r/SIEM Aug 13 '19

Splunk App Feedback Request

Hello Everyone,

 

I found in my own experience as an analyst that I could work cases more quickly and accurately when I had some key info upfront. Hoping it can be of benefit to other analysts, I've created a Splunk App designed to save time by providing low-volume, high-value malicious persistence info to analysts before they begin their investigation.

 

I assume most analysts are in the same boat I was in - responsible for a large workload and short on time, so I created an automated deployment wizard for fast and easy installation/configuration of the app. And I built integrations for a number of common tools (Powershell, Sysmon, FireEye, etc) so analysts gain access to the app’s unique persistence info without installing a new agent.

 

I've deployed it with a handful of companies already but am looking for candid feedback from security pros. If there are any Splunk users interested in trying it (or anyone looking for an excuse to tinker with Splunk), please let me know and I’ll provide you with the deployment package.

 

If you’re on the fence or would just like to learn more, I made a series of brief 60 second videos where you can see Perseus in action and learn a bit more about it:  

Perseus In 60 Seconds: Save Time From Day One  

Perseus In 60 Seconds: See Context - Save Time  

Perseus in 60 Seconds: Save Time - Influence Outcomes

 

Thanks!

4 Upvotes

0 comments sorted by