App / Add-on | Download | Notes |
---|---|---|
Splunk Enterprise / Free | http://www.splunk.com | |
Haversine | https://splunkbase.splunk.com/app/936/ | If the Haversine application can't be uploaded through the Splunk UI, then extract the file contents to $SPLUNK_HOME/etc/apps |
ASN Lookup Generator | https://splunkbase.splunk.com/app/3531/ | Requires the asngen command to be executed to populate the asn lookup |
aeae995 / dfur-splunk-app Goto Github PK
View Code? Open in Web Editor NEWThis project forked from mandiant/dfur-splunk-app
The "DFUR" Splunk application and data that was presented at the 2020 SANS DFIR Summit.
License: MIT License