inspired's Stars
jlevy/the-art-of-command-line
Master the command line, in one page
microsoft/Microsoft-365-Defender-Hunting-Queries
Sample queries for Advanced hunting in Microsoft 365 Defender
burghardt/easy-wg-quick
Creates Wireguard configuration for hub and peers with ease
correlatedsecurity/Awesome-SOAR
A curated Cyber "Security Orchestration, Automation and Response (SOAR)" awesome list.
netsampler/goflow2
High performance sFlow/IPFIX/NetFlow Collector
splunk/splunk-ansible
Ansible playbooks for configuring and managing Splunk Enterprise and Universal Forwarder deployments
mthcht/Purpleteam
Purpleteam scripts simulation & Detection - trigger events for SOC detections
nocproject/noc
Official read only mirror for
jymcheong/SysmonResources
Consolidation of various resources related to Microsoft Sysmon & sample data/log
splunk/rba
RBA is Splunk's method to aggregate low-fidelity security events as interesting observations tagged with security metadata to create high-fidelity, low-volume alerts.
MattUebel/splunk_UF_hardening
scripts to configure the Splunk Universal Forwarder in a locked down state
gjanders/Splunk
Splunk (Other Splunk scripts which do not fit into the SplunkAdmins application)
klockcykel/godiode
Golang PoC software for reliable file transfers over a data diode. DIY gigabit data diode hardware instructions
splunk/azure-functions-splunk
Azure Functions for getting data in to Splunk
Exporttool/exporttool
This is a python script that can be run on each Splunk Indexer for the purpose of exporting historical bucket data (raw events + metadata) at scale by balancing the work across multiple CPUs then forwarding to Cribl.
tmuth/splunk-export
hovu96/splunk_as_a_service_app
A Splunk app to deploy, manage and monitor Splunk environments in remote Kubernetes clusters
jorritfolmer/TA-ad-assets-identities
Dump all users, groups and computers from an Active Directory domain into an asset and identities lookup usable by Splunk Enterprise Security.
Sens-Consulting/TA-microsoft-365-defender-threat-vulnerability-add-on
doksu/TA-statemachine
State Machine Technology Add-On for Splunk
hobbes3/meraki
mnatkin-splunk/SOAR_Autobahn
murchisd/splunk_rerun_app
Repository for Splunk Rerun Application
bcusick65/splunk_risk_visuals
Visualization repo for Splunk and ES
stressboi/TA-hrs
bentleymi/ta-ms_loganalytics
TA-ms-loganalytics
jmaas/splunk-ta-journald
Simple TA to enable on-boarding of journald events into Splunk.
lucas-alados/netflow_sample_dashboards
Netflow sample dashboards app for Splunk
SILJAEUROPA/Splunk-Delay-Detector
Detects Delays in recently ran Splunk saved searches
thilles/splunk_admin_views