icon/x Created with Sketch.

Splunk Cookie Policy

We use our own and third-party cookies to provide you with a great online experience. We also use these cookies to improve our products and services, support our marketing campaigns, and advertise to you on our website and other websites. Some cookies may continue to collect information after you have left our website. Learn more (including how to update your settings) here.
Accept Cookie Policy

Accept License Agreements

This app is provided by a third party and your right to use the app is in accordance with the license provided by that third-party licensor. Splunk is not responsible for any third-party apps and does not provide any warranty or support. If you have any questions, complaints or claims with respect to this app, please contact the licensor directly.

Thank You

Downloading MITRE ATTACK App for Splunk
SHA256 checksum (mitre-attack-app-for-splunk_110.tgz) f232278bc5c87b3b025357d0fa693f9aafbdb8437ce8a7a950e7199dbd303d00 SHA256 checksum (mitre-attack-app-for-splunk_100.tgz) 2c934d0ff001ffeb9f591c27fb4da196cf823ed752f50ca9be98d2f3a5ac1f95
To install your download
For instructions specific to your download, click the Details tab after closing this window.

Flag As Inappropriate

MITRE ATTACK App for Splunk

Splunk AppInspect Passed
Overview
Details
This application provides compliance and triage dashboards for MITRE ATT&CK Framework that are fully integrated with Splunk Enterprise Security (https://splunkbase.splunk.com/app/263/) and Splunk ES Content Update (https://splunkbase.splunk.com/app/3449/) with drill-down capabilities.

MITRE ATT&CK App for Splunk::DA-ESS-MitreContent

Overview

This application provides compliance and triage dashboards for MITRE ATT&CK Framework that are fully integrated with Splunk Enterprise Security(https://splunkbase.splunk.com/app/263/) and Splunk ES Content Update (https://splunkbase.splunk.com/app/3449/) with drill-down capabilities.

Prerequisites:

Splunk Enterprise 7.x or above
Splunk Enterprise Security 5.2 or above
Splunk ES Content Update 1.0.40 or above

Setup Instructions

Upon initial installation you may need to manually run "Mitre Compliance Lookup Gen" saved search/report in order to populate the lookup table.

Saved Searches

This application comes with a predefined saved search (Mitre Compliance Lookup Gen) which checks currently enabled correlation rules via analytic stories and creates a lookup file to match them to MITRE ATT&CK Framework techniques for compliance. By default this search is scheduled to run at midnight everyday to populate the lookup table.

Release Notes:

Version 1.0.0
- Initial version for Splunkbase
- Test to run on 7.3.0 and ES App 5.3

Version 1.1.0
- Bug fixes & typos
- Added descriptions to dashboards
- Added improvements for initial lookup generator

Support

Contact information for reporting an issue: development@seynur.com

Release Notes

Version 1.1.0
Aug. 6, 2019

Bug fixes & typos
Added descriptions to dashboards
Added improvements for initial lookup generator

Version 1.0.0
July 25, 2019

Initial release

132
Installs
308
Downloads
Share Subscribe LOGIN TO DOWNLOAD

Subscribe Share

AppInspect Tooling

Splunk AppInspect evaluates Splunk apps against a set of Splunk-defined criteria to assess the validity and security of an app package and components.

Are you a developer?

As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 50GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps and add-ons from Splunk, our partners and our community. Find an app or add-on for most any data source and user need, or simply create your own with help from our developer portal.

Follow Us:
© 2005-2019 Splunk Inc. All rights reserved.
Splunk®, Splunk>®, Listen to Your Data®, The Engine for Machine Data®, Hunk®, Splunk Cloud™, Splunk Light™, SPL™ and Splunk MINT™ are trademarks and registered trademarks of Splunk Inc. in the United States and other countries. All other brand names, product names, or trademarks belong to their respective owners.