File Hashes Analysis with Power BI from Data Stored in DShield SIEM, (Wed, Mar 12th)
ID: 187bced1-0d60-5d83-9263-bdb54343bf20
STIX ID: report--187bced1-0d60-5d83-9263-bdb54343bf20
Feed Name: SANS ISC Diary
Threat Score
The author explains how they exported 60 days of honeypot/SIEM data from Kibana into Power BI to visualize activity and identify malicious artifacts; the analysis surfaces repeated uploads from specific IPs, filenames and hashes tied to RedTail cryptomining malware, Xorddos, and an IRCBot, and emphasizes that exporting large datasets can reveal otherwise overlooked indicators for retrospective hunting.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
