Files
splunk-security_content/responses/credential_dumping_attack.yml
2020-04-29 13:01:45 +02:00

20 lines
685 B
YAML

name: Credential Dumping Attack
id: 570dd98e-6cab-443c-bdd8-3dbb5fe4188d
version: 1
date: '2020-04-29'
description: This response workflow guide you through the investigation of a credential dumping attack.
author: Patrick Bareiss, Splunk
response_tasks:
- identification:
- id: c5506139-ef86-4cd9-8535-0512aa732e79
name: Process Chain Analysis
- id: 6ee5c067-8228-4926-abb2-54f2c59d726e
name: Analyze Malicious File
- id: 1d7b437a-5114-4b94-a585-04c3362ba08f
name: Malware Hunt and Contain
- containment:
- id: 60c4cfa5-81b7-44e2-9ad4-71524e4a3e78
name: Quarantaine Infected Host
tags:
analytics_story: Credential Dumping