mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
3b58b30516
Adding custom functions & playbooks
2329 lines
112 KiB
JSON
2329 lines
112 KiB
JSON
{
|
|
"blockly": false,
|
|
"blockly_xml": "<xml></xml>",
|
|
"category": "Use Cases",
|
|
"coa": {
|
|
"data": {
|
|
"clean": true,
|
|
"code_block": "from random import randint\nfrom random import shuffle",
|
|
"description": "This playbook resets the password of a potentially compromised user account. First, an analyst is prompted to evaluate the situation and choose whether to reset the account. If they approve, a strong password is generated and the password is reset.",
|
|
"joint": {
|
|
"cells": [
|
|
{
|
|
"attrs": {
|
|
".connection": {
|
|
"stroke": "#818D99",
|
|
"stroke-width": 2
|
|
},
|
|
".marker-target": {
|
|
"d": "M 10 0 L 0 5 L 10 10 z",
|
|
"fill": "#818D99",
|
|
"stroke": "#818D99"
|
|
}
|
|
},
|
|
"connector": {
|
|
"args": {
|
|
"radius": 5
|
|
},
|
|
"name": "rounded"
|
|
},
|
|
"endDirections": [
|
|
"left"
|
|
],
|
|
"id": "27ea0953-b4ce-4902-8ece-63e24eae1d1e",
|
|
"router": {
|
|
"name": "metro"
|
|
},
|
|
"source": {
|
|
"id": "23da15dd-a900-4675-80fc-8278f452b007",
|
|
"port": null,
|
|
"selector": "g:nth-child(1) > g:nth-child(2) > g:nth-child(1) > circle:nth-child(1)"
|
|
},
|
|
"startDirections": [
|
|
"right"
|
|
],
|
|
"target": {
|
|
"id": "3ba40b74-3829-4cf7-8a11-6df171d3f874",
|
|
"selector": ".port-body[type=\"input\"]"
|
|
},
|
|
"type": "link",
|
|
"z": 14
|
|
},
|
|
{
|
|
"attrs": {
|
|
".connection": {
|
|
"stroke": "#818D99",
|
|
"stroke-width": 2
|
|
},
|
|
".marker-target": {
|
|
"d": "M 10 0 L 0 5 L 10 10 z",
|
|
"fill": "#818D99",
|
|
"stroke": "#818D99"
|
|
}
|
|
},
|
|
"connector": {
|
|
"args": {
|
|
"radius": 5
|
|
},
|
|
"name": "rounded"
|
|
},
|
|
"endDirections": [
|
|
"left"
|
|
],
|
|
"id": "6dd2b606-b2ce-4ffb-8131-c0acc1a1ffe0",
|
|
"router": {
|
|
"name": "metro"
|
|
},
|
|
"source": {
|
|
"id": "3ba40b74-3829-4cf7-8a11-6df171d3f874",
|
|
"port": "out-1",
|
|
"selector": "g:nth-child(1) > g:nth-child(2) > g:nth-child(1) > circle:nth-child(1)"
|
|
},
|
|
"startDirections": [
|
|
"right"
|
|
],
|
|
"target": {
|
|
"id": "7cecdc7c-0289-4151-be2f-87a24bd0b1da",
|
|
"port": null,
|
|
"selector": "g:nth-child(1) > g:nth-child(1) > g:nth-child(1) > circle:nth-child(1)"
|
|
},
|
|
"type": "link",
|
|
"z": 16
|
|
},
|
|
{
|
|
"attrs": {
|
|
".connection": {
|
|
"stroke": "#818D99",
|
|
"stroke-width": 2
|
|
},
|
|
".marker-target": {
|
|
"d": "M 10 0 L 0 5 L 10 10 z",
|
|
"fill": "#818D99",
|
|
"stroke": "#818D99"
|
|
}
|
|
},
|
|
"connector": {
|
|
"args": {
|
|
"radius": 5
|
|
},
|
|
"name": "rounded"
|
|
},
|
|
"endDirections": [
|
|
"left"
|
|
],
|
|
"id": "197ac0dd-c42a-43a2-a97c-8ee3120d9a6f",
|
|
"router": {
|
|
"name": "metro"
|
|
},
|
|
"source": {
|
|
"id": "7cecdc7c-0289-4151-be2f-87a24bd0b1da",
|
|
"port": null,
|
|
"selector": "g:nth-child(1) > g:nth-child(2) > g:nth-child(1) > circle:nth-child(1)"
|
|
},
|
|
"startDirections": [
|
|
"right"
|
|
],
|
|
"target": {
|
|
"id": "398259e5-8720-484b-a46b-ebe664b02687",
|
|
"selector": ".port-body[type=\"input\"]"
|
|
},
|
|
"type": "link",
|
|
"z": 17
|
|
},
|
|
{
|
|
"attrs": {
|
|
".connection": {
|
|
"stroke": "#818D99",
|
|
"stroke-width": 2
|
|
},
|
|
".marker-target": {
|
|
"d": "M 10 0 L 0 5 L 10 10 z",
|
|
"fill": "#818D99",
|
|
"stroke": "#818D99"
|
|
}
|
|
},
|
|
"connector": {
|
|
"args": {
|
|
"radius": 5
|
|
},
|
|
"name": "rounded"
|
|
},
|
|
"endDirections": [
|
|
"left"
|
|
],
|
|
"id": "c11890e9-62ac-43d6-9cef-8f2ed68f88b2",
|
|
"router": {
|
|
"name": "metro"
|
|
},
|
|
"source": {
|
|
"id": "398259e5-8720-484b-a46b-ebe664b02687",
|
|
"port": null,
|
|
"selector": "g:nth-child(1) > g:nth-child(2) > g:nth-child(1) > circle:nth-child(1)"
|
|
},
|
|
"startDirections": [
|
|
"right"
|
|
],
|
|
"target": {
|
|
"id": "fb2817ec-55f2-4baf-a578-4ea49fdae81a",
|
|
"port": null,
|
|
"selector": "g:nth-child(1) > g:nth-child(1) > g:nth-child(1) > circle:nth-child(1)"
|
|
},
|
|
"type": "link",
|
|
"z": 19
|
|
},
|
|
{
|
|
"attrs": {
|
|
".connection": {
|
|
"stroke": "#818D99",
|
|
"stroke-width": 2
|
|
},
|
|
".marker-target": {
|
|
"d": "M 10 0 L 0 5 L 10 10 z",
|
|
"fill": "#818D99",
|
|
"stroke": "#818D99"
|
|
}
|
|
},
|
|
"connector": {
|
|
"args": {
|
|
"radius": 5
|
|
},
|
|
"name": "rounded"
|
|
},
|
|
"endDirections": [
|
|
"left"
|
|
],
|
|
"id": "f1b0583c-1735-4c91-a6af-146682766127",
|
|
"router": {
|
|
"name": "metro"
|
|
},
|
|
"source": {
|
|
"id": "7cecdc7c-0289-4151-be2f-87a24bd0b1da",
|
|
"port": null,
|
|
"selector": "g:nth-child(1) > g:nth-child(2) > g:nth-child(1) > circle:nth-child(1)"
|
|
},
|
|
"startDirections": [
|
|
"right"
|
|
],
|
|
"target": {
|
|
"id": "5210febc-fbbb-4879-b338-c8f349c0a9c0",
|
|
"selector": ".port-body[type=\"input\"]"
|
|
},
|
|
"type": "link",
|
|
"z": 22
|
|
},
|
|
{
|
|
"attrs": {
|
|
".connection": {
|
|
"stroke": "#818D99",
|
|
"stroke-width": 2
|
|
},
|
|
".marker-target": {
|
|
"d": "M 10 0 L 0 5 L 10 10 z",
|
|
"fill": "#818D99",
|
|
"stroke": "#818D99"
|
|
}
|
|
},
|
|
"connector": {
|
|
"args": {
|
|
"radius": 5
|
|
},
|
|
"name": "rounded"
|
|
},
|
|
"endDirections": [
|
|
"left"
|
|
],
|
|
"id": "10428cae-be4e-46dc-99c8-88724df2b0e9",
|
|
"router": {
|
|
"name": "metro"
|
|
},
|
|
"source": {
|
|
"id": "5210febc-fbbb-4879-b338-c8f349c0a9c0",
|
|
"port": null,
|
|
"selector": "g:nth-child(1) > g:nth-child(2) > g:nth-child(1) > circle:nth-child(1)"
|
|
},
|
|
"startDirections": [
|
|
"right"
|
|
],
|
|
"target": {
|
|
"id": "10cc4157-7f8e-4dc0-91eb-22e60ff84c02",
|
|
"port": null,
|
|
"selector": "g:nth-child(1) > g:nth-child(1) > g:nth-child(1) > circle:nth-child(1)"
|
|
},
|
|
"type": "link",
|
|
"z": 24
|
|
},
|
|
{
|
|
"attrs": {
|
|
".connection": {
|
|
"stroke": "#818D99",
|
|
"stroke-width": 2
|
|
},
|
|
".marker-target": {
|
|
"d": "M 10 0 L 0 5 L 10 10 z",
|
|
"fill": "#818D99",
|
|
"stroke": "#818D99"
|
|
}
|
|
},
|
|
"connector": {
|
|
"args": {
|
|
"radius": 5
|
|
},
|
|
"name": "rounded"
|
|
},
|
|
"endDirections": [
|
|
"left"
|
|
],
|
|
"id": "54d586c2-b91a-47ca-8638-ae343466c5d2",
|
|
"router": {
|
|
"name": "metro"
|
|
},
|
|
"source": {
|
|
"id": "10cc4157-7f8e-4dc0-91eb-22e60ff84c02",
|
|
"port": null,
|
|
"selector": "g:nth-child(1) > g:nth-child(2) > g:nth-child(1) > circle:nth-child(1)"
|
|
},
|
|
"startDirections": [
|
|
"right"
|
|
],
|
|
"target": {
|
|
"id": "fb2817ec-55f2-4baf-a578-4ea49fdae81a",
|
|
"port": null,
|
|
"selector": "g:nth-child(1) > g:nth-child(1) > g:nth-child(1) > circle:nth-child(1)"
|
|
},
|
|
"type": "link",
|
|
"z": 25
|
|
},
|
|
{
|
|
"attrs": {
|
|
".connection": {
|
|
"stroke": "#818D99",
|
|
"stroke-width": 2
|
|
},
|
|
".marker-target": {
|
|
"d": "M 10 0 L 0 5 L 10 10 z",
|
|
"fill": "#818D99",
|
|
"stroke": "#818D99"
|
|
}
|
|
},
|
|
"connector": {
|
|
"args": {
|
|
"radius": 5
|
|
},
|
|
"name": "rounded"
|
|
},
|
|
"endDirections": [
|
|
"left"
|
|
],
|
|
"id": "84ef3f58-73e1-47b9-b331-04926d73c00e",
|
|
"router": {
|
|
"name": "metro"
|
|
},
|
|
"source": {
|
|
"id": "3ba40b74-3829-4cf7-8a11-6df171d3f874",
|
|
"port": "out-2",
|
|
"selector": "g:nth-child(1) > g:nth-child(2) > g:nth-child(2) > circle:nth-child(1)"
|
|
},
|
|
"startDirections": [
|
|
"right"
|
|
],
|
|
"target": {
|
|
"id": "456dd1f4-e8be-4f08-93e4-53340f34c3f5",
|
|
"selector": ".port-body[type=\"input\"]"
|
|
},
|
|
"type": "link",
|
|
"z": 27
|
|
},
|
|
{
|
|
"attrs": {
|
|
".connection": {
|
|
"stroke": "#818D99",
|
|
"stroke-width": 2
|
|
},
|
|
".marker-target": {
|
|
"d": "M 10 0 L 0 5 L 10 10 z",
|
|
"fill": "#818D99",
|
|
"stroke": "#818D99"
|
|
}
|
|
},
|
|
"connector": {
|
|
"args": {
|
|
"radius": 5
|
|
},
|
|
"name": "rounded"
|
|
},
|
|
"endDirections": [
|
|
"left"
|
|
],
|
|
"id": "dceb1651-6554-4b0a-90a5-366e0dae1c79",
|
|
"router": {
|
|
"name": "metro"
|
|
},
|
|
"source": {
|
|
"id": "456dd1f4-e8be-4f08-93e4-53340f34c3f5",
|
|
"port": null,
|
|
"selector": "g:nth-child(1) > g:nth-child(2) > g:nth-child(1) > circle:nth-child(1)"
|
|
},
|
|
"startDirections": [
|
|
"right"
|
|
],
|
|
"target": {
|
|
"id": "bf0b85aa-0086-4b5d-a690-281f55555dd3",
|
|
"selector": ".port-body[type=\"input\"]"
|
|
},
|
|
"type": "link",
|
|
"z": 29
|
|
},
|
|
{
|
|
"attrs": {
|
|
".connection": {
|
|
"stroke": "#818D99",
|
|
"stroke-width": 2
|
|
},
|
|
".marker-target": {
|
|
"d": "M 10 0 L 0 5 L 10 10 z",
|
|
"fill": "#818D99",
|
|
"stroke": "#818D99"
|
|
}
|
|
},
|
|
"connector": {
|
|
"args": {
|
|
"radius": 5
|
|
},
|
|
"name": "rounded"
|
|
},
|
|
"endDirections": [
|
|
"left"
|
|
],
|
|
"id": "760bf213-d7a5-41e9-a385-e8927d27fc93",
|
|
"router": {
|
|
"name": "metro"
|
|
},
|
|
"source": {
|
|
"id": "bf0b85aa-0086-4b5d-a690-281f55555dd3",
|
|
"port": null,
|
|
"selector": "g:nth-child(1) > g:nth-child(2) > g:nth-child(1) > circle:nth-child(1)"
|
|
},
|
|
"startDirections": [
|
|
"right"
|
|
],
|
|
"target": {
|
|
"id": "fb2817ec-55f2-4baf-a578-4ea49fdae81a",
|
|
"port": null,
|
|
"selector": "g:nth-child(1) > g:nth-child(1) > g:nth-child(1) > circle:nth-child(1)"
|
|
},
|
|
"type": "link",
|
|
"z": 31
|
|
},
|
|
{
|
|
"attrs": {
|
|
".connection": {
|
|
"stroke": "#818D99",
|
|
"stroke-width": 2
|
|
},
|
|
".marker-target": {
|
|
"d": "M 10 0 L 0 5 L 10 10 z",
|
|
"fill": "#818D99",
|
|
"stroke": "#818D99"
|
|
}
|
|
},
|
|
"connector": {
|
|
"args": {
|
|
"radius": 5
|
|
},
|
|
"name": "rounded"
|
|
},
|
|
"endDirections": [
|
|
"left"
|
|
],
|
|
"id": "20b16b2c-253c-41e7-8a12-9d4f83285c17",
|
|
"router": {
|
|
"name": "metro"
|
|
},
|
|
"source": {
|
|
"id": "83d4f311-84e7-42df-bca6-0fcb9ba484d7",
|
|
"port": null,
|
|
"selector": "g:nth-child(1) > g:nth-child(2) > g:nth-child(1) > circle:nth-child(1)"
|
|
},
|
|
"startDirections": [
|
|
"right"
|
|
],
|
|
"target": {
|
|
"id": "23da15dd-a900-4675-80fc-8278f452b007",
|
|
"port": null,
|
|
"selector": "g:nth-child(1) > g:nth-child(1) > g:nth-child(1) > circle:nth-child(1)"
|
|
},
|
|
"type": "link",
|
|
"z": 58
|
|
},
|
|
{
|
|
"0": "S",
|
|
"1": "T",
|
|
"2": "A",
|
|
"3": "R",
|
|
"4": "T",
|
|
"active": false,
|
|
"angle": 0,
|
|
"attrs": {
|
|
".background": {
|
|
"fill": "#000000",
|
|
"stroke": "#5C6773"
|
|
},
|
|
".color-band": {
|
|
"fill": "#3C444D"
|
|
},
|
|
".outPorts>.port-out": {
|
|
"ref": ".background",
|
|
"ref-x": 0.5
|
|
},
|
|
".outPorts>.port-out>.port-body": {
|
|
"port": {
|
|
"id": "out",
|
|
"type": "out"
|
|
}
|
|
},
|
|
".title": {
|
|
"ref-x": 33,
|
|
"ref-y": 8,
|
|
"text": "START"
|
|
},
|
|
"g.code image": {
|
|
"xlink:href": "/inc/coa/img/block_icon_code_dark_on.svg"
|
|
},
|
|
"g.delete": {
|
|
"display": "none"
|
|
},
|
|
"g.error": {
|
|
"opacity": 0
|
|
},
|
|
"g.icon image": {
|
|
"ref-x": 13,
|
|
"xlink:href": "/inc/coa/img/block_icon_start.svg"
|
|
},
|
|
"g.notes": {
|
|
"display": "block"
|
|
}
|
|
},
|
|
"block_code": "def on_start(container):\n phantom.debug('on_start() called')\n \n # call 'decision_2' block\n decision_2(container=container)\n\n return",
|
|
"callback_code": "# read-only block view not available",
|
|
"callback_start": 1,
|
|
"callsback": false,
|
|
"connected_to_start": true,
|
|
"connection_name": "",
|
|
"connection_type": "",
|
|
"custom_callback": "",
|
|
"custom_code": "def on_start(container):\n phantom.debug('on_start() called')\n\n reset_password(container=container)\n\n return",
|
|
"custom_join": "",
|
|
"custom_name": "",
|
|
"description": "",
|
|
"has_custom": true,
|
|
"has_custom_block": true,
|
|
"has_custom_callback": false,
|
|
"has_custom_join": false,
|
|
"id": "83d4f311-84e7-42df-bca6-0fcb9ba484d7",
|
|
"inPorts": [],
|
|
"join_code": "# read-only block view not available",
|
|
"join_optional": [],
|
|
"join_start": 1,
|
|
"line_end": 24,
|
|
"line_start": 17,
|
|
"name": "",
|
|
"notes": "",
|
|
"number": 0,
|
|
"order": 1,
|
|
"outPorts": [
|
|
"out"
|
|
],
|
|
"ports": {
|
|
"groups": {
|
|
"in": {
|
|
"attrs": {
|
|
".port-body": {
|
|
"fill": "#fff",
|
|
"magnet": true,
|
|
"r": 10,
|
|
"stroke": "#000"
|
|
},
|
|
".port-label": {
|
|
"fill": "#000"
|
|
}
|
|
},
|
|
"label": {
|
|
"position": {
|
|
"args": {
|
|
"y": 10
|
|
},
|
|
"name": "left"
|
|
}
|
|
},
|
|
"position": {
|
|
"name": "left"
|
|
}
|
|
},
|
|
"out": {
|
|
"attrs": {
|
|
".port-body": {
|
|
"fill": "#fff",
|
|
"magnet": true,
|
|
"r": 10,
|
|
"stroke": "#000"
|
|
},
|
|
".port-label": {
|
|
"fill": "#000"
|
|
}
|
|
},
|
|
"label": {
|
|
"position": {
|
|
"args": {
|
|
"y": 10
|
|
},
|
|
"name": "right"
|
|
}
|
|
},
|
|
"position": {
|
|
"name": "right"
|
|
}
|
|
}
|
|
}
|
|
},
|
|
"position": {
|
|
"x": 80,
|
|
"y": 100
|
|
},
|
|
"previous_function": "",
|
|
"previous_name": "",
|
|
"show_number": true,
|
|
"size": {
|
|
"height": 54,
|
|
"width": 80
|
|
},
|
|
"status": "",
|
|
"title": "START",
|
|
"type": "coa.StartEnd",
|
|
"warn": false,
|
|
"z": 120
|
|
},
|
|
{
|
|
"active": false,
|
|
"angle": 0,
|
|
"attrs": {
|
|
".background": {
|
|
"fill": "#000000",
|
|
"stroke": "#637282",
|
|
"transform": "rotate(45 30 70)"
|
|
},
|
|
".inPorts>.port-0>.port-body": {
|
|
"port": {
|
|
"id": "in",
|
|
"type": "in"
|
|
}
|
|
},
|
|
".number": {
|
|
"text": 1
|
|
},
|
|
".outPorts>.port-0": {
|
|
"port": {
|
|
"id": "out-1",
|
|
"type": "out"
|
|
},
|
|
"ref-x": 83,
|
|
"ref-y": 40
|
|
},
|
|
".outPorts>.port-0>.port-body": {
|
|
"port": {
|
|
"id": "out-1",
|
|
"type": "out"
|
|
}
|
|
},
|
|
".outPorts>.port-1": {
|
|
"port": {
|
|
"id": "out-2",
|
|
"type": "out"
|
|
},
|
|
"ref-x": 41,
|
|
"ref-y": 82
|
|
},
|
|
".outPorts>.port-1>.port-body": {
|
|
"port": {
|
|
"id": "out-2",
|
|
"type": "out"
|
|
}
|
|
},
|
|
"g.delete": {
|
|
"display": "none"
|
|
},
|
|
"g.error": {
|
|
"opacity": 0
|
|
},
|
|
"g.error image": {
|
|
"xlink:href": "/inc/coa/img/block_icon_warn.svg"
|
|
},
|
|
"g.notes": {
|
|
"display": "block"
|
|
},
|
|
"g.notes image": {
|
|
"opacity": 1,
|
|
"xlink:href": "/inc/coa/img/block_icon_note_dark_on.svg"
|
|
}
|
|
},
|
|
"block_code": "def reset_option(action=None, success=None, container=None, results=None, handle=None, filtered_artifacts=None, filtered_results=None, custom_function=None, **kwargs):\n phantom.debug('reset_option() called')\n\n # check for 'if' condition 1\n matched = phantom.decision(\n container=container,\n action_results=results,\n conditions=[\n [\"reset_password:action_result.summary.responses.0\", \"==\", \"Yes\"],\n ])\n\n # call connected blocks if condition 1 matched\n if matched:\n generate_password(action=action, success=success, container=container, results=results, handle=handle, custom_function=custom_function)\n return\n\n # call connected blocks for 'else' condition 2\n format_decline_msg(action=action, success=success, container=container, results=results, handle=handle, custom_function=custom_function)\n\n return",
|
|
"callback_code": "",
|
|
"callback_start": 1,
|
|
"callsback": false,
|
|
"connected_to_start": true,
|
|
"connection_name": "reset password",
|
|
"connection_type": "action",
|
|
"custom_callback": "",
|
|
"custom_code": "",
|
|
"custom_join": "",
|
|
"custom_name": "reset option",
|
|
"description": "",
|
|
"hasElse": true,
|
|
"has_custom": false,
|
|
"has_custom_block": false,
|
|
"has_custom_callback": false,
|
|
"has_custom_join": false,
|
|
"id": "3ba40b74-3829-4cf7-8a11-6df171d3f874",
|
|
"inPorts": [
|
|
"in"
|
|
],
|
|
"join_code": "",
|
|
"join_optional": [],
|
|
"join_start": 1,
|
|
"line_end": 113,
|
|
"line_start": 92,
|
|
"name": "decision",
|
|
"notes": "Follow direction of the prompt for resetting the user's password\n\nGREEN: Proceed with reset\nPURPLE: Proceed to end (with notes)",
|
|
"number": 1,
|
|
"order": 4,
|
|
"outPorts": [
|
|
"out-1",
|
|
"out-2"
|
|
],
|
|
"outputs": [
|
|
{
|
|
"conditions": [
|
|
{
|
|
"comparison": "==",
|
|
"data_type": "",
|
|
"param": "reset_password:action_result.summary.responses.0",
|
|
"value": "Yes"
|
|
}
|
|
],
|
|
"display": "If",
|
|
"logic": "and",
|
|
"type": "if"
|
|
},
|
|
{
|
|
"conditions": [
|
|
{
|
|
"comparison": "==",
|
|
"data_type": "",
|
|
"param": "",
|
|
"value": ""
|
|
}
|
|
],
|
|
"display": "Else",
|
|
"logic": "and",
|
|
"type": "else"
|
|
}
|
|
],
|
|
"ports": {
|
|
"groups": {
|
|
"in": {
|
|
"attrs": {
|
|
".port-body": {
|
|
"fill": "#fff",
|
|
"magnet": true,
|
|
"r": 10,
|
|
"stroke": "#000"
|
|
},
|
|
".port-label": {
|
|
"fill": "#000"
|
|
}
|
|
},
|
|
"label": {
|
|
"position": {
|
|
"args": {
|
|
"y": 10
|
|
},
|
|
"name": "left"
|
|
}
|
|
},
|
|
"position": {
|
|
"name": "left"
|
|
}
|
|
},
|
|
"out": {
|
|
"attrs": {
|
|
".port-body": {
|
|
"fill": "#fff",
|
|
"magnet": true,
|
|
"r": 10,
|
|
"stroke": "#000"
|
|
},
|
|
".port-label": {
|
|
"fill": "#000"
|
|
}
|
|
},
|
|
"label": {
|
|
"position": {
|
|
"args": {
|
|
"y": 10
|
|
},
|
|
"name": "right"
|
|
}
|
|
},
|
|
"position": {
|
|
"name": "right"
|
|
}
|
|
}
|
|
}
|
|
},
|
|
"position": {
|
|
"x": 380,
|
|
"y": 80
|
|
},
|
|
"previous_function": "",
|
|
"previous_name": "reset_option",
|
|
"show_number": true,
|
|
"size": {
|
|
"height": 82,
|
|
"width": 82
|
|
},
|
|
"state": "decision",
|
|
"status": "",
|
|
"type": "coa.Decision",
|
|
"warn": "",
|
|
"z": 122
|
|
},
|
|
{
|
|
"active": false,
|
|
"angle": 0,
|
|
"attrs": {
|
|
".background": {
|
|
"fill": "#000000",
|
|
"stroke": "#5C6773"
|
|
},
|
|
".color-band": {
|
|
"fill": "#3C444D"
|
|
},
|
|
".format": {
|
|
"text": "format decline msg"
|
|
},
|
|
".inPorts>.port-in": {
|
|
"ref": ".background",
|
|
"ref-x": 0.5
|
|
},
|
|
".inPorts>.port-in>.port-body": {
|
|
"port": {
|
|
"id": "in",
|
|
"type": "in"
|
|
}
|
|
},
|
|
".message": {
|
|
"opacity": 0,
|
|
"text": "Configuring now"
|
|
},
|
|
".outPorts>.port-out-1": {
|
|
"ref": ".background",
|
|
"ref-x": 0.5
|
|
},
|
|
".outPorts>.port-out-1>.port-body": {
|
|
"port": {
|
|
"id": "out-1",
|
|
"type": "out"
|
|
}
|
|
},
|
|
".title": {
|
|
"text": "format"
|
|
},
|
|
"g.code image": {
|
|
"opacity": 1
|
|
},
|
|
"g.delete": {
|
|
"display": "none"
|
|
},
|
|
"g.error": {
|
|
"opacity": 0
|
|
},
|
|
"g.error image": {
|
|
"xlink:href": "/inc/coa/img/block_icon_warn.svg"
|
|
},
|
|
"g.notes": {
|
|
"display": "block"
|
|
},
|
|
"g.notes image": {
|
|
"opacity": 1,
|
|
"xlink:href": "/inc/coa/img/block_icon_note_dark_on.svg"
|
|
}
|
|
},
|
|
"block_code": "def format_decline_msg(action=None, success=None, container=None, results=None, handle=None, filtered_artifacts=None, filtered_results=None, custom_function=None, **kwargs):\n phantom.debug('format_decline_msg() called')\n \n template = \"\"\"Analyst declined to reset password for user: {0}\"\"\"\n\n # parameter list for template variable replacement\n parameters = [\n \"artifact:*.cef.compromisedUserName\",\n ]\n\n phantom.format(container=container, template=template, parameters=parameters, name=\"format_decline_msg\")\n\n add_comment_no_reset(container=container)\n\n return",
|
|
"callback_code": "",
|
|
"callback_start": 1,
|
|
"callsback": false,
|
|
"connected_to_start": true,
|
|
"connection_name": "reset password",
|
|
"connection_type": "action",
|
|
"custom_callback": "",
|
|
"custom_code": "",
|
|
"custom_join": "",
|
|
"custom_name": "format decline msg",
|
|
"description": "Formats a message stating the user declined to reset the password",
|
|
"format": "format",
|
|
"has_custom": false,
|
|
"has_custom_block": false,
|
|
"has_custom_callback": false,
|
|
"has_custom_join": false,
|
|
"id": "456dd1f4-e8be-4f08-93e4-53340f34c3f5",
|
|
"inPorts": [
|
|
"in"
|
|
],
|
|
"join_code": "",
|
|
"join_optional": [],
|
|
"join_start": 1,
|
|
"line_end": 189,
|
|
"line_start": 173,
|
|
"message": "Configuring now",
|
|
"name": "format",
|
|
"notes": "Formats a message stating the user declined to reset the password",
|
|
"number": 2,
|
|
"order": 8,
|
|
"outPorts": [
|
|
"out-1"
|
|
],
|
|
"parameters": [
|
|
{
|
|
"position": 0,
|
|
"type": "",
|
|
"value": "artifact:*.cef.compromisedUserName"
|
|
}
|
|
],
|
|
"ports": {
|
|
"groups": {
|
|
"in": {
|
|
"attrs": {
|
|
".port-body": {
|
|
"fill": "#fff",
|
|
"magnet": true,
|
|
"r": 10,
|
|
"stroke": "#000"
|
|
},
|
|
".port-label": {
|
|
"fill": "#000"
|
|
}
|
|
},
|
|
"label": {
|
|
"position": {
|
|
"args": {
|
|
"y": 10
|
|
},
|
|
"name": "left"
|
|
}
|
|
},
|
|
"position": {
|
|
"name": "left"
|
|
}
|
|
},
|
|
"out": {
|
|
"attrs": {
|
|
".port-body": {
|
|
"fill": "#fff",
|
|
"magnet": true,
|
|
"r": 10,
|
|
"stroke": "#000"
|
|
},
|
|
".port-label": {
|
|
"fill": "#000"
|
|
}
|
|
},
|
|
"label": {
|
|
"position": {
|
|
"args": {
|
|
"y": 10
|
|
},
|
|
"name": "right"
|
|
}
|
|
},
|
|
"position": {
|
|
"name": "right"
|
|
}
|
|
}
|
|
}
|
|
},
|
|
"position": {
|
|
"x": 520,
|
|
"y": 220
|
|
},
|
|
"previous_function": "",
|
|
"previous_name": "format_decline_msg",
|
|
"show_number": true,
|
|
"size": {
|
|
"height": 100,
|
|
"width": 180
|
|
},
|
|
"state": "format",
|
|
"status": "",
|
|
"template": "Analyst declined to reset password for user: {0}",
|
|
"title": "format",
|
|
"type": "coa.Format",
|
|
"warn": false,
|
|
"z": 127
|
|
},
|
|
{
|
|
"active": false,
|
|
"angle": 0,
|
|
"api": "add comment",
|
|
"attrs": {
|
|
".api": {
|
|
"text": "add comment no reset"
|
|
},
|
|
".background": {
|
|
"fill": "#000000",
|
|
"stroke": "#5C6773"
|
|
},
|
|
".color-band": {
|
|
"fill": "#3C444D"
|
|
},
|
|
".inPorts>.port-in": {
|
|
"ref": ".background",
|
|
"ref-x": 0.5
|
|
},
|
|
".inPorts>.port-in>.port-body": {
|
|
"port": {
|
|
"id": "in",
|
|
"type": "in"
|
|
}
|
|
},
|
|
".message": {
|
|
"opacity": 0,
|
|
"ref-x": 5,
|
|
"ref-y": 105,
|
|
"text": "Configuring now"
|
|
},
|
|
".outPorts>.port-out": {
|
|
"ref": ".background",
|
|
"ref-x": 0.5
|
|
},
|
|
".outPorts>.port-out>.port-body": {
|
|
"port": {
|
|
"id": "out",
|
|
"type": "out"
|
|
}
|
|
},
|
|
".title": {
|
|
"text": "API"
|
|
},
|
|
"g.code image": {
|
|
"opacity": 1
|
|
},
|
|
"g.delete": {
|
|
"display": "none"
|
|
},
|
|
"g.error": {
|
|
"opacity": 0
|
|
},
|
|
"g.error image": {
|
|
"xlink:href": "/inc/coa/img/block_icon_warn.svg"
|
|
},
|
|
"g.notes": {
|
|
"display": "block"
|
|
},
|
|
"g.notes image": {
|
|
"opacity": 1,
|
|
"xlink:href": "/inc/coa/img/block_icon_note_dark_on.svg"
|
|
}
|
|
},
|
|
"block_code": "def add_comment_no_reset(action=None, success=None, container=None, results=None, handle=None, filtered_artifacts=None, filtered_results=None, custom_function=None, **kwargs):\n phantom.debug('add_comment_no_reset() called')\n\n formatted_data_1 = phantom.get_format_data(name='format_decline_msg')\n\n phantom.comment(container=container, comment=formatted_data_1)\n\n return",
|
|
"callback_code": "",
|
|
"callback_start": 1,
|
|
"callsback": false,
|
|
"color": "",
|
|
"configured": [
|
|
{
|
|
"addCommentComment": "format_decline_msg:formatted_data",
|
|
"key": "add-comment"
|
|
}
|
|
],
|
|
"connected_to_start": true,
|
|
"connection_name": "reset password",
|
|
"connection_type": "action",
|
|
"custom_callback": "",
|
|
"custom_code": "",
|
|
"custom_join": "",
|
|
"custom_name": "add comment no reset",
|
|
"description": "Add the comment notifying the reader that the password reset was declined",
|
|
"has_custom": false,
|
|
"has_custom_block": false,
|
|
"has_custom_callback": false,
|
|
"has_custom_join": false,
|
|
"id": "bf0b85aa-0086-4b5d-a690-281f55555dd3",
|
|
"inPorts": [
|
|
"in"
|
|
],
|
|
"join_code": "",
|
|
"join_optional": [],
|
|
"join_start": 1,
|
|
"line_end": 201,
|
|
"line_start": 192,
|
|
"message": "Configuring now",
|
|
"name": "add comment",
|
|
"notes": "Add the comment notifying the reader that the password reset was declined",
|
|
"number": 3,
|
|
"order": 9,
|
|
"outPorts": [
|
|
"out"
|
|
],
|
|
"ports": {
|
|
"groups": {
|
|
"in": {
|
|
"attrs": {
|
|
".port-body": {
|
|
"fill": "#fff",
|
|
"magnet": true,
|
|
"r": 10,
|
|
"stroke": "#000"
|
|
},
|
|
".port-label": {
|
|
"fill": "#000"
|
|
}
|
|
},
|
|
"label": {
|
|
"position": {
|
|
"args": {
|
|
"y": 10
|
|
},
|
|
"name": "left"
|
|
}
|
|
},
|
|
"position": {
|
|
"name": "left"
|
|
}
|
|
},
|
|
"out": {
|
|
"attrs": {
|
|
".port-body": {
|
|
"fill": "#fff",
|
|
"magnet": true,
|
|
"r": 10,
|
|
"stroke": "#000"
|
|
},
|
|
".port-label": {
|
|
"fill": "#000"
|
|
}
|
|
},
|
|
"label": {
|
|
"position": {
|
|
"args": {
|
|
"y": 10
|
|
},
|
|
"name": "right"
|
|
}
|
|
},
|
|
"position": {
|
|
"name": "right"
|
|
}
|
|
}
|
|
}
|
|
},
|
|
"position": {
|
|
"x": 1000,
|
|
"y": 220
|
|
},
|
|
"previous_function": "",
|
|
"previous_name": "add_comment_no_reset",
|
|
"show_number": false,
|
|
"size": {
|
|
"height": 100,
|
|
"width": 180
|
|
},
|
|
"state": "api",
|
|
"status": "",
|
|
"title": "API",
|
|
"type": "coa.API",
|
|
"warn": false,
|
|
"z": 130
|
|
},
|
|
{
|
|
"active": false,
|
|
"angle": 0,
|
|
"attrs": {
|
|
".background": {
|
|
"fill": "#000000",
|
|
"stroke": "#5C6773"
|
|
},
|
|
".color-band": {
|
|
"fill": "#3C444D"
|
|
},
|
|
".format": {
|
|
"text": "format pwd message"
|
|
},
|
|
".inPorts>.port-in": {
|
|
"ref": ".background",
|
|
"ref-x": 0.5
|
|
},
|
|
".inPorts>.port-in>.port-body": {
|
|
"port": {
|
|
"id": "in",
|
|
"type": "in"
|
|
}
|
|
},
|
|
".message": {
|
|
"opacity": 0,
|
|
"text": "Configuring now"
|
|
},
|
|
".outPorts>.port-out-1": {
|
|
"ref": ".background",
|
|
"ref-x": 0.5
|
|
},
|
|
".outPorts>.port-out-1>.port-body": {
|
|
"port": {
|
|
"id": "out-1",
|
|
"type": "out"
|
|
}
|
|
},
|
|
".title": {
|
|
"text": "format"
|
|
},
|
|
"g.code image": {
|
|
"opacity": 1
|
|
},
|
|
"g.delete": {
|
|
"display": "none"
|
|
},
|
|
"g.error": {
|
|
"opacity": 0
|
|
},
|
|
"g.error image": {
|
|
"xlink:href": "/inc/coa/img/block_icon_warn.svg"
|
|
},
|
|
"g.notes": {
|
|
"display": "block"
|
|
},
|
|
"g.notes image": {
|
|
"opacity": 1,
|
|
"xlink:href": "/inc/coa/img/block_icon_note_dark_on.svg"
|
|
}
|
|
},
|
|
"block_code": "def format_pwd_message(action=None, success=None, container=None, results=None, handle=None, filtered_artifacts=None, filtered_results=None, custom_function=None, **kwargs):\n phantom.debug('format_pwd_message() called')\n \n template = \"\"\"Reset user {0} password to {1}\"\"\"\n\n # parameter list for template variable replacement\n parameters = [\n \"artifact:*.cef.compromisedUserName\",\n \"generate_password:custom_function:strong_password\",\n ]\n\n phantom.format(container=container, template=template, parameters=parameters, name=\"format_pwd_message\")\n\n add_comment_pwd_reset(container=container)\n\n return",
|
|
"callback_code": "",
|
|
"callback_start": 1,
|
|
"callsback": false,
|
|
"connected_to_start": true,
|
|
"connection_name": "reset password",
|
|
"connection_type": "action",
|
|
"custom_callback": "",
|
|
"custom_code": "",
|
|
"custom_join": "",
|
|
"custom_name": "format pwd message",
|
|
"description": "Formats a message about the password reset to provide in the comments",
|
|
"format": "format",
|
|
"has_custom": false,
|
|
"has_custom_block": false,
|
|
"has_custom_callback": false,
|
|
"has_custom_join": false,
|
|
"id": "5210febc-fbbb-4879-b338-c8f349c0a9c0",
|
|
"inPorts": [
|
|
"in"
|
|
],
|
|
"join_code": "",
|
|
"join_optional": [],
|
|
"join_start": 1,
|
|
"line_end": 170,
|
|
"line_start": 153,
|
|
"message": "Configuring now",
|
|
"name": "format",
|
|
"notes": "Formats a message about the password reset to provide in the comments",
|
|
"number": 1,
|
|
"order": 7,
|
|
"outPorts": [
|
|
"out-1"
|
|
],
|
|
"parameters": [
|
|
{
|
|
"position": 0,
|
|
"type": "",
|
|
"value": "artifact:*.cef.compromisedUserName"
|
|
},
|
|
{
|
|
"position": 1,
|
|
"type": "",
|
|
"value": "generate_password:custom_function:strong_password"
|
|
}
|
|
],
|
|
"ports": {
|
|
"groups": {
|
|
"in": {
|
|
"attrs": {
|
|
".port-body": {
|
|
"fill": "#fff",
|
|
"magnet": true,
|
|
"r": 10,
|
|
"stroke": "#000"
|
|
},
|
|
".port-label": {
|
|
"fill": "#000"
|
|
}
|
|
},
|
|
"label": {
|
|
"position": {
|
|
"args": {
|
|
"y": 10
|
|
},
|
|
"name": "left"
|
|
}
|
|
},
|
|
"position": {
|
|
"name": "left"
|
|
}
|
|
},
|
|
"out": {
|
|
"attrs": {
|
|
".port-body": {
|
|
"fill": "#fff",
|
|
"magnet": true,
|
|
"r": 10,
|
|
"stroke": "#000"
|
|
},
|
|
".port-label": {
|
|
"fill": "#000"
|
|
}
|
|
},
|
|
"label": {
|
|
"position": {
|
|
"args": {
|
|
"y": 10
|
|
},
|
|
"name": "right"
|
|
}
|
|
},
|
|
"position": {
|
|
"name": "right"
|
|
}
|
|
}
|
|
}
|
|
},
|
|
"position": {
|
|
"x": 760,
|
|
"y": -60
|
|
},
|
|
"previous_function": "",
|
|
"previous_name": "format_pwd_message",
|
|
"show_number": true,
|
|
"size": {
|
|
"height": 100,
|
|
"width": 180
|
|
},
|
|
"state": "format",
|
|
"status": "",
|
|
"template": "Reset user {0} password to {1}",
|
|
"title": "format",
|
|
"type": "coa.Format",
|
|
"warn": false,
|
|
"z": 132
|
|
},
|
|
{
|
|
"active": false,
|
|
"angle": 0,
|
|
"api": "add comment",
|
|
"attrs": {
|
|
".api": {
|
|
"text": "add comment pwd reset"
|
|
},
|
|
".background": {
|
|
"fill": "#000000",
|
|
"stroke": "#5C6773"
|
|
},
|
|
".color-band": {
|
|
"fill": "#3C444D"
|
|
},
|
|
".inPorts>.port-in": {
|
|
"ref": ".background",
|
|
"ref-x": 0.5
|
|
},
|
|
".inPorts>.port-in>.port-body": {
|
|
"port": {
|
|
"id": "in",
|
|
"type": "in"
|
|
}
|
|
},
|
|
".message": {
|
|
"opacity": 0,
|
|
"ref-x": 5,
|
|
"ref-y": 105,
|
|
"text": "Configuring now"
|
|
},
|
|
".outPorts>.port-out": {
|
|
"ref": ".background",
|
|
"ref-x": 0.5
|
|
},
|
|
".outPorts>.port-out>.port-body": {
|
|
"port": {
|
|
"id": "out",
|
|
"type": "out"
|
|
}
|
|
},
|
|
".title": {
|
|
"text": "API"
|
|
},
|
|
"g.code image": {
|
|
"opacity": 1
|
|
},
|
|
"g.delete": {
|
|
"display": "none"
|
|
},
|
|
"g.error": {
|
|
"opacity": 0
|
|
},
|
|
"g.error image": {
|
|
"xlink:href": "/inc/coa/img/block_icon_warn.svg"
|
|
},
|
|
"g.notes": {
|
|
"display": "block"
|
|
},
|
|
"g.notes image": {
|
|
"opacity": 1,
|
|
"xlink:href": "/inc/coa/img/block_icon_note_dark_on.svg"
|
|
}
|
|
},
|
|
"block_code": "def add_comment_pwd_reset(action=None, success=None, container=None, results=None, handle=None, filtered_artifacts=None, filtered_results=None, custom_function=None, **kwargs):\n phantom.debug('add_comment_pwd_reset() called')\n\n formatted_data_1 = phantom.get_format_data(name='format_pwd_message')\n\n phantom.comment(container=container, comment=formatted_data_1)\n\n return",
|
|
"callback_code": "",
|
|
"callback_start": 1,
|
|
"callsback": false,
|
|
"color": "",
|
|
"configured": [
|
|
{
|
|
"addCommentComment": "format_pwd_message:formatted_data",
|
|
"key": "add-comment"
|
|
}
|
|
],
|
|
"connected_to_start": true,
|
|
"connection_name": "reset password",
|
|
"connection_type": "action",
|
|
"custom_callback": "",
|
|
"custom_code": "",
|
|
"custom_join": "",
|
|
"custom_name": "add comment pwd reset",
|
|
"description": "",
|
|
"has_custom": false,
|
|
"has_custom_block": false,
|
|
"has_custom_callback": false,
|
|
"has_custom_join": false,
|
|
"id": "10cc4157-7f8e-4dc0-91eb-22e60ff84c02",
|
|
"inPorts": [
|
|
"in"
|
|
],
|
|
"join_code": "",
|
|
"join_optional": [],
|
|
"join_start": 1,
|
|
"line_end": 150,
|
|
"line_start": 141,
|
|
"message": "Configuring now",
|
|
"name": "add comment",
|
|
"notes": "This block adds a comment to the Activities pane stating which user had their password reset and the new password",
|
|
"number": 2,
|
|
"order": 6,
|
|
"outPorts": [
|
|
"out"
|
|
],
|
|
"ports": {
|
|
"groups": {
|
|
"in": {
|
|
"attrs": {
|
|
".port-body": {
|
|
"fill": "#fff",
|
|
"magnet": true,
|
|
"r": 10,
|
|
"stroke": "#000"
|
|
},
|
|
".port-label": {
|
|
"fill": "#000"
|
|
}
|
|
},
|
|
"label": {
|
|
"position": {
|
|
"args": {
|
|
"y": 10
|
|
},
|
|
"name": "left"
|
|
}
|
|
},
|
|
"position": {
|
|
"name": "left"
|
|
}
|
|
},
|
|
"out": {
|
|
"attrs": {
|
|
".port-body": {
|
|
"fill": "#fff",
|
|
"magnet": true,
|
|
"r": 10,
|
|
"stroke": "#000"
|
|
},
|
|
".port-label": {
|
|
"fill": "#000"
|
|
}
|
|
},
|
|
"label": {
|
|
"position": {
|
|
"args": {
|
|
"y": 10
|
|
},
|
|
"name": "right"
|
|
}
|
|
},
|
|
"position": {
|
|
"name": "right"
|
|
}
|
|
}
|
|
}
|
|
},
|
|
"position": {
|
|
"x": 1000,
|
|
"y": -60
|
|
},
|
|
"previous_function": "",
|
|
"previous_name": "add_comment_pwd_reset",
|
|
"show_number": false,
|
|
"size": {
|
|
"height": 100,
|
|
"width": 180
|
|
},
|
|
"state": "api",
|
|
"status": "",
|
|
"title": "API",
|
|
"type": "coa.API",
|
|
"warn": false,
|
|
"z": 135
|
|
},
|
|
{
|
|
"0": "E",
|
|
"1": "N",
|
|
"2": "D",
|
|
"active": false,
|
|
"angle": 0,
|
|
"attrs": {
|
|
".background": {
|
|
"fill": "#000000",
|
|
"stroke": "#5C6773"
|
|
},
|
|
".color-band": {
|
|
"fill": "#3C444D"
|
|
},
|
|
".inPorts>.port-in": {
|
|
"ref": ".background",
|
|
"ref-x": 0.5
|
|
},
|
|
".inPorts>.port-in>.port-body": {
|
|
"port": {
|
|
"id": "in",
|
|
"type": "in"
|
|
}
|
|
},
|
|
".title": {
|
|
"text": "END"
|
|
},
|
|
"g.delete": {
|
|
"display": "none"
|
|
},
|
|
"g.error": {
|
|
"opacity": 0
|
|
},
|
|
"g.icon image": {
|
|
"xlink:href": "/inc/coa/img/block_icon_end.svg"
|
|
},
|
|
"g.notes": {
|
|
"display": "block"
|
|
}
|
|
},
|
|
"block_code": "def on_finish(container, summary):\n phantom.debug('on_finish() called')\n # This function is called after all actions are completed.\n # summary of all the action and/or all details of actions\n # can be collected here.\n\n # summary_json = phantom.get_summary()\n # if 'result' in summary_json:\n # for action_result in summary_json['result']:\n # if 'action_run_id' in action_result:\n # action_results = phantom.get_action_results(action_run_id=action_result['action_run_id'], result_data=False, flatten=False)\n # phantom.debug(action_results)\n\n return",
|
|
"callback_code": "# read-only block view not available",
|
|
"callback_start": 1,
|
|
"callsback": false,
|
|
"connected_to_start": true,
|
|
"connection_name": "reset ad password, reset password, reset password",
|
|
"connection_type": "action",
|
|
"custom_callback": "",
|
|
"custom_code": "",
|
|
"custom_join": "",
|
|
"custom_name": "",
|
|
"description": "",
|
|
"has_custom": false,
|
|
"has_custom_block": false,
|
|
"has_custom_callback": false,
|
|
"has_custom_join": false,
|
|
"id": "fb2817ec-55f2-4baf-a578-4ea49fdae81a",
|
|
"inPorts": [
|
|
"in"
|
|
],
|
|
"join_code": "# read-only block view not available",
|
|
"join_optional": [],
|
|
"join_start": 1,
|
|
"line_end": 214,
|
|
"line_start": 201,
|
|
"name": "",
|
|
"notes": "",
|
|
"number": 0,
|
|
"order": 10,
|
|
"outPorts": [],
|
|
"ports": {
|
|
"groups": {
|
|
"in": {
|
|
"attrs": {
|
|
".port-body": {
|
|
"fill": "#fff",
|
|
"magnet": true,
|
|
"r": 10,
|
|
"stroke": "#000"
|
|
},
|
|
".port-label": {
|
|
"fill": "#000"
|
|
}
|
|
},
|
|
"label": {
|
|
"position": {
|
|
"args": {
|
|
"y": 10
|
|
},
|
|
"name": "left"
|
|
}
|
|
},
|
|
"position": {
|
|
"name": "left"
|
|
}
|
|
},
|
|
"out": {
|
|
"attrs": {
|
|
".port-body": {
|
|
"fill": "#fff",
|
|
"magnet": true,
|
|
"r": 10,
|
|
"stroke": "#000"
|
|
},
|
|
".port-label": {
|
|
"fill": "#000"
|
|
}
|
|
},
|
|
"label": {
|
|
"position": {
|
|
"args": {
|
|
"y": 10
|
|
},
|
|
"name": "right"
|
|
}
|
|
},
|
|
"position": {
|
|
"name": "right"
|
|
}
|
|
}
|
|
}
|
|
},
|
|
"position": {
|
|
"x": 1240,
|
|
"y": 180
|
|
},
|
|
"previous_function": "",
|
|
"previous_name": "",
|
|
"show_number": true,
|
|
"size": {
|
|
"height": 54,
|
|
"width": 80
|
|
},
|
|
"status": "",
|
|
"title": "END",
|
|
"type": "coa.StartEnd",
|
|
"warn": false,
|
|
"z": 137
|
|
},
|
|
{
|
|
"action": "set password",
|
|
"action_type": "contain",
|
|
"active": false,
|
|
"active_keys": {},
|
|
"active_values": {
|
|
"new_password": "generate_password:custom_function:strong_password",
|
|
"username": "artifact:*.cef.compromisedUserName"
|
|
},
|
|
"angle": 0,
|
|
"app": "",
|
|
"appid": "",
|
|
"approver": "",
|
|
"assets": [
|
|
{
|
|
"action": "set password",
|
|
"actions": [
|
|
"run query",
|
|
"list users",
|
|
"get system info",
|
|
"list services",
|
|
"get users",
|
|
"reset password",
|
|
"set password",
|
|
"get system attributes",
|
|
"get user attributes",
|
|
"set system attribute",
|
|
"change system ou",
|
|
"list user groups",
|
|
"enable user",
|
|
"disable user",
|
|
"test connectivity"
|
|
],
|
|
"active": true,
|
|
"app_name": "LDAP",
|
|
"app_version": "1.2.40",
|
|
"appid": "84110F27-6602-4DC8-A6F2-0311B1720BF8",
|
|
"asset_name": "active directory",
|
|
"config_type": "asset",
|
|
"count": 0,
|
|
"fields": {
|
|
"new_password": "generate_password:custom_function:strong_password",
|
|
"username": "artifact:*.cef.compromisedUserName"
|
|
},
|
|
"has_app": true,
|
|
"id": 22,
|
|
"loaded": false,
|
|
"missing": false,
|
|
"name": "active directory",
|
|
"output": [
|
|
{
|
|
"data_path": "action_result.status",
|
|
"data_type": "string",
|
|
"example_values": [
|
|
"success",
|
|
"failed"
|
|
]
|
|
},
|
|
{
|
|
"data_path": "action_result.parameter.new_password",
|
|
"data_type": "string",
|
|
"example_values": [
|
|
"abc@123"
|
|
]
|
|
},
|
|
{
|
|
"column_name": "Username",
|
|
"column_order": 0,
|
|
"contains": [
|
|
"user name",
|
|
"ldap distinguished name"
|
|
],
|
|
"data_path": "action_result.parameter.username",
|
|
"data_type": "string",
|
|
"example_values": [
|
|
"test_user3"
|
|
]
|
|
},
|
|
{
|
|
"data_path": "action_result.data",
|
|
"data_type": "string"
|
|
},
|
|
{
|
|
"data_path": "action_result.summary",
|
|
"data_type": "string"
|
|
},
|
|
{
|
|
"column_name": "Message",
|
|
"column_order": 1,
|
|
"data_path": "action_result.message",
|
|
"data_type": "string",
|
|
"example_values": [
|
|
"User password changed"
|
|
]
|
|
},
|
|
{
|
|
"data_path": "summary.total_objects",
|
|
"data_type": "numeric",
|
|
"example_values": [
|
|
1
|
|
]
|
|
},
|
|
{
|
|
"data_path": "summary.total_objects_successful",
|
|
"data_type": "numeric",
|
|
"example_values": [
|
|
1
|
|
]
|
|
}
|
|
],
|
|
"parameters": {
|
|
"new_password": {
|
|
"data_type": "string",
|
|
"default": null,
|
|
"description": "Password string to set",
|
|
"key": "new_password",
|
|
"order": 1,
|
|
"required": true
|
|
},
|
|
"username": {
|
|
"contains": [
|
|
"user name",
|
|
"ldap distinguished name"
|
|
],
|
|
"data_type": "string",
|
|
"default": null,
|
|
"description": "Username to change password of",
|
|
"key": "username",
|
|
"order": 0,
|
|
"primary": true,
|
|
"required": true
|
|
}
|
|
},
|
|
"product_name": "Windows Server",
|
|
"product_vendor": "Microsoft",
|
|
"targets": "22",
|
|
"type": "endpoint"
|
|
}
|
|
],
|
|
"attrs": {
|
|
".action": {
|
|
"text": "reset ad password"
|
|
},
|
|
".background": {
|
|
"fill": "#000000",
|
|
"stroke": "#5C6773"
|
|
},
|
|
".color-band": {
|
|
"fill": "#3C444D"
|
|
},
|
|
".inPorts>.port-in": {
|
|
"ref": ".background",
|
|
"ref-x": 0.5
|
|
},
|
|
".inPorts>.port-in>.port-body": {
|
|
"port": {
|
|
"id": "in",
|
|
"type": "in"
|
|
}
|
|
},
|
|
".message": {
|
|
"opacity": 0,
|
|
"ref-x": 5,
|
|
"ref-y": 105,
|
|
"text": "Configuring now"
|
|
},
|
|
".outPorts>.port-out": {
|
|
"ref": ".background",
|
|
"ref-x": 0.5
|
|
},
|
|
".outPorts>.port-out>.port-body": {
|
|
"port": {
|
|
"id": "out",
|
|
"type": "out"
|
|
}
|
|
},
|
|
".title": {
|
|
"text": "Contain"
|
|
},
|
|
"g.approver image": {
|
|
"opacity": 1
|
|
},
|
|
"g.code image": {
|
|
"opacity": 1
|
|
},
|
|
"g.delete": {
|
|
"display": "none"
|
|
},
|
|
"g.error": {
|
|
"opacity": 0
|
|
},
|
|
"g.error image": {
|
|
"xlink:href": "/inc/coa/img/block_icon_warn.svg"
|
|
},
|
|
"g.icon image": {
|
|
"xlink:href": "/inc/coa/img/block_icon_contain.svg"
|
|
},
|
|
"g.notes": {
|
|
"display": "block"
|
|
},
|
|
"g.notes image": {
|
|
"opacity": 1,
|
|
"xlink:href": "/inc/coa/img/block_icon_note_dark_on.svg"
|
|
},
|
|
"g.timer image": {
|
|
"opacity": 1
|
|
}
|
|
},
|
|
"block_code": "def reset_ad_password(action=None, success=None, container=None, results=None, handle=None, filtered_artifacts=None, filtered_results=None, custom_function=None, **kwargs):\n phantom.debug('reset_ad_password() called')\n \n #phantom.debug('Action: {0} {1}'.format(action['name'], ('SUCCEEDED' if success else 'FAILED')))\n \n generate_password__strong_password = json.loads(phantom.get_run_data(key='generate_password:strong_password'))\n # collect data for 'reset_ad_password' call\n container_data = phantom.collect2(container=container, datapath=['artifact:*.cef.compromisedUserName', 'artifact:*.id'])\n\n parameters = []\n \n # build parameters list for 'reset_ad_password' call\n for container_item in container_data:\n if container_item[0]:\n parameters.append({\n 'username': container_item[0],\n 'new_password': generate_password__strong_password,\n # context (artifact id) is added to associate results with the artifact\n 'context': {'artifact_id': container_item[1]},\n })\n\n phantom.act(action=\"set password\", parameters=parameters, assets=['active directory'], name=\"reset_ad_password\")\n\n return",
|
|
"callback_code": "",
|
|
"callback_start": 1,
|
|
"callsback": true,
|
|
"color": "",
|
|
"connected_to_start": true,
|
|
"connection_name": "reset password",
|
|
"connection_type": "action",
|
|
"custom_callback": "",
|
|
"custom_code": "",
|
|
"custom_join": "",
|
|
"custom_name": "reset ad password",
|
|
"delay": 0,
|
|
"description": "Reset the Active Directory password of the user to the generated password",
|
|
"has_custom": false,
|
|
"has_custom_block": false,
|
|
"has_custom_callback": false,
|
|
"has_custom_join": false,
|
|
"id": "398259e5-8720-484b-a46b-ebe664b02687",
|
|
"inPorts": [
|
|
"in"
|
|
],
|
|
"join_code": "",
|
|
"join_optional": [],
|
|
"join_start": 1,
|
|
"line_end": 141,
|
|
"line_start": 116,
|
|
"message": "Configuring now",
|
|
"name": "set password",
|
|
"notes": "Reset the Active Directory password of the user to the generated password",
|
|
"number": 1,
|
|
"order": 5,
|
|
"outPorts": [
|
|
"out"
|
|
],
|
|
"ports": {
|
|
"groups": {
|
|
"in": {
|
|
"attrs": {
|
|
".port-body": {
|
|
"fill": "#fff",
|
|
"magnet": true,
|
|
"r": 10,
|
|
"stroke": "#000"
|
|
},
|
|
".port-label": {
|
|
"fill": "#000"
|
|
}
|
|
},
|
|
"label": {
|
|
"position": {
|
|
"args": {
|
|
"y": 10
|
|
},
|
|
"name": "left"
|
|
}
|
|
},
|
|
"position": {
|
|
"name": "left"
|
|
}
|
|
},
|
|
"out": {
|
|
"attrs": {
|
|
".port-body": {
|
|
"fill": "#fff",
|
|
"magnet": true,
|
|
"r": 10,
|
|
"stroke": "#000"
|
|
},
|
|
".port-label": {
|
|
"fill": "#000"
|
|
}
|
|
},
|
|
"label": {
|
|
"position": {
|
|
"args": {
|
|
"y": 10
|
|
},
|
|
"name": "right"
|
|
}
|
|
},
|
|
"position": {
|
|
"name": "right"
|
|
}
|
|
}
|
|
}
|
|
},
|
|
"position": {
|
|
"x": 1000,
|
|
"y": 80
|
|
},
|
|
"previous_function": "",
|
|
"previous_name": "reset_ad_password",
|
|
"required_params": {
|
|
"new_password": true,
|
|
"username": true
|
|
},
|
|
"reviewer": "",
|
|
"show_number": false,
|
|
"size": {
|
|
"height": 100,
|
|
"width": 180
|
|
},
|
|
"state": "action_assets",
|
|
"status": "",
|
|
"title": "Contain",
|
|
"type": "coa.Action",
|
|
"warn": false,
|
|
"z": 138
|
|
},
|
|
{
|
|
"active": false,
|
|
"angle": 0,
|
|
"approver": "admin",
|
|
"attrs": {
|
|
".background": {
|
|
"fill": "#000000",
|
|
"stroke": "#5C6773"
|
|
},
|
|
".inPorts>.port-in": {
|
|
"ref": ".background",
|
|
"ref-x": 0.5
|
|
},
|
|
".inPorts>.port-in>.port-body": {
|
|
"port": {
|
|
"id": "in",
|
|
"type": "in"
|
|
}
|
|
},
|
|
".number": {
|
|
"text": 1
|
|
},
|
|
".outPorts>.port-out": {
|
|
"ref": ".background",
|
|
"ref-x": 0.5
|
|
},
|
|
".outPorts>.port-out>.port-body": {
|
|
"port": {
|
|
"id": "out",
|
|
"type": "out"
|
|
}
|
|
},
|
|
"g.delete": {
|
|
"display": "none"
|
|
},
|
|
"g.error": {
|
|
"opacity": 0
|
|
},
|
|
"g.error image": {
|
|
"xlink:href": "/inc/coa/img/block_icon_warn.svg"
|
|
},
|
|
"g.notes": {
|
|
"display": "block"
|
|
},
|
|
"g.notes image": {
|
|
"opacity": 1,
|
|
"xlink:href": "/inc/coa/img/block_icon_note_dark_on.svg"
|
|
}
|
|
},
|
|
"block_code": "def reset_password(action=None, success=None, container=None, results=None, handle=None, filtered_artifacts=None, filtered_results=None, custom_function=None, **kwargs):\n phantom.debug('reset_password() called')\n \n # set user and message variables for phantom.prompt call\n user = \"admin\"\n message = \"\"\"Found the account \\\"{0}\\\" has a compromised credential! Would you like to automatically reset the password?\"\"\"\n\n # parameter list for template variable replacement\n parameters = [\n \"artifact:*.cef.compromisedUserName\",\n ]\n\n #responses:\n response_types = [\n {\n \"prompt\": \"\",\n \"options\": {\n \"type\": \"list\",\n \"choices\": [\n \"Yes\",\n \"No\",\n ]\n },\n },\n ]\n\n phantom.prompt2(container=container, user=user, message=message, respond_in_mins=30, name=\"reset_password\", parameters=parameters, response_types=response_types, callback=reset_option)\n\n return",
|
|
"callback_code": "",
|
|
"callback_start": 1,
|
|
"callsback": true,
|
|
"connected_to_start": true,
|
|
"connection_name": "",
|
|
"connection_type": "",
|
|
"custom_callback": "",
|
|
"custom_code": "",
|
|
"custom_join": "",
|
|
"custom_name": "reset password",
|
|
"description": "",
|
|
"has_custom": false,
|
|
"has_custom_block": false,
|
|
"has_custom_callback": false,
|
|
"has_custom_join": false,
|
|
"id": "23da15dd-a900-4675-80fc-8278f452b007",
|
|
"inPorts": [
|
|
"in"
|
|
],
|
|
"join_code": "",
|
|
"join_optional": [],
|
|
"join_start": 1,
|
|
"line_end": 92,
|
|
"line_start": 62,
|
|
"message": "Found the account \"{0}\" has a compromised credential! Would you like to automatically reset the password?",
|
|
"name": "prompt",
|
|
"notes": "Prompts the user if they'd like to reset the password in Active Directory",
|
|
"number": 1,
|
|
"order": 3,
|
|
"outPorts": [
|
|
"out"
|
|
],
|
|
"parameters": [
|
|
{
|
|
"position": 0,
|
|
"type": "",
|
|
"value": "artifact:*.cef.compromisedUserName"
|
|
}
|
|
],
|
|
"ports": {
|
|
"groups": {
|
|
"in": {
|
|
"attrs": {
|
|
".port-body": {
|
|
"fill": "#fff",
|
|
"magnet": true,
|
|
"r": 10,
|
|
"stroke": "#000"
|
|
},
|
|
".port-label": {
|
|
"fill": "#000"
|
|
}
|
|
},
|
|
"label": {
|
|
"position": {
|
|
"args": {
|
|
"y": 10
|
|
},
|
|
"name": "left"
|
|
}
|
|
},
|
|
"position": {
|
|
"name": "left"
|
|
}
|
|
},
|
|
"out": {
|
|
"attrs": {
|
|
".port-body": {
|
|
"fill": "#fff",
|
|
"magnet": true,
|
|
"r": 10,
|
|
"stroke": "#000"
|
|
},
|
|
".port-label": {
|
|
"fill": "#000"
|
|
}
|
|
},
|
|
"label": {
|
|
"position": {
|
|
"args": {
|
|
"y": 10
|
|
},
|
|
"name": "right"
|
|
}
|
|
},
|
|
"position": {
|
|
"name": "right"
|
|
}
|
|
}
|
|
}
|
|
},
|
|
"position": {
|
|
"x": 240,
|
|
"y": 80
|
|
},
|
|
"previous_function": "",
|
|
"previous_name": "reset_password",
|
|
"respond_in": "30",
|
|
"response_key": "Message",
|
|
"response_options": [],
|
|
"response_type": "list",
|
|
"responses": [
|
|
{
|
|
"response_key": "Yes/No",
|
|
"response_options": [
|
|
"Yes",
|
|
"No"
|
|
],
|
|
"response_prompt": "",
|
|
"response_type": "list"
|
|
}
|
|
],
|
|
"show_number": true,
|
|
"size": {
|
|
"height": 80,
|
|
"width": 80
|
|
},
|
|
"state": "prompt",
|
|
"status": "",
|
|
"type": "coa.Prompt",
|
|
"warn": false,
|
|
"z": 139
|
|
},
|
|
{
|
|
"active": false,
|
|
"angle": 0,
|
|
"attrs": {
|
|
".background": {
|
|
"fill": "#000000",
|
|
"stroke": "#5C6773"
|
|
},
|
|
".color-band": {
|
|
"fill": "#3C444D"
|
|
},
|
|
".functionBlock": {
|
|
"text": "generate password"
|
|
},
|
|
".inPorts>.port-in": {
|
|
"ref": ".background",
|
|
"ref-x": 0.5
|
|
},
|
|
".inPorts>.port-in>.port-body": {
|
|
"port": {
|
|
"id": "in",
|
|
"type": "in"
|
|
}
|
|
},
|
|
".message": {
|
|
"opacity": 0,
|
|
"ref-x": 5,
|
|
"ref-y": 105,
|
|
"text": "Configuring now"
|
|
},
|
|
".outPorts>.port-out": {
|
|
"ref": ".background",
|
|
"ref-x": 0.5
|
|
},
|
|
".outPorts>.port-out>.port-body": {
|
|
"port": {
|
|
"id": "out",
|
|
"type": "out"
|
|
}
|
|
},
|
|
".title": {
|
|
"text": "custom function"
|
|
},
|
|
"g.delete": {
|
|
"display": "none"
|
|
},
|
|
"g.error": {
|
|
"opacity": 1
|
|
},
|
|
"g.error image": {
|
|
"xlink:href": "/inc/coa/img/block_icon_warn_grey.svg"
|
|
},
|
|
"g.notes": {
|
|
"display": "block"
|
|
},
|
|
"g.notes image": {
|
|
"opacity": 1,
|
|
"xlink:href": "/inc/coa/img/block_icon_note_dark_on.svg"
|
|
}
|
|
},
|
|
"block_code": "def generate_password(action=None, success=None, container=None, results=None, handle=None, filtered_artifacts=None, filtered_results=None, custom_function=None, **kwargs):\n phantom.debug('generate_password() called')\n \n input_parameter_0 = \"\"\n\n generate_password__strong_password = None\n\n ################################################################################\n ## Custom Code Start\n ################################################################################\n\n alpha = 'abcdefghijklmnopqrstuvwxyz'\n num = '0123456789'\n special = '!@#$%^&*('\n \n pwd = ''\n for i in range(5):\n pwd += alpha[randint(0, len(alpha)-1)]\n pwd += (alpha[randint(0, len(alpha)-1)]).upper()\n pwd += num[randint(0, len(num)-1)]\n pwd += special[randint(0, len(special)-1)]\n r = list(pwd)\n shuffle(r)\n generate_password__strong_password = ''.join(r)\n\n ################################################################################\n ## Custom Code End\n ################################################################################\n\n phantom.save_run_data(key='generate_password:strong_password', value=json.dumps(generate_password__strong_password))\n reset_ad_password(container=container)\n format_pwd_message(container=container)\n\n return",
|
|
"callback_code": "",
|
|
"callback_start": 1,
|
|
"callsback": false,
|
|
"connected_to_start": true,
|
|
"connection_name": "reset password",
|
|
"connection_type": "action",
|
|
"customCodeEndLineOffset": 8,
|
|
"customCodeStartLine": 10,
|
|
"custom_callback": "",
|
|
"custom_code": "def generate_password(action=None, success=None, container=None, results=None, handle=None, filtered_artifacts=None, filtered_results=None):\n phantom.debug('custom_function_1() called')\n input_parameter_0 = \"\"\n\n generate_password__strong_password = None\n\n ################################################################################\n ## Custom Code Start\n ################################################################################\n\n alpha = 'abcdefghijklmnopqrstuvwxyz'\n num = '0123456789'\n special = '!@#$%^&*('\n \n pwd = ''\n for i in range(5):\n pwd += alpha[randint(0, len(alpha)-1)]\n pwd += (alpha[randint(0, len(alpha)-1)]).upper()\n pwd += num[randint(0, len(num)-1)]\n pwd += special[randint(0, len(special)-1)]\n r = list(pwd)\n shuffle(r)\n generate_password__strong_password = ''.join(r)\n\n ################################################################################\n ## Custom Code End\n ################################################################################\n\n phantom.save_run_data(key='custom_function_1:strong_password', value=json.dumps(generate_password__strong_password))\n\n return",
|
|
"custom_join": "",
|
|
"custom_name": "generate password",
|
|
"description": "Custom code block that generates a strong random password",
|
|
"functionBlock": "custom function",
|
|
"has_custom": true,
|
|
"has_custom_block": false,
|
|
"has_custom_callback": false,
|
|
"has_custom_join": false,
|
|
"id": "7cecdc7c-0289-4151-be2f-87a24bd0b1da",
|
|
"inPorts": [
|
|
"in"
|
|
],
|
|
"join_code": "",
|
|
"join_optional": [],
|
|
"join_start": 1,
|
|
"legacy": true,
|
|
"line_end": 62,
|
|
"line_start": 27,
|
|
"message": "Configuring now",
|
|
"name": "custom function",
|
|
"notes": "Custom code block that generates a strong random password",
|
|
"number": 1,
|
|
"order": 2,
|
|
"outPorts": [
|
|
"out"
|
|
],
|
|
"outputVariables": [
|
|
{
|
|
"position": 0,
|
|
"type": "",
|
|
"value": "strong_password"
|
|
}
|
|
],
|
|
"parameters": [
|
|
{
|
|
"position": 0,
|
|
"type": "",
|
|
"value": ""
|
|
}
|
|
],
|
|
"ports": {
|
|
"groups": {
|
|
"in": {
|
|
"attrs": {
|
|
".port-body": {
|
|
"fill": "#fff",
|
|
"magnet": true,
|
|
"r": 10,
|
|
"stroke": "#000"
|
|
},
|
|
".port-label": {
|
|
"fill": "#000"
|
|
}
|
|
},
|
|
"label": {
|
|
"position": {
|
|
"args": {
|
|
"y": 10
|
|
},
|
|
"name": "left"
|
|
}
|
|
},
|
|
"position": {
|
|
"name": "left"
|
|
}
|
|
},
|
|
"out": {
|
|
"attrs": {
|
|
".port-body": {
|
|
"fill": "#fff",
|
|
"magnet": true,
|
|
"r": 10,
|
|
"stroke": "#000"
|
|
},
|
|
".port-label": {
|
|
"fill": "#000"
|
|
}
|
|
},
|
|
"label": {
|
|
"position": {
|
|
"args": {
|
|
"y": 10
|
|
},
|
|
"name": "right"
|
|
}
|
|
},
|
|
"position": {
|
|
"name": "right"
|
|
}
|
|
}
|
|
}
|
|
},
|
|
"position": {
|
|
"x": 520,
|
|
"y": 80
|
|
},
|
|
"previous_function": "",
|
|
"previous_name": "generate_password",
|
|
"show_number": true,
|
|
"size": {
|
|
"height": 100,
|
|
"width": 180
|
|
},
|
|
"state": "custom function",
|
|
"status": "deprecating",
|
|
"title": "custom function",
|
|
"type": "coa.FunctionBlock",
|
|
"userGeneratedCode": "\n alpha = 'abcdefghijklmnopqrstuvwxyz'\n num = '0123456789'\n special = '!@#$%^&*('\n \n pwd = ''\n for i in range(5):\n pwd += alpha[randint(0, len(alpha)-1)]\n pwd += (alpha[randint(0, len(alpha)-1)]).upper()\n pwd += num[randint(0, len(num)-1)]\n pwd += special[randint(0, len(special)-1)]\n r = list(pwd)\n shuffle(r)\n generate_password__strong_password = ''.join(r)\n",
|
|
"warn": false,
|
|
"z": 140
|
|
}
|
|
]
|
|
},
|
|
"notes": "This playbook uses the following Apps:\n - LDAP (set password) - reset the password of a user\n\nDeployment Notes:\n - This playbook works on artifacts with artifact:*.cef.compromisedUserName which can be created as shown in the playbook \"recorded_future_handle_leaked_credentials\"\n - The prompt is hard-coded to use \"admin\" as the user, so change it to the correct user or role"
|
|
},
|
|
"python_version": "3",
|
|
"schema": 4,
|
|
"version": "4.10.0.40677"
|
|
},
|
|
"create_time": "2020-12-08T16:37:21.322527+00:00",
|
|
"draft_mode": false,
|
|
"labels": [
|
|
"events"
|
|
],
|
|
"tags": [],
|
|
"misc": {
|
|
"apps_list": [
|
|
"LDAP"
|
|
]
|
|
}
|
|
} |