Branch was auto-updated.

This commit is contained in:
pyth0n1c
2022-02-28 14:24:54 -08:00
committed by GitHub
31 changed files with 31 additions and 0 deletions
@@ -12,6 +12,7 @@ app_list:
- "LDAP"
tags:
platform_tags: []
playbook_type: Automation
playbook_fields:
- compromisedUserName
product:
+1
View File
@@ -14,6 +14,7 @@ app_list:
tags:
platform_tags:
- Cloud
playbook_type: Input
playbook_fields:
- aws_username
product:
+1
View File
@@ -15,6 +15,7 @@ app_list:
tags:
platform_tags:
- Cloud
playbook_type: Automation
playbook_fields: []
product:
- Splunk SOAR
+1
View File
@@ -14,6 +14,7 @@ app_list:
- "OpenDNS Umbrella"
tags:
platform_tags: []
playbook_type: Automation
playbook_fields:
- destinationDnsDomain
- destinationAddress
+1
View File
@@ -12,6 +12,7 @@ app_list:
- "Crowdstrike OAuth"
tags:
platform_tags: []
playbook_type: Automation
playbook_fields:
- filePath
- destinationAddress
+1
View File
@@ -16,6 +16,7 @@ tags:
detections:
- Executable File Written in Administrative SMB Share
platform_tags: []
playbook_type: Automation
playbook_fields:
- filePath
- destinationAddress
@@ -15,6 +15,7 @@ app_list:
- "SMTP"
tags:
platform_tags: []
playbook_type: Automation
playbook_fields:
- fileHash
- vaultId
@@ -15,6 +15,7 @@ tags:
analytic_story:
- Log4Shell CVE-2021-44228
platform_tags: []
playbook_type: Input
playbook_fields:
- hostName
- destinationAddress
@@ -12,6 +12,7 @@ app_list:
- "SSH"
tags:
platform_tags: []
playbook_type: Input
playbook_fields: []
product:
- Splunk SOAR
@@ -12,6 +12,7 @@ app_list:
- "SSH"
tags:
platform_tags: []
playbook_type: Input
playbook_fields: []
product:
- Splunk SOAR
@@ -12,6 +12,7 @@ app_list:
- "SSH"
tags:
platform_tags: []
playbook_type: Input
playbook_fields: []
product:
- Splunk SOAR
@@ -12,6 +12,7 @@ app_list:
- "Windows Remote Management"
tags:
platform_tags: []
playbook_type: Input
playbook_fields: []
product:
- Splunk SOAR
@@ -12,6 +12,7 @@ app_list:
- "Windows Remote Management"
tags:
platform_tags: []
playbook_type: Input
playbook_fields: []
product:
- Splunk SOAR
@@ -12,6 +12,7 @@ app_list:
- "Windows Remote Management"
tags:
platform_tags: []
playbook_type: Input
playbook_fields: []
product:
- Splunk SOAR
+1
View File
@@ -30,5 +30,6 @@ tags:
- Log4Shell JNDI Payload Injection with Outbound Connection
- Detect Outbound LDAP Traffic
playbook_fields: []
playbook_type: Automation
product:
- Splunk SOAR
+1
View File
@@ -30,5 +30,6 @@ tags:
- Log4Shell JNDI Payload Injection with Outbound Connection
- Detect Outbound LDAP Traffic
playbook_fields: []
playbook_type: Automation
product:
- Splunk SOAR
+1
View File
@@ -15,6 +15,7 @@ app_list:
- "VirusTotal"
tags:
platform_tags: []
playbook_type: Automation
playbook_fields:
- fileHash
product:
@@ -22,6 +22,7 @@ tags:
- Conti Common Exec parameter
platform_tags:
- Ransomware
playbook_type: Automation
playbook_fields:
- ComputerName
- Username
@@ -18,6 +18,7 @@ tags:
playbook_outputs:
- note_title
- note_content
playbook_type: Automation
platform_tags:
- Risk Notable
product:
+1
View File
@@ -17,6 +17,7 @@ tags:
playbook_outputs:
- note_title
- note_content
playbook_type: Automation
platform_tags:
- Risk Notable
product:
+1
View File
@@ -34,6 +34,7 @@ tags:
- note_content
platform_tags:
- Risk Notable
playbook_type: Automation
playbook_fields:
- event_id
- info_min_time
+1
View File
@@ -14,6 +14,7 @@ app_list:
tags:
labels:
- risk_notable
playbook_type: Automation
platform_tags:
- Risk Notable
product:
+1
View File
@@ -17,6 +17,7 @@ tags:
playbook_outputs:
- note_title
- note_content
playbook_type: Automation
platform_tags:
- Risk Notable
product:
+1
View File
@@ -13,6 +13,7 @@ app_list:
tags:
labels:
- risk_notable
playbook_type: Automation
platform_tags:
- Risk Notable
product:
+1
View File
@@ -20,6 +20,7 @@ tags:
- risk_notable
platform_tags:
- Risk Notable
playbook_type: Automation
playbook_fields:
- event_id
- info_min_time
@@ -16,6 +16,7 @@ tags:
playbook_outputs:
- note_title
- note_content
playbook_type: Automation
platform_tags:
- Risk Notable
product:
@@ -15,5 +15,6 @@ tags:
- risk_notable
platform_tags:
- Risk Notable
playbook_type: Automation
product:
- Splunk SOAR
+1
View File
@@ -15,5 +15,6 @@ tags:
- risk_notable
platform_tags:
- Risk Notable
playbook_type: Automation
product:
- Splunk SOAR
+1
View File
@@ -12,5 +12,6 @@ app_list: []
tags:
platform_tags: []
playbook_fields: []
playbook_type: Automation
product:
- Splunk SOAR
+1
View File
@@ -13,6 +13,7 @@ app_list: []
tags:
platform_tags:
- threat_intel
playbook_type: Automation
playbook_fields: []
product:
- Splunk SOAR
+1
View File
@@ -15,6 +15,7 @@ tags:
platform_tags:
- threat_intel
- risk_notable
playbook_type: Input
playbook_fields:
- indicators
product: