Files
kbouchard fc1596e371 had to remove 8.5 from the name of response plans
had to remove 8.5 from the name of response plans
2026-04-01 20:55:54 -07:00

1 line
29 KiB
JSON

{"id": "24bed4c7-0619-48cc-99f2-bb743b906b86", "create_time": 1774285685.1605833, "update_time": 1774287836.187132, "name": "Account Compromise", "description": "This response template defines a response to the potential compromise of one or more system or application accounts. Across the enterprise, user and service accounts are high-value targets that provide access to wide varieties of resources and capabilities. If an unauthorized entity gains access to an account in your organization, you can use these phases and tasks to organize the effort to investigate and respond. No two account compromises are the same, so some portions of this template might not apply to certain types of account takeovers, and in most cases there will be additional appropriate responses going beyond those listed below. The general structure of this template is based on NIST SP 800-61 Revision 2, and some of the techniques come from the Credential Access tactic in the MITRE ATT&CK framework (https://attack.mitre.org/tactics/TA0006/).", "template_status": "published", "creator": "splunker", "updated_by": "splunker", "is_default": false, "version": 3, "phases": [{"id": "59f2cf8d-3c77-491f-8ff4-65ed341c7503", "create_time": 1774286335.6388953, "update_time": 1774287836.1570373, "name": "Detection and Analysis", "order": 1, "tasks": [{"id": "ea986cd7-db3e-48d5-8a44-e9f0f6420d24", "create_time": 1764758755.835523, "update_time": 1774287836.1558409, "name": "Contact account owner", "order": 1, "tag": "51815ce4-c186-4418-9d6c-716e101953f0", "description": "If%20situational%20awareness%20concerns%20allow%20it,%20contact%20the%20legitimate%20owner%20of%20the%20account%20to%20gather%20additional%20insight,%20rule%20out%20false%20positives,%20and%20provide%20guidance%20on%20how%20to%20cooperate.%0A%0ASuggested%20Dashboards%0A1.%20%5BIdentity%20Center%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/identity_center)%0A2.%20%5BAsset%20Center%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/asset_center)%0A%0ASuggested%20Integration%20(%20if%20not%20already%20configured%20navigate%20%5BHERE%5D(/app/SplunkEnterpriseSecuritySuite/ess_configuration/#/soar/soar_apps/apps)%20to%20locate%20and%20configure)%0A1.%20SMTP%0A2.%20%20MS%20Graph%20for%20Office%20365%0A3.%20%20G%20Suite%20for%20GMail%0A4.%20Cisco%20Webex%0A5.%20Slack%0A6.%20Microsoft%20Teams%0A", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [{"id": "8455876d-ff87-4e0c-94a7-d0701bfafd1a", "create_time": 1774286335.6375985, "update_time": 1774287836.155941, "last_job_id": 0, "name": "send email - MS Graph for Office 365", "action": "8880", "description": "Sends an email with optional text rendering. Attachments are allowed a Content-ID tag for reference within the html", "type": "send email", "app_id": 175, "asset": 15, "parameters": [{"cc": "", "to": "", "bcc": "", "body": "", "from": "", "headers": "", "subject": "", "attachments": ""}]}, {"id": "805d728f-1b7e-4f8b-a3e7-d4cd0ae95e8f", "create_time": 1774286335.6376438, "update_time": 1774287836.155979, "last_job_id": 0, "name": "send email - G Suite for GMail", "action": "9227", "description": "Send emails", "type": "send email", "app_id": 123, "asset": 34, "parameters": [{"cc": "", "to": "", "bcc": "", "body": "", "from": "", "headers": "", "subject": "", "reply_to": "", "alias_name": "", "alias_email": "", "attachments": ""}]}, {"id": "6bc80e11-fe95-4b12-8a0b-3901d9227cc2", "create_time": 1774286335.637685, "update_time": 1774287836.1560147, "last_job_id": 0, "name": "send email - SMTP", "action": "9244", "description": "Sends an email", "type": "send email", "app_id": 260, "asset": 36, "parameters": [{"cc": "", "to": "", "bcc": "", "body": "", "from": "", "headers": "", "subject": "", "attachments": ""}]}, {"id": "7f0b5859-cf10-41f0-86aa-e0d41425665b", "create_time": 1774286335.6377256, "update_time": 1774287836.1560483, "last_job_id": 0, "name": "send message - Cisco Webex", "action": "9205", "description": "Send message to user or room", "type": "send message", "app_id": 64, "asset": 32, "parameters": [{"message": "", "endpoint_id": "", "is_markdown": false, "destination_type": ""}]}, {"id": "88126d92-3fa1-4871-9c76-a2a873731077", "create_time": 1774286335.6377847, "update_time": 1774287836.1560822, "last_job_id": 0, "name": "send message - Slack", "action": "8927", "description": "Send a message to Slack", "type": "send message", "app_id": 277, "asset": 22, "parameters": [{"blocks": "", "message": "", "link_names": false, "destination": "", "reply_broadcast": false, "parent_message_ts": ""}]}, {"id": "d382f065-82d3-420f-bb87-624e599c5cf5", "create_time": 1774286335.6378274, "update_time": 1774287836.1561167, "last_job_id": 0, "name": "send chat message - Microsoft Teams", "action": "9235", "description": "Send a message to specific chat", "type": "send chat message", "app_id": 198, "asset": 35, "parameters": [{"chat_id": "", "message": ""}]}], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "c24b5ac1-3e44-4f91-a55e-5c93a0c17a8a", "create_time": 1764758755.8356514, "update_time": 1774287836.1562, "name": "Determine the scope of the compromise", "order": 2, "tag": "4f6e6b64-aeec-456c-806d-d0b66c9db56c", "description": "Determine%20the%20resources%20and%20capabilities%20available%20to%20the%20compromised%20account.%20Consider%20other%20types%20of%20accounts%20that%20can%20also%20be%20accessed%20based%20on%20the%20initial%20compromise.%20Is%20this%20account%20an%20Administrative%20account?%20What%20systems%20has%20the%20account%20logged%20into?%0A%0ASuggested%20Dashboards%0A1.%20%5BRisk%20Analysis%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/risk_analysis)%0A2.%20%5BTraffic%20Center%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/traffic_center)%0A3.%20%5BPort%20and%20Protocol%20Tracker%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/port_protocol_tracker)%0A4.%20%5BMalware%20Center%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/malware_center)%0A5.%20%5BMalware%20Search%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/malware_search)%0A6.%20%5BEmail%20Search%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/email_search)", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "4b7b5058-f28e-4776-8806-c71fdfaab979", "create_time": 1764758755.8357468, "update_time": 1774287836.1563084, "name": "Analyze usage of access", "order": 3, "tag": "62fe4b55-7da1-44ba-ae88-93f42cb724c8", "description": "Query%20monitoring%20systems%20to%20determine%20which%20of%20the%20potential%20resources%20and%20capabilities%20were%20actually%20used%20by%20the%20adversary.%20Look%20for%20patterns%20in%20targeted%20resources%20and%20capabilities.%20Was%20the%20compromised%20account%20used%20to%20install%20or%20download%20something?%20Were%20credentials%20to%20other%20accounts%20collected%20and%20used?%0A%0ASuggested%20Dashboards%0A1.%20%5BAccess%20Center%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/access_center)%0A2.%20%5BAccount%20Management%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/account_management)%0A3.%20%5BAccess%20Tracker%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/access_tracker)", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "ad738c70-a259-4627-84fc-30f881b1065f", "create_time": 1764758755.835839, "update_time": 1774287836.1564088, "name": "Estimate impact", "order": 4, "tag": "5abdf8e0-f364-4f39-956a-aa912e0543c0", "description": "Estimate the business impact to appropriately allocate priority and resources.", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "1bc12376-4d51-45ed-9e37-38abc31a497a", "create_time": 1764758755.8359327, "update_time": 1774287836.1564844, "name": "Track stolen credentials", "order": 5, "tag": "b7814a6d-ac12-4936-a5ef-8e1a636a08dd", "description": "If%20compromised%20credentials%20were%20used,%20try%20to%20determine%20where%20else%20they%20may%20grant%20access%0A%0ASuggested%20Dashboards%0A1.%20%5BAccount%20Management%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/account_management)", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "5de28da8-76f3-4104-8d62-b44f8f46a4a4", "create_time": 1764758755.8360248, "update_time": 1774287836.1565707, "name": "Investigate external communications", "order": 6, "tag": "4a46b5da-c9b9-453a-80ad-161db306822e", "description": "Look%20for%20exfiltration%20and/or%20command%20and%20control%20activity.%20Inspect%20network%20traffic%20with%20abnormal%20content,%20focusing%20on%20traffic%20to%20external%20hosts%20and%20internal%20systems%20that%20are%20not%20normally%20connected%20to%20the%20system%20under%20investigation.%0A%0ASuggested%20Dashboards%0A1.%20%5BTraffic%20Center%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/traffic_center)%0A2.%20%5BPort%20and%20Protocol%20Tracker%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/port_protocol_tracker)", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "6956c82f-6811-4b3d-975b-fe690e0b54ef", "create_time": 1764758755.836118, "update_time": 1774287836.1566656, "name": "Determine initial access mechanism", "order": 7, "tag": "3b962a5e-16da-4962-9f9f-c237e88e24a3", "description": "Attempt%20to%20trace%20activity%20back%20to%20the%20point%20of%20initial%20access.%20Consider%20phishing,%20watering%20hole%20attacks,%20public-facing%20exploits,%20supply%20chain%20compromises,%20and%20other%20common%20attack%20mechanisms.%0A%0ASuggested%20Dashboards%0A1.%20%5BRisk%20Analysis%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/risk_analysis)%0A2.%20%5BTraffic%20Center%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/traffic_center)%0A3.%20%5BPort%20and%20Protocol%20Tracker%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/port_protocol_tracker)%0A4.%20%5BMalware%20Center%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/malware_center)%0A5.%20%5BMalware%20Search%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/malware_search)%0A6.%20%5BEmail%20Search%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/email_search)", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "62a7c0a4-1c2e-4922-8dd2-9114ef305607", "create_time": 1764758755.8362353, "update_time": 1774287836.1567857, "name": "Detect persistent system access", "order": 8, "tag": "023e3b98-335b-4364-8292-e34e221dcdcd", "description": "Look%20for%20attempts%20to%20establish%20persistent%20access%20to%20one%20or%20more%20systems.%20The%20persistence%20technique%20could%20include%20an%20email%20forwarding%20rule%20for%20an%20email%20account,%20a%20scheduled%20task%20on%20an%20endpoint,%20a%20newly%20added%20login%20method%20for%20a%20business%20application,%20or%20a%20wide%20array%20of%20others.%20One%20non-exhaustive%20list%20of%20persistence%20techniques%20is%20in%20the%20MITRE%20ATT&CK%20framework%20(https://attack.mitre.org/tactics/TA0003/)%20and%20another%20for%20Windows%20endpoints%20in%20particular%20is%20within%20the%20SysInternals%20Autoruns%20tool.%0A%0ASuggested%20Dashboards%0A1.%20%5BRisk%20Analysis%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/risk_analysis)%0A2.%20%5BTraffic%20Center%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/traffic_center)%0A3.%20%5BPort%20and%20Protocol%20Tracker%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/port_protocol_tracker)%0A4.%20%5BMalware%20Center%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/malware_center)%0A5.%20%5BMalware%20Search%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/malware_search)%0A6.%20%5BEmail%20Search%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/email_search)", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "0bc09ecd-b582-4b51-82bd-845113fe9025", "create_time": 1764758755.8363278, "update_time": 1774287836.156898, "name": "Enumerate other similarly vulnerable accounts", "order": 9, "tag": "44b55fc1-e45f-46ce-82d8-d23b1392790f", "description": "If an initial attack vector or other activity pattern is found, use it to look for other similarly compromised accounts.", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "60b63967-c82f-4378-80ab-7234d3b8d01a", "create_time": 1764758755.8364184, "update_time": 1774287836.156971, "name": "Notify stakeholders", "order": 10, "tag": "6f26711e-c173-4394-91cf-f2e9c7c88d8a", "description": "Notify%20incident%20response%20leadership,%20system%20owners,%20and%20other%20stakeholders%20in%20accordance%20with%20established%20incident%20notification%20and%20escalation%20procedures.%0A%0ASuggested%20Dashboards%0A1.%20%5BIdentity%20Center%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/identity_center)%0A2.%20%5BAsset%20Center%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/asset_center)%0A%0ASuggested%20Integration%20(%20if%20not%20already%20configured%20navigate%20%5BHERE%5D(/app/SplunkEnterpriseSecuritySuite/ess_configuration/#/soar/soar_apps/apps)%20to%20locate%20and%20configure)%0A1.%20SMTP%0A2.%20%20MS%20Graph%20for%20Office%20365%0A3.%20%20G%20Suite%20for%20GMail%0A4.%20Cisco%20Webex%0A5.%20Slack%0A6.%20Microsoft%20Teams%0A", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}]}, {"id": "48075a18-75b5-45d5-9c14-c791c0975316", "create_time": 1774286335.6392124, "update_time": 1774287836.1582365, "name": "Containment, Eradication, and Recovery", "order": 2, "tasks": [{"id": "4fa28acc-820f-4b9c-8fbe-b06dc8f735bb", "create_time": 1764758755.8365533, "update_time": 1774287836.157103, "name": "Disable account", "order": 1, "tag": "582f0358-63c7-4a15-ba9e-a42861e854b5", "description": "If%20the%20business%20risk%20is%20deemed%20acceptable,%20disable%20the%20account%20or%20reset%20credentials%20to%20prevent%20further%20malicious%20usage.%0A%0ASuggested%20Integration%20(%20if%20not%20already%20configured%20navigate%20%5BHERE%5D(/app/SplunkEnterpriseSecuritySuite/ess_configuration/#/soar/soar_apps/apps)%20to%20locate%20and%20configure)%0A1.%20MS%20Graph%20For%20Active%20Directory%0A2.%20AD%20LDAP%0A3.%20Okta%0A4.%20AWS%20IAM%0A5.%20Azure%20AD%20Graph", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [{"id": "0c30864f-6c65-46b6-b59e-8e1a20c37563", "create_time": 1774287088.690807, "update_time": 1774287836.157173, "last_job_id": 0, "name": "disable account - AD LDAP", "action": "8679", "description": "Disables an Active Directory account", "type": "disable account", "app_id": 1, "asset": 8, "parameters": [{"user": "", "use_samaccountname": false}]}, {"id": "a46062fe-273b-4fa5-889d-858beb41953b", "create_time": 1774287088.6908832, "update_time": 1774287836.157207, "last_job_id": 0, "name": "disable user - Okta", "action": "8889", "description": "Disables the specified user", "type": "disable user", "app_id": 215, "asset": 17, "parameters": [{"id": ""}]}, {"id": "fcf9cd36-1c87-4f4d-83f6-d6749a8fe568", "create_time": 1774287088.6909559, "update_time": 1774287836.157241, "last_job_id": 0, "name": "disable user - Azure AD Graph", "action": "8722", "description": "Disable a user", "type": "disable user", "app_id": 30, "asset": 39, "parameters": [{"user_id": ""}]}, {"id": "c63553c3-1f1d-4f42-8e36-4b599bf2e01f", "create_time": 1774287088.6910272, "update_time": 1774287836.157275, "last_job_id": 0, "name": "disable user - AWS IAM", "action": "211", "description": "Disable login profile and access keys of a user", "type": "disable user", "app_id": 10, "asset": 38, "parameters": [{"username": "", "credentials": "", "disable_access_keys": false}]}, {"id": "e20226fb-5240-4afe-aad5-e65e4f02a926", "create_time": 1774287088.6911008, "update_time": 1774287836.1573093, "last_job_id": 0, "name": "disable user - MS Graph for Active Directory", "action": "9252", "description": "Disable a user", "type": "disable user", "app_id": 174, "asset": 37, "parameters": [{"user_id": ""}]}], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "f20c28db-b508-4cce-bd08-df4a1b92b1e4", "create_time": 1764758755.836641, "update_time": 1774287836.1573668, "name": "Remove persistent system access", "order": 2, "tag": "5cfd8324-141b-407f-ac19-3ab946178fc8", "description": "If%20persistent%20access%20mechanisms%20were%20detected,%20remove%20them%20by%20uninstalling%20software,%20unhooking%20libraries,%20reimaging%20systems,%20disabling%20compromised%20credentials,%20or%20implementing%20other%20remediations.%20If%20this%20action%20will%20cause%20a%20service%20outage,%20it%20may%20be%20prudent%20to%20notify%20the%20affected%20teams%20or%20organizations.%0A%0ASuggested%20Integration%20(%20if%20not%20already%20configured%20navigate%20%5BHERE%5D(/app/SplunkEnterpriseSecuritySuite/ess_configuration/#/soar/soar_apps/apps)%20to%20locate%20and%20configure)%0A1.%20MS%20Graph%20For%20Active%20Directory%0A2.%20AD%20LDAP%0A3.%20Okta%0A4.%20AWS%20IAM%0A5.%20Azure%20AD%20Graph%0A6.%20Crowdstrike%0A7.%20Microsoft%20Defender%20for%20Endpoint%0A8.%20VMware%20Carbon%20Black%20Cloud%20for%20Splunk%20SOAR", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [{"id": "1cf4d6ae-8933-43dd-aca4-04aa64728568", "create_time": 1774287549.2973208, "update_time": 1774287836.1574392, "last_job_id": 0, "name": "disable account - AD LDAP", "action": "8679", "description": "Disables an Active Directory account", "type": "disable account", "app_id": 1, "asset": 8, "parameters": [{"user": "", "use_samaccountname": false}]}, {"id": "15ac2d9c-4805-4909-b356-9adcda27a445", "create_time": 1774287549.2973638, "update_time": 1774287836.1574743, "last_job_id": 0, "name": "disable tokens - Azure AD Graph", "action": "8720", "description": "Invalidate all active refresh tokens for a user in an Azure AD environment", "type": "disable tokens", "app_id": 30, "asset": 39, "parameters": [{"user_id": ""}]}, {"id": "96474342-0e1e-4a56-906a-d6d0fce31213", "create_time": 1774287549.2974057, "update_time": 1774287836.1575081, "last_job_id": 0, "name": "disable tokens - MS Graph for Active Directory", "action": "9250", "description": "Invalidate all active refresh tokens for a user in a Microsoft AD environment", "type": "disable tokens", "app_id": 174, "asset": 37, "parameters": [{"user_id": ""}]}, {"id": "b7db5b25-56f3-4ea1-9c39-db385ac25f75", "create_time": 1774287549.2974458, "update_time": 1774287836.157542, "last_job_id": 0, "name": "disable user - Azure AD Graph", "action": "8722", "description": "Disable a user", "type": "disable user", "app_id": 30, "asset": 39, "parameters": [{"user_id": ""}]}, {"id": "58b75339-9d0c-4cd0-a10d-ab68d81c8b58", "create_time": 1774287549.2974875, "update_time": 1774287836.1575754, "last_job_id": 0, "name": "disable user - AWS IAM", "action": "211", "description": "Disable login profile and access keys of a user", "type": "disable user", "app_id": 10, "asset": 38, "parameters": [{"username": "", "credentials": "", "disable_access_keys": false}]}, {"id": "8b6656a3-d7ee-4c9b-9148-f4f8b57cd332", "create_time": 1774287549.29753, "update_time": 1774287836.1576087, "last_job_id": 0, "name": "disable user - Okta", "action": "8889", "description": "Disables the specified user", "type": "disable user", "app_id": 215, "asset": 17, "parameters": [{"id": ""}]}, {"id": "f9193347-6a02-4da4-bb2c-c2183834faea", "create_time": 1774287549.2975752, "update_time": 1774287836.1576407, "last_job_id": 0, "name": "disable user - MS Graph for Active Directory", "action": "9252", "description": "Disable a user", "type": "disable user", "app_id": 174, "asset": 37, "parameters": [{"user_id": ""}]}, {"id": "9ceee2cc-6f18-4000-ae9d-05ec3447a566", "create_time": 1774287549.2976165, "update_time": 1774287836.1576743, "last_job_id": 0, "name": "terminate process - Carbon Black Response", "action": "8745", "description": "Kill running processes on a machine", "type": "terminate process", "app_id": 48, "asset": 10, "parameters": [{"pid": "", "sensor_id": "", "ip_hostname": ""}]}, {"id": "7af6b790-cab6-4351-9ff0-b7394d593330", "create_time": 1774287549.2976594, "update_time": 1774287836.157708, "last_job_id": 0, "name": "block hash - Carbon Black Response", "action": "8753", "description": "Add a hash to the Carbon Black Response blacklist", "type": "block hash", "app_id": 48, "asset": 10, "parameters": [{"hash": "", "comment": ""}]}, {"id": "9f93d670-579c-48e7-a5b4-33f096275b72", "create_time": 1774287549.2977145, "update_time": 1774287836.1577415, "last_job_id": 0, "name": "quarantine device - Carbon Black Response", "action": "8740", "description": "Quarantine the endpoint", "type": "quarantine device", "app_id": 48, "asset": 10, "parameters": [{"ip_hostname": ""}]}, {"id": "e6b0151c-4730-4319-afe8-2e6e74bd6704", "create_time": 1774287765.4104307, "update_time": 1774287836.1578002, "last_job_id": 0, "name": "quarantine device - CrowdStrike OAuth API", "action": "8761", "description": "Block the device", "type": "quarantine device", "app_id": 77, "asset": 44, "parameters": [{"hostname": "", "device_id": ""}]}, {"id": "e9445024-0335-4cfc-83d8-a29ce8188511", "create_time": 1774287765.4105, "update_time": 1774287836.157846, "last_job_id": 0, "name": "quarantine device - Windows Defender ATP", "action": "9016", "description": "Quarantine the device", "type": "quarantine device", "app_id": 191, "asset": 45, "parameters": [{"type": "", "comment": "", "timeout": "", "device_id": ""}]}, {"id": "2c9625bd-ce71-40bd-99eb-def8c381577b", "create_time": 1774287765.4105673, "update_time": 1774287836.1578796, "last_job_id": 0, "name": "quarantine file - Windows Defender ATP", "action": "9020", "description": "Quarantine a file", "type": "quarantine file", "app_id": 191, "asset": 45, "parameters": [{"comment": "", "timeout": "", "device_id": "", "file_hash": ""}]}], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "b94cc55d-a653-466a-8faf-846f699ebb75", "create_time": 1764758755.836737, "update_time": 1774287836.15795, "name": "Mitigate or remediate vulnerabilities", "order": 3, "tag": "25d66876-4448-420d-80b5-bc359805598b", "description": "If%20any%20vulnerabilities%20were%20used%20in%20this%20compromise,%20find%20a%20way%20to%20mitigate%20or%20remediate%20them.%20This%20could%20be%20a%20system%20update,%20a%20change%20in%20software,%20disabling%20a%20certain%20feature,%20a%20change%20in%20policy,%20or%20another%20action.%0A%0ASuggested%20Integration%20(%20if%20not%20already%20configured%20navigate%20%5BHERE%5D(/app/SplunkEnterpriseSecuritySuite/ess_configuration/#/soar/soar_apps/apps)%20to%20locate%20and%20configure)%0A1.%20%20Crowdstrike%0A2.%20Microsoft%20Defender%20for%20Endpoint%0A3.%20%20VMware%20Carbon%20Black%20Cloud%20for%20Splunk%20SOAR", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [{"id": "4abb5626-2df7-4f56-b034-8505848fae08", "create_time": 1774287765.4108996, "update_time": 1774287836.158022, "last_job_id": 0, "name": "quarantine device - Carbon Black Response", "action": "8740", "description": "Quarantine the endpoint", "type": "quarantine device", "app_id": 48, "asset": 10, "parameters": [{"ip_hostname": ""}]}, {"id": "83657a16-7ef7-4515-b04f-d55530a32a6a", "create_time": 1774287765.4109678, "update_time": 1774287836.1580565, "last_job_id": 0, "name": "quarantine device - CrowdStrike OAuth API", "action": "8761", "description": "Block the device", "type": "quarantine device", "app_id": 77, "asset": 44, "parameters": [{"hostname": "", "device_id": ""}]}, {"id": "656d4af6-efdf-4edf-bcfc-cb01ecde1323", "create_time": 1774287765.4110315, "update_time": 1774287836.1580904, "last_job_id": 0, "name": "quarantine device - Windows Defender ATP", "action": "9016", "description": "Quarantine the device", "type": "quarantine device", "app_id": 191, "asset": 45, "parameters": [{"type": "", "comment": "", "timeout": "", "device_id": ""}]}, {"id": "4654ed0a-488e-4556-9053-1a8cb65ef239", "create_time": 1774287765.4111028, "update_time": 1774287836.158123, "last_job_id": 0, "name": "quarantine file - Windows Defender ATP", "action": "9020", "description": "Quarantine a file", "type": "quarantine file", "app_id": 191, "asset": 45, "parameters": [{"comment": "", "timeout": "", "device_id": "", "file_hash": ""}]}, {"id": "0c99b09c-590b-4bbd-bcdb-d0a3a607a3fc", "create_time": 1774287765.4111738, "update_time": 1774287836.1581693, "last_job_id": 0, "name": "block hash - Carbon Black Response", "action": "8753", "description": "Add a hash to the Carbon Black Response blacklist", "type": "block hash", "app_id": 48, "asset": 10, "parameters": [{"hash": "", "comment": ""}]}, {"id": "07b29c2f-76c5-466f-81ab-ecd80103eb87", "create_time": 1774287765.4112391, "update_time": 1774287836.1582043, "last_job_id": 0, "name": "terminate process - Carbon Black Response", "action": "8745", "description": "Kill running processes on a machine", "type": "terminate process", "app_id": 48, "asset": 10, "parameters": [{"pid": "", "sensor_id": "", "ip_hostname": ""}]}], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}]}, {"id": "36274751-b970-4375-85dc-b06a13d05cc2", "create_time": 1774286335.639487, "update_time": 1774287836.1585217, "name": "Post-incident Activity", "order": 3, "tasks": [{"id": "c601515a-bbef-485f-819a-9c1e477e413e", "create_time": 1764758755.8368754, "update_time": 1774287836.1583033, "name": "Notify necessary parties", "order": 1, "tag": "6e6b6839-fced-46a4-a660-e00281118cda", "description": "Determine%20if%20a%20regulatory%20risk%20calls%20for%20a%20notification%20to%20an%20internal%20or%20external%20compliance%20organization.%20Also%20consider%20an%20informational%20notice%20to%20users%20to%20prevent%20similar%20compromises%20through%20improved%20security%20hygiene.%0A%0ASuggested%20Integration%20(%20if%20not%20already%20configured%20navigate%20%5BHERE%5D(/app/SplunkEnterpriseSecuritySuite/ess_configuration/#/soar/soar_apps/apps)%20to%20locate%20and%20configure)%0A1.%20SMTP%0A2.%20%20MS%20Graph%20for%20Office%20365%0A3.%20%20G%20Suite%20for%20GMail%0A4.%20Cisco%20Webex%0A5.%20Slack%0A6.%20Microsoft%20Teams%0A6.%20%5BMicrosoft%20Teams%5D(https://splunkbase.splunk.com/app/5818)", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "33acb96f-1113-489b-8dc4-882695963f99", "create_time": 1764758755.836966, "update_time": 1774287836.158404, "name": "Tune prevention systems", "order": 2, "tag": "47e3bd73-9fea-4f85-a805-9ebedfd000ed", "description": "Depending on the mechanism of access and the systems affected, there may be a clear next step to prevent similar compromises. This might involve deployment of strong multi-factor authentication, improved automated response, stronger application of least privilege, user training, and/or a wide array of other defensive measures. Consider using CIS Cybersecurity Best Practices (https://www.cisecurity.org/cybersecurity-best-practices/) or a similar framework to assess improvements in prevention.", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "0d0ded65-d9dd-497f-ab9d-f51864ad88af", "create_time": 1764758755.8370595, "update_time": 1774287836.1584785, "name": "Tune detection systems", "order": 3, "tag": "9411f544-f06a-4e79-9972-3844f61cc1f7", "description": "Any of the steps taken within the Detection and Analysis phase may be candidates for automated or regularly scheduled detections to find similar activity. Focus on the most generalizable patterns that will catch high-impact compromises as early as possible.", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}]}], "origin": {"id": "94198adf-1fc1-4c2d-8c94-baf4523bee4f", "name": "Account Compromise", "version": 3}, "template_id": "66c8c4d6-96eb-4744-9013-6f89315f1301", "active": true, "used": false, "ai_generated": false, "source_attachment_id": null, "_user": "nobody", "_key": "24bed4c7-0619-48cc-99f2-bb743b906b86"}