Building Threat Intelligence Enrichment In Splunk

Build automated IOC enrichment pipelines in Splunk Enterprise Security by ingesting threat feeds into KV Store collections and correlating them against security events via lookup tables, modular inputs, and the Threat Intelligence Framework. Use when wiring threat intel into Splunk correlation searches to flag IOC matches and cut SOC triage time.

gabrielmoreira Updated 17 repo stars

File contents

gabrielmoreira/agent-skills-mirror/tree/main/mirrors/repos/mukul975@Anthropic-Cybersecurity-Skills/skills/building-threat-intelligence-enrichment-in-splunk commit cc177aa6a8

Frequently asked questions

npx skillmds@latest add gabrielmoreira/building-threat-intelligence-enrichment-in-splunk