Based on the details provided, I think the most likely answer is TTP-driven hunting. The analyst started with a hypothesis and used existing data, which suggests they were looking for specific threat tactics, techniques, and procedures.
Based on my experience, the default path for the deployment server.conf file is SPLUNK_HOME/etc/system/local. That's where Splunk tends to put local configuration files.
upvoted 0 times
...
Log in to Pass4Success
Sign in:
Report Comment
Is the comment made by USERNAME spam or abusive?
Commenting
In order to participate in the comments you need to be logged-in.
You can sign-up or
login
Harris
4 months agoScarlet
4 months agoOwen
4 months agoAlberto
4 months agoGlennis
4 months agoShasta
5 months agoBeckie
5 months agoAlton
5 months agoLashawnda
5 months agoVerdell
5 months agoCheryll
5 months ago