updating build

This commit is contained in:
divious1
2019-05-22 10:35:41 -07:00
4 changed files with 8 additions and 8 deletions
+1 -1
View File
@@ -1,6 +1,6 @@
#############
# Automatically generated by generator.py in splunk/security-content
# On Date: 2019-05-21T19:50:27 UTC
# On Date: 2019-05-21T23:30:47 UTC
# Author: Splunk Security Research
# Contact: research@splunk.com
#############
+1 -1
View File
@@ -4,7 +4,7 @@
is_configured = false
state = enabled
state_change_requires_restart = false
build = 3333
build = 653
[triggers]
reload.analytic_stories = simple
+1 -1
View File
@@ -1,6 +1,6 @@
#############
# Automatically generated by generator.py in splunk/security-content
# On Date: 2019-05-21T19:50:27 UTC
# On Date: 2019-05-21T23:30:47 UTC
# Author: Splunk Security Research
# Contact: research@splunk.com
#############
+5 -5
View File
@@ -1,6 +1,6 @@
#############
# Automatically generated by generator.py in splunk/security-content
# On Date: 2019-05-21T19:50:27 UTC
# On Date: 2019-05-21T23:30:47 UTC
# Author: Splunk Security Research
# Contact: research@splunk.com
#############
@@ -2858,15 +2858,15 @@ how_to_implement = If Splunk>Phantom is also configured in your environment, a P
\
known_false_positives = None at this time
earliest_time_offset = 604800
latest_time_offset = 0
earliest_time_offset = 43200
latest_time_offset = 1
[savedsearch://ESCU - Domain Certificate Investigation]
type = investigation
explanation = none
how_to_implement = To successfully implement this phantom playbook, you must integrate Enterprise Security with Phantom. Configure this playbook in the correlation search `Detect DNS requests to Phishing Sites leveraging EvilGinx2` ,as an adaptive response action.
known_false_positives = None at this time
earliest_time_offset = 0
earliest_time_offset = 864000
latest_time_offset = 86400
[savedsearch://ESCU - Excessive Account Lockouts Enrichment And Response]
@@ -2874,7 +2874,7 @@ type = investigation
explanation = none
how_to_implement = Import playbook into phantom
known_false_positives = None at this time
earliest_time_offset = 14400
earliest_time_offset = 604800
latest_time_offset = 0
[savedsearch://ESCU - Get All AWS Activity From City]