mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
3953a43f05
* Create response_plan directory * Update directory name * Copy response_templates artifacts to dist/api * Add response-templates schema validation workflow * Add feature branch for testing purpose * Update endpoint to playground * Revert back debug changes * Move scripts to workflows * Remove manual check in * Add sorting for version and template name * Raise exception when file name not match * Add indentation for json output * Add debug option to dump json schema * Generate merged templates at runtime * Rename openAPI spec yaml to yml * Move validation to build.yml * Use stem to get file name * Fix python package install * Update version sorting using int * Update openAPI spec for version * Move build response templates to separate workflow * Fix naming in build-response-templates.yml * Update response templates to the ones for first release * Fix naming of response templates * Response templates to be added by response plan team * Keep response_templates directory * Skip .gitkeep checking when check non-json files * Remove the .gitkeep * Initial version of Response Templates * Initial version of Response Templates * Initial version of Response Templates * Revert "Initial version of Response Templates" This reverts commit3a174dd02e. * Revert "Initial version of Response Templates" This reverts commit26fa66ddde. * Revert "Initial version of Response Templates" This reverts commit6014b4870b. * Initial version of Response Templates * Initial version of Response Templates * Update and rename AccountCompromise_v14.json to AccountCompromise_v2.json * Update and rename DataBreach_v15.json to DataBreach_v2.json * Update and rename GenericIncidentResponse_v13.json to GenericIncidentResponse_v2.json * Update and rename NIST80061_v14.json to NIST80061_v2.json * Update and rename NetworkIndicatorEnrichment_v6.json to NetworkIndicatorEnrichment_v2.json * Update and rename SelfReplicatingMalware_v14.json to SelfReplicatingMalware_v2.json * Update and rename SuspiciousEmail_v35.json to SuspiciousEmail_v2.json * Update and rename VulnerabilityDisclosure_v10.json to VulnerabilityDisclosure_v2.json * Add comments --------- Co-authored-by: pyth0n1c <87383215+pyth0n1c@users.noreply.github.com> Co-authored-by: Christian Cloutier <ccloutier@splunk.com> Co-authored-by: kbouchard <47464052+kbouchardherjavecgroup@users.noreply.github.com> Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
2 lines
20 KiB
JSON
2 lines
20 KiB
JSON
{"id": "c3326c0e-417c-46de-b79a-7a33e457b91b", "create_time": 1764862802.518435, "update_time": 1765478297.8226988, "name": "Generic Incident Response", "description": "", "template_status": "published", "creator": "splunker", "updated_by": "splunker", "is_default": false, "version": 2, "phases": [{"id": "c8c1bb29-a14c-4230-ba02-283f98645b90", "create_time": 1765478297.7930639, "update_time": 1765478297.7930644, "name": "Detection", "order": 1, "tasks": [{"id": "76fd8383-b2f7-47d8-b952-49a60105c23f", "create_time": 1764758755.9055116, "update_time": 1765478297.7925363, "name": "Report incident response execution", "order": 1, "tag": "69c9baf1-bd12-4b09-b6b6-a77df9428682", "description": "Alert%20appropriate%20parties%20that%20incident%20response%20is%20starting.%0A%0ASuggested%20Integrations%0A1.%20SMTP%20(preconfigured)%0A2.%20%5BMS%20Graph%20for%20Office%20365%5D(https://splunkbase.splunk.com/app/5824)%0A3.%20%5BG%20Suite%20for%20GMail%5D(https://splunkbase.splunk.com/app/5795)%0A4.%20%5BCisco%20Webex%5D(https://splunkbase.splunk.com/app/5781)%0A5.%20%5BSlack%5D(https://splunkbase.splunk.com/app/5846)%0A6.%20%20%5BMicrosoft%20Teams%5D(https://splunkbase.splunk.com/app/5818)", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "c62f8956-c622-4c11-a664-9d68661f2df1", "create_time": 1764758755.905616, "update_time": 1765478297.7928247, "name": "Document associated events", "order": 2, "tag": "8ca56a2a-f0d7-43c1-96e3-06bac95deffe", "description": "This is the escalation. Create a notable and populate it with significant data.", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "8e84a157-60e0-4914-97e7-a59936ba4fcf", "create_time": 1764758755.9057095, "update_time": 1765478297.7929223, "name": "Document known attack surface and attacker information", "order": 3, "tag": "604e26c0-fb5a-4320-9d95-ef887d406d71", "description": "Rough triage of the situation. No complete picture of the situation, but targets to analyze.", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "ea952b70-0c68-4750-b791-7489117f5a3a", "create_time": 1764758755.9058, "update_time": 1765478297.7930133, "name": "Assign roles", "order": 4, "tag": "389fce05-2170-4971-aabb-da3d88ea668a", "description": "For example: Incident commander, Tech lead, Scribe, Intel analysts, Security analysts", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}]}, {"id": "816cf263-fcdd-45d6-8f5f-f4c5c3f638bd", "create_time": 1765478297.7943053, "update_time": 1765478297.7943058, "name": "Analysis", "order": 2, "tasks": [{"id": "2444a355-821e-4485-86c5-03c836cba7c5", "create_time": 1764758755.9059348, "update_time": 1765478297.7931442, "name": "Research intelligence resources", "order": 1, "tag": "595d75bb-316e-4dec-bfc6-6729d3e7b280", "description": "Find%20out%20if%20this%20attacker%20is%20a%20known%20agent%20and%20gather%20associated%20tactics,%20techniques,%20and%20procedures%20(TTP)%20used.%0A%0ASuggested%20Integrations%0A1.%20%5BSplunk%20Attack%20Analyzer%5D(https://splunkbase.splunk.com/app/6783)%0A2.%20%5BCisco%20Talos%20Intelligence%5D(https://splunkbase.splunk.com/app/7711)%0A3.%203.%20%5BVirusTotal%20v3%5D(https://splunkbase.splunk.com/app/5865)%0A4.%20%20PhishTank%20(preconfigured)", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "a947eacc-04e3-485e-bac4-6566e85df173", "create_time": 1764758755.9060266, "update_time": 1765478297.7932744, "name": "Research proxy logs", "order": 2, "tag": "7586c74e-6844-45bb-9535-4924752ff0de", "description": "Find%20and%20document%20any%20evidence%20linked%20to%20attacker%20actions.%0A%0ASuggested%20Integrations%0A1.%20%5BWeb%20Center%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/web_center)%0A2.%20%5BTraffic%20Center%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/traffic_center)", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "bfa0b1ad-7bb1-484d-bcfa-16df7989518c", "create_time": 1764758755.906122, "update_time": 1765478297.7933776, "name": "Research firewall logs", "order": 3, "tag": "5f7e4c57-343a-4a5c-8c90-643bdb578dbb", "description": "Find%20and%20document%20any%20evidence%20linked%20to%20attacker%20actions.%0A%0ASuggested%20Integrations%0A1.%20%5BTraffic%20Search%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/traffic_search)%0A2.%20%5BTraffic%20Size%20Analysis%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/traffic_size_analysis)%0A3.%20%5BPort%20and%20Protocol%20Tracker%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/port_protocol_tracker)%0A4.%20%5BEndpoint%20Changes%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/endpoint_changes)%0A5.%20%5BMalware%20Center%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/malware_center)%0A6.%20%5BMalware%20Search%5D(/app/SplunkEnterpriseSecuritySuite/malware_search)", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "0168209e-eb24-4a5a-b72a-7c074a96a19c", "create_time": 1764758755.906265, "update_time": 1765478297.7934852, "name": "Research OS logs", "order": 4, "tag": "357d8065-7af2-4968-a52e-1daba8d36bcb", "description": "Find%20and%20document%20any%20evidence%20linked%20to%20attacker%20actions.%0A%0ASuggested%20Integrations%0A1.%20%5BEndpoint%20Changes%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/endpoint_changes)%0A2.%20%5BMalware%20Center%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/malware_center)%0A3.%20%5BMalware%20Search%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/malware_search)", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "82beb15d-df47-49e4-a504-6a7dd5f33558", "create_time": 1764758755.9063575, "update_time": 1765478297.7935877, "name": "Research network logs", "order": 5, "tag": "f5aabd39-0213-498c-9a91-db8b62c1d262", "description": "Find%20and%20document%20any%20evidence%20linked%20to%20attacker%20actions.%0A%0ASuggested%20Integrations%0A1.%20%5BWeb%20Center%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/web_center)%0A2.%20%5BTraffic%20Center%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/traffic_center)", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "d339af9b-fdfb-4944-8f9a-6febf9fbceb3", "create_time": 1764758755.9064476, "update_time": 1765478297.7936852, "name": "Research endpoint protection logs", "order": 6, "tag": "a0d0a5b6-e961-470a-8fed-2fd0f1f56e54", "description": "Find%20and%20document%20any%20evidence%20linked%20to%20attacker%20actions.%0A%0ASuggested%20Integrations%0A1.%20%5BEndpoint%20Changes%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/endpoint_changes)", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "8a6d8b29-55f0-4eb8-817b-281fbddccd40", "create_time": 1764758755.9065409, "update_time": 1765478297.7937844, "name": "Determine infection vector", "order": 7, "tag": "e840c5b9-b804-4851-ace7-ed2b20e94374", "description": "Find and document how the initial infection occurred.", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "ef1d9524-231c-4c12-9544-f01fe50f0e9b", "create_time": 1764758755.9066322, "update_time": 1765478297.7938728, "name": "Document all attack targets", "order": 8, "tag": "2a1efed7-4cba-4f66-b7f4-c51555f6dafd", "description": "Find and document the full attack surface.", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "27b6ef2b-735d-4598-ab6e-6875f837a484", "create_time": 1764758755.9067245, "update_time": 1765478297.7939599, "name": "Document all attacker sources and TTP", "order": 9, "tag": "3ce58599-9e4e-4936-a604-9b2783fbb4be", "description": "Document all discovered attack sources and tactics, techniques, and procedures (TTP).", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "a2fdf16b-e79d-4cf6-8f57-026a2c0b63d0", "create_time": 1764758755.9068127, "update_time": 1765478297.794048, "name": "Document infected devices", "order": 10, "tag": "8854bf07-df2e-4536-a7ef-c268776eba0e", "description": "Document all devices known to have been modified by the attacker.", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "a16d098a-10a7-4b53-a798-fd83c467ddb6", "create_time": 1764758755.9069023, "update_time": 1765478297.7941349, "name": "Determine full impact of attack", "order": 11, "tag": "2419ca1b-fa9e-4443-8334-4642877218c4", "description": "For example, the functional and informational impact of the attack.", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "92b46948-e8f0-4194-9ada-76bbf21bea3a", "create_time": 1764758755.9069924, "update_time": 1765478297.7942424, "name": "Analyze malware samples", "order": 12, "tag": "7486b744-568f-4a71-b6ab-6c18b0975234", "description": "Analyze%20discovered%20malware%20and%20document%20indicators%20of%20compromise%20(IOCs).%0A%0ASuggested%20Integrations%0A1.%20%5BSplunk%20Attack%20Analyzer%5D(https://splunkbase.splunk.com/app/6783)%0A2.%20%5BCisco%20Talos%20Intelligence%5D(https://splunkbase.splunk.com/app/7711)", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}]}, {"id": "1cfc9549-b74f-4dfd-b1c5-956b1587e546", "create_time": 1765478297.7946434, "update_time": 1765478297.7946439, "name": "Containment", "order": 3, "tasks": [{"id": "91691144-6812-44e7-ae84-769b7c91778f", "create_time": 1764758755.9071276, "update_time": 1765478297.7943835, "name": "Acquire, preserve, secure, and document evidence", "order": 1, "tag": "fa5fbdd4-4224-460f-80b1-081083c3a8e5", "description": "Before modifying systems housing evidence of the attack, document the evidence.", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "884da2c4-4fb8-494f-bd5a-2c0eacb81646", "create_time": 1764758755.9072351, "update_time": 1765478297.794471, "name": "Report devices and applications to be contained to proper channels", "order": 2, "tag": "f735a650-8d7e-42ee-95fa-ca8122e29df4", "description": "Suggested%20Integrations%0A1.%20%5BCisco%20Webex%5D(https://splunkbase.splunk.com/app/5781)%0A2.%20%5BSlack%5D(https://splunkbase.splunk.com/app/5846)%0A3.%20%5BMicrosoft%20Teams%5D(https://splunkbase.splunk.com/app/5818)", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "5b6fd766-744a-4ada-9612-9934ff090668", "create_time": 1764758755.9073257, "update_time": 1765478297.7945688, "name": "Contain incident", "order": 3, "tag": "de5b8d96-bc90-47e5-a707-4b4ce273b2f5", "description": "Suggested%20Integrations%0A1.%20%20%5BCisco%20Firepower%5D(https://splunkbase.splunk.com/app/5995)%0A2.%20%5BCisco%20Secure%20Firewall%5D(https://splunkbase.splunk.com/app/7745)%0A3.%20%5B%20Palo%20Alto%5D(https://splunkbase.splunk.com/app/5830)%0A4.%20%5BZscaler%5D(https://splunkbase.splunk.com/app/5872)%0A5.%20%5BCrowdstrike%5D(https://splunkbase.splunk.com/app/5786)%0A6.%20%5BMicrosoft%20Defender%20for%20Endpoint%5D(https://splunkbase.splunk.com/app/5870)%0A7.%20%5BVMware%20Carbon%20Black%20Cloud%20for%20Splunk%20SOAR%5D(https://splunkbase.splunk.com/app/6732)%0A8.%20%5BMS%20Graph%20For%20Active%20Directory%5D(https://splunkbase.splunk.com/app/6395)%0A9.%20%5BAD%20LDAP%5D(https://splunkbase.splunk.com/app/5755)%0A10.%20%5BOkta%5D(https://splunkbase.splunk.com/app/5921)%0A11.%20%5BAWS%20IAM%5D(https://splunkbase.splunk.com/app/5763)%0A12.%20%5BAzure%20AD%20Graph%5D(https://splunkbase.splunk.com/app/5771)", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}]}, {"id": "a5675456-ec54-4045-beb4-d521f14192cc", "create_time": 1765478297.7949696, "update_time": 1765478297.7949698, "name": "Eradication", "order": 4, "tasks": [{"id": "74739ca3-8849-4d32-b41f-6dcf53ab6598", "create_time": 1764758755.9074597, "update_time": 1765478297.7947214, "name": "Identify and mitigate all vulnerabilities that were exploited", "order": 1, "tag": "160a14ef-e1d7-46db-9a35-5e452602416a", "description": "Suggested%20Integrations%0A1.%20%20%5BCrowdstrike%5D(https://splunkbase.splunk.com/app/5786)%0A2.%20%5BMicrosoft%20Defender%20for%20Endpoint%5D(https://splunkbase.splunk.com/app/5870)%0A3.%20%5BVMware%20Carbon%20Black%20Cloud%20for%20Splunk%20SOAR%5D(https://splunkbase.splunk.com/app/6732)%0A", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "bf7fc36c-f08b-4fda-89ec-95594bbf238c", "create_time": 1764758755.9075792, "update_time": 1765478297.794821, "name": "Remove malware, inappropriate materials and other components", "order": 2, "tag": "f02e09fa-0ed7-4ca7-a001-a6adcfe83437", "description": "Suggested%20Integrations%0A1.%20%20%5BCrowdstrike%5D(https://splunkbase.splunk.com/app/5786)%0A2.%20%5BMicrosoft%20Defender%20for%20Endpoint%5D(https://splunkbase.splunk.com/app/5870)%0A3.%20%5BVMware%20Carbon%20Black%20Cloud%20for%20Splunk%20SOAR%5D(https://splunkbase.splunk.com/app/6732)%0A", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "f5c72b7c-f274-4825-9b9f-5c34f8d384e9", "create_time": 1764758755.907677, "update_time": 1765478297.7949193, "name": "Repeat analysis and containment on any newly discovered infected hosts", "order": 3, "tag": "c8032097-7574-438a-8473-d614b8f135ff", "description": "", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}]}, {"id": "50452b43-98af-43ab-bfb0-1e9f7368b2c9", "create_time": 1765478297.795289, "update_time": 1765478297.7952893, "name": "Recovery", "order": 5, "tasks": [{"id": "91a74317-f931-4ced-b4aa-6cdf54433221", "create_time": 1764758755.9079046, "update_time": 1765478297.7950459, "name": "Return affected systems to an operationally ready state", "order": 1, "tag": "c3c83a87-0d75-4d0a-b4e7-9fef0d60e5f4", "description": "Restore network connectivity and system access.", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "91f6342d-a92b-4157-a124-5e87ab0c9827", "create_time": 1764758755.9080007, "update_time": 1765478297.7951343, "name": "Confirm that the affected systems are functioning normally", "order": 2, "tag": "27d8d5a5-4c1b-470c-b995-c39275b61444", "description": "Work with system owners to validate successful recovery.", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "5840a534-399b-4ac1-b0bc-80927edf8f8b", "create_time": 1764758755.9080942, "update_time": 1765478297.7952387, "name": "If necessary, implement additional monitoring to look for future related activity", "order": 3, "tag": "085d0c66-3bb9-48c8-9403-0fc21217d77c", "description": "Be ready to identify a similar attack with proper monitoring.", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}]}, {"id": "dd359232-b8be-435a-b5bc-1a5fd3e44559", "create_time": 1765478297.795616, "update_time": 1765478297.7956161, "name": "Post", "order": 6, "tasks": [{"id": "0f4c6d6e-5e22-4d2c-8de3-8fb45346b917", "create_time": 1764758755.908245, "update_time": 1765478297.7953663, "name": "Schedule after-action review meeting", "order": 1, "tag": "815e442f-e87d-42ef-81ea-5c13b4d1e3cf", "description": "", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "8864f28a-1b75-4317-b6e7-4088f8d19d9a", "create_time": 1764758755.9083498, "update_time": 1765478297.7954535, "name": "Generate incident response action report", "order": 2, "tag": "5a4862af-5001-4418-a48b-e028ef91b542", "description": "Both an executive report and a detailed final report.", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "08014d2b-5977-45d2-a14e-519c990aed93", "create_time": 1764758755.9084463, "update_time": 1765478297.7955399, "name": "Report incident response complete", "order": 3, "tag": "4b12a641-8105-4b64-bd89-eef26fabb47a", "description": "Alert%20appropriate%20parties%20that%20incident%20response%20is%20complete.%0A%0ASuggested%20Integrations%0A1.%20SMTP%20(preconfigured)%0A2.%20%5BMS%20Graph%20for%20Office%20365%5D(https://splunkbase.splunk.com/app/5824)%0A3.%20%5BG%20Suite%20for%20GMail%5D(https://splunkbase.splunk.com/app/5795)%0A4.%20%5BCisco%20Webex%5D(https://splunkbase.splunk.com/app/5781)%0A5.%20%5BSlack%5D(https://splunkbase.splunk.com/app/5846)%0A6.%20%20%5BMicrosoft%20Teams%5D(https://splunkbase.splunk.com/app/5818)", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}]}], "template_id": "28753dcd-47c7-44ad-b85f-f840c3f0da96", "active": true, "used": false, "_user": "nobody", "_key": "c3326c0e-417c-46de-b79a-7a33e457b91b"}
|