mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
fc1596e371
had to remove 8.5 from the name of response plans
1 line
12 KiB
JSON
1 line
12 KiB
JSON
{"id": "fa831ce6-8899-4fb5-8e53-95048dc18b1b", "create_time": 1774464283.360491, "update_time": 1774464693.2253447, "name": "Vulnerability Disclosure", "description": "", "template_status": "published", "creator": "splunker", "updated_by": "splunker", "is_default": false, "version": 3, "phases": [{"id": "63140a0e-8d42-4aba-943a-899170cc7fd3", "create_time": 1774464693.1930168, "update_time": 1774464693.1930172, "name": "Understand the vulnerability", "order": 1, "tasks": [{"id": "c2906aa1-2ba2-4d46-b927-04a348dfc8ed", "create_time": 1764758755.9402392, "update_time": 1774464693.1926908, "name": "Research types of systems that are affected", "order": 1, "tag": "f0045b4e-6680-4782-b80b-ba292805d290", "description": "Research%20the%20known%20hardware%20or%20software%20systems%20and%20versions%20that%20are%20affected.%20If%20possible%20use,%20a%20vulnerability%20database%20or%20software%20composition%20analysis%20solution%20to%20walk%20the%20dependency%20chain%20and%20evaluate%20the%20scope%20of%20the%20vulnerability.%0A%0ASuggested%20Dashboards%0A1.%20%5BTraffic%20Search%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/traffic_search)%0A2.%20%5BTraffic%20Size%20Analysis%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/traffic_size_analysis)%0A3.%20%5BPort%20and%20Protocol%20Tracker%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/port_protocol_tracker)%0A4.%20%5BEndpoint%20Changes%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/endpoint_changes)%0A5.%20%5BMalware%20Center%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/malware_center)%0A6.%20%5BAsset%20and%20Risk%20Intelligence%5D(https://splunkbase.splunk.com/app/7180)", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "bd74c974-5d88-4136-aae1-13642d0f5bb5", "create_time": 1764758755.9403417, "update_time": 1774464693.1929107, "name": "Research how the vulnerability works", "order": 2, "tag": "207e6bdb-1eed-41f8-9ee6-f87bf260978a", "description": "Research%20the%20mechanism%20that%20makes%20the%20system%20vulnerable%20and%20the%20conditions%20in%20which%20the%20system%20is%20vulnerable.%20Often%20there%20are%20certain%20configurations,%20software%20packages,%20system%20states,%20operating%20modes,%20and%20other%20characteristics%20that%20make%20a%20vulnerability%20exploitable%20and%20affect%20the%20impact%20if%20exploited.%20Assess%20the%20difficulty%20to%20exploit%20the%20vulnerability%20and%20the%20reliability%20of%20the%20exploit.%0A%0ASplunk%20Resources%0A1.%20%5BES%20Use%20Case%20Library%5D(/app/SplunkEnterpriseSecuritySuite/ess_use_case_library)%0A2.%20%5BSplunk%20Security%20Content%5D(https://research.splunk.com/)", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}]}, {"id": "0e4796c9-bcb5-4837-b0cd-7c83b40dd2c3", "create_time": 1774464693.1934826, "update_time": 1774464693.1934834, "name": "Understand impact to the organization", "order": 2, "tasks": [{"id": "6dc2dedf-7fe4-4d02-bc74-4b386a320460", "create_time": 1764758755.940481, "update_time": 1774464693.1931124, "name": "Find potentially affected systems", "order": 1, "tag": "b5bcfe17-e8a5-40a0-984c-c8fefe77093c", "description": "Check%20the%20internal%20environment%20and%20dependencies%20of%20the%20organization%20for%20the%20software%20or%20hardware%20that%20is%20vulnerable.%0A%0ASuggested%20Dashboards%0A1.%20%5BTraffic%20Search%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/traffic_search)%0A2.%20%5BTraffic%20Size%20Analysis%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/traffic_size_analysis)%0A3.%20%5BPort%20and%20Protocol%20Tracker%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/port_protocol_tracker)%0A4.%20%5BEndpoint%20Changes%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/endpoint_changes)%0A5.%20%5BMalware%20Center%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/malware_center)%0A6.%20%5BRisk%20Analysis%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/risk_analysis)%0A7.%20%5BAsset%20and%20Risk%20Intelligence%5D(https://splunkbase.splunk.com/app/7180)", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "26f32c1e-5de3-4565-9a72-c17aa0dfee4e", "create_time": 1764758755.9405725, "update_time": 1774464693.1932135, "name": "Determine exploitability", "order": 2, "tag": "9b967031-b163-4c25-a971-011f10df8051", "description": "Check%20for%20exploitable%20conditions.%20If%20appropriate,%20attempt%20to%20implement%20the%20vulnerability%20or%20use%20a%20safe%20proof%20of%20concept%20to%20verify%20exploitability.%0A%0ASuggested%20Integration%20(%20if%20not%20already%20configured%20navigate%20%5BHERE%5D(/app/SplunkEnterpriseSecuritySuite/ess_configuration/#/soar/soar_apps/apps)%20to%20locate%20and%20configure)%0A1.%20Splunk%20Attack%20Analyzer", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [{"id": "8736df4b-5177-41d8-be93-b68f394b0812", "create_time": 1774464407.0508225, "update_time": 1774464693.19329, "last_job_id": 0, "name": "detonate file - Splunk Attack Analyzer Connector for Splunk SOAR", "action": "8939", "description": "Submit File for Scanning", "type": "detonate file", "app_id": 283, "asset": 23, "parameters": [{"file": "", "ph_0": "", "profile": "", "user_agent": "", "internet_region": "", "archive_password": "", "custom_user_agent": ""}]}, {"id": "470423f5-951c-4a34-ad8e-772f8ce4dbaa", "create_time": 1774464407.050864, "update_time": 1774464693.1933255, "last_job_id": 0, "name": "detonate url - Splunk Attack Analyzer Connector for Splunk SOAR", "action": "8940", "description": "Submit New URL for Scanning", "type": "detonate url", "app_id": 283, "asset": 23, "parameters": [{"url": "", "ph_0": "", "profile": "", "user_agent": "", "internet_region": "", "archive_password": "", "custom_user_agent": ""}]}, {"id": "7bee2271-65b5-4fef-9548-17e35ce0c226", "create_time": 1774464407.0509033, "update_time": 1774464693.1933591, "last_job_id": 0, "name": "get job summary - Splunk Attack Analyzer Connector for Splunk SOAR", "action": "8937", "description": "Get a job summary for a submitted job", "type": "get job summary", "app_id": 283, "asset": 23, "parameters": [{"job_id": "", "timeout": ""}]}], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "1f4e957a-1bc6-4b22-b222-44c845454b45", "create_time": 1764758755.9406626, "update_time": 1774464693.193417, "name": "Investigate possible exploitation", "order": 3, "tag": "b944edaa-aa8a-4877-8b78-f022580d2731", "description": "Investigate%20whether%20or%20not%20vulnerable%20systems%20were%20exploited.%20Use%20the%20particular%20behavior%20of%20the%20exploit%20and%20likely%20post-exploitation%20techniques%20to%20narrow%20down%20the%20search%20for%20exploited%20systems.%0A%0ASuggested%20Dashboards%0A1.%20%5BTraffic%20Search%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/traffic_search)%0A2.%20%5BTraffic%20Size%20Analysis%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/traffic_size_analysis)%0A3.%20%5BPort%20and%20Protocol%20Tracker%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/port_protocol_tracker)%0A4.%20%5BEndpoint%20Changes%20%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/endpoint_changes)%0A5.%20%5BMalware%20Center%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/malware_center)%0A6.%20%5BRisk%20Analysis%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/risk_analysis)", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}]}, {"id": "e8928704-4ba7-41c1-abba-a0444d548fe0", "create_time": 1774464693.1936033, "update_time": 1774464693.1936038, "name": "Decide how to respond", "order": 3, "tasks": [{"id": "860d180e-5d53-4eb7-b867-97ad48f470e6", "create_time": 1764758755.9407957, "update_time": 1774464693.193548, "name": "Evaluate patches, workarounds, and service outages", "order": 1, "tag": "23a1b3d3-d2db-40d9-9a96-39a154c94ff0", "description": "Consider%20how%20mitigations,%20remediations,%20and%20forced%20system%20shutdowns%20affect%20the%20situation.%0A%0ASuggested%20Dashboards%0A1.%20%5BUpdate%20Center%20Dashboard%5D(/app/SplunkEnterpriseSecuritySuite/update_center)%0A2.%20%5BAsset%20and%20Risk%20Intelligence%5D(https://splunkbase.splunk.com/app/7180)", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}]}, {"id": "1559a28c-3e76-4910-a22e-f5e6977d0647", "create_time": 1774464693.194012, "update_time": 1774464693.1940124, "name": "Execute the response", "order": 4, "tasks": [{"id": "1d4394f7-8781-4802-a6a2-7d77b655a9ee", "create_time": 1764758755.9409366, "update_time": 1774464693.1936662, "name": "Remediate", "order": 1, "tag": "6e13819e-dfdf-4e48-90fa-95c7ddfc139c", "description": "Apply%20patches,%20upgrades,%20configuration%20changes,%20or%20state%20changes%20that%20can%20remediate%20the%20vulnerability.%0A%0ASuggested%20Integration%20(%20if%20not%20already%20configured%20navigate%20%5BHERE%5D(/app/SplunkEnterpriseSecuritySuite/ess_configuration/#/soar/soar_apps/apps)%20to%20locate%20and%20configure)%0A1.%20Microsoft%20Defender%20for%20Endpoint%0A2.%20VMware%20Carbon%20Black%20Cloud%20for%20Splunk%20SOARSuggested%20Integrations%0A3.%20CrowdStrike", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [{"id": "e926a4e7-2488-4b16-83cf-e01351ad50fd", "create_time": 1774464650.6995573, "update_time": 1774464693.1937368, "last_job_id": 0, "name": "quarantine device - Carbon Black Response", "action": "8740", "description": "Quarantine the endpoint", "type": "quarantine device", "app_id": 48, "asset": 10, "parameters": [{"ip_hostname": ""}]}, {"id": "787f7317-c263-4cd1-b3ee-dc3de3ca4e76", "create_time": 1774464650.6995978, "update_time": 1774464693.193791, "last_job_id": 0, "name": "quarantine device - Windows Defender ATP", "action": "9016", "description": "Quarantine the device", "type": "quarantine device", "app_id": 191, "asset": 45, "parameters": [{"type": "", "comment": "", "timeout": "", "device_id": ""}]}, {"id": "45cfd51b-bff5-4685-b080-d0ffb74afb54", "create_time": 1774464650.6996362, "update_time": 1774464693.193826, "last_job_id": 0, "name": "quarantine device - CrowdStrike OAuth API", "action": "8761", "description": "Block the device", "type": "quarantine device", "app_id": 77, "asset": 44, "parameters": [{"hostname": "", "device_id": ""}]}], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "43f50b91-ee22-4731-a5fe-c6b4463134cf", "create_time": 1764758755.941027, "update_time": 1774464693.1938844, "name": "Mitigate", "order": 2, "tag": "5c813f0c-e55c-492a-933b-59b99ad11071", "description": "Apply%20workarounds,%20temporary%20fixes,%20additional%20hardening,%20new%20security%20tools,%20new%20detections,%20and%20other%20mitigations%20to%20reduce%20risk.%0A%0A", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}, {"id": "90f60618-b458-4baa-ae0d-af0fe1c4b3ec", "create_time": 1764758755.941116, "update_time": 1774464693.19397, "name": "Document accepted risks", "order": 3, "tag": "47c9830a-c0e1-4b75-ae76-4b5e0cddbf5c", "description": "Document remaining risk and notify stakeholders.", "owner": "", "is_note_required": false, "status": "Pending", "notes": [], "files": [], "suggestions": {"playbooks": [], "actions": [], "searches": []}, "start_time": 0, "end_time": 0, "total_time_taken": 0}]}], "origin": {"id": "83c7c93e-eb22-4a6c-981f-d7a857b71dfc", "name": "Vulnerability Disclosure", "version": 3}, "template_id": "3be24fbf-0c0c-402f-9382-df053ab6e698", "active": true, "used": false, "ai_generated": false, "source_attachment_id": null, "_user": "nobody", "_key": "fa831ce6-8899-4fb5-8e53-95048dc18b1b"} |