Recorded Future was recognized as Splunk’s 2024 Global Technology Innovation Partner of the Year at .conf24. Chris Coburn delves into their Splunk integration and innovation in this video.
Transcript
Auto-generated captions, lightly cleaned. Speakers are not separately labeled.
hey everyone we’re out here at doom4 and I’m talking to recorded future The Innovation partner of the Year hey can you tell us a little bit more about what you’re doing with Splunk and what the Innovation is sure yeah thanks so much we’re really excited to have won that award you know we’ve worked really really hard on how we integrate our threat intelligence into Splunk so for those of you who aren’t aware of recorded future we’re the world’s largest source of cyber threat intelligence we collect threat intelligence from a million different sources things like the dark web Deep Web GitHub Network traffic analysis entity and malware detonations all of this kind of stuff the key thing is this intelligence graph of data we take that data we make it available in this spunk for three major use cases we allow you to correlate right we allow you to say hey you’re getting all of this data that have these external IP addresses and domains and hashes and URLs we allow you to take that data and correlate it against our known bad indicators so now when you say hey I got this destination IP address and it’s communicating to known C2 server I can know about that right away to lower that mean time to detection the next major use case your analyst needs the context to make a decision as fast as possible so we allow you to enrich with all of the vast context that reported future provides around indicators so that they can say hey this IP address is a C2 infrastructure for this piece of Mal whereare I know what I need to do now right no more spending 30 seconds trying to Google what that external IP address is they can make a decision immediately lowering that meantime to response the third stage is now the you have your correlation and your enrichment all tuned threat hunting let’s look at Pro retroactive and proactive threats from an indicator perspective or from a behavior perspective with the rich threat intelligence that recorded future provides all that within the Splunk UI without having to Pivot anywhere else we’re only able to do that because Splunk offers such incredible extensibility and such incredible power it’s in my opinion the perfect marriage of the you know industry-leading cyber threat intelligence and industry-leading analytics and that this fantastic overview so if I want to go get some more information where do I go to get started sure you can go to the recorded future.com website we have lots of information about everything we do in spunk as well as all of the other intelligence products that we offer we also offer a 30-day free trial of the spunk integration if you’re already a spunk customer and you’d like to see what the power of that threat intelligence within your platform would look like incredible thank you thank you