chan2git / splunk-botsLinks
This repository is dedicated to hosting personal comprehensive walkthrough solutions for Splunk's Boss of the SOC (BOTS) CTF-style labs. To be eventually updated with all BOTS events.
☆10Updated last year
Alternatives and similar repositories for splunk-bots
Users that are interested in splunk-bots are comparing it to the libraries listed below
Sorting:
- This repository is a comprehensive collection of resources, documentation, apps, and add-ons related to Splunk, a powerful data analytics…☆23Updated last week
- Shell script to download apps from Splunkbase☆23Updated 5 years ago
- Playbooks-On-Rails for Splunk (PORS)☆16Updated 6 months ago
- A list of Splunk queries that I've collected and used over time.☆87Updated 4 years ago
- Generate Indexes from SANS PDFs☆18Updated last year
- RBA is Splunk's method to aggregate low-fidelity security events as interesting observations tagged with security metadata to create high…☆61Updated this week
- Downloading Splunk, made easy through scripts☆24Updated 3 weeks ago
- Tools to automatically create a SANS index based off the course pdf files.☆110Updated 5 years ago
- Home for Splunk security datasets.☆125Updated 5 years ago
- Real-time Response scripts and schema☆119Updated last week
- Technical add-on for Splunk related to TheHive/Cortex from TheHive project☆53Updated last month
- Ansible playbooks for configuring and managing Splunk Cloud deployments with the Admin Config Service (ACS) API☆26Updated 3 weeks ago
- Config viewer and file editor for Splunk. Based on VSCode.☆31Updated 2 weeks ago
- This repository contains Splunk queries to hunt some anomalies☆44Updated 3 years ago
- WISKESS automates the Windows evidence processing for Incident Response investigations. Rust version.☆14Updated 2 weeks ago
- SPL cheatsheet for Splunk.☆24Updated 2 years ago
- Dettectinator - The Python library to your DeTT&CT YAML files.☆117Updated 6 months ago
- Splunk Boss of the SOC version 3 dataset.☆386Updated 5 years ago
- Awesome Splunk SPL hunt queries that can be used to detect the latest vulnerability exploitation attempts & subsequent compromise☆67Updated last year
- ☆45Updated 3 years ago
- Resources To Learn And Understand SIGMA Rules☆181Updated 2 years ago
- Run Velociraptor on Security Onion☆40Updated 3 years ago
- Splunk Content Control Tool☆120Updated last week
- Incident Response documents and tooling☆106Updated last month
- Learn Splunk by creating a lab instance in seconds. Includes Eventgen and Splunk's Machine Learning app!☆106Updated 4 months ago
- Scripted inputs designed to address common use-cases in forwarder misconfigurations in a Splunk deployment☆35Updated last year
- Collection of useful python scripts to interact with Splunk's API.☆15Updated 3 years ago
- Convert Sigma rules to Wazuh rules☆73Updated last month
- Re-play Adversarial Techniques☆45Updated 4 years ago
- Harness the power of Splunk for your investigations☆137Updated 2 weeks ago