TryHackMe - Splunk 101 | IAANSEC

Introduction to Splunk

Typically when people think of a SIEM, they think of Splunk, and rightly so. Per the Splunk website, they boast that 91 of the Fortune 100 use Splunk.

Splunk is not only used for security; it’s used for data analysis, DevOps, etc. But before speaking more on Splunk, what is a SIEM exactly?

A SIEM (Security Information and Event Management) is a software solution that provides a central location to collect log data from multiple sources within your environment. This data is aggregated and normalized, which can then be queried by an analyst.

As stated by Varonis, there are 3 critical capabilities for a SIEM:

Some other SIEM features:

This room is a general overview of Splunk and its core features. Having experience with Splunk will help your resume stick out from the rest.

Splunk was named a “Leader” in Gartner’s 2020 Magic Quadrant for Security Information and Event Management.

Per Gartner, “Thousands of organizations around the world use Splunk as their SIEM for security monitoring, advanced threat detection, incident investigation and forensics, incident response, SOC automation and a wide range of security analytics and operations use cases.”

Room Machine

Before moving forward, deploy the machine. If you want to RDP into the machine yourself:

Open Chrome and navigate to the Splunk instance ( You may need to refresh the page until Splunk loads.

Note: Splunk can take up to five minutes to fully load.

If you want to install Splunk on your own machine, follow Splunk’s official installation notes here.

Splunk Apps

Q. What is the ‘Folder name’ for the add-on?

Answer: TA-microsoft-sysmon

Q. What is the Version?

Answer: 10.6.2

Adding Data

Q. Upload the Splunk tutorial data on the desktop. How many events are in this source?

Note: Make sure you upload the data once only.

To add the tutorial data, start by:

  1. Clicking “Add Data” on the homepage.

  1. Click “Upload”.

  1. Click “Select file” or drag and drop the “tutorialdata” zip from the desktop into Splunk.

  1. Click “Next” to proceed to “Input Settings”.

  1. Leaving everything as default in “Input Settings” and click “Review”.

  1. Click “Submit”.

  1. Click “Start Searching”.

  1. Lastly wait Splunk to load all the events.

Answer: 109,864

Splunk Queries

Q. What is the sourcetype?

  1. Start by searching “failed password” in the search field.

  1. The sourcetype can be found in the bottom right corner of each of the events.

Answer: www1/secure

Q. What is the last username in this tab?

  1. After heading over to the “Patterns” tab the last pattern mentions the username “myuan”.

Answer: myuan

Q. Search for failed password events for this specific username. How many events are returned?

  1. While still under the “Patterns” tab, add the username that was found to the search query. After doing so, the events will be filtered to match the query.

Answer: 16

Sigma Rules

Q. Use the Select document feature. What is the Splunk query for ‘sigma: APT29’?

  1. Head over to
  2. In the “Select document” bar start typing “apt” and select APT29
  3. Select Splunk and translate, the splunk rule will be displayed in the box to the right.

Answer: CommandLine="-noni -ep bypass $

Q. Use the Github Sigma repo. What is the Splunk query for ‘CACTUSTORCH Remote Thread Creation’?

  1. Head over to the Sigma github repo.
  2. Navigate to *rules > windows > create_remote_thread > sysmon_cactustorch.yml.
  3. Copy and paste the yml rule into and translate it to Splunk.

Answer: SourceImage=“\System32\cscript.exe" OR SourceImage="\System32\wscript.exe” OR SourceImage=“\System32\mshta.exe" OR SourceImage="\winword.exe” OR SourceImage=“\excel.exe") AND TargetImage="\SysWOW64\*” AND NOT StartModule="

Dashboards & Visualizations

  1. Add the tutorialdata to Splunk and query for * | top limit=5 EventID

  1. From there follow the diagrams provided in the Dashboards & Visualizations and you should be able to get the graph to display.

Connect With Me :slightly_smiling_face:

Website Website Website Website