What it does. Build automated IOC enrichment pipelines in Splunk Enterprise Security by ingesting threat feeds into KV Store collections and correlating them against security events via lookup tables, modular inputs, and the Threat Intelligence Framework. Use when wiring threat intel into Splunk correlation searches to flag IOC matches and cut SOC triage time. Part of mukul975/Anthropic-Cybersecurity-Skills (817 security skills) (mukul975/Anthropic-Cybersecurity-Skills).
Install
npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill building-threat-intelligence-enrichment-in-splunk, or copy the skill folder into ~/.claude/skills/building-threat-intelligence-enrichment-in-splunk/.
- Raw file:
curl -sL https://raw.githubusercontent.com/mukul975/Anthropic-Cybersecurity-Skills/HEAD/skills/building-threat-intelligence-enrichment-in-splunk/SKILL.md
SKILL.md (verbatim)
2 placeholder credentials were shortened (for example to api_key=YOUR_KEY) to pass the site's secret filter.
name: building-threat-intelligence-enrichment-in-splunk
description: Build automated IOC enrichment pipelines in Splunk Enterprise Security by ingesting threat feeds into KV Store collections and correlating them against security events via lookup tables, modular inputs, and the Threat Intelligence Framework. Use when wiring threat intel into Splunk correlation searches to flag IOC matches and cut SOC triage time.
domain: cybersecurity
subdomain: soc-operations
tags:
- splunk
- threat-intelligence
- enrichment
- ioc
- lookup
- siem
- soc
- enterprise-security
version: '1.0'
author: mahipal
license: Apache-2.0
nist_csf:
- DE.CM-01
- DE.AE-02
- RS.MA-01
- DE.AE-06
mitre_attack:
- T1071
- T1105
- T1041
Building Threat Intelligence Enrichment in Splunk
Overview
Splunk's Threat Intelligence Framework in Enterprise Security enables SOC teams to automatically correlate indicators of compromise (IOCs) against security events. The framework ingests threat feeds, normalizes indicators into KV Store collections, and uses lookup-based correlation searches to flag matching events. Splunk Threat Intelligence Management centralizes collection, normalization, and enrichment from multiple sources, reducing triage time by providing analysts with immediate context.
When to Use
- When deploying or configuring building threat intelligence enrichment in splunk capabilities in your environment
- When establishing security controls aligned to compliance requirements
- When building or improving security architecture for this domain
- When conducting security assessments that require this implementation
Prerequisites
- Splunk Enterprise Security (ES) 7.x or later
- Threat Intelligence Management add-on or Threat Intelligence Framework
- API keys for external threat intelligence feeds (MISP, OTX, VirusTotal, AbuseIPDB)
- KV Store enabled and properly configured
- Admin access for modular input configuration
Threat Intelligence Framework Architecture
External TI Sources (STIX/TAXII, CSV, API)
|
v
Modular Inputs (download and parse feeds)
|
v
KV Store Collections (normalized IOC storage)
|-- ip_intel
|-- domain_intel
|-- file_intel
|-- url_intel
|-- email_intel
|
v
Threat Intelligence Lookups
|
v
Correlation Searches (match events against IOCs)
|
v
Notable Events (enriched with TI context)
Configuring Threat Intelligence Sources
STIX/TAXII Feed Integration
# inputs.conf - TAXII feed configuration
[threatlist://taxii_feed_example]
description = TAXII 2.1 Threat Feed
type = taxii
url = https://threatfeed.example.com/taxii2/
collection = threat-indicators-v21
polling_interval = 3600
api_key = YOUR_KEY
disabled = false
CSV-Based Threat List
# inputs.conf - CSV threat list
[threatlist://custom_blocklist]
description = Internal threat blocklist
type = csv
url = https://internal.company.com/threat-feeds/blocklist.csv
polling_interval = 1800
disabled = false
# bin/threatfeed_otx.py - OTX AlienVault feed collector
import json
import sys
import requests
from splunklib.modularinput import Script, Scheme, Argument, Event
class OTXFeedInput(Script):
def get_scheme(self):
scheme = Scheme("OTX AlienVault Feed")
scheme.description = "Collects IOCs from AlienVault OTX"
scheme.use_external_validation = False
scheme.streaming_mode = Scheme.streaming_mode_xml
api_key_arg = Argument("api_key")
api_key_arg.data_type = Argument.data_type_string
api_key_arg.required_on_create = True
scheme.add_argument(api_key_arg)
pulse_days_arg = Argument("pulse_days")
pulse_days_arg.data_type = Argument.data_type_number
pulse_days_arg.required_on_create = False
scheme.add_argument(pulse_days_arg)
return scheme
def stream_events(self, inputs, ew):
for input_name, input_item in inputs.inputs.items():
api_key = YOUR_KEY
pulse_days = int(input_item.get("pulse_days", 30))
headers = {"X-OTX-API-KEY": api_key}
url = f"https://otx.alienvault.com/api/v1/pulses/subscribed?modified_since={pulse_days}d"
try:
response = requests.get(url, headers=headers, timeout=60)
response.raise_for_status()
data = response.json()
for pulse in data.get("results", []):
for indicator in pulse.get("indicators", []):
event = Event()
event.stanza = input_name
event.data = json.dumps({
"indicator": indicator["indicator"],
"type": indicator["type"],
"pulse_name": pulse["name"],
"pulse_id": pulse["id"],
"description": indicator.get("description", ""),
"created": indicator.get("created", ""),
"threat_source": "OTX",
"confidence": pulse.get("adversary", "unknown"),
})
ew.write_event(event)
except requests.RequestException as e:
ew.log("ERROR", f"OTX feed collection failed: {str(e)}")
if __name__ == "__main__":
sys.exit(OTXFeedInput().run(sys.argv))
Building Enrichment Lookups
KV Store Collection Configuration
# collections.conf
[ip_threat_intel]
field.ip = string
field.threat_type = string
field.confidence = number
field.source = string
field.description = string
field.first_seen = time
field.last_seen = time
field.severity = string
[domain_threat_intel]
field.domain = string
field.threat_type = string
field.confidence = number
field.source = string
field.whois_registrar = string
field.whois_created = string
[file_hash_intel]
field.file_hash = string
field.hash_type = string
field.malware_family = string
field.confidence = number
field.source = string
field.detection_names = string
Lookup Table Definitions
# transforms.conf
[ip_threat_intel_lookup]
external_type = kvstore
collection = ip_threat_intel
fields_list = ip, threat_type, confidence, source, description, severity
[domain_threat_intel_lookup]
external_type = kvstore
collection = domain_threat_intel
fields_list = domain, threat_type, confidence, source
[file_hash_intel_lookup]
external_type = kvstore
collection = file_hash_intel
fields_list = file_hash, hash_type, malware_family, confidence, source
Enrichment Correlation Searches
IP-Based Threat Intelligence Correlation
| tstats summariesonly=true count from datamodel=Network_Traffic
where All_Traffic.action=allowed
by All_Traffic.src_ip, All_Traffic.dest_ip, All_Traffic.dest_port, _time span=5m
| rename "All_Traffic.*" as *
| lookup ip_threat_intel_lookup ip as dest_ip OUTPUT threat_type, confidence, source as ti_source, severity as ti_severity
| where isnotnull(threat_type)
| lookup asset_lookup ip as src_ip OUTPUT asset_name, asset_owner, asset_priority
| eval urgency=case(
ti_severity=="critical" AND asset_priority=="critical", "critical",
ti_severity=="high" OR asset_priority=="critical", "high",
ti_severity=="medium", "medium",
true(), "low"
)
| eval description="Connection from ".src_ip." (".asset_name.") to known malicious IP ".dest_ip." (".threat_type.") - Source: ".ti_source
Domain-Based Threat Intelligence Correlation
index=dns sourcetype=stream:dns query_type=A OR query_type=AAAA
| lookup domain_threat_intel_lookup domain as query OUTPUT threat_type as domain_threat, confidence as domain_confidence, source as ti_source
| where isnotnull(domain_threat) AND domain_confidence > 70
| stats count dc(src_ip) as unique_sources values(src_ip) as source_ips by query, domain_threat, ti_source
| eval severity=case(domain_confidence > 90, "critical", domain_confidence > 70, "high", true(), "medium")
| eval description="DNS queries to malicious domain ".query." from ".unique_sources." hosts - Threat: ".domain_threat
File Hash Correlation
index=endpoint sourcetype=sysmon EventCode=1
| lookup file_hash_intel_lookup file_hash as Hashes OUTPUT malware_family, confidence as hash_confidence, source as ti_source
| where isnotnull(malware_family)
| stats count values(ParentCommandLine) as parent_commands by Computer, User, Image, malware_family, ti_source
| eval severity="critical"
| eval description="Known malware ".malware_family." executed on ".Computer." by ".User." - Binary: ".Image
Multi-Source Enrichment Pipeline
index=firewall sourcetype=pan:traffic action=allowed
| eval indicators=mvappend(src_ip, dest_ip)
| mvexpand indicators
| lookup ip_threat_intel_lookup ip as indicators OUTPUT threat_type as ip_threat, confidence as ip_confidence, source as ip_ti_source
| lookup geo_ip_lookup ip as indicators OUTPUT country, city, latitude, longitude
| lookup whois_lookup ip as indicators OUTPUT org as ip_org, asn as ip_asn
| where isnotnull(ip_threat)
| stats count
values(ip_threat) as threat_types
values(ip_ti_source) as intel_sources
values(country) as countries
values(ip_org) as organizations
latest(_time) as last_seen
earliest(_time) as first_seen
by src_ip, dest_ip, dest_port
| eval enrichment_context="Threat: ".mvjoin(threat_types, ", ")." | Geo: ".mvjoin(countries, ", ")." | Org: ".mvjoin(organizations, ", ")
Threat Intelligence Dashboards
IOC Coverage Statistics
| inputlookup ip_threat_intel_lookup
| stats count by source, threat_type
| sort -count
| head 20
Feed Freshness Monitoring
| inputlookup ip_threat_intel_lookup
| eval age_days=round((now() - strptime(last_seen, "%Y-%m-%dT%H:%M:%S")) / 86400, 0)
| stats count avg(age_days) as avg_age_days max(age_days) as max_age_days by source
| eval status=case(avg_age_days > 30, "STALE", avg_age_days > 7, "AGING", true(), "FRESH")
References
Other files in this skill
assets/template.md (verbatim)
Threat Intelligence Enrichment Template
Feed Configuration
| Field |
Value |
| Feed Name |
|
| Source |
|
| Feed Type |
STIX/TAXII / CSV / API / Manual |
| Polling Interval |
|
| IOC Types |
IP / Domain / Hash / URL / Email |
| Confidence Threshold |
|
KV Store Collection
| Field |
Type |
Description |
| _key |
string |
Unique indicator hash |
| indicator_value |
string |
IOC value |
| threat_type |
string |
C2/Phishing/Malware/Scanner |
| confidence |
number |
0-100 |
| source |
string |
Feed name |
| severity |
string |
critical/high/medium/low |
| first_seen |
time |
First observation |
| last_seen |
time |
Last observation |
Correlation Search Template
| tstats summariesonly=true count
from datamodel=<DataModel>
by <fields>, _time span=5m
| rename "<DataModel>.*" as *
| lookup <lookup_name> <match_field> as <event_field>
OUTPUT threat_type, confidence, source as ti_source
| where isnotnull(threat_type) AND confidence > <threshold>
| eval description="TI match: ".<matched_field>." (".<threat_type>.")"
Feed Health Dashboard
| Metric |
Current |
Target |
| Total active indicators |
|
|
| Feed freshness (avg age) |
|
< 7 days |
| Hit rate (last 30 days) |
|
> 0.5% |
| False positive rate |
|
< 5% |
| Feed overlap rate |
|
< 30% |
references/api-reference.md (verbatim)
API Reference: Threat Intelligence Enrichment in Splunk
Splunk KV Store REST API
# Create collection
curl -k -u admin:pass -X POST \
"https://localhost:8089/servicesNS/nobody/SA-ThreatIntelligence/storage/collections/config" \
-d name=ip_intel
# Insert record
curl -k -u admin:pass -X POST \
"https://localhost:8089/servicesNS/nobody/SA-ThreatIntelligence/storage/collections/data/ip_intel" \
-H "Content-Type: application/json" \
-d '{"ip":"198.51.100.42","threat_key":"c2_server","weight":"3"}'
# Batch insert
curl -k -u admin:pass -X POST \
"https://localhost:8089/servicesNS/nobody/SA-ThreatIntelligence/storage/collections/data/ip_intel/batch_save" \
-H "Content-Type: application/json" \
-d '[{"ip":"1.2.3.4","threat_key":"malware"},{"ip":"5.6.7.8","threat_key":"c2"}]'
Splunk Enterprise Security TI Framework
| Collection |
Lookup |
Data Model |
| ip_intel |
ip_intel_lookup |
Network_Traffic |
| domain_intel |
domain_intel_lookup |
Network_Resolution |
| file_intel |
file_intel_lookup |
Endpoint |
| email_intel |
email_intel_lookup |
Email |
| http_intel |
http_intel_lookup |
Web |
SPL Threat Matching
| tstats summariesonly=t count from datamodel=Network_Traffic
by All_Traffic.dest_ip
| rename All_Traffic.dest_ip as ip
| lookup ip_intel_lookup ip OUTPUT threat_key description
| where isnotnull(threat_key)
AlienVault OTX API
# Get pulse indicators
curl "https://otx.alienvault.com/api/v1/pulses/PULSE_ID/indicators"
# Search pulses
curl -H "X-OTX-API-KEY: $OTX_KEY" \
"https://otx.alienvault.com/api/v1/search/pulses?q=ransomware&page=1"
Splunk Python SDK
import splunklib.client as client
service = client.connect(
host="localhost", port=8089,
username="admin", password="changeme"
)
# Access KV store collection
collection = service.kvstore["ip_intel"]
collection.data.insert(json.dumps({
"ip": "198.51.100.42",
"threat_key": "c2_server"
}))
references/standards.md (verbatim)
Standards - Threat Intelligence Enrichment in Splunk
Threat Intelligence Standards
- Version 2.1 is the current standard for representing threat intelligence
- Defines objects: Indicator, Malware, Attack Pattern, Threat Actor, Campaign
- Used as the interchange format between TI platforms and SIEMs
- Transport mechanism for STIX data
- TAXII 2.1 provides RESTful API for feed collection
- Supports Collection and Channel sharing models
OpenIOC
- Mandiant's open framework for sharing IOCs
- XML-based format for indicator definitions
OCSF (Open Cybersecurity Schema Framework)
- Industry standard for normalizing security event data
- Version 1.0 released at BlackHat 2023
Splunk CIM Data Models for TI
| Data Model |
TI Correlation Fields |
| Network_Traffic |
src_ip, dest_ip, dest_port |
| Web |
url, http_user_agent, domain |
| Email |
src_user, file_hash, url |
| Endpoint |
process_hash, file_hash, dest |
| Authentication |
src_ip, user, app |
| DNS |
query, answer, src_ip |
IOC Types and Confidence Levels
| IOC Type |
Splunk Field |
Confidence Threshold |
| IP Address |
ip_intel |
> 70% |
| Domain |
domain_intel |
> 70% |
| File Hash (SHA256) |
file_intel |
> 80% |
| URL |
url_intel |
> 75% |
| Email Address |
email_intel |
> 80% |
references/workflows.md (verbatim)
Workflows - Threat Intelligence Enrichment in Splunk
TI Feed Integration Workflow
1. Identify Relevant TI Sources
- Commercial feeds (Recorded Future, Mandiant)
- Open source (OTX, AbuseIPDB, VirusTotal)
- Industry ISACs
- Internal threat lists
|
v
2. Configure Modular Inputs
- Set polling intervals
- Configure authentication
- Map feed fields to Splunk schema
|
v
3. Normalize to KV Store
- Parse raw feed data
- Map to standard field names
- Set confidence scores
- Add source attribution
|
v
4. Create Lookup Definitions
- Define transforms.conf entries
- Set field mappings
- Enable automatic lookups where appropriate
|
v
5. Build Correlation Searches
- Match events against IOC lookups
- Add asset/identity enrichment
- Set severity based on confidence
|
v
6. Monitor and Maintain
- Track feed freshness
- Remove stale indicators
- Measure hit rates per source
IOC Lifecycle Management
Ingestion --> Validation --> Active Use --> Aging --> Expiration --> Removal
| | | | |
v v v v v
Raw feeds Dedup and Correlation Reduce Archive
parsed confidence matching confidence or delete
scoring weighting
Feed Quality Assessment
| Metric |
Good |
Warning |
Critical |
| Feed latency |
< 1 hour |
1-24 hours |
> 24 hours |
| False positive rate |
< 5% |
5-15% |
> 15% |
| Hit rate |
> 1% |
0.1-1% |
< 0.1% |
| Coverage overlap |
< 30% |
30-60% |
> 60% |
| Indicator freshness |
< 7 days |
7-30 days |
> 30 days |
Back to mukul975/Anthropic-Cybersecurity-Skills (817 security skills) or Agent skills.