Splunk rolled out new enterprise security capabilities at its annual .conf event that it says provide a full security operations center (SOC) platform with threat intelligence, security analytics, and automation.
The updates center on the Splunk Security Cloud and Splunk SOAR, and in addition to new features for both products, the company also announced an incident response team called SURGe.
Splunk first announced its Security Cloud in June. The platform originally combined Splunk’s security analytics and security information and event management (SIEM) with its security orchestration, automation, and response (SOAR). It now also includes threat intelligence, investigation, and response capabilities from Splunk’s TrueStar acquisition, which closed in May.
Splunk Boosts Threat Intel, Response With TrueStar“Today, we’re announcing that TrueStar will officially become Splunk Intelligence Management and excitingly, it will soon be available to all of our enterprise security customers,” Splunk SVP and CPO Garth Fort said during his .conf keynote. This will allow customers to integrate open source and other threat-intelligence feeds to support their own internal intelligence, he added.
“Customers have reported a double-digit percent improvement in both mean time to detect and mean time to resolution by operationalizing security enrichment from third-party sources,” Fort said.
TrueStar’s technology also allows customers to create secure enclaves in the cloud. These cloud-based repositories with strict access controls allow SOC teams to share security events, he said.
Additionally, Spunk announced several other new Security Cloud features, which it says are “coming soon.”
Splunk Security Cloud UpdatesThese include a new Executive Summary Dashboard, which will provide SOC insights, including mean time to triage and resolution, investigations created, and risk-based alerting trends.
Similar to the Executive Summary Dashboard, the upcoming Security Operations Dashboard will provide deeper analysis for SOC analysts. Previously, Splunk announced an incident-review feature that allows teams to record whether an event was a true positive, false positive, or a benign positive. “Coming soon, you will see and report on this data over time, and get a deep dive into exactly which correlation sources contribute to each of the four default disposition types,” Splunk VP of Security Products Jane Wong wrote in a blog post. “This will allow your team to decide which events should be expanded and which are eligible to be retired.”
Splunk will also update its Cloud Security Monitoring Dashboard to provide better visibility into Amazon Web Services (AWS) and Microsoft 365 environments with new dashboards such as AWS Security Groups and AWS IAM Activity.
Additionally, Security Cloud customers will soon get in-product, automated real-time content updates from the Splunk Threat Research Team and behavioral analytics, which is now available in preview. Behavioral analytics, which highlight anomalous user and entity behavior, help augment customers’ security information and event management (SIEM) in the cloud with real-time search and analytics. This will “accelerate your mean time to detect” so SOC teams can “spend more time hunting with higher-fidelity, risk-based behavioral alerts,” Wong explained.
And finally, Splunk updated Security Essentials with pre-built detections and analytic stories, which are grouped detections against adversaries or events, and MITRE ATT&CK industry-based detection recommendations and custom content mapping.
Don’t Forget SOARWith SOAR, Splunk added features that it says increase speed of response through automation.
In August, Splunk SOAR launched an updated visual playbook editor to help eliminate manual security tasks and automate responses to security incidents. And today is released a new SOAR App Editor to edit, test, and create SOAR apps. It also provides integration and automation between Splunk SOAR and commonly used third-party tools.
Comments