Advanced APT Hunting With Splunk Takeaway
Advanced APT Hunting With Splunk Takeaway
Advanced APT Hunting With Splunk Takeaway
Thank you for attending Advanced APT Hunting with Splunk. We hope you found it helpful.
Below are reference materials and links that were found throughout the workshop.
Depending on how many of the hunts you performed, some of these links may be more
relevant than others. For grouping purposes, links are grouped by hunt.
While the BOTSv2 data set and app that we used is not yet available, if you are interested in
hunting and investigating a Splunk BOTS data set, you have a few options. Below are links to
blogs and the data sets where you can learn more about downloading your own copy or using
our sandbox.
If you want to learn more about some of the techniques that we touched on, check out the
Hunting with Splunk! Blog Series:
https://www.splunk.com/blog/2017/07/06/hunting-with-splunk-the-basics.html
Hunt 0
Quick search to get a list of all sourcetypes in a specific index and when they were first seen and
last seen
CyberChef: https://gchq.github.io/CyberChef
NET.exe Share
https://ss64.com/nt/net-share.html
Adversary Infrastructure
Censys.IO: http://Censys.io
Robtex: https://www.robtex.com/ip-lookup/45.77.65.211
Spearphising Attachment
MIME Types: https://developer.mozilla.org/en-
US/docs/Web/HTTP/Basics_of_HTTP/MIME_types
Whois: https://whois.domaintools.com/
CyberChef: https://gchq.github.io/CyberChef
VirusTotal: https://www.virustotal.com/#/home/search
User Execution
Phishing with Empire (Blog): https://enigma0x3.net/2016/03/15/phishing-with-empire/
Account Persistence
Windows Command Reference: https://docs.microsoft.com/en-us/windows/security/threat-
protection/auditing/event-4720
Scheduled Tasks
Schtasks.exe command reference:
https://msdn.microsoft.com/en-us/library/windows/desktop/bb736357(v=vs.85).aspx
Reconnaissance
What is my browser: https://whatismybrowser.com
Whois: https://whois.domaintools.com/
ExpressVPN: https://www.expressvpn.com/
Lateral Movement
Detecting Lateral Movement through Tracking Event Logs:
http://www.jpcert.or.jp/english/pub/sr/Detecting%20Lateral%20Movement%20through%20Tr
acking%20Event%20Logs_version2.pdf
Data Staging
MITRE ATT&CK Techniques Referenced
Data Staged - https://attack.mitre.org/techniques/T1074/