Skip to main content
PhishIQ Plus app icon

PhishIQ Plus

URL phishing enrichment for Splunk with API-based risk scoring, caching, reliability controls, and SOC dashboards; built for enterprise workflows including Microsoft Sentinel and Microsoft security services.Built by NTrigo LTD
splunk product badge

Default Version 1.1.2

April 24, 2026

Compatibility

Splunk Enterprise, Splunk Cloud

Platform Version: 10.5, 10.4, 10.3, 10.2

Rating
0
(0)

Log in to rate this app

Support
Developer Supported

PhishIQPlus Technical for Splunk enriches URL telemetry in Splunk with phishing risk intelligence from the PhishIQPlus API. The app helps SOC teams prioritize investigations by adding prediction, confidence, risk level, source, cache status, and analysis metadata to URL-related events. It supports both dynamic enrichment from live Splunk searches and controlled batch processing, with built-in retry logic, circuit breaker protection, caching, and internal telemetry dashboards for operational visibility. This app is designed for enterprise security operations, including environments that integrate with Microsoft Sentinel and Microsoft security services, to provide consistent URL risk context across detection and response workflows.