All Apps and Add-ons

Test Server for Splice - STIX TAXII CybOX

j666gak
Communicator

Hi, I have installed the Splice app and have it working for local IOC files. However I want to get it work with TAXII, and remotely IOCs.

Is anybody aware of a of a test server which can be subscribed to for picking up IOCs?

Tags (1)
0 Karma

cleroux_splunk
Splunk Employee
Splunk Employee

since the first answer, SPLICE has been successfully tested with http://www.hailataxii.com feeds (-:

CSmoke
Path Finder
0 Karma

cleroux_splunk
Splunk Employee
Splunk Employee

I’m not aware of any public TAXII feed except the Yeti test server from MITRE (http://taxiitest.mitre.org/) which allows to test a basic TAXII communication (http only).

Other projects that may interest you :
- MISP - https://github.com/MISP/MISP
- CRITS - https://crits.github.io
- Solra - http://www.soltra.com (formerly known as Avalanche)
- and probably others I forgot

Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...