May 20, 2026
RST Threat Feed App for Splunk
Detect threats faster with RST Threat Feed’s automated IOC management. Query by score, threat name, or threat category to enable efficient detection and threat hunting.Built by Yury SergeevSplunk Enterprise, Splunk Cloud
Platform Version: 10.5, 10.4, 10.3, 10.2, 10.1, 10.0, 9.4, 9.3, 9.2, 9.1, 9.0
CIM Version: 8.x, 6.x, 5.x
Log in to rate this app
#48 in Threat Intel
This app provides integration of Splunk with RST Threat Feed. It is shipped with health reports and dashboards and also includes sample detection rules. This threat intelligence feed covers multiple categories of indicators including Phishing, Web Attacks, C2 Servers, Botnet, Malware, TOR nodes, Scanning Hosts, Bad Bots, DDoS, Cryptomining, Spamming Hosts, Fraud and other types. It includes the following types of indicators: IP, Domain, URL, md5, sha1, sha256 Each indicator has an individual score calculated based on its actuality and risk: what type of the indicators it is, who is the reporter of the indicators, how many others are already aware of that indicator, was that indicator exposed previously and many other contributing factors. A trial key can be obtained from https://www.rstcloud.com/#free-trial
Log in to report this app listing.