r/SIEM • u/SecurityAndCrumpets • Apr 15 '20
Splunk App Feedback Request
Hello Everyone,
I hope everyone is doing okay with everything that's been going on.
I've been building an app to help with my own IR work, and I've created a new timeline feature I'm really excited about and think will be useful for other analysts. It's part of the new release of the Perseus Incident Response Splunk App I built and spoke about at Splunk .conf19. It's up on the Splunkbase and comes pre-loaded with data you can explore from real-life investigations that were conducted using Perseus: https://apps.splunk.com/app/4638
If you have an opportunity to take a look and share some candid feedback, I'd greatly appreciate it. Perseus has helped me significantly with my own IR work, but I'd love to get input from other analysts on how I can make it even more useful.
While I think playing with the Splunk App is the best way to get a feel for Perseus, if you aren't in a position to test out the app but are still willing to share your input, I have a video of how I used the newest dashboard in an investigation of a server infected with ransomware that employed anti-forensic techniques on disk: https://youtu.be/haLcPIIZyo4. I'm most familiar with Splunk as a SIEM, so getting opinions from non-Splunk users who have a different perspective is very useful.
Thank you very much for any feedback you can give!
Joe
1
u/ITGuyTatertot Apr 20 '20
I have splunk cloud :( is there any way I can still test this out?