mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
1.5 KiB
1.5 KiB
title, last_modified_at, toc, toc_label, tags
| title | last_modified_at | toc | toc_label | tags | |||
|---|---|---|---|---|---|---|---|
| Delete Detected Files | 2021-03-29 | true |
|
Try in Splunk SOAR{: .btn .btn--success}
Description
This playbook acts upon events where a file has been determined to be malicious (ie webshells being dropped on an end host). Before deleting the file, we run a "more" command on the file in question to extract its contents. We then run a delete on the file in question.
- Type: Response
- Product: Splunk SOAR
- Apps: [Windows Remote Management](https://splunkbase.splunk.com/apps/#/search/Windows Remote Management/product/soar)
- Last Updated: 2021-03-29
- Author: Philip Royer, Splunk
- ID: fc0edc96-ff2b-48b0-9a6f-63da6783fd63
Associated Detections
How To Implement
This playbook reads and then deletes files stored with artifact:.cef.filePath from hosts stored in artifact:.cef.destinationAddress. Windows Remote Management must be enabled on the remote computer.
Playbooks
Required field
Reference
source | version: 1
