apger / SA-RBA
Risk Based Alerting Supporting Add-On (SA) for Splunk
☆45Updated 3 years ago
Related projects ⓘ
Alternatives and complementary repositories for SA-RBA
- Data validator agains Splunk Common Information Model (CIM)☆75Updated 7 months ago
- scripts to configure the Splunk Universal Forwarder in a locked down state☆40Updated 5 years ago
- Scripted inputs designed to address common use-cases in forwarder misconfigurations in a Splunk deployment☆33Updated 2 months ago
- TrackMe - Data tracking system for Splunk admins☆49Updated last year
- A Splunk app to use MISP in background☆109Updated 2 weeks ago
- Sunburst IOCs for Splunk Ingest☆18Updated 3 years ago
- Splunk (Other Splunk scripts which do not fit into the SplunkAdmins application)☆38Updated 2 months ago
- ☆118Updated 2 years ago
- A repository for generalized splunk code, dashboards, resources and suggestions/recommendations.☆30Updated last year
- ☆55Updated 2 years ago
- Converts Sigma detection rules to a Splunk alert configuration.☆107Updated 4 years ago
- Searches and dashboards to assist with optimising concurrency settings☆30Updated 2 years ago
- Splunk Remote Work Insights - Executive Dashboard☆40Updated 4 years ago
- ☆69Updated 4 months ago
- Mark Baggett's (@MarkBaggett - GSE #15, SANS SEC573 Author) tool for detecting randomness using NLP techniques rather than pure entropy c…☆123Updated 2 years ago
- Splunk Content Control Tool☆91Updated this week
- A Splunk app with saved reports derived from Sigma rules☆72Updated 6 years ago
- RBA is Splunk's method to aggregate low-fidelity security events as interesting observations tagged with security metadata to create high…☆46Updated this week
- Splunk spec files version history☆32Updated last month
- Pulls IOCs from MISP and adds the to reference sets in QRadar☆33Updated last year
- Phantom Apps Repo☆82Updated 3 years ago
- Sysmon Splunk App☆46Updated 6 years ago
- ☆14Updated 8 years ago
- scripts using splunk application lookup-editor endpoint. Download, upload and update splunk lookups content☆28Updated 4 months ago
- Files and Folders for BSides Splunk 2021☆22Updated 3 years ago
- Splunk Admins application to assist with troubleshooting Splunk enterprise installations☆90Updated 2 weeks ago
- A Splunk App containing Sigma detection rules, which can be updated from a Git repository.☆107Updated 4 years ago