diff --git a/playbooks/internal_host_splunk_investigate_log4j.png b/playbooks/internal_host_splunk_investigate_log4j.png new file mode 100644 index 0000000000..2d674ea010 Binary files /dev/null and b/playbooks/internal_host_splunk_investigate_log4j.png differ diff --git a/playbooks/internal_host_splunk_investigate_log4j.yml b/playbooks/internal_host_splunk_investigate_log4j.yml index cc9bb56c5a..cf751a74e4 100644 --- a/playbooks/internal_host_splunk_investigate_log4j.yml +++ b/playbooks/internal_host_splunk_investigate_log4j.yml @@ -1,12 +1,12 @@ -name: Log4J Investigate And Respond +name: Log4j Investigate And Respond id: fc0adc66-ff2b-48b0-9a6f-63da6783fd63 version: 1 date: '2021-12-14' author: Lou Stella, Splunk type: Investigation -description: This input playbook is part of the -playbook: log4j_investigate_and_respond -how_to_implement: This playbook reads and then deletes files stored with artifact:*.cef.filePath from hosts stored in artifact:*.cef.destinationAddress. Windows Remote Management must be enabled on the remote computer. +description: Published in response to CVE-2021-44228, this playbook utilizes data already in your Splunk environment to help investigate and remediate impacts caused by this vulnerability in your environment. +playbook: internal_host_splunk_investigate_log4j +how_to_implement: This playbook presumes you have Enterprise Security and have configured Assets & Identities, as well as the Endpoint.Processes datamodel references: - https://www.splunk.com/en_us/blog/security/log-jammin-log4j-2-rce.html app_list: