Observables supported by Splunk Intelligence Management
Splunk Intelligence Management identifies the following observables:
Entity | Type |
---|---|
REGISTRY KEY | Observable |
IPV6 | Observable |
IPV4 | Observable |
CIDR BLOCK | Observable |
URL | Observable |
MD5 | Observable |
SHA1 | Observable |
SHA256 | Observable |
BITCOIN ADDRESSES | Observable |
SOFTWARE | Observable |
EMAIL ADDRESS | Observable |
PHONE NUMBERS | Observable |
DOMAIN | Observable |
CVE (based on NIST's CVE standard) | Attribute |
MALWARE | Attribute |
THREAT ACTOR | Attribute |
MITRE ATT&CK | Attribute |
Your account owner must enable phone numbers based on enclaves because they are not extracted by default.
This documentation applies to the following versions of Splunk® Intelligence Management (Legacy): current
Feedback submitted, thanks!