Welcome to the new Splunkbase! To return to the old Splunkbase, click here.
APT Falconer app icon

APT Falconer

Security teams often struggle to turn detection logic into something that is easy to explore, manage, and operationalize inside Splunk. Detection content is frequently scattered across searches, lookups, and dashboards, making it difficult to understand coverage, assess gaps, and evolve signals over time.

Built by
splunk product badge
screenshot
screenshot
screenshot
screenshot
screenshot

Latest Version 3.0.3
December 20, 2025
Compatibility
Splunk Enterprise, Splunk Cloud
Platform Version: 10.1, 10.0, 9.4, 9.3, 9.2, 9.1, 9.0
CIM Version: 6.x
Rating

0

(0)

Log in to rate this app
Support
APT Falconer support icon
Developer Supported app
Ranking

#50

in Investigative
Security teams often struggle to turn detection logic into something that is easy to explore, manage, and operationalize inside Splunk. Detection content is frequently scattered across searches, lookups, and dashboards, making it difficult to understand coverage, assess gaps, and evolve signals over time. APT Falconer provides a centralized way to work with detection signals in Splunk. It allows analysts and engineers to explore signal definitions, view related context, and understand how signals map to attacker behavior. By organizing signals in a structured and searchable way, APT Falconer helps teams move beyond ad-hoc searches toward more intentional and repeatable detection engineering. The app is designed to be lightweight and easy to evaluate. It installs quickly, requires minimal configuration, and works with standard Splunk Enterprise deployments. Dashboards and views are optimized to remain usable even when signal data is incomplete or evolving, allowing teams to safely explore and iterate. APT Falconer is well suited for teams looking to better understand their detection posture, experiment with new detection ideas, or establish a foundation for managing detection content at scale within Splunk.

Categories

Investigative, Security, Fraud & Compliance

Created By

Splunk Works

Type

app

Downloads

426

Resources

Log in to report this app listing