Using Splunk to Catch Pesky Employees Outsourcing Their Job

 

There was a Case Study published by Andrew Valentine over at the Verizon Business Security Blog titled “Pro-active Log Review Might Be A Good Idea” which details an incident where an employee working for a “U.S. critical infrastructure company” was found to have outsourced his own job to a Chinese consulting firm. Here’s a quick snippet from the Case Study:

“As it turns out, Bob had simply outsourced his own job to a Chinese consulting firm. Bob spent less that one fifth of his six-figure salary for a Chinese firm to do his job for him. Authentication was no problem, he physically FedExed his RSA token to China so that the third-party contractor could log-in under his credentials during the workday. It would appear that he was working an average 9 to 5 work day.”

Slidedeck From My Most Recent Splunk Event Presentation

 

Decided to finally make public the slide deck I created as a “customer presentation” for a Splunk & Herjavec Group sponsored event here in Toronto on Dec 14, 2012. It was my 6th time being a customer presenter for a Splunk event and as always enjoyed the opportunity to speak, share ideas and meet new faces. So….. Thoughts? Annoyances? Public lashing? I welcome all 🙂 Slides can be found here:

http://www.slideshare.net/iam_joshd/josh-diakun-cust-pres-splunk-partner-event