Incident handling with Splunk

CVE-2014-6271

joomla

acunetix

192.168.250.70

23.22.63.114

/joomla/administrator/index.php

admin

batman

412

40.80.148.42

AAE3F5A29935E6ABCC2C2754D12A9AF0

NT AUTHORITY\IUSR

ab.exe

poisonivy-is-coming-for-you-batman.jpeg

HTTP.URI.SQL.Injection

prankglassinebracket.jumpingcrab.com

23.22.63.114

lillian.rose@po1s0nvy.com

c99131e0169171935c5ac32615ed6261

MirandaTateScreensaver.scr.exe