Hi @gmbdrj ,
it's realli diffi coult to answer to your question in few words.
A>nyway, installi the MItre Att@ck app, you can start from a mapping of your Searches with this framework.
Then you can use the Enterprise Security (if you have) and/or the Splunk Security Essentials App to be guided in Use Cases implementation.
Anyway, remember that the starting poins is always data: you have to analyze the data you have to understand which Use Cases you can enable.