mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
fc1596e371
had to remove 8.5 from the name of response plans
1 line
32 KiB
JSON
1 line
32 KiB
JSON
{"id": "0784962a-e50b-47c0-b5ac-bcd7669c045d", "create_time": 1774377200.9147449, "update_time": 1774386512.9425516, "name": "Self-Replicating Malware", "description": "This response template outlines a response to a potential infection by self-replicating malware (malware that propagates itself without human interaction). While there is much overlap between the response necessary for self-replicating malware and the response to any other malware, the ability to propagate from one system to the next automatically adds the potential for faster and more thorough infection of enterprise systems. Often the infection mechanism is a particular network service or shared resource, so an appropriate response tends to be a fast configuration change to contain the effect immediately.\n\nThis template is adapted from a modified version of the CERT Societe Generale Incident Response Methodology called Worm Infection Response. The full methodology is available at https://github.com/certsocietegenerale/IRM/blob/HEAD/EN/IRM-1-WormInfection.pdf and is covered under the Creative Commons Attribution 3.0 Imported license available at https://github.com/certsocietegenerale/IRM/blob/HEAD/LICENSE.md, while the CERT Societe Generale homepage is https://cert.societegenerale.com/en/.", "template_status": "published", "creator": "splunker", "updated_by": "splunker", "is_default": false, "version": 3, "phases": [{"id": "56b864aa-4f46-4eab-8631-15340fe85f3d", "create_time": 1774386512.907017, "update_time": 1774386512.9070175, "name": "Preparation", "order": 1, "tasks": [{"id": "ec3ed15c-7140-4e3d-ad5f-324edaf32d30", "create_time": 1764758755.867025, "update_time": 1774386512.9060833, "name": "Define team members", "order": 1, "tag": "a901e393-ab86-4ca7-95db-14d8774a60da", "description": "Determine%20which%20team%20members%20will%20play%20which%20role%20in%20the%20response%20and%20establish%20communications%20channels%20with%20all%20involved.%0A%0ASuggested%20Integrations%0A1.%20%5BCisco%20Webex%5D(https://splunkbase.splunk.com/app/5781)%0A2.%20%5BSlack%5D(https://splunkbase.splunk.com/app/5846)%0A3.%20%5BMicrosoft%20Teams%5D(https://splunkbase.splunk.com/app/5818)", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "faf9efef-e4dc-4100-98b4-3ed62777f915", "create_time": 1764758755.867135, "update_time": 1774386512.9062238, "name": "Check analysis tools", "order": 2, "tag": "6700e71f-245c-4f8c-b835-d91eaefe716b", "description": "Test%20connectivity,%20check%20patch%20level,%20and%20run%20example%20queries%20on%20all%20analysis%20tools.%0A%0ASuggested%20Integration%20(%20if%20not%20already%20configured%20navigate%20%5BHERE%5D(/app/SplunkEnterpriseSecuritySuite/ess_configuration/#/soar/soar_apps/apps)%20to%20locate%20and%20configure)%0A1.%20Splunk%20Attack%20Analyzer%0A2.%20Cisco%20Talos%20Intelligence%0A3.%20VirusTotal%20v3%0A4.%20PhishTank%20%0A5.%20Recorded%20Future%20for%20Splunk%20SOAR", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [{"id": "92d27bbb-6bb3-4912-8c26-cabe842c7185", "create_time": 1774384810.4404502, "update_time": 1774386512.9063063, "last_job_id": 0, "name": "detonate file - Splunk Attack Analyzer Connector for Splunk SOAR", "action": "8939", "description": "Submit File for Scanning", "type": "detonate file", "app_id": 283, "asset": 23, "parameters": [{"file": "", "ph_0": "", "profile": "", "user_agent": "", "internet_region": "", "archive_password": "", "custom_user_agent": ""}]}, {"id": "a558c30d-f425-47a9-9024-4de2804dc3fb", "create_time": 1774384810.4404945, "update_time": 1774386512.906343, "last_job_id": 0, "name": "detonate url - Splunk Attack Analyzer Connector for Splunk SOAR", "action": "8940", "description": "Submit New URL for Scanning", "type": "detonate url", "app_id": 283, "asset": 23, "parameters": [{"url": "", "ph_0": "", "profile": "", "user_agent": "", "internet_region": "", "archive_password": "", "custom_user_agent": ""}]}, {"id": "46354458-f915-49d4-adb2-3bcb4bc741a2", "create_time": 1774384810.4405363, "update_time": 1774386512.906378, "last_job_id": 0, "name": "get job summary - Splunk Attack Analyzer Connector for Splunk SOAR", "action": "8937", "description": "Get a job summary for a submitted job", "type": "get job summary", "app_id": 283, "asset": 23, "parameters": [{"job_id": "", "timeout": ""}]}, {"id": "47a93494-1807-458e-a25e-aa9eedc22f53", "create_time": 1774384810.4405768, "update_time": 1774386512.9064128, "last_job_id": 0, "name": "domain reputation - Cisco Talos Intelligence", "action": "7850", "description": "Query domain info", "type": "domain reputation", "app_id": 61, "asset": 11, "parameters": [{"domain": ""}]}, {"id": "bb3a22e6-1d35-41e1-8c56-272aa0a43dd2", "create_time": 1774384810.4406168, "update_time": 1774386512.906446, "last_job_id": 0, "name": "ip reputation - Cisco Talos Intelligence", "action": "7849", "description": "Query IP info", "type": "ip reputation", "app_id": 61, "asset": 11, "parameters": [{"ip": ""}]}, {"id": "c910a1bc-0ce6-45ff-9cd1-b0594616799c", "create_time": 1774384810.440657, "update_time": 1774386512.9064798, "last_job_id": 0, "name": "url reputation - Cisco Talos Intelligence", "action": "7851", "description": "Query URL info", "type": "url reputation", "app_id": 61, "asset": 11, "parameters": [{"url": ""}]}, {"id": "b7806c00-2372-43c8-a9ee-db6fd2da78df", "create_time": 1774384810.4406974, "update_time": 1774386512.9065132, "last_job_id": 0, "name": "file reputation - VirusTotal v3", "action": "9000", "description": "Queries VirusTotal for file reputation info", "type": "file reputation", "app_id": 323, "asset": 28, "parameters": [{"hash": ""}]}, {"id": "6542c98e-e3b3-4778-b1e3-56697c46b165", "create_time": 1774384810.4407372, "update_time": 1774386512.9065466, "last_job_id": 0, "name": "domain reputation - VirusTotal v3", "action": "8999", "description": "Queries VirusTotal for domain info", "type": "domain reputation", "app_id": 323, "asset": 28, "parameters": [{"domain": ""}]}, {"id": "ca5a6a39-2e0d-45ab-93d1-030939fc63c4", "create_time": 1774384810.4407997, "update_time": 1774386512.9065802, "last_job_id": 0, "name": "ip reputation - VirusTotal v3", "action": "9002", "description": "Queries VirusTotal for IP info", "type": "ip reputation", "app_id": 323, "asset": 28, "parameters": [{"ip": ""}]}, {"id": "f745dd7c-7cb5-4529-a663-28daf1e5870d", "create_time": 1774384810.4408424, "update_time": 1774386512.9066138, "last_job_id": 0, "name": "url reputation - VirusTotal v3", "action": "9003", "description": "Queries VirusTotal for URL info (run this action after running detonate url)", "type": "url reputation", "app_id": 323, "asset": 28, "parameters": [{"url": ""}]}, {"id": "10ebf987-55b9-4bee-8a6c-14931efc00ca", "create_time": 1774384810.4408824, "update_time": 1774386512.9066467, "last_job_id": 0, "name": "file intelligence - Recorded Future For Splunk SOAR", "action": "4270", "description": "Get threat intelligence for a file identified by its hash", "type": "file intelligence", "app_id": 247, "asset": 19, "parameters": [{"hash": ""}]}, {"id": "caa048fa-4c02-4ee5-b1bf-5c22dc3083db", "create_time": 1774384810.4409223, "update_time": 1774386512.90668, "last_job_id": 0, "name": "url intelligence - Recorded Future For Splunk SOAR", "action": "4266", "description": "Get threat intelligence for a URL", "type": "url intelligence", "app_id": 247, "asset": 19, "parameters": [{"url": ""}]}, {"id": "c01795dd-463f-4896-bfdc-f2caa98a8509", "create_time": 1774384810.4409626, "update_time": 1774386512.906713, "last_job_id": 0, "name": "file reputation - Recorded Future For Splunk SOAR", "action": "4271", "description": "Get a quick indicator of the risk associated with a file identified by its hash", "type": "file reputation", "app_id": 247, "asset": 19, "parameters": [{"hash": ""}]}], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "e8b572ad-9cb7-4a0b-accc-dc0d6bc672af", "create_time": 1764758755.867274, "update_time": 1774386512.9067976, "name": "Acquire architecture map", "order": 3, "tag": "10b5cc45-188d-4152-99c2-d9ee90a0df52", "description": "Find or build an up-to-date map of the network.", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "49e8c224-9ffe-472f-b5d5-d0134314ddc0", "create_time": 1764758755.8673825, "update_time": 1774386512.9068766, "name": "Acquire asset inventory", "order": 4, "tag": "27d598df-8c52-4d6b-871d-93ee5ccdaf3f", "description": "Find%20or%20build%20an%20up-to-date%20inventory%20of%20all%20devices.%0A%0ASuggested%20Dashboards%0A1.%20%5BAsset%20Center%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/asset_center)%0A%0ASuggested%20Integration%20(%20if%20not%20already%20configured%20navigate%20%5BHERE%5D(/app/SplunkEnterpriseSecuritySuite/ess_configuration/#/soar/soar_apps/apps)%20to%20locate%20and%20configure)%0A1.%20ServiceNow%0A2.%20%5BAsset%20and%20Risk%20Intelligence%5D(https://splunkbase.splunk.com/app/7180)%0A", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "bd65385f-53f6-4b16-ae5b-8480703a5e29", "create_time": 1764758755.8674753, "update_time": 1774386512.9069724, "name": "Continuous monitoring", "order": 5, "tag": "3959e856-64e9-486e-a0b6-0cb97176c283", "description": "Monitor threat trends and system activity.", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}]}, {"id": "d8781b52-5f94-496a-9221-20af11959541", "create_time": 1774386512.9074764, "update_time": 1774386512.9074771, "name": "Identification", "order": 2, "tasks": [{"id": "0fc8d25d-2b92-4617-b573-518330fb9da1", "create_time": 1764758755.867626, "update_time": 1774386512.9070833, "name": "Detect the infection", "order": 1, "tag": "27c2ab29-35d9-4643-9216-85a8c201e0ed", "description": "Detect%20abnormalities%20and%20potential%20infections%20using%20endpoint%20and%20network%20intrusion%20detection%20systems,%20application%20logs,%20authentication%20logs,%20system%20load%20monitoring,%20notification%20from%20external%20sources,%20and%20other%20methods.%20Seek%20a%20repeatable%20detection%20that%20is%20as%20reliable%20as%20possible,%20as%20future%20steps%20call%20for%20checking%20and%20re-checking%20to%20monitor%20progress.%0A%0ASuggested%20Dashboards%0A1.%20%5BAnalyst%20Queue%5D(/app/SplunkEnterpriseSecuritySuite/incident_review)%0A2.%20%5BRisk%20Analysis%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/risk_analysis)%0A3.%20%5BMalware%20Center%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/malware_center)%0A4.%20%5BMalware%20Search%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/malware_search)%0A5.%20%5BOpen%20Email%20Search%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/email_search)%0A6.%20%5BTraffic%20Center%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/traffic_center)%0A7.%20%5BAccess%20Anomalies%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/access_anomalies)%0A8.%20%5BIndicators%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/threat_artifacts)", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "709ed3e1-de9b-421a-b7b2-eae661d66b04", "create_time": 1764758755.867718, "update_time": 1774386512.9072006, "name": "Identify the infection", "order": 2, "tag": "fcd59f33-221b-43aa-a26f-7a7536dc298a", "description": "Compare%20the%20known%20symptoms%20to%20all%20available%20threat%20intelligence%20and%20try%20to%20identify%20the%20threat%20as%20specifically%20as%20possible.%0A%0ASuggested%20Dashboards%0A1.%20%5BAnalyst%20Queue%5D(/app/SplunkEnterpriseSecuritySuite/incident_review)%0A2.%20%5BRisk%20Analysis%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/risk_analysis)%0A3.%20%5BMalware%20Center%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/malware_center)%0A4.%20%5BMalware%20Search%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/malware_search)%0A5.%20%5BOpen%20Email%20Search%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/email_search)%0A6.%20%5BTraffic%20Center%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/traffic_center)%0A7.%20%5BAccess%20Anomalies%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/access_anomalies)%0A8.%20%5BIndicators%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/threat_artifacts)%0A", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "07f7f8bf-c7d0-4312-a878-1cc5910284e3", "create_time": 1764758755.8678086, "update_time": 1774386512.9073658, "name": "Assess the perimeter of the infection", "order": 3, "tag": "d5aa1644-4d52-4274-92b7-c8b9e33b56e0", "description": "Check%20systems%20in%20different%20parts%20of%20the%20organization%20to%20define%20the%20perimeter%20of%20the%20infection%20and%20assess%20the%20potential%20business%20impact.%0A%0ASuggested%20Dashboards%0A1.%20%5BAnalyst%20Queue%5D(/app/SplunkEnterpriseSecuritySuite/incident_review)%0A2.%20%5BRisk%20Analysis%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/risk_analysis)%0A3.%20%5BMalware%20Center%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/malware_center)%0A4.%20%5BMalware%20Search%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/malware_search)%0A5.%20%5BOpen%20Email%20Search%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/email_search)%0A6.%20%5BTraffic%20Center%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/traffic_center)%0A7.%20%5BAccess%20Anomalies%5D(/app/SplunkEnterpriseSecuritySuite/access_anomalies)%0A8.%20%5BAsset%20and%20Risk%20Intelligence%5D(https://splunkbase.splunk.com/app/7180)", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}]}, {"id": "b077cd75-7ba9-467c-a53e-bfcea36eb013", "create_time": 1774386512.908651, "update_time": 1774386512.9086516, "name": "Containment", "order": 3, "tasks": [{"id": "3aee7278-0f5f-48ff-ad16-9ddaec267689", "create_time": 1764758755.8679423, "update_time": 1774386512.9075892, "name": "Disconnect infected areas from the internet", "order": 1, "tag": "e53fd536-8058-4a06-8c6c-e6fc9467ddf8", "description": "Stop%20command%20and%20control%20behavior%20and%20further%20propagation%20by%20disconnecting%20affected%20areas%20from%20the%20internet.%0A%0ASuggested%20Integration%20(%20if%20not%20already%20configured%20navigate%20%5BHERE%5D(/app/SplunkEnterpriseSecuritySuite/ess_configuration/#/soar/soar_apps/apps)%20to%20locate%20and%20configure)%0A1.%20%20Crowdstrike%0A2.%20Windows%20Defender%20ATP%0A3.%20VMware%20Carbon%20Black%20Cloud%20for%20Splunk%20SOAR", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [{"id": "50fe46cd-ed21-4f49-be3e-31c24704475e", "create_time": 1774385444.6014853, "update_time": 1774386512.9077039, "last_job_id": 0, "name": "quarantine device - Carbon Black Response", "action": "8740", "description": "Quarantine the endpoint", "type": "quarantine device", "app_id": 48, "asset": 10, "parameters": [{"ip_hostname": ""}]}, {"id": "2895d424-21ca-456f-93cc-0a522302a21e", "create_time": 1774385444.6015267, "update_time": 1774386512.907741, "last_job_id": 0, "name": "quarantine file - Windows Defender ATP", "action": "9020", "description": "Quarantine a file", "type": "quarantine file", "app_id": 191, "asset": 45, "parameters": [{"comment": "", "timeout": "", "device_id": "", "file_hash": ""}]}, {"id": "18c32315-b596-40c2-ab52-bfbc9ad7c284", "create_time": 1774385444.601569, "update_time": 1774386512.9077997, "last_job_id": 0, "name": "quarantine device - CrowdStrike OAuth API", "action": "8761", "description": "Block the device", "type": "quarantine device", "app_id": 77, "asset": 44, "parameters": [{"hostname": "", "device_id": ""}]}], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "50bcd8ba-7edc-4b44-8a04-fdd5ee6daa0b", "create_time": 1764758755.8680344, "update_time": 1774386512.9078639, "name": "Isolate infected area from all networks", "order": 2, "tag": "884437ea-ff98-40f7-999d-69efd55841ae", "description": "Enforce%20more%20strict%20network%20segmentation%20to%20prevent%20further%20internal%20spreading.%20Consider%20disconnecting%20mobile%20devices%20and%20laptops%20to%20minimize%20the%20propagation%20surface.%0A%0ASuggested%20Integration%20(%20if%20not%20already%20configured%20navigate%20%5BHERE%5D(/app/SplunkEnterpriseSecuritySuite/ess_configuration/#/soar/soar_apps/apps)%20to%20locate%20and%20configure)%0A1.%20%20Cisco%20Firepower%0A2.%20Cisco%20Secure%20Firewall%0A3.%20Palo%20Alto%0A4.%20Zscaler%0A", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [{"id": "cabcfb22-727b-4863-a377-4745a236c1ef", "create_time": 1774385444.6017046, "update_time": 1774386512.9079368, "last_job_id": 0, "name": "block ip - Cisco Firepower", "action": "9266", "description": "Blocks an IP network", "type": "block ip", "app_id": 56, "asset": 40, "parameters": [{"ip": ""}]}, {"id": "7eb65f38-9266-437b-8d4a-b9d931c0b854", "create_time": 1774385444.6017454, "update_time": 1774386512.9079711, "last_job_id": 0, "name": "delete network object - Cisco Secure Firewall", "action": "9272", "description": "Deletes a network object in FMC", "type": "delete network object", "app_id": 59, "asset": 41, "parameters": [{"type": "", "object_id": "", "domain_name": ""}]}, {"id": "7fbc8a08-6bca-42ff-be3a-40f992e6425c", "create_time": 1774385444.6018152, "update_time": 1774386512.908006, "last_job_id": 0, "name": "block ip - Panorama", "action": "8651", "description": "Block an IP", "type": "block ip", "app_id": 220, "asset": 42, "parameters": [{"ip": "", "policy_name": "", "policy_type": "", "device_group": "", "audit_comment": "", "should_add_tag": false, "is_source_address": false, "use_partial_commit": false, "should_commit_changes": false}]}, {"id": "edc831c7-b6c7-4677-bd87-7cf5024b1b65", "create_time": 1774385444.601857, "update_time": 1774386512.9080405, "last_job_id": 0, "name": "block url - Panorama", "action": "8647", "description": "Block an URL", "type": "block url", "app_id": 220, "asset": 42, "parameters": [{"url": "", "policy_name": "", "policy_type": "", "device_group": "", "audit_comment": "", "use_partial_commit": false, "should_commit_changes": false}]}, {"id": "907d0ada-e046-4658-bad3-c0a038f0611e", "create_time": 1774385444.6018982, "update_time": 1774386512.9080873, "last_job_id": 0, "name": "custom block policy - Panorama", "action": "8663", "description": "Block IP addresses, Address Groups, EDLs(External Dynamic List), Applications, or URL Categories in Panorama and creates a custom uni-directional (direction parameter value as from or to) or bi-directional (direction parameter value as both) security rule", "type": "custom block policy", "app_id": 220, "asset": 42, "parameters": [{"dst": "", "ph0": "", "tag": "", "where": "", "target": "", "direction": "", "rule_type": "", "description": "", "object_type": "", "policy_name": "", "policy_type": "", "device_group": "", "object_value": "", "audit_comment": "", "log_forwarding": "", "icmp_unreachable": "", "use_partial_commit": false, "should_commit_changes": false}]}, {"id": "e8f428e0-3604-421d-80b5-f477df3fddbf", "create_time": 1774385444.6019397, "update_time": 1774386512.9081216, "last_job_id": 0, "name": "block ip - Zscaler", "action": "9074", "description": "Block an IP", "type": "block ip", "app_id": 338, "asset": 30, "parameters": [{"ip": "", "url_category": ""}]}, {"id": "f580672c-1fd3-4407-8db2-7a29e864b882", "create_time": 1774385444.6019795, "update_time": 1774386512.9081564, "last_job_id": 0, "name": "block url - Zscaler", "action": "9075", "description": "Block a URL", "type": "block url", "app_id": 338, "asset": 30, "parameters": [{"url": "", "url_category": ""}]}], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "8ff5509b-ae70-431c-ac11-f4445d9bd890", "create_time": 1764758755.8681533, "update_time": 1774386512.9082158, "name": "Monitor business-critical network connections that cannot be disconnected", "order": 3, "tag": "400bb1f4-670c-4503-91a0-fe813d7285f2", "description": "For%20those%20applications%20that%20cannot%20be%20disconnected%20due%20to%20continuity%20needs,%20increase%20monitoring%20and%20analyze%20traffic%20for%20malicious%20activity.%0A%0ASuggested%20Dashboards%0A1.%20%5BAnalyst%20Queue%5D(/app/SplunkEnterpriseSecuritySuite/incident_review)%0A2.%20%5BRisk%20Analysis%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/risk_analysis)%0A3.%20%5BMalware%20Center%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/malware_center)%0A4.%20%5BMalware%20Search%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/malware_search)%0A5.%20%5BEmail%20Search%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/email_search)%0A6.%20%5BTraffic%20Center%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/traffic_center)%0A7.%20%5BAccess%20Anomalies%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/access_anomalies)%0A8.%20%5BAsset%20and%20Risk%20Intelligence%5D(https://splunkbase.splunk.com/app/7180)", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "d220afbd-3306-4e8a-ad41-3028fb9f309f", "create_time": 1764758755.8682685, "update_time": 1774386512.9083161, "name": "Neutralize propagation vectors", "order": 4, "tag": "92bef873-aca9-4ef8-946b-edfb9ce66e36", "description": "Deploy%20patches,%20change%20configurations,%20sinkhole%20domains,%20re-image%20systems,%20stop%20services,%20or%20take%20other%20appropriate%20actions%20to%20prevent%20further%20propagation%20using%20all%20known%20vectors.%20Notify%20users%20of%20changes%20that%20will%20affect%20them%20and/or%20request%20their%20assistance%20for%20manual%20neutralization%20steps.%0A%0ASuggested%20Integration%20(%20if%20not%20already%20configured%20navigate%20%5BHERE%5D(/app/SplunkEnterpriseSecuritySuite/ess_configuration/#/soar/soar_apps/apps)%20to%20locate%20and%20configure)%0A1.%20Crowdstrike%0A2.%20Windows%20Defender%20ATP%0A3.%20VMware%20Carbon%20Black%20Cloud%20for%20Splunk%20SOARSuggested%20Integrations", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [{"id": "0ec039e2-cc7d-4c6d-9dc6-c8ee864fbebb", "create_time": 1774386449.1275365, "update_time": 1774386512.9083855, "last_job_id": 0, "name": "quarantine device - Carbon Black Response", "action": "8740", "description": "Quarantine the endpoint", "type": "quarantine device", "app_id": 48, "asset": 10, "parameters": [{"ip_hostname": ""}]}, {"id": "32c679a1-8f54-48e5-b26d-537e7f1df255", "create_time": 1774386449.1275787, "update_time": 1774386512.90842, "last_job_id": 0, "name": "quarantine device - CrowdStrike OAuth API", "action": "8761", "description": "Block the device", "type": "quarantine device", "app_id": 77, "asset": 44, "parameters": [{"hostname": "", "device_id": ""}]}, {"id": "5490b33e-8ea8-4b0e-94e8-378b3fd693f5", "create_time": 1774386449.1276183, "update_time": 1774386512.9084735, "last_job_id": 0, "name": "quarantine device - Windows Defender ATP", "action": "9016", "description": "Quarantine the device", "type": "quarantine device", "app_id": 191, "asset": 45, "parameters": [{"type": "", "comment": "", "timeout": "", "device_id": ""}]}, {"id": "73ac3634-b083-4d96-a823-78314b3b0259", "create_time": 1774386449.1276588, "update_time": 1774386512.908509, "last_job_id": 0, "name": "block hash - Carbon Black Response", "action": "8753", "description": "Add a hash to the Carbon Black Response blacklist", "type": "block hash", "app_id": 48, "asset": 10, "parameters": [{"hash": "", "comment": ""}]}, {"id": "253c1795-eefa-4eb6-a567-4a84277f054d", "create_time": 1774386449.1276984, "update_time": 1774386512.9085426, "last_job_id": 0, "name": "restrict app execution - Windows Defender ATP", "action": "9033", "description": "Restrict execution of all applications on the device except a predefined set", "type": "restrict app execution", "app_id": 191, "asset": 45, "parameters": [{"comment": "", "timeout": "", "device_id": ""}]}], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "640ecd84-2bff-4b55-b16e-2f00b863cfe0", "create_time": 1764758755.8683593, "update_time": 1774386512.9086058, "name": "Monitor progress", "order": 5, "tag": "66412e78-657c-4f0d-a15a-2533d1b9a948", "description": "Re-check neutralized systems and repeat or improve processes to cover important systems as quickly as possible.", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}]}, {"id": "4999e420-9fa9-46ea-9da3-4ffb078c45a0", "create_time": 1774386512.909092, "update_time": 1774386512.9090922, "name": "Remediation", "order": 4, "tasks": [{"id": "06bd975f-1fb6-4333-b714-27ce6a1ced40", "create_time": 1764758755.8684924, "update_time": 1774386512.9087322, "name": "Identify", "order": 1, "tag": "7f4c59cc-2f64-459c-8245-31bb42439ea9", "description": "Consider vendor fixes, antivirus updates, external support options, and custom solutions. Use these to define a disinfection process and validate it with a reputable source if possible.", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "93e47407-dfd0-40ba-a01d-1ef596ee0c42", "create_time": 1764758755.8685825, "update_time": 1774386512.9088724, "name": "Test", "order": 2, "tag": "e0cc2310-9631-4a7f-b637-79d890e0a79a", "description": "Test the disinfection process on a system that is as close to a production configuration as possible and verify that it works while not damaging any service.", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "448524ff-39de-428d-95f7-2cc16c03ea28", "create_time": 1764758755.8686728, "update_time": 1774386512.908973, "name": "Deploy", "order": 3, "tag": "69ea1765-0326-4559-9f52-0202bcd1684e", "description": "Deploy the process and scale it up if possible.", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "154ef40e-9a4e-4072-b222-e4b5c286ce4f", "create_time": 1764758755.8687656, "update_time": 1774386512.9090486, "name": "Confirm", "order": 4, "tag": "ec04ad38-972d-40d5-9672-64ccce7f2ebc", "description": "Confirm that the malware did not block remediations and find a workaround if it did.", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}]}, {"id": "46c10e9a-74fd-4c28-ae23-80c66c6959ff", "create_time": 1774386512.9095664, "update_time": 1774386512.9095669, "name": "Recovery", "order": 5, "tasks": [{"id": "b5137ace-0638-4c0d-bf3a-89808acb2796", "create_time": 1764758755.8689115, "update_time": 1774386512.9091556, "name": "Verify Containment and Remediation", "order": 1, "tag": "11e7491e-04ec-46dd-8763-7f7259aa86a9", "description": "Review current progress towards remediation by re-checking systems.", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "916ce97e-d38f-41bd-8e31-fd4ebac266fa", "create_time": 1764758755.8690028, "update_time": 1774386512.909229, "name": "Reopen propagation network mechanism", "order": 2, "tag": "3e4bb0aa-beab-472e-b19a-5d0974e25942", "description": "Turn off network enforcement for a segment of the network and monitor for new attempts to reinfect.", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "1d6b12db-a684-4eee-b942-8d720c1e7c1a", "create_time": 1764758755.8690934, "update_time": 1774386512.9093044, "name": "Reconnect isolated sub-areas to each other", "order": 3, "tag": "ecd50bc1-ba91-4333-b50e-8065b2552e83", "description": "Turn off inter-area network enforcement and monitor.", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "77f860e3-1ab9-47f4-b9f5-29b02f762628", "create_time": 1764758755.8692014, "update_time": 1774386512.9093792, "name": "Reconnect mobile devices", "order": 4, "tag": "786a211c-5a54-4465-a6ae-fb26047d3d77", "description": "Reconnect mobile devices and laptops to monitor for persistence and check coverage across all device categories.", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "eea6a167-30bf-434e-a7a5-7f0af8bd0ec6", "create_time": 1764758755.8692956, "update_time": 1774386512.9094522, "name": "Reconnect isolated areas to main enterprise network", "order": 5, "tag": "739634b9-8f30-4fb4-b531-8f3e1bb5dcbc", "description": "Disable network enforcement between cleaned areas and the rest of the network while monitoring for reinfection.", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "7947c3e9-c721-44ad-92e5-cbda84dd7687", "create_time": 1764758755.8693867, "update_time": 1774386512.909524, "name": "Reconnect to the internet", "order": 6, "tag": "d80ab11b-58f4-4aed-a533-93f344fdc898", "description": "Reconnect to the internet and monitor.", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}]}, {"id": "76b0e701-8fe2-49da-a85d-c100fc2a3a19", "create_time": 1774386512.909781, "update_time": 1774386512.9097812, "name": "Aftermath", "order": 6, "tasks": [{"id": "bb39e701-edec-47a4-a5d9-47483140b788", "create_time": 1764758755.8695176, "update_time": 1774386512.909643, "name": "Build crisis report", "order": 1, "tag": "bb5d871c-99f4-408a-8a1e-9efa55ff1465", "description": "Notify affected parties with as much detail as is appropriate. Consider the initial cause of the infection, actions and timelines of important events, what went right, what went wrong, and the incident cost.", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "4a48b7c9-f36d-412f-a2e2-c369a98d4261", "create_time": 1764758755.8696067, "update_time": 1774386512.909723, "name": "Improve processes", "order": 2, "tag": "114c1009-376f-4715-a825-145c3dbcbba0", "description": "Capitalize on the experience by improving the processes that were used, creating new processes where needed, and automating that which is generalizable and repeatable.", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}]}], "origin": {"id": "ec7f5b1d-f689-4ea7-b00c-703d062755ef", "name": "Self-Replicating Malware", "version": 3}, "template_id": "e3b082d7-756e-48de-bcfe-7975933f9b75", "active": true, "used": false, "ai_generated": false, "source_attachment_id": null, "_user": "nobody", "_key": "0784962a-e50b-47c0-b5ac-bcd7669c045d"} |