updating package files

This commit is contained in:
research bot
2019-05-22 17:44:49 +00:00
parent 6b73ea0575
commit adbe1dee01
4 changed files with 10 additions and 10 deletions
+1 -1
View File
@@ -1,6 +1,6 @@
#############
# Automatically generated by generator.py in splunk/security-content
# On Date: 2019-05-21T23:30:47 UTC
# On Date: 2019-05-22T17:44:44 UTC
# Author: Splunk Security Research
# Contact: research@splunk.com
#############
+1 -1
View File
@@ -4,7 +4,7 @@
is_configured = false
state = enabled
state_change_requires_restart = false
build = 653
build = 659
[triggers]
reload.analytic_stories = simple
+1 -1
View File
@@ -1,6 +1,6 @@
#############
# Automatically generated by generator.py in splunk/security-content
# On Date: 2019-05-21T23:30:47 UTC
# On Date: 2019-05-22T17:44:44 UTC
# Author: Splunk Security Research
# Contact: research@splunk.com
#############
+7 -7
View File
@@ -1,6 +1,6 @@
#############
# Automatically generated by generator.py in splunk/security-content
# On Date: 2019-05-21T23:30:47 UTC
# On Date: 2019-05-22T17:44:44 UTC
# Author: Splunk Security Research
# Contact: research@splunk.com
#############
@@ -2858,24 +2858,24 @@ how_to_implement = If Splunk>Phantom is also configured in your environment, a P
\
known_false_positives = None at this time
earliest_time_offset = 43200
latest_time_offset = 1
earliest_time_offset = 14400
latest_time_offset = 0
[savedsearch://ESCU - Domain Certificate Investigation]
type = investigation
explanation = none
how_to_implement = To successfully implement this phantom playbook, you must integrate Enterprise Security with Phantom. Configure this playbook in the correlation search `Detect DNS requests to Phishing Sites leveraging EvilGinx2` ,as an adaptive response action.
known_false_positives = None at this time
earliest_time_offset = 864000
latest_time_offset = 86400
earliest_time_offset = 86400
latest_time_offset = 0
[savedsearch://ESCU - Excessive Account Lockouts Enrichment And Response]
type = investigation
explanation = none
how_to_implement = Import playbook into phantom
known_false_positives = None at this time
earliest_time_offset = 604800
latest_time_offset = 0
earliest_time_offset = 3600
latest_time_offset = 3600
[savedsearch://ESCU - Get All AWS Activity From City]
type = investigation