icon/x Created with Sketch.

Splunk Cookie Policy

We use our own and third-party cookies to provide you with a great online experience. We also use these cookies to improve our products and services, support our marketing campaigns, and advertise to you on our website and other websites. Some cookies may continue to collect information after you have left our website. Learn more (including how to update your settings) here.
Accept Cookie Policy

We are working on something new...

A Fresh New Splunkbase
We are designing a New Splunkbase to improve search and discoverability of apps. Check out our new and improved features like Categories and Collections. New Splunkbase is currently in preview mode, as it is under active development. We welcome you to navigate New Splunkbase and give us feedback.

Accept License Agreements

Thank You

Downloading ThreatConnect
SHA256 checksum (threatconnect_301.tgz) e225f561440bd3af233704124d3eaaf45c110c7e588ceef982b14a7249c11f2e SHA256 checksum (threatconnect_300.tgz) add949bc214767ca92a912f7ad4f8263dddf0841e98661e604d20b16b33e7ccf SHA256 checksum (threatconnect_227.tgz) 5aa0426210b8ea98381989cb748bd1a72c7af7377bf434d337e98466b7b2323a SHA256 checksum (threatconnect_226.tgz) ff4c19db7d95ce05eba96e78369fe4f224a1c66ccf93ce3d9b57a977e86e8f57 SHA256 checksum (threatconnect_225.tgz) 5131df85857e35097f2ae63f4cadcc45e70dafd8cb6e8545523435c9b5f30a6b SHA256 checksum (threatconnect_223.tgz) 988ecb67b87bf724d92723ed38e35e26277e2a799b6b446398afd20036051edd SHA256 checksum (threatconnect_213.tgz) 00513b043baa38dad40bbfd4ac624e6486712b8302ac281a3a6ccba4321a8741

Flag As Inappropriate

soar

ThreatConnect

Splunk SOAR Cloud
Splunk Built
Overview
This app integrates with the ThreatConnect platform to provide various hunting actions in addition to threat ingestion

Supported Actions Version 3.0.1

  • on poll: Callback action for the on_poll ingest functionality
  • test connectivity: Validate the asset configuration for connectivity
  • list owners: List the owners visible with the configured credentials
  • post data: Create an indicator and post it to ThreatConnect
  • hunt ip: Hunt an IP and retrieve any available information
  • hunt file: Hunt a file hash and retrieve available information
  • hunt email: Hunt an email and retrieve available information
  • hunt domain: Hunt a domain and retrieve available information
  • hunt url: Hunt a URL and retrieve available information

Supported Actions Version 3.0.0

  • on poll: Callback action for the on_poll ingest functionality
  • test connectivity: Validate the asset configuration for connectivity
  • list owners: List the owners visible with the configured credentials
  • post data: Create an indicator and post it to ThreatConnect
  • hunt ip: Hunt an IP and retrieve any available information
  • hunt file: Hunt a file hash and retrieve available information
  • hunt email: Hunt an email and retrieve available information
  • hunt domain: Hunt a domain and retrieve available information
  • hunt url: Hunt a URL and retrieve available information

Supported Actions Version 2.2.7

  • on poll: Callback action for the on_poll ingest functionality
  • test connectivity: Validate the asset configuration for connectivity
  • list owners: List the owners visible with the configured credentials
  • post data: Create an indicator and post it to ThreatConnect
  • hunt ip: Hunt an IP and retrieve any available information
  • hunt file: Hunt a file hash and retrieve available information
  • hunt email: Hunt an email and retrieve available information
  • hunt domain: Hunt a domain and retrieve available information
  • hunt url: Hunt a URL and retrieve available information

Supported Actions Version 2.2.6

  • on poll: Callback action for the on_poll ingest functionality
  • test connectivity: Validate the asset configuration for connectivity
  • list owners: List the owners visible with the configured credentials
  • post data: Create an indicator and post it to ThreatConnect
  • hunt ip: Hunt an IP and retrieve any available information
  • hunt file: Hunt a file hash and retrieve available information
  • hunt email: Hunt an email and retrieve available information
  • hunt domain: Hunt a domain and retrieve available information
  • hunt url: Hunt a URL and retrieve available information

Supported Actions Version 2.2.5

  • on poll: Callback action for the on_poll ingest functionality
  • test connectivity: Validate the asset configuration for connectivity
  • list owners: List the owners visible with the configured credentials
  • post data: Create an indicator and post it to ThreatConnect
  • hunt ip: Hunt an IP and retrieve any available information
  • hunt file: Hunt a file hash and retrieve available information
  • hunt email: Hunt an email and retrieve available information
  • hunt domain: Hunt a domain and retrieve available information
  • hunt url: Hunt a URL and retrieve available information

Supported Actions Version 2.2.3

  • on poll: Callback action for the on_poll ingest functionality
  • test connectivity: Validate the asset configuration for connectivity
  • list owners: List the owners visible with the configured credentials
  • post data: Create an indicator and post it to ThreatConnect
  • hunt ip: Hunt an IP and retrieve any available information
  • hunt file: Hunt a file hash and retrieve available information
  • hunt email: Hunt an email and retrieve available information
  • hunt domain: Hunt a domain and retrieve available information
  • hunt url: Hunt a URL and retrieve available information

Supported Actions Version 2.1.3

  • on poll: Callback action for the on_poll ingest functionality
  • test connectivity: Validate the asset configuration for connectivity
  • list owners: List the owners visible with the configured credentials
  • post data: Create an indicator and post it to ThreatConnect
  • hunt ip: Hunt an IP and retrieve any available information
  • hunt file: Hunt a file hash and retrieve available information
  • hunt email: Hunt an email and retrieve available information
  • hunt domain: Hunt a domain and retrieve available information
  • hunt url: Hunt a URL and retrieve available information

Release Notes

Version 3.0.1
April 11, 2025
  • Update Python dependencies for vulnerabilities, package updates, and platform built-in removals
  • Update Python dependencies for Python 3.13 support
  • Update NOTICE file with updated dependencies
  • Apply pre-commit fixes
Version 3.0.0
March 31, 2025

Unreleased * Moved API support from V2 to V3 * Action hunt ip gained 3 new boolean parameters controlling which data is retrieved for Indicators: attribute, tag, and security label * Action hunt file gained 3 new boolean parameters controlling which data is retrieved for Indicators: attribute, tag, and security label * Action hunt email gained 3 new boolean parameters controlling which data is retrieved for Indicators: attribute, tag, and security label * Action hunt domain gained 3 new boolean parameters controlling which data is retrieved for Indicators: attribute, tag, and security label * Action hunt url gained 3 new boolean parameters controlling which data is retrieved for Indicators: attribute, tag, and security label * As a result, the output data paths have been updated. To ensure your existing playbooks function correctly, please update, reinsert, modify, or delete the affected action blocks accordingly.

Version 2.2.7
July 31, 2023
  • Removed django and requests dependencies in order to use platform packages [PAPP-31087, PAPP-31082, PAPP-31096, PAPP-30822]
Version 2.2.6
May 19, 2023
  • Update Django module per [CVE-2022-28347] [CVE-2022-36359] - [PAPP-30335]
Version 2.2.5
Feb. 4, 2022

ThreatConnect Release Notes - Published by Splunk February 04, 2022

Version 2.2.5 - Released February 04, 2022

  • Marked the app as FIPS Compliant [PAPP-21696]
  • Added support for Python 3.9
Version 2.2.3
Nov. 17, 2021

ThreatConnect Release Notes - Published by Splunk November 17, 2021

Version 2.2.3 - Released November 17, 2021

  • Added the Fields into post data action [PAPP-4815]
Version 2.1.3
Sept. 21, 2021

ThreatConnect Release Notes - Published by Splunk August 16, 2021

Version 2.1.3 - Released August 16, 2021

  • Minor bug fix in schedule poll [PAPP-17216]

Subscribe Share

Are you a developer?

As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 10GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps from Splunk, our partners and our community. Find an app for most any data source and user need, or simply create your own with help from our developer portal.

Follow Us:
Splunk, Splunk>,Turn Data Into Doing, Data-to-Everything, and D2E are trademarks or registered trademarks of Splunk LLC in the United States and other countries. All other brand names,product names,or trademarks belong to their respective owners.