Files
splunk-security_content/response_tasks/playbooks/implement_additional_monitoring.yml
T

36 lines
1.0 KiB
YAML

author: ButterCup, Splunk
automation:
actions:
- run query
is_note_required: false
playbooks:
- playook: ''
scm: null
role: null
sla: null
sla_type: minutes
date: '2020-04-21'
description: 'Implement additional monitoring that reviews not only host/network containment
success. Monitor network blocks for additional hosts that might not have been identified.
Reassess containment as needed depending on any new information. If this is a mass
infection, it''s advised that a 24 no change process be implemented.
'
id: edb7867c-2e81-4356-a422-92781f4fa34c
name: Implement additional monitoring
references:
- 3.2.4 Incident Analysis - https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r2.pdf
requirements: null
tags:
nist: RS.RP
product:
- Splunk Phantom
type: response
version: 1
workflow: '1. Create additional monitoring for network and host detection for abnormal
activity to ensure containment is effective.
2. Re-investigate new hosts found but not on the containment list
'