Skip to main content
RansomLeak Add-on app icon

RansomLeak Add-on

Indexes RansomLeak security-awareness data as five CIM-normalised sourcetypes: phishing simulation outcomes, identity and admin audit events, per-enrollment training state, human risk score and programme metrics. Ships five Dashboard Studio views and an alert action that assigns training. Requires a RansomLeak tenant and API token.Built by Ransomleak OÜ, an official Splunk Partner
splunk product badge

Default Version 0.0.1

August 25, 2026

Compatibility

Splunk Enterprise, Splunk Cloud

Platform Version: 10.5, 10.4, 10.3, 10.2, 10.1, 10.0, 9.4, 9.3, 9.2, 9.1, 9.0

CIM Version: 8.x, 6.x

Rating
0
(0)

Log in to rate this app

Support
Developer Supported

RansomLeak is a security-awareness platform: phishing simulations, training assignments, and a per-user human risk score. This add-on brings that data into Splunk over the RansomLeak REST API. FIVE MODULAR INPUTS, each enabled and scheduled independently, so you index only what you need: - Phishing Events (ransomleak:phishing) - simulation outcomes: opens, clicks, attachment opens, credential submissions, OAuth grants and user reports. - Audit Events (ransomleak:audit) - identity and administrative events: sign-in, MFA, SCIM provisioning, password, role, licence, API-token and tenant-settings changes. - Training State (ransomleak:training) - per-enrollment assignment, due and completion state. - Risk Posture (ransomleak:risk) - human risk score and overdue-assignment counts, optionally faceted by team. - Programme Metrics (ransomleak:metrics) - tenant-level aggregates: training completion rate, phishing click and report rates, assignments by category. CIM: audit events are normalised to the Common Information Model and populate the Authentication and Change data models. ALSO INCLUDED: - Five Dashboard Studio views: Overview, Phishing, Identity, Training and Health. - A custom alert action, Assign RansomLeak training, which assigns an exercise to every user named in a triggering search's results. Assignment is idempotent, so a search firing repeatedly over an overlapping window will not re-assign the same person. Requires a RansomLeak tenant and an API token.