Default Version 1.0.15
January 2, 2026
January 2, 2026
Splunk Enterprise, Splunk Cloud
Platform Version: 10.1, 10.0, 9.4, 9.3, 9.2, 9.1, 9.0
CIM Version: 6.x, 5.x
Log in to rate this app
The Ransomware Add-on for Splunk integrates ransomware-related threat intelligence and incident data into your Splunk environment. This add-on leverages Python scripts to collect, parse, and organize data such as victim details, indicators of compromise (IOCs), ransomware notes, negotiation information, and YARA rules. It provides enhanced visibility into ransomware activities and enables efficient monitoring, alerting, and analysis within your Splunk ecosystem
Log in to report this app listing.