mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
20 lines
685 B
YAML
20 lines
685 B
YAML
name: Credential Dumping Attack
|
|
id: 570dd98e-6cab-443c-bdd8-3dbb5fe4188d
|
|
version: 1
|
|
date: '2020-04-29'
|
|
description: This response workflow guide you through the investigation of a credential dumping attack.
|
|
author: Patrick Bareiss, Splunk
|
|
response_tasks:
|
|
- identification:
|
|
- id: c5506139-ef86-4cd9-8535-0512aa732e79
|
|
name: Process Chain Analysis
|
|
- id: 6ee5c067-8228-4926-abb2-54f2c59d726e
|
|
name: Analyze Malicious File
|
|
- id: 1d7b437a-5114-4b94-a585-04c3362ba08f
|
|
name: Malware Hunt and Contain
|
|
- containment:
|
|
- id: 60c4cfa5-81b7-44e2-9ad4-71524e4a3e78
|
|
name: Quarantaine Infected Host
|
|
tags:
|
|
analytics_story: Credential Dumping
|