Resources¶
Threat Intelligence Apps¶
| App | Notes |
|---|---|
| Splunk ThreatHunting App | ATT&CK-aligned hunting dashboards (resources) |
| Splunk Enterprise Security | Splunk's SIEM; adding local intel, Sunburst detections |
| Splunk Security Essentials | Free detection examples mapped to frameworks |
| Dragos | ICS/OT threat intelligence |
Splunk References¶
Windows Logging Cheat Sheets¶
Malware Archaeology maintains the Windows logging and ATT&CK cheat sheets (Logging, Advanced Logging, File/Registry Auditing, PowerShell, Sysmon, Splunk):
Online Tools¶
| Tool | Use |
|---|---|
| regex101 | Build and test regex for rex |
| crontab.guru | Cron expressions for scheduled searches |
| Mockaroo | Generate fake test data |
| DomainTools Whois | Domain and IP lookups |
| Ultimate Windows Security: Event Encyclopedia | Windows event ID reference |
| MITRE ATT&CK | Technique reference |