Files
splunk-security_content/playbooks/internal_host_ssh_log4j_respond.yml
2022-10-26 15:43:37 -05:00

20 lines
800 B
YAML

name: Internal Host SSH Log4j Response
id: 6ea2007c-8ef8-4647-a4a4-7825cfee3866
version: 1
date: '2021-12-14'
author: Kelby Shelton, Splunk
type: Response
description: Published in response to CVE-2021-44228, this playbook accepts a list of hosts and filenames to remediate on the endpoint. If filenames are provided, the endpoints will be searched and then the user can approve deletion. Then the user is prompted to quarantine the endpoint.
playbook: internal_host_ssh_log4j_respond
how_to_implement: The ssh asset may require ssh access to delete some files depending on their permissions.
references: ["https://github.com/Neo23x0/Fenrir/blob/master/fenrir.sh"]
app_list:
- "SSH"
tags:
platform_tags: []
playbook_type: Input
vpe_type: Modern
playbook_fields: []
product:
- Splunk SOAR