- the
| kyberisstreaming search command — batched enrichment of indicator fields, with CIM Threat Intelligence field mapping for Enterprise Security; - the Kyberis enrichment alert action — a core Splunk alert action and Enterprise Security adaptive response action that enriches an alert’s triggering results and indexes the verdicts;
- a cross-search KV Store cache, so repeated indicators cost zero API calls within a configurable TTL;
- the
| kyberischeckdiagnostic command and a setup page for managing named credential profiles in Splunk secure storage.
The app is published on Splunkbase as
Kyberis Threat Intelligence. Install it
from Apps → Find More Apps in Splunk Web, or download the package from the
listing — see Installation.
.png?fit=max&auto=format&n=u7saXgSwhIjXsY7P&q=85&s=66da6f97e851defcb12af05b800a8a27)
.png?fit=max&auto=format&n=u7saXgSwhIjXsY7P&q=85&s=37df025ce7a3cc54dd90f8edad1cf54f)