Splunk Threat Hunting

Use when proactively hunting for threats in Splunk that existing alerts didn't catch — forming a hypothesis, exploring data for anomalies, looking for lateral movement, beaconing, living-off-the-land, persistence, or suspicious patterns, and turning findings into detections. Distinct from incident investigation (no known alert) and from writing detections (hunting discovers what to detect).

zap-coding-agent Updated

File contents

zap-coding-agent/awesome-skills/tree/main/splunk-threat-hunting commit a596ef60c0

Frequently asked questions

npx skillmds@latest add zap-coding-agent/splunk-threat-hunting