🔍 SPL Threat Hunt Library
Splunk SPL Threat Hunting Queries
Ready-to-run SPL threat hunting queries for proactive investigation in Splunk SIEM. Mapped to MITRE ATT&CK and CERT-In incident categories.
36
Hunt Queries
7
Categories
12
MITRE Tactics
100%
SPL Native
How to use: Copy any query into Splunk Enterprise or Splunk Cloud → Search & Reporting. Set your time range (start with last 7 days for hunting). Adjust
index= values to match your Splunk index names. Replace placeholder values (domain names, IP ranges, account patterns) with your environment specifics before running.
Showing 0 of 36 hunting queries