Add screenshot & updated description text

This commit is contained in:
Lou Stella
2021-12-14 18:20:29 -06:00
parent bf1fec5139
commit 672609671b
2 changed files with 4 additions and 4 deletions
Binary file not shown.

After

Width:  |  Height:  |  Size: 50 KiB

@@ -1,12 +1,12 @@
name: Log4J Investigate And Respond
name: Log4j Investigate And Respond
id: fc0adc66-ff2b-48b0-9a6f-63da6783fd63
version: 1
date: '2021-12-14'
author: Lou Stella, Splunk
type: Investigation
description: This input playbook is part of the
playbook: log4j_investigate_and_respond
how_to_implement: This playbook reads and then deletes files stored with artifact:*.cef.filePath from hosts stored in artifact:*.cef.destinationAddress. Windows Remote Management must be enabled on the remote computer.
description: Published in response to CVE-2021-44228, this playbook utilizes data already in your Splunk environment to help investigate and remediate impacts caused by this vulnerability in your environment.
playbook: internal_host_splunk_investigate_log4j
how_to_implement: This playbook presumes you have Enterprise Security and have configured Assets & Identities, as well as the Endpoint.Processes datamodel
references:
- https://www.splunk.com/en_us/blog/security/log-jammin-log4j-2-rce.html
app_list: