Ross ROSS = Recommend OSS · open-source software intelligence for agents

splunk/security_content resource

Splunk Security Content observed · 2026-08-28

github.com/splunk/security_content · homepage · Python · Apache-2.0 (permissive) observed · 2026-08-28

Health v2 · maintenance only

98/100

  • Activity 99
  • Release rhythm 97
  • Longevity 100
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: 14
  • age_days: 2815
  • days_rel: 21
  • days_push: 7
  • n_releases_24m: 40

Full methodology

Adoption not part of the score

1676 stars · 489 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

A repository of Splunk security detections, Analytic Stories, and SOAR playbooks maintained by the Splunk Threat Research Team, mapped to MITRE ATT&CK, the Cyber Kill Chain, and CIS Controls. It provides pre-built searches, machine-learning algorithms, and response playbooks for detecting, investigating, and responding to threats in Splunk environments.

Use cases

  • find pre-built Splunk detections for MITRE ATT&CK techniques
  • build a SOC detection library without writing searches from scratch
  • map my detection coverage across the MITRE ATT&CK framework
  • get automated response playbooks for common threats
  • research TTPs and detection strategies for emerging threats
  • integrate threat research content into Splunk Enterprise Security
  • test detections against simulated attack data

When to choose

  • you run Splunk (Enterprise Security, Essentials, or core) and want curated, maintained detections
  • you need MITRE ATT&CK-mapped detection coverage with analytic stories and playbooks
  • you want vendor-maintained security content updated with the latest threat research

When to avoid

  • you use a SIEM other than Splunk and cannot translate SPL queries
  • you need a detection engine or runtime rather than content (rules/queries)
  • you want a general-purpose threat intelligence feed rather than detection content

Facets

dataset · maturity active

security monitoring alerting ci-cd security developer-tools self-hosted cross-platform detection-engineering mitre-attack siem splunk analytic-stories soc threat-hunting soar-playbooks automation

3 sources

Member repositories

RepositoryRoleHealth v2
splunk/security_contentmain98

For agents

markdown · JSON · MCP: product_card(name="splunk/security_content")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem