mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
fc1596e371
had to remove 8.5 from the name of response plans
1 line
14 KiB
JSON
1 line
14 KiB
JSON
{"id": "2a00cbdd-0c2b-4774-80e5-f407efbc9afe", "create_time": 1774376328.600492, "update_time": 1774376857.001495, "name": "Network Indicator Enrichment", "description": "Gather and analyze contextual information about URLs, hostnames, top level domain names, IP addresses, TLS certificates, and MAC addresses. These network indicators can be involved in security investigations of all types, so this response template is meant to be added as a modular component into an event or case that can have other more specific phases and tasks. For instance, when investigating an account compromise, this response template can be used during the investigation phase to rule out false positives and inform decisions about further investigation and response.", "template_status": "published", "creator": "splunker", "updated_by": "splunker", "is_default": false, "version": 3, "phases": [{"id": "5fc00a86-ecb5-473c-af5f-0eabced9921e", "create_time": 1774376703.721249, "update_time": 1774376856.8819904, "name": "Network Indicator Enrichment", "order": 1, "tasks": [{"id": "09b3b9c0-1c5b-4c3f-941f-fcc4bcb6f2f6", "create_time": 1764758755.7974405, "update_time": 1774376856.873719, "name": "Enrich URLs", "order": 1, "tag": "8fab0a3f-b436-4e3e-8c3a-9cc0a9cff8b5", "description": "Gather%20reputation%20and%20behavioral%20information%20about%20a%20suspicious%20URL.%20Automated%20actions%20can%20include%20querying%20threat%20intelligence%20databases,%20dynamic%20profiling%20of%20the%20URL%20and%20the%20associated%20redirects,%20or%20checking%20the%20categorization%20of%20a%20URL%20in%20a%20proxy%20or%20other%20safe%20browsing%20tool.%20Manual%20actions%20can%20include%20checking%20for%20typosquatting/brandjacking,%20evaluating%20the%20appropriateness%20of%20the%20URL%20given%20the%20context%20in%20which%20it%20was%20detected,%20or%20manually%20investigating%20the%20site%20from%20a%20sandboxed%20environment.%20Additionally,%20it%20might%20be%20appropriate%20to%20ask%20the%20user%20if%20they%20can%20explain%20why%20the%20URL%20was%20accessed.%20Outputs%20from%20this%20task%20could%20be%20used%20to%20pivot%20to%20investigation%20to%20underlying%20or%20associated%20domain%20names,%20other%20URLs,%20TLS%20certificates,%20IP%20addresses,%20or%20specific%20behaviors%20associated%20with%20the%20website%20such%20as%20Javascript%20execution%20patterns%20or%20downloaded%20files.%0A%0ASuggested%20Integration%20(%20if%20not%20already%20configured%20navigate%20%5BHERE%5D(/app/SplunkEnterpriseSecuritySuite/ess_configuration/#/soar/soar_apps/apps)%20to%20locate%20and%20configure)%0A1.%20Splunk%20Attack%20Analyzer%0A2.%20Cisco%20Talos%20Intelligence%0A3.%20VirusTotal%20v3%0A4.%20PhishTank%20", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [{"id": "fb4ce38b-b976-4a14-bf31-4909c50c36dd", "create_time": 1774376703.7195108, "update_time": 1774376856.8739007, "last_job_id": 0, "name": "detonate url - Splunk Attack Analyzer Connector for Splunk SOAR", "action": "8940", "description": "Submit New URL for Scanning", "type": "detonate url", "app_id": 283, "asset": 23, "parameters": [{"url": "", "ph_0": "", "profile": "", "user_agent": "", "internet_region": "", "archive_password": "", "custom_user_agent": ""}]}, {"id": "d53a4936-ad17-40ec-a55c-55f6895d72a9", "create_time": 1774376703.7195892, "update_time": 1774376856.8739712, "last_job_id": 0, "name": "get job summary - Splunk Attack Analyzer Connector for Splunk SOAR", "action": "8937", "description": "Get a job summary for a submitted job", "type": "get job summary", "app_id": 283, "asset": 23, "parameters": [{"job_id": "", "timeout": ""}]}, {"id": "77340139-c701-4f70-944e-b2599fc00696", "create_time": 1774376703.7196612, "update_time": 1774376856.874036, "last_job_id": 0, "name": "url reputation - Cisco Talos Intelligence", "action": "7851", "description": "Query URL info", "type": "url reputation", "app_id": 61, "asset": 11, "parameters": [{"url": ""}]}, {"id": "2e99c953-d1eb-4b5a-873c-7dee5cfc905a", "create_time": 1774376703.7197337, "update_time": 1774376856.8741004, "last_job_id": 0, "name": "url reputation - VirusTotal v3", "action": "9003", "description": "Queries VirusTotal for URL info (run this action after running detonate url)", "type": "url reputation", "app_id": 323, "asset": 28, "parameters": [{"url": ""}]}, {"id": "45dfb4f0-e556-4c6a-94e3-59d6726d942b", "create_time": 1774376703.7198265, "update_time": 1774376856.8741732, "last_job_id": 0, "name": "url reputation - PhishTank", "action": "8902", "description": "Queries PhishTank for URL's phishing reputation", "type": "url reputation", "app_id": 225, "asset": 3, "parameters": [{"url": ""}]}], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "b77c2c5b-488b-4ef6-a987-d4f1795e8c09", "create_time": 1764758755.7976081, "update_time": 1774376856.874365, "name": "Enrich domain names", "order": 2, "tag": "f494c551-d513-4503-a268-32d14cd9352c", "description": "Domain%20names%20can%20be%20involved%20in%20investigations%20of%20phishing,%20watering%20hole%20attacks,%20malware%20command%20and%20control,%20exfiltration,%20and%20many%20other%20malicious%20behaviors.%20Some%20of%20the%20key%20questions%20to%20answer%20about%20a%20domain%20are:%20Who%20controls%20the%20domain?%20Who%20registered%20the%20domain?%20What%20is%20the%20purpose%20of%20the%20domain?%20What%20services%20are%20hosted%20on%20the%20domain?%20What%20traffic%20would%20you%20expect%20to%20see%20to%20and%20from%20the%20domain?%20How%20popular%20is%20the%20domain?%20Does%20the%20domain%20host%20dynamic%20content%20such%20as%20cloud%20services?%20What%20sub-domains%20or%20parent%20domains%20are%20associated%20with%20the%20domain?%20Is%20the%20domain%20known%20to%20host%20malicious%20content?%20Where%20in%20the%20world%20is%20the%20domain%20hosted?%20How%20recently%20was%20the%20domain%20registered?%20What%20is%20the%20DNS%20history%20of%20the%20domain?%20Is%20the%20domain%20meant%20to%20look%20similar%20to%20another%20more%20legitimate%20domain?%20Does%20the%20domain%20name%20appear%20to%20have%20been%20randomly%20generated?%20The%20results%20of%20these%20queries%20can%20produce%20related%20IP%20addresses,%20file%20hashes,%20downloaded%20files,%20URLs,%20TLS%20certificates,%20and%20behaviors%20which%20are%20useful%20elsewhere%20in%20this%20investigation.%0A%0ASuggested%20Integration%20(%20if%20not%20already%20configured%20navigate%20%5BHERE%5D(/app/SplunkEnterpriseSecuritySuite/ess_configuration/#/soar/soar_apps/apps)%20to%20locate%20and%20configure)%0A1.%20Cisco%20Talos%20Intelligence%0A2.%20VirusTotal%20v3%0A3.%20%20Recorded%20Future%20For%20Splunk%20SOAR%0A4.%20AlienVault%20OTX%20", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [{"id": "fd1bbd56-1e75-4eac-a13f-659a8c5479c5", "create_time": 1774376703.7202172, "update_time": 1774376856.8745027, "last_job_id": 0, "name": "domain reputation - Cisco Talos Intelligence", "action": "7850", "description": "Query domain info", "type": "domain reputation", "app_id": 61, "asset": 11, "parameters": [{"domain": ""}]}, {"id": "38449ea7-786f-4f5b-8e9a-6bffd45aec37", "create_time": 1774376703.7202878, "update_time": 1774376856.8745666, "last_job_id": 0, "name": "domain reputation - VirusTotal v3", "action": "8999", "description": "Queries VirusTotal for domain info", "type": "domain reputation", "app_id": 323, "asset": 28, "parameters": [{"domain": ""}]}, {"id": "f737f9d8-64cf-4551-a7b8-a44cf114f374", "create_time": 1774376703.720357, "update_time": 1774376856.8746321, "last_job_id": 0, "name": "domain reputation - Recorded Future For Splunk SOAR", "action": "4273", "description": "Get a quick indicator of the risk associated with a domain", "type": "domain reputation", "app_id": 247, "asset": 19, "parameters": [{"domain": ""}]}, {"id": "c5cdf3bc-2802-4494-baf8-2c17e0c470b2", "create_time": 1774376703.7204268, "update_time": 1774376856.8746967, "last_job_id": 0, "name": "domain reputation - AlienVault OTX", "action": "9311", "description": "Queries for domain reputation information", "type": "domain reputation", "app_id": 24, "asset": 47, "parameters": [{"domain": "", "response_type": ""}]}], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "fed103ab-b8bf-458e-a9d1-a80d7c1691ce", "create_time": 1764758755.7977073, "update_time": 1774376856.8810358, "name": "Enrich IP addresses", "order": 3, "tag": "b0444819-8d84-47b0-8011-97c9004966cc", "description": "Enrichment%20of%20IP%20addresses%20can%20be%20similar%20to%20domain%20names%20in%20many%20ways,%20but%20typically%20IP%20addresses%20will%20change%20more%20frequently.%20Frequent%20changes%20can%20be%20legitimate%20behavior%20caused%20by%20load%20balancers%20or%20content%20delivery%20networks,%20or%20it%20can%20be%20malicious%20behavior%20due%20to%20fast%20flux%20DNS%20changes,%20so%20additional%20context%20about%20the%20network%20traffic%20is%20needed.%20Also%20consider%20that%20traffic%20going%20straight%20to%20an%20IP%20address%20without%20doing%20a%20DNS%20query%20might%20be%20relevant%20to%20the%20investigation,%20and%20consider%20querying%20Tor%20or%20other%20anonymization%20systems%20to%20check%20if%20the%20IP%20address%20is%20a%20known%20exit%20node.%20Outputs%20of%20this%20task%20can%20inform%20URL%20enrichment,%20downloaded%20file%20analysis,%20domain%20name%20enrichment,%20TLS%20certificate%20enrichment,%20and%20more%20advanced%20behavioral%20analysis%20based%20on%20the%20services%20hosted%20at%20the%20IP%20address%20in%20question.%0A%0ASuggested%20Integration%20(%20if%20not%20already%20configured%20navigate%20%5BHERE%5D(/app/SplunkEnterpriseSecuritySuite/ess_configuration/#/soar/soar_apps/apps)%20to%20locate%20and%20configure)%0A1.%20Cisco%20Talos%20Intelligence%0A2.%20VirusTotal%20v3%0A3.%20%20Recorded%20Future%20For%20Splunk%20SOAR%0A4.%20AlienVault%20OTX%20", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [{"id": "b0028ace-454d-434e-8810-f17aa294c913", "create_time": 1774376847.1800668, "update_time": 1774376856.88121, "last_job_id": 0, "name": "ip reputation - Cisco Talos Intelligence", "action": "7849", "description": "Query IP info", "type": "ip reputation", "app_id": 61, "asset": 11, "parameters": [{"ip": ""}]}, {"id": "e5ae7c22-211c-4b3f-a47a-a81577ebc08f", "create_time": 1774376847.1801095, "update_time": 1774376856.8812802, "last_job_id": 0, "name": "ip reputation - VirusTotal v3", "action": "9002", "description": "Queries VirusTotal for IP info", "type": "ip reputation", "app_id": 323, "asset": 28, "parameters": [{"ip": ""}]}, {"id": "7fe6cc9e-111e-4e6b-86d0-bc28fa987d22", "create_time": 1774376847.18015, "update_time": 1774376856.8813462, "last_job_id": 0, "name": "ip reputation - Recorded Future For Splunk SOAR", "action": "4282", "description": "Get a quick indicator of the risk associated with an IP address", "type": "ip reputation", "app_id": 247, "asset": 19, "parameters": [{"ip": ""}]}, {"id": "02a3c9e3-273f-4da8-9a9b-ee912539c1b2", "create_time": 1774376847.1801913, "update_time": 1774376856.8814104, "last_job_id": 0, "name": "ip reputation - AlienVault OTX", "action": "9312", "description": "Queries for IP reputation information", "type": "ip reputation", "app_id": 24, "asset": 47, "parameters": [{"ip": "", "response_type": ""}]}], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "9d096815-7876-4f42-9c93-73e3cc21d3ce", "create_time": 1764758755.7977993, "update_time": 1774376856.8816028, "name": "Enrich TLS certificates", "order": 4, "tag": "d98902d9-2620-41c6-90d2-d197a49a90ca", "description": "If%20an%20investigation%20involves%20a%20TLS%20certificate,%20it%20can%20be%20useful%20to%20gather%20registrant%20and%20certificate%20authority%20information%20about%20that%20certificate,%20and%20to%20query%20for%20other%20uses%20of%20similar%20infrastructure.%20The%20usage%20of%20free%20and%20automated%20certificate%20authorities%20such%20as%20Let's%20Encrypt%20does%20not%20necessarily%20imply%20that%20a%20domain%20is%20malicious,%20but%20that%20is%20a%20common%20technique%20used%20to%20build%20malicious%20infrastructure%20so%20it%20should%20warrant%20further%20investigation.%20Consider%20comparing%20the%20registrant%20information%20and%20certificate%20authority%20chain%20with%20the%20expected%20values%20for%20the%20organization%20allegedly%20hosting%20the%20website%20in%20question.%0A%0ASuggested%20Dasboards%0A1.%20%5BTraffic%20Center%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/traffic_center)%0A2.%20%5BNetwork%20Changes%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/network_changes)%0A", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "4e38a46a-1af2-477a-9349-8defa965ac2b", "create_time": 1764758755.7979288, "update_time": 1774376856.8818426, "name": "Enrich MAC addresses", "order": 5, "tag": "38d3329d-0ecd-494f-bbcf-5be0fd99a7c3", "description": "While%20MAC%20(media%20access%20control)%20addresses%20are%20less%20frequently%20involved%20in%20security%20investigations,%20when%20they%20are%20present%20they%20can%20sometimes%20be%20useful%20to%20cross-reference,%20identify,%20or%20profile%20a%20device.%20MAC%20addresses%20can%20be%20changed%20and%20spoofed,%20but%20it%20is%20usually%20less%20common%20than%20a%20change%20in%20IP%20address%20or%20hostname.%20In%20wifi%20investigations%20the%20MAC%20address%20can%20be%20used%20to%20identify%20both%20the%20access%20point%20and%20the%20clients%20that%20connect%20to%20it.%0A%0ASuggested%20Dashboards%0A1.%20%5BTraffic%20Center%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/traffic_center)%0A2.%20%5BNetwork%20Changes%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/network_changes)%0A", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}]}], "origin": {"id": "8b1df498-d692-4212-a4fd-6b99b99e9027", "name": "Network Indicator Enrichment", "version": 3}, "template_id": "40baabd7-3950-4907-a3c8-802105fb33a0", "active": true, "used": false, "ai_generated": false, "source_attachment_id": null, "_user": "nobody", "_key": "2a00cbdd-0c2b-4774-80e5-f407efbc9afe"} |