logo

File Hashes Analysis with Power BI from Data Stored in DShield SIEM, (Wed, Mar 12th)

ID: 187bced1-0d60-5d83-9263-bdb54343bf20

STIX ID: report--187bced1-0d60-5d83-9263-bdb54343bf20

Feed Name: SANS ISC Diary

Threat Score
45/100

Date Published: 2025-03-13

Date Updated: 2026-04-19

...
...

The author explains how they exported 60 days of honeypot/SIEM data from Kibana into Power BI to visualize activity and identify malicious artifacts; the analysis surfaces repeated uploads from specific IPs, filenames and hashes tied to RedTail cryptomining malware, Xorddos, and an IRCBot, and emphasizes that exporting large datasets can reveal otherwise overlooked indicators for retrospective hunting.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.