Tag: Sigma to Splunk

Linux Syscall Threat Detection in Splunk with Uncoder AI
Linux Syscall Threat Detection in Splunk with Uncoder AI

How It Works The detection logic here is built around monitoring use of the mknod syscall, which is rarely used in legitimate workflows but can be exploited by attackers to: Create fake block or character devices Interact with kernel interfaces Bypass file system controls or establish backdoors Left Panel – Sigma Rule: Logsource: auditd on […]

Read More