mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
36 lines
1.0 KiB
YAML
36 lines
1.0 KiB
YAML
author: ButterCup, Splunk
|
|
automation:
|
|
actions:
|
|
- run query
|
|
is_note_required: false
|
|
playbooks:
|
|
- playook: ''
|
|
scm: null
|
|
role: null
|
|
sla: null
|
|
sla_type: minutes
|
|
date: '2020-04-21'
|
|
description: 'Implement additional monitoring that reviews not only host/network containment
|
|
success. Monitor network blocks for additional hosts that might not have been identified.
|
|
Reassess containment as needed depending on any new information. If this is a mass
|
|
infection, it''s advised that a 24 no change process be implemented.
|
|
|
|
'
|
|
id: edb7867c-2e81-4356-a422-92781f4fa34c
|
|
name: Implement additional monitoring
|
|
references:
|
|
- 3.2.4 Incident Analysis - https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r2.pdf
|
|
requirements: null
|
|
tags:
|
|
nist: RS.RP
|
|
product:
|
|
- Splunk Phantom
|
|
type: response
|
|
version: 1
|
|
workflow: '1. Create additional monitoring for network and host detection for abnormal
|
|
activity to ensure containment is effective.
|
|
|
|
2. Re-investigate new hosts found but not on the containment list
|
|
|
|
'
|