Files
2020-05-18 17:00:15 -07:00

5.5 KiB

Response Task Schema Schema

http://example.com/example.json

schema for response tasks

Abstract Extensible Status Identifiable Custom Properties Additional Properties Defined In
Can be instantiated No Experimental No Forbidden Permitted

Response Task Schema Properties

Property Type Required Nullable Default Defined by
author string Required No "" Response Task Schema (this schema)
dashboard string Optional No "" Response Task Schema (this schema)
date string Required No "" Response Task Schema (this schema)
description string Required No "" Response Task Schema (this schema)
how_to_implement string Optional No "" Response Task Schema (this schema)
id string Required No "" Response Task Schema (this schema)
inputs array Optional No [] Response Task Schema (this schema)
name string Required No "" Response Task Schema (this schema)
playbook object Optional No {} Response Task Schema (this schema)
search string Optional No "" Response Task Schema (this schema)
version integer Required No 0 Response Task Schema (this schema)
* any Additional Yes this schema allows additional properties

author

Author of response task

author

  • is required
  • type: string
  • default: ""
  • defined in this schema

author Type

string

author Example

"Patrick Bareiß, Splunk"

dashboard

Name of dashboard used as response task

dashboard

  • is optional
  • type: string
  • default: ""
  • defined in this schema

dashboard Type

string

dashboard Example

"process_chain_analysis.json"

date

date of creation or modification, format yyyy-mm-dd

date

  • is required
  • type: string
  • default: ""
  • defined in this schema

date Type

string

date Example

"2019-12-06"

description

Description of response task

description

  • is required
  • type: string
  • default: ""
  • defined in this schema

description Type

string

description Example

"Response Task example description"

how_to_implement

information about how to implement. Only needed for non standard implementations.

how_to_implement

  • is optional
  • type: string
  • default: ""
  • defined in this schema

how_to_implement Type

string

how_to_implement Example

"This search requires Sysmon Logs and a Sysmon configuration, which includes EventCode 10 for lsass.exe."

id

UUID as unique identifier

id

  • is required
  • type: string
  • default: ""
  • defined in this schema

id Type

string

id Example

"fb4c31b0-13e8-4155-8aa5-24de4b8d6717"

inputs

Inputs used from the response task

inputs

  • is optional

  • type: array

  • default: []

  • defined in this schema

inputs Type

Array type: array

inputs Example

[
  "lookup_file"
]

name

Namo fo response task

name

  • is required
  • type: string
  • default: ""
  • defined in this schema

name Type

string

name Example

"Response Tas Example"

playbook

A phantom playbook as response task

playbook

  • is optional
  • type: object
  • default: {}
  • defined in this schema

playbook Type

object with following properties:

Property Type Required Default
name string Required ""
url_json string Required ""
url_python string Required ""

name

Name of Phantom Playbook

name

  • is required
  • type: string
  • default: ""
name Type

string

name Example
lets_encrypt_domain_investigate.json

url_json

URL for phantom playbook json file

url_json

  • is required
  • type: string
  • default: ""
url_json Type

string

url_json Example
https://github.com/phantomcyber/playbooks/blob/4.6/lets_encrypt_domain_investigate.json

url_python

URL for phantom playbook python file

url_python

  • is required
  • type: string
  • default: ""
url_python Type

string

url_python Example
https://github.com/phantomcyber/playbooks/blob/4.6/lets_encrypt_domain_investigate.py

playbook Example

{
  "name": "lets_encrypt_domain_investigate.json",
  "url_json": "https://github.com/phantomcyber/playbooks/blob/4.6/lets_encrypt_domain_investigate.json",
  "url_python": "https://github.com/phantomcyber/playbooks/blob/4.6/lets_encrypt_domain_investigate.py"
}

Search as response task

search

  • is optional
  • type: string
  • default: ""
  • defined in this schema

search Type

string

search Example

"`sysmon` EventCode=1 | search [| inputlookup %lookup_file% ] | stats count by dest user process_name"

version

version of detection, e.g. 1 or 2 ...

version

  • is required
  • type: integer
  • default: 0
  • defined in this schema

version Type

integer

version Example

3