mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
26 lines
786 B
YAML
26 lines
786 B
YAML
name: AWS IAM Account Unlocking
|
|
id: f15a4db3-b157-4225-86ae-c36ab78b50f2
|
|
version: 2
|
|
creation_date: '2023-06-22'
|
|
modification_date: '2026-05-19'
|
|
author: Lou Stella, Splunk
|
|
type: Response
|
|
description: "Accepts user, to be enabled using AWS IAM connector. Enabling an account involves reattaching their login profile which will require setting a new password. This playbook produces a normalized observables output for each user. "
|
|
playbook: AWS_IAM_Account_Unlocking
|
|
how_to_implement: This input playbook requires the AWS IAM connector to be configured.
|
|
references: []
|
|
app_list:
|
|
- AWS IAM
|
|
platform_tags:
|
|
- user
|
|
- aws_iam
|
|
- D3-RUAA
|
|
- enable_account
|
|
playbook_type: Input
|
|
vpe_type: Modern
|
|
playbook_fields: []
|
|
product:
|
|
- Splunk SOAR
|
|
defend_technique_id:
|
|
- D3-RUAA
|