icon/x Created with Sketch.

Splunk Cookie Policy

We use our own and third-party cookies to provide you with a great online experience. We also use these cookies to improve our products and services, support our marketing campaigns, and advertise to you on our website and other websites. Some cookies may continue to collect information after you have left our website. Learn more (including how to update your settings) here.
Accept Cookie Policy

We are working on something new...

A Fresh New Splunkbase
We are designing a New Splunkbase to improve search and discoverability of apps. Check out our new and improved features like Categories and Collections. New Splunkbase is currently in preview mode, as it is under active development. We welcome you to navigate New Splunkbase and give us feedback.

Accept License Agreements

This app is provided by a third party and your right to use the app is in accordance with the license provided by that third-party licensor. Splunk is not responsible for any third-party apps and does not provide any warranty or support. If you have any questions, complaints or claims with respect to this app, please contact the licensor directly.

Thank You

Downloading Accedian Skylight powered Security
SHA256 checksum (accedian-skylight-powered-security_133.tgz) b3f342544a384b4b323ba7d095901dfadbd8b70fb4810effff12a75f960b8d6c SHA256 checksum (accedian-skylight-powered-security_132.tgz) d29001d23c07b1a9a239d84e2329fdb1e2771ebc526a1ef2327f18abdc222d60 SHA256 checksum (accedian-skylight-powered-security_131.tgz) 6b371b85fb4203407512ce9d777e45e5c00d7eab4917237ff47fc4b5990fa911 SHA256 checksum (accedian-skylight-powered-security_130.tgz) 19a20fbaffc853a36ca1d805d6527948758c30f1118ee4f85de1efae2f5885c6 SHA256 checksum (accedian-skylight-powered-security_122.tgz) aa22b9313b8c32704eb29ca52911c1bbcad5eadad433e0024a5d4b958315d4f1 SHA256 checksum (accedian-skylight-powered-security_121.tgz) c38ddbcc8e3851131f8c01e1c8c62275766706abf34f2736cf55be636f2d0c7a SHA256 checksum (accedian-skylight-powered-security_120.tgz) 57da129c6d12c30b1a55408e6f77b4cea46d6dd4d49ce611b2caa2743f547b27 SHA256 checksum (accedian-skylight-powered-security_111.tgz) 45573cda779e466a7463e038e270f22a0cef5a9ad8daf14e12521000710dcbb0 SHA256 checksum (accedian-skylight-powered-security_110.tgz) e34f53db47baeb0bf01d0a53b3b7c4518c677745ecc8a5f0fa248afc231a4255 SHA256 checksum (accedian-skylight-powered-security_106.tgz) 1bdf6f75b77c5956f9b880a9da4a435a96003ff978583463c886b6b4d6324cfa SHA256 checksum (accedian-skylight-powered-security_105.tgz) 8a027fc0ed122dfcefd63959efd775bd083c04cb6d98b01c50e6f3db887f2fbb SHA256 checksum (accedian-skylight-powered-security_104.tgz) 73d51db2927c820d1baac5854efa268c2936c9706ec2c8006aec7b2232d075b0 SHA256 checksum (accedian-skylight-powered-security_102.tgz) c580ab7dcbd8f6ad9c26e7908b98e79f4740d962737d6ea9cf4470150b85feb1 SHA256 checksum (accedian-skylight-powered-security_101.tgz) 791bc37c61d96192026b3915ce2c2769e83e48054c7d1a1e49fb152177c41dbb
To install your download
For instructions specific to your download, click the Details tab after closing this window.

Flag As Inappropriate

splunk

Accedian Skylight powered Security

This app has been archived. Learn more about app archiving.
This app is NOT supported by Splunk. Please read about what that means for you here.
Overview
Details
Accedian Skylight provides advanced threat detection, investigation, and long-term retention of high-definition forensic source data.

Gain full security visibility, including north-south and east-west visibility (server to server communication) across all networks, with Accedian Skylight—behaviour-based intrusion detection for today's hybrid environments. This ready-to-use solution, developed specifically for security analytics team, is simple to use, quick to get started, and aimed at helping you focus on what's important so that your time is spent as effectively as possible.

List of Required Apps:
TA Accedian Skylight powered Security https://splunkbase.splunk.com/app/4702/
Lookup File Editor https://splunkbase.splunk.com/app/1724/
Sankey Diagram - Custom Visualization https://splunkbase.splunk.com/app/3112/
Punchcard - Custom Visualization https://splunkbase.splunk.com/app/3129/
Parallel Coordinates - Custom Visualization https://splunkbase.splunk.com/app/3137/
Force Directed App For Splunk https://splunkbase.splunk.com/app/3767/
Splunk Common Information Model (CIM) https://splunkbase.splunk.com/app/1621/
URL Toolbox https://splunkbase.splunk.com/app/2734/

Installation Manual:
Accedian Skylight powered Security Installation Manual for Splunk: https://accedian.com/wp-content/uploads/2020/02/Accedian-Skylight-powered-Security-app-for-Splunk-Installation-manual-v-1.0.6_.pdf

The following features are included in the Skylight powered Security app:
- Visibility of your entire operational environment on the incident posture dashboard available in seconds
- Alerts sent to your preferred messenger(s) with minimal false-positive rates
- Built-in threat intelligence monitoring, plus custom TI feeds
- Enriched user and host context associated with each alert
- Suggested next investigation steps to help you decide if an issue is a true threat and to get to the bottom of it quickly
- Ability to review and adjust incident urgency to improve operations scheduling
- Complete visibility for issue status – new, in progress and resolved
- On-premises and cloud deployment available
- 10+ Gb/s monitoring throughput
- Well-suited and scalable for telecom, large enterprise and distributed physical and virtual networks (SDNs)
- Long-term retention of forensic quality source data including 100% of application security protocol transactions at 1 minute reporting interval (detailed granularity with easy to select time frame options)

Release Notes

Version 1.3.3
April 26, 2021
Version 1.3.2
Feb. 19, 2021
  • Minor changes in License Validation functionality
Version 1.3.1
Dec. 22, 2020
  • Added compatibility with Windows
Version 1.3.0
Nov. 16, 2020
  • Created a new data model for Alert Manager
  • Improved performance of Alert Manager
  • Implemented Splunk Licensing Safeguard
  • Implemented PoC and Full Modes
  • Fixed bugs

Added new security detections:
- SMB share scanning detection
- SMB file enumeration

Improved security detections:
- DNS tunneling
- Web traffic to Dynamic DNS providers
- Protocols or Port mismatch
- VPN traffic
- SQL injection
- Weak encryption

Adjusted throttle of security detections:
- Connection to the host from the high risky country
- Detect Web traffic to dynamic domain providers
- Internal hosts Query to non-corporate DNS
- Outbound SMB Traffic
- Possible Empire Powershell HTTP beacon communication
- Prohibited Network traffic Allowed
- Protocol or port mismatch
- Scanner's User-Agents
- VPN Traffic

Version 1.2.2
Sept. 14, 2020
  • Fixed SMB delete and SMB share scanning detections
  • Fixed DGA ML detection
  • Changed default schedule for alerts

Added new detection:
- Suspicious DCE/RPC
- Suspicious Named pipes
- Executable Read/Write to admin share
- Cobalt strike SMB beacon
- SMB beaconing by time
- SMB beaconing by size
- HTTP beaconing by size
- DNS beaconing by time
- Threat Activity detected(Connection to malicious IP address)
- Threat Activity detected(Connection to malicious Domain)

Beaconing detection by time changes:
- Begin time used instead of default time
- Time in event changed from 'lastTime' to 'First time'

Version 1.2.1
Aug. 14, 2020
  • Improved Skylight Sensors indicator.
  • Improved Network Graph Connection dashboard.
  • Fixed some bugs.
  • Updated Data Exfiltration alert.
  • Added new alert: Empire detection.
Version 1.2.0
July 15, 2020
Version 1.1.1
May 8, 2020
  • Improved whitelist functionality.
  • Added asset inventory
  • Added multi-site support
  • Fixed bugs
Version 1.1.0
March 12, 2020
  • Improved Dashobards efficiency using Data Model acceleration.
  • Improved Alerts efficiency using Data Model acceleration.
  • Improved whitelist functionality.
  • Fixed bugs.
Version 1.0.6
Feb. 13, 2020
Version 1.0.5
Jan. 14, 2020
Version 1.0.4
Dec. 12, 2019

-New and improved detection scenarios;
-Added detailed cipher info into SSl Activity dashboard;
-Possibility to change the status for several tickets;
-Added white list functionality for alerts;
-Added Skylight sensor connection indicator;
-Fixed bugs.

Version 1.0.2
Sept. 19, 2019
Version 1.0.1
Sept. 18, 2019

Subscribe Share

Are you a developer?

As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 10GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps from Splunk, our partners and our community. Find an app for most any data source and user need, or simply create your own with help from our developer portal.

Follow Us:
Splunk, Splunk>,Turn Data Into Doing, Data-to-Everything, and D2E are trademarks or registered trademarks of Splunk Inc. in the United States and other countries. All other brand names,product names,or trademarks belong to their respective owners.