Tag: Sigma to Splunk

Linux Syscall Threat Detection in Splunk with Uncoder AI
Linux Syscall Threat Detection in Splunk with Uncoder AI

Linux Syscall Threat Detection in Splunk with Uncoder AI How It Works The detection logic here is built around monitoring use of the mknod syscall, which is rarely used in legitimate workflows but can be exploited by attackers to: Create fake block or character devices Interact with kernel interfaces Bypass file system controls or establish […]

Read More