diff --git a/package/default/analytic_stories.conf b/package/default/analytic_stories.conf index f809ddaab3..b01c90bbad 100644 --- a/package/default/analytic_stories.conf +++ b/package/default/analytic_stories.conf @@ -1,6 +1,6 @@ ############# # Automatically generated by generator.py in splunk/security-content -# On Date: 2019-05-21T23:30:47 UTC +# On Date: 2019-05-22T17:44:44 UTC # Author: Splunk Security Research # Contact: research@splunk.com ############# diff --git a/package/default/app.conf b/package/default/app.conf index 4a7f76c7dd..e59afaf3c6 100644 --- a/package/default/app.conf +++ b/package/default/app.conf @@ -4,7 +4,7 @@ is_configured = false state = enabled state_change_requires_restart = false -build = 653 +build = 659 [triggers] reload.analytic_stories = simple diff --git a/package/default/savedsearches.conf b/package/default/savedsearches.conf index ab38b94a84..02ad30bd3b 100644 --- a/package/default/savedsearches.conf +++ b/package/default/savedsearches.conf @@ -1,6 +1,6 @@ ############# # Automatically generated by generator.py in splunk/security-content -# On Date: 2019-05-21T23:30:47 UTC +# On Date: 2019-05-22T17:44:44 UTC # Author: Splunk Security Research # Contact: research@splunk.com ############# diff --git a/package/default/use_case_library.conf b/package/default/use_case_library.conf index 15eedde024..69d617a98d 100644 --- a/package/default/use_case_library.conf +++ b/package/default/use_case_library.conf @@ -1,6 +1,6 @@ ############# # Automatically generated by generator.py in splunk/security-content -# On Date: 2019-05-21T23:30:47 UTC +# On Date: 2019-05-22T17:44:44 UTC # Author: Splunk Security Research # Contact: research@splunk.com ############# @@ -2858,24 +2858,24 @@ how_to_implement = If Splunk>Phantom is also configured in your environment, a P \ known_false_positives = None at this time -earliest_time_offset = 43200 -latest_time_offset = 1 +earliest_time_offset = 14400 +latest_time_offset = 0 [savedsearch://ESCU - Domain Certificate Investigation] type = investigation explanation = none how_to_implement = To successfully implement this phantom playbook, you must integrate Enterprise Security with Phantom. Configure this playbook in the correlation search `Detect DNS requests to Phishing Sites leveraging EvilGinx2` ,as an adaptive response action. known_false_positives = None at this time -earliest_time_offset = 864000 -latest_time_offset = 86400 +earliest_time_offset = 86400 +latest_time_offset = 0 [savedsearch://ESCU - Excessive Account Lockouts Enrichment And Response] type = investigation explanation = none how_to_implement = Import playbook into phantom known_false_positives = None at this time -earliest_time_offset = 604800 -latest_time_offset = 0 +earliest_time_offset = 3600 +latest_time_offset = 3600 [savedsearch://ESCU - Get All AWS Activity From City] type = investigation