Files
kbouchard fc1596e371 had to remove 8.5 from the name of response plans
had to remove 8.5 from the name of response plans
2026-04-01 20:55:54 -07:00

1 line
58 KiB
JSON

{"id": "8fc25dd2-407f-4841-ab2a-00b669765a92", "create_time": 1774461020.802911, "update_time": 1774464670.3884838, "name": "Suspicious Email", "description": "There are many ways in which attackers can use email to gain a foothold in an organization or advance an existing campaign. This response template guides an analyst through the process of investigating and remediating several of these methods. The main objective of the first three phases is to determine if the email is malicious and what impact it might have if the attack is successful. The fourth and fifth phases focus on taking action to prevent further harm to the organization and conducting more investigation and analysis to learn more about the threat. Finally, the sixth phase describes communications to other parts of the organization which may be appropriate based on what was observed in the first five phases. This response template uses the structure of the SOEL framework (https://www.sans.org/cyber-security-summit/archives/file/summit-archive-1532986430.pdf) to organize the phases and tasks.", "template_status": "published", "creator": "splunker", "updated_by": "splunker", "is_default": false, "version": 3, "phases": [{"id": "7eddb898-085a-43fa-a03b-3ded48d53093", "create_time": 1774464670.33876, "update_time": 1774464670.3387606, "name": "Ingestion", "order": 1, "tasks": [{"id": "de8fa91f-bfad-41e6-bfe5-e3a2732db2c2", "create_time": 1764758755.6795278, "update_time": 1774464670.3380775, "name": "Create ticket", "order": 1, "tag": "3d75cc89-a55b-4680-931c-7a5e091baaf6", "description": "Create%20any%20necessary%20tickets%20or%20tracking%20documents%20describing%20the%20initial%20conditions%20of%20the%20suspicious%20email%20investigation.%20As%20additional%20information%20is%20collected%20or%20actions%20are%20taken%20in%20the%20following%20tasks%20and%20phases,%20update%20the%20ticket%20with%20links%20and%20relevant%20information%20to%20allow%20collaboration%20and%20tracking.%0A%0A%0A", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "163d3490-d8de-4df9-8900-f5a2554b8024", "create_time": 1764758755.6797986, "update_time": 1774464670.338298, "name": "Ingest email", "order": 2, "tag": "b4f73c35-e4af-40bf-a349-bed4c51cb0fc", "description": "Identify%20and%20ingest%20the%20suspicious%20email%20into%20Splunk%20Mission%20Control.%20Actual%20steps%20vary%20depending%20on%20how%20you%20create%20the%20Splunk%20Mission%20Control%20notable%20and%20where%20the%20suspicious%20email%20resides.%20For%20example,%20if%20you%20had%20a%20Splunk%20Enterprise%20Security%20correlation%20search%20running%20to%20identify%20suspicious%20emails,%20and%20forward%20those%20notable%20events%20to%20Splunk%20Mission%20Control%20as%20notables,%20you%20have%20many%20of%20the%20useful%20artifacts%20needed%20to%20investigate%20the%20email.%20If%20you%20need%20additional%20metadata,%20you%20can%20run%20the%20%22get%20email%22%20action%20to%20retrieve%20it,%20or%20the%20%22extract%20email%22%20action%20to%20add%20the%20email%20to%20Splunk%20Mission%20Control%20if%20it%20is%20in%20the%20.msg%20or%20.eml%20format.%20Or%20for%20example,%20if%20you%20send%20suspicious%20emails%20to%20a%20dedicated%20email%20address%20for%20suspected%20phishing%20attempts,%20you%20can%20use%20a%20connector%20such%20as%20IMAP,%20EWS%20for%20Exchange,%20EWS%20for%20OFfice,%20or%20GSuite%20for%20GMail%20to%20poll%20that%20inbox%20directly%20and%20send%20the%20suspicious%20email%20to%20Splunk%20Mission%20Control%20as%20a%20notable.%0A%0ASuggested%20Integration%20(%20if%20not%20already%20configured%20navigate%20%5BHERE%5D(/app/SplunkEnterpriseSecuritySuite/ess_configuration/#/soar/soar_apps/apps)%20to%20locate%20and%20configure)%0A1.%20%20Splunk%20Attack%20Analyzer%0A2.%20Cisco%20Secure%20Email%20and%20Web%20Manager%0A%0A", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [{"id": "950a92b7-9730-46cd-96fc-2bc39b277697", "create_time": 1774461267.1722639, "update_time": 1774464670.3384364, "last_job_id": 0, "name": "detonate file - Splunk Attack Analyzer Connector for Splunk SOAR", "action": "8939", "description": "Submit File for Scanning", "type": "detonate file", "app_id": 283, "asset": 23, "parameters": [{"file": "", "ph_0": "", "profile": "", "user_agent": "", "internet_region": "", "archive_password": "", "custom_user_agent": ""}]}, {"id": "200707a2-fcd6-4ff8-be34-1f86184c2eef", "create_time": 1774461267.1723077, "update_time": 1774464670.3385012, "last_job_id": 0, "name": "delete quarantine message - Cisco Secure Email and Web Manager", "action": "9301", "description": "Delete a message from Policy, Virus, Outbreak, or other quarantines", "type": "delete quarantine message", "app_id": 58, "asset": 46, "parameters": [{"message_id": "", "quarantine_name": ""}]}], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "a6d6d47d-3c94-42ea-b575-c197be210f97", "create_time": 1764758755.6799636, "update_time": 1774464670.3386793, "name": "Extract actionable metadata and files", "order": 3, "tag": "0c5acee1-e985-43ec-aefa-9355f46fef2d", "description": "Depending on how the email was ingested, additional steps might be required to extract actionable metadata and files. For example, if the suspicious email is attached to the Splunk Mission Control notable as a file, run the \"extract ioc\" action to extract URLs, domain names, IP addresses, file hashes, and whole file attachments as artifacts. In some cases, you might need to write specific playbooks or ingestion scripts to extract or reformat fields from the email. Be aware that malicious emails can obfuscate links and file attachments, so it might be necessary to view the email in a sandboxed email client to see it in the same context as a user would see it.", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}]}, {"id": "9510afc9-a689-434d-8622-e7dbcf607e54", "create_time": 1774464670.3412151, "update_time": 1774464670.3412154, "name": "External Investigation", "order": 2, "tasks": [{"id": "2bedd439-1521-4bc1-aa32-f6502bc3b4eb", "create_time": 1764758755.6802204, "update_time": 1774464670.338899, "name": "Investigate URLs", "order": 1, "tag": "5c7e7c30-139a-45e5-9622-63c788fe10a3", "description": "Perhaps%20the%20most%20common%20email%20attack%20vector%20is%20a%20clickable%20link%20that%20brings%20a%20user%20to%20a%20malicious%20website.%20The%20malicious%20website%20might%20collect%20credentials%20or%20other%20confidential%20information,%20attempt%20to%20exploit%20the%20user's%20browser,%20lead%20the%20user%20to%20download%20a%20malicious%20file,%20or%20gather%20preliminary%20fingerprint%20information%20about%20the%20user%20to%20inform%20further%20operations.%20Investigate%20all%20URLs%20contained%20in%20the%20suspicious%20email%20using%20a%20mix%20of%20automated%20and%20manual%20techniques.%20Query%20threat%20intelligence%20services%20and%20other%20sources%20of%20reputation%20information%20to%20see%20if%20the%20URLs%20are%20linked%20to%20known%20malicious%20activity.%20Check%20the%20categorization%20of%20the%20URLs%20and%20their%20popularity%20using%20services%20such%20as%20Censys%20or%20Alexa.%20Determine%20whether%20the%20URL%20is%20spoofing%20a%20brand%20using%20a%20similar%20spelling,%20a%20unicode%20substitution,%20or%20an%20out-of-order%20domain%20name.%20Also%20consider%20using%20a%20less%20passive%20technique%20that%20analyzes%20the%20current%20state%20of%20the%20URL,%20such%20as%20a%20sandboxed%20URL%20detonation,%20a%20website%20scanning%20tool%20such%20as%20urlscan.io%20or%20SSL%20Labs,%20a%20manual%20inspection%20from%20a%20sandboxed%20environment,%20or%20a%20website%20screenshot%20engine%20such%20as%20Screenshot%20Machine.%20Consider%20that%20targeted%20attacks%20might%20only%20reveal%20the%20malicious%20behavior%20of%20a%20website%20if%20the%20user%20agent%20and/or%20the%20source%20address%20of%20the%20request%20matches%20the%20target%20environment.%20The%20output%20of%20this%20task%20might%20be%20more%20linked%20URLs,%20the%20domain%20names%20of%20the%20underlying%20servers%20responding%20to%20the%20request,%20other%20domain%20names%20used%20by%20the%20website,%20IP%20addresses,%20or%20downloadable%20files.%20All%20of%20the%20above%20should%20be%20passed%20on%20to%20further%20investigative%20tasks%20if%20needed.%0A%0ASuggested%20Dashboards%0A1.%20%5BWeb%20Center%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/web_center)%0A2.%20%5BTraffic%20Center%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/traffic_center)%0A%0ASuggested%20Integration%20(%20if%20not%20already%20configured%20navigate%20%5BHERE%5D(/app/SplunkEnterpriseSecuritySuite/ess_configuration/#/soar/soar_apps/apps)%20to%20locate%20and%20configure)%0A1.%20%20Splunk%20Attack%20Analyzer%0A2.%20Cisco%20Talos%20Intelligence%0A3.%20VirusTotal%20v3%0A4.%20%20PhishTank%0A5.%20%20Alien%20Vault%0A6.%20Recorded%20Future%20for%20Splunk%20SOAR%0A7.%20Crowdstrike", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [{"id": "8df06487-1d05-46a6-932a-44c2e97331ea", "create_time": 1774461597.2544773, "update_time": 1774464670.339028, "last_job_id": 0, "name": "detonate url - Splunk Attack Analyzer Connector for Splunk SOAR", "action": "8940", "description": "Submit New URL for Scanning", "type": "detonate url", "app_id": 283, "asset": 23, "parameters": [{"url": "", "ph_0": "", "profile": "", "user_agent": "", "internet_region": "", "archive_password": "", "custom_user_agent": ""}]}, {"id": "47567dff-ffcc-4297-9d18-5dd0136b0ece", "create_time": 1774461597.254519, "update_time": 1774464670.3390915, "last_job_id": 0, "name": "detonate url - VirusTotal v3", "action": "9004", "description": "Load a URL to Virus Total and retrieve analysis results", "type": "detonate url", "app_id": 323, "asset": 28, "parameters": [{"url": "", "wait_time": ""}]}, {"id": "5b1449a7-f0a2-4553-b251-8e9de0c6786c", "create_time": 1774461597.2545595, "update_time": 1774464670.339156, "last_job_id": 0, "name": "detonate url - CrowdStrike OAuth API", "action": "8806", "description": "Upload an url to CrowdStrike and retrieve the analysis results", "type": "detonate url", "app_id": 77, "asset": 44, "parameters": [{"url": "", "sort": "", "limit": "", "offset": "", "user_tags": "", "enable_tor": false, "environment": "", "command_line": "", "action_script": "", "detail_report": false, "document_password": ""}]}, {"id": "ac5da22b-29f3-4c97-8924-73551ffd742c", "create_time": 1774461597.2545986, "update_time": 1774464670.3392186, "last_job_id": 0, "name": "url reputation - Cisco Talos Intelligence", "action": "7851", "description": "Query URL info", "type": "url reputation", "app_id": 61, "asset": 11, "parameters": [{"url": ""}]}, {"id": "d3fd8e4e-6e69-4477-a11d-3d1e6653643e", "create_time": 1774461597.2546387, "update_time": 1774464670.339284, "last_job_id": 0, "name": "url reputation - VirusTotal v3", "action": "9003", "description": "Queries VirusTotal for URL info (run this action after running detonate url)", "type": "url reputation", "app_id": 323, "asset": 28, "parameters": [{"url": ""}]}, {"id": "0c46415a-579b-4b9d-afc3-46f714289fe1", "create_time": 1774461597.2546794, "update_time": 1774464670.3393438, "last_job_id": 0, "name": "url reputation - CrowdStrike OAuth API", "action": "8803", "description": "Queries CrowdStrike for the url info", "type": "url reputation", "app_id": 77, "asset": 44, "parameters": [{"url": "", "sort": "", "limit": "", "offset": "", "detail_report": false}]}, {"id": "422ede77-85a1-44da-b15b-9fd881b3b627", "create_time": 1774461597.2547185, "update_time": 1774464670.3394055, "last_job_id": 0, "name": "url reputation - Recorded Future For Splunk SOAR", "action": "4267", "description": "Get a quick indicator of the risk associated with a URL", "type": "url reputation", "app_id": 247, "asset": 19, "parameters": [{"url": ""}]}, {"id": "2526463f-1823-4f88-82d8-a7dfd5bf8961", "create_time": 1774461597.254758, "update_time": 1774464670.339467, "last_job_id": 0, "name": "url reputation - AlienVault OTX", "action": "9314", "description": "Queries for URL reputation information", "type": "url reputation", "app_id": 24, "asset": 47, "parameters": [{"url": "", "response_type": ""}]}], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "16fc04ea-4b88-4a0e-8f68-66ac2c216f8f", "create_time": 1764758755.6803753, "update_time": 1774464670.3397064, "name": "Investigate file attachments", "order": 2, "tag": "87e971c5-924c-4eee-8a08-e84975c01812", "description": "Another%20common%20email%20attack%20vector%20is%20a%20malicious%20file%20attachment.%20Any%20file%20could%20be%20malicious,%20but%20most%20attacks%20involve%20executables,%20scripts,%20or%20documents.%20Investigate%20these%20files%20using%20either%20a%20whole%20copy%20of%20the%20file%20or%20the%20file%20hash.%20Query%20threat%20intelligence%20and%20reputation%20databases%20using%20the%20hash%20to%20see%20if%20the%20file%20has%20been%20seen%20before,%20to%20see%20if%20there%20is%20suspicious%20activity%20associated%20with%20the%20file,%20and%20to%20learn%20more%20about%20the%20file's%20behavior.%20Query%20for%20previous%20analyses%20or%20submit%20the%20file%20for%20examination%20in%20a%20dynamic%20or%20static%20tool%20to%20check%20for%20potentially%20malicious%20behaviors%20or%20properties.%20Actions%20used%20for%20this%20task%20might%20extract%20associated%20URLs,%20domain%20names,%20IP%20addresses,%20or%20secondary%20file%20hashes%20which%20can%20be%20explored%20further%20in%20other%20tasks.%0A%0ASuggested%20Integration%20(%20if%20not%20already%20configured%20navigate%20%5BHERE%5D(/app/SplunkEnterpriseSecuritySuite/ess_configuration/#/soar/soar_apps/apps)%20to%20locate%20and%20configure)%0A1.%20%20Splunk%20Attack%20Analyzer%0A2.%20Cisco%20Talos%20Intelligence%0A3.%20VirusTotal%20v3%0A4.%20%20Alien%20Vault%0A5.%20Recorded%20Future%20for%20Splunk%20SOAR%0A6.%20Crowdstrike%0A", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [{"id": "ec69daa6-b0cf-4981-8cd9-1c61a030f5c2", "create_time": 1774461872.1304905, "update_time": 1774464670.33986, "last_job_id": 0, "name": "detonate file - CrowdStrike OAuth API", "action": "8805", "description": "Upload a file to CrowdStrike and retrieve the analysis results", "type": "detonate file", "app_id": 77, "asset": 44, "parameters": [{"sort": "", "limit": "", "offset": "", "comment": "", "vault_id": "", "user_tags": "", "enable_tor": false, "environment": "", "submit_name": "", "command_line": "", "action_script": "", "detail_report": false, "is_confidential": false, "document_password": ""}]}, {"id": "ae2ae215-8d77-4d81-b73a-45b47e8fc160", "create_time": 1774461872.1305325, "update_time": 1774464670.3399234, "last_job_id": 0, "name": "detonate file - VirusTotal v3", "action": "9005", "description": "Upload a file to Virus Total and retrieve the analysis results", "type": "detonate file", "app_id": 323, "asset": 28, "parameters": [{"vault_id": "", "wait_time": ""}]}, {"id": "a66d6b46-3426-4285-b446-a2671a6894e3", "create_time": 1774461872.1305726, "update_time": 1774464670.339988, "last_job_id": 0, "name": "detonate file - Threat Grid", "action": "8950", "description": "Run the file in the Threat Grid sandbox and retrieve the analysis results", "type": "detonate file", "app_id": 60, "asset": 24, "parameters": [{"vm": "", "tags": "", "private": false, "playbook": "", "vault_id": "", "file_name": "", "vm_runtime": "", "force_analysis": false, "sample_password": ""}]}, {"id": "4e003ee8-8990-493b-9efb-6a7425b9d6eb", "create_time": 1774461872.1306121, "update_time": 1774464670.3400507, "last_job_id": 0, "name": "detonate file - Splunk Attack Analyzer Connector for Splunk SOAR", "action": "8939", "description": "Submit File for Scanning", "type": "detonate file", "app_id": 283, "asset": 23, "parameters": [{"file": "", "ph_0": "", "profile": "", "user_agent": "", "internet_region": "", "archive_password": "", "custom_user_agent": ""}]}, {"id": "99544533-1fb9-45de-bd7b-483d3dd9cc23", "create_time": 1774461872.130652, "update_time": 1774464670.3401008, "last_job_id": 0, "name": "file reputation - CrowdStrike OAuth API", "action": "8802", "description": "Queries CrowdStrike for the file info given a vault ID or a SHA256 hash, vault ID has higher priority than SHA256 hash if both are provided", "type": "file reputation", "app_id": 77, "asset": 44, "parameters": [{"sort": "", "limit": "", "offset": "", "sha256": "", "vault_id": "", "detail_report": false}]}, {"id": "9819cd0a-2ee1-4aea-9485-1789ec0074ea", "create_time": 1774461872.1306915, "update_time": 1774464670.3401353, "last_job_id": 0, "name": "file reputation - VirusTotal v3", "action": "9000", "description": "Queries VirusTotal for file reputation info", "type": "file reputation", "app_id": 323, "asset": 28, "parameters": [{"hash": ""}]}, {"id": "d31bb481-9e4d-42ad-b0d6-6f1e4f86b0f5", "create_time": 1774461872.1307437, "update_time": 1774464670.3401687, "last_job_id": 0, "name": "file reputation - Recorded Future For Splunk SOAR", "action": "4271", "description": "Get a quick indicator of the risk associated with a file identified by its hash", "type": "file reputation", "app_id": 247, "asset": 19, "parameters": [{"hash": ""}]}, {"id": "24d974c2-3b09-427b-9eb1-86056437e651", "create_time": 1774461872.1307988, "update_time": 1774464670.3402026, "last_job_id": 0, "name": "file reputation - AlienVault OTX", "action": "9313", "description": "Queries for file reputation information", "type": "file reputation", "app_id": 24, "asset": 47, "parameters": [{"hash": "", "response_type": ""}]}], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "a259ee42-6bdf-4d0c-9b27-efae878c42c2", "create_time": 1764758755.6805224, "update_time": 1774464670.3402948, "name": "Investigate%20email", "order": 3, "tag": "39af1503-2dae-40d0-8164-818a7232bf95", "description": "Analyze%20the%20full%20email%E2%80%94headers,%20subject,%20and%20body%E2%80%94using%20both%20automated%20and%20manual%20techniques%20to%20determine%20its%20origin%20and%20assess%20for%20malicious%20intent.%20Inspect%20header%20fields%20(e.g.,%20%E2%80%9CFrom,%E2%80%9D%20%E2%80%9CSender,%E2%80%9D%20%E2%80%9CReply-to%E2%80%9D)%20for%20inconsistencies,%20misleading%20display%20names,%20and%20suspicious%20infrastructure,%20validating%20authentication%20results%20such%20as%20SPF,%20DKIM,%20and%20DMARC.%20Enrich%20findings%20with%20threat%20intelligence%20and%20reputation%20sources,%20and%20use%20tools%20like%20Microsoft%20Message%20Header%20Analyzer%20or%20MxToolbox%20for%20deeper%20interpretation.%20Evaluate%20the%20content%20for%20social%20engineering%20indicators%E2%80%94such%20as%20urgency,%20context%20manipulation,%20or%20attempts%20to%20solicit%20confidential%20information%E2%80%94recognizing%20that%20these%20often%20require%20manual%20judgment%20and,%20when%20appropriate,%20direct%20confirmation%20from%20the%20recipient.%20Outputs%20such%20as%20domains%20and%20IPs%20should%20be%20forwarded%20for%20further%20analysis.%0A%0ASuggested%20Dashboards%0A1.%20%20%5BEmail%20Search%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/email_search)%0A2.%20%20%5BEmail%20Activity%5D(/app/SplunkEnterpriseSecuritySuite/email_activity)", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": [{"id": "cf182fd6-c616-4adb-a8f6-b9969549c873", "create_time": 1764952188.108695, "update_time": 1774464670.340368, "name": "Email - Query on Affected User", "description": "You need to have your email data being ingested into the Email data model. \n\nNOTE: in this search we have pulled the tokened field of \"src_user\" if you detection uses another output field you will need to update your search accordingly. ", "spl": "%7C%20tstats%20%60summariesonly%60%20max(_time)%20as%20_time%2C%20values(All_Email.action)%20as%20action%2C%20values(All_Email.message_id)%20as%20message_id%2C%20values(All_Email.subject)%20as%20subject%2C%20values(All_Email.size)%20as%20size%2C%20values(All_Email.protocol)%20as%20protocol%2C%20values(All_Email.recipient)%20as%20recipient%2C%20count%20from%20datamodel%3DEmail.All_Email%20by%20All_Email.src%2CAll_Email.src_user%2CAll_Email.dest%20%0A%7C%20%60drop_dm_object_name(%22All_Email%22)%60%20%0A%7C%20search%20recipient%20IN%20(%24src_user%24)%0A%7C%20sort%20-%20count%20%0A%7C%20normalizeip%20src%20dest%20%0A%7C%20fields%20_time%2C%20action%2C%20message_id%2C%20subject%2C%20size%2C%20protocol%2C%20src%2C%20src_user%2C%20dest%2C%20recipient%2C%20count"}]}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "987a5f9d-4fa2-4474-a923-10ee1fca36e9", "create_time": 1764758755.680672, "update_time": 1774464670.3404598, "name": "Investigate domains", "order": 4, "tag": "65ec0d02-4e41-4bef-ad64-bcbbe64589bf", "description": "At%20this%20point%20domain%20names%20from%20various%20sources%20should%20be%20collected%20in%20the%20notable,%20including%20email%20sending%20and%20receiving%20servers,%20web%20servers%20from%20URLs%20in%20the%20email,%20domains%20associated%20to%20other%20indicators%20in%20threat%20intelligence%20databases,%20and%20domains%20contained%20in%20the%20file%20attachment%20or%20detected%20by%20the%20detonation%20of%20the%20file%20attachment.%20Check%20each%20of%20these%20against%20threat%20intelligence%20and%20reputation%20databases,%20passive%20DNS%20trackers,%20whois%20services,%20and%20other%20information%20services.%20Look%20for%20known%20malicious%20or%20unknown%20domains,%20focusing%20more%20on%20those%20associated%20to%20clickable%20URLs%20and%20file%20attachments.%20Evaluate%20what%20services%20are%20running%20on%20each%20suspicious%20domain%20using%20a%20scanning%20service%20such%20as%20Censys%20or%20Shodan.%20Check%20the%20TLS%20certificate%20(if%20applicable),%20website%20categorization,%20popularity,%20and%20any%20other%20available%20information.%20Compare%20this%20information%20to%20the%20expected%20outcome%20given%20the%20alleged%20context%20of%20the%20email.%20For%20unknown%20domains,%20consider%20the%20domain%20history,%20the%20hosting%20provider,%20and%20whether%20the%20domain%20name%20appears%20to%20have%20been%20dynamically%20generated.%20IP%20addresses%20currently%20and%20previously%20associated%20with%20the%20domain%20should%20be%20further%20processed%20elsewhere%20in%20your%20investigation.%0A%0ASuggested%20Integrations%0A1.%20Lookup%20Domain%0A2.%20Recorded%20Future%20for%20Splunk%20SOAR%0A3.%20Cisco%20Talos%20Intelligence%20%0A4.%20Virustotal%20V3%0A5.%20AlienVault%0A6.%20Whois", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [{"id": "dee429cb-11e6-48d8-bd7c-df1692b8c8e1", "create_time": 1774463124.0442307, "update_time": 1774464670.34053, "last_job_id": 0, "name": "domain intelligence - Recorded Future For Splunk SOAR", "action": "4272", "description": "Get threat intelligence for a domain", "type": "domain intelligence", "app_id": 247, "asset": 19, "parameters": [{"domain": ""}]}, {"id": "bad49f19-f530-474e-bfb4-20bc80b72c72", "create_time": 1774463124.0442715, "update_time": 1774464670.3405638, "last_job_id": 0, "name": "domain reputation - Cisco Talos Intelligence", "action": "7850", "description": "Query domain info", "type": "domain reputation", "app_id": 61, "asset": 11, "parameters": [{"domain": ""}]}, {"id": "6e88bc3f-008d-4a18-974c-1ed4ae76de14", "create_time": 1774463124.0443115, "update_time": 1774464670.3405974, "last_job_id": 0, "name": "domain reputation - VirusTotal v3", "action": "8999", "description": "Queries VirusTotal for domain info", "type": "domain reputation", "app_id": 323, "asset": 28, "parameters": [{"domain": ""}]}, {"id": "7a7f51f4-23c5-4656-b979-ee4e92a87254", "create_time": 1774463124.0443516, "update_time": 1774464670.3406312, "last_job_id": 0, "name": "domain reputation - Recorded Future For Splunk SOAR", "action": "4273", "description": "Get a quick indicator of the risk associated with a domain", "type": "domain reputation", "app_id": 247, "asset": 19, "parameters": [{"domain": ""}]}, {"id": "06c31ec1-1701-42ee-8ceb-0f3854442130", "create_time": 1774463124.0443919, "update_time": 1774464670.3406641, "last_job_id": 0, "name": "domain reputation - AlienVault OTX", "action": "9311", "description": "Queries for domain reputation information", "type": "domain reputation", "app_id": 24, "asset": 47, "parameters": [{"domain": "", "response_type": ""}]}, {"id": "8828f2da-09cb-4b81-97a1-8018f7c1f534", "create_time": 1774463124.044433, "update_time": 1774464670.340727, "last_job_id": 0, "name": "whois domain - WHOIS", "action": "9011", "description": "Execute a whois lookup on the given domain", "type": "whois domain", "app_id": 325, "asset": 5, "parameters": [{"domain": ""}]}, {"id": "b7fbe2bf-cf70-4815-a48a-3d3aa46b6d7e", "create_time": 1774463124.044473, "update_time": 1774464670.3407865, "last_job_id": 0, "name": "lookup domain - DNS", "action": "8821", "description": "Query DNS records for a Domain or Host Name", "type": "lookup domain", "app_id": 83, "asset": 1, "parameters": [{"type": "", "domain": ""}]}], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "c4f72802-ef36-47d2-a6c0-9d1ab5e0aa2c", "create_time": 1764758755.6808305, "update_time": 1774464670.340887, "name": "Investigate IP addresses", "order": 5, "tag": "bd473b00-1dc1-4446-8ce2-36d7fc8ef468", "description": "IP%20addresses%20may%20be%20involved%20in%20this%20investigation%20for%20several%20reasons.%20Some%20email%20headers%20can%20contain%20IP%20addresses%20(such%20as%20X-Originating-IP),%20URLs%20can%20contain%20IP%20addresses%20instead%20of%20hostnames,%20file%20attachments%20can%20contain%20IP%20addresses%20or%20generate%20IP%20addresses%20and%20try%20to%20connect%20to%20them%20(like%20domain%20generation%20algorithms),%20and%20IP%20addresses%20can%20be%20added%20to%20the%20notable%20through%20association%20or%20domain%20name%20resolution%20in%20other%20tasks%20within%20this%20investigation.%20Consider%20IP%20addresses%20in%20URLs%20that%20are%20not%20internal%20IP%20addresses%20for%20the%20organization%20highly%20suspicious.%20Investigate%20all%20suspicious%20IP%20addresses%20by%20checking%20the%20reputation,%20geolocation,%20whois%20record,%20DNS%20history,%20and%20by%20gathering%20information%20from%20other%20available%20services.%0A%0ASuggested%20Integrations%0A1.%20MaxMind%0A2.%20Recorded%20Future%20for%20Splunk%20SOAR%0A3.%20Cisco%20Talos%20Intelligence%20%0A4.%20Virustotal%20V3%0A5.%20AlienVault%0A6.%20Whois", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [{"id": "32dfb093-b1a2-4430-83fc-f93bcce46307", "create_time": 1774462938.408724, "update_time": 1774464670.3409607, "last_job_id": 0, "name": "ip intelligence - Recorded Future For Splunk SOAR", "action": "4274", "description": "Get threat intelligence for an IP address", "type": "ip intelligence", "app_id": 247, "asset": 19, "parameters": [{"ip": ""}]}, {"id": "8063c8d1-fbb4-487e-97f7-6ce701ec1270", "create_time": 1774462938.4088063, "update_time": 1774464670.340998, "last_job_id": 0, "name": "geolocate ip - MaxMind", "action": "3254", "description": "Queries MaxMind for IP location info", "type": "geolocate ip", "app_id": 182, "asset": 2, "parameters": [{"ip": ""}]}, {"id": "a8daaffa-7bb3-4d6e-88a7-2462593dca58", "create_time": 1774462938.408869, "update_time": 1774464670.3410332, "last_job_id": 0, "name": "ip reputation - Cisco Talos Intelligence", "action": "7849", "description": "Query IP info", "type": "ip reputation", "app_id": 61, "asset": 11, "parameters": [{"ip": ""}]}, {"id": "75b2fba2-f55f-4612-bfad-9d75d7772a2d", "create_time": 1774462938.4089308, "update_time": 1774464670.3410676, "last_job_id": 0, "name": "ip reputation - VirusTotal v3", "action": "9002", "description": "Queries VirusTotal for IP info", "type": "ip reputation", "app_id": 323, "asset": 28, "parameters": [{"ip": ""}]}, {"id": "33694839-b970-4e11-9e3f-f64485547c36", "create_time": 1774462938.4089913, "update_time": 1774464670.3411016, "last_job_id": 0, "name": "ip reputation - Recorded Future For Splunk SOAR", "action": "4282", "description": "Get a quick indicator of the risk associated with an IP address", "type": "ip reputation", "app_id": 247, "asset": 19, "parameters": [{"ip": ""}]}, {"id": "6393c7da-9a89-49e2-88a0-d7bbc6635b30", "create_time": 1774462938.4090517, "update_time": 1774464670.3411348, "last_job_id": 0, "name": "ip reputation - AlienVault OTX", "action": "9312", "description": "Queries for IP reputation information", "type": "ip reputation", "app_id": 24, "asset": 47, "parameters": [{"ip": "", "response_type": ""}]}, {"id": "3093d945-2d85-4b50-840d-90cd54ed44da", "create_time": 1774462938.4091127, "update_time": 1774464670.341168, "last_job_id": 0, "name": "whois ip - WHOIS", "action": "9012", "description": "Execute a whois lookup on the given IP", "type": "whois ip", "app_id": 325, "asset": 5, "parameters": [{"ip": ""}]}], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}]}, {"id": "d36a2713-63b9-4bfd-8a66-e50df079ace9", "create_time": 1774464670.3416803, "update_time": 1774464670.341681, "name": "Internal Hunting", "order": 3, "tasks": [{"id": "4012859c-a956-4b21-ba9e-a2004dfeb036", "create_time": 1764758755.6812239, "update_time": 1774464670.3412812, "name": "Hunt email activity", "order": 1, "tag": "e7a6d9a6-8b9e-4f8c-afdb-475b0b3472b7", "description": "Find%20other%20similar%20emails%20sent%20into%20the%20organization%20based%20on%20the%20sender%20address,%20sender%20domain,%20subject,%20embedded%20URLs,%20file%20attachments,%20or%20other%20similar%20attributes%20shared%20across%20multiple%20emails.%20If%20possible%20determine%20which%20emails%20were%20opened,%20forwarded,%20deleted,%20marked%20as%20spam,%20or%20reported%20as%20potential%20phishing.%20Consider%20which%20types%20of%20users%20are%20targeted%20and%20why.%20Also%20check%20whether%20internal%20users%20replied%20to%20the%20emails%20and%20what%20information%20was%20contained%20in%20the%20replies.%0A%0ASuggested%20Dashboards%0A1.%20%5BEmail%20Search%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/email_search)", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "1701120f-ca73-42cf-87e1-5dcb228ab5a0", "create_time": 1764758755.681366, "update_time": 1774464670.3413844, "name": "Hunt network activity", "order": 2, "tag": "427ba972-75bd-42eb-8218-4a522f98b947", "description": "Based%20on%20previously%20collected%20information,%20try%20to%20determine%20whether%20or%20not%20URLs%20in%20the%20email%20were%20clicked,%20phishing%20websites%20were%20visited,%20or%20other%20suspicious%20network%20connections%20were%20made%20from%20the%20computers%20of%20users%20who%20opened%20the%20email.%20This%20can%20be%20done%20using%20many%20types%20of%20network%20monitoring,%20including%20netflow,%20full%20packet%20capture,%20DNS%20logging,%20and/or%20endpoint%20monitoring.%0A%0ASuggested%20Dashboards%0A1.%20%5BTraffic%20Center%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/traffic_center)%0A2.%20%5BTraffic%20Search%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/traffic_search)%0A3.%20%5BTraffic%20Size%20Analysis%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/traffic_size_analysis)%0A4.%20%5BPort%20and%20Protocol%20Tracker%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/port_protocol_tracker)%0A5.%20%5BNetwork%20Changes%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/network_changes)", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "24d8fa33-d658-4800-8113-5d7f7c90ad1d", "create_time": 1764758755.681554, "update_time": 1774464670.3414962, "name": "Hunt file executions", "order": 3, "tag": "ebe5a0e7-8705-4e69-b1e7-a21058c87822", "description": "If%20the%20email%20included%20a%20file%20attachment,%20try%20to%20determine%20which%20users%20downloaded%20the%20attachment%20and%20which%20users%20executed%20it%20or%20opened%20it%20in%20some%20other%20way.%20Use%20the%20file%20hash%20of%20the%20attachment%20to%20search%20across%20endpoint%20monitoring%20or%20network%20monitoring%20solutions%20for%20the%20transmission%20and/or%20execution%20of%20the%20file.%20If%20executions%20are%20detected,%20try%20to%20determine%20the%20behavior%20of%20the%20created%20process.%20If%20a%20potentially%20malicious%20document%20or%20other%20file%20type%20was%20opened,%20try%20to%20determine%20which%20application%20opened%20it%20and%20whether%20the%20file%20exploited%20or%20abused%20the%20opening%20application.%0A%0ASuggested%20Dashboards%0A1.%20%5BEndpoint%20Changes%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/endpoint_changes)%0A2.%20%5BMalware%20Center%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/malware_center)%0A3.%20%5BMalware%20Search%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/malware_search)", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "24ad66ec-2b93-4677-b1c4-a6e2c2bd6207", "create_time": 1764758755.6817021, "update_time": 1774464670.3416119, "name": "Hunt user activity", "order": 4, "tag": "32798d9d-6440-4f39-98c7-6d4c30d26e1e", "description": "If%20a%20phishing%20attempt%20or%20other%20user%20account%20compromise%20attempt%20is%20suspected,%20investigate%20how%20the%20credentials%20or%20account%20access%20are%20being%20used.%20Enumerate%20resources%20available%20to%20the%20account%20and%20search%20the%20access%20logs%20for%20those%20resources,%20looking%20for%20anomalous%20usage%20patterns.%0A%0ASuggested%20Dashboards%0A1.%20%5BRisk%20Analysis%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/risk_analysis)%0A2.%20%5BIdentity%20Investigator%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/identity_investigator)%0A%0ASuggested%20Integrations%0A1.%20%20%5BAsset%20and%20Risk%20Intelligence%5D(https://splunkbase.splunk.com/app/7180)", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}]}, {"id": "42eb2edf-fc7d-4327-8f3e-37ee80c2536c", "create_time": 1774464670.342922, "update_time": 1774464670.3429222, "name": "Enforcement and increased monitoring", "order": 4, "tasks": [{"id": "2eb1f1a5-8f1a-45d8-8953-ba30d1a8a6e9", "create_time": 1764758755.6819034, "update_time": 1774464670.3417504, "name": "Block or monitor email activity", "order": 1, "tag": "6b567916-424d-41b3-836f-b4abfa555448", "description": "If%20specific%20malicious%20emails%20have%20been%20identified,%20delete%20them%20from%20any%20mailboxes%20in%20which%20they%20still%20pose%20a%20threat.%20Similarly,%20if%20a%20sender%20address%20or%20an%20entire%20sender%20domain%20is%20found%20to%20be%20malicious,%20block%20inbound%20email%20from%20that%20source.%20Set%20filtering%20rules%20to%20block%20inbound%20email%20or%20increase%20monitoring%20of%20email%20based%20on%20other%20detected%20characteristics%20of%20an%20email%20campaign%20or%20malicious%20technique.%0A%0ASuggested%20Dashboards%0A1.%20%5BEmail%20Search%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/email_search)%0A%0ASuggested%20Integration%20(%20if%20not%20already%20configured%20navigate%20%5BHERE%5D(/app/SplunkEnterpriseSecuritySuite/ess_configuration/#/soar/soar_apps/apps)%20to%20locate%20and%20configure)%0A1.%20MS%20Graph%20for%20Office%20365%0A2.%20G%20Suite%20for%20GMail", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [{"id": "8a243a09-160b-47d2-b92d-ae1fdb6ad2f4", "create_time": 1774463463.9849086, "update_time": 1774464670.3418393, "last_job_id": 0, "name": "delete email - MS Graph for Office 365", "action": "8873", "description": "Delete an email", "type": "delete email", "app_id": 175, "asset": 15, "parameters": [{"id": "", "email_address": ""}]}, {"id": "c6ad5551-59a2-4abc-981e-aff11350ab7c", "create_time": 1774463463.984975, "update_time": 1774464670.3418756, "last_job_id": 0, "name": "delete email - MS Graph for Office 365", "action": "8873", "description": "Delete an email", "type": "delete email", "app_id": 175, "asset": 15, "parameters": [{"id": "", "email_address": ""}]}], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "f0d28b16-b4ba-46a9-8d20-c888d0d50137", "create_time": 1764758755.6820495, "update_time": 1774464670.3419485, "name": "Block or monitor network activity", "order": 2, "tag": "b537f91c-ce46-4a52-8894-0797dbc13b6b", "description": "Based%20on%20gathered%20indicators%20and%20metadata,%20block%20or%20increase%20monitoring%20of%20malicious%20network%20connections%20associated%20with%20the%20suspicious%20email.%20Prevent%20other%20receivers%20of%20similar%20phishing%20emails%20from%20accessing%20the%20clickable%20URL%20by%20blocking%20that%20URL%20itself,%20the%20underlying%20domain%20name,%20and/or%20the%20underlying%20IP%20addresses.%20If%20malware%20or%20unwanted%20software%20was%20detected,%20block%20outbound%20connections%20known%20to%20be%20associated%20with%20that%20malware%20based%20on%20threat%20intelligence%20or%20dynamic%20analysis.%20If%20the%20threat%20is%20severe%20enough,%20consider%20isolating%20entire%20portions%20of%20the%20network.%0A%0ASuggested%20Dashboards%0A1.%20%5BTraffic%20Center%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/traffic_center)%0A%0ASuggested%20Integration%20(%20if%20not%20already%20configured%20navigate%20%5BHERE%5D(/app/SplunkEnterpriseSecuritySuite/ess_configuration/#/soar/soar_apps/apps)%20to%20locate%20and%20configure)%0A1.%20Cisco%20Firepower%0A2.%20Cisco%20Secure%20Firewall%0A3.%20Palo%20Alto%0A4.%20Zscaler%0A", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [{"id": "0ea6b3e9-4390-45f2-adde-f3970b54f72a", "create_time": 1774463807.8372653, "update_time": 1774464670.3420188, "last_job_id": 0, "name": "block ip - Cisco Firepower", "action": "9266", "description": "Blocks an IP network", "type": "block ip", "app_id": 56, "asset": 40, "parameters": [{"ip": ""}]}, {"id": "819339b4-b988-49c6-b342-e764fd5f4734", "create_time": 1774463807.8373063, "update_time": 1774464670.342054, "last_job_id": 0, "name": "delete network object - Cisco Secure Firewall", "action": "9272", "description": "Deletes a network object in FMC", "type": "delete network object", "app_id": 59, "asset": 41, "parameters": [{"type": "", "object_id": "", "domain_name": ""}]}, {"id": "0f21c543-322b-4c6d-9e3d-672ace73adc9", "create_time": 1774463807.8373466, "update_time": 1774464670.342087, "last_job_id": 0, "name": "block ip - Panorama", "action": "8651", "description": "Block an IP", "type": "block ip", "app_id": 220, "asset": 42, "parameters": [{"ip": "", "policy_name": "", "policy_type": "", "device_group": "", "audit_comment": "", "should_add_tag": false, "is_source_address": false, "use_partial_commit": false, "should_commit_changes": false}]}, {"id": "682edc39-6050-4f5d-8347-dcf47dcae334", "create_time": 1774463807.837387, "update_time": 1774464670.3421197, "last_job_id": 0, "name": "block url - Panorama", "action": "8647", "description": "Block an URL", "type": "block url", "app_id": 220, "asset": 42, "parameters": [{"url": "", "policy_name": "", "policy_type": "", "device_group": "", "audit_comment": "", "use_partial_commit": false, "should_commit_changes": false}]}, {"id": "7e5001ba-59a6-4311-97b8-8b1622df3305", "create_time": 1774463807.8374271, "update_time": 1774464670.3421648, "last_job_id": 0, "name": "delete address - Panorama", "action": "8674", "description": "Delete address details for the supplied address name", "type": "delete address", "app_id": 220, "asset": 42, "parameters": [{"name": "", "device_group": "", "use_partial_commit": false, "should_commit_changes": false}]}, {"id": "ef5f9555-f5f0-472a-b939-8a1c8231a92a", "create_time": 1774463807.837467, "update_time": 1774464670.3421988, "last_job_id": 0, "name": "block ip - Zscaler", "action": "9074", "description": "Block an IP", "type": "block ip", "app_id": 338, "asset": 30, "parameters": [{"ip": "", "url_category": ""}]}, {"id": "7ca3f82c-0605-4046-aa8e-729a3adc985c", "create_time": 1774463807.8375063, "update_time": 1774464670.3422313, "last_job_id": 0, "name": "block url - Zscaler", "action": "9075", "description": "Block a URL", "type": "block url", "app_id": 338, "asset": 30, "parameters": [{"url": "", "url_category": ""}]}], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "79abbff6-2d34-46b0-b570-c9788da8668a", "create_time": 1764758755.6822183, "update_time": 1774464670.342305, "name": "Block or monitor file executions", "order": 3, "tag": "e7cb23b5-9baa-4a66-994d-43cd0f17d017", "description": "Based%20on%20gathered%20indicators%20and%20metadata,%20block%20or%20increase%20monitoring%20of%20endpoint%20activity%20caused%20by%20the%20suspicious%20email.%20This%20could%20mean%20blocking%20the%20hash%20of%20the%20file%20attachment,%20blocking%20the%20hash%20of%20a%20file%20downloaded%20from%20a%20URL%20in%20an%20email,%20blocking%20a%20malicious%20hash%20associated%20with%20the%20email%20by%20threat%20intelligence,%20or%20blocking%20secondary%20executions%20such%20as%20dropped%20stages%20of%20malware%20identified%20from%20dynamic%20analysis.%0A%0ASuggested%20Integration%20(%20if%20not%20already%20configured%20navigate%20%5BHERE%5D(/app/SplunkEnterpriseSecuritySuite/ess_configuration/#/soar/soar_apps/apps)%20to%20locate%20and%20configure)%0A1.%20Microsoft%20Defender%20for%20Endpoint%0A2.%20VMware%20Carbon%20Black%20Cloud%20for%20Splunk%20SOARSuggested%20Integrations", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [{"id": "4b20e307-4835-4935-99bd-18c10e50afea", "create_time": 1774463807.837656, "update_time": 1774464670.3423738, "last_job_id": 0, "name": "quarantine file - Windows Defender ATP", "action": "9020", "description": "Quarantine a file", "type": "quarantine file", "app_id": 191, "asset": 45, "parameters": [{"comment": "", "timeout": "", "device_id": "", "file_hash": ""}]}, {"id": "e5f80fc2-cf03-4b2f-b609-6ecbbdb678af", "create_time": 1774463807.837697, "update_time": 1774464670.3424082, "last_job_id": 0, "name": "block hash - Carbon Black Response", "action": "8753", "description": "Add a hash to the Carbon Black Response blacklist", "type": "block hash", "app_id": 48, "asset": 10, "parameters": [{"hash": "", "comment": ""}]}], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "fa4ad6aa-7fc1-4897-9588-e2366ce2cc8e", "create_time": 1764758755.6823559, "update_time": 1774464670.3424766, "name": "Contain endpoints", "order": 4, "tag": "746ae480-2639-4ffe-80ce-698238ec5721", "description": "If%20an%20endpoint%20compromise%20is%20suspected,%20it%20might%20be%20necessary%20to%20quarantine%20or%20otherwise%20contain%20that%20endpoint%20until%20further%20investigation%20and%20remediation%20can%20be%20done.%20Consider%20the%20criticality%20of%20the%20system%20and%20the%20likelihood%20of%20a%20compromise.%20In%20other%20cases,%20simply%20increasing%20the%20monitoring%20or%20scanning%20for%20more%20information%20can%20be%20prudent.%0A%0ASuggested%20Integration%20(%20if%20not%20already%20configured%20navigate%20%5BHERE%5D(/app/SplunkEnterpriseSecuritySuite/ess_configuration/#/soar/soar_apps/apps)%20to%20locate%20and%20configure)%0A1.%20Microsoft%20Defender%20for%20Endpoint%0A2.%20VMware%20Carbon%20Black%20Cloud%20for%20Splunk%20SOARSuggested%20Integrations%0A3.%20CrowdStrike", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [{"id": "14aa8a3b-e1bc-4e9e-8471-1540cfe73a59", "create_time": 1774463898.3934326, "update_time": 1774464670.3425434, "last_job_id": 0, "name": "quarantine device - Windows Defender ATP", "action": "9016", "description": "Quarantine the device", "type": "quarantine device", "app_id": 191, "asset": 45, "parameters": [{"type": "", "comment": "", "timeout": "", "device_id": ""}]}, {"id": "51ca9815-7858-4e55-937d-e4ec21da9769", "create_time": 1774463898.3934734, "update_time": 1774464670.3425767, "last_job_id": 0, "name": "quarantine device - Carbon Black Response", "action": "8740", "description": "Quarantine the endpoint", "type": "quarantine device", "app_id": 48, "asset": 10, "parameters": [{"ip_hostname": ""}]}, {"id": "d7361393-54e7-4be3-bea1-b03417fa9f20", "create_time": 1774463898.3935122, "update_time": 1774464670.3426096, "last_job_id": 0, "name": "quarantine device - CrowdStrike OAuth API", "action": "8761", "description": "Block the device", "type": "quarantine device", "app_id": 77, "asset": 44, "parameters": [{"hostname": "", "device_id": ""}]}], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "8ffee892-3e52-4aed-ba5f-30554d3de579", "create_time": 1764758755.6824956, "update_time": 1774464670.3426752, "name": "Contain user accounts", "order": 5, "tag": "702244fa-e9c6-42d7-846a-697fb74ea060", "description": "If%20a%20user%20account%20compromise%20is%20suspected,%20it%20might%20be%20necessary%20to%20reset%20the%20credentials,%20reduce%20the%20account%20privileges,%20or%20disable%20the%20account%20until%20further%20investigation%20is%20completed.%0A%0ASuggested%20Integration%20(%20if%20not%20already%20configured%20navigate%20%5BHERE%5D(/app/SplunkEnterpriseSecuritySuite/ess_configuration/#/soar/soar_apps/apps)%20to%20locate%20and%20configure)%0A1.%20MS%20Graph%20For%20Active%20Directory%0A2.%20AD%20LDAP%0A3.%20Okta%0A4.%20AWS%20IAM%0A5.%20Azure%20AD%20Graph", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [{"id": "acc26fcb-3a41-4a50-ab34-bcb2c9566f6e", "create_time": 1774464029.5737805, "update_time": 1774464670.3427422, "last_job_id": 0, "name": "disable account - AD LDAP", "action": "8679", "description": "Disables an Active Directory account", "type": "disable account", "app_id": 1, "asset": 8, "parameters": [{"user": "", "use_samaccountname": false}]}, {"id": "3fea686d-7838-4e8e-8610-7ef1ca5ebfd6", "create_time": 1774464029.5738244, "update_time": 1774464670.3427927, "last_job_id": 0, "name": "disable user - Okta", "action": "8889", "description": "Disables the specified user", "type": "disable user", "app_id": 215, "asset": 17, "parameters": [{"id": ""}]}, {"id": "aa142b97-8127-4594-b56c-9e9efaca8a3f", "create_time": 1774464029.5738668, "update_time": 1774464670.3428268, "last_job_id": 0, "name": "disable user - AWS IAM", "action": "211", "description": "Disable login profile and access keys of a user", "type": "disable user", "app_id": 10, "asset": 38, "parameters": [{"username": "", "credentials": "", "disable_access_keys": false}]}, {"id": "dc5f6910-3393-4b90-92ac-0bbf677e0f2f", "create_time": 1774464029.5739067, "update_time": 1774464670.342859, "last_job_id": 0, "name": "disable user - Azure AD Graph", "action": "8722", "description": "Disable a user", "type": "disable user", "app_id": 30, "asset": 39, "parameters": [{"user_id": ""}]}, {"id": "3dd60b49-436f-464d-9032-465307f7e2ea", "create_time": 1774464029.5739467, "update_time": 1774464670.3428931, "last_job_id": 0, "name": "disable user - MS Graph for Active Directory", "action": "9252", "description": "Disable a user", "type": "disable user", "app_id": 174, "asset": 37, "parameters": [{"user_id": ""}]}], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}]}, {"id": "f3f3a7c8-dcb4-4565-8827-356c60cac5f6", "create_time": 1774464670.343151, "update_time": 1774464670.3431516, "name": "Longer-running analysis jobs", "order": 5, "tasks": [{"id": "09b37ed6-4b6e-4fe0-a4c5-561480ed7c10", "create_time": 1764758755.68271, "update_time": 1774464670.3429852, "name": "Analyze network activity", "order": 1, "tag": "9cf69134-6b81-45ca-ada8-fd4136a1912f", "description": "Perform%20any%20resource-intensive%20analysis%20of%20network%20activity%20left%20over%20from%20the%20External%20Investigation%20and%20Internal%20Hunting%20phases.%20This%20might%20mean%20full%20packet%20capture%20collection%20and%20analysis,%20sandbox%20detonation%20of%20URLs,%20long-running%20queries%20of%20network%20history%20and%20anomalous%20behavior,%20or%20other%20similar%20analysis%20tasks.%0A%0ASuggested%20Dashboards%0A1.%20%5BTraffic%20Center%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/traffic_center)%0A2.%20%5BTraffic%20Search%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/traffic_search)%0A3.%20%5BTraffic%20Size%20Analysis%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/traffic_size_analysis)%0A4.%20%5BPort%20and%20Protocol%20Tracker%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/port_protocol_tracker)", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "627cb8cc-b780-437e-951d-8ec9c64062e7", "create_time": 1764758755.682851, "update_time": 1774464670.3430834, "name": "Analyze endpoint activity", "order": 2, "tag": "2497b494-b80f-417b-b51d-f4c8d7aff019", "description": "Conduct%20deeper%20analysis%20on%20remaining%20malware%20and%20endpoint%20investigation%20tasks%20not%20finished%20in%20the%20External%20Investigation%20and%20Internal%20Hunting%20phases.%20This%20might%20mean%20sandbox%20detonation%20of%20files,%20forensic%20analysis%20of%20associated%20devices%20or%20memory%20dumps,%20reverse%20engineering%20of%20suspected%20malware,%20long-running%20queries%20of%20endpoint%20activity%20history%20and%20anomalous%20behavior,%20or%20other%20similar%20analysis%20tasks.%0A%0ASuggested%20Dashboards%0A1.%20%5BEndpoint%20Changes%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/endpoint_changes)%0A2.%20%5BMalware%20Center%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/malware_center)%0A3.%20%5BMalware%20Search%20%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/malware_search)%0A4.%20%5BAsset%20and%20Risk%20Intelligence%5D(https://splunkbase.splunk.com/app/7180)", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}]}, {"id": "934b1327-2484-49e2-9701-36a33a1462f9", "create_time": 1774464670.343888, "update_time": 1774464670.3438883, "name": "Notification", "order": 6, "tasks": [{"id": "3b692da7-b9dc-491b-add5-2c674251a7be", "create_time": 1764758755.683051, "update_time": 1774464670.3432143, "name": "Update tickets", "order": 1, "tag": "dad41274-fb84-4b6f-bed9-fb43be506987", "description": "Make%20sure%20that%20all%20the%20necessary%20outputs%20and%20status%20updates%20from%20the%20previous%20phases%20and%20tasks%20are%20documented%20in%20the%20appropriate%20system%20of%20record.%20Summarize%20the%20current%20state%20of%20the%20investigation%20and%20any%20remaining%20tasks.%0A", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "644d1cc6-f855-4dfb-ae28-a0a58fbee6d2", "create_time": 1764758755.6832078, "update_time": 1774464670.3433015, "name": "Notify system owners", "order": 2, "tag": "824481e3-9dc5-4668-9abd-585d1cd331ca", "description": "For%20any%20systems%20that%20have%20been%20changed%20or%20need%20to%20be%20changed,%20notify%20the%20necessary%20system%20owners%20so%20the%20appropriate%20change%20management%20procedures%20can%20be%20followed.%0A%0ASuggested%20Integration%20(%20if%20not%20already%20configured%20navigate%20%5BHERE%5D(/app/SplunkEnterpriseSecuritySuite/ess_configuration/#/soar/soar_apps/apps)%20to%20locate%20and%20configure)%0A1.%20SMTP%0A2.%20%20MS%20Graph%20for%20Office%20365%0A3.%20%20G%20Suite%20for%20GMail%0A4.%20Cisco%20Webex%0A5.%20Slack%0A6.%20Microsoft%20Teams", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [{"id": "821be969-975d-4420-b038-f3fd8d9793ed", "create_time": 1774464185.863417, "update_time": 1774464670.3433692, "last_job_id": 0, "name": "send email - SMTP", "action": "9244", "description": "Sends an email", "type": "send email", "app_id": 260, "asset": 36, "parameters": [{"cc": "", "to": "", "bcc": "", "body": "", "from": "", "headers": "", "subject": "", "attachments": ""}]}, {"id": "f249402b-1dd3-4cf6-992c-99b7065a857b", "create_time": 1774464185.8634572, "update_time": 1774464670.3434021, "last_job_id": 0, "name": "send email - MS Graph for Office 365", "action": "8880", "description": "Sends an email with optional text rendering. Attachments are allowed a Content-ID tag for reference within the html", "type": "send email", "app_id": 175, "asset": 15, "parameters": [{"cc": "", "to": "", "bcc": "", "body": "", "from": "", "headers": "", "subject": "", "attachments": ""}]}, {"id": "c9cb46ee-e2da-4b28-83f1-6f18df1957bb", "create_time": 1774464185.8634965, "update_time": 1774464670.3434355, "last_job_id": 0, "name": "send email - G Suite for GMail", "action": "9227", "description": "Send emails", "type": "send email", "app_id": 123, "asset": 34, "parameters": [{"cc": "", "to": "", "bcc": "", "body": "", "from": "", "headers": "", "subject": "", "reply_to": "", "alias_name": "", "alias_email": "", "attachments": ""}]}, {"id": "ea1ef95b-ce56-4b0d-989a-e80ac7265fde", "create_time": 1774464185.8635354, "update_time": 1774464670.3434682, "last_job_id": 0, "name": "send message - Cisco Webex", "action": "9205", "description": "Send message to user or room", "type": "send message", "app_id": 64, "asset": 32, "parameters": [{"message": "", "endpoint_id": "", "is_markdown": false, "destination_type": ""}]}, {"id": "dc5fd3dd-a036-4170-8ef7-64598013bdc0", "create_time": 1774464185.8635745, "update_time": 1774464670.343501, "last_job_id": 0, "name": "send message - Slack", "action": "8927", "description": "Send a message to Slack", "type": "send message", "app_id": 277, "asset": 22, "parameters": [{"blocks": "", "message": "", "link_names": false, "destination": "", "reply_broadcast": false, "parent_message_ts": ""}]}, {"id": "12ab4085-4f3f-4a42-8658-e62278e670e6", "create_time": 1774464185.863613, "update_time": 1774464670.3435338, "last_job_id": 0, "name": "send direct message - Microsoft Teams", "action": "9234", "description": "Send a direct message to a user", "type": "send direct message", "app_id": 198, "asset": 35, "parameters": [{"message": "", "user_id": ""}]}], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "81905435-dd7e-493d-babf-fc5f108cbb9a", "create_time": 1764758755.6833851, "update_time": 1774464670.3435926, "name": "Notify regulatory compliance team", "order": 3, "tag": "c7f7005c-6b51-49a7-a3f9-f22aaf9dfbe4", "description": "If%20appropriate,%20notify%20the%20regulatory%20compliance%20team%20to%20support%20them%20as%20they%20report%20this%20incident%20to%20the%20correct%20regulatory%20or%20accrediting%20organizations.%0A%0A6.%20%5BMicrosoft%20Teams%5D(https://splunkbase.splunk.com/app/5818)", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "a4260d25-53f9-45c4-b984-4c10deddbb82", "create_time": 1764758755.6836178, "update_time": 1774464670.3436801, "name": "Assign additional tasks", "order": 4, "tag": "29d21b34-5221-4dee-9bff-276a8241b2bd", "description": "Create tickets to track any follow-on tasks that came out of this investigation. Example tasks might include conducting deeper endpoint investigation, re-provisioning systems, re-enabling accounts, or tuning filtering systems to block future emails.", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "d0cf948f-2ba6-4a7d-82c9-851aacfa80a6", "create_time": 1764758755.6839995, "update_time": 1774464670.3437545, "name": "Educate users", "order": 5, "tag": "7ee89bfe-e39d-42c9-baa0-2e74b39adcd1", "description": "If appropriate, inform the broader user base about the types of suspicious emails being sent to the organization to try to prevent them from clicking malicious links or opening malicious file attachments in the future.", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "5b78276c-3dff-4546-8ff4-78cd4e1b04d3", "create_time": 1764758755.6842132, "update_time": 1774464670.3438444, "name": "Share threat intelligence", "order": 6, "tag": "3773742e-ecd3-4588-a0ae-6ac80e6b70ce", "description": "If appropriate, communicate relevant findings to trusted third parties and/or the public threat intelligence community. Make sure that outbound messages do not contain confidential information. Consider sharing or confirming the usage of indicators and techniques to peer organizations, security vendors, public databases, or industry-specific threat intelligence sharing communities.", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}]}], "origin": {"id": "a72d40f3-a567-48e2-9fd3-c29db06c3907", "name": "Suspicious Email", "version": 3}, "template_id": "f433d837-0893-4223-8927-f48ab6ca3f04", "active": true, "used": false, "ai_generated": false, "source_attachment_id": null, "_user": "nobody", "_key": "8fc25dd2-407f-4841-ab2a-00b669765a92"}