Analytics Story: Monitor for Unauthorized Software
REMOVED ANALYTIC STORY
This analytic story has been removed from the Splunk Threat Research content library and is no longer maintained or supported.
Reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
Removed in version: 5.2.0
If you have any questions or concerns, please reach out to us at research@splunk.com.
Description
Identify and investigate prohibited/unauthorized software or processes that may be concealing malicious behavior within your environment.
Why it matters
It is critical to identify unauthorized software and processes running on enterprise endpoints and determine whether they are likely to be malicious. This Analytic Story requires the user to populate the Interesting Processes table within Enterprise Security with prohibited processes. An included support search will augment this data, adding information on processes thought to be malicious. This search requires data from endpoint detection-and-response solutions, endpoint data sources (such as Sysmon), or Windows Event Logs--assuming that the Active Directory administrator has enabled process tracking within the System Event Audit Logs. It is important to investigate any software identified as suspicious, in order to understand how it was installed or executed. Analyzing authentication logs or any historic notable events might elicit additional investigative leads of interest. For best results, schedule the search to run every two weeks.
Detections
| Name | Technique | Type |
|---|
Data Sources
| Name | Platform | Sourcetype | Source |
|---|
References
Version: 2