Threat-Hunting-With-Splunk

Threat detection queries

Provides Splunk queries to detect vulnerability exploitation attempts and subsequent compromise, including threat hunting for MITRE ATT&CK TTPs

Awesome Splunk SPL hunt queries that can be used to detect the latest vulnerability exploitation attempts & subsequent compromise

GitHub

58 stars
3 watching
8 forks
last commit: over 2 years ago
Linked from 1 awesome list

arcanedoorbpfdoorbpfdoor-detectioncve-2024-20353cve-2024-20359detectiondetection-engineeringesxi-malwareesxi-ransomwareline-dancerline-runnermitre-attackrtm-lockersplunktext4shellvulnerability

Backlinks from these awesome lists:

Related projects:

RepositoryDescriptionStars
inodee/threathunting-splProvides Splunk code and prototypes for building rules and queries to detect malicious activity268
olafhartong/threathuntingA Splunk application designed to guide threat hunts by mapping investigations to the MITRE ATT&CK framework1,141
sbousseaden/slidesCollection of resources and concepts for threat hunting and detection engineering.372
sapphirex00/threat-huntingA collection of threat intelligence resources and tools for analyzing APT malware257
sk4la/plastA modular threat-hunting tool framework for detecting indicators of compromise in incident-response operations.17
a3sal0n/cyberthreathuntingA collection of tools and resources for threat hunters to identify and respond to cyber threats.861
splunk/security_contentDelivers threat intelligence and detection capabilities to Splunk Enterprise Security1,319
gauravnarwani97/trishulAutomated vulnerability detection tool for web applications235
sbousseaden/pcap-attackA collection of PCAP captures used to demonstrate post-exploitation techniques and threat hunting tactics.346
bugcrowd/huntAn extension for Burp Suite that provides a structured approach to identifying and testing common vulnerability parameters.2,192
xnl-h4ck3r/gap-burp-extensionAn extension for Burp Suite that identifies potential security vulnerabilities in web applications by analyzing endpoints, parameters, and generating custom target wordlists.1,278
secdec/attack-surface-detector-burpIdentifies web app endpoints and parameters to help detect vulnerabilities98
mdecrevoisier/splunk-input-windows-baselineProvides an advanced Splunk configuration for collecting Windows log data relevant to threat detection, incident response, and forensic analysis.85
initroot/burpsqltruncsannerAutomatically scans endpoints for potential SQL Truncation vulnerabilities by fuzzing request parameters62
splunk/botsv2A comprehensive security dataset and CTF platform for analysis and training of information security professionals.358