Skip to main content
Binary Defense app icon

Binary Defense

Provides shared knowledge objects (macros, lookups, and field normalizations) that support Binary Defense's detection rules in customer Splunk environments.Built by Christopher Rex
splunk product badge

Default Version 0.1.2

October 2, 2026

Compatibility

Splunk Enterprise, Splunk Cloud

Platform Version: 10.6, 10.5, 10.4, 10.3, 10.2, 10.1, 10.0, 9.4, 9.3, 9.2, 9.1, 9.0

Rating
0
(0)

Log in to rate this app

Support
Developer Supported

The Binary Defense app provides a centralized repository of knowledge objects that support Binary Defense's detection rules running in customer Splunk environments. This foundation app contains macros, lookups, and field normalizations that are shared across all Binary Defense detections deployed in the environment. The knowledge objects are configured with global sharing, making them accessible to correlation searches in any app, including Splunk Enterprise Security. The app serves as a prerequisite component for Binary Defense's security content, ensuring consistent data normalization and lookup functionality across all detection rules. It includes an Overview dashboard for monitoring the app's operational status.