Port playbooks#4089
Merged
Merged
Conversation
…tions in playbooks that were previously unvalidated. Add a MANUAL_REVIEW section, which is commented out, for clarity and to allow CICD to run and pass on this content. Renamed an existing playbook because it diverges from the name of that playbook elsewhere.
Collaborator
Author
|
I am removing this from DRAFT and marking as READY FOR REVIEW. The details requiring manual review, as called out in the description, have all been mitigated to my satisfaction :) |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This is intentionally a separate branch since other content has already been reviewed.
It ports playbooks to ESCU 6 format as well.
The CICD tooling to validate these has not landed yet.
This PR will be updated when that new tooling has landed.
Please review the following changes, that have already been made, to determine if these changes should persist:
Filenames changed because it does not align with source material. The "name" field of the YML has also been changed:
https://github.com/splunk/security_content/pull/4089/changes#diff-01993ff5adbff89edf17922137d10eec8cc524bf4e6929d2c280f5b5b8c6a6f4R30
https://github.com/splunk/security_content/pull/4089/changes#diff-8a028269350f2b9c96900df06c97726afc3b284aea59d75d0d5c566cae9e2aea
https://github.com/splunk/security_content/pull/4089/changes#diff-f3d9ad36926825a831cad441b5d900cce3d703cf8d509b3302935b135b5dc22e
Please note the naming in the source for these files:
https://github.com/phantomcyber/playbooks/blob/8.5/CiscoTalosIntelligence_Identifier_Reputation_Analysis.json
Both of these pointed at detections that have since been deprecated. The deprecated detections have been removed and they point at the relevant replacement_content, per the deprecation_info
https://github.com/splunk/security_content/pull/4089/changes#diff-dc1bbdaf780f8d72ced924c3535702b80ccf62997a2bfa1190ada11feed35c7cR34
https://github.com/splunk/security_content/pull/4089/changes#diff-caa85e2fa4d6df1a1175ab1b40a9ccd4e524c46d387cb162f421982ab646d895R34