The ReversingLabs TitaniumScale Dashboard application for Splunk is a custom security and threat intelligence visualization solution that interprets extensive sets of ReversingLabs TitaniumScale file analysis reports on the Splunk platform.
The Splunk platform receives JSON reports over HTTP or HTTPS from the TitaniumScale product and enables detailed search and interpretation of analyzed files through this application.
By providing visualization of potentially harmful and malicious files, this application can prevent potential malware from harming the user environment by detecting it and making it visible to threat analysts.
ReversingLabs TitaniumScale provides advanced static file analysis methods and file visibility for exposing potential attacks before they strike.
“TitaniumScale helps enterprises form a comprehensive assessment of millions of files from web traffic, email, file transfers, endpoints or storage. The solution uses unique ReversingLabs File Decomposition technology to extract detailed metadata, add global reputation context and classify threats.”
The ReversingLabs TitaniumScale Dashboard app for Splunk can be used for:
- Breaking down analyzed files by type
- Displaying file type statistics
- Summarizing files by threat level
- Displaying threat type statistics
- Searching file reports by:
- File names or hash values
- Threat names
- File types
- Import hashes
- YARA matches
- Certificates
$SPLUNK_HOME/bin/splunk remove app reversinglabs <username>:<password>
https://www.reversinglabs.com/products/enterprise-scale-file-visibility.html
ReversingLabs TitaniumScale visualization for Splunk version 1.0.1
- minor configuration changes
- added a detailed user manual
Initial release.
The app provides detailed search, visualization and analysis of ReversingLabs TitaniumScale file report data.
As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 10GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps from Splunk, our partners and our community. Find an app for most any data source and user need, or simply create your own with help from our developer portal.