diff --git a/playbooks/AD_LDAP_Account_Locking.yml b/playbooks/AD_LDAP_Account_Locking.yml index de25477e50..36717dec74 100644 --- a/playbooks/AD_LDAP_Account_Locking.yml +++ b/playbooks/AD_LDAP_Account_Locking.yml @@ -10,7 +10,7 @@ how_to_implement: This input playbook requires the Microsoft AD LDAP connector t It is designed to work in conjunction with the Dynamic Attribute Lookup playbook or other playbooks in the same style. references: [] app_list: - - AD LDAP API + - AD LDAP tags: platform_tags: - user @@ -22,3 +22,7 @@ tags: playbook_fields: [] product: - Splunk SOAR + use_cases: + - Phishing + - Endpoint + defend_technique_id: D3-AL \ No newline at end of file diff --git a/playbooks/AD_LDAP_Entity_Attribute_Lookup.yml b/playbooks/AD_LDAP_Entity_Attribute_Lookup.yml index 9b98ce7457..6df100865b 100644 --- a/playbooks/AD_LDAP_Entity_Attribute_Lookup.yml +++ b/playbooks/AD_LDAP_Entity_Attribute_Lookup.yml @@ -20,4 +20,6 @@ tags: vpe_type: Modern playbook_fields: [] product: - - Splunk SOAR \ No newline at end of file + - Splunk SOAR + use_cases: + - Enrichment \ No newline at end of file diff --git a/playbooks/AWS_IAM_Account_Locking.yml b/playbooks/AWS_IAM_Account_Locking.yml index 9430bcf0e1..390f78d66f 100644 --- a/playbooks/AWS_IAM_Account_Locking.yml +++ b/playbooks/AWS_IAM_Account_Locking.yml @@ -10,7 +10,7 @@ how_to_implement: This input playbook requires the AWS IAM connector to be confi It is designed to work in conjunction with the Dynamic Attribute Lookup playbook or other playbooks in the same style. references: [] app_list: - - AWS IAM API + - AWS IAM tags: platform_tags: - user @@ -21,4 +21,8 @@ tags: vpe_type: Modern playbook_fields: [] product: - - Splunk SOAR \ No newline at end of file + - Splunk SOAR + use_cases: + - Phishing + - Endpoint + defend_technique_id: D3-AL \ No newline at end of file diff --git a/playbooks/Active_Directory_Disable_Account_Dispatch.yml b/playbooks/Active_Directory_Disable_Account_Dispatch.yml index a559491c4d..7b288dd89b 100644 --- a/playbooks/Active_Directory_Disable_Account_Dispatch.yml +++ b/playbooks/Active_Directory_Disable_Account_Dispatch.yml @@ -10,9 +10,8 @@ playbook: Active_Directory_Disable_Account_Dispatch how_to_implement: This automatic playbook requires "disable_account" tag be present on each input playbook you want to launch. references: [] app_list: - - microsoft_ad_ldap - - azure_ad_graph - - aws_iam + - AD LDAP + - Azure AD Graph tags: platform_tags: - user @@ -22,4 +21,8 @@ tags: vpe_type: Modern playbook_fields: [] product: - - Splunk SOAR \ No newline at end of file + - Splunk SOAR + use_cases: + - Phishing + - Endpoint + defend_technique_id: D3-AL \ No newline at end of file diff --git a/playbooks/Attribute_Lookup_Dispatch.yml b/playbooks/Attribute_Lookup_Dispatch.yml index 63ac503fd9..6ba8311e5c 100644 --- a/playbooks/Attribute_Lookup_Dispatch.yml +++ b/playbooks/Attribute_Lookup_Dispatch.yml @@ -16,3 +16,5 @@ tags: playbook_fields: [] product: - Splunk SOAR + use_cases: + - Enrichment \ No newline at end of file diff --git a/playbooks/Azure_AD_Account_Locking.yml b/playbooks/Azure_AD_Account_Locking.yml index 8835daf6c5..c6f9a19f6d 100644 --- a/playbooks/Azure_AD_Account_Locking.yml +++ b/playbooks/Azure_AD_Account_Locking.yml @@ -10,7 +10,7 @@ how_to_implement: This input playbook requires the Azure AD Graph connector to b It is designed to work in conjunction with the Dynamic Attribute Lookup playbook or other playbooks in the same style. references: [] app_list: - - Azure AD Graph API + - Azure AD Graph tags: platform_tags: - user @@ -22,3 +22,7 @@ tags: playbook_fields: [] product: - Splunk SOAR + use_cases: + - Phishing + - Endpoint + defend_technique_id: D3-AL diff --git a/playbooks/Azure_AD_Graph_User_Attribute_Lookup.yml b/playbooks/Azure_AD_Graph_User_Attribute_Lookup.yml index a5a3d4abfa..af8b703ab6 100644 --- a/playbooks/Azure_AD_Graph_User_Attribute_Lookup.yml +++ b/playbooks/Azure_AD_Graph_User_Attribute_Lookup.yml @@ -20,4 +20,6 @@ tags: vpe_type: Modern playbook_fields: [] product: - - Splunk SOAR \ No newline at end of file + - Splunk SOAR + use_cases: + - Enrichment \ No newline at end of file diff --git a/playbooks/Cisco_Umbrella_DNS_Denylisting.yml b/playbooks/Cisco_Umbrella_DNS_Denylisting.yml index d60ea29383..98bfbb63cb 100644 --- a/playbooks/Cisco_Umbrella_DNS_Denylisting.yml +++ b/playbooks/Cisco_Umbrella_DNS_Denylisting.yml @@ -22,3 +22,7 @@ tags: playbook_fields: [] product: - Splunk SOAR + use_cases: + - Phishing + - Endpoint + defend_technique_id: D3-DNSDL diff --git a/playbooks/CrowdStrike_OAuth_API_Device_Attribute_Lookup.yml b/playbooks/CrowdStrike_OAuth_API_Device_Attribute_Lookup.yml index 3df08bd472..ad6eeb0244 100644 --- a/playbooks/CrowdStrike_OAuth_API_Device_Attribute_Lookup.yml +++ b/playbooks/CrowdStrike_OAuth_API_Device_Attribute_Lookup.yml @@ -23,3 +23,6 @@ tags: playbook_fields: [] product: - Splunk SOAR + use_cases: + - Enrichment + - Endpoint diff --git a/playbooks/CrowdStrike_OAuth_API_Dynamic_Analysis.yml b/playbooks/CrowdStrike_OAuth_API_Dynamic_Analysis.yml index 441e004c36..8cf8cfba15 100644 --- a/playbooks/CrowdStrike_OAuth_API_Dynamic_Analysis.yml +++ b/playbooks/CrowdStrike_OAuth_API_Dynamic_Analysis.yml @@ -23,3 +23,8 @@ tags: playbook_fields: [] product: - Splunk SOAR + use_cases: + - Enrichment + - Phishing + - Endpoint + defend_technique_id: D3-DA diff --git a/playbooks/CrowdStrike_OAuth_API_Identifier_Activity_Analysis.yml b/playbooks/CrowdStrike_OAuth_API_Identifier_Activity_Analysis.yml index 6f2199de38..5e13c7131a 100644 --- a/playbooks/CrowdStrike_OAuth_API_Identifier_Activity_Analysis.yml +++ b/playbooks/CrowdStrike_OAuth_API_Identifier_Activity_Analysis.yml @@ -20,3 +20,7 @@ tags: playbook_fields: [] product: - Splunk SOAR + use_cases: + - Enrichment + - Endpoint + defend_technique_id: D3-IAA diff --git a/playbooks/DNS_Denylisting_Dispatch.yml b/playbooks/DNS_Denylisting_Dispatch.yml index 6840f5382f..30369b9ef6 100644 --- a/playbooks/DNS_Denylisting_Dispatch.yml +++ b/playbooks/DNS_Denylisting_Dispatch.yml @@ -17,4 +17,8 @@ tags: vpe_type: Modern playbook_fields: [] product: - - Splunk SOAR \ No newline at end of file + - Splunk SOAR + use_cases: + - Phishing + - Endpoint + defend_technique_id: D3-DNSDL \ No newline at end of file diff --git a/playbooks/Dynamic_Analysis_Dispatch.yml b/playbooks/Dynamic_Analysis_Dispatch.yml index 2a642f1fd5..5e7d282b74 100644 --- a/playbooks/Dynamic_Analysis_Dispatch.yml +++ b/playbooks/Dynamic_Analysis_Dispatch.yml @@ -9,11 +9,7 @@ description: Automatically dispatches input playbooks with the 'sandbox' tag. playbook: Dynamic_Analysis_Dispatch how_to_implement: This automatic playbook requires "sandbox" tag be present on each input playbook you want to launch. references: [] -app_list: - - CrowdStrike OAuth API - - urlscan.io - - VirusTotal_v3 - - SAA +app_list: [] tags: platform_tags: - url @@ -25,4 +21,9 @@ tags: vpe_type: Modern playbook_fields: [] product: - - Splunk SOAR \ No newline at end of file + - Splunk SOAR + use_cases: + - Enrichment + - Phishing + - Endpoint + defend_technique_id: D3-DA \ No newline at end of file diff --git a/playbooks/G_Suite_for_GMail_Message_Identifier_Activity_Analysis.yml b/playbooks/G_Suite_for_GMail_Message_Identifier_Activity_Analysis.yml index d4277770c5..4c7c0f0004 100644 --- a/playbooks/G_Suite_for_GMail_Message_Identifier_Activity_Analysis.yml +++ b/playbooks/G_Suite_for_GMail_Message_Identifier_Activity_Analysis.yml @@ -20,3 +20,6 @@ tags: playbook_fields: [] product: - Splunk SOAR + use_cases: + - Phishing + defend_technique_id: D3-IAA diff --git a/playbooks/Identifier_Activity_Analysis_Dispatch.yml b/playbooks/Identifier_Activity_Analysis_Dispatch.yml index 0d8119bfe0..acefe70dcf 100644 --- a/playbooks/Identifier_Activity_Analysis_Dispatch.yml +++ b/playbooks/Identifier_Activity_Analysis_Dispatch.yml @@ -15,4 +15,7 @@ tags: vpe_type: Modern playbook_fields: [] product: - - Splunk SOAR \ No newline at end of file + - Splunk SOAR + use_cases: + - Enrichment + defend_technique_id: D3-IAA \ No newline at end of file diff --git a/playbooks/Identifier_Reputation_Analysis_Dispatch.yml b/playbooks/Identifier_Reputation_Analysis_Dispatch.yml index 0b8e3832ff..c0ad76e13b 100644 --- a/playbooks/Identifier_Reputation_Analysis_Dispatch.yml +++ b/playbooks/Identifier_Reputation_Analysis_Dispatch.yml @@ -18,3 +18,6 @@ tags: playbook_fields: [] product: - Splunk SOAR + use_cases: + - Enrichment + defend_technique_id: D3-IRA diff --git a/playbooks/Panorama_Outbound_Traffic_Filtering.yml b/playbooks/Panorama_Outbound_Traffic_Filtering.yml index 0d11b42dd0..a21d74d803 100644 --- a/playbooks/Panorama_Outbound_Traffic_Filtering.yml +++ b/playbooks/Panorama_Outbound_Traffic_Filtering.yml @@ -21,3 +21,7 @@ tags: playbook_fields: [] product: - Splunk SOAR + use_cases: + - Phishing + - Endpoint + defend_technique_id: D3-OTF diff --git a/playbooks/PhishTank_URL_Reputation_Analysis.yml b/playbooks/PhishTank_URL_Reputation_Analysis.yml index 7d331e797e..a3ad191eed 100644 --- a/playbooks/PhishTank_URL_Reputation_Analysis.yml +++ b/playbooks/PhishTank_URL_Reputation_Analysis.yml @@ -23,3 +23,7 @@ tags: playbook_fields: [] product: - Splunk SOAR + use_cases: + - Enrichment + - Phishing + defend_technique_id: D3-IRA diff --git a/playbooks/Related_Tickets_Search_Dispatch.yml b/playbooks/Related_Tickets_Search_Dispatch.yml index 6b85d030ec..93e1f8165c 100644 --- a/playbooks/Related_Tickets_Search_Dispatch.yml +++ b/playbooks/Related_Tickets_Search_Dispatch.yml @@ -16,4 +16,6 @@ tags: vpe_type: Modern playbook_fields: [] product: - - Splunk SOAR \ No newline at end of file + - Splunk SOAR + use_cases: + - Enrichment \ No newline at end of file diff --git a/playbooks/ServiceNow_Related_Tickets_Search.yml b/playbooks/ServiceNow_Related_Tickets_Search.yml index 5cf7e82961..5e179e05b4 100644 --- a/playbooks/ServiceNow_Related_Tickets_Search.yml +++ b/playbooks/ServiceNow_Related_Tickets_Search.yml @@ -10,7 +10,7 @@ how_to_implement: This input playbook requires the ServiceNow connector to be co references: - https://d3fend.mitre.org/technique/d3f:IdentifierReputationAnalysis/ app_list: - - Splunk + - ServiceNow tags: platform_tags: - user @@ -21,4 +21,6 @@ tags: vpe_type: Modern playbook_fields: [] product: - - Splunk SOAR \ No newline at end of file + - Splunk SOAR + use_cases: + - Enrichment \ No newline at end of file diff --git a/playbooks/Splunk_Attack_Analyzer_Dynamic_Analysis.yml b/playbooks/Splunk_Attack_Analyzer_Dynamic_Analysis.yml index 0d61fb92c3..3a32316c0d 100644 --- a/playbooks/Splunk_Attack_Analyzer_Dynamic_Analysis.yml +++ b/playbooks/Splunk_Attack_Analyzer_Dynamic_Analysis.yml @@ -9,7 +9,7 @@ playbook: Splunk_Attack_Analyzer_Dynamic_Analysis how_to_implement: This input playbook requires the SAA API connector to be configured. It is designed to work in conjunction with the Dynamic Attribute Lookup playbook or other playbooks in the same style. references: [] app_list: - - Splunk Attack Analyzer API + - Splunk Attack Analyzer Connector for Splunk SOAR tags: platform_tags: - url @@ -21,4 +21,9 @@ tags: vpe_type: Modern playbook_fields: [] product: - - Splunk SOAR \ No newline at end of file + - Splunk SOAR + use_cases: + - Enrichment + - Phishing + - Endpoint + defend_technique_id: D3-DA \ No newline at end of file diff --git a/playbooks/Splunk_Identifier_Activity_Analysis.yml b/playbooks/Splunk_Identifier_Activity_Analysis.yml index 605fac3797..34cdfc0d82 100644 --- a/playbooks/Splunk_Identifier_Activity_Analysis.yml +++ b/playbooks/Splunk_Identifier_Activity_Analysis.yml @@ -22,3 +22,6 @@ tags: playbook_fields: [] product: - Splunk SOAR + use_cases: + - Enrichment + defend_technique_id: D3-IAA \ No newline at end of file diff --git a/playbooks/Splunk_Message_Identifier_Activity_Analysis.yml b/playbooks/Splunk_Message_Identifier_Activity_Analysis.yml index 24e8b3445d..be3d9da81b 100644 --- a/playbooks/Splunk_Message_Identifier_Activity_Analysis.yml +++ b/playbooks/Splunk_Message_Identifier_Activity_Analysis.yml @@ -21,3 +21,6 @@ tags: playbook_fields: [] product: - Splunk SOAR + use_cases: + - Phishing + defend_technique_id: D3-IAA diff --git a/playbooks/Splunk_Notable_Related_Tickets_Search.yml b/playbooks/Splunk_Notable_Related_Tickets_Search.yml index c94b5a58c2..5c880045aa 100644 --- a/playbooks/Splunk_Notable_Related_Tickets_Search.yml +++ b/playbooks/Splunk_Notable_Related_Tickets_Search.yml @@ -21,4 +21,6 @@ tags: vpe_type: Modern playbook_fields: [] product: - - Splunk SOAR \ No newline at end of file + - Splunk SOAR + use_cases: + - Enrichment \ No newline at end of file diff --git a/playbooks/URL_Outbound_Traffic_Filtering_Dispatch.yml b/playbooks/URL_Outbound_Traffic_Filtering_Dispatch.yml index db27a3523e..8c4fa29ed9 100644 --- a/playbooks/URL_Outbound_Traffic_Filtering_Dispatch.yml +++ b/playbooks/URL_Outbound_Traffic_Filtering_Dispatch.yml @@ -16,4 +16,8 @@ tags: vpe_type: Modern playbook_fields: [] product: - - Splunk SOAR \ No newline at end of file + - Splunk SOAR + use_cases: + - Phishing + - Endpoint + defend_technique_id: D3-OTF \ No newline at end of file diff --git a/playbooks/UrlScan_IO_Dynamic_Analysis.yml b/playbooks/UrlScan_IO_Dynamic_Analysis.yml index 069c34e8e7..bc2748b30e 100644 --- a/playbooks/UrlScan_IO_Dynamic_Analysis.yml +++ b/playbooks/UrlScan_IO_Dynamic_Analysis.yml @@ -22,3 +22,8 @@ tags: playbook_fields: [] product: - Splunk SOAR + use_cases: + - Enrichment + - Phishing + - Endpoint + defend_technique_id: D3-DA diff --git a/playbooks/VirusTotal_v3_Dynamic_Analysis.yml b/playbooks/VirusTotal_v3_Dynamic_Analysis.yml index 8b514e204c..39454913a8 100644 --- a/playbooks/VirusTotal_v3_Dynamic_Analysis.yml +++ b/playbooks/VirusTotal_v3_Dynamic_Analysis.yml @@ -10,7 +10,7 @@ how_to_implement: This input playbook requires the Virustotal V3 API connector t It is designed to work in conjunction with the Dynamic Attribute Lookup playbook or other playbooks in the same style. references: [] app_list: - - virustotal v3 + - VirusTotal v3 tags: platform_tags: - url @@ -24,3 +24,8 @@ tags: playbook_fields: [] product: - Splunk SOAR + use_cases: + - Enrichment + - Phishing + - Endpoint + defend_technique_id: D3-DA diff --git a/playbooks/VirusTotal_v3_Identifier_Reputation_Analysis.yml b/playbooks/VirusTotal_v3_Identifier_Reputation_Analysis.yml index 22a8d83519..e546db336d 100644 --- a/playbooks/VirusTotal_v3_Identifier_Reputation_Analysis.yml +++ b/playbooks/VirusTotal_v3_Identifier_Reputation_Analysis.yml @@ -28,4 +28,7 @@ tags: vpe_type: Modern playbook_fields: [] product: - - Splunk SOAR \ No newline at end of file + - Splunk SOAR + use_cases: + - Enrichment + defend_technique_id: D3-IRA \ No newline at end of file diff --git a/playbooks/Windows_Defender_ATP_Identifier_Activity_Analysis.yml b/playbooks/Windows_Defender_ATP_Identifier_Activity_Analysis.yml index dba4325b67..0f757f1ba2 100644 --- a/playbooks/Windows_Defender_ATP_Identifier_Activity_Analysis.yml +++ b/playbooks/Windows_Defender_ATP_Identifier_Activity_Analysis.yml @@ -20,3 +20,7 @@ tags: playbook_fields: [] product: - Splunk SOAR + use_cases: + - Enrichment + - Endpoint + defend_technique_id: D3-IAA diff --git a/playbooks/Zscaler_Outbound_Traffic_Filtering.yml b/playbooks/Zscaler_Outbound_Traffic_Filtering.yml index f99cf8c988..78e2dd1953 100644 --- a/playbooks/Zscaler_Outbound_Traffic_Filtering.yml +++ b/playbooks/Zscaler_Outbound_Traffic_Filtering.yml @@ -10,15 +10,19 @@ how_to_implement: This input playbook requires the ZScaler connector to be confi references: - https://d3fend.mitre.org/technique/d3f:OutboundTrafficFiltering/ app_list: - - ZScaler + - Zscaler tags: platform_tags: - denylist - url - D3-OTF - - ZScaler + - Zscaler playbook_type: Input vpe_type: Modern playbook_fields: [] product: - - Splunk SOAR \ No newline at end of file + - Splunk SOAR + use_cases: + - Phishing + - Endpoint + defend_technique_id: D3-OTF \ No newline at end of file diff --git a/playbooks/activedirectory_reset_password.yml b/playbooks/activedirectory_reset_password.yml index a8b2c9bed9..35acf6fb02 100644 --- a/playbooks/activedirectory_reset_password.yml +++ b/playbooks/activedirectory_reset_password.yml @@ -9,7 +9,7 @@ playbook: activedirectory_reset_password how_to_implement: This playbook works on artifacts with artifact:*.cef.compromisedUserName which can be created as shown in the playbook "recorded_future_handle_leaked_credentials" - The prompt is hard-coded to use "admin" as the user, so change it to the correct user or role references: [] app_list: -- "LDAP" +- AD LDAP tags: platform_tags: [] playbook_type: Automation diff --git a/playbooks/aws_disable_user_accounts.yml b/playbooks/aws_disable_user_accounts.yml index ccb513fda0..2fdfeff1e8 100644 --- a/playbooks/aws_disable_user_accounts.yml +++ b/playbooks/aws_disable_user_accounts.yml @@ -10,7 +10,7 @@ how_to_implement: "This playbook works with the community playbook aws_find_inac references: - https://www.splunk.com/en_us/blog/security/splunk-soar-playbooks-finding-and-disabling-inactive-users-on-aws.html app_list: -- "AWS IAM" +- AWS IAM tags: platform_tags: - Cloud diff --git a/playbooks/aws_find_inactive_users.yml b/playbooks/aws_find_inactive_users.yml index c95fd59e44..13f484a9b2 100644 --- a/playbooks/aws_find_inactive_users.yml +++ b/playbooks/aws_find_inactive_users.yml @@ -10,8 +10,8 @@ how_to_implement: "This playbook is meant to run on a Timer, such as once per we references: - https://www.splunk.com/en_us/blog/security/splunk-soar-playbooks-finding-and-disabling-inactive-users-on-aws.html app_list: -- "AWS IAM" -- "Phantom" +- AWS IAM +- Phantom tags: platform_tags: - Cloud diff --git a/playbooks/block_indicators.yml b/playbooks/block_indicators.yml index 05fbca3fae..f73b4f363f 100644 --- a/playbooks/block_indicators.yml +++ b/playbooks/block_indicators.yml @@ -10,8 +10,8 @@ how_to_implement: "This playbook uses the following custom lists: ip_address_bl references: [] app_list: - "Palo Alto Networks Firewall" -- "CarbonBlack Response" -- "OpenDNS Umbrella" +- "Carbon Black Response" +- "Cisco Umbrella" tags: platform_tags: [] playbook_type: Automation diff --git a/playbooks/crowdstrike_malware_triage.yml b/playbooks/crowdstrike_malware_triage.yml index 585229fd2e..a95db53441 100644 --- a/playbooks/crowdstrike_malware_triage.yml +++ b/playbooks/crowdstrike_malware_triage.yml @@ -9,7 +9,7 @@ playbook: crowdstrike_malware_triage how_to_implement: This playbook uses the Crowdstrike OAuth app. Change the target user of the prompt from admin to the appropriate user or role. references: [] app_list: -- "Crowdstrike OAuth" +- CrowdStrike OAuth API tags: platform_tags: [] playbook_type: Automation diff --git a/playbooks/email_notification_for_malware.yml b/playbooks/email_notification_for_malware.yml index d3fe969c17..154d804900 100644 --- a/playbooks/email_notification_for_malware.yml +++ b/playbooks/email_notification_for_malware.yml @@ -11,7 +11,7 @@ references: [] app_list: - "VirusTotal" - "WildFire" -- "CarbonBlack Response" +- "Carbon Black Response" - "SMTP" tags: platform_tags: [] diff --git a/playbooks/hunting.yml b/playbooks/hunting.yml index f4b8d8befa..8c91a9e0e7 100644 --- a/playbooks/hunting.yml +++ b/playbooks/hunting.yml @@ -11,7 +11,7 @@ references: [] app_list: - "Splunk" - "Reversing Labs" -- "CarbonBlack Response" +- "Carbon Black Response" - "Threat Grid" - "Falcon Host API" tags: diff --git a/playbooks/malware_hunt_and_contain.yml b/playbooks/malware_hunt_and_contain.yml index 3b97c10d52..e3254ce67a 100644 --- a/playbooks/malware_hunt_and_contain.yml +++ b/playbooks/malware_hunt_and_contain.yml @@ -11,7 +11,7 @@ references: [] app_list: - "LDAP" - "ServiceNow" -- "CarbonBlack Response" +- "Carbon Black Response" - "VirusTotal" tags: platform_tags: [] diff --git a/playbooks/risk_notable_block_indicators.yml b/playbooks/risk_notable_block_indicators.yml index ce0249f01b..fef4d2fbb9 100644 --- a/playbooks/risk_notable_block_indicators.yml +++ b/playbooks/risk_notable_block_indicators.yml @@ -6,12 +6,11 @@ author: Kelby Shelton, Splunk type: Response description: This playbook handles locating indicators marked for blocking and determining if any blocking playbooks exist. If there is a match to the appropriate tags in the playbook, a filter block routes the name of the playbook to launch to a code block. playbook: risk_notable_block_indicators -how_to_implement: tbd +how_to_implement: For detailed implementation see https://docs.splunk.com/Documentation/ESSOC/latest/user/Useplaybookpack references: - https://docs.splunk.com/Documentation/ESSOC/latest/user/Useplaybookpack#Call_child_playbooks_with_the_dynamic_playbook_system - https://docs.splunk.com/Documentation/ESSOC/latest/user/Useplaybookpack#Indicator_tagging_system -app_list: - - "None" +app_list: [] tags: labels: - risk_notable diff --git a/playbooks/risk_notable_enrich.yml b/playbooks/risk_notable_enrich.yml index a13b96d249..12299a549d 100644 --- a/playbooks/risk_notable_enrich.yml +++ b/playbooks/risk_notable_enrich.yml @@ -6,11 +6,10 @@ author: Kelby Shelton, Splunk type: Investigation description: This playbook collects the available Indicator data types within the event as well as available investigative playbooks. It will launch any playbooks that meet the filtered criteria. playbook: risk_notable_enrich -how_to_implement: tbd +how_to_implement: For detailed implementation see https://docs.splunk.com/Documentation/ESSOC/latest/user/Useplaybookpack references: - https://docs.splunk.com/Documentation/ESSOC/latest/user/Useplaybookpack#Call_child_playbooks_with_the_dynamic_playbook_system -app_list: - - "None" +app_list: [] tags: labels: - risk_notable diff --git a/playbooks/risk_notable_import_data.yml b/playbooks/risk_notable_import_data.yml index 069493612a..65c3f0742b 100644 --- a/playbooks/risk_notable_import_data.yml +++ b/playbooks/risk_notable_import_data.yml @@ -6,21 +6,7 @@ author: Kelby Shelton, Splunk type: Investigation description: This playbook gathers all of the events associated with the risk notable and imports them as artifacts. It also generates a custom markdown formatted note. playbook: risk_notable_import_data -how_to_implement: > - The Splunk search used to locate contributing events requires three fields in the notable artifact\: risk_object, info_min_time, and info_max_time. The query also performs some deduplication on contributing events and may need to be adjusted based on individual Enterprise Security environments. Mitre Tactics and Techniques appear if using the annotation framework in Splunk ES." - - ```index=risk risk_object=\"{0}\" earliest=\"{1}\" latest="{2}\" - | rex field=source \".*-\s(?.*)\s+-\s+\w+\s+-\s+Rule\" - | fillnull value=\"unknown\" threat_object - | eval risk_message=coalesce(risk_message,source) - | stats values(*) as * by _time source threat_object risk_message - | rename annotations.mitre_attack.mitre_technique_id as mitre_technique_id annotations.mitre_attack.mitre_tactic as mitre_tactic annotations.mitre_attack.mitre_technique as mitre_technique - | fields - annotations* risk_object_* date_* orig_* user_* src_user_* src_* dest_* dest_user_* info_* search_* splunk_* tag* risk_modifier* risk_rule* sourcetype timestamp index next_cron_time timeendpos timestartpos testmode linecount - | sort + _time - | `uitime(_time)` - | dedup source threat_object``` - - A custom code block sorts the returned event data and produces a markdown formatted note into the note_content output field. This field is then available for use in downstream playbooks." +how_to_implement: For detailed implementation see https://docs.splunk.com/Documentation/ESSOC/latest/user/Useplaybookpack references: - https://docs.splunk.com/Documentation/ESSOC/latest/user/Useplaybookpack - http://docs.splunk.com/Documentation/ES/6.6.2/Admin/Configurecorrelationsearches#Use_security_framework_annotations_in_correlation_searches diff --git a/playbooks/risk_notable_investigate.yml b/playbooks/risk_notable_investigate.yml index f8985dbf45..ebbf5249a5 100644 --- a/playbooks/risk_notable_investigate.yml +++ b/playbooks/risk_notable_investigate.yml @@ -6,11 +6,10 @@ author: Kelby Shelton, Splunk type: Investigation description: This playbook checks for the presence of the Risk Investigation workbook and updates tasks or leaves generic notes. playbook: risk_notable_investigate -how_to_implement: Set this playbook to run in Active mode on the Risk Notable label in Splunk SOAR. +how_to_implement: For detailed implementation see https://docs.splunk.com/Documentation/ESSOC/latest/user/Useplaybookpack references: - https://docs.splunk.com/Documentation/ESSOC/latest/user/Useplaybookpack -app_list: - - "None" +app_list: [] tags: labels: - risk_notable diff --git a/playbooks/risk_notable_merge_events.yml b/playbooks/risk_notable_merge_events.yml index 3bfbde9cc3..05f6f92824 100644 --- a/playbooks/risk_notable_merge_events.yml +++ b/playbooks/risk_notable_merge_events.yml @@ -6,11 +6,10 @@ author: Kelby Shelton, Splunk type: Investigation description: This playbook finds related events based on key fields in a risk notable and allows the user to process the results and decide which events to merge into the current investigation. playbook: risk_notable_merge_events -how_to_implement: Combining the list_merge utility within the playbook with the find_related_containers utility allows for fine-tuning of related event criteria. For example, the default filtering criteria uses description, risk_object, and threat_object as the important fields and requires at least three matches before an event is considered related. There are several options to customize the associated criteria, including adding more fields in list_merge, reducing or increasing the minimum match count, or utilizing the wildcard feature of find_related_containers. +how_to_implement: For detailed implementation see https://docs.splunk.com/Documentation/ESSOC/latest/user/Useplaybookpack references: - https://docs.splunk.com/Documentation/ESSOC/latest/user/Useplaybookpack -app_list: - - "None" +app_list: [] tags: labels: - risk_notable diff --git a/playbooks/risk_notable_mitigate.yml b/playbooks/risk_notable_mitigate.yml index b2da240dfc..6a57ba6f14 100644 --- a/playbooks/risk_notable_mitigate.yml +++ b/playbooks/risk_notable_mitigate.yml @@ -6,7 +6,7 @@ author: Kelby Shelton, Splunk type: Response description: This playbook checks for the presence of the Risk Response workbook and updates tasks or leaves generic notes. The risk_notable_verdict playbooks recommends this playbook as a second phase of the investigation. Additionally, this playbook can be used in ad-hoc investigations or incorporated into custom workbooks. playbook: risk_notable_mitigate -how_to_implement: tbd +how_to_implement: For detailed implementation see https://docs.splunk.com/Documentation/ESSOC/latest/user/Useplaybookpack references: - https://docs.splunk.com/Documentation/ESSOC/latest/user/Useplaybookpack app_list: [] diff --git a/playbooks/risk_notable_preprocess.yml b/playbooks/risk_notable_preprocess.yml index 8e62e3115f..d3d0c9b9cf 100644 --- a/playbooks/risk_notable_preprocess.yml +++ b/playbooks/risk_notable_preprocess.yml @@ -10,7 +10,7 @@ description: > 2. Posts a link to this container in the comment field of Splunk ES. 3. Updates the container name, description, and severity to reflect the data in the notable artifact." playbook: risk_notable_preprocess -how_to_implement: tbd +how_to_implement: For detailed implementation see https://docs.splunk.com/Documentation/ESSOC/latest/user/Useplaybookpack references: - https://docs.splunk.com/Documentation/ESSOC/latest/user/Useplaybookpack app_list: diff --git a/playbooks/risk_notable_protect_assets_and_users.yml b/playbooks/risk_notable_protect_assets_and_users.yml index 67587dd793..4429c9bf1b 100644 --- a/playbooks/risk_notable_protect_assets_and_users.yml +++ b/playbooks/risk_notable_protect_assets_and_users.yml @@ -6,11 +6,10 @@ author: Kelby Shelton, Splunk type: Response description: This playbook attempts to find assets and users from the notable event and match those with assets and identities from Splunk ES. If a match was found and the user has playbooks available to contain entities, the analyst decides which entities to disable or quarantine. playbook: risk_notable_protect_assets_and_users -how_to_implement: tbd +how_to_implement: For detailed implementation see https://docs.splunk.com/Documentation/ESSOC/latest/user/Useplaybookpack references: - https://docs.splunk.com/Documentation/ESSOC/latest/user/Useplaybookpack#Call_child_playbooks_with_the_dynamic_playbook_system -app_list: - - "None" +app_list: [] tags: labels: - risk_notable diff --git a/playbooks/risk_notable_review_indicators.yml b/playbooks/risk_notable_review_indicators.yml index 02d750fe35..446aa2a2c6 100644 --- a/playbooks/risk_notable_review_indicators.yml +++ b/playbooks/risk_notable_review_indicators.yml @@ -6,11 +6,10 @@ author: Kelby Shelton, Splunk type: Response description: This playbook was designed to be called by a user to process indicators that are marked as suspicious within the SOAR platform. Analysts will review indicators in a prompt and mark them as blocked or safe. playbook: risk_notable_review_indicators -how_to_implement: tbd +how_to_implement: For detailed implementation see https://docs.splunk.com/Documentation/ESSOC/latest/user/Useplaybookpack references: - https://docs.splunk.com/Documentation/ESSOC/latest/user/Useplaybookpack#Indicator_tagging_system -app_list: - - "None" +app_list: [] tags: labels: - risk_notable diff --git a/playbooks/risk_notable_verdict.yml b/playbooks/risk_notable_verdict.yml index 208cf66a42..a8b06dd070 100644 --- a/playbooks/risk_notable_verdict.yml +++ b/playbooks/risk_notable_verdict.yml @@ -6,11 +6,10 @@ author: Kelby Shelton, Splunk type: Response description: This playbook locates available playbooks with the response tag and presents them to the analyst. Based on the analyst selection, it will launch its chosen playbook. playbook: risk_notable_verdict -how_to_implement: tbd +how_to_implement: For detailed implementation see https://docs.splunk.com/Documentation/ESSOC/latest/user/Useplaybookpack references: - https://docs.splunk.com/Documentation/ESSOC/latest/user/Useplaybookpack#Call_child_playbooks_with_the_dynamic_playbook_system -app_list: - - "None" +app_list: [] tags: labels: - risk_notable diff --git a/requirements.txt b/requirements.txt index 69d835fe7a..5f235f7d66 100644 --- a/requirements.txt +++ b/requirements.txt @@ -1,8 +1,8 @@ attackcti==0.3.9 docker==6.1.3 -GitPython==3.1.32 +GitPython==3.1.33 Jinja2==3.1.2 -jsonschema==4.17.3 +jsonschema==4.19.0 mock==4.0.3 psutil==5.9.5 pycvesearch==1.2 diff --git a/spec/playbooks.spec.json b/spec/playbooks.spec.json index 23603b484c..33af1eeb25 100644 --- a/spec/playbooks.spec.json +++ b/spec/playbooks.spec.json @@ -108,7 +108,8 @@ "detections": "Conti Common Exec parameter", "platform_tags": "Investigate", "playbook_fields": "Username", - "product": "Splunk SOAR" + "product": "Splunk SOAR", + "defend_technique_id": "D3-DA" } ], "minItems": 1,