Super Speed with Phantom Slash Commands

Are you the type of person who loves the command-line? Is tab-complete your friend? Do you move faster on a keyboard than with a mouse? Then Phantom Slash Commands are for you!

What Are They?

In short, slash commands are a command-line interface for investigating Phantom events. Slash commands are instructions written into Splunk Phantom’s activity pane text box that begin with a forward slash ( / ) followed by a command. These allow you to run playbooks and actions by simply typing into your CLI, saving you time and effort by removing the need for excess mouse clicks. Paired with keyboard navigation from Phantom’s 508 compliance, slash commands are a powerful tool for every Phantom user.

Here is a screenshot of where they appear in the Phantom UI:

As you can see, when you start with a forward-slash Phantom automatically gives you a list of available commands. Here is a full list in text form:

Features of Slash Commands

Slash commands come with some excellent accessibility features and in a few cases, are quicker than the same process using just a mouse and keyboard. For example, as I type /action, Phantom shows me the full syntax for executing an action.

In addition to showing proper syntax, Slash commands feature suggested arguments and allows you to tab auto-complete your word, as well as use the keyboard directional keys to select which item from the pop-out menu you want to select.

How to Use Slash Commands

Now let's return to our example of executing an action. After I select the “/action” command, it's time to pick which action to use.

But “Wait!”, you say. “What if I don’t know which action I can run?” “What if I don’t know the name of the app?” Don’t worry, Phantom has you covered here. As I press space, Phantom shows me all the available actions.

I can either click the action with a mouse, type in the first letters and use tab auto-complete, or use the keyboard directional keys to select an action and press enter.

Next, Phantom shows me which apps are available to perform the action that I selected. In this case it is showing “VirusTotal” and “Recorded Future” — the two apps that I have configured to do “ip_reputation.”

Finally, I need to enter an IP address to execute my “ip_reputation.” Optionally, you can enter the name of a specific asset, if you have multiple to pick from, with the optional flag “--asset.” In this case, I only have one configured asset for VirusTotal.

In the next screenshot, you can see my command in the audit trail and the resulting summary. Turns out that quite a few URLs talk out to this IP address (who knew!).

I can also use the new enhanced keyboard navigation to select the details of the IP Reputation action and get a full screen view.

Lastly, it wouldn’t be a command-line interface without a --help command. If you’re ever lost you can always enter --help to figure out what information is required.

This is just a small walkthrough of what you can do with the power of Slash Commands. Tune in to our webinar, "Super Speed with Phantom Slash Commands" to see an in depth demo on how Slash Commands speed up investigations to save you time and effort.

This blog post is co-authored by Olivia Courtney and Kelby Shelton.

Related Articles

Predicting Cyber Fraud Through Real-World Events: Insights from Domain Registration Trends
Security
12 Minute Read

Predicting Cyber Fraud Through Real-World Events: Insights from Domain Registration Trends

By analyzing new domain registrations around major real-world events, researchers show how fraud campaigns take shape early, helping defenders spot threats before scams surface.
When Your Fraud Detection Tool Doubles as a Wellness Check: The Unexpected Intersection of Security and HR
Security
4 Minute Read

When Your Fraud Detection Tool Doubles as a Wellness Check: The Unexpected Intersection of Security and HR

Behavioral analytics can spot fraud and burnout. With UEBA built into Splunk ES Premier, one data set helps security and HR reduce risk, retain talent, faster.
Splunk Security Content for Threat Detection & Response: November Recap
Security
1 Minute Read

Splunk Security Content for Threat Detection & Response: November Recap

Discover Splunk's November security content updates, featuring enhanced Castle RAT threat detection, UAC bypass analytics, and deeper insights for validating detections on research.splunk.com.
Security Staff Picks To Read This Month, Handpicked by Splunk Experts
Security
2 Minute Read

Security Staff Picks To Read This Month, Handpicked by Splunk Experts

Our Splunk security experts share their favorite reads of the month so you can follow the most interesting, news-worthy, and innovative stories coming from the wide world of cybersecurity.
Behind the Walls: Techniques and Tactics in Castle RAT Client Malware
Security
10 Minute Read

Behind the Walls: Techniques and Tactics in Castle RAT Client Malware

Uncover CastleRAT malware's techniques (TTPs) and learn how to build Splunk detections using MITRE ATT&CK. Protect your network from this advanced RAT.
AI for Humans: A Beginner’s Field Guide
Security
12 Minute Read

AI for Humans: A Beginner’s Field Guide

Unlock AI with the our beginner's field guide. Demystify LLMs, Generative AI, and Agentic AI, exploring their evolution and critical cybersecurity applications.
Splunk Security Content for Threat Detection & Response: November 2025 Update
Security
5 Minute Read

Splunk Security Content for Threat Detection & Response: November 2025 Update

Learn about the latest security content from Splunk.
Operation Defend the North: What High-Pressure Cyber Exercises Teach Us About Resilience and How OneCisco Elevates It
Security
3 Minute Read

Operation Defend the North: What High-Pressure Cyber Exercises Teach Us About Resilience and How OneCisco Elevates It

The OneCisco approach is not about any single platform or toolset; it's about fusing visibility, analytics, and automation into a shared source of operational truth so that teams can act decisively, even in the fog of crisis.
Data Fit for a Sovereign: How to Consider Sovereignty in Your Digital Resilience Strategy
Security
5 Minute Read

Data Fit for a Sovereign: How to Consider Sovereignty in Your Digital Resilience Strategy

Explore how digital sovereignty shapes resilient strategies for European organisations. Learn how to balance control, compliance, and agility in your data infrastructure with Cisco and Splunk’s flexible, secure solutions for the AI era.