mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
791 lines
37 KiB
JSON
791 lines
37 KiB
JSON
{
|
|
"blockly": false,
|
|
"blockly_xml": "<xml></xml>",
|
|
"category": "Attribute Lookup",
|
|
"coa": {
|
|
"data": {
|
|
"description": "Detects available entities and routes them to attribute lookup playbooks. The output of the playbooks will create new artifacts for any technologies that returned information.",
|
|
"edges": [
|
|
{
|
|
"id": "port_0_to_port_2",
|
|
"sourceNode": "0",
|
|
"sourcePort": "0_out",
|
|
"targetNode": "2",
|
|
"targetPort": "2_in"
|
|
},
|
|
{
|
|
"conditions": [
|
|
{
|
|
"index": 0
|
|
}
|
|
],
|
|
"id": "port_2_to_port_3",
|
|
"sourceNode": "2",
|
|
"sourcePort": "2_out",
|
|
"targetNode": "3",
|
|
"targetPort": "3_in"
|
|
},
|
|
{
|
|
"conditions": [
|
|
{
|
|
"index": 1
|
|
}
|
|
],
|
|
"id": "port_2_to_port_4",
|
|
"sourceNode": "2",
|
|
"sourcePort": "2_out",
|
|
"targetNode": "4",
|
|
"targetPort": "4_in"
|
|
},
|
|
{
|
|
"conditions": [
|
|
{
|
|
"index": 0
|
|
}
|
|
],
|
|
"id": "port_3_to_port_5",
|
|
"sourceNode": "3",
|
|
"sourcePort": "3_out",
|
|
"targetNode": "5",
|
|
"targetPort": "5_in"
|
|
},
|
|
{
|
|
"id": "port_5_to_port_7",
|
|
"sourceNode": "5",
|
|
"sourcePort": "5_out",
|
|
"targetNode": "7",
|
|
"targetPort": "7_in"
|
|
},
|
|
{
|
|
"conditions": [
|
|
{
|
|
"index": 1
|
|
}
|
|
],
|
|
"id": "port_7_to_port_8",
|
|
"sourceNode": "7",
|
|
"sourcePort": "7_out",
|
|
"targetNode": "8",
|
|
"targetPort": "8_in"
|
|
},
|
|
{
|
|
"id": "port_6_to_port_9",
|
|
"sourceNode": "6",
|
|
"sourcePort": "6_out",
|
|
"targetNode": "9",
|
|
"targetPort": "9_in"
|
|
},
|
|
{
|
|
"id": "port_9_to_port_1",
|
|
"sourceNode": "9",
|
|
"sourcePort": "9_out",
|
|
"targetNode": "1",
|
|
"targetPort": "1_in"
|
|
},
|
|
{
|
|
"conditions": [
|
|
{
|
|
"index": 0
|
|
}
|
|
],
|
|
"id": "port_7_to_port_10",
|
|
"sourceNode": "7",
|
|
"sourcePort": "7_out",
|
|
"targetNode": "10",
|
|
"targetPort": "10_in"
|
|
},
|
|
{
|
|
"conditions": [
|
|
{
|
|
"index": 0
|
|
}
|
|
],
|
|
"id": "port_10_to_port_6",
|
|
"sourceNode": "10",
|
|
"sourcePort": "10_out",
|
|
"targetNode": "6",
|
|
"targetPort": "6_in"
|
|
}
|
|
],
|
|
"hash": "8ad22687b84264bdee2b40d4620b13cb9f7af309",
|
|
"nodes": {
|
|
"0": {
|
|
"data": {
|
|
"advanced": {
|
|
"join": []
|
|
},
|
|
"functionName": "on_start",
|
|
"id": "0",
|
|
"type": "start"
|
|
},
|
|
"errors": {},
|
|
"id": "0",
|
|
"type": "start",
|
|
"warnings": {},
|
|
"x": 300,
|
|
"y": -1.2789769243681803e-13
|
|
},
|
|
"1": {
|
|
"data": {
|
|
"advanced": {
|
|
"join": []
|
|
},
|
|
"functionName": "on_finish",
|
|
"id": "1",
|
|
"type": "end"
|
|
},
|
|
"errors": {},
|
|
"id": "1",
|
|
"type": "end",
|
|
"warnings": {},
|
|
"x": 300,
|
|
"y": 1536
|
|
},
|
|
"10": {
|
|
"data": {
|
|
"advanced": {
|
|
"customName": "observable filter",
|
|
"customNameId": 0,
|
|
"description": "Exclude Null playbook outputs",
|
|
"join": [],
|
|
"note": "Exclude Null playbook outputs"
|
|
},
|
|
"conditions": [
|
|
{
|
|
"comparisons": [
|
|
{
|
|
"conditionIndex": 0,
|
|
"op": "!=",
|
|
"param": "dispatch_attribute_lookup:playbook_output:observable",
|
|
"value": "None"
|
|
}
|
|
],
|
|
"conditionIndex": 0,
|
|
"customName": "observable not none",
|
|
"logic": "and"
|
|
}
|
|
],
|
|
"functionId": 2,
|
|
"functionName": "observable_filter",
|
|
"id": "10",
|
|
"type": "filter"
|
|
},
|
|
"errors": {},
|
|
"id": "10",
|
|
"type": "filter",
|
|
"warnings": {},
|
|
"x": 340,
|
|
"y": 852
|
|
},
|
|
"2": {
|
|
"data": {
|
|
"advanced": {
|
|
"join": []
|
|
},
|
|
"conditions": [
|
|
{
|
|
"comparisons": [
|
|
{
|
|
"conditionIndex": 0,
|
|
"op": "!=",
|
|
"param": "artifact:*.id",
|
|
"value": ""
|
|
}
|
|
],
|
|
"conditionIndex": 0,
|
|
"customName": "artifact exists",
|
|
"display": "If",
|
|
"logic": "and",
|
|
"type": "if"
|
|
},
|
|
{
|
|
"comparisons": [
|
|
{
|
|
"conditionIndex": 1,
|
|
"op": "==",
|
|
"param": "",
|
|
"value": ""
|
|
}
|
|
],
|
|
"conditionIndex": 1,
|
|
"customName": "artifact does not exist",
|
|
"display": "Else",
|
|
"logic": "and",
|
|
"type": "else"
|
|
}
|
|
],
|
|
"functionId": 1,
|
|
"functionName": "decision_1",
|
|
"id": "2",
|
|
"type": "decision"
|
|
},
|
|
"errors": {},
|
|
"id": "2",
|
|
"type": "decision",
|
|
"warnings": {},
|
|
"x": 360,
|
|
"y": 148
|
|
},
|
|
"3": {
|
|
"data": {
|
|
"advanced": {
|
|
"customName": "new artifact filter",
|
|
"customNameId": 0,
|
|
"description": "Only include new artifacts",
|
|
"join": [],
|
|
"note": "Only include new artifacts"
|
|
},
|
|
"conditions": [
|
|
{
|
|
"comparisons": [
|
|
{
|
|
"conditionIndex": 0,
|
|
"op": "!=",
|
|
"param": "artifact:*.id",
|
|
"value": ""
|
|
}
|
|
],
|
|
"conditionIndex": 0,
|
|
"customName": "artifacts",
|
|
"logic": "and"
|
|
}
|
|
],
|
|
"functionId": 1,
|
|
"functionName": "new_artifact_filter",
|
|
"id": "3",
|
|
"type": "filter"
|
|
},
|
|
"errors": {},
|
|
"id": "3",
|
|
"type": "filter",
|
|
"warnings": {},
|
|
"x": 200,
|
|
"y": 328
|
|
},
|
|
"4": {
|
|
"data": {
|
|
"advanced": {
|
|
"description": "Leave a comment indicating no new artifacts were found",
|
|
"join": [],
|
|
"note": "Leave a comment indicating no new artifacts were found"
|
|
},
|
|
"functionId": 1,
|
|
"functionName": "add_comment_1",
|
|
"id": "4",
|
|
"selectMore": false,
|
|
"tab": "apis",
|
|
"type": "utility",
|
|
"utilities": {
|
|
"comment": {
|
|
"description": "",
|
|
"fields": [
|
|
{
|
|
"description": "",
|
|
"label": "comment",
|
|
"name": "comment",
|
|
"placeholder": "Enter a comment",
|
|
"renderType": "datapath",
|
|
"required": true
|
|
},
|
|
{
|
|
"hidden": true,
|
|
"name": "container",
|
|
"required": false
|
|
},
|
|
{
|
|
"hidden": true,
|
|
"name": "author",
|
|
"required": false
|
|
},
|
|
{
|
|
"hidden": true,
|
|
"name": "trace",
|
|
"required": false
|
|
}
|
|
],
|
|
"label": "add comment",
|
|
"name": "comment"
|
|
}
|
|
},
|
|
"utilityType": "api",
|
|
"values": {
|
|
"comment": {
|
|
"_internal": [
|
|
"container",
|
|
"author",
|
|
"trace"
|
|
],
|
|
"comment": "No new artifacts found."
|
|
}
|
|
}
|
|
},
|
|
"errors": {},
|
|
"id": "4",
|
|
"type": "utility",
|
|
"warnings": {},
|
|
"x": 420,
|
|
"y": 329
|
|
},
|
|
"5": {
|
|
"data": {
|
|
"advanced": {
|
|
"customName": "Dispatch Attribute Lookup",
|
|
"customNameId": 0,
|
|
"join": []
|
|
},
|
|
"functionId": 1,
|
|
"functionName": "dispatch_attribute_lookup",
|
|
"id": "5",
|
|
"inputs": {
|
|
"artifact_ids_include": {
|
|
"datapaths": [
|
|
"filtered-data:new_artifact_filter:condition_1:artifact:*.id"
|
|
],
|
|
"deduplicate": false
|
|
},
|
|
"indicator_tags_exclude": {
|
|
"datapaths": [],
|
|
"deduplicate": false
|
|
},
|
|
"indicator_tags_include": {
|
|
"datapaths": [],
|
|
"deduplicate": false
|
|
},
|
|
"playbook_repo": {
|
|
"datapaths": [
|
|
""
|
|
],
|
|
"deduplicate": false
|
|
},
|
|
"playbook_tags": {
|
|
"datapaths": [
|
|
"attributes"
|
|
],
|
|
"deduplicate": false
|
|
}
|
|
},
|
|
"playbookName": "dispatch_input_playbooks",
|
|
"playbookRepo": 1,
|
|
"playbookRepoName": "community",
|
|
"playbookType": "data",
|
|
"synchronous": true,
|
|
"type": "playbook"
|
|
},
|
|
"errors": {},
|
|
"id": "5",
|
|
"type": "playbook",
|
|
"userCode": "\n # Write your custom code here...\n\n",
|
|
"warnings": {},
|
|
"x": 140,
|
|
"y": 508
|
|
},
|
|
"6": {
|
|
"customCode": null,
|
|
"data": {
|
|
"advanced": {
|
|
"customName": "create entity artifact",
|
|
"customNameId": 0,
|
|
"description": "Create new artifacts with the outputs of the dispatch lookup (Contains custom code)",
|
|
"join": [],
|
|
"note": "Create new artifacts with the outputs of the dispatch lookup (Contains custom code)"
|
|
},
|
|
"customFunction": {
|
|
"draftMode": false,
|
|
"name": "artifact_create",
|
|
"repoName": "community"
|
|
},
|
|
"functionId": 2,
|
|
"functionName": "create_entity_artifact",
|
|
"id": "6",
|
|
"selectMore": false,
|
|
"tab": "customFunctions",
|
|
"type": "utility",
|
|
"utilities": {
|
|
"artifact_create": {
|
|
"description": "Create a new artifact with the specified attributes. Supports all fields available in /rest/artifact. Add any unlisted inputs as dictionary keys in input_json. Unsupported keys will automatically be dropped.",
|
|
"fields": [
|
|
{
|
|
"dataTypes": [
|
|
"phantom container id"
|
|
],
|
|
"description": "Container which the artifact will be added to.",
|
|
"inputType": "item",
|
|
"label": "container",
|
|
"name": "container",
|
|
"placeholder": "container:id",
|
|
"renderType": "datapath",
|
|
"required": false
|
|
},
|
|
{
|
|
"dataTypes": [],
|
|
"description": "The name of the new artifact, which is optional and defaults to \"artifact\".",
|
|
"inputType": "item",
|
|
"label": "name",
|
|
"name": "name",
|
|
"placeholder": "artifact",
|
|
"renderType": "datapath",
|
|
"required": false
|
|
},
|
|
{
|
|
"dataTypes": [],
|
|
"description": "The label of the new artifact, which is optional and defaults to \"events\"",
|
|
"inputType": "item",
|
|
"label": "label",
|
|
"name": "label",
|
|
"placeholder": "events",
|
|
"renderType": "datapath",
|
|
"required": false
|
|
},
|
|
{
|
|
"dataTypes": [
|
|
""
|
|
],
|
|
"description": "The severity of the new artifact, which is optional and defaults to \"Medium\". Typically this is either \"High\", \"Medium\", or \"Low\".",
|
|
"inputType": "item",
|
|
"label": "severity",
|
|
"name": "severity",
|
|
"placeholder": "Medium",
|
|
"renderType": "datapath",
|
|
"required": false
|
|
},
|
|
{
|
|
"dataTypes": [],
|
|
"description": "The name of the CEF field to populate in the artifact, such as \"destinationAddress\" or \"sourceDnsDomain\". Required only if cef_value is provided.",
|
|
"inputType": "item",
|
|
"label": "cef_field",
|
|
"name": "cef_field",
|
|
"placeholder": "destinationAddress",
|
|
"renderType": "datapath",
|
|
"required": false
|
|
},
|
|
{
|
|
"dataTypes": [
|
|
"*"
|
|
],
|
|
"description": "The value of the CEF field to populate in the artifact, such as the IP address, domain name, or file hash. Required only if cef_field is provided.",
|
|
"inputType": "item",
|
|
"label": "cef_value",
|
|
"name": "cef_value",
|
|
"placeholder": "192.0.2.192",
|
|
"renderType": "datapath",
|
|
"required": false
|
|
},
|
|
{
|
|
"dataTypes": [],
|
|
"description": "The CEF data type of the data in cef_value. For example, this could be \"ip\", \"hash\", or \"domain\". Optional.",
|
|
"inputType": "item",
|
|
"label": "cef_data_type",
|
|
"name": "cef_data_type",
|
|
"placeholder": "ip",
|
|
"renderType": "datapath",
|
|
"required": false
|
|
},
|
|
{
|
|
"dataTypes": [],
|
|
"description": "A comma-separated list of tags to apply to the created artifact, which is optional.",
|
|
"inputType": "item",
|
|
"label": "tags",
|
|
"name": "tags",
|
|
"placeholder": "tag1, tag2, tag3",
|
|
"renderType": "datapath",
|
|
"required": false
|
|
},
|
|
{
|
|
"dataTypes": [],
|
|
"description": "Either \"true\" or \"false\", depending on whether or not the new artifact should trigger the execution of any playbooks that are set to active on the label of the container the artifact will be added to. Optional and defaults to \"false\".",
|
|
"inputType": "item",
|
|
"label": "run_automation",
|
|
"name": "run_automation",
|
|
"placeholder": "false",
|
|
"renderType": "datapath",
|
|
"required": false
|
|
},
|
|
{
|
|
"dataTypes": [],
|
|
"description": "Optional parameter to modify any extra attributes of the artifact. Input_json will be merged with other inputs. In the event of a conflict, input_json will take precedence.",
|
|
"inputType": "item",
|
|
"label": "input_json",
|
|
"name": "input_json",
|
|
"placeholder": "{\"source_data_identifier\": \"1234\", \"data\": \"5678\"}",
|
|
"renderType": "datapath",
|
|
"required": false
|
|
}
|
|
],
|
|
"label": "artifact_create",
|
|
"name": "artifact_create"
|
|
}
|
|
},
|
|
"utilityType": "custom_function",
|
|
"values": {
|
|
"artifact_create": {
|
|
"cef_data_type": null,
|
|
"cef_field": null,
|
|
"cef_value": null,
|
|
"container": "container:id",
|
|
"input_json": "",
|
|
"label": "attribute_lookup",
|
|
"name": "filtered-data:observable_filter:condition_1:dispatch_attribute_lookup:playbook_output:observable",
|
|
"run_automation": null,
|
|
"severity": null,
|
|
"tags": null
|
|
}
|
|
}
|
|
},
|
|
"errors": {},
|
|
"id": "6",
|
|
"type": "utility",
|
|
"userCode": "\n parameters = []\n \n for filtered_output_0_dispatch_attribute_lookup_output_observable_item in filtered_output_0_dispatch_attribute_lookup_output_observable:\n name = (\n f\"{filtered_output_0_dispatch_attribute_lookup_output_observable_item[0]['type'].capitalize()} \"\n f\"\\'{filtered_output_0_dispatch_attribute_lookup_output_observable_item[0]['value']}\\' \"\n f\"details from \"\n f\"{filtered_output_0_dispatch_attribute_lookup_output_observable_item[0]['source']}\"\n )\n cef_dict = {\n \"cef\": filtered_output_0_dispatch_attribute_lookup_output_observable_item[0]['attributes']\n }\n parameters.append({\n \"name\": name,\n \"tags\": None,\n \"label\": \"attribute_lookup\",\n \"severity\": None,\n \"cef_field\": None,\n \"cef_value\": None,\n \"container\": id_value,\n \"input_json\": json.dumps(cef_dict),\n \"cef_data_type\": None,\n \"run_automation\": None,\n })\n",
|
|
"warnings": {},
|
|
"x": 280,
|
|
"y": 1220
|
|
},
|
|
"7": {
|
|
"data": {
|
|
"advanced": {
|
|
"customName": "observable decision",
|
|
"customNameId": 0,
|
|
"description": "Determine if there are any results from the dispatch playbook",
|
|
"join": [],
|
|
"note": "Determine if there are any results from the dispatch playbook"
|
|
},
|
|
"conditions": [
|
|
{
|
|
"comparisons": [
|
|
{
|
|
"conditionIndex": 0,
|
|
"op": "!=",
|
|
"param": "dispatch_attribute_lookup:playbook_output:observable",
|
|
"value": "None"
|
|
}
|
|
],
|
|
"conditionIndex": 0,
|
|
"customName": "observables exist",
|
|
"display": "If",
|
|
"logic": "and",
|
|
"type": "if"
|
|
},
|
|
{
|
|
"comparisons": [
|
|
{
|
|
"conditionIndex": 1,
|
|
"op": "==",
|
|
"param": "",
|
|
"value": ""
|
|
}
|
|
],
|
|
"conditionIndex": 1,
|
|
"customName": "observables do not exist",
|
|
"display": "Else",
|
|
"logic": "and",
|
|
"type": "else"
|
|
}
|
|
],
|
|
"functionId": 2,
|
|
"functionName": "observable_decision",
|
|
"id": "7",
|
|
"type": "decision"
|
|
},
|
|
"errors": {},
|
|
"id": "7",
|
|
"type": "decision",
|
|
"warnings": {},
|
|
"x": 220,
|
|
"y": 672
|
|
},
|
|
"8": {
|
|
"data": {
|
|
"advanced": {
|
|
"description": "Leave a comment indicating the playbooks did not have results.",
|
|
"join": [],
|
|
"note": "Leave a comment indicating the playbooks did not have results."
|
|
},
|
|
"functionId": 3,
|
|
"functionName": "add_comment_3",
|
|
"id": "8",
|
|
"selectMore": false,
|
|
"tab": "apis",
|
|
"type": "utility",
|
|
"utilities": {
|
|
"comment": {
|
|
"description": "",
|
|
"fields": [
|
|
{
|
|
"description": "",
|
|
"label": "comment",
|
|
"name": "comment",
|
|
"placeholder": "Enter a comment",
|
|
"renderType": "datapath",
|
|
"required": true
|
|
},
|
|
{
|
|
"hidden": true,
|
|
"name": "container",
|
|
"required": false
|
|
},
|
|
{
|
|
"hidden": true,
|
|
"name": "author",
|
|
"required": false
|
|
},
|
|
{
|
|
"hidden": true,
|
|
"name": "trace",
|
|
"required": false
|
|
}
|
|
],
|
|
"label": "add comment",
|
|
"name": "comment"
|
|
}
|
|
},
|
|
"utilityType": "api",
|
|
"values": {
|
|
"comment": {
|
|
"_internal": [
|
|
"container",
|
|
"author",
|
|
"trace"
|
|
],
|
|
"comment": "No observable data found."
|
|
}
|
|
}
|
|
},
|
|
"errors": {},
|
|
"id": "8",
|
|
"type": "utility",
|
|
"warnings": {},
|
|
"x": 0,
|
|
"y": 853
|
|
},
|
|
"9": {
|
|
"data": {
|
|
"advanced": {
|
|
"join": []
|
|
},
|
|
"customFunction": {
|
|
"draftMode": false,
|
|
"name": "workbook_task_update",
|
|
"repoName": "community"
|
|
},
|
|
"functionId": 4,
|
|
"functionName": "workbook_task_update_4",
|
|
"id": "9",
|
|
"selectMore": false,
|
|
"tab": "customFunctions",
|
|
"type": "utility",
|
|
"utilities": {
|
|
"workbook_task_update": {
|
|
"description": "Update a workbook task by task name",
|
|
"fields": [
|
|
{
|
|
"dataTypes": [
|
|
"*"
|
|
],
|
|
"description": "Name of a workbook task (Required)",
|
|
"inputType": "item",
|
|
"label": "task_name",
|
|
"name": "task_name",
|
|
"placeholder": "my_task",
|
|
"renderType": "datapath",
|
|
"required": false
|
|
},
|
|
{
|
|
"dataTypes": [
|
|
"*"
|
|
],
|
|
"description": "Note title goes here (Optional)",
|
|
"inputType": "item",
|
|
"label": "note_title",
|
|
"name": "note_title",
|
|
"placeholder": "My Title",
|
|
"renderType": "datapath",
|
|
"required": false
|
|
},
|
|
{
|
|
"dataTypes": [
|
|
"*"
|
|
],
|
|
"description": "Body of note goes here (Optional)",
|
|
"inputType": "item",
|
|
"label": "note_content",
|
|
"name": "note_content",
|
|
"placeholder": "My notes",
|
|
"renderType": "datapath",
|
|
"required": false
|
|
},
|
|
{
|
|
"dataTypes": [
|
|
"*"
|
|
],
|
|
"description": "One of: incomplete, in_progress, complete (Optional)",
|
|
"inputType": "item",
|
|
"label": "status",
|
|
"name": "status",
|
|
"placeholder": "in_progress",
|
|
"renderType": "datapath",
|
|
"required": false
|
|
},
|
|
{
|
|
"dataTypes": [
|
|
"*"
|
|
],
|
|
"description": "Assigns task to provided owner. Accepts keyword 'current\" to assign task to currently running playbook user. (Optional)",
|
|
"inputType": "item",
|
|
"label": "owner",
|
|
"name": "owner",
|
|
"placeholder": "username",
|
|
"renderType": "datapath",
|
|
"required": false
|
|
},
|
|
{
|
|
"dataTypes": [
|
|
"phantom container id"
|
|
],
|
|
"description": "ID of Phantom Container (Required)",
|
|
"inputType": "item",
|
|
"label": "container",
|
|
"name": "container",
|
|
"placeholder": "container:id",
|
|
"renderType": "datapath",
|
|
"required": false
|
|
}
|
|
],
|
|
"label": "workbook_task_update",
|
|
"name": "workbook_task_update"
|
|
}
|
|
},
|
|
"utilityType": "custom_function",
|
|
"values": {
|
|
"workbook_task_update": {
|
|
"container": "container:id",
|
|
"note_content": null,
|
|
"note_title": null,
|
|
"owner": null,
|
|
"status": "complete",
|
|
"task_name": "playbook"
|
|
}
|
|
}
|
|
},
|
|
"errors": {},
|
|
"id": "9",
|
|
"type": "utility",
|
|
"warnings": {},
|
|
"x": 280,
|
|
"y": 1388
|
|
}
|
|
},
|
|
"notes": "Outputs: \n- Creates artifacts for attribute details\n- Concludes task"
|
|
},
|
|
"input_spec": null,
|
|
"output_spec": null,
|
|
"playbook_type": "automation",
|
|
"python_version": "3.13",
|
|
"schema": "5.0.9",
|
|
"version": "6.0.0.114895"
|
|
},
|
|
"create_time": "2023-04-06T23:23:35.143183+00:00",
|
|
"draft_mode": false,
|
|
"labels": [
|
|
"*"
|
|
],
|
|
"tags": []
|
|
} |