Most SOC teams we work with need to match activity in their Splunk environment against current indicators of compromise, then investigate what turns up. The Mallory App for Splunk, available today, closes that loop end to end.
The app imports Mallory's IoC intelligence into Splunk Enterprise Security on a schedule you control, makes it available for matching against the telemetry you already collect, and can report confirmed matches back to Mallory as sightings for further investigation.
Bring Mallory intelligence into Splunk ES
Mallory's Intelligence Graph connects observables with reporting on threat actors, malware, vulnerabilities, and campaigns. The Splunk app makes that indicator intelligence available inside your SIEM.
Connect the app with a Mallory API key and choose an import schedule. The app imports observables into Splunk ES as a threat intelligence source, and scheduled imports keep new intelligence flowing in as Mallory collects and processes it. Your team controls the refresh cadence to fit its own detection workflow.
Match indicators against your logs
The app includes searches for IoC matching, plus guidance for configuring the indexes and fields those searches use, so your team can adapt matching to the telemetry sources that matter in your environment.
A match means an indicator turned up in your logs. Analysts can pull up the associated event, identify the systems involved, and decide whether the activity is worth escalating. Matching runs inside Splunk, alongside the telemetry and searches your team already uses.
Report sightings back to Mallory, then automate the investigation
When a search identifies an IoC match, the app can report it to Mallory as a sighting with its Splunk source context. That connects Mallory's intelligence about an observable with evidence of where and when it actually showed up in your environment.
Sightings give your team a starting point for investigation in Mallory. Set up an automation routine to pull the intelligence linking that observable to threat actors, malware, or vulnerabilities, and use those relationships to decide what to check next, without leaving Mallory.
An indicator tied to a known malware family, for example, can pull in reporting on that family's behavior and known exploitation activity, so an investigator knows which systems to check and what else to search for.
Existing customers: reach out to your Mallory contact to get the Splunk app, connect your intelligence feed, and configure IoC matching in Splunk ES. New to Mallory? Talk to sales to learn how Mallory fits your Splunk environment.
Close the loop between intelligence and telemetry
The Mallory App for Splunk brings IoC matching and sighting-based investigation into the SIEM your team already runs.
Start Free Trial