Weaponizing Splunk: Using Blue Team Tools for Evil

BSides Tampa 2017

Presented by: Ryan Hays
Date: Saturday February 11, 2017
Time: 13:00 - 13:45
Location: 2nd Floor Seminar Room

Companies are always looking for easier ways to review, audit, and track all the systems within an environment. Splunk has taken a large chunk of that market space as companies jump to quickly purchase and deploy their solution. Red teamers and penetration testers can also use this tool but in an even more creative way to penetrate the environment and more laterally until the entire domain is compromised.

Ryan Hays

Ryan is the Security Programs Director at TBG Security. He has 14yrs of experience on both the offense and defense sides of the house. Currently working primarily with commercial customer he previously was a defense contractor and Navy Veteran.


KhanFu - Mobile schedules for INFOSEC conferences.
Mobile interface | Alternate Formats