File Hashes Analysis with Power BI from Data Stored in DShield SIEM, (Wed, Mar 12th)
SANS Internet Storm Center, InfoCON: green 2025-03-13
Summary:
I previously used Power BI [;2]; to analyze DShield sensor data and this time I wanted to show how it could be used by selecting certain type of data as a large dataset and export it for analysis. This time, I ran a query in Elastic Discover and exported that data to analyze it in PowerBI into a CSV format. The first step was to run a query in Discover and select the past 60 days with the following query: file.name : *