Skip to content

Splunk Tools

A working collection of Splunk SPL searches, detections, and threat-hunting references I use for security monitoring and investigations.

Sections

Section What's Inside
SPL Searches Ready-to-adapt searches: detections, web and HTTP analysis, and investigation walkthroughs
Threat Hunting and IOCs Indicator categories to pivot on during a hunt or incident
Sysmon Installing Sysmon and getting its data into Splunk
Resources Threat intelligence apps, references, and tools

Using These Searches

  • Index names, sourcetypes, and field names in these searches reflect the data they were written against (including the public Boss of the SOC datasets). Adjust them to your environment's data model.
  • The Investigations pages are walkthroughs against the BOTS datasets, so they double as a way to practice the technique end to end.
  • This is a companion to my Blue Team Toolkit; the detection logic there is written in both SPL and KQL.

The source is on GitHub.