mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
283 lines
12 KiB
JSON
283 lines
12 KiB
JSON
{
|
|
"blockly": false,
|
|
"blockly_xml": "<xml></xml>",
|
|
"category": "Account Locking",
|
|
"coa": {
|
|
"data": {
|
|
"description": "Accepts user name that needs to be disabled in AWS IAM Active Directory. Disabling an account involves deleting their login profile which will clear the user's password. Generates an observable output based on the status of account locking or disabling.",
|
|
"edges": [
|
|
{
|
|
"id": "port_0_to_port_2",
|
|
"sourceNode": "0",
|
|
"sourcePort": "0_out",
|
|
"targetNode": "2",
|
|
"targetPort": "2_in"
|
|
},
|
|
{
|
|
"id": "port_6_to_port_1",
|
|
"sourceNode": "6",
|
|
"sourcePort": "6_out",
|
|
"targetNode": "1",
|
|
"targetPort": "1_in"
|
|
},
|
|
{
|
|
"id": "port_3_to_port_7",
|
|
"sourceNode": "3",
|
|
"sourcePort": "3_out",
|
|
"targetNode": "7",
|
|
"targetPort": "7_in"
|
|
},
|
|
{
|
|
"conditions": [
|
|
{
|
|
"index": 0
|
|
}
|
|
],
|
|
"id": "port_2_to_port_3",
|
|
"sourceNode": "2",
|
|
"sourcePort": "2_out",
|
|
"targetNode": "3",
|
|
"targetPort": "3_in"
|
|
},
|
|
{
|
|
"conditions": [
|
|
{
|
|
"index": 0
|
|
}
|
|
],
|
|
"id": "port_7_to_port_6",
|
|
"sourceNode": "7",
|
|
"sourcePort": "7_out",
|
|
"targetNode": "6",
|
|
"targetPort": "6_in"
|
|
}
|
|
],
|
|
"hash": "5cd799e95d456dc116881e04c82ec7bd2e783edc",
|
|
"nodes": {
|
|
"0": {
|
|
"data": {
|
|
"advanced": {
|
|
"join": []
|
|
},
|
|
"functionName": "on_start",
|
|
"id": "0",
|
|
"type": "start"
|
|
},
|
|
"errors": {},
|
|
"id": "0",
|
|
"type": "start",
|
|
"warnings": {},
|
|
"x": 19.999999999999986,
|
|
"y": -4.476419235288631e-13
|
|
},
|
|
"1": {
|
|
"data": {
|
|
"advanced": {
|
|
"join": []
|
|
},
|
|
"functionName": "on_finish",
|
|
"id": "1",
|
|
"type": "end"
|
|
},
|
|
"errors": {},
|
|
"id": "1",
|
|
"type": "end",
|
|
"warnings": {},
|
|
"x": 19.999999999999986,
|
|
"y": 860
|
|
},
|
|
"2": {
|
|
"data": {
|
|
"advanced": {
|
|
"customName": "username filter",
|
|
"customNameId": 0,
|
|
"description": "Filter user name inputs to route inputs to appropriate actions.",
|
|
"join": [],
|
|
"note": "Filter user name inputs to route inputs to appropriate actions."
|
|
},
|
|
"conditions": [
|
|
{
|
|
"comparisons": [
|
|
{
|
|
"conditionIndex": 0,
|
|
"op": "!=",
|
|
"param": "playbook_input:user",
|
|
"value": ""
|
|
}
|
|
],
|
|
"conditionIndex": 0,
|
|
"customName": "username_filter",
|
|
"logic": "and"
|
|
}
|
|
],
|
|
"functionId": 1,
|
|
"functionName": "username_filter",
|
|
"id": "2",
|
|
"type": "filter"
|
|
},
|
|
"errors": {},
|
|
"id": "2",
|
|
"type": "filter",
|
|
"warnings": {
|
|
"config": [
|
|
"Reconfigure invalid datapath."
|
|
]
|
|
},
|
|
"x": 60,
|
|
"y": 140
|
|
},
|
|
"3": {
|
|
"data": {
|
|
"action": "disable user",
|
|
"actionType": "contain",
|
|
"advanced": {
|
|
"customName": "disable user account",
|
|
"customNameId": 0,
|
|
"description": "Disable user account from filtered playbook inputs.",
|
|
"join": [],
|
|
"note": "Disable user account from filtered playbook inputs."
|
|
},
|
|
"connector": "AWS IAM",
|
|
"connectorConfigs": [
|
|
"aws_iam"
|
|
],
|
|
"connectorId": "7d06523f-d524-4dbd-befd-7f30f5492882",
|
|
"connectorVersion": "v1",
|
|
"functionId": 1,
|
|
"functionName": "disable_user_account",
|
|
"id": "3",
|
|
"parameters": {
|
|
"disable_access_keys": true,
|
|
"username": "filtered-data:username_filter:condition_1:playbook_input:user"
|
|
},
|
|
"requiredParameters": [
|
|
{
|
|
"data_type": "string",
|
|
"field": "username"
|
|
},
|
|
{
|
|
"data_type": "boolean",
|
|
"default": true,
|
|
"field": "disable_access_keys"
|
|
}
|
|
],
|
|
"type": "action"
|
|
},
|
|
"errors": {},
|
|
"id": "3",
|
|
"type": "action",
|
|
"warnings": {},
|
|
"x": 0,
|
|
"y": 320
|
|
},
|
|
"6": {
|
|
"data": {
|
|
"advanced": {
|
|
"customName": "username observables",
|
|
"customNameId": 0,
|
|
"description": "Format a normalized output for each user.",
|
|
"join": [],
|
|
"note": "Format a normalized output for each user."
|
|
},
|
|
"functionId": 2,
|
|
"functionName": "username_observables",
|
|
"id": "6",
|
|
"inputParameters": [
|
|
"filtered-data:filter_disable_result:condition_1:disable_user_account:action_result.parameter.disable_access_keys",
|
|
"filtered-data:filter_disable_result:condition_1:disable_user_account:action_result.parameter.username",
|
|
"filtered-data:filter_disable_result:condition_1:disable_user_account:action_result.parameter.credentials",
|
|
"filtered-data:filter_disable_result:condition_1:disable_user_account:action_result.data.*.RequestId",
|
|
"filtered-data:filter_disable_result:condition_1:disable_user_account:action_result.message",
|
|
"filtered-data:filter_disable_result:condition_1:disable_user_account:action_result.status"
|
|
],
|
|
"outputVariables": [
|
|
"observable_array"
|
|
],
|
|
"type": "code"
|
|
},
|
|
"errors": {},
|
|
"id": "6",
|
|
"type": "code",
|
|
"userCode": "\n # Write your custom code here...\n username_observables__observable_array = []\n \n for access_key, usrname, creds, req_id, msg, status in zip(filtered_result_0_parameter_disable_access_keys, filtered_result_0_parameter_username, filtered_result_0_parameter_credentials, filtered_result_0_data___requestid, filtered_result_0_message, filtered_result_0_status):\n user_acc_status = {\n \"type\": \"aws iam user name\",\n \"value\": usrname,\n \"message\": msg,\n \"status\": status\n }\n\n username_observables__observable_array.append(user_acc_status)\n #phantom.debug(username_observables__observable_array)\n",
|
|
"warnings": {},
|
|
"x": 0,
|
|
"y": 680
|
|
},
|
|
"7": {
|
|
"data": {
|
|
"advanced": {
|
|
"customName": "filter disable result",
|
|
"customNameId": 0,
|
|
"description": "filter check if the user is disabled successfully.",
|
|
"join": [],
|
|
"note": "filter check if the user is disabled successfully."
|
|
},
|
|
"conditions": [
|
|
{
|
|
"comparisons": [
|
|
{
|
|
"conditionIndex": 0,
|
|
"op": "==",
|
|
"param": "disable_user_account:action_result.status",
|
|
"value": "success"
|
|
}
|
|
],
|
|
"conditionIndex": 0,
|
|
"customName": "disable_success",
|
|
"logic": "and"
|
|
}
|
|
],
|
|
"functionId": 2,
|
|
"functionName": "filter_disable_result",
|
|
"id": "7",
|
|
"type": "filter"
|
|
},
|
|
"errors": {},
|
|
"id": "7",
|
|
"type": "filter",
|
|
"warnings": {},
|
|
"x": 60,
|
|
"y": 500
|
|
}
|
|
},
|
|
"notes": "Inputs: users\nInteractions: AWS IAM\nActions: Account Locking/Disabling\nOutputs: observables"
|
|
},
|
|
"input_spec": [
|
|
{
|
|
"contains": [
|
|
"user name",
|
|
"aws iam user name"
|
|
],
|
|
"description": "A user name provided for account locking - AWS IAM",
|
|
"name": "user"
|
|
}
|
|
],
|
|
"output_spec": [
|
|
{
|
|
"contains": [],
|
|
"datapaths": [
|
|
"username_observables:custom_function:observable_array"
|
|
],
|
|
"deduplicate": false,
|
|
"description": "An array of observable dictionaries ",
|
|
"metadata": {},
|
|
"name": "observable"
|
|
}
|
|
],
|
|
"playbook_type": "data",
|
|
"python_version": "3",
|
|
"schema": "5.0.9",
|
|
"version": "6.0.0.114895"
|
|
},
|
|
"create_time": "2023-05-25T07:50:39.360247+00:00",
|
|
"draft_mode": false,
|
|
"labels": [
|
|
"*"
|
|
],
|
|
"tags": [
|
|
"user",
|
|
"aws_iam",
|
|
"disable_account",
|
|
"D3-AL"
|
|
]
|
|
} |