Skip to main content

 

Splunk Lantern

Working with threat intelligence sources in Enterprise Security 8.5

Splunk Enterprise Security (ES) manages threat intelligence through two primary pillars: the native ES threat intelligence framework and the cloud-based Splunk Threat Intelligence Management (TIM). Knowing their role and how they relate to one another is key to building an effective threat surfacing strategy.

This series breaks the topic down into focused, hands-on articles suitable for detection engineers, admins, data architects and similar roles. Together they form an end-to-end guide on how threat intel is ingested, processed, matched, alerted on, and used to enrich investigations in ES 8.5.

About threat intelligence in Splunk Enterprise Security

Splunk Enterprise Security 8.5 offers two distinct onboarding methods of threat intel data.

As Splunk works towards further integration of TIM Cloud into the existing, native ES threat engine, Splunk Help terminology has shifted to emphasize the core distinction between native and cloud-based intelligence. For that reason, in Splunk Help documentation as well as in our articles, you might come across the Threat Intelligence Framework referred to as native threat intelligence, and TIM Cloud as cloud-based intelligence.

Articles in this series

The articles below are designed to be read in order, but each one stands on its own if you're looking for guidance on a specific task.

Article What you'll learn
Configuring native threat intelligence sources in Enterprise Security 8.5 Activate a prepackaged threat intel source (using PhishTank as an example), understand how TIF parses and routes downloaded data into *_intel collections, and add a custom feed using Malware Bazaar as an example.
Detecting threats and enriching investigations with native threat intelligence in Enterprise Security 8.5 Unpack how threat matching searches surface IOC matches, how findings become alerts through detections like Threat Activity Detected, and how to capture IOCs as observables in the Investigation Intelligence tab.
Enriching threat intelligence with cloud-based sources in Enterprise Security 8.5 Access and configure TIM Cloud feeds, understand how the tim_iocs collection stores cloud intel and connects to the native framework, search the collection with spath, and interpret TIM Cloud's normalized threat scoring.

Additional resources

These resources might help you understand and implement this guidance: