Splunk Asset and Risk Intelligence (Splunk ARI) discovers and reports on risks affecting assets and identities. This risk discovery is performed in real-time, ensuring that risks can be quickly addressed, helping to limit exposure and increase overall security posture. In this post, we highlight three use cases related to asset risk using Splunk ARI.
https://discoveredintelligence.com/wp-content/uploads/2025/04/ari_risk_insights.png8321402Discovered Intelligencehttps://discoveredintelligence.com/wp-content/uploads/2013/12/DI-Logo1-300x137.pngDiscovered Intelligence2025-04-08 08:52:002025-05-06 15:19:11Finding Asset and Identity Risk with Splunk Asset and Risk Intelligence
Data protection is a critical priority for any organization, especially when dealing with sensitive information like personal identifiable information (PII) and protected health information (PHI) data. Implementing robust protection mechanisms not only ensures compliance with regulations like the General Data Protection Regulation (GDPR) but also mitigates the risk of data breaches.
https://discoveredintelligence.com/wp-content/uploads/2025/01/field_filters.jpg7201000Carlos Moreno Buitragohttps://discoveredintelligence.com/wp-content/uploads/2013/12/DI-Logo1-300x137.pngCarlos Moreno Buitrago2025-01-21 15:45:242025-01-21 15:47:43Field Filters 101: The Basics You Need to Know
With the recent release of Splunk Asset and Risk Intelligence (ARI), you may be looking for a better understanding of this great new solution and how you may get started. We have compiled a list of materials and resources you can use to help achieve this goal.
Read and Learn
Product overviews and briefs
If this is your first time reading up on Splunk Asset and Risk Intelligence, check these out first:
Get a quick look at the Splunk ARI interface with screen shots of the platform, along with information about its features and capabilities through the following blog posts:
It is often quicker, easier and more cost effective to get the Splunk ARI experts in. Our award winning consultants are highly trained on Splunk ARI and will ensure your continued success.
https://discoveredintelligence.com/wp-content/uploads/2018/10/gettingstarted.jpg286420Discovered Intelligencehttps://discoveredintelligence.com/wp-content/uploads/2013/12/DI-Logo1-300x137.pngDiscovered Intelligence2024-12-02 15:02:342024-12-03 16:58:22Help Getting Started with Splunk Asset and Risk Intelligence (ARI)
Splunk Asset and Risk Intelligence (ARI) provides teams with detailed and powerful visibility into risks affecting discovered assets. This helps teams to quickly identify and address gaps in security controls, understand compliance with cybersecurity frameworks and offers greater context during security investigations.
Splunk Asset and Risk Intelligence (ARI) provides detailed insights into how active an asset has been over time. Instantly identify who had what asset and when, view any asset changes or even identify unusual asset activity within your network.
Splunk Asset and Risk Intelligence (ARI) enables your team to quickly perform complete and thorough asset investigations. An interactive and holistic approach provides security teams with much needed context about assets, including asset health, network activity and associations.
Splunk Asset and Risk Intelligence (ARI) continuously discovers all assets on the network using a unique approach that creates a single source of truth from multiple sources of record, resulting in comprehensive and accurate asset visibility and reporting.
Splunk Asset and Risk Intelligence (ARI) is a powerful, premium application from Splunk which delivers proactive risk mitigation through continuous asset discovery and compliance monitoring.
At the recent Splunk .Conf in Las Vegas a couple of weeks ago, we were able to get a detailed demo of Splunk’s new and exciting Splunk Asset and Risk Intelligence (Splunk ARI) security solution. What a great solution and one that is much needed within their security solution portfolio. Splunk ARI falls into a category of products known as CAASM – Cyber Asset Attack Surface Management. In this post, we dive a little deeper into what CAASM is, why it is critical tool for your organization and how Splunk ARI can help.
https://discoveredintelligence.com/wp-content/uploads/2024/06/ari_homepage.png4651000Discovered Intelligencehttps://discoveredintelligence.com/wp-content/uploads/2013/12/DI-Logo1-300x137.pngDiscovered Intelligence2024-07-02 09:00:002024-07-17 14:09:26Splunk Asset and Risk Intelligence – a CAASM Solution for Splunk
The quote from Check Point Research above illustrates where the future trend of cybersecurity is headed and the challenges that organizations must face. However, anticipating and preparing the system defenses to evade and mitigate these attacks is not an easy task. From defining response and incident strategies to preparing work teams and configuring monitoring systems, it can all be a challenge.
Your core business is not to detect and mitigate security attacks, but is this essential to the achievement of your objectives? Have you ever wondered how you can simulate attacks and detections within a controlled environment to validate the configuration of your detection systems without spending part of your annual security budget? Read on and discover Splunk Attack Range.
What is Splunk Attack Range?
Splunk Attack Range is a tool developed by Splunk Threat Research Team (STRT) to simulate cyber attacks in a controlled environment for the purpose of improving an organization’s security posture. It allows security teams to test and validate their detection and response capabilities against a wide range of attack scenarios and techniques, such as phishing, malware infections, lateral movement, and data exfiltration.
Splunk Attack Range is designed to work with Splunk Enterprise Security, which is a security information and event management (SIEM) solution, and includes pre-built attack scenarios that are aligned with the MITRE ATT&CK framework, these ones can be customized to simulate the specific threats and vulnerabilities that are relevant to an organization’s environment.
Where can I get Attack Range?
The STRT and the Splunk community are maintaining the project in GitHub.
Is Splunk Attack Range Easy to Deploy?
Yes, it is really straightforward! You can deploy it locally (if you have a powerful machine), on Azure or on AWS. Internally, we use our AWS environment and with a few simple steps, in a matter of minutes, terraform and ansible automatically deploy a complete test lab to validate our customers’ security configurations and optimize the security posture with Splunk’s real-time monitoring. This process allows for a proactive approach to managing security postures with Splunk and saves a lot of time for your Blue Team.
…and now?
Have fun! By merging our Splunk expertise and using these kinds of automation tools, we have been able to speed up our internal testing processes, stay agile and secure with Splunk’s security posture management tool, and transfer this knowledge and configurations on to our customers’ cybersecurity teams.
We strongly encourage you to try this tool. Check out an overview of v1.0, v2.0 and v3.0 in the Splunk blog.
https://discoveredintelligence.com/wp-content/uploads/2023/03/splunk-attack-range-logo-e1678466676167.png693696Carlos Moreno Buitragohttps://discoveredintelligence.com/wp-content/uploads/2013/12/DI-Logo1-300x137.pngCarlos Moreno Buitrago2023-03-14 15:17:262023-03-14 15:17:29Save Time and Improve your Security Posture with Splunk Attack Range