Available open intelligence sources for Splunk Enterprise Security

Note: This documentation topic on threat intelligence applies only to users with access to the threat intelligence management (cloud) system, and not the threat intelligence management system, in Splunk Enterprise Security

Open intelligence sources are sources that are freely available without any subscription requirement. Use the following table to find the supported observable types for each open intelligence source:

Intelligence source Update type Update frequency Supported observable types
URLHaus Feed-based 60 minutes
  • URL
Abuse SSL IP Blacklist Feed-based 15 minutes
  • IP
  • URL