mrpappagiorgio / threathunting-spl

Splunk code (SPL) useful for serious threat hunters.

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

threathunting-spl

This is a repository to store Splunk code (SPL) and prototypes useful for building rules (correlation searches) and queries to find and hunt for malicious activity.

About

Feel free to contribute and share your feedbak in case you find it useful. For more Splunk (and Security) related stuff also check the following :

About

Splunk code (SPL) useful for serious threat hunters.