Files
splunk-security_content/docs/_playbooks/delete_detected_files.md
2022-03-22 21:43:34 -04:00

1.5 KiB

title, last_modified_at, toc, toc_label, tags
title last_modified_at toc toc_label tags
Delete Detected Files 2021-03-29 true
Response
Splunk SOAR
Windows Remote Management

Try in Splunk SOAR{: .btn .btn--success}

Description

This playbook acts upon events where a file has been determined to be malicious (ie webshells being dropped on an end host). Before deleting the file, we run a "more" command on the file in question to extract its contents. We then run a delete on the file in question.

Associated Detections

How To Implement

This playbook reads and then deletes files stored with artifact:.cef.filePath from hosts stored in artifact:.cef.destinationAddress. Windows Remote Management must be enabled on the remote computer.

Playbooks

Required field

Reference

source | version: 1