From 494feb93e2224d0f93ee9acb2feaeb3071fa0edf Mon Sep 17 00:00:00 2001 From: research bot Date: Tue, 21 May 2019 23:30:10 +0000 Subject: [PATCH 1/2] updating package files --- package/default/analytic_stories.conf | 2 +- package/default/app.conf | 2 +- package/default/savedsearches.conf | 2 +- package/default/use_case_library.conf | 10 +++++----- 4 files changed, 8 insertions(+), 8 deletions(-) diff --git a/package/default/analytic_stories.conf b/package/default/analytic_stories.conf index 7cf898bd98..6e4791b200 100644 --- a/package/default/analytic_stories.conf +++ b/package/default/analytic_stories.conf @@ -1,6 +1,6 @@ ############# # Automatically generated by generator.py in splunk/security-content -# On Date: 2019-05-21T19:50:27 UTC +# On Date: 2019-05-21T23:29:56 UTC # Author: Splunk Security Research # Contact: research@splunk.com ############# diff --git a/package/default/app.conf b/package/default/app.conf index 80acd216d8..818903abd0 100644 --- a/package/default/app.conf +++ b/package/default/app.conf @@ -4,7 +4,7 @@ is_configured = false state = enabled state_change_requires_restart = false -build = @version.build@ +build = 651 [triggers] reload.analytic_stories = simple diff --git a/package/default/savedsearches.conf b/package/default/savedsearches.conf index d4824b7ec5..e89b2feeab 100644 --- a/package/default/savedsearches.conf +++ b/package/default/savedsearches.conf @@ -1,6 +1,6 @@ ############# # Automatically generated by generator.py in splunk/security-content -# On Date: 2019-05-21T19:50:27 UTC +# On Date: 2019-05-21T23:29:56 UTC # Author: Splunk Security Research # Contact: research@splunk.com ############# diff --git a/package/default/use_case_library.conf b/package/default/use_case_library.conf index 10ba194b10..cacaae820a 100644 --- a/package/default/use_case_library.conf +++ b/package/default/use_case_library.conf @@ -1,6 +1,6 @@ ############# # Automatically generated by generator.py in splunk/security-content -# On Date: 2019-05-21T19:50:27 UTC +# On Date: 2019-05-21T23:29:56 UTC # Author: Splunk Security Research # Contact: research@splunk.com ############# @@ -2866,16 +2866,16 @@ type = investigation explanation = none how_to_implement = To successfully implement this phantom playbook, you must integrate Enterprise Security with Phantom. Configure this playbook in the correlation search `Detect DNS requests to Phishing Sites leveraging EvilGinx2` ,as an adaptive response action. known_false_positives = None at this time -earliest_time_offset = 0 -latest_time_offset = 86400 +earliest_time_offset = 86400 +latest_time_offset = 0 [savedsearch://ESCU - Excessive Account Lockouts Enrichment And Response] type = investigation explanation = none how_to_implement = Import playbook into phantom known_false_positives = None at this time -earliest_time_offset = 14400 -latest_time_offset = 0 +earliest_time_offset = 86400 +latest_time_offset = 86400 [savedsearch://ESCU - Get All AWS Activity From City] type = investigation From 4e385c59baf08f92d2d70a14a805ca4438eb2303 Mon Sep 17 00:00:00 2001 From: research bot Date: Tue, 21 May 2019 23:31:11 +0000 Subject: [PATCH 2/2] updating package files --- package/default/analytic_stories.conf | 2 +- package/default/app.conf | 2 +- package/default/savedsearches.conf | 2 +- package/default/use_case_library.conf | 14 +++++++------- 4 files changed, 10 insertions(+), 10 deletions(-) diff --git a/package/default/analytic_stories.conf b/package/default/analytic_stories.conf index 6e4791b200..f809ddaab3 100644 --- a/package/default/analytic_stories.conf +++ b/package/default/analytic_stories.conf @@ -1,6 +1,6 @@ ############# # Automatically generated by generator.py in splunk/security-content -# On Date: 2019-05-21T23:29:56 UTC +# On Date: 2019-05-21T23:30:47 UTC # Author: Splunk Security Research # Contact: research@splunk.com ############# diff --git a/package/default/app.conf b/package/default/app.conf index 818903abd0..4a7f76c7dd 100644 --- a/package/default/app.conf +++ b/package/default/app.conf @@ -4,7 +4,7 @@ is_configured = false state = enabled state_change_requires_restart = false -build = 651 +build = 653 [triggers] reload.analytic_stories = simple diff --git a/package/default/savedsearches.conf b/package/default/savedsearches.conf index e89b2feeab..ab38b94a84 100644 --- a/package/default/savedsearches.conf +++ b/package/default/savedsearches.conf @@ -1,6 +1,6 @@ ############# # Automatically generated by generator.py in splunk/security-content -# On Date: 2019-05-21T23:29:56 UTC +# On Date: 2019-05-21T23:30:47 UTC # Author: Splunk Security Research # Contact: research@splunk.com ############# diff --git a/package/default/use_case_library.conf b/package/default/use_case_library.conf index cacaae820a..15eedde024 100644 --- a/package/default/use_case_library.conf +++ b/package/default/use_case_library.conf @@ -1,6 +1,6 @@ ############# # Automatically generated by generator.py in splunk/security-content -# On Date: 2019-05-21T23:29:56 UTC +# On Date: 2019-05-21T23:30:47 UTC # Author: Splunk Security Research # Contact: research@splunk.com ############# @@ -2858,24 +2858,24 @@ how_to_implement = If Splunk>Phantom is also configured in your environment, a P \ known_false_positives = None at this time -earliest_time_offset = 604800 -latest_time_offset = 0 +earliest_time_offset = 43200 +latest_time_offset = 1 [savedsearch://ESCU - Domain Certificate Investigation] type = investigation explanation = none how_to_implement = To successfully implement this phantom playbook, you must integrate Enterprise Security with Phantom. Configure this playbook in the correlation search `Detect DNS requests to Phishing Sites leveraging EvilGinx2` ,as an adaptive response action. known_false_positives = None at this time -earliest_time_offset = 86400 -latest_time_offset = 0 +earliest_time_offset = 864000 +latest_time_offset = 86400 [savedsearch://ESCU - Excessive Account Lockouts Enrichment And Response] type = investigation explanation = none how_to_implement = Import playbook into phantom known_false_positives = None at this time -earliest_time_offset = 86400 -latest_time_offset = 86400 +earliest_time_offset = 604800 +latest_time_offset = 0 [savedsearch://ESCU - Get All AWS Activity From City] type = investigation