Files
splunk-security_content/docs/_playbooks/internal_host_winrm_response.md
2021-12-15 17:42:47 -06:00

1.3 KiB

title, last_modified_at, toc, toc_label, tags
title last_modified_at toc toc_label tags
Internal Host WinRM Response 2021-12-14 true
Investigation
Splunk SOAR
Windows Remote Management

Try in Splunk SOAR{: .btn .btn--success}

Description

Published in response to CVE-2021-44228, this playbook accepts a list of hosts and filenames to remediate on the endpoint. If filenames are provided, the endpoints will be searched and then the user can approve deletion. Then the user is prompted to quarantine the endpoint.

  • Type: Investigation
  • Product: Splunk SOAR
  • Apps: [Windows Remote Management](https://splunkbase.splunk.com/apps/#/search/Windows Remote Management/product/soar)
  • Last Updated: 2021-12-14
  • Author: Kelby Shelton, Splunk
  • ID: 32fd9db5-5201-4b2f-b2c2-9299c7b3495d

Associated Detections

How To Implement

The winrm asset requires Administrator access to gather certain files.

Playbooks

Required field

Reference

source | version: 1