mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
updating package files
This commit is contained in:
@@ -1,6 +1,6 @@
|
||||
#############
|
||||
# Automatically generated by generator.py in splunk/security-content
|
||||
# On Date: 2019-05-21T19:50:27 UTC
|
||||
# On Date: 2019-05-21T23:29:56 UTC
|
||||
# Author: Splunk Security Research
|
||||
# Contact: research@splunk.com
|
||||
#############
|
||||
|
||||
@@ -4,7 +4,7 @@
|
||||
is_configured = false
|
||||
state = enabled
|
||||
state_change_requires_restart = false
|
||||
build = @version.build@
|
||||
build = 651
|
||||
|
||||
[triggers]
|
||||
reload.analytic_stories = simple
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
#############
|
||||
# Automatically generated by generator.py in splunk/security-content
|
||||
# On Date: 2019-05-21T19:50:27 UTC
|
||||
# On Date: 2019-05-21T23:29:56 UTC
|
||||
# Author: Splunk Security Research
|
||||
# Contact: research@splunk.com
|
||||
#############
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
#############
|
||||
# Automatically generated by generator.py in splunk/security-content
|
||||
# On Date: 2019-05-21T19:50:27 UTC
|
||||
# On Date: 2019-05-21T23:29:56 UTC
|
||||
# Author: Splunk Security Research
|
||||
# Contact: research@splunk.com
|
||||
#############
|
||||
@@ -2866,16 +2866,16 @@ type = investigation
|
||||
explanation = none
|
||||
how_to_implement = To successfully implement this phantom playbook, you must integrate Enterprise Security with Phantom. Configure this playbook in the correlation search `Detect DNS requests to Phishing Sites leveraging EvilGinx2` ,as an adaptive response action.
|
||||
known_false_positives = None at this time
|
||||
earliest_time_offset = 0
|
||||
latest_time_offset = 86400
|
||||
earliest_time_offset = 86400
|
||||
latest_time_offset = 0
|
||||
|
||||
[savedsearch://ESCU - Excessive Account Lockouts Enrichment And Response]
|
||||
type = investigation
|
||||
explanation = none
|
||||
how_to_implement = Import playbook into phantom
|
||||
known_false_positives = None at this time
|
||||
earliest_time_offset = 14400
|
||||
latest_time_offset = 0
|
||||
earliest_time_offset = 86400
|
||||
latest_time_offset = 86400
|
||||
|
||||
[savedsearch://ESCU - Get All AWS Activity From City]
|
||||
type = investigation
|
||||
|
||||
Reference in New Issue
Block a user