The Splunk Attack Range framework allows the use of adversarial simulation engines – along with tools for measurement, translation, verification and recording in defence technologies that help streamline the process of creating defence artefacts (signatures, detection, investigation, analytics, playbooks and so on). This framework enables an enterprise defender to keep up with the rapidly evolving threat landscape and allows an analyst to produce data and to:Visualise and record attacks;Translate attacks into measurable data;Drive defence artefacts based on produced data (firewall, endpoint, Snort, etc);Test malicious/exploit code in a safe and isolated environment;Translate defence artefacts into the Splunk environment (detection, investigation, analytics, SOAR playbooks); andShare artefacts (detection/investigation using Splunk Search Processing Language, Splunk apps and data models, both within the enterprise and within the community).