{"adoption": {"forks": 489, "observed_at": "2026-08-28T04:05:20.571448+00:00", "stars": 1676}, "canonical_url": "https://ross.abutalabs.com/products/security_content", "card": {"archived": false, "artifact_type": "dataset", "description": "Splunk Security Content", "domain": ["security", "developer-tools"], "enriched": true, "function": ["security", "monitoring", "alerting", "ci-cd"], "health_score": 100, "homepage": "https://research.splunk.com", "language": "Python", "license": "Apache-2.0", "license_family": "permissive", "maturity": "active", "member_repos": ["splunk/security_content"], "name": "splunk/security_content", "platform": ["self-hosted", "cross-platform"], "pushed_at": "2026-08-26T20:01:13+00:00", "repo": "splunk/security_content", "stars": 1676, "tags": ["detection-engineering", "mitre-attack", "siem", "splunk", "analytic-stories", "soc", "threat-hunting", "soar-playbooks", "automation"], "topics": ["splunk", "detection", "engineering", "responses", "cicd", "cybersecurity", "detection-engineering"], "urls": [], "use_cases": ["find pre-built Splunk detections for MITRE ATT&CK techniques", "build a SOC detection library without writing searches from scratch", "map my detection coverage across the MITRE ATT&CK framework", "get automated response playbooks for common threats", "research TTPs and detection strategies for emerging threats", "integrate threat research content into Splunk Enterprise Security", "test detections against simulated attack data"], "what_it_is": "A repository of Splunk security detections, Analytic Stories, and SOAR playbooks maintained by the Splunk Threat Research Team, mapped to MITRE ATT&CK, the Cyber Kill Chain, and CIS Controls. It provides pre-built searches, machine-learning algorithms, and response playbooks for detecting, investigating, and responding to threats in Splunk environments.", "when_to_avoid": ["you use a SIEM other than Splunk and cannot translate SPL queries", "you need a detection engine or runtime rather than content (rules/queries)", "you want a general-purpose threat intelligence feed rather than detection content"], "when_to_choose": ["you run Splunk (Enterprise Security, Essentials, or core) and want curated, maintained detections", "you need MITRE ATT&CK-mapped detection coverage with analytic stories and playbooks", "you want vendor-maintained security content updated with the latest threat research"]}, "data_as_of": "2026-08-30T08:39:29.467469+00:00", "members": [{"path": "/products/security_content", "repo": "splunk/security_content", "role": "main", "score": 98}], "provenance": {"archived": {"kind": "observed", "observed_at": "2026-08-28T04:05:20.571448+00:00", "source": "github"}, "artifact_type": {"confidence": null, "enriched_at": "2026-08-30T03:42:27.224256+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "cfcf0ff872beab8a5967c9be0356ffcab8b9c77bde671ab1833f8d392b589d26", "fetched_at": "2026-08-28T04:05:20.571448+00:00", "kind": "readme", "missing": false, "url": "https://github.com/splunk/security_content"}, {"content_hash": "fb003efba6a6701044ffb901491e5a319eed9d428bdaf4489f6f74b99075c2c3", "fetched_at": "2026-08-29T11:15:19.200637+00:00", "kind": "homepage", "missing": false, "url": "https://research.splunk.com"}, {"content_hash": "07f9fd6adad88ea60f47f81ef865e6e75a98de128b5cad71463f86b3e3281fb6", "fetched_at": "2026-08-29T11:15:19.203481+00:00", "kind": "site_page", "missing": false, "url": "http://splunk.com/threat-research"}], "taxonomy_version": 1}, "description": {"kind": "observed", "observed_at": "2026-08-28T04:05:20.571448+00:00", "source": "github"}, "domain": {"confidence": null, "enriched_at": "2026-08-30T03:42:27.224256+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "cfcf0ff872beab8a5967c9be0356ffcab8b9c77bde671ab1833f8d392b589d26", "fetched_at": "2026-08-28T04:05:20.571448+00:00", "kind": "readme", "missing": false, "url": "https://github.com/splunk/security_content"}, {"content_hash": "fb003efba6a6701044ffb901491e5a319eed9d428bdaf4489f6f74b99075c2c3", "fetched_at": "2026-08-29T11:15:19.200637+00:00", "kind": "homepage", "missing": false, "url": "https://research.splunk.com"}, {"content_hash": "07f9fd6adad88ea60f47f81ef865e6e75a98de128b5cad71463f86b3e3281fb6", "fetched_at": "2026-08-29T11:15:19.203481+00:00", "kind": "site_page", "missing": false, "url": "http://splunk.com/threat-research"}], "taxonomy_version": 1}, "enriched": {"inputs": [], "kind": "computed", "method": "enrichment_status"}, "function": {"confidence": null, "enriched_at": "2026-08-30T03:42:27.224256+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "cfcf0ff872beab8a5967c9be0356ffcab8b9c77bde671ab1833f8d392b589d26", "fetched_at": "2026-08-28T04:05:20.571448+00:00", "kind": "readme", "missing": false, "url": "https://github.com/splunk/security_content"}, {"content_hash": "fb003efba6a6701044ffb901491e5a319eed9d428bdaf4489f6f74b99075c2c3", "fetched_at": "2026-08-29T11:15:19.200637+00:00", "kind": "homepage", "missing": false, "url": "https://research.splunk.com"}, {"content_hash": "07f9fd6adad88ea60f47f81ef865e6e75a98de128b5cad71463f86b3e3281fb6", "fetched_at": "2026-08-29T11:15:19.203481+00:00", "kind": "site_page", "missing": false, "url": "http://splunk.com/threat-research"}], "taxonomy_version": 1}, "health_score": {"inputs": ["days_since_push", "days_since_release", "archived"], "kind": "computed", "method": "health_v1"}, "homepage": {"kind": "observed", "observed_at": "2026-08-28T04:05:20.571448+00:00", "source": "github"}, "language": {"kind": "observed", "observed_at": "2026-08-28T04:05:20.571448+00:00", "source": "github"}, "license": {"kind": "observed", "observed_at": "2026-08-28T04:05:20.571448+00:00", "source": "github"}, "license_family": {"inputs": ["license"], "kind": "computed", "method": "license_family"}, "maturity": {"confidence": null, "enriched_at": "2026-08-30T03:42:27.224256+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "cfcf0ff872beab8a5967c9be0356ffcab8b9c77bde671ab1833f8d392b589d26", "fetched_at": "2026-08-28T04:05:20.571448+00:00", "kind": "readme", "missing": false, "url": "https://github.com/splunk/security_content"}, {"content_hash": "fb003efba6a6701044ffb901491e5a319eed9d428bdaf4489f6f74b99075c2c3", "fetched_at": "2026-08-29T11:15:19.200637+00:00", "kind": "homepage", "missing": false, "url": "https://research.splunk.com"}, {"content_hash": "07f9fd6adad88ea60f47f81ef865e6e75a98de128b5cad71463f86b3e3281fb6", "fetched_at": "2026-08-29T11:15:19.203481+00:00", "kind": "site_page", "missing": false, "url": "http://splunk.com/threat-research"}], "taxonomy_version": 1}, "member_repos": {"kind": "observed", "observed_at": "2026-08-28T04:05:20.571448+00:00", "source": "github"}, "name": {"kind": "observed", "observed_at": "2026-08-28T04:05:20.571448+00:00", "source": "github"}, "platform": {"confidence": null, "enriched_at": "2026-08-30T03:42:27.224256+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "cfcf0ff872beab8a5967c9be0356ffcab8b9c77bde671ab1833f8d392b589d26", "fetched_at": "2026-08-28T04:05:20.571448+00:00", "kind": "readme", "missing": false, "url": "https://github.com/splunk/security_content"}, {"content_hash": "fb003efba6a6701044ffb901491e5a319eed9d428bdaf4489f6f74b99075c2c3", "fetched_at": "2026-08-29T11:15:19.200637+00:00", "kind": "homepage", "missing": false, "url": "https://research.splunk.com"}, {"content_hash": "07f9fd6adad88ea60f47f81ef865e6e75a98de128b5cad71463f86b3e3281fb6", "fetched_at": "2026-08-29T11:15:19.203481+00:00", "kind": "site_page", "missing": false, "url": "http://splunk.com/threat-research"}], "taxonomy_version": 1}, "pushed_at": {"kind": "observed", "observed_at": "2026-08-28T04:05:20.571448+00:00", "source": "github"}, "repo": {"kind": "observed", "observed_at": "2026-08-28T04:05:20.571448+00:00", "source": "github"}, "stars": {"kind": "observed", "observed_at": "2026-08-28T04:05:20.571448+00:00", "source": "github"}, "tags": {"confidence": null, "enriched_at": "2026-08-30T03:42:27.224256+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "cfcf0ff872beab8a5967c9be0356ffcab8b9c77bde671ab1833f8d392b589d26", "fetched_at": "2026-08-28T04:05:20.571448+00:00", "kind": "readme", "missing": false, "url": "https://github.com/splunk/security_content"}, {"content_hash": "fb003efba6a6701044ffb901491e5a319eed9d428bdaf4489f6f74b99075c2c3", "fetched_at": "2026-08-29T11:15:19.200637+00:00", "kind": "homepage", "missing": false, "url": "https://research.splunk.com"}, {"content_hash": "07f9fd6adad88ea60f47f81ef865e6e75a98de128b5cad71463f86b3e3281fb6", "fetched_at": "2026-08-29T11:15:19.203481+00:00", "kind": "site_page", "missing": false, "url": "http://splunk.com/threat-research"}], "taxonomy_version": 1}, "topics": {"kind": "observed", "observed_at": "2026-08-28T04:05:20.571448+00:00", "source": "github"}, "urls": {"kind": "observed", "observed_at": "2026-08-28T04:05:20.571448+00:00", "source": "github"}, "use_cases": {"confidence": null, "enriched_at": "2026-08-30T03:42:27.224256+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "cfcf0ff872beab8a5967c9be0356ffcab8b9c77bde671ab1833f8d392b589d26", "fetched_at": "2026-08-28T04:05:20.571448+00:00", "kind": "readme", "missing": false, "url": "https://github.com/splunk/security_content"}, {"content_hash": "fb003efba6a6701044ffb901491e5a319eed9d428bdaf4489f6f74b99075c2c3", "fetched_at": "2026-08-29T11:15:19.200637+00:00", "kind": "homepage", "missing": false, "url": "https://research.splunk.com"}, {"content_hash": "07f9fd6adad88ea60f47f81ef865e6e75a98de128b5cad71463f86b3e3281fb6", "fetched_at": "2026-08-29T11:15:19.203481+00:00", "kind": "site_page", "missing": false, "url": "http://splunk.com/threat-research"}], "taxonomy_version": 1}, "what_it_is": {"confidence": null, "enriched_at": "2026-08-30T03:42:27.224256+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "cfcf0ff872beab8a5967c9be0356ffcab8b9c77bde671ab1833f8d392b589d26", "fetched_at": "2026-08-28T04:05:20.571448+00:00", "kind": "readme", "missing": false, "url": "https://github.com/splunk/security_content"}, {"content_hash": "fb003efba6a6701044ffb901491e5a319eed9d428bdaf4489f6f74b99075c2c3", "fetched_at": "2026-08-29T11:15:19.200637+00:00", "kind": "homepage", "missing": false, "url": "https://research.splunk.com"}, {"content_hash": "07f9fd6adad88ea60f47f81ef865e6e75a98de128b5cad71463f86b3e3281fb6", "fetched_at": "2026-08-29T11:15:19.203481+00:00", "kind": "site_page", "missing": false, "url": "http://splunk.com/threat-research"}], "taxonomy_version": 1}, "when_to_avoid": {"confidence": null, "enriched_at": "2026-08-30T03:42:27.224256+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "cfcf0ff872beab8a5967c9be0356ffcab8b9c77bde671ab1833f8d392b589d26", "fetched_at": "2026-08-28T04:05:20.571448+00:00", "kind": "readme", "missing": false, "url": "https://github.com/splunk/security_content"}, {"content_hash": "fb003efba6a6701044ffb901491e5a319eed9d428bdaf4489f6f74b99075c2c3", "fetched_at": "2026-08-29T11:15:19.200637+00:00", "kind": "homepage", "missing": false, "url": "https://research.splunk.com"}, {"content_hash": "07f9fd6adad88ea60f47f81ef865e6e75a98de128b5cad71463f86b3e3281fb6", "fetched_at": "2026-08-29T11:15:19.203481+00:00", "kind": "site_page", "missing": false, "url": "http://splunk.com/threat-research"}], "taxonomy_version": 1}, "when_to_choose": {"confidence": null, "enriched_at": "2026-08-30T03:42:27.224256+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "cfcf0ff872beab8a5967c9be0356ffcab8b9c77bde671ab1833f8d392b589d26", "fetched_at": "2026-08-28T04:05:20.571448+00:00", "kind": "readme", "missing": false, "url": "https://github.com/splunk/security_content"}, {"content_hash": "fb003efba6a6701044ffb901491e5a319eed9d428bdaf4489f6f74b99075c2c3", "fetched_at": "2026-08-29T11:15:19.200637+00:00", "kind": "homepage", "missing": false, "url": "https://research.splunk.com"}, {"content_hash": "07f9fd6adad88ea60f47f81ef865e6e75a98de128b5cad71463f86b3e3281fb6", "fetched_at": "2026-08-29T11:15:19.203481+00:00", "kind": "site_page", "missing": false, "url": "http://splunk.com/threat-research"}], "taxonomy_version": 1}}, "score": {"components": {"activity": 99, "longevity": 100, "rhythm": 97}, "computed_at": "2026-09-03T02:20:16.233290+00:00", "flags": [], "formula": "round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)", "inputs": {"age_days": 2815, "days_push": 7, "days_rel": 21, "gap_med": 14, "n_releases_24m": 40}, "score": 98, "version": 2}, "staleness": {"enrichment_outdated": false, "low_confidence": false, "scrape_days": 9, "stale_scrape": false}}