Skip to main content
Mandiant Threat Intelligence app icon

Mandiant Threat Intelligence

Enrich your data with Threat Intelligence from Mandiant. The modular input included in this application collects context-rich indicators of compromise from the Mandiant API and ingests them locally into a Splunk index where they can be queried and used to provide additional context to security telemetry through Splunk lookups.Built by Adam Levy
splunk product badge

Default Version 1.1.1

June 1, 2026

Compatibility

Splunk Enterprise, Splunk Cloud

Platform Version: 10.5, 10.4, 10.3, 10.2, 10.1, 10.0, 9.4, 9.3

Rating
0
(0)

Log in to rate this app

Support
Developer Supported

Enrich your data with Threat Intelligence from Mandiant. The modular input included in this application collects context-rich indicators of compromise from the Mandiant API and ingests them locally into a Splunk index where they can be queried and used to provide additional context to security telemetry through Splunk lookups.