Open Source Projects

Security tools, machine learning frameworks, and research datasets for the security community. Contributing to open source and sharing knowledge to advance the state of security operations.

10
Public Projects
55
GitHub Stars
Community
Driven

splunk_deployment_automation

22

Enterprise-grade automation framework for deploying and managing Splunk at scale. Streamlines infrastructure provisioning, configuration management, and deployment orchestration for large Splunk environments.

  • Automated Splunk deployment workflows
  • Configuration management at scale
  • Multi-environment orchestration
  • Enterprise deployment best practices
SplunkAutomationDevOpsInfrastructure as Code
View on GitHub

analytics_toolkit

13

Comprehensive toolkit for Machine Learning & Analytics use cases in security operations. Provides pre-built workflows, algorithms, and visualizations for security practitioners to operationalize ML without deep data science expertise.

  • Pre-built ML workflows for common security use cases
  • Anomaly detection templates
  • Threat hunting algorithms
  • Operational ML best practices
Machine LearningSecurity AnalyticsSplunkData Science
View on GitHub

SA-Synaptic_Echo

5

Supporting Add-On for parsing PDF indicators of compromise (IOCs). Maintains a repository of uploaded PDFs and runs scheduled searches against IOCs, automating threat intelligence ingestion from PDF reports.

  • Automated PDF IOC extraction
  • Scheduled IOC searches
  • Threat intel repository management
  • Integration with threat feeds
SplunkThreat IntelligenceIOCSecurity Automation
View on GitHub

TA-Suricata

4

Technical Add-On that normalizes Suricata eve.json fields to match Splunk's Common Information Model (CIM). Enables seamless integration of Suricata IDS telemetry with Splunk Enterprise Security for threat detection and security analytics.

  • CIM-compliant field normalization
  • Enterprise Security integration
  • eve.json parsing and enrichment
  • Network threat detection enablement
SuricataSplunk CIMIDSNetwork Security
View on GitHub

splunkforsccm

4

Installation package for deploying Splunk Universal Forwarder via Microsoft System Center Configuration Manager (SCCM). Enables centralized, automated Splunk agent deployment across Windows enterprise environments.

SplunkSCCMWindowsEnterprise Deployment
View on GitHub

Mirai Source Code & Research Data

2

Leaked Mirai botnet source code and captured network traffic for security research and IOC development. Includes Mirai and WannaCry traffic logs captured using Suricata for threat analysis and detection development.

  • Mirai botnet source code analysis
  • Network traffic captures
  • Suricata logs for signature development
  • Research datasets for ML training
Security ResearchBotnet AnalysisSuricataThreat Intelligence
View on GitHub

Splunk_delete_fishbucket

2

Remote administration tool for deleting Splunk's fishbucket on deployment clients. Enables controlled data reindexing across distributed Splunk deployments without manual intervention on individual forwarders.

SplunkAdministrationData Management
View on GitHub

mirai_wannacry.tgz

1

Real-world network traffic and Linux OS logs from a honeypot operational during the peak of the Mirai botnet and WannaCry ransomware attacks. Captured with Suricata for threat research, IOC development, and machine learning model training.

  • Real-world attack traffic captures
  • Netflow and OS-level telemetry
  • Suricata eve.json logs
  • ML training datasets for botnet detection
HoneypotMalware ResearchNetwork ForensicsWannaCryMirai
View on GitHub

TA-Suricata_rules

1

Technical Add-On that indexes Suricata rule files from /etc/suricata/rules into Splunk. Enables security teams to review Snort/Suricata signatures, track rule changes over time, and maintain visibility into IDS detection capabilities.

SuricataSnortIDS RulesSignature Management
View on GitHub

conf2016_extras

1

Supplementary materials and code samples from Splunk .conf2016 presentations, including Boss of the SOC security app development workshop materials.

SplunkSecurity AppsConferenceWorkshop
View on GitHub

Contributions Welcome

Found these projects useful? Star them on GitHub or contribute improvements!

View All Repositories