All Apps and Add-ons

Test Server for Splice - STIX TAXII CybOX

j666gak
Communicator

Hi, I have installed the Splice app and have it working for local IOC files. However I want to get it work with TAXII, and remotely IOCs.

Is anybody aware of a of a test server which can be subscribed to for picking up IOCs?

Tags (1)
0 Karma

cleroux_splunk
Splunk Employee
Splunk Employee

since the first answer, SPLICE has been successfully tested with http://www.hailataxii.com feeds (-:

CSmoke
Path Finder
0 Karma

cleroux_splunk
Splunk Employee
Splunk Employee

I’m not aware of any public TAXII feed except the Yeti test server from MITRE (http://taxiitest.mitre.org/) which allows to test a basic TAXII communication (http only).

Other projects that may interest you :
- MISP - https://github.com/MISP/MISP
- CRITS - https://crits.github.io
- Solra - http://www.soltra.com (formerly known as Avalanche)
- and probably others I forgot

Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...