Skip to main content
DFIR Dashboards by DFIRVault app icon

DFIR Dashboards by DFIRVault

A comprehensive DFIR and threat hunting dashboard for Windows environments that performs large-scale IOC detection, MITRE ATT&CK mapping, risk-based alerting, attack path inference, entity behavior analysis, and investigation workflow support — all natively inside Splunk.Built by Jacob Wilson
splunk product badge

Default Version 1.0.0

January 13, 2026

Compatibility

Splunk Enterprise, Splunk Cloud

Platform Version: 10.5, 10.4, 10.3, 10.2, 10.1, 10.0, 9.4, 9.3, 9.2, 9.1, 9.0

CIM Version: 6.x, 5.x, 4.x, 3.x

Rating
0
(0)

Log in to rate this app

Support
Developer Supported

DFIRVault is an advanced, analyst-driven threat detection and investigation platform built entirely in Splunk. It combines detection engineering, behavior analytics, and investigation workflows into a single operational view for security operations and digital forensics teams. The app ingests Windows security, Sysmon, PowerShell, and endpoint telemetry and automatically enriches events with MITRE ATT&CK techniques, risk scores, kill-chain stages, adversary emulation context, and entity relationships. DFIRVault goes beyond traditional dashboards by incorporating: - Risk-based alerting (RBA) - Peer group and golden image baselining - Attack path and blast radius inference - Entity-centric timelines - MITRE coverage analysis and detection gap identification - Integrated investigation notebooking This allows analysts to move seamlessly from detection → triage → scoping → investigation → documentation, all without leaving Splunk. DFIRVault is designed to be modular, transparent, and extensible — making it suitable for blue teams, DFIR responders, threat hunters, and detection engineers alike.