Welcome to the new Splunkbase! To return to the old Splunkbase, .
Warning

This app is archived.

Third Man Correlation Search app icon

Third Man Correlation Search

== THIS APP IS CURRENT UNDERGOING SIGNIFICANT REFACTORING - PLEASE CHECK IN AGAIN LATER FOR A NEW VERSION ==

Built by
splunk product badge
screenshot
screenshot
screenshot

Latest Version 2.0.1
February 15, 2016
Compatibility
Not Available
CIM Version: 4.x
Rating

0

(0)

Log in to rate this app
Support
Third Man Correlation Search support icon
Not Supported
== THIS APP IS CURRENT UNDERGOING SIGNIFICANT REFACTORING - PLEASE CHECK IN AGAIN LATER FOR A NEW VERSION == Is the use of stolen credentials through phishing and other means a concern in your organisation? The Third Man Correlation Search app detects misappropriated credentials using an abstract statistical fingerprint of users' successful auth behaviour. The correlation search takes the CIM Authentication data model and enriches it with autonomous system information and an abstraction of time, then creates a statistical "fingerprint" of each users' behaviour in relation to what, when, where and how they successfully auth. A significant deviation from a user's pattern triggers the alert. Although this sounds relatively straightforward, importantly this correlation searches' ability to detect anomalous behaviour is derived from it's unique high-level abstraction of circumstances.

Categories

Created By

Doug Brown

Type

app

Downloads

602

Licensing

Splunk Answers

Resources

Log in to report this app listing