Splunk Enterprise Security

Enterprise Security - Threat intel (General Discussion)

siddh01r
New Member

Hi All,

Just curious to see what threat intel Enterprise Security Specialists/administrators are using for their SIEM.
Out of the box you get plenty of options but most of them are false positives that cause a lot of noise.

So i am keen to see what paid/free threat intel other security specialists are using out there or have had great experience with?
some that give less false positives and are more accurate.

I know this a very general question but certainly will help me step towards creating a good business case to on board paid intels.

Thanks everyone.

0 Karma

jawaharas
Motivator

Recorded Future for Splunk provides real-time threat intelligence for SOC teams with a Splunk security solution. We tried in my team and it provides better threat intel.

https://www.recordedfuture.com/

0 Karma

jawaharas
Motivator

@siddh01r

Can you accept the answer if it's helped you? Thanks.

0 Karma
Get Updates on the Splunk Community!

Archived Metrics Now Available for APAC and EMEA realms

We’re excited to announce the launch of Archived Metrics in Splunk Infrastructure Monitoring for our customers ...

Detecting Remote Code Executions With the Splunk Threat Research Team

WATCH NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If exploited, ...

Enter the Dashboard Challenge and Watch the .conf24 Global Broadcast!

The Splunk Community Dashboard Challenge is still happening, and it's not too late to enter for the week of ...