Splunk Indicator Hunting

This playbook queries Splunk for indicators such as file hashes, IP addresses, domains, or urls. It outputs detected users, ip addresses, and hostnames related to the indicators.

Pack
SplunkPy
Tasks
77

Inputs

Outputs

Commands used