PhishIQ Plus

Splunk Community

PhishIQ Plus

PhishIQ Plus
PhishIQPlus Technical for Splunk enriches URL telemetry in Splunk with phishing risk intelligence from the PhishIQPlus API. The app helps SOC teams prioritize investigations by adding prediction, confidence, risk level, source, cache status, and analysis metadata to URL-related events. It supports both dynamic enrichment from live Splunk searches and controlled batch processing, with built-in retry logic, circuit breaker protection, caching, and internal telemetry dashboards for operational visibility. This app is designed for enterprise security operations, including environments that integrate with Microsoft Sentinel and Microsoft security services, to provide consistent URL risk context across detection and response workflows.
0 topics and 0 replies mentioned PhishIQ Plus in
Latest Topics
No posts to display.
Latest Replies
No posts to display.
Top Topics
No posts to display.
My Topics
No posts to display.