Jump to: 🔥 Challenge News ⚡ Intel 🔬 Research Labs 📡 All News →
🔍 SPL Threat Hunt Library

Splunk SPL Threat Hunting Queries

Ready-to-run SPL threat hunting queries for proactive investigation in Splunk SIEM. Mapped to MITRE ATT&CK and CERT-In incident categories.

36
Hunt Queries
7
Categories
12
MITRE Tactics
100%
SPL Native
How to use: Copy any query into Splunk Enterprise or Splunk Cloud → Search & Reporting. Set your time range (start with last 7 days for hunting). Adjust index= values to match your Splunk index names. Replace placeholder values (domain names, IP ranges, account patterns) with your environment specifics before running.
Showing 0 of 36 hunting queries