mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
SSH response
This commit is contained in:
@@ -0,0 +1,18 @@
|
||||
name: Internal Host SSH Log4j Respond
|
||||
id: 6ea2007c-8ef8-4647-a4a4-7825cfee3866
|
||||
version: 1
|
||||
date: '2021-12-14'
|
||||
author: Kelby Shelton, Splunk
|
||||
type: Respond
|
||||
description: Published in response to CVE-2021-44228, this playbook accepts a list of hosts and filenames to remediate on the endpoint. If filenames are provided, the endpoints will be searched and then the user can approve deletion. Then the user is prompted to quarantine the endpoint.
|
||||
playbook: internal_host_ssh_log4j_respond
|
||||
how_to_implement: The ssh asset may require ssh access to delete some files depending on their permissions.
|
||||
references: ["https://github.com/Neo23x0/Fenrir/blob/master/fenrir.sh"]
|
||||
app_list:
|
||||
- "SSH"
|
||||
tags:
|
||||
platform_tags:
|
||||
- Response
|
||||
playbook_fields: []
|
||||
product:
|
||||
- Splunk SOAR
|
||||
Reference in New Issue
Block a user