mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
27 lines
944 B
YAML
27 lines
944 B
YAML
name: Splunk Message Identifier Activity Analysis
|
|
id: 5299b9dc-e8c4-46ba-d942-98dae0fa816d
|
|
version: 2
|
|
creation_date: '2023-05-16'
|
|
modification_date: '2026-05-19'
|
|
author: Lou Stella, Splunk; Kelby Shelton, Splunk
|
|
type: Investigation
|
|
description: "Accepts an internet message id, and asks Splunk to look for records that have a matching internet message id. It then produces a normalized output and summary table."
|
|
playbook: Splunk_Message_Identifier_Activity_Analysis
|
|
how_to_implement: This input playbook requires the Splunk connector to be configured. You will also need data populating the Email.All_Email datamodel in the out-of-the-box configuration of this playbook.
|
|
references: []
|
|
app_list:
|
|
- Splunk
|
|
platform_tags:
|
|
- message_identifier_activity
|
|
- internet_message_id
|
|
- splunk
|
|
playbook_type: Input
|
|
vpe_type: Modern
|
|
playbook_fields: []
|
|
product:
|
|
- Splunk SOAR
|
|
use_cases:
|
|
- Phishing
|
|
defend_technique_id:
|
|
- D3-IAA
|