mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
3953a43f05
* Create response_plan directory * Update directory name * Copy response_templates artifacts to dist/api * Add response-templates schema validation workflow * Add feature branch for testing purpose * Update endpoint to playground * Revert back debug changes * Move scripts to workflows * Remove manual check in * Add sorting for version and template name * Raise exception when file name not match * Add indentation for json output * Add debug option to dump json schema * Generate merged templates at runtime * Rename openAPI spec yaml to yml * Move validation to build.yml * Use stem to get file name * Fix python package install * Update version sorting using int * Update openAPI spec for version * Move build response templates to separate workflow * Fix naming in build-response-templates.yml * Update response templates to the ones for first release * Fix naming of response templates * Response templates to be added by response plan team * Keep response_templates directory * Skip .gitkeep checking when check non-json files * Remove the .gitkeep * Initial version of Response Templates * Initial version of Response Templates * Initial version of Response Templates * Revert "Initial version of Response Templates" This reverts commit3a174dd02e. * Revert "Initial version of Response Templates" This reverts commit26fa66ddde. * Revert "Initial version of Response Templates" This reverts commit6014b4870b. * Initial version of Response Templates * Initial version of Response Templates * Update and rename AccountCompromise_v14.json to AccountCompromise_v2.json * Update and rename DataBreach_v15.json to DataBreach_v2.json * Update and rename GenericIncidentResponse_v13.json to GenericIncidentResponse_v2.json * Update and rename NIST80061_v14.json to NIST80061_v2.json * Update and rename NetworkIndicatorEnrichment_v6.json to NetworkIndicatorEnrichment_v2.json * Update and rename SelfReplicatingMalware_v14.json to SelfReplicatingMalware_v2.json * Update and rename SuspiciousEmail_v35.json to SuspiciousEmail_v2.json * Update and rename VulnerabilityDisclosure_v10.json to VulnerabilityDisclosure_v2.json * Add comments --------- Co-authored-by: pyth0n1c <87383215+pyth0n1c@users.noreply.github.com> Co-authored-by: Christian Cloutier <ccloutier@splunk.com> Co-authored-by: kbouchard <47464052+kbouchardherjavecgroup@users.noreply.github.com> Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
2 lines
22 KiB
JSON
2 lines
22 KiB
JSON
{"id": "ec7f5b1d-f689-4ea7-b00c-703d062755ef", "create_time": 1764862816.2406306, "update_time": 1765478655.8295362, "name": "Self-Replicating Malware", "description": "This response template outlines a response to a potential infection by self-replicating malware (malware that propagates itself without human interaction). While there is much overlap between the response necessary for self-replicating malware and the response to any other malware, the ability to propagate from one system to the next automatically adds the potential for faster and more thorough infection of enterprise systems. Often the infection mechanism is a particular network service or shared resource, so an appropriate response tends to be a fast configuration change to contain the effect immediately.\n\nThis template is adapted from a modified version of the CERT Societe Generale Incident Response Methodology called Worm Infection Response. The full methodology is available at https://github.com/certsocietegenerale/IRM/blob/HEAD/EN/IRM-1-WormInfection.pdf and is covered under the Creative Commons Attribution 3.0 Imported license available at https://github.com/certsocietegenerale/IRM/blob/HEAD/LICENSE.md, while the CERT Societe Generale homepage is https://cert.societegenerale.com/en/.", "template_status": "published", "creator": "splunker", "updated_by": "splunker", "is_default": false, "version": 2, "phases": [{"id": "56b864aa-4f46-4eab-8631-15340fe85f3d", "create_time": 1765478655.800768, "update_time": 1765478655.8007686, "name": "Preparation", "order": 1, "tasks": [{"id": "ec3ed15c-7140-4e3d-ad5f-324edaf32d30", "create_time": 1764758755.867025, "update_time": 1765478655.8002567, "name": "Define team members", "order": 1, "tag": "a901e393-ab86-4ca7-95db-14d8774a60da", "description": "Determine%20which%20team%20members%20will%20play%20which%20role%20in%20the%20response%20and%20establish%20communications%20channels%20with%20all%20involved.%0A%0ASuggested%20Integrations%0A1.%20%5BCisco%20Webex%5D(https://splunkbase.splunk.com/app/5781)%0A2.%20%5BSlack%5D(https://splunkbase.splunk.com/app/5846)%0A3.%20%5BMicrosoft%20Teams%5D(https://splunkbase.splunk.com/app/5818)", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "faf9efef-e4dc-4100-98b4-3ed62777f915", "create_time": 1764758755.867135, "update_time": 1765478655.8004067, "name": "Check analysis tools", "order": 2, "tag": "6700e71f-245c-4f8c-b835-d91eaefe716b", "description": "Test%20connectivity,%20check%20patch%20level,%20and%20run%20example%20queries%20on%20all%20analysis%20tools.%0A%0ASuggested%20Integrations%0A1.%20%5BUpdate%20Center%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/update_center)%0A2.%20%5BSplunk%20Attack%20Analyzer%5D(https://splunkbase.splunk.com/app/6783)%0A3.%20%5BCisco%20Talos%20Intelligence%5D(https://splunkbase.splunk.com/app/7711)%0A4.%20%5BVirusTotal%20v3%5D(https://splunkbase.splunk.com/app/5865)%0A5.%20%20PhishTank%20(preconfigured)%0A6.%20%20%5BAlien%20Vault%5D(https://splunkbase.splunk.com/app/5878)", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "e8b572ad-9cb7-4a0b-accc-dc0d6bc672af", "create_time": 1764758755.867274, "update_time": 1765478655.8005216, "name": "Acquire architecture map", "order": 3, "tag": "10b5cc45-188d-4152-99c2-d9ee90a0df52", "description": "Find or build an up-to-date map of the network.", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "49e8c224-9ffe-472f-b5d5-d0134314ddc0", "create_time": 1764758755.8673825, "update_time": 1765478655.800613, "name": "Acquire asset inventory", "order": 4, "tag": "27d598df-8c52-4d6b-871d-93ee5ccdaf3f", "description": "Find%20or%20build%20an%20up-to-date%20inventory%20of%20all%20devices.%0A%0ASuggested%20Integrations%0A1.%20%5BAsset%20Center%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/asset_center)%0A2.%20%5BServiceNow%5D(https://splunkbase.splunk.com/app/5932)%0A3.%20%5BAsset%20and%20Risk%20Intelligence%5D(https://splunkbase.splunk.com/app/7180)%0A", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "bd65385f-53f6-4b16-ae5b-8480703a5e29", "create_time": 1764758755.8674753, "update_time": 1765478655.8007166, "name": "Continuous monitoring", "order": 5, "tag": "3959e856-64e9-486e-a0b6-0cb97176c283", "description": "Monitor threat trends and system activity.", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}]}, {"id": "d8781b52-5f94-496a-9221-20af11959541", "create_time": 1765478655.8011546, "update_time": 1765478655.8011549, "name": "Identification", "order": 2, "tasks": [{"id": "0fc8d25d-2b92-4617-b573-518330fb9da1", "create_time": 1764758755.867626, "update_time": 1765478655.8008454, "name": "Detect the infection", "order": 1, "tag": "27c2ab29-35d9-4643-9216-85a8c201e0ed", "description": "Detect%20abnormalities%20and%20potential%20infections%20using%20endpoint%20and%20network%20intrusion%20detection%20systems,%20application%20logs,%20authentication%20logs,%20system%20load%20monitoring,%20notification%20from%20external%20sources,%20and%20other%20methods.%20Seek%20a%20repeatable%20detection%20that%20is%20as%20reliable%20as%20possible,%20as%20future%20steps%20call%20for%20checking%20and%20re-checking%20to%20monitor%20progress.%0A%0ASuggested%20Integrations%0A1.%20%5BAnalyst%20Queue%5D(/app/SplunkEnterpriseSecuritySuite/incident_review)%0A2.%20%5BRisk%20Analysis%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/risk_analysis)%0A3.%20%5BMalware%20Center%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/malware_center)%0A4.%20%5BMalware%20Search%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/malware_search)%0A5.%20%5BOpen%20Email%20Search%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/email_search)%0A6.%20%5BTraffic%20Center%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/traffic_center)%0A7.%20%5BAccess%20Anomalies%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/access_anomalies)", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "709ed3e1-de9b-421a-b7b2-eae661d66b04", "create_time": 1764758755.867718, "update_time": 1765478655.8009667, "name": "Identify the infection", "order": 2, "tag": "fcd59f33-221b-43aa-a26f-7a7536dc298a", "description": "Compare%20the%20known%20symptoms%20to%20all%20available%20threat%20intelligence%20and%20try%20to%20identify%20the%20threat%20as%20specifically%20as%20possible.%0A%0ASuggested%20Integrations%0A1.%20%5BSplunk%20Attack%20Analyzer%5D(https://splunkbase.splunk.com/app/6783)%0A2.%20%5BCisco%20Talos%20Intelligence%5D(https://splunkbase.splunk.com/app/7711)%0A3.%20%5BVirusTotal%20v3%5D(https://splunkbase.splunk.com/app/5865)%0A4.%20%20PhishTank%20(preconfigured)%0A5.%20%20%5BAlien%20Vault%5D(https://splunkbase.splunk.com/app/5878)%0A6.%20%5BIndicators%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/threat_artifacts)", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "07f7f8bf-c7d0-4312-a878-1cc5910284e3", "create_time": 1764758755.8678086, "update_time": 1765478655.8010774, "name": "Assess the perimeter of the infection", "order": 3, "tag": "d5aa1644-4d52-4274-92b7-c8b9e33b56e0", "description": "Check%20systems%20in%20different%20parts%20of%20the%20organization%20to%20define%20the%20perimeter%20of%20the%20infection%20and%20assess%20the%20potential%20business%20impact.%0A%0ASuggested%20Integrations%0A1.%20%5BAnalyst%20Queue%5D(/app/SplunkEnterpriseSecuritySuite/incident_review)%0A2.%20%5BRisk%20Analysis%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/risk_analysis)%0A3.%20%5BMalware%20Center%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/malware_center)%0A4.%20%5BMalware%20Search%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/malware_search)%0A5.%20%5BOpen%20Email%20Search%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/email_search)%0A6.%20%5BTraffic%20Center%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/traffic_center)%0A7.%20%5BAccess%20Anomalies%5D(/app/SplunkEnterpriseSecuritySuite/access_anomalies)%0A8.%20%5BAsset%20and%20Risk%20Intelligence%5D(https://splunkbase.splunk.com/app/7180)", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}]}, {"id": "b077cd75-7ba9-467c-a53e-bfcea36eb013", "create_time": 1765478655.8017411, "update_time": 1765478655.8017416, "name": "Containment", "order": 3, "tasks": [{"id": "3aee7278-0f5f-48ff-ad16-9ddaec267689", "create_time": 1764758755.8679423, "update_time": 1765478655.80125, "name": "Disconnect infected areas from the internet", "order": 1, "tag": "e53fd536-8058-4a06-8c6c-e6fc9467ddf8", "description": "Stop%20command%20and%20control%20behavior%20and%20further%20propagation%20by%20disconnecting%20affected%20areas%20from%20the%20internet.%0A%0ASuggested%20Integrations%0A1.%20%20%5BCisco%20Firepower%5D(https://splunkbase.splunk.com/app/5995)%0A2.%20%5BCisco%20Secure%20Firewall%5D(https://splunkbase.splunk.com/app/7745)%0A3.%20%5B%20Palo%20Alto%5D(https://splunkbase.splunk.com/app/5830)%0A4.%20%5BZscaler%5D(https://splunkbase.splunk.com/app/5872)%0A5.%20%5BCrowdstrike%5D(https://splunkbase.splunk.com/app/5786)%0A6.%20%5BMicrosoft%20Defender%20for%20Endpoint%5D(https://splunkbase.splunk.com/app/5870)%0A7.%20%5BVMware%20Carbon%20Black%20Cloud%20for%20Splunk%20SOAR%5D(https://splunkbase.splunk.com/app/6732)", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "50bcd8ba-7edc-4b44-8a04-fdd5ee6daa0b", "create_time": 1764758755.8680344, "update_time": 1765478655.8013616, "name": "Isolate infected area from all networks", "order": 2, "tag": "884437ea-ff98-40f7-999d-69efd55841ae", "description": "Enforce%20more%20strict%20network%20segmentation%20to%20prevent%20further%20internal%20spreading.%20Consider%20disconnecting%20mobile%20devices%20and%20laptops%20to%20minimize%20the%20propagation%20surface.%0A%0ASuggested%20Integrations%0A1.%20%20%5BCisco%20Firepower%5D(https://splunkbase.splunk.com/app/5995)%0A2.%20%5BCisco%20Secure%20Firewall%5D(https://splunkbase.splunk.com/app/7745)%0A3.%20%5B%20Palo%20Alto%5D(https://splunkbase.splunk.com/app/5830)%0A4.%20%5BZscaler%5D(https://splunkbase.splunk.com/app/5872)%0A5.%20%5BCrowdstrike%5D(https://splunkbase.splunk.com/app/5786)%0A6.%20%5BMicrosoft%20Defender%20for%20Endpoint%5D(https://splunkbase.splunk.com/app/5870)%0A7.%20%5BVMware%20Carbon%20Black%20Cloud%20for%20Splunk%20SOAR%5D(https://splunkbase.splunk.com/app/6732)", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "8ff5509b-ae70-431c-ac11-f4445d9bd890", "create_time": 1764758755.8681533, "update_time": 1765478655.8014727, "name": "Monitor business-critical network connections that cannot be disconnected", "order": 3, "tag": "400bb1f4-670c-4503-91a0-fe813d7285f2", "description": "For%20those%20applications%20that%20cannot%20be%20disconnected%20due%20to%20continuity%20needs,%20increase%20monitoring%20and%20analyze%20traffic%20for%20malicious%20activity.%0A%0ASuggested%20Integrations%0A1.%20%5BAnalyst%20Queue%5D(/app/SplunkEnterpriseSecuritySuite/incident_review)%0A2.%20%5BRisk%20Analysis%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/risk_analysis)%0A3.%20%5BMalware%20Center%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/malware_center)%0A4.%20%5BMalware%20Search%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/malware_search)%0A5.%20%5BEmail%20Search%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/email_search)%0A6.%20%5BTraffic%20Center%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/traffic_center)%0A7.%20%5BAccess%20Anomalies%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/access_anomalies)%0A8.%20%5BAsset%20and%20Risk%20Intelligence%5D(https://splunkbase.splunk.com/app/7180)", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "d220afbd-3306-4e8a-ad41-3028fb9f309f", "create_time": 1764758755.8682685, "update_time": 1765478655.8015823, "name": "Neutralize propagation vectors", "order": 4, "tag": "92bef873-aca9-4ef8-946b-edfb9ce66e36", "description": "Deploy%20patches,%20change%20configurations,%20sinkhole%20domains,%20re-image%20systems,%20stop%20services,%20or%20take%20other%20appropriate%20actions%20to%20prevent%20further%20propagation%20using%20all%20known%20vectors.%20Notify%20users%20of%20changes%20that%20will%20affect%20them%20and/or%20request%20their%20assistance%20for%20manual%20neutralization%20steps.%0A%0ASuggested%20Integrations%0A1.%20%5BCrowdstrike%5D(https://splunkbase.splunk.com/app/5786)%0A2.%20%5BMicrosoft%20Defender%20for%20Endpoint%5D(https://splunkbase.splunk.com/app/5870)%0A3.%20%5BVMware%20Carbon%20Black%20Cloud%20for%20Splunk%20SOAR%5D(https://splunkbase.splunk.com/app/6732)", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "640ecd84-2bff-4b55-b16e-2f00b863cfe0", "create_time": 1764758755.8683593, "update_time": 1765478655.8016906, "name": "Monitor progress", "order": 5, "tag": "66412e78-657c-4f0d-a15a-2533d1b9a948", "description": "Re-check neutralized systems and repeat or improve processes to cover important systems as quickly as possible.", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}]}, {"id": "4999e420-9fa9-46ea-9da3-4ffb078c45a0", "create_time": 1765478655.8021305, "update_time": 1765478655.802131, "name": "Remediation", "order": 4, "tasks": [{"id": "06bd975f-1fb6-4333-b714-27ce6a1ced40", "create_time": 1764758755.8684924, "update_time": 1765478655.8018172, "name": "Identify", "order": 1, "tag": "7f4c59cc-2f64-459c-8245-31bb42439ea9", "description": "Consider vendor fixes, antivirus updates, external support options, and custom solutions. Use these to define a disinfection process and validate it with a reputable source if possible.", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "93e47407-dfd0-40ba-a01d-1ef596ee0c42", "create_time": 1764758755.8685825, "update_time": 1765478655.8019052, "name": "Test", "order": 2, "tag": "e0cc2310-9631-4a7f-b637-79d890e0a79a", "description": "Test the disinfection process on a system that is as close to a production configuration as possible and verify that it works while not damaging any service.", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "448524ff-39de-428d-95f7-2cc16c03ea28", "create_time": 1764758755.8686728, "update_time": 1765478655.801993, "name": "Deploy", "order": 3, "tag": "69ea1765-0326-4559-9f52-0202bcd1684e", "description": "Deploy the process and scale it up if possible.", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "154ef40e-9a4e-4072-b222-e4b5c286ce4f", "create_time": 1764758755.8687656, "update_time": 1765478655.8020792, "name": "Confirm", "order": 4, "tag": "ec04ad38-972d-40d5-9672-64ccce7f2ebc", "description": "Confirm that the malware did not block remediations and find a workaround if it did.", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}]}, {"id": "46c10e9a-74fd-4c28-ae23-80c66c6959ff", "create_time": 1765478655.802708, "update_time": 1765478655.8027081, "name": "Recovery", "order": 5, "tasks": [{"id": "b5137ace-0638-4c0d-bf3a-89808acb2796", "create_time": 1764758755.8689115, "update_time": 1765478655.8022254, "name": "Verify Containment and Remediation", "order": 1, "tag": "11e7491e-04ec-46dd-8763-7f7259aa86a9", "description": "Review current progress towards remediation by re-checking systems.", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "916ce97e-d38f-41bd-8e31-fd4ebac266fa", "create_time": 1764758755.8690028, "update_time": 1765478655.8023124, "name": "Reopen propagation network mechanism", "order": 2, "tag": "3e4bb0aa-beab-472e-b19a-5d0974e25942", "description": "Turn off network enforcement for a segment of the network and monitor for new attempts to reinfect.", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "1d6b12db-a684-4eee-b942-8d720c1e7c1a", "create_time": 1764758755.8690934, "update_time": 1765478655.8024004, "name": "Reconnect isolated sub-areas to each other", "order": 3, "tag": "ecd50bc1-ba91-4333-b50e-8065b2552e83", "description": "Turn off inter-area network enforcement and monitor.", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "77f860e3-1ab9-47f4-b9f5-29b02f762628", "create_time": 1764758755.8692014, "update_time": 1765478655.8024862, "name": "Reconnect mobile devices", "order": 4, "tag": "786a211c-5a54-4465-a6ae-fb26047d3d77", "description": "Reconnect mobile devices and laptops to monitor for persistence and check coverage across all device categories.", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "eea6a167-30bf-434e-a7a5-7f0af8bd0ec6", "create_time": 1764758755.8692956, "update_time": 1765478655.802572, "name": "Reconnect isolated areas to main enterprise network", "order": 5, "tag": "739634b9-8f30-4fb4-b531-8f3e1bb5dcbc", "description": "Disable network enforcement between cleaned areas and the rest of the network while monitoring for reinfection.", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "7947c3e9-c721-44ad-92e5-cbda84dd7687", "create_time": 1764758755.8693867, "update_time": 1765478655.8026576, "name": "Reconnect to the internet", "order": 6, "tag": "d80ab11b-58f4-4aed-a533-93f344fdc898", "description": "Reconnect to the internet and monitor.", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}]}, {"id": "76b0e701-8fe2-49da-a85d-c100fc2a3a19", "create_time": 1765478655.80292, "update_time": 1765478655.8029208, "name": "Aftermath", "order": 6, "tasks": [{"id": "bb39e701-edec-47a4-a5d9-47483140b788", "create_time": 1764758755.8695176, "update_time": 1765478655.8027844, "name": "Build crisis report", "order": 1, "tag": "bb5d871c-99f4-408a-8a1e-9efa55ff1465", "description": "Notify affected parties with as much detail as is appropriate. Consider the initial cause of the infection, actions and timelines of important events, what went right, what went wrong, and the incident cost.", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "4a48b7c9-f36d-412f-a2e2-c369a98d4261", "create_time": 1764758755.8696067, "update_time": 1765478655.8028712, "name": "Improve processes", "order": 2, "tag": "114c1009-376f-4715-a825-145c3dbcbba0", "description": "Capitalize on the experience by improving the processes that were used, creating new processes where needed, and automating that which is generalizable and repeatable.", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}]}], "template_id": "633942a9-b466-49c5-9cb0-1a4488da8473", "active": true, "used": false, "_user": "nobody", "_key": "ec7f5b1d-f689-4ea7-b00c-703d062755ef"}
|