Ad

attack_data: Attack datasets for Splunk detection

attack_data provides curated datasets of attack simulations to facilitate detection development and testing within Splunk environments.
Screenshot of splunk/attack_data homepage

attack_data curates datasets from various attacks to easily develop detections without environment setup or attack simulation. This project supports testing Splunk Security Content and replay datasets into streaming pipelines. It leverages a lightweight tool called TOTAL-REPLAY to enhance the utilization of Splunk's detection metadata.

The project offers a practical solution for developing and validating security detections. It is well-structured with clear documentation on dataset acquisition and replay methods. The integration with Splunk's Attack Range and TOTAL-REPLAY significantly enhances its utility and streamline workflow.

  • Dataset Variety: Includes datasets generated through automated simulations and manual attacks covering diverse attack techniques.
  • Replay Functionality: Provides tools and instructions for easily replaying datasets within Splunk and using the TOTAL-REPLAY tool.
  • Contribution Model: A clear process is defined for users to generate and contribute their own datasets to the repository.
  • Automation: Automates the generation of datasets using the attack_data_service project.
  • Integrations: Designed to integrate seamlessly with Splunk's Security Content and Attack Range.
  • Data Formats: Primarily utilizes raw log files with common sourcetypes and formats.
  • Developer Experience: Streamlined installation and usage instructions for both dataset acquisition and data replay.

The project is actively maintained, with recent commits and a growing community. The documentation is comprehensive, providing detailed instructions for installation, dataset acquisition, and contribution. The project acknowledges dependencies on related projects like Attack Range and TOTAL-REPLAY, indicating a cohesive ecosystem.

Security analysts and security engineers benefit from attack_data by providing readily available datasets for developing, testing, and validating detection rules in Splunk. This project streamlines the process of working with attack data, enabling faster security analysis and proactive threat detection. It lowers the barrier to entry for creating custom detection content by providing pre-generated attack data.

Languages:
Summarize:
Share:
Stars
785
Forks
141
Issues
0
Created
6 years ago
Commit
2 months ago
License
APACHE-2.0
Archived
No
Updated 1 month ago

Similar Repositories