Splunk Add-on
Ingest DarkStrata credential-exposure intelligence into Splunk and Enterprise Security
Overview
The DarkStrata Threat Intelligence Add-on for Splunk brings DarkStrata's credential-exposure intelligence directly into Splunk and Splunk Enterprise Security (ES). It provides two modular inputs that pull threat intelligence in STIX 2.1 format, maps it to the Common Information Model, and ships pre-built knowledge objects, correlation searches and adaptive-response actions for your SOC.
Use it to:
- Detect compromised credentials before they're used maliciously
- Identify malware infections through infostealer credential detection
- Monitor third-party risk by tracking corporate credentials exposed on external sites
- Automate incident response via ES notable events and adaptive-response actions
- Enrich threat hunting with credential-exposure context
Requirements
| Component | Minimum | Recommended |
|---|---|---|
| Splunk Enterprise | 9.0.0 | Latest 9.x / 10.x |
| Splunk Cloud | Victoria Experience | Latest |
| Splunk Enterprise Security (optional) | 7.0.0 | 7.3+ |
You will also need:
- An active DarkStrata subscription and an API key with the
siem:readscope - Outbound HTTPS connectivity to
api.darkstrata.io(port 443) - Python 3.9+ (bundled with Splunk 9.0+)
Enterprise Security is only required for the correlation searches and adaptive-response actions - the modular inputs and CIM mappings work on Splunk Enterprise and Splunk Cloud without ES.
Installation
From Splunkbase (recommended)
- In Splunk Web, go to Apps > Find More Apps.
- Search for DarkStrata and select the Threat Intelligence Add-on.
- Click Install, enter your Splunk.com credentials if prompted, and restart Splunk when asked.
- Or install directly from our official Splunkbase listing.
Manual installation
Download the latest TA-darkstrata-x.x.x.tar.gz from the GitHub releases page, then either upload it via Apps > Manage Apps > Install app from file, or install from the command line:
tar -xzf TA-darkstrata-x.x.x.tar.gz -C $SPLUNK_HOME/etc/apps/
$SPLUNK_HOME/bin/splunk restartConfiguration
1. Add your account
Open the add-on's Configuration page and add an account on the Account tab:
- API Base URL -
https://api.darkstrata.io/v1 - API Key - your DarkStrata key with the
siem:readscope
The key is validated against the API when you save, and stored encrypted using Splunk's credential store. Optional Proxy, Performance and Loggingtabs let you configure an HTTP/SOCKS5 proxy, batch size and rate limiting, and the log level.
2. Create inputs
On the Inputs page, create one or both modular inputs:
| Input | Endpoint | Purpose |
|---|---|---|
| Indicators | /stix/indicators | Streaming credential-exposure indicators (observed-data) |
| Alerts | /stix/alerts | Credential-exposure alert bundles for your monitored assets |
Each input supports:
- Confidence threshold - only ingest events at or above a STIX confidence score
- Hash emails - optionally SHA-256 hash email addresses for privacy/compliance
- Interval - collection is incremental and checkpoint-based, so each run fetches only new data
Data & sourcetypes
Events are written in STIX 2.1 JSON under two sourcetypes:
| Sourcetype | Contents |
|---|---|
darkstrata:stix:observed-data | Individual credential-exposure indicators |
darkstrata:stix:alert | Alert bundles (report plus referenced observed-data) |
Fields are mapped to the Authentication and Threat IntelligenceCIM data models, and the add-on ships event types, tags, macros and lookups so the data is ready for search, dashboards and acceleration. Try:
sourcetype=darkstrata:stix:observed-data
| stats count by darkstrata_source_type, darkstrata_flowEnterprise Security integration
When installed alongside Splunk ES, the add-on adds:
- Threat-intelligence collections that feed the ES threat-intel framework
- Correlation searches that raise notable events on credential exposure
- Adaptive-response actions to act on DarkStrata alerts directly from a notable event:
- Update Alert Status
- Close Alert
- Reopen Alert
- Get Alert Details (enrichment)
These actions call back to the DarkStrata API over verified TLS, keeping alert state in sync between Splunk and DarkStrata.
SOAR & automation
The add-on includes sample Splunk SOAR playbooks - credential-exposure triage, auto-acknowledge and alert enrichment - that you can adapt to your own workflows, plus a REST API reference for custom integrations.
Troubleshooting
- If saving an account fails, confirm the API key has the
siem:readscope and that Splunk has outbound HTTPS access toapi.darkstrata.io. - No events? Lower the confidence threshold, check the input is enabled, and review the add-on logs (set the level on the Logging tab).
- Behind a proxy? Configure it on the Proxy tab; both HTTP and SOCKS5 are supported.
Resources & support
For the full API reference and integration guides, see the developer documentation. If you need a hand, our team is happy to help.