App / Add-on | Download | Notes |
---|---|---|
Splunk Enterprise / Free | http://www.splunk.com | |
Haversine | https://splunkbase.splunk.com/app/936/ | If the Haversine application can't be uploaded through the Splunk UI, then extract the file contents to $SPLUNK_HOME/etc/apps |
ASN Lookup Generator | https://splunkbase.splunk.com/app/3531/ | Requires the asngen command to be executed to populate the asn lookup |
This repository has been archived by the owner on Sep 27, 2023. It is now read-only.
-
Notifications
You must be signed in to change notification settings - Fork 16
The "DFUR" Splunk application and data that was presented at the 2020 SANS DFIR Summit.
License
mandiant/DFUR-Splunk-App
Folders and files
Name | Name | Last commit message | Last commit date | |
---|---|---|---|---|
Repository files navigation
About
The "DFUR" Splunk application and data that was presented at the 2020 SANS DFIR Summit.
Topics
Resources
License
Stars
Watchers
Forks
Releases
No releases published
Packages 0
No packages published