Skip to Main Content
NOTICE: Your download and use of Edge Hub beta firmware is subject to the terms and conditions of your Splunk Partner Agreement, the Splunk General Terms, or the Splunk Beta Evaluation Agreement – Splunk IoT Edge Hub, as applicable to you.
Ideas
EdgeHub Beta Ideas Portal
Categories Use Cases
Created by shannond_splunk
Created on Jul 26, 2023

Edge Hub as Honeypot/Deception Technology

This idea is to have the Edge Hub present itself as a PLC/HMI/other OT function. As the Edge Hub isn't part of the customer's production environment, any interaction can be deemed suspicious, and alerts should be fired.

With the Edge Hub logging to Splunk, these alerts would be easy for us to ingest. The customer would be warned early about any malicious activity in their OT/ICS environments.

  • Attach files