














Feedly Threat Intelligence now finds Splunk Hunting Queries published across the open web, extracts them from the article, and makes them easy to import into your own tooling.
Create an AI Feed that pairs the new AI Model with your intelligence requirements to continuously collect relevant articles and reports containing Splunk Hunting Queries from 5,000 vetted CTI sources and repositories.
In addition to Splunk Hunting Queries, Feedly Threat Intelligence also identifies Suricata, Sigma, YARA, Snort rules, and KQL-based Hunting Queries for Microsoft Defender and Sentinel across open source reporting, covering network traffic inspection, file and malware matching, and log-based detection.
In case you need to convert your detection rule into Splunk SPL, we’ve put together a free prompt on our CTI Prompt Library Volume 2 that does this for you.
Splunk hunting queries are just the start. Add any of the detection rule/hunting query AI Models to your AI Feed and automatically collect relevant Suricata, Sigma, YARA, Snort, Suricata, and KQL queries as they surface across open source reporting.

A Splunk Hunting Query is a search, written in Splunk's Search Processing Language (SPL), that tells Splunk what to look for across your ingested log and event data. Each query defines the data sources to search, the conditions or patterns that signal suspicious activity, and how to filter or aggregate the results. Analysts use them to hunt for malicious behavior and indicators of compromise in their logs.
Detection content is scattered across vendor blogs, threat reports, GitHub repos, and researcher write-ups, which makes it time-consuming to track down manually. Feedly Threat Intelligence reads across open source reporting and surfaces the articles carrying Splunk Hunting Queries, so you can find relevant ones in one place instead of searching site by site.
Add the Splunk Hunting Queries AI Model to your AI Feed, then pair it with other AI Models to narrow the results to the topics, threats, or malware families you care about. When Feedly finds an article with a Splunk Hunting Query, you can copy it directly for tweaking or importing into your own tooling.
Yes. If a CVE has an associated Splunk Hunting Query, you can download it straight from Feedly Threat Intelligence's CVE Insights Card and jump to the article that referenced it, so you get both the detection logic and the surrounding context.
Alongside Splunk Hunting Queries, Feedly automatically identifies Suricata, Sigma, YARA, Snort, and KQL-based hunting queries for Microsoft Defender and Sentinel. Together these cover network traffic inspection, file and malware matching, and log-based detection.
Both are query languages for hunting through log data, but they run on different platforms. SPL is Splunk's language, while KQL powers Microsoft Defender and Sentinel. The syntax differs between them, so a query written for one usually needs to be translated before it will run on the other. Because Feedly Threat Intelligence recognizes both formats, you can collect hunting queries for whichever platform you run.
It is worth reviewing any query before you run it in production. Queries pulled from open reporting are a strong starting point, but tuning for your own data sources, field mappings, and false-positive tolerance will get you the best results.
此内容由惯性聚合(RSS阅读器)自动聚合整理,仅供阅读参考。 原文来自 — 版权归原作者所有。