Detections
A free library of hand-authored Splunk threat hunting queries, mapped to MITRE ATT&CK v16 and organized by tactic and telemetry source. Sourced from the CTI Threat Hunt Map. Index names are generic (sysmon, wineventlog, corelight) — adapt them to your environment, and validate every query before production use. The Sigma and YARA tabs collect rules published inside RedSheep reports, each linked back to its source report.
Loading…
All queries are provided "as is" for defensive security use — test and tune in your environment before relying on them. Technique mappings reference MITRE ATT&CK v16. Full disclaimer.