Files
splunk-security_content/docs/index.markdown
T
2021-12-15 17:42:47 -06:00

3.7 KiB

layout, header, excerpt, feature_row
layout header excerpt feature_row
splash
overlay_color overlay_filter overlay_image actions
#000 0.5 /static/splunk_banner.png
label url
Download https://splunkbase.splunk.com/app/3449/
Get the latest **FREE** Enterprise Security Content Update (ESCU) App with **696** detections for Splunk.
image_path alt title excerpt url btn_class btn_label
/static/feature_detection.png customizable Detections See all **696** Splunk Analytics built to find evil 😈. /detections btn--primary Explore
image_path alt title excerpt url btn_class btn_label
/static/feature_stories.png fully responsive Analytic Stories See all **107** use cases, 📦 of detections built to address a threat. /stories btn--primary Explore
image_path alt title excerpt url btn_class btn_label
/static/feature_playbooks.png 100% free Playbooks See all **23** sets of steps 🐾 to automatically response to a threat. /playbooks btn--primary Explore

{% include feature_row %}

Welcome to Splunk Security Content

This project gives you access to our repository of Analytic Stories that are security guides which provide background on TTPs, mapped to the MITRE framework, the Lockheed Martin Kill Chain, and CIS controls. They include Splunk searches, machine-learning algorithms, and Splunk Phantom playbooks (where available)—all designed to work together to detect, investigate, and respond to threats.

Try in Splunk Security Cloud{: .btn .btn--success}

Detection Coverage 🗺

Below is a snapshot in time of what technique we currently have some detection coverage for. The darker the shade of blue the more detections we have for this particular technique.

View Our Content 🔎

If you prefer working with the command line, check out our API:

curl -s https://content.splunkresearch.com | jq
{
  "hello": "welcome to Splunks Research security content api"
}

Test Out The Detections 🏗

Replay any detection dataset to a Splunk Enterprise Server by using our replay.py tool or the UI. Alternatively use:

The Splunk Attack Range which allows you to create a isolated environment to launch attacks and test/build detections.

Questions? 📞

Please use the GitHub issue tracker to submit bugs or request features.

If you have questions or need support, you can:

Contribute Content 🥰

If you want to help the rest of the security community by sharing your own detections, see our contributor guide for more information on how to get involved!