Archive
Highlighted

Which Splunk Threat Intelligence app in splunkbase lets us add our own IoC/ data for searching?

Explorer

Hi, Can somebody suggest a threat intel app available (apary from ES) which allows us to add our IOCs for searching matching events.

Thanks.

0 Karma
Highlighted

Re: Which Splunk Threat Intelligence app in splunkbase lets us add our own IoC/ data for searching?

Splunk Employee
Splunk Employee

There appear to be several options on Splunkbase, but it'll depend upon the format your IOCs are created in. One that stands out is SA-Splice for ingesting STIX 1.1, CybOX 2.1, OpenIOC 1.0 and 1.1 formats. A quick search on Splunkbase for "IOC" should give you plenty to work with.

Good luck!

View solution in original post