diff --git a/package/default/analytic_stories.conf b/package/default/analytic_stories.conf index 7cf898bd98..f809ddaab3 100644 --- a/package/default/analytic_stories.conf +++ b/package/default/analytic_stories.conf @@ -1,6 +1,6 @@ ############# # Automatically generated by generator.py in splunk/security-content -# On Date: 2019-05-21T19:50:27 UTC +# On Date: 2019-05-21T23:30:47 UTC # Author: Splunk Security Research # Contact: research@splunk.com ############# diff --git a/package/default/app.conf b/package/default/app.conf index 3d06c6b5aa..4a7f76c7dd 100644 --- a/package/default/app.conf +++ b/package/default/app.conf @@ -4,7 +4,7 @@ is_configured = false state = enabled state_change_requires_restart = false -build = 3333 +build = 653 [triggers] reload.analytic_stories = simple diff --git a/package/default/savedsearches.conf b/package/default/savedsearches.conf index d4824b7ec5..ab38b94a84 100644 --- a/package/default/savedsearches.conf +++ b/package/default/savedsearches.conf @@ -1,6 +1,6 @@ ############# # Automatically generated by generator.py in splunk/security-content -# On Date: 2019-05-21T19:50:27 UTC +# On Date: 2019-05-21T23:30:47 UTC # Author: Splunk Security Research # Contact: research@splunk.com ############# diff --git a/package/default/use_case_library.conf b/package/default/use_case_library.conf index 10ba194b10..15eedde024 100644 --- a/package/default/use_case_library.conf +++ b/package/default/use_case_library.conf @@ -1,6 +1,6 @@ ############# # Automatically generated by generator.py in splunk/security-content -# On Date: 2019-05-21T19:50:27 UTC +# On Date: 2019-05-21T23:30:47 UTC # Author: Splunk Security Research # Contact: research@splunk.com ############# @@ -2858,15 +2858,15 @@ how_to_implement = If Splunk>Phantom is also configured in your environment, a P \ known_false_positives = None at this time -earliest_time_offset = 604800 -latest_time_offset = 0 +earliest_time_offset = 43200 +latest_time_offset = 1 [savedsearch://ESCU - Domain Certificate Investigation] type = investigation explanation = none how_to_implement = To successfully implement this phantom playbook, you must integrate Enterprise Security with Phantom. Configure this playbook in the correlation search `Detect DNS requests to Phishing Sites leveraging EvilGinx2` ,as an adaptive response action. known_false_positives = None at this time -earliest_time_offset = 0 +earliest_time_offset = 864000 latest_time_offset = 86400 [savedsearch://ESCU - Excessive Account Lockouts Enrichment And Response] @@ -2874,7 +2874,7 @@ type = investigation explanation = none how_to_implement = Import playbook into phantom known_false_positives = None at this time -earliest_time_offset = 14400 +earliest_time_offset = 604800 latest_time_offset = 0 [savedsearch://ESCU - Get All AWS Activity From City]