Files
splunk-security_content/playbooks/activedirectory_reset_password.yml
2022-10-26 15:43:37 -05:00

20 lines
910 B
YAML

name: Active Directory Reset password
id: fc0edc96-ff2b-48b0-9f6f-63da6783fd63
version: 1
date: '2020-12-08'
author: Philip Royer, Splunk
type: Response
description: This playbook resets the password of a potentially compromised user account. First, an analyst is prompted to evaluate the situation and choose whether to reset the account. If they approve, a strong password is generated and the password is reset.
playbook: activedirectory_reset_password
how_to_implement: This playbook works on artifacts with artifact:*.cef.compromisedUserName which can be created as shown in the playbook "recorded_future_handle_leaked_credentials" - The prompt is hard-coded to use "admin" as the user, so change it to the correct user or role
references: []
app_list:
- "LDAP"
tags:
platform_tags: []
playbook_type: Automation
vpe_type: Classic
playbook_fields:
- compromisedUserName
product:
- Splunk SOAR