mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
3953a43f05
* Create response_plan directory * Update directory name * Copy response_templates artifacts to dist/api * Add response-templates schema validation workflow * Add feature branch for testing purpose * Update endpoint to playground * Revert back debug changes * Move scripts to workflows * Remove manual check in * Add sorting for version and template name * Raise exception when file name not match * Add indentation for json output * Add debug option to dump json schema * Generate merged templates at runtime * Rename openAPI spec yaml to yml * Move validation to build.yml * Use stem to get file name * Fix python package install * Update version sorting using int * Update openAPI spec for version * Move build response templates to separate workflow * Fix naming in build-response-templates.yml * Update response templates to the ones for first release * Fix naming of response templates * Response templates to be added by response plan team * Keep response_templates directory * Skip .gitkeep checking when check non-json files * Remove the .gitkeep * Initial version of Response Templates * Initial version of Response Templates * Initial version of Response Templates * Revert "Initial version of Response Templates" This reverts commit3a174dd02e. * Revert "Initial version of Response Templates" This reverts commit26fa66ddde. * Revert "Initial version of Response Templates" This reverts commit6014b4870b. * Initial version of Response Templates * Initial version of Response Templates * Update and rename AccountCompromise_v14.json to AccountCompromise_v2.json * Update and rename DataBreach_v15.json to DataBreach_v2.json * Update and rename GenericIncidentResponse_v13.json to GenericIncidentResponse_v2.json * Update and rename NIST80061_v14.json to NIST80061_v2.json * Update and rename NetworkIndicatorEnrichment_v6.json to NetworkIndicatorEnrichment_v2.json * Update and rename SelfReplicatingMalware_v14.json to SelfReplicatingMalware_v2.json * Update and rename SuspiciousEmail_v35.json to SuspiciousEmail_v2.json * Update and rename VulnerabilityDisclosure_v10.json to VulnerabilityDisclosure_v2.json * Add comments --------- Co-authored-by: pyth0n1c <87383215+pyth0n1c@users.noreply.github.com> Co-authored-by: Christian Cloutier <ccloutier@splunk.com> Co-authored-by: kbouchard <47464052+kbouchardherjavecgroup@users.noreply.github.com> Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
2 lines
9.8 KiB
JSON
2 lines
9.8 KiB
JSON
{"id": "83c7c93e-eb22-4a6c-981f-d7a857b71dfc", "create_time": 1764862787.2717, "update_time": 1765478160.218586, "name": "Vulnerability Disclosure", "description": "", "template_status": "published", "creator": "splunker", "updated_by": "splunker", "is_default": false, "version": 2, "phases": [{"id": "63140a0e-8d42-4aba-943a-899170cc7fd3", "create_time": 1765478079.1544676, "update_time": 1765478160.185931, "name": "Understand the vulnerability", "order": 1, "tasks": [{"id": "c2906aa1-2ba2-4d46-b927-04a348dfc8ed", "create_time": 1764758755.9402392, "update_time": 1765478160.1855013, "name": "Research types of systems that are affected", "order": 1, "tag": "f0045b4e-6680-4782-b80b-ba292805d290", "description": "Research%20the%20known%20hardware%20or%20software%20systems%20and%20versions%20that%20are%20affected.%20If%20possible%20use,%20a%20vulnerability%20database%20or%20software%20composition%20analysis%20solution%20to%20walk%20the%20dependency%20chain%20and%20evaluate%20the%20scope%20of%20the%20vulnerability.%0A%0ASuggested%20Integrations%0A1.%20%5BTraffic%20Search%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/traffic_search)%0A2.%20%5BTraffic%20Size%20Analysis%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/traffic_size_analysis)%0A3.%20%5BPort%20and%20Protocol%20Tracker%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/port_protocol_tracker)%0A4.%20%5BEndpoint%20Changes%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/endpoint_changes)%0A5.%20%5BMalware%20Center%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/malware_center)%0A6.%20%5BAsset%20and%20Risk%20Intelligence%5D(https://splunkbase.splunk.com/app/7180)", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "bd74c974-5d88-4136-aae1-13642d0f5bb5", "create_time": 1764758755.9403417, "update_time": 1765478160.185846, "name": "Research how the vulnerability works", "order": 2, "tag": "207e6bdb-1eed-41f8-9ee6-f87bf260978a", "description": "Research%20the%20mechanism%20that%20makes%20the%20system%20vulnerable%20and%20the%20conditions%20in%20which%20the%20system%20is%20vulnerable.%20Often%20there%20are%20certain%20configurations,%20software%20packages,%20system%20states,%20operating%20modes,%20and%20other%20characteristics%20that%20make%20a%20vulnerability%20exploitable%20and%20affect%20the%20impact%20if%20exploited.%20Assess%20the%20difficulty%20to%20exploit%20the%20vulnerability%20and%20the%20reliability%20of%20the%20exploit.%0A%0A%0A1.%20%5BES%20Use%20Case%20Library%5D(/app/SplunkEnterpriseSecuritySuite/ess_use_case_library)%0A2.%20%5BSplunk%20Security%20Content%5D(https://research.splunk.com/)", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}]}, {"id": "0e4796c9-bcb5-4837-b0cd-7c83b40dd2c3", "create_time": 1765478079.1550362, "update_time": 1765478160.1863368, "name": "Understand impact to the organization", "order": 2, "tasks": [{"id": "6dc2dedf-7fe4-4d02-bc74-4b386a320460", "create_time": 1764758755.940481, "update_time": 1765478160.186015, "name": "Find potentially affected systems", "order": 1, "tag": "b5bcfe17-e8a5-40a0-984c-c8fefe77093c", "description": "Check%20the%20internal%20environment%20and%20dependencies%20of%20the%20organization%20for%20the%20software%20or%20hardware%20that%20is%20vulnerable.%0A%0ASuggested%20Integrations%0A1.%20%5BTraffic%20Search%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/traffic_search)%0A2.%20%5BTraffic%20Size%20Analysis%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/traffic_size_analysis)%0A3.%20%5BPort%20and%20Protocol%20Tracker%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/port_protocol_tracker)%0A4.%20%5BEndpoint%20Changes%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/endpoint_changes)%0A5.%20%5BMalware%20Center%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/malware_center)%0A6.%20%5BRisk%20Analysis%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/risk_analysis)%0A7.%20%5BAsset%20and%20Risk%20Intelligence%5D(https://splunkbase.splunk.com/app/7180)", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "26f32c1e-5de3-4565-9a72-c17aa0dfee4e", "create_time": 1764758755.9405725, "update_time": 1765478160.186133, "name": "Determine exploitability", "order": 2, "tag": "9b967031-b163-4c25-a971-011f10df8051", "description": "Check%20for%20exploitable%20conditions.%20If%20appropriate,%20attempt%20to%20implement%20the%20vulnerability%20or%20use%20a%20safe%20proof%20of%20concept%20to%20verify%20exploitability.%0A%0ASuggested%20Integrations%0A1.%20%5BSplunk%20Attack%20Analyzer%5D(https://splunkbase.splunk.com/app/6783)", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "1f4e957a-1bc6-4b22-b222-44c845454b45", "create_time": 1764758755.9406626, "update_time": 1765478160.1862617, "name": "Investigate possible exploitation", "order": 3, "tag": "b944edaa-aa8a-4877-8b78-f022580d2731", "description": "Investigate%20whether%20or%20not%20vulnerable%20systems%20were%20exploited.%20Use%20the%20particular%20behavior%20of%20the%20exploit%20and%20likely%20post-exploitation%20techniques%20to%20narrow%20down%20the%20search%20for%20exploited%20systems.%0A%0ASuggested%20Integrations%0A1.%20%5BTraffic%20Search%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/traffic_search)%0A2.%20%5BTraffic%20Size%20Analysis%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/traffic_size_analysis)%0A3.%20%5BPort%20and%20Protocol%20Tracker%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/port_protocol_tracker)%0A4.%20%5BEndpoint%20Changes%20%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/endpoint_changes)%0A5.%20%5BMalware%20Center%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/malware_center)%0A6.%20%5BRisk%20Analysis%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/risk_analysis)", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}]}, {"id": "e8928704-4ba7-41c1-abba-a0444d548fe0", "create_time": 1765478079.1552103, "update_time": 1765478160.1864805, "name": "Decide how to respond", "order": 3, "tasks": [{"id": "860d180e-5d53-4eb7-b867-97ad48f470e6", "create_time": 1764758755.9407957, "update_time": 1765478160.1864188, "name": "Evaluate patches, workarounds, and service outages", "order": 1, "tag": "23a1b3d3-d2db-40d9-9a96-39a154c94ff0", "description": "Consider%20how%20mitigations,%20remediations,%20and%20forced%20system%20shutdowns%20affect%20the%20situation.%0A%0ASuggested%20Integrations%0A1.%20%5BUpdate%20Center%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/update_center)%0A2.%20%5BAsset%20and%20Risk%20Intelligence%5D(https://splunkbase.splunk.com/app/7180)", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}]}, {"id": "1559a28c-3e76-4910-a22e-f5e6977d0647", "create_time": 1765478079.1555555, "update_time": 1765478160.1868198, "name": "Execute the response", "order": 4, "tasks": [{"id": "1d4394f7-8781-4802-a6a2-7d77b655a9ee", "create_time": 1764758755.9409366, "update_time": 1765478160.1865623, "name": "Remediate", "order": 1, "tag": "6e13819e-dfdf-4e48-90fa-95c7ddfc139c", "description": "Apply%20patches,%20upgrades,%20configuration%20changes,%20or%20state%20changes%20that%20can%20remediate%20the%20vulnerability.%0A%0ASuggested%20Integrations%0A1.%20%5BCrowdstrike%5D(https://splunkbase.splunk.com/app/5786)%0A2.%20%5BMicrosoft%20Defender%20for%20Endpoint%5D(https://splunkbase.splunk.com/app/5870)%0A3.%20%5BVMware%20Carbon%20Black%20Cloud%20for%20Splunk%20SOAR%5D(https://splunkbase.splunk.com/app/6732)", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "43f50b91-ee22-4731-a5fe-c6b4463134cf", "create_time": 1764758755.941027, "update_time": 1765478160.186665, "name": "Mitigate", "order": 2, "tag": "5c813f0c-e55c-492a-933b-59b99ad11071", "description": "Apply%20workarounds,%20temporary%20fixes,%20additional%20hardening,%20new%20security%20tools,%20new%20detections,%20and%20other%20mitigations%20to%20reduce%20risk.%0A%0ASuggested%20Integrations%0A1.%20%5BCisco%20Firepower%5D(https://splunkbase.splunk.com/app/5995)%0A2.%20%5BCisco%20Secure%20Firewall%5D(https://splunkbase.splunk.com/app/7745)%0A3.%20%5B%20Palo%20Alto%5D(https://splunkbase.splunk.com/app/5830)%0A4.%20%5BZscaler%5D(https://splunkbase.splunk.com/app/5872)", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "90f60618-b458-4baa-ae0d-af0fe1c4b3ec", "create_time": 1764758755.941116, "update_time": 1765478160.1867695, "name": "Document accepted risks", "order": 3, "tag": "47c9830a-c0e1-4b75-ae76-4b5e0cddbf5c", "description": "Document remaining risk and notify stakeholders.", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}]}], "template_id": "b0687c98-dcde-4d9a-bf6f-4a31859fef16", "active": true, "used": false, "_user": "nobody", "_key": "83c7c93e-eb22-4a6c-981f-d7a857b71dfc"}
|