Files
splunk-security_content/docs/_playbooks/email_notification_for_malware.md
2022-03-10 10:27:29 +01:00

1.7 KiB

title, last_modified_at, toc, toc_label, tags
title last_modified_at toc toc_label tags
Email Notification for Malware 2021-01-19 true
Response
Splunk SOAR
VirusTotal
WildFire
CarbonBlack Response
SMTP

Try in Splunk SOAR{: .btn .btn--success}

Description

This playbook tries to determine if a file is malware and whether or not the file is present on any managed machines. VirusTotal "file reputation" and PAN WildFire "detonate file" are used to determine if a file is malware, and CarbonBlack Response "hunt file" is used to search managed machines for the file. The results of these investigations are summarized in an email to the incident response team.

Associated Detections

How To Implement

Be sure to update asset naming to reflect the asset names configured in your environment.

Playbooks

Required field

Reference

source | version: 1