heroui logo

Monitor Web Traffic For Brand Abuse

Splunk Security Content

View Source
Summary
The analytic "Monitor Web Traffic For Brand Abuse" focuses on detecting web requests made to domains that are similar to an organization's official brand domain, which may signify brand abuse activities such as phishing or impersonation attempts. This detection mechanism utilizes data gathered from web traffic sources, such as web proxies or tools for analyzing network traffic, and matches those requests against a list of known domain variations sourced from the "ESCU - DNSTwist Domain Names" search. The key goal is to identify potentially malicious activities that could compromise user credentials, facilitate the spread of malware, or cause serious reputational harm to the brand. The analytic is currently marked as experimental and requires rigorous implementation steps, including the ingestion of relevant web traffic data and domain permutation searches.
Categories
  • Web
  • Network
Data Sources
  • Web Credential
  • Network Traffic
Created: 2024-11-15