Splunk Search

first packet recorded of the reconnaissance

cyberfan
Explorer

 any idea to write the query to capture the first packet recorded of the reconnaissance from the vulnerability scanner

Labels (1)
0 Karma

thambisetty
SplunkTrust
SplunkTrust

What’s the logic you applied to detect vulnerability scanner? 
Share your logic to guide you to get first event of vulnerability scanner?

————————————
If this helps, give a like below.
0 Karma
Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

WATCH NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If exploited, ...

Enter the Splunk Community Dashboard Challenge for Your Chance to Win!

The Splunk Community Dashboard Challenge is underway! This is your chance to showcase your skills in creating ...

.conf24 | Session Scheduler is Live!!

.conf24 is happening June 11 - 14 in Las Vegas, and we are thrilled to announce that the conference catalog ...