Retour au classement

olafhartong/ThreatHunting

A Splunk app mapped to MITRE ATT&CK to guide your threat hunts

splunkmitre-attackthreat-huntingdfir
Croissance des étoiles
Étoiles
1.2k
Forks
179
Croissance hebdomadaire
Issues
22
5001k
nov. 2018mai 2021déc. 2023juil. 2026
README

Logo

ThreatHunting | A Splunk app mapped to MITRE ATT&CK to guide your threat hunts

license Maintenance GitHub last commit Arsenal Arsenal Twitter

This is a Splunk application containing several dashboards and over 130 reports that will facilitate initial hunting indicators to investigate.

You obviously need to be ingesting Sysmon data into Splunk, a good configuration can be found here

Note: This application is not a magic bullet, it will require tuning and real investigative work to be truly effective in your environment. Try to become best friends with your system administrators. They will be able to explain a lot of the initially discovered indicators.

Big credit goes out to MITRE for creating the ATT&CK framework!

Pull requests / issue tickets and new additions will be greatly appreciated!

Mitre ATT&CK

I strive to map all searches to the ATT&CK framework. A current ATT&CK navigator export of all linked configurations is found here and can be viewed here Mapping

Required actions after deployment

  • Follow all the steps on the About page in the app, make sure all requirements are met.
  • Make sure the threathunting index is present on your indexers
  • Edit the macro's to suit your environment > https://YOURSPLUNK/en-US/manager/ThreatHunting/admin/macros (make sure the sourcetype is correct)
  • The app is shipped without whitelist lookup files, you'll need to create them yourself. This is so you won't accidentally overwrite them on an upgrade of the app.
  • Install the lookup csv's or create them yourself, empty csv's are here

A step by step guide kindly written by Kirtar Oza can be found here

Usage

A more detailed explanation of all functions can be found here or in this blog post

Dépôts similaires
openobserve/openobserve

Open source observability platform for logs, metrics, traces, frontend monitoring, pipelines and LLM observability. A sophisticated, simple and highly performant alternative to Datadog, Splunk, and Elasticsearch with 140x lower storage costs and single binary deployment.

TypeScriptnpmGNU Affero General Public License v3.0logsmetrics
openobserve.ai
20.3k952
SigmaHQ/sigma

Main Sigma Rule Repository

PythonPyPIOthersecuritymonitoring
sigmahq.io
10.8k2.7k
graphistry/pygraphistry

PyGraphistry is a Python library to quickly load, shape, embed, and explore big graphs with the GPU-accelerated Graphistry visual graph analyzer

PythonPyPIBSD 3-Clause "New" or "Revised" Licensegraphvisualization
2.5k231
siglens/siglens

100x Efficient Log Management than Splunk :rocket: Reduce your observability cost by 90%

GoGo ModulesApache License 2.0distributed-tracinggo
siglens.com
1.8k332
splunk/security_content

Splunk Security Content

PythonPyPIApache License 2.0splunkdetection
research.splunk.com
1.7k477
orlangure/gnomock

Test your code without writing mocks with ephemeral Docker containers 📦 Setup popular services with just a couple lines of code ⏱️ No bash, no yaml, only code 💻

GoGo ModulesMIT Licensegogolang
1.5k79
infosecB/awesome-detection-engineering

Detection Engineering is a tactical function of a cybersecurity defense program that involves the design, implementation, and operation of detective controls with the goal of proactively identifying malicious or unauthorized activity before it negatively impacts an individual or an organization.

Creative Commons Zero v1.0 Universaldetection-engineeringsplunk
1.3k135