mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
updating build
This commit is contained in:
@@ -1,6 +1,6 @@
|
||||
#############
|
||||
# Automatically generated by generator.py in splunk/security-content
|
||||
# On Date: 2019-05-21T19:50:27 UTC
|
||||
# On Date: 2019-05-21T23:30:47 UTC
|
||||
# Author: Splunk Security Research
|
||||
# Contact: research@splunk.com
|
||||
#############
|
||||
|
||||
@@ -4,7 +4,7 @@
|
||||
is_configured = false
|
||||
state = enabled
|
||||
state_change_requires_restart = false
|
||||
build = 3333
|
||||
build = 653
|
||||
|
||||
[triggers]
|
||||
reload.analytic_stories = simple
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
#############
|
||||
# Automatically generated by generator.py in splunk/security-content
|
||||
# On Date: 2019-05-21T19:50:27 UTC
|
||||
# On Date: 2019-05-21T23:30:47 UTC
|
||||
# Author: Splunk Security Research
|
||||
# Contact: research@splunk.com
|
||||
#############
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
#############
|
||||
# Automatically generated by generator.py in splunk/security-content
|
||||
# On Date: 2019-05-21T19:50:27 UTC
|
||||
# On Date: 2019-05-21T23:30:47 UTC
|
||||
# Author: Splunk Security Research
|
||||
# Contact: research@splunk.com
|
||||
#############
|
||||
@@ -2858,15 +2858,15 @@ how_to_implement = If Splunk>Phantom is also configured in your environment, a P
|
||||
\
|
||||
|
||||
known_false_positives = None at this time
|
||||
earliest_time_offset = 604800
|
||||
latest_time_offset = 0
|
||||
earliest_time_offset = 43200
|
||||
latest_time_offset = 1
|
||||
|
||||
[savedsearch://ESCU - Domain Certificate Investigation]
|
||||
type = investigation
|
||||
explanation = none
|
||||
how_to_implement = To successfully implement this phantom playbook, you must integrate Enterprise Security with Phantom. Configure this playbook in the correlation search `Detect DNS requests to Phishing Sites leveraging EvilGinx2` ,as an adaptive response action.
|
||||
known_false_positives = None at this time
|
||||
earliest_time_offset = 0
|
||||
earliest_time_offset = 864000
|
||||
latest_time_offset = 86400
|
||||
|
||||
[savedsearch://ESCU - Excessive Account Lockouts Enrichment And Response]
|
||||
@@ -2874,7 +2874,7 @@ type = investigation
|
||||
explanation = none
|
||||
how_to_implement = Import playbook into phantom
|
||||
known_false_positives = None at this time
|
||||
earliest_time_offset = 14400
|
||||
earliest_time_offset = 604800
|
||||
latest_time_offset = 0
|
||||
|
||||
[savedsearch://ESCU - Get All AWS Activity From City]
|
||||
|
||||
Reference in New Issue
Block a user