub : https://github.com/0xSpidey/cloudrecon.git Please follow me on GitHub and don't forget to give a star to this repo. Thank you all!❤️ #BugBounty #bugbountyTools — Share & Support Us — ➯ Channel : @Hide_Club 🔒

Repost from Hypersec
#تبادل👆