olafhartong / ThreatHunting

A Splunk app mapped to MITRE ATT&CK to guide your threat hunts
MIT License
1.12k stars 177 forks source link

threathunting Summary Index Macro #37

Closed billmurrin closed 2 years ago

billmurrin commented 4 years ago

Olaf,

Our team uses a custom name for the threathunting index. With that in mind, we realized how you used the sysmon macro and thought it might a great idea if you also included a threathunting macro to help define the threathunting summary index. If you like that idea, I don't mind helping out doing some of the lifting to make that work.

olafhartong commented 4 years ago

Hi Bill, not a bad idea, I can imagine some companies have a strict naming convention. If you don't mind please go ahead a file a pull request.

I am a bit stretched for time to coming weeks

OutpostSecurity commented 3 years ago

I can grab this and work n it throughout this week.