An investigation with Splunk + CKCΒΆ The only marathon where the finish line is a .conf file. Splunk investigation walkthrough I am really not batman Reconnaissance phase Exploitation phase Installation phase Action on objectives Command and control phase Weaponisation phase Delivery phase