The field file_acl contains access controls associated with files affected by an event. In which data model would an analyst find this field?
Which of the following is not considered an Indicator of Compromise (IOC)?
The Security Operations Center (SOC) manager is interested in creating a new dashboard for typosquatting after a successful campaign against a group of senior executives. Which existing ES dashboard could be used as a starting point to create a custom dashboard?
When threat hunting for outliers in Splunk, which of the following SPL pipelines would filter for users with over a thousand occurrences?