Hands-on Workshop

Splunk Attack Analyzer with Splunk Enterprise & Splunk SOAR

Get hands-on with Splunk to automate threat analysis and accelerate response.

Investigate Smarter. Respond Faster.

Join us as we explore how Splunk Attack Analyzer, in combination with Splunk Enterprise and Splunk SOAR, can help organisations streamline threat investigation and automate the analysis of phishing and malware-based attacks. This hands-on workshop is designed to provide practical experience in using these solutions to detect, analyse, and respond to real-world threats.

In this session, we’ll guide you through the core features and workflows of Splunk Attack Analyzer and demonstrate how it integrates seamlessly with Splunk’s wider security ecosystem to accelerate response times and reduce analyst workload.

Discover how Splunk enables you to submit suspicious emails, files, and URLs, review rich analysis reports, and trigger automated playbooks in Splunk SOAR — helping your teams stay ahead of evolving threats. Whether you’re enhancing an existing SOC workflow or looking to improve how threats are triaged, this session will deliver actionable insights you can apply immediately.

The lab environment includes access to Splunk Enterprise, Splunk Attack Analyzer, and Splunk SOAR, and will remain available after the session, allowing you to continue exploring integrations and automation at your own pace.

Agenda

  • Introductions
  • Overview of Splunk Attack Analyzer
  • Submitting and analysing phishing and malware threats
  • Using Splunk Enterprise to explore correlated threat data
  • Triggering playbooks with Splunk SOAR
  • End-to-end threat response walkthrough
  • Conclusion / Q&A

Meet the Expert

Jake Hamacott Somerford Associates

Jake Hammacott

Splunk Security Technical Expert at Somerford

Who Should Attend

  • Security analysts, incident responders, and SOC team members.
  • Practitioners focused on phishing, malware, and email threat investigation.
  • Teams looking to integrate automated threat analysis into existing Splunk environments.
  • Anyone exploring how Splunk can support rapid threat detection and response workflows.

Additional Information

  • This session is ideal for organisations managing industrial assets or critical infrastructure.
  • Our experts will provide hands-on guidance, technical walkthroughs, and live demonstrations using Splunk Attack Analyser, Splunk App for Attack Analyzer and Splunk SOAR features.
  • Lab access will remain available after the session so you can continue exploring at your own pace.

If you have any problems or require support, please email: marketing@somerfordassociates.com

Resources

What is Splunk Edge Hub?

How is Splunk Cloud Architected?

Top 5 Splunk Use Cases

Have any Questions?

Feel free to reach out to us with any questions about the event.

Scroll to Top