Skip to content

Framework that sits on top of Splunk Enterprise Security to do auto-mitigation

Notifications You must be signed in to change notification settings

josehelps/Splunk-Mitigation-Framework

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

21 Commits
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Splunk Mitigation Framework

TODOs

  • setup.xml
  • documentation
  • error handling for the endpoint component

Presentation Content

Slides

Demo Video

Installation

Primariy package is the SA-Mitigation which contains a setup function with instructions on what to configure to get the framework setup.

SA-Mitigation (Search Head Component)

Contains all the search logic and the custom commands to take action.

Search Architecture

search_arch

Installation Instructions

coming soon...

SA--Mitigator-Endpoint (Endpoint Component)

Endpoing component architecture

search_arch

Installation Instructions

comin soon...

About

Framework that sits on top of Splunk Enterprise Security to do auto-mitigation

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Languages