Skip to content

Resources

Threat Intelligence Apps

App Notes
Splunk ThreatHunting App ATT&CK-aligned hunting dashboards (resources)
Splunk Enterprise Security Splunk's SIEM; adding local intel, Sunburst detections
Splunk Security Essentials Free detection examples mapped to frameworks
Dragos ICS/OT threat intelligence

Splunk References

Windows Logging Cheat Sheets

Malware Archaeology maintains the Windows logging and ATT&CK cheat sheets (Logging, Advanced Logging, File/Registry Auditing, PowerShell, Sysmon, Splunk):

Online Tools

Tool Use
regex101 Build and test regex for rex
crontab.guru Cron expressions for scheduled searches
Mockaroo Generate fake test data
DomainTools Whois Domain and IP lookups
Ultimate Windows Security: Event Encyclopedia Windows event ID reference
MITRE ATT&CK Technique reference

Further Reading