Hands-on Splunk BOTS investigations showcasing threat hunting, SPL queries, and detection logic.
-
Updated
Mar 2, 2026
Hands-on Splunk BOTS investigations showcasing threat hunting, SPL queries, and detection logic.
Hands-on Splunk lab work covering SPL querying, alerting, and dashboard building using the BOTSv1 dataset and linux_secure sourcetype, progressing through the full Cyber Kill Chain from reconnaissance to actions on objectives.
SOC monitoring environment built with Splunk Enterprise — detection rules for brute force, privilege escalation, and account lockout using real Windows event logs and BOTSv1 attack data
A phased cybersecurity portfolio demonstrating Log Analysis, Threat Hunting (BOTSv1), and AI/ML Anomaly Detection. Built with Python, Splunk, and Pandas.
Splunk Boss of the SOC v1 investigation writeups covering website defacement and Cerber ransomware, with SPL queries, IOC analysis, MITRE ATT&CK mapping, OSINT pivots, and supporting screenshots.
Splunk SIEM detection engineering on 33.4M BOTSv1 events — Risk-Based Alerting, contentctl detection-as-code with CI-built app, CIM/tstats detections mapped to MITRE ATT&CK, and Suricata EVE ingest.
SIEM & threat detection case files documenting SSH brute-force attacks and endpoint security investigations in Splunk
To associate your repository with the botsv1 topic, visit your repo's landing page and select "manage topics."