May 3, 2024
Qintel QSentry Feed Add-on for Splunk
QSentry is a consumable feed of anonymization and threat actor IP addresses sourced from the Deep and DarkWeb and QIntel’s proprietary research. The IPs in the feed are associated with infrastructure actively utilized or abused by cyber criminals, including VPN/Proxy services and IP addresses linked to the malicious infrastructure of criminal and nation-state actors. With this integration, users can fetch a daily list of newly compiled indicators from QSentry’s collections.Built by Qintel IntegrationsSplunk Enterprise
Platform Version: 9.4, 9.3, 9.2, 9.1, 9.0
CIM Version: 5.x, 4.x, 3.x
Log in to rate this app
QSentry is a consumable feed of anonymization and threat actor IP addresses sourced from the Deep and DarkWeb and QIntel’s proprietary research. The IPs in the feed are associated with infrastructure actively utilized or abused by cyber criminals, including VPN/Proxy services and IP addresses linked to the malicious infrastructure of criminal and nation-state actors. With this integration, users can fetch a daily list of newly compiled indicators from QSentry’s collections. The Qintel QSentry Technology Add-on allows you to ingest the Qintel QSentry feed into a key value store in Splunk so that your logs data can be enriched automatically or at search time.
Log in to report this app listing.