Skip to content

Port playbooks#4089

Merged
ljstella merged 4 commits into
escu6_manual_reviewfrom
port_playbooks
May 20, 2026
Merged

Port playbooks#4089
ljstella merged 4 commits into
escu6_manual_reviewfrom
port_playbooks

Conversation

@pyth0n1c
Copy link
Copy Markdown
Collaborator

@pyth0n1c pyth0n1c commented May 19, 2026

This is intentionally a separate branch since other content has already been reviewed.
It ports playbooks to ESCU 6 format as well.
The CICD tooling to validate these has not landed yet.

This PR will be updated when that new tooling has landed.

Please review the following changes, that have already been made, to determine if these changes should persist:

Filenames changed because it does not align with source material. The "name" field of the YML has also been changed:
https://github.com/splunk/security_content/pull/4089/changes#diff-01993ff5adbff89edf17922137d10eec8cc524bf4e6929d2c280f5b5b8c6a6f4R30
https://github.com/splunk/security_content/pull/4089/changes#diff-8a028269350f2b9c96900df06c97726afc3b284aea59d75d0d5c566cae9e2aea
https://github.com/splunk/security_content/pull/4089/changes#diff-f3d9ad36926825a831cad441b5d900cce3d703cf8d509b3302935b135b5dc22e
Please note the naming in the source for these files:
https://github.com/phantomcyber/playbooks/blob/8.5/CiscoTalosIntelligence_Identifier_Reputation_Analysis.json

Both of these pointed at detections that have since been deprecated. The deprecated detections have been removed and they point at the relevant replacement_content, per the deprecation_info
https://github.com/splunk/security_content/pull/4089/changes#diff-dc1bbdaf780f8d72ced924c3535702b80ccf62997a2bfa1190ada11feed35c7cR34

https://github.com/splunk/security_content/pull/4089/changes#diff-caa85e2fa4d6df1a1175ab1b40a9ccd4e524c46d387cb162f421982ab646d895R34

pyth0n1c and others added 2 commits May 19, 2026 14:28
…tions

in playbooks that were previously unvalidated.
Add a MANUAL_REVIEW section, which is commented out,
for clarity and to allow CICD to run and pass on this content.
Renamed an existing playbook because it diverges from the name
of that playbook elsewhere.
@pyth0n1c pyth0n1c marked this pull request as ready for review May 20, 2026 16:34
@pyth0n1c
Copy link
Copy Markdown
Collaborator Author

I am removing this from DRAFT and marking as READY FOR REVIEW. The details requiring manual review, as called out in the description, have all been mitigated to my satisfaction :)

Copy link
Copy Markdown
Contributor

@ljstella ljstella left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Merging into my branch

@ljstella ljstella merged commit e5dc0c4 into escu6_manual_review May 20, 2026
2 of 5 checks passed
@ljstella ljstella deleted the port_playbooks branch May 20, 2026 16:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants