Splunk Enterprise Security

Enterprise Security - Threat intel (General Discussion)

siddh01r
New Member

Hi All,

Just curious to see what threat intel Enterprise Security Specialists/administrators are using for their SIEM.
Out of the box you get plenty of options but most of them are false positives that cause a lot of noise.

So i am keen to see what paid/free threat intel other security specialists are using out there or have had great experience with?
some that give less false positives and are more accurate.

I know this a very general question but certainly will help me step towards creating a good business case to on board paid intels.

Thanks everyone.

0 Karma

jawaharas
Motivator

Recorded Future for Splunk provides real-time threat intelligence for SOC teams with a Splunk security solution. We tried in my team and it provides better threat intel.

https://www.recordedfuture.com/

0 Karma

jawaharas
Motivator

@siddh01r

Can you accept the answer if it's helped you? Thanks.

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...