Splunk Security Content Logo

Splunk Security Content

0
Free
Visit Website

Welcome to the Splunk Security Content. This project provides access to a repository of Analytic Stories, security guides that offer insights into tactics, techniques, and procedures (TTPs) mapped to the MITRE ATT&CK Framework, Lockheed Martin Cyber Kill Chain, and CIS Controls. It includes Splunk searches, machine learning algorithms, and Splunk Phantom playbooks designed to work together for threat detection, investigation, and response. Additionally, there are sister projects like Splunk Attack Range, an attack simulation lab, and Contentctl, a tool for building, testing, and packaging content for distribution.

FEATURES

ALTERNATIVES

Tool for deleting logs on Linux/Windows servers.

Free

A cloud-native SIEM platform that provides security analytics, intuitive workflow, and simplified incident response to help security teams defend against cyber threats.

Commercial

A pure Python parser for Windows Event Log files with access to File and Chunk headers, record templates, and event entries.

Free

A tool that collects and displays user activity and system events on a Windows system.

Free

Sysdig is a system visibility tool with native container support.

Free

Elastic is a search-powered AI company that enables users to find answers from all data in real-time at scale.

Commercial

IBM QRadar is a SIEM solution for real-time threat detection.

Free

A logging proxy tool created in response to the 'MongoDB Apocalypse', with Docker support.

Free
CyberSecTools logoCyberSecTools

Explore the largest curated directory of cybersecurity tools and resources to enhance your security practices. Find the right solution for your domain.

Copyright © 2024 - All rights reserved