Skip to main content
Kyberis Threat Intelligence enriches indicators of compromise — IPs, domains, URLs, hashes, and emails — from Splunk search results and alerts with Kyberis threat verdicts, scores, and context. The app provides:
  • the | kyberis streaming search command — batched enrichment of indicator fields, with CIM Threat Intelligence field mapping for Enterprise Security;
  • the Kyberis enrichment alert action — a core Splunk alert action and Enterprise Security adaptive response action that enriches an alert’s triggering results and indexes the verdicts;
  • a cross-search KV Store cache, so repeated indicators cost zero API calls within a configurable TTL;
  • the | kyberischeck diagnostic command and a setup page for managing named credential profiles in Splunk secure storage.
Everything runs on search heads. Indexers and forwarders need nothing installed and make no outbound connections.
The app is published on Splunkbase as Kyberis Threat Intelligence. Install it from Apps → Find More Apps in Splunk Web, or download the package from the listing — see Installation.

Guides

Compatibility matrix

Support

Email [email protected].