mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
3.6 KiB
3.6 KiB
Response Schema Schema
http://example.com/example.json
schema for response
| Abstract | Extensible | Status | Identifiable | Custom Properties | Additional Properties | Defined In |
|---|---|---|---|---|---|---|
| Can be instantiated | No | Experimental | No | Forbidden | Permitted |
Response Schema Properties
| Property | Type | Required | Nullable | Default | Defined by |
|---|---|---|---|---|---|
| author | string |
Required | No | "" |
Response Schema (this schema) |
| date | string |
Required | No | "" |
Response Schema (this schema) |
| description | string |
Required | No | "" |
Response Schema (this schema) |
| id | string |
Required | No | "" |
Response Schema (this schema) |
| name | string |
Required | No | "" |
Response Schema (this schema) |
| response_tasks | array |
Required | No | {} |
Response Schema (this schema) |
| tags | object |
Required | No | {} |
Response Schema (this schema) |
| version | integer |
Required | No | 0 |
Response Schema (this schema) |
* |
any | Additional | Yes | this schema allows additional properties |
author
Author of the response
author
- is required
- type:
string - default:
"" - defined in this schema
author Type
string
author Example
"Rico Valdez, Patrick Bareiß, Splunk"
date
version of detection, e.g. 1 or 2 ...
date
- is required
- type:
string - default:
"" - defined in this schema
date Type
string
date Example
"2019-12-06"
description
Description of response
description
- is required
- type:
string - default:
"" - defined in this schema
description Type
string
description Example
"Response example."
id
UUID as unique identifier
id
- is required
- type:
string - default:
"" - defined in this schema
id Type
string
id Example
"fb4c31b0-13e8-4155-8aa5-24de4b8d6717"
name
Name of response
name
- is required
- type:
string - default:
"" - defined in this schema
name Type
string
name Example
"Response Example"
response_tasks
Response tasks divided into phases
response_tasks
- is required
- type:
array - at least
1items in the array - default:
{} - defined in this schema
response_tasks Type
Array type: array
response_tasks Example
{
"another_phase": [
{
"id": "7c72d944-3995-4485-8e57-67b4c353989b",
"name": "Another investigation"
}
],
"identification": [
{
"id": "c36f3f48-e0bb-4c20-a62a-cdc8f6418892",
"name": "Investigate Indicator of Compromise Hash"
},
{
"id": "0dc849b2-2eb4-4fd2-add1-b6cc475765f0",
"name": "Investigate Domains"
}
]
}
tags
An array of key value pairs for tagging
tags
- is required
- type:
object - default:
{} - defined in this schema
tags Type
object with following properties:
| Property | Type | Required |
|---|
tags Example
{
"analytics_story": "credential_dumping"
}
version
version of detection, e.g. 1 or 2 ...
version
- is required
- type:
integer - default:
0 - defined in this schema
version Type
integer
version Example
1