Splunk Security Content Logo

Splunk Security Content

0
Free
Visit Website

Welcome to the Splunk Security Content. This project provides access to a repository of Analytic Stories, security guides that offer insights into tactics, techniques, and procedures (TTPs) mapped to the MITRE ATT&CK Framework, Lockheed Martin Cyber Kill Chain, and CIS Controls. It includes Splunk searches, machine learning algorithms, and Splunk Phantom playbooks designed to work together for threat detection, investigation, and response. Additionally, there are sister projects like Splunk Attack Range, an attack simulation lab, and Contentctl, a tool for building, testing, and packaging content for distribution.

FEATURES

ALTERNATIVES

Sysdig is a system visibility tool with native container support.

Free

HoneyView is a tool for analyzing honeyd logfiles graphically and textually.

Free

Elasticsearch is a versatile platform for centralized data storage, fast search, and scalable analytics.

Free

Windows Event Log Analyzer with logon timeline generator and noise reduction for fast forensics.

Free

GrokEVT is a tool for reading Windows event log files and converting them to a human-readable format.

Free

A toolset for collecting and processing netflow/ipfix and sflow data from netflow/sflow compatible devices.

Free

A community-led project focused on standardizing security event logs.

Free

Procmon for Linux is a reimagining of the classic Procmon tool from Windows, allowing Linux developers to trace syscall activity efficiently.

Free

PINNED