Files
xqi-splunk 3953a43f05 Concept Shippable Response Plans (#3803)
* Create response_plan directory

* Update directory name

* Copy response_templates artifacts to dist/api

* Add response-templates schema validation workflow

* Add feature branch for testing purpose

* Update endpoint to playground

* Revert back debug changes

* Move scripts to workflows

* Remove manual check in

* Add sorting for version and template name

* Raise exception when file name not match

* Add indentation for json output

* Add debug option to dump json schema

* Generate merged templates at runtime

* Rename openAPI spec yaml to yml

* Move validation to build.yml

* Use stem to get file name

* Fix python package install

* Update version sorting using int

* Update openAPI spec for version

* Move build response templates to separate workflow

* Fix naming in build-response-templates.yml

* Update response templates to the ones for first release

* Fix naming of response templates

* Response templates to be added by response plan team

* Keep response_templates directory

* Skip .gitkeep checking when check non-json files

* Remove the .gitkeep

* Initial version of Response Templates

* Initial version of Response Templates

* Initial version of Response Templates

* Revert "Initial version of Response Templates"

This reverts commit 3a174dd02e.

* Revert "Initial version of Response Templates"

This reverts commit 26fa66ddde.

* Revert "Initial version of Response Templates"

This reverts commit 6014b4870b.

* Initial version of Response Templates

* Initial version of Response Templates

* Update and rename AccountCompromise_v14.json to AccountCompromise_v2.json

* Update and rename DataBreach_v15.json to DataBreach_v2.json

* Update and rename GenericIncidentResponse_v13.json to GenericIncidentResponse_v2.json

* Update and rename NIST80061_v14.json to NIST80061_v2.json

* Update and rename NetworkIndicatorEnrichment_v6.json to NetworkIndicatorEnrichment_v2.json

* Update and rename SelfReplicatingMalware_v14.json to SelfReplicatingMalware_v2.json

* Update and rename SuspiciousEmail_v35.json to SuspiciousEmail_v2.json

* Update and rename VulnerabilityDisclosure_v10.json to VulnerabilityDisclosure_v2.json

* Add comments

---------

Co-authored-by: pyth0n1c <87383215+pyth0n1c@users.noreply.github.com>
Co-authored-by: Christian Cloutier <ccloutier@splunk.com>
Co-authored-by: kbouchard <47464052+kbouchardherjavecgroup@users.noreply.github.com>
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
2025-12-17 02:30:20 +05:30

2 lines
36 KiB
JSON

{"id": "a72d40f3-a567-48e2-9fd3-c29db06c3907", "create_time": 1765479748.831508, "update_time": 1765479748.831508, "name": "Suspicious Email", "description": "There are many ways in which attackers can use email to gain a foothold in an organization or advance an existing campaign. This response template guides an analyst through the process of investigating and remediating several of these methods. The main objective of the first three phases is to determine if the email is malicious and what impact it might have if the attack is successful. The fourth and fifth phases focus on taking action to prevent further harm to the organization and conducting more investigation and analysis to learn more about the threat. Finally, the sixth phase describes communications to other parts of the organization which may be appropriate based on what was observed in the first five phases. This response template uses the structure of the SOEL framework (https://www.sans.org/cyber-security-summit/archives/file/summit-archive-1532986430.pdf) to organize the phases and tasks.", "template_status": "published", "creator": "splunker", "updated_by": "splunker", "is_default": false, "version": 2, "phases": [{"id": "7eddb898-085a-43fa-a03b-3ded48d53093", "create_time": 1765479748.831965, "update_time": 1765479796.6274312, "name": "Ingestion", "order": 1, "tasks": [{"id": "de8fa91f-bfad-41e6-bfe5-e3a2732db2c2", "create_time": 1764758755.6795278, "update_time": 1765479796.626802, "name": "Create ticket", "order": 1, "tag": "3d75cc89-a55b-4680-931c-7a5e091baaf6", "description": "Create%20any%20necessary%20tickets%20or%20tracking%20documents%20describing%20the%20initial%20conditions%20of%20the%20suspicious%20email%20investigation.%20As%20additional%20information%20is%20collected%20or%20actions%20are%20taken%20in%20the%20following%20tasks%20and%20phases,%20update%20the%20ticket%20with%20links%20and%20relevant%20information%20to%20allow%20collaboration%20and%20tracking.%0A%0A%5BSuggested%20Integrations%5D(https://splunkbase.splunk.com/apps?page=1&product=soar&categories=ticketing)%0A", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "163d3490-d8de-4df9-8900-f5a2554b8024", "create_time": 1764758755.6797986, "update_time": 1765479796.6270301, "name": "Ingest email", "order": 2, "tag": "b4f73c35-e4af-40bf-a349-bed4c51cb0fc", "description": "Identify%20and%20ingest%20the%20suspicious%20email%20into%20Splunk%20Mission%20Control.%20Actual%20steps%20vary%20depending%20on%20how%20you%20create%20the%20Splunk%20Mission%20Control%20notable%20and%20where%20the%20suspicious%20email%20resides.%20For%20example,%20if%20you%20had%20a%20Splunk%20Enterprise%20Security%20correlation%20search%20running%20to%20identify%20suspicious%20emails,%20and%20forward%20those%20notable%20events%20to%20Splunk%20Mission%20Control%20as%20notables,%20you%20have%20many%20of%20the%20useful%20artifacts%20needed%20to%20investigate%20the%20email.%20If%20you%20need%20additional%20metadata,%20you%20can%20run%20the%20%22get%20email%22%20action%20to%20retrieve%20it,%20or%20the%20%22extract%20email%22%20action%20to%20add%20the%20email%20to%20Splunk%20Mission%20Control%20if%20it%20is%20in%20the%20.msg%20or%20.eml%20format.%20Or%20for%20example,%20if%20you%20send%20suspicious%20emails%20to%20a%20dedicated%20email%20address%20for%20suspected%20phishing%20attempts,%20you%20can%20use%20a%20connector%20such%20as%20IMAP,%20EWS%20for%20Exchange,%20EWS%20for%20OFfice,%20or%20GSuite%20for%20GMail%20to%20poll%20that%20inbox%20directly%20and%20send%20the%20suspicious%20email%20to%20Splunk%20Mission%20Control%20as%20a%20notable.%0A%0ASuggested%20Integrations%0A1.%20%20%5BSplunk%20Attack%20Analyzer%5D(https://splunkbase.splunk.com/app/6783)%0A2.%20%5BMS%20Graph%20for%20Office%5D(https://splunkbase.splunk.com/app/5824)%0A3.%20%20%5BGmail%5D(https://splunkbase.splunk.com/app/5795)%0A4.%20%20%5BIMAP%5D(https://splunkbase.splunk.com/app/5798)", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "a6d6d47d-3c94-42ea-b575-c197be210f97", "create_time": 1764758755.6799636, "update_time": 1765479796.627336, "name": "Extract actionable metadata and files", "order": 3, "tag": "0c5acee1-e985-43ec-aefa-9355f46fef2d", "description": "Depending on how the email was ingested, additional steps might be required to extract actionable metadata and files. For example, if the suspicious email is attached to the Splunk Mission Control notable as a file, run the \"extract ioc\" action to extract URLs, domain names, IP addresses, file hashes, and whole file attachments as artifacts. In some cases, you might need to write specific playbooks or ingestion scripts to extract or reformat fields from the email. Be aware that malicious emails can obfuscate links and file attachments, so it might be necessary to view the email in a sandboxed email client to see it in the same context as a user would see it.", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}]}, {"id": "9510afc9-a689-434d-8622-e7dbcf607e54", "create_time": 1765479748.832889, "update_time": 1765479796.6289487, "name": "External Investigation", "order": 2, "tasks": [{"id": "2bedd439-1521-4bc1-aa32-f6502bc3b4eb", "create_time": 1764758755.6802204, "update_time": 1765479796.6275756, "name": "Investigate URLs", "order": 1, "tag": "5c7e7c30-139a-45e5-9622-63c788fe10a3", "description": "Perhaps%20the%20most%20common%20email%20attack%20vector%20is%20a%20clickable%20link%20that%20brings%20a%20user%20to%20a%20malicious%20website.%20The%20malicious%20website%20might%20collect%20credentials%20or%20other%20confidential%20information,%20attempt%20to%20exploit%20the%20user's%20browser,%20lead%20the%20user%20to%20download%20a%20malicious%20file,%20or%20gather%20preliminary%20fingerprint%20information%20about%20the%20user%20to%20inform%20further%20operations.%20Investigate%20all%20URLs%20contained%20in%20the%20suspicious%20email%20using%20a%20mix%20of%20automated%20and%20manual%20techniques.%20Query%20threat%20intelligence%20services%20and%20other%20sources%20of%20reputation%20information%20to%20see%20if%20the%20URLs%20are%20linked%20to%20known%20malicious%20activity.%20Check%20the%20categorization%20of%20the%20URLs%20and%20their%20popularity%20using%20services%20such%20as%20Censys%20or%20Alexa.%20Determine%20whether%20the%20URL%20is%20spoofing%20a%20brand%20using%20a%20similar%20spelling,%20a%20unicode%20substitution,%20or%20an%20out-of-order%20domain%20name.%20Also%20consider%20using%20a%20less%20passive%20technique%20that%20analyzes%20the%20current%20state%20of%20the%20URL,%20such%20as%20a%20sandboxed%20URL%20detonation,%20a%20website%20scanning%20tool%20such%20as%20urlscan.io%20or%20SSL%20Labs,%20a%20manual%20inspection%20from%20a%20sandboxed%20environment,%20or%20a%20website%20screenshot%20engine%20such%20as%20Screenshot%20Machine.%20Consider%20that%20targeted%20attacks%20might%20only%20reveal%20the%20malicious%20behavior%20of%20a%20website%20if%20the%20user%20agent%20and/or%20the%20source%20address%20of%20the%20request%20matches%20the%20target%20environment.%20The%20output%20of%20this%20task%20might%20be%20more%20linked%20URLs,%20the%20domain%20names%20of%20the%20underlying%20servers%20responding%20to%20the%20request,%20other%20domain%20names%20used%20by%20the%20website,%20IP%20addresses,%20or%20downloadable%20files.%20All%20of%20the%20above%20should%20be%20passed%20on%20to%20further%20investigative%20tasks%20if%20needed.%0A%0ASuggested%20Integrations%0A1.%20%5BSplunk%20Attack%20Analyzer%5D(https://splunkbase.splunk.com/app/6783)%0A2.%20%5BCisco%20Talos%20Intelligence%5D(https://splunkbase.splunk.com/app/7711)%0A3.%20%5BVirusTotal%20v3%5D(https://splunkbase.splunk.com/app/5865)%0A4.%20%20PhishTank%20(preconfigured)%0A5.%20%20%5BAlien%20Vault%5D(https://splunkbase.splunk.com/app/5878)", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "16fc04ea-4b88-4a0e-8f68-66ac2c216f8f", "create_time": 1764758755.6803753, "update_time": 1765479796.6279, "name": "Investigate file attachments", "order": 2, "tag": "87e971c5-924c-4eee-8a08-e84975c01812", "description": "Another%20common%20email%20attack%20vector%20is%20a%20malicious%20file%20attachment.%20Any%20file%20could%20be%20malicious,%20but%20most%20attacks%20involve%20executables,%20scripts,%20or%20documents.%20Investigate%20these%20files%20using%20either%20a%20whole%20copy%20of%20the%20file%20or%20the%20file%20hash.%20Query%20threat%20intelligence%20and%20reputation%20databases%20using%20the%20hash%20to%20see%20if%20the%20file%20has%20been%20seen%20before,%20to%20see%20if%20there%20is%20suspicious%20activity%20associated%20with%20the%20file,%20and%20to%20learn%20more%20about%20the%20file's%20behavior.%20Query%20for%20previous%20analyses%20or%20submit%20the%20file%20for%20examination%20in%20a%20dynamic%20or%20static%20tool%20to%20check%20for%20potentially%20malicious%20behaviors%20or%20properties.%20Actions%20used%20for%20this%20task%20might%20extract%20associated%20URLs,%20domain%20names,%20IP%20addresses,%20or%20secondary%20file%20hashes%20which%20can%20be%20explored%20further%20in%20other%20tasks.%0A%0A%0A", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "a259ee42-6bdf-4d0c-9b27-efae878c42c2", "create_time": 1764758755.6805224, "update_time": 1765479796.62813, "name": "Investigate%20email", "order": 3, "tag": "39af1503-2dae-40d0-8164-818a7232bf95", "description": "Analyze%20the%20full%20email%E2%80%94headers,%20subject,%20and%20body%E2%80%94using%20both%20automated%20and%20manual%20techniques%20to%20determine%20its%20origin%20and%20assess%20for%20malicious%20intent.%20Inspect%20header%20fields%20(e.g.,%20%E2%80%9CFrom,%E2%80%9D%20%E2%80%9CSender,%E2%80%9D%20%E2%80%9CReply-to%E2%80%9D)%20for%20inconsistencies,%20misleading%20display%20names,%20and%20suspicious%20infrastructure,%20validating%20authentication%20results%20such%20as%20SPF,%20DKIM,%20and%20DMARC.%20Enrich%20findings%20with%20threat%20intelligence%20and%20reputation%20sources,%20and%20use%20tools%20like%20Microsoft%20Message%20Header%20Analyzer%20or%20MxToolbox%20for%20deeper%20interpretation.%20Evaluate%20the%20content%20for%20social%20engineering%20indicators%E2%80%94such%20as%20urgency,%20context%20manipulation,%20or%20attempts%20to%20solicit%20confidential%20information%E2%80%94recognizing%20that%20these%20often%20require%20manual%20judgment%20and,%20when%20appropriate,%20direct%20confirmation%20from%20the%20recipient.%20Outputs%20such%20as%20domains%20and%20IPs%20should%20be%20forwarded%20for%20further%20analysis.%0A%0ASuggested%20Integrations%0A1.%20%20%5BEmail%20Search%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/email_search)", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": [{"id": "cf182fd6-c616-4adb-a8f6-b9969549c873", "create_time": 1764952188.108695, "update_time": 1765479796.6283174, "name": "Email - Query on Affected User", "description": "You need to have your email data being ingested into the Email data model. \n\nNOTE: in this search we have pulled the tokened field of \"src_user\" if you detection uses another output field you will need to update your search accordingly. ", "spl": "%7C%20tstats%20%60summariesonly%60%20max(_time)%20as%20_time%2C%20values(All_Email.action)%20as%20action%2C%20values(All_Email.message_id)%20as%20message_id%2C%20values(All_Email.subject)%20as%20subject%2C%20values(All_Email.size)%20as%20size%2C%20values(All_Email.protocol)%20as%20protocol%2C%20values(All_Email.recipient)%20as%20recipient%2C%20count%20from%20datamodel%3DEmail.All_Email%20by%20All_Email.src%2CAll_Email.src_user%2CAll_Email.dest%20%0A%7C%20%60drop_dm_object_name(%22All_Email%22)%60%20%0A%7C%20search%20recipient%20IN%20(%24src_user%24)%0A%7C%20sort%20-%20count%20%0A%7C%20normalizeip%20src%20dest%20%0A%7C%20fields%20_time%2C%20action%2C%20message_id%2C%20subject%2C%20size%2C%20protocol%2C%20src%2C%20src_user%2C%20dest%2C%20recipient%2C%20count"}]}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "987a5f9d-4fa2-4474-a923-10ee1fca36e9", "create_time": 1764758755.680672, "update_time": 1765479796.6285076, "name": "Investigate domains", "order": 4, "tag": "65ec0d02-4e41-4bef-ad64-bcbbe64589bf", "description": "At%20this%20point%20domain%20names%20from%20various%20sources%20should%20be%20collected%20in%20the%20notable,%20including%20email%20sending%20and%20receiving%20servers,%20web%20servers%20from%20URLs%20in%20the%20email,%20domains%20associated%20to%20other%20indicators%20in%20threat%20intelligence%20databases,%20and%20domains%20contained%20in%20the%20file%20attachment%20or%20detected%20by%20the%20detonation%20of%20the%20file%20attachment.%20Check%20each%20of%20these%20against%20threat%20intelligence%20and%20reputation%20databases,%20passive%20DNS%20trackers,%20whois%20services,%20and%20other%20information%20services.%20Look%20for%20known%20malicious%20or%20unknown%20domains,%20focusing%20more%20on%20those%20associated%20to%20clickable%20URLs%20and%20file%20attachments.%20Evaluate%20what%20services%20are%20running%20on%20each%20suspicious%20domain%20using%20a%20scanning%20service%20such%20as%20Censys%20or%20Shodan.%20Check%20the%20TLS%20certificate%20(if%20applicable),%20website%20categorization,%20popularity,%20and%20any%20other%20available%20information.%20Compare%20this%20information%20to%20the%20expected%20outcome%20given%20the%20alleged%20context%20of%20the%20email.%20For%20unknown%20domains,%20consider%20the%20domain%20history,%20the%20hosting%20provider,%20and%20whether%20the%20domain%20name%20appears%20to%20have%20been%20dynamically%20generated.%20IP%20addresses%20currently%20and%20previously%20associated%20with%20the%20domain%20should%20be%20further%20processed%20elsewhere%20in%20your%20investigation.%0A%0ASuggested%20Integrations%0A1.%20%5BSplunk%20Attack%20Analyzer%5D(https://splunkbase.splunk.com/app/6783)%0A2.%20%5BCisco%20Talos%20Intelligence%5D(https://splunkbase.splunk.com/app/7711)%0A3.%20%5BVirusTotal%20v3%5D(https://splunkbase.splunk.com/app/5865)%0A4.%20%5BAlien%20Vault%5D(https://splunkbase.splunk.com/app/5878)%0A5.%20%5BDomainTools%20Iris%20Investigate%5D(https://splunkbase.splunk.com/app/6010)%0A6.%20%5BCisco%20Umbrella%20Investigates%5D(https://splunkbase.splunk.com/app/5780)", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "c4f72802-ef36-47d2-a6c0-9d1ab5e0aa2c", "create_time": 1764758755.6808305, "update_time": 1765479796.6287827, "name": "Investigate IP addresses", "order": 5, "tag": "bd473b00-1dc1-4446-8ce2-36d7fc8ef468", "description": "IP%20addresses%20may%20be%20involved%20in%20this%20investigation%20for%20several%20reasons.%20Some%20email%20headers%20can%20contain%20IP%20addresses%20(such%20as%20X-Originating-IP),%20URLs%20can%20contain%20IP%20addresses%20instead%20of%20hostnames,%20file%20attachments%20can%20contain%20IP%20addresses%20or%20generate%20IP%20addresses%20and%20try%20to%20connect%20to%20them%20(like%20domain%20generation%20algorithms),%20and%20IP%20addresses%20can%20be%20added%20to%20the%20notable%20through%20association%20or%20domain%20name%20resolution%20in%20other%20tasks%20within%20this%20investigation.%20Consider%20IP%20addresses%20in%20URLs%20that%20are%20not%20internal%20IP%20addresses%20for%20the%20organization%20highly%20suspicious.%20Investigate%20all%20suspicious%20IP%20addresses%20by%20checking%20the%20reputation,%20geolocation,%20whois%20record,%20DNS%20history,%20and%20by%20gathering%20information%20from%20other%20available%20services.%0A%0ASuggested%20Integrations%0A1.%20%5BCisco%20Talos%20Intelligence%5D(https://splunkbase.splunk.com/app/7711)%0A2.%20%5BVirusTotal%20v3%5D(https://splunkbase.splunk.com/app/5865)%0A3.%20%5BAlien%20Vault%5D(https://splunkbase.splunk.com/app/5878)%0A4.%20Whois%20(preconfigured)%0A5.%20MaxMind%20(preconfigured)", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}]}, {"id": "d36a2713-63b9-4bfd-8a66-e50df079ace9", "create_time": 1765479748.8334155, "update_time": 1765479796.6299407, "name": "Internal Hunting", "order": 3, "tasks": [{"id": "4012859c-a956-4b21-ba9e-a2004dfeb036", "create_time": 1764758755.6812239, "update_time": 1765479796.6290972, "name": "Hunt email activity", "order": 1, "tag": "e7a6d9a6-8b9e-4f8c-afdb-475b0b3472b7", "description": "Find%20other%20similar%20emails%20sent%20into%20the%20organization%20based%20on%20the%20sender%20address,%20sender%20domain,%20subject,%20embedded%20URLs,%20file%20attachments,%20or%20other%20similar%20attributes%20shared%20across%20multiple%20emails.%20If%20possible%20determine%20which%20emails%20were%20opened,%20forwarded,%20deleted,%20marked%20as%20spam,%20or%20reported%20as%20potential%20phishing.%20Consider%20which%20types%20of%20users%20are%20targeted%20and%20why.%20Also%20check%20whether%20internal%20users%20replied%20to%20the%20emails%20and%20what%20information%20was%20contained%20in%20the%20replies.%0A%0ASuggested%20Integrations%0A1.%20%5BSplunk%20Attack%20Analyzer%5D(https://splunkbase.splunk.com/app/6783)%0A2.%20%20%5BCisco%20Secure%20Malware%20Analytics%20(Threat%20Grid)%5D(https://splunkbase.splunk.com/app/6145)%0A3.%20%5BEmail%20Search%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/email_search)", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "1701120f-ca73-42cf-87e1-5dcb228ab5a0", "create_time": 1764758755.681366, "update_time": 1765479796.629352, "name": "Hunt network activity", "order": 2, "tag": "427ba972-75bd-42eb-8218-4a522f98b947", "description": "Based%20on%20previously%20collected%20information,%20try%20to%20determine%20whether%20or%20not%20URLs%20in%20the%20email%20were%20clicked,%20phishing%20websites%20were%20visited,%20or%20other%20suspicious%20network%20connections%20were%20made%20from%20the%20computers%20of%20users%20who%20opened%20the%20email.%20This%20can%20be%20done%20using%20many%20types%20of%20network%20monitoring,%20including%20netflow,%20full%20packet%20capture,%20DNS%20logging,%20and/or%20endpoint%20monitoring.%0A%0ASuggested%20Integrations%0A1.%20%5BTraffic%20Center%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/traffic_center)%0A2.%20%5BTraffic%20Search%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/traffic_search)%0A3.%20%5BTraffic%20Size%20Analysis%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/traffic_size_analysis)%0A4.%20%5BPort%20and%20Protocol%20Tracker%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/port_protocol_tracker)%0A5.%20%5BNetwork%20Changes%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/network_changes)", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "24d8fa33-d658-4800-8113-5d7f7c90ad1d", "create_time": 1764758755.681554, "update_time": 1765479796.6295755, "name": "Hunt file executions", "order": 3, "tag": "ebe5a0e7-8705-4e69-b1e7-a21058c87822", "description": "If%20the%20email%20included%20a%20file%20attachment,%20try%20to%20determine%20which%20users%20downloaded%20the%20attachment%20and%20which%20users%20executed%20it%20or%20opened%20it%20in%20some%20other%20way.%20Use%20the%20file%20hash%20of%20the%20attachment%20to%20search%20across%20endpoint%20monitoring%20or%20network%20monitoring%20solutions%20for%20the%20transmission%20and/or%20execution%20of%20the%20file.%20If%20executions%20are%20detected,%20try%20to%20determine%20the%20behavior%20of%20the%20created%20process.%20If%20a%20potentially%20malicious%20document%20or%20other%20file%20type%20was%20opened,%20try%20to%20determine%20which%20application%20opened%20it%20and%20whether%20the%20file%20exploited%20or%20abused%20the%20opening%20application.%0A%0ASuggested%20Integrations%0A1.%20%5BEndpoint%20Changes%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/endpoint_changes)%0A2.%20%5BMalware%20Center%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/malware_center)%0A3.%20%5BMalware%20Search%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/malware_search)", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "24ad66ec-2b93-4677-b1c4-a6e2c2bd6207", "create_time": 1764758755.6817021, "update_time": 1765479796.6298037, "name": "Hunt user activity", "order": 4, "tag": "32798d9d-6440-4f39-98c7-6d4c30d26e1e", "description": "If%20a%20phishing%20attempt%20or%20other%20user%20account%20compromise%20attempt%20is%20suspected,%20investigate%20how%20the%20credentials%20or%20account%20access%20are%20being%20used.%20Enumerate%20resources%20available%20to%20the%20account%20and%20search%20the%20access%20logs%20for%20those%20resources,%20looking%20for%20anomalous%20usage%20patterns.%0A%0ASuggested%20Integrations%0A1.%20%5BRisk%20Analysis%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/risk_analysis)%0A2.%20%5BIdentity%20Investigator%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/identity_investigator)%0A3.%20%5BAsset%20and%20Risk%20Intelligence%5D(https://splunkbase.splunk.com/app/7180)", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}]}, {"id": "42eb2edf-fc7d-4327-8f3e-37ee80c2536c", "create_time": 1765479748.8340182, "update_time": 1765479796.6310995, "name": "Enforcement and increased monitoring", "order": 4, "tasks": [{"id": "2eb1f1a5-8f1a-45d8-8953-ba30d1a8a6e9", "create_time": 1764758755.6819034, "update_time": 1765479796.6300797, "name": "Block or monitor email activity", "order": 1, "tag": "6b567916-424d-41b3-836f-b4abfa555448", "description": "If%20specific%20malicious%20emails%20have%20been%20identified,%20delete%20them%20from%20any%20mailboxes%20in%20which%20they%20still%20pose%20a%20threat.%20Similarly,%20if%20a%20sender%20address%20or%20an%20entire%20sender%20domain%20is%20found%20to%20be%20malicious,%20block%20inbound%20email%20from%20that%20source.%20Set%20filtering%20rules%20to%20block%20inbound%20email%20or%20increase%20monitoring%20of%20email%20based%20on%20other%20detected%20characteristics%20of%20an%20email%20campaign%20or%20malicious%20technique.%0A%0ASuggested%20Intergrations%0A1.%20%5BMS%20Graph%20for%20Office%20365%5D(https://splunkbase.splunk.com/app/5824)%0A2.%20%5BG%20Suite%20for%20GMail%5D(https://splunkbase.splunk.com/app/5795)%0A3.%20%5BEmail%20Search%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/email_search)", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "f0d28b16-b4ba-46a9-8d20-c888d0d50137", "create_time": 1764758755.6820495, "update_time": 1765479796.6303134, "name": "Block or monitor network activity", "order": 2, "tag": "b537f91c-ce46-4a52-8894-0797dbc13b6b", "description": "Based%20on%20gathered%20indicators%20and%20metadata,%20block%20or%20increase%20monitoring%20of%20malicious%20network%20connections%20associated%20with%20the%20suspicious%20email.%20Prevent%20other%20receivers%20of%20similar%20phishing%20emails%20from%20accessing%20the%20clickable%20URL%20by%20blocking%20that%20URL%20itself,%20the%20underlying%20domain%20name,%20and/or%20the%20underlying%20IP%20addresses.%20If%20malware%20or%20unwanted%20software%20was%20detected,%20block%20outbound%20connections%20known%20to%20be%20associated%20with%20that%20malware%20based%20on%20threat%20intelligence%20or%20dynamic%20analysis.%20If%20the%20threat%20is%20severe%20enough,%20consider%20isolating%20entire%20portions%20of%20the%20network.%0A%0ASuggested%20Integrations%0A1.%20%20%5BCisco%20Firepower%5D(https://splunkbase.splunk.com/app/5995)%0A2.%20%5BCisco%20Secure%20Firewall%5D(https://splunkbase.splunk.com/app/7745)%0A3.%20%5B%20Palo%20Alto%5D(https://splunkbase.splunk.com/app/5830)%0A4.%20%5BZscaler%5D(https://splunkbase.splunk.com/app/5872)%0A5.%20%5BTraffic%20Center%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/traffic_center)", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "79abbff6-2d34-46b0-b570-c9788da8668a", "create_time": 1764758755.6822183, "update_time": 1765479796.6305444, "name": "Block or monitor file executions", "order": 3, "tag": "e7cb23b5-9baa-4a66-994d-43cd0f17d017", "description": "Based%20on%20gathered%20indicators%20and%20metadata,%20block%20or%20increase%20monitoring%20of%20endpoint%20activity%20caused%20by%20the%20suspicious%20email.%20This%20could%20mean%20blocking%20the%20hash%20of%20the%20file%20attachment,%20blocking%20the%20hash%20of%20a%20file%20downloaded%20from%20a%20URL%20in%20an%20email,%20blocking%20a%20malicious%20hash%20associated%20with%20the%20email%20by%20threat%20intelligence,%20or%20blocking%20secondary%20executions%20such%20as%20dropped%20stages%20of%20malware%20identified%20from%20dynamic%20analysis.%0A%0ASuggested%20Integrations%0A1.%20%20%5BCrowdstrike%5D(https://splunkbase.splunk.com/app/5786)%0A2.%20%5BMicrosoft%20Defender%20for%20Endpoint%5D(https://splunkbase.splunk.com/app/5870)%0A3.%20%5BVMware%20Carbon%20Black%20Cloud%20for%20Splunk%20SOAR%5D(https://splunkbase.splunk.com/app/6732)", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "fa4ad6aa-7fc1-4897-9588-e2366ce2cc8e", "create_time": 1764758755.6823559, "update_time": 1765479796.6307607, "name": "Contain endpoints", "order": 4, "tag": "746ae480-2639-4ffe-80ce-698238ec5721", "description": "If%20an%20endpoint%20compromise%20is%20suspected,%20it%20might%20be%20necessary%20to%20quarantine%20or%20otherwise%20contain%20that%20endpoint%20until%20further%20investigation%20and%20remediation%20can%20be%20done.%20Consider%20the%20criticality%20of%20the%20system%20and%20the%20likelihood%20of%20a%20compromise.%20In%20other%20cases,%20simply%20increasing%20the%20monitoring%20or%20scanning%20for%20more%20information%20can%20be%20prudent.%0A%0ASuggested%20Integrations%0A1.%20%20%5BCrowdstrike%5D(https://splunkbase.splunk.com/app/5786)%0A2.%20%5BMicrosoft%20Defender%20for%20Endpoint%5D(https://splunkbase.splunk.com/app/5870)%0A3.%20%5BVMware%20Carbon%20Black%20Cloud%20for%20Splunk%20SOAR%5D(https://splunkbase.splunk.com/app/6732)", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "8ffee892-3e52-4aed-ba5f-30554d3de579", "create_time": 1764758755.6824956, "update_time": 1765479796.6309698, "name": "Contain user accounts", "order": 5, "tag": "702244fa-e9c6-42d7-846a-697fb74ea060", "description": "If%20a%20user%20account%20compromise%20is%20suspected,%20it%20might%20be%20necessary%20to%20reset%20the%20credentials,%20reduce%20the%20account%20privileges,%20or%20disable%20the%20account%20until%20further%20investigation%20is%20completed.%0A%0ASuggested%20Integrations%0A1.%20%5BMS%20Graph%20For%20Active%20Directory%5D(https://splunkbase.splunk.com/app/6395)%0A2.%20%5BAD%20LDAP%5D(https://splunkbase.splunk.com/app/5755)%0A3.%20%5BOkta%5D(https://splunkbase.splunk.com/app/5921)%0A4.%20%5BAWS%20IAM%5D(https://splunkbase.splunk.com/app/5763)%0A5.%20%5BAzure%20AD%20Graph%5D(https://splunkbase.splunk.com/app/5771)", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}]}, {"id": "f3f3a7c8-dcb4-4565-8827-356c60cac5f6", "create_time": 1765479748.8343027, "update_time": 1765479796.6315908, "name": "Longer-running analysis jobs", "order": 5, "tasks": [{"id": "09b37ed6-4b6e-4fe0-a4c5-561480ed7c10", "create_time": 1764758755.68271, "update_time": 1765479796.631251, "name": "Analyze network activity", "order": 1, "tag": "9cf69134-6b81-45ca-ada8-fd4136a1912f", "description": "Perform%20any%20resource-intensive%20analysis%20of%20network%20activity%20left%20over%20from%20the%20External%20Investigation%20and%20Internal%20Hunting%20phases.%20This%20might%20mean%20full%20packet%20capture%20collection%20and%20analysis,%20sandbox%20detonation%20of%20URLs,%20long-running%20queries%20of%20network%20history%20and%20anomalous%20behavior,%20or%20other%20similar%20analysis%20tasks.%0A%0ASuggested%20Integrations%0A1.%20%5BTraffic%20Center%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/traffic_center)%0A2.%20%5BTraffic%20Search%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/traffic_search)%0A3.%20%5BTraffic%20Size%20Analysis%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/traffic_size_analysis)%0A4.%20%5BPort%20and%20Protocol%20Tracker%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/port_protocol_tracker)", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "627cb8cc-b780-437e-951d-8ec9c64062e7", "create_time": 1764758755.682851, "update_time": 1765479796.631454, "name": "Analyze endpoint activity", "order": 2, "tag": "2497b494-b80f-417b-b51d-f4c8d7aff019", "description": "Conduct%20deeper%20analysis%20on%20remaining%20malware%20and%20endpoint%20investigation%20tasks%20not%20finished%20in%20the%20External%20Investigation%20and%20Internal%20Hunting%20phases.%20This%20might%20mean%20sandbox%20detonation%20of%20files,%20forensic%20analysis%20of%20associated%20devices%20or%20memory%20dumps,%20reverse%20engineering%20of%20suspected%20malware,%20long-running%20queries%20of%20endpoint%20activity%20history%20and%20anomalous%20behavior,%20or%20other%20similar%20analysis%20tasks.%0A%0ASuggested%20Integrations%0A1.%20%5BEndpoint%20Changes%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/endpoint_changes)%0A2.%20%5BMalware%20Center%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/malware_center)%0A3.%20%5BMalware%20Search%20%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/malware_search)%0A4.%20%5BAsset%20and%20Risk%20Intelligence%5D(https://splunkbase.splunk.com/app/7180)", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}]}, {"id": "934b1327-2484-49e2-9701-36a33a1462f9", "create_time": 1765479748.8349223, "update_time": 1765479796.6327975, "name": "Notification", "order": 6, "tasks": [{"id": "3b692da7-b9dc-491b-add5-2c674251a7be", "create_time": 1764758755.683051, "update_time": 1765479796.6317682, "name": "Update tickets", "order": 1, "tag": "dad41274-fb84-4b6f-bed9-fb43be506987", "description": "Make%20sure%20that%20all%20the%20necessary%20outputs%20and%20status%20updates%20from%20the%20previous%20phases%20and%20tasks%20are%20documented%20in%20the%20appropriate%20system%20of%20record.%20Summarize%20the%20current%20state%20of%20the%20investigation%20and%20any%20remaining%20tasks.%0A%0A%5BSuggested%20Integrations%5D(https://splunkbase.splunk.com/apps?page=1&product=soar&categories=ticketing)", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "644d1cc6-f855-4dfb-ae28-a0a58fbee6d2", "create_time": 1764758755.6832078, "update_time": 1765479796.631959, "name": "Notify system owners", "order": 2, "tag": "824481e3-9dc5-4668-9abd-585d1cd331ca", "description": "For%20any%20systems%20that%20have%20been%20changed%20or%20need%20to%20be%20changed,%20notify%20the%20necessary%20system%20owners%20so%20the%20appropriate%20change%20management%20procedures%20can%20be%20followed.%0A%0ASuggested%20Integrations%0A1.%20SMTP%20(preconfigured)%0A2.%20%5BMS%20Graph%20for%20Office%20365%5D(https://splunkbase.splunk.com/app/5824)%0A3.%20%5BG%20Suite%20for%20GMail%5D(https://splunkbase.splunk.com/app/5795)%0A4.%20%5BCisco%20Webex%5D(https://splunkbase.splunk.com/app/5781)%0A5.%20%5BSlack%5D(https://splunkbase.splunk.com/app/5846)%0A6.%20%5BMicrosoft%20Teams%5D(https://splunkbase.splunk.com/app/5818)", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "81905435-dd7e-493d-babf-fc5f108cbb9a", "create_time": 1764758755.6833851, "update_time": 1765479796.6321607, "name": "Notify regulatory compliance team", "order": 3, "tag": "c7f7005c-6b51-49a7-a3f9-f22aaf9dfbe4", "description": "If%20appropriate,%20notify%20the%20regulatory%20compliance%20team%20to%20support%20them%20as%20they%20report%20this%20incident%20to%20the%20correct%20regulatory%20or%20accrediting%20organizations.%0A%0ASuggested%20Integrations%0A1.%20SMTP%20(preconfigured)%0A2.%20%5BMS%20Graph%20for%20Office%20365%5D(https://splunkbase.splunk.com/app/5824)%0A3.%20%5BG%20Suite%20for%20GMail%5D(https://splunkbase.splunk.com/app/5795)%0A4.%20%5BCisco%20Webex%5D(https://splunkbase.splunk.com/app/5781)%0A5.%20%5BSlack%5D(https://splunkbase.splunk.com/app/5846)%0A6.%20%5BMicrosoft%20Teams%5D(https://splunkbase.splunk.com/app/5818)", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "a4260d25-53f9-45c4-b984-4c10deddbb82", "create_time": 1764758755.6836178, "update_time": 1765479796.6323862, "name": "Assign additional tasks", "order": 4, "tag": "29d21b34-5221-4dee-9bff-276a8241b2bd", "description": "Create tickets to track any follow-on tasks that came out of this investigation. Example tasks might include conducting deeper endpoint investigation, re-provisioning systems, re-enabling accounts, or tuning filtering systems to block future emails.", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "d0cf948f-2ba6-4a7d-82c9-851aacfa80a6", "create_time": 1764758755.6839995, "update_time": 1765479796.6325488, "name": "Educate users", "order": 5, "tag": "7ee89bfe-e39d-42c9-baa0-2e74b39adcd1", "description": "If appropriate, inform the broader user base about the types of suspicious emails being sent to the organization to try to prevent them from clicking malicious links or opening malicious file attachments in the future.", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "5b78276c-3dff-4546-8ff4-78cd4e1b04d3", "create_time": 1764758755.6842132, "update_time": 1765479796.6327078, "name": "Share threat intelligence", "order": 6, "tag": "3773742e-ecd3-4588-a0ae-6ac80e6b70ce", "description": "If appropriate, communicate relevant findings to trusted third parties and/or the public threat intelligence community. Make sure that outbound messages do not contain confidential information. Consider sharing or confirming the usage of indicators and techniques to peer organizations, security vendors, public databases, or industry-specific threat intelligence sharing communities.", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}]}], "template_id": "84c951b5-a7f7-439d-9e59-b8031190be63", "active": true, "used": true, "_user": "nobody", "_key": "a72d40f3-a567-48e2-9fd3-c29db06c3907"}