Skip to main content
DarkStrata Threat Intelligence Add-on for Splunk app icon

DarkStrata Threat Intelligence Add-on for Splunk

Ingest DarkStrata credential-exposure threat intelligence into Splunk and Enterprise Security. Detect compromised credentials, infostealer infections and third-party exposure in real time, with CIM-compliant data, ES correlation searches and adaptive-response actions.Built by Dave Bullough
splunk product badge

Default Version 1.1.2

July 31, 2026

Compatibility

Splunk Enterprise, Splunk Cloud

Platform Version: 10.5, 10.4, 10.3, 10.2, 10.1, 10.0, 9.4, 9.3, 9.2, 9.1, 9.0

CIM Version: 8.x, 6.x, 5.x, 4.x

Rating
0
(0)

Log in to rate this app

Support
Developer Supported

DarkStrata Threat Intelligence Add-on for Splunk brings DarkStrata's credential-exposure intelligence directly into Splunk and Splunk Enterprise Security (ES), so your SOC can detect and respond to compromised credentials before they're used against you. DarkStrata continuously monitors breach data, infostealer/malware logs and third-party exposure for credentials tied to your organisation. This add-on pulls that intelligence into Splunk as structured, CIM-compliant events - ready for correlation, alerting, dashboards and automated response. Use it to: - Detect compromised credentials before they're used maliciously - Identify malware infections through infostealer credential detection - Monitor third-party risk by tracking corporate credentials exposed on external sites - Automate incident response via ES notable events, correlation searches and adaptive-response actions - Enrich threat hunting with credential-exposure context Data is delivered in STIX 2.1 format and mapped to the Authentication and Threat Intelligence CIM data models, so it works out of the box with Enterprise Security's threat-intelligence framework. Collection is incremental and checkpoint-based - only new intelligence is fetched on each run - with configurable batching, rate limiting and connection pooling for predictable performance.