Skip to main content

contentctl

The Future of contentctl

We are shifting future investment from contentctl to Detection Studio as we work to bring this functionality into Splunk as an officially supported capability. This repository will remain publicly available for reference, but we are no longer accepting new pull requests or feature requests. Going forward, continued use of contentctl may require customer-managed customization to support specific environments and requirements.

the logo for the contentctl project, which depicts a doodled 4 legged animal that is supposed to represent a capybara, with the name of the project below it

What is contentctl?

contentctl is a tool developed by the Splunk Threat Research Team to help with managing the content living in splunk/security_content and producing the Enterprise Security Content Update app for Splunk. While its development is largely driven by STRT's needs, it has been somewhat genericized and can be used by customers and partners to package their own content. Simply put, contentctl is the workhorse that packages detections, macros, lookups, dashboards into a Splunk app that you can use, and that understands the YAML structure and project layout we've selected to keep development clean.

Quick Start Guide

Check out our User Guide to get started!

Content Testing

Read more about how contentctl can help test and validate your content in a real Splunk instance here.

Sample CICD Workflows

Already using contentctl, or looking to get started with it already configured in GitHub Actions? Our guide includes workflows to help you build and test your app.

Ecosystem

Project Description
Splunk Security Content Splunk Threat Research Team's Content included in the Enterprise Security Content Update App (ESCU)
Splunk Attack Range Easily deploy a preconfigured Splunk Environment locally or on AWS containing a Splunk Instance, Windows and Linux Machines, and Attacker Tools like Kali Linux. Automatically simulate attacks or run your own
Splunk Attack Data Repository of Attack Simulation Data for writing and Testing Detections
Splunk contentctl Generate, validate, build, test, and deploy custom Security Content
SigmaHQ Sigma Rules Official Repository for Sigma Rules. These rules are an excellent starting point for new content.
PurpleSharp Attack Simulation Open source adversary simulation tool for Windows Active Directory environments (integrated into Attack Range)
Red Canary Atomic Red Team Library of attack simulations mapped to the MITRE ATT&CK® framework (integrated into Attack Range)

License

Copyright 2023 Splunk Inc.

Licensed under the Apache License, Version 2.0 (the "License"); you may not use this file except in compliance with the License. You may obtain a copy of the License at

http://www.apache.org/licenses/LICENSE-2.0

Unless required by applicable law or agreed to in writing, software distributed under the License is distributed on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the License for the specific language governing permissions and limitations under the License.

Metadata

Release files for contentctl 5.6.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for contentctl 5.6.1
File Size Uploaded
contentctl-5.6.1.tar.gz 235.1 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for contentctl 5.6.1
File Interpreter ABI Platform
contentctl-5.6.1-py3-none-any.whl Python 3 none any Details

Total release size: 535.6 kB

Release files / contentctl-5.6.1.tar.gz

Download URL contentctl-5.6.1.tar.gz
Size 235.1 kB
Tags Source
SHA-256 checksum
How to use checksums
a2abaeb13a2106718dcc28e2f34d6489a53d9c9ed4d7cfd65966f5bd7ba2ce8f
BLAKE2b-256 checksum
How to use checksums
e8d48c733d0cf955ed00608fcbbcce7878e1758608d2744aaf42031967e0fb99
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via poetry/2.4.2 CPython/3.11.16 Linux/6.8.0-1064-azure

Release files / contentctl-5.6.1-py3-none-any.whl

Download URL contentctl-5.6.1-py3-none-any.whl
Size 300.5 kB
Tags Python 3
SHA-256 checksum
How to use checksums
1fa61070948dc9c6b62d3a67872489f801ae89d040c97b0ebb99a6847960a83a
BLAKE2b-256 checksum
How to use checksums
f1aa2fa224f7453eb9873855e02f079b013c01db215b5e11930f32408852ed62
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via poetry/2.4.2 CPython/3.11.16 Linux/6.8.0-1064-azure

Release history Release notifications | RSS feed

This release

5.6.1 This release

2 release files

5.6.0

2 release files

5.5.15

2 release files

5.5.10

2 release files

5.5.9

2 release files

5.5.8

2 release files

5.5.7

2 release files

5.5.6

2 release files

5.5.5

2 release files

5.5.4

2 release files

5.5.3

2 release files

5.5.2

2 release files

5.5.1

2 release files

5.5.0

2 release files

5.4.1

2 release files

5.4.0

2 release files

5.3.2

2 release files

5.3.1

2 release files

5.3.0

2 release files

5.2.0

2 release files

5.1.0

2 release files

5.0.5

2 release files

5.0.4

2 release files

5.0.3

2 release files

5.0.2

2 release files

5.0.1

2 release files

5.0.0

2 release files

4.4.7

2 release files

4.4.6

2 release files

4.4.5

2 release files

4.4.4

2 release files

4.4.3

2 release files

4.4.1

2 release files

4.4.0

2 release files

4.3.5

2 release files

4.3.4

2 release files

4.3.3

2 release files

4.3.2

2 release files

4.3.1

2 release files

4.3.0

2 release files

4.2.5

2 release files

4.2.4

2 release files

4.2.2

2 release files

4.2.1

2 release files

4.2.0

2 release files

4.1.5

2 release files

4.1.4

2 release files

4.1.3

2 release files

4.1.2

2 release files

4.1.1

2 release files

4.1.0

2 release files

4.0.5

2 release files

4.0.4

2 release files

4.0.3

2 release files

4.0.2

2 release files

4.0.1

2 release files

3.6.0

2 release files

3.5.0

2 release files

3.4.3

2 release files

3.4.2

2 release files

3.4.1

2 release files

3.4.0

2 release files

3.3.0

2 release files

3.2.0

2 release files

3.1.0

2 release files

3.0.2

2 release files

3.0.1

2 release files

3.0.0

2 release files

2.0.1

2 release files

2.0.0

2 release files

1.0.1

2 release files

1.0.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page