mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
3953a43f05
* Create response_plan directory * Update directory name * Copy response_templates artifacts to dist/api * Add response-templates schema validation workflow * Add feature branch for testing purpose * Update endpoint to playground * Revert back debug changes * Move scripts to workflows * Remove manual check in * Add sorting for version and template name * Raise exception when file name not match * Add indentation for json output * Add debug option to dump json schema * Generate merged templates at runtime * Rename openAPI spec yaml to yml * Move validation to build.yml * Use stem to get file name * Fix python package install * Update version sorting using int * Update openAPI spec for version * Move build response templates to separate workflow * Fix naming in build-response-templates.yml * Update response templates to the ones for first release * Fix naming of response templates * Response templates to be added by response plan team * Keep response_templates directory * Skip .gitkeep checking when check non-json files * Remove the .gitkeep * Initial version of Response Templates * Initial version of Response Templates * Initial version of Response Templates * Revert "Initial version of Response Templates" This reverts commit3a174dd02e. * Revert "Initial version of Response Templates" This reverts commit26fa66ddde. * Revert "Initial version of Response Templates" This reverts commit6014b4870b. * Initial version of Response Templates * Initial version of Response Templates * Update and rename AccountCompromise_v14.json to AccountCompromise_v2.json * Update and rename DataBreach_v15.json to DataBreach_v2.json * Update and rename GenericIncidentResponse_v13.json to GenericIncidentResponse_v2.json * Update and rename NIST80061_v14.json to NIST80061_v2.json * Update and rename NetworkIndicatorEnrichment_v6.json to NetworkIndicatorEnrichment_v2.json * Update and rename SelfReplicatingMalware_v14.json to SelfReplicatingMalware_v2.json * Update and rename SuspiciousEmail_v35.json to SuspiciousEmail_v2.json * Update and rename VulnerabilityDisclosure_v10.json to VulnerabilityDisclosure_v2.json * Add comments --------- Co-authored-by: pyth0n1c <87383215+pyth0n1c@users.noreply.github.com> Co-authored-by: Christian Cloutier <ccloutier@splunk.com> Co-authored-by: kbouchard <47464052+kbouchardherjavecgroup@users.noreply.github.com> Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
2 lines
18 KiB
JSON
2 lines
18 KiB
JSON
{"id": "94198adf-1fc1-4c2d-8c94-baf4523bee4f", "create_time": 1765479652.5729501, "update_time": 1765479652.5729501, "name": "Account Compromise", "description": "This response template defines a response to the potential compromise of one or more system or application accounts. Across the enterprise, user and service accounts are high-value targets that provide access to wide varieties of resources and capabilities. If an unauthorized entity gains access to an account in your organization, you can use these phases and tasks to organize the effort to investigate and respond. No two account compromises are the same, so some portions of this template might not apply to certain types of account takeovers, and in most cases there will be additional appropriate responses going beyond those listed below. The general structure of this template is based on NIST SP 800-61 Revision 2, and some of the techniques come from the Credential Access tactic in the MITRE ATT&CK framework (https://attack.mitre.org/tactics/TA0006/).", "template_status": "published", "creator": "splunker", "updated_by": "splunker", "is_default": false, "version": 2, "phases": [{"id": "59f2cf8d-3c77-491f-8ff4-65ed341c7503", "create_time": 1765479652.5742395, "update_time": 1765479652.57424, "name": "Detection and Analysis", "order": 1, "tasks": [{"id": "ea986cd7-db3e-48d5-8a44-e9f0f6420d24", "create_time": 1764758755.835523, "update_time": 1765479652.5730562, "name": "Contact account owner", "order": 1, "tag": "51815ce4-c186-4418-9d6c-716e101953f0", "description": "If%20situational%20awareness%20concerns%20allow%20it,%20contact%20the%20legitimate%20owner%20of%20the%20account%20to%20gather%20additional%20insight,%20rule%20out%20false%20positives,%20and%20provide%20guidance%20on%20how%20to%20cooperate.%0A%0ASuggested%20Integrations%0A1.%20%5BIdentity%20Center%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/identity_center)%0A2.%20%5BAsset%20Center%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/asset_center)%0A3.%20SMTP%20(preconfigured)%0A4.%20%5BMS%20Graph%20for%20Office%20365%5D(https://splunkbase.splunk.com/app/5824)%0A5.%20%5BG%20Suite%20for%20GMail%5D(https://splunkbase.splunk.com/app/5795)%0A6.%20%5BCisco%20Webex%5D(https://splunkbase.splunk.com/app/5781)%0A7.%20%5BSlack%5D(https://splunkbase.splunk.com/app/5846)%0A8.%20%5BMicrosoft%20Teams%5D(https://splunkbase.splunk.com/app/5818)", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "c24b5ac1-3e44-4f91-a55e-5c93a0c17a8a", "create_time": 1764758755.8356514, "update_time": 1765479652.573373, "name": "Determine the scope of the compromise", "order": 2, "tag": "4f6e6b64-aeec-456c-806d-d0b66c9db56c", "description": "Determine%20the%20resources%20and%20capabilities%20available%20to%20the%20compromised%20account.%20Consider%20other%20types%20of%20accounts%20that%20can%20also%20be%20accessed%20based%20on%20the%20initial%20compromise.%20Is%20this%20account%20an%20Administrative%20account?%20What%20systems%20has%20the%20account%20logged%20into?%0A%0ASuggested%20Integrations%0A1.%20%5BRisk%20Analysis%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/risk_analysis)%0A2.%20%5BTraffic%20Center%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/traffic_center)%0A3.%20%5BPort%20and%20Protocol%20Tracker%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/port_protocol_tracker)%0A4.%20%5BMalware%20Center%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/malware_center)%0A5.%20%5BMalware%20Search%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/malware_search)%0A6.%20%5BEmail%20Search%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/email_search)", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "4b7b5058-f28e-4776-8806-c71fdfaab979", "create_time": 1764758755.8357468, "update_time": 1765479652.5734894, "name": "Analyze usage of access", "order": 3, "tag": "62fe4b55-7da1-44ba-ae88-93f42cb724c8", "description": "Query%20monitoring%20systems%20to%20determine%20which%20of%20the%20potential%20resources%20and%20capabilities%20were%20actually%20used%20by%20the%20adversary.%20Look%20for%20patterns%20in%20targeted%20resources%20and%20capabilities.%20Was%20the%20compromised%20account%20used%20to%20install%20or%20download%20something?%20Were%20credentials%20to%20other%20accounts%20collected%20and%20used?%0A%0ASuggested%20Integrations%0A1.%20%5BAccess%20Center%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/access_center)%0A2.%20%5BAccount%20Management%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/account_management)%0A3.%20%5BAccess%20Tracker%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/access_tracker)", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "ad738c70-a259-4627-84fc-30f881b1065f", "create_time": 1764758755.835839, "update_time": 1765479652.5735939, "name": "Estimate impact", "order": 4, "tag": "5abdf8e0-f364-4f39-956a-aa912e0543c0", "description": "Estimate the business impact to appropriately allocate priority and resources.", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "1bc12376-4d51-45ed-9e37-38abc31a497a", "create_time": 1764758755.8359327, "update_time": 1765479652.5736716, "name": "Track stolen credentials", "order": 5, "tag": "b7814a6d-ac12-4936-a5ef-8e1a636a08dd", "description": "If%20compromised%20credentials%20were%20used,%20try%20to%20determine%20where%20else%20they%20may%20grant%20access%0A%0ASuggested%20Integrations%0A1.%20%5BAccount%20Management%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/account_management)", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "5de28da8-76f3-4104-8d62-b44f8f46a4a4", "create_time": 1764758755.8360248, "update_time": 1765479652.573762, "name": "Investigate external communications", "order": 6, "tag": "4a46b5da-c9b9-453a-80ad-161db306822e", "description": "Look%20for%20exfiltration%20and/or%20command%20and%20control%20activity.%20Inspect%20network%20traffic%20with%20abnormal%20content,%20focusing%20on%20traffic%20to%20external%20hosts%20and%20internal%20systems%20that%20are%20not%20normally%20connected%20to%20the%20system%20under%20investigation.%0A%0ASuggested%20Integrations%0A1.%20%5BTraffic%20Center%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/traffic_center)%0A2.%20%5BPort%20and%20Protocol%20Tracker%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/port_protocol_tracker)", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "6956c82f-6811-4b3d-975b-fe690e0b54ef", "create_time": 1764758755.836118, "update_time": 1765479652.5738606, "name": "Determine initial access mechanism", "order": 7, "tag": "3b962a5e-16da-4962-9f9f-c237e88e24a3", "description": "Attempt%20to%20trace%20activity%20back%20to%20the%20point%20of%20initial%20access.%20Consider%20phishing,%20watering%20hole%20attacks,%20public-facing%20exploits,%20supply%20chain%20compromises,%20and%20other%20common%20attack%20mechanisms.%0A%0ASuggested%20Integrations%0A1.%20%5BRisk%20Analysis%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/risk_analysis)%0A2.%20%5BTraffic%20Center%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/traffic_center)%0A3.%20%5BPort%20and%20Protocol%20Tracker%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/port_protocol_tracker)%0A4.%20%5BMalware%20Center%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/malware_center)%0A5.%20%5BMalware%20Search%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/malware_search)%0A6.%20%5BEmail%20Search%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/email_search)", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "62a7c0a4-1c2e-4922-8dd2-9114ef305607", "create_time": 1764758755.8362353, "update_time": 1765479652.573958, "name": "Detect persistent system access", "order": 8, "tag": "023e3b98-335b-4364-8292-e34e221dcdcd", "description": "Look%20for%20attempts%20to%20establish%20persistent%20access%20to%20one%20or%20more%20systems.%20The%20persistence%20technique%20could%20include%20an%20email%20forwarding%20rule%20for%20an%20email%20account,%20a%20scheduled%20task%20on%20an%20endpoint,%20a%20newly%20added%20login%20method%20for%20a%20business%20application,%20or%20a%20wide%20array%20of%20others.%20One%20non-exhaustive%20list%20of%20persistence%20techniques%20is%20in%20the%20MITRE%20ATT&CK%20framework%20(https://attack.mitre.org/tactics/TA0003/)%20and%20another%20for%20Windows%20endpoints%20in%20particular%20is%20within%20the%20SysInternals%20Autoruns%20tool.%0A%0ASuggested%20Integrations%0A1.%20%5BRisk%20Analysis%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/risk_analysis)%0A2.%20%5BTraffic%20Center%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/traffic_center)%0A3.%20%5BPort%20and%20Protocol%20Tracker%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/port_protocol_tracker)%0A4.%20%5BMalware%20Center%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/malware_center)%0A5.%20%5BMalware%20Search%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/malware_search)%0A6.%20%5BEmail%20Search%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/email_search)", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "0bc09ecd-b582-4b51-82bd-845113fe9025", "create_time": 1764758755.8363278, "update_time": 1765479652.5740716, "name": "Enumerate other similarly vulnerable accounts", "order": 9, "tag": "44b55fc1-e45f-46ce-82d8-d23b1392790f", "description": "If an initial attack vector or other activity pattern is found, use it to look for other similarly compromised accounts.", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "60b63967-c82f-4378-80ab-7234d3b8d01a", "create_time": 1764758755.8364184, "update_time": 1765479652.5741494, "name": "Notify stakeholders", "order": 10, "tag": "6f26711e-c173-4394-91cf-f2e9c7c88d8a", "description": "Notify%20incident%20response%20leadership,%20system%20owners,%20and%20other%20stakeholders%20in%20accordance%20with%20established%20incident%20notification%20and%20escalation%20procedures.%0A%0ASuggested%20Integrations%0A1.%20%5BIdentity%20Center%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/identity_center)%0A2.%20%5BAsset%20Center%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/asset_center)%0A3.%20SMTP%20(preconfigured)%0A4.%20%5BMS%20Graph%20for%20Office%20365%5D(https://splunkbase.splunk.com/app/5824)%0A5.%20%5BG%20Suite%20for%20GMail%5D(https://splunkbase.splunk.com/app/5795)%0A6.%20%5BCisco%20Webex%5D(https://splunkbase.splunk.com/app/5781)%0A7.%20%5BSlack%5D(https://splunkbase.splunk.com/app/5846)%0A8.%20%5BMicrosoft%20Teams%5D(https://splunkbase.splunk.com/app/5818)", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}]}, {"id": "48075a18-75b5-45d5-9c14-c791c0975316", "create_time": 1765479652.574572, "update_time": 1765479652.5745726, "name": "Containment, Eradication, and Recovery", "order": 2, "tasks": [{"id": "4fa28acc-820f-4b9c-8fbe-b06dc8f735bb", "create_time": 1764758755.8365533, "update_time": 1765479652.5743093, "name": "Disable account", "order": 1, "tag": "582f0358-63c7-4a15-ba9e-a42861e854b5", "description": "If%20the%20business%20risk%20is%20deemed%20acceptable,%20disable%20the%20account%20or%20reset%20credentials%20to%20prevent%20further%20malicious%20usage.%0A%0ASuggested%20Integrations%0A1.%20%5BMS%20Graph%20For%20Active%20Directory%5D(https://splunkbase.splunk.com/app/6395)%0A2.%20%5BAD%20LDAP%5D(https://splunkbase.splunk.com/app/5755)%0A3.%20%5BOkta%5D(https://splunkbase.splunk.com/app/5921)%0A4.%20%5BAWS%20IAM%5D(https://splunkbase.splunk.com/app/5763)%0A5.%20%5BAzure%20AD%20Graph%5D(https://splunkbase.splunk.com/app/5771)", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "f20c28db-b508-4cce-bd08-df4a1b92b1e4", "create_time": 1764758755.836641, "update_time": 1765479652.5744092, "name": "Remove persistent system access", "order": 2, "tag": "5cfd8324-141b-407f-ac19-3ab946178fc8", "description": "If%20persistent%20access%20mechanisms%20were%20detected,%20remove%20them%20by%20uninstalling%20software,%20unhooking%20libraries,%20reimaging%20systems,%20disabling%20compromised%20credentials,%20or%20implementing%20other%20remediations.%20If%20this%20action%20will%20cause%20a%20service%20outage,%20it%20may%20be%20prudent%20to%20notify%20the%20affected%20teams%20or%20organizations.%0A%0ASuggested%20Integrations%0A1.%20%5BMS%20Graph%20For%20Active%20Directory%5D(https://splunkbase.splunk.com/app/6395)%0A2.%20%5BAD%20LDAP%5D(https://splunkbase.splunk.com/app/5755)%0A3.%20%5BOkta%5D(https://splunkbase.splunk.com/app/5921)%0A4.%20%5BAWS%20IAM%5D(https://splunkbase.splunk.com/app/5763)%0A5.%20%5BAzure%20AD%20Graph%5D(https://splunkbase.splunk.com/app/5771)", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "b94cc55d-a653-466a-8faf-846f699ebb75", "create_time": 1764758755.836737, "update_time": 1765479652.5745091, "name": "Mitigate or remediate vulnerabilities", "order": 3, "tag": "25d66876-4448-420d-80b5-bc359805598b", "description": "If%20any%20vulnerabilities%20were%20used%20in%20this%20compromise,%20find%20a%20way%20to%20mitigate%20or%20remediate%20them.%20This%20could%20be%20a%20system%20update,%20a%20change%20in%20software,%20disabling%20a%20certain%20feature,%20a%20change%20in%20policy,%20or%20another%20action.%0A%0ASuggested%20Integrations%0A1.%20%20%5BCrowdstrike%5D(https://splunkbase.splunk.com/app/5786)%0A2.%20%5BMicrosoft%20Defender%20for%20Endpoint%5D(https://splunkbase.splunk.com/app/5870)%0A3.%20%5BVMware%20Carbon%20Black%20Cloud%20for%20Splunk%20SOAR%5D(https://splunkbase.splunk.com/app/6732)", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}]}, {"id": "36274751-b970-4375-85dc-b06a13d05cc2", "create_time": 1765479652.5748563, "update_time": 1765479652.5748568, "name": "Post-incident Activity", "order": 3, "tasks": [{"id": "c601515a-bbef-485f-819a-9c1e477e413e", "create_time": 1764758755.8368754, "update_time": 1765479652.57464, "name": "Notify necessary parties", "order": 1, "tag": "6e6b6839-fced-46a4-a660-e00281118cda", "description": "Determine%20if%20a%20regulatory%20risk%20calls%20for%20a%20notification%20to%20an%20internal%20or%20external%20compliance%20organization.%20Also%20consider%20an%20informational%20notice%20to%20users%20to%20prevent%20similar%20compromises%20through%20improved%20security%20hygiene.%0A%0ASuggested%20Integrations%0A1.%20SMTP%20(preconfigured)%0A2.%20%5BMS%20Graph%20for%20Office%20365%5D(https://splunkbase.splunk.com/app/5824)%0A3.%20%5BG%20Suite%20for%20GMail%5D(https://splunkbase.splunk.com/app/5795)%0A4.%20%5BCisco%20Webex%5D(https://splunkbase.splunk.com/app/5781)%0A5.%20%5BSlack%5D(https://splunkbase.splunk.com/app/5846)%0A6.%20%5BMicrosoft%20Teams%5D(https://splunkbase.splunk.com/app/5818)", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "33acb96f-1113-489b-8dc4-882695963f99", "create_time": 1764758755.836966, "update_time": 1765479652.574736, "name": "Tune prevention systems", "order": 2, "tag": "47e3bd73-9fea-4f85-a805-9ebedfd000ed", "description": "Depending on the mechanism of access and the systems affected, there may be a clear next step to prevent similar compromises. This might involve deployment of strong multi-factor authentication, improved automated response, stronger application of least privilege, user training, and/or a wide array of other defensive measures. Consider using CIS Cybersecurity Best Practices (https://www.cisecurity.org/cybersecurity-best-practices/) or a similar framework to assess improvements in prevention.", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "0d0ded65-d9dd-497f-ab9d-f51864ad88af", "create_time": 1764758755.8370595, "update_time": 1765479652.574812, "name": "Tune detection systems", "order": 3, "tag": "9411f544-f06a-4e79-9972-3844f61cc1f7", "description": "Any of the steps taken within the Detection and Analysis phase may be candidates for automated or regularly scheduled detections to find similar activity. Focus on the most generalizable patterns that will catch high-impact compromises as early as possible.", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}]}], "template_id": "8b0ea69b-c29f-4a70-b58b-59164312a491", "active": true, "used": true, "_user": "nobody", "_key": "94198adf-1fc1-4c2d-8c94-baf4523bee4f"}
|