Malware intelligence sources
Splunk Intelligence Management supports the following malware sandboxes as intelligence sources:
- Cisco AMP Threat Grid Analysis
- Joe Sandbox
Cisco AMP Threat Grid Analysis
Cisco Threat Grid Analysis combines advanced sandboxing with threat intelligence into one unified solution to protect organizations from malware.
- Source Type: Premium Intel
- Update Type: Feed-based
- Update Frequency: 15 minutes
- Parser: Yes
- Time to Install: 10 minutes
Observables Supported
- IP
- Domain
- URL (Domains are extracted from URL)
- SHA256
- SHA1
- MD5
- REGISTRY_KEY
Requirements
- A license for Cisco Threat Grid.
- Access to the Threat Grid portal to generate an API key.
- Splunk Intelligence Management Admin rights are required to activate this premium intelligence source.
Getting Started
- Log into the Splunk Intelligence Management Web App.
- Click the Marketplace icon on the left side icon list.
- Choose Premium Intel.
- Click Subscribe on the Cisco Threat Grid Indicator Query box.
- Enter your Cisco API key and click Save Credentials & Request Subscription.
Splunk Intelligence Management will validate the integration within 48 hours and send an email when the integration has been enabled.
Joe Sandbox
Joe Sandbox executes files and URLs fully automated in a controlled environment and monitors the behavior of applications and the operating system for suspicious activities and compiles it in an extensive analysis report.
- Source Type: Premium Intel
- Update Type: Feed-based
- Update Frequency: 15 minutes
- Parser: Yes
- Time to Install: 10 minutes
Observables Supported
- All Observables supported by Splunk Intelligence Management
Requirements
- Registered customer of Joe Security
- Joe Sandbox Cloud API key
- Splunk Intelligence Management Admin rights are required to activate this Premium Intelligence feed.
Getting Started
- Log into the Splunk Intelligence Management Web App.
- Click the Marketplace icon on the left side navigation bar.
- Choose Premium Intel.
- Click Subscribe in the Joe Sandbox icon.
- Enter your Joe Sandbox API key, then click Save Credentials & Request Subscription.
Splunk Intelligence Management will validate the integration within 48 hours and send an email when the integration has been enabled.
Other intelligence sources | Configure the indicator prioritization intelligence workflow |
This documentation applies to the following versions of Splunk® Intelligence Management (Legacy): current
Feedback submitted, thanks!