Skip to main content
Warning
This app is archived. App archiving documentation
ThreatBook Cloud API app icon

ThreatBook Cloud API

The Splunk Threat Intelligence App streamlines security operations by automating the enrichment and response of threat intelligence within Splunk. It extracts and de-duplicates key indicators of compromise (IOCs)—including IP addresses, domains, and file hashes—from raw security logs and submits them to the threatbook.io API for threat verdiction. Malicious IOCs are enriched with detailed intelligence and stored in a user-defined target index, while a dedicated dashboard provides clear visibility into threats across the environment. Analysts can correlate enriched intelligence with raw logs for deeper investigation and leverage the data to drive automated response actions, such as blocking malicious entities. Built-in de-duplication and API-aware processing ensure efficiency and optimized performance.Built by Hui Wang
splunk product badge

Default Version 1.0.4

January 28, 2026

Compatibility

Splunk Enterprise

Platform Version: 9.4, 9.3, 9.2, 9.1, 9.0

CIM Version: 6.x

Rating
0
(0)

Log in to rate this app

Support
Archived App

The Splunk Threat Intelligence App streamlines security operations by automating the enrichment and response of threat intelligence within Splunk. It extracts and de-duplicates key indicators of compromise (IOCs)—including IP addresses, domains, and file hashes—from raw security logs and submits them to the threatbook.io API for threat verdiction. Malicious IOCs are enriched with detailed intelligence and stored in a user-defined target index, while a dedicated dashboard provides clear visibility into threats across the environment. Analysts can correlate enriched intelligence with raw logs for deeper investigation and leverage the data to drive automated response actions, such as blocking malicious entities. Built-in de-duplication and API-aware processing ensure efficiency and optimized performance.