Splunk SIEM investigation lab with SPL detection rules, BOTS dataset analysis, and IR reports mapped to MITRE ATT&CK
-
Updated
Jun 14, 2026
Splunk SIEM investigation lab with SPL detection rules, BOTS dataset analysis, and IR reports mapped to MITRE ATT&CK
SOC investigation into external web reconnaissance and username enumeration attack against a vBulletin forum server using Splunk BOTS v3.
SOC investigation into anomalous internal host behaviour using Splunk BOTS v3 — cross-sourcetype analysis across HTTP, DNS, and Windows endpoint logs leading to a false positive determination.
Add a description, image, and links to the bots-v3 topic page so that developers can more easily learn about it.
To associate your repository with the bots-v3 topic, visit your repo's landing page and select "manage topics."