Default Version 1.2.0
November 16, 2022
November 16, 2022
Splunk Enterprise
Platform Version: 9.4, 9.3, 9.2, 9.1, 9.0
CIM Version: 5.x, 4.x
Log in to rate this app
This add-on integrates Cyber Triage to allow you to collect and analyze endpoint data using Cyber Triage. It will send an agentless collection tool to the remote endpoint, retrieve volatile and file system data, and analyze it for evidence of an intrusion. You can then import the Cyber Triage result back into splunk.
Log in to report this app listing.