From f8d3d5a1f92a9268113bed33006b4142950f545e Mon Sep 17 00:00:00 2001 From: Lou Stella Date: Tue, 14 Dec 2021 19:43:19 -0600 Subject: [PATCH] SSH response --- playbooks/internal_host_ssh_log4j_respond.yml | 18 ++++++++++++++++++ 1 file changed, 18 insertions(+) create mode 100644 playbooks/internal_host_ssh_log4j_respond.yml diff --git a/playbooks/internal_host_ssh_log4j_respond.yml b/playbooks/internal_host_ssh_log4j_respond.yml new file mode 100644 index 0000000000..70ccfe1842 --- /dev/null +++ b/playbooks/internal_host_ssh_log4j_respond.yml @@ -0,0 +1,18 @@ +name: Internal Host SSH Log4j Respond +id: 6ea2007c-8ef8-4647-a4a4-7825cfee3866 +version: 1 +date: '2021-12-14' +author: Kelby Shelton, Splunk +type: Respond +description: Published in response to CVE-2021-44228, this playbook accepts a list of hosts and filenames to remediate on the endpoint. If filenames are provided, the endpoints will be searched and then the user can approve deletion. Then the user is prompted to quarantine the endpoint. +playbook: internal_host_ssh_log4j_respond +how_to_implement: The ssh asset may require ssh access to delete some files depending on their permissions. +references: ["https://github.com/Neo23x0/Fenrir/blob/master/fenrir.sh"] +app_list: +- "SSH" +tags: + platform_tags: + - Response + playbook_fields: [] + product: + - Splunk SOAR