Skip to content

Commit c498d21

Browse files
committed
Manual Review completion
1 parent 13f06b5 commit c498d21

3 files changed

Lines changed: 0 additions & 36 deletions

File tree

playbooks/CiscoTalosIntelligence_Identifier_Reputation_Analysis.yml

Lines changed: 0 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -27,6 +27,3 @@ use_cases:
2727
- Enrichment
2828
defend_technique_id:
2929
- D3-IRA
30-
# MANUAL_REVIEW:
31-
# rationale: This filename was changed from Cisco Talos Intelligence Identifier Reputation Analysis to
32-
# CiscoTalosIntelligence Identifier Reputation Analysis in line with how it exists in the source of truth.

playbooks/log4j_investigate.yml

Lines changed: 0 additions & 17 deletions
Original file line numberDiff line numberDiff line change
@@ -31,20 +31,3 @@ detections:
3131
- Log4Shell JNDI Payload Injection Attempt
3232
- Log4Shell JNDI Payload Injection with Outbound Connection
3333
- Detect Outbound LDAP Traffic
34-
# MANUAL_REVIEW:
35-
# rationale: detections section contained references to two removed detections.
36-
# They have been remapped to their replacement content.
37-
# unmodified_detections_section:
38-
# - Curl Download and Bash Execution
39-
# - Wget Download and Bash Execution
40-
# - Linux Java Spawning Shell
41-
# - Windows Java Spawning Shells
42-
# - Java Class File download by Java User Agent
43-
# - Outbound Network Connection from Java Using Default Ports
44-
# - Log4Shell JNDI Payload Injection Attempt
45-
# - Log4Shell JNDI Payload Injection with Outbound Connection
46-
# - Detect Outbound LDAP Traffic
47-
# manually_added_detections_from_replacement_content:
48-
# - File Download or Read to Pipe Execution
49-
# - Web or Application Server Spawning a Shell
50-

playbooks/log4j_respond.yml

Lines changed: 0 additions & 16 deletions
Original file line numberDiff line numberDiff line change
@@ -31,19 +31,3 @@ detections:
3131
- Log4Shell JNDI Payload Injection Attempt
3232
- Log4Shell JNDI Payload Injection with Outbound Connection
3333
- Detect Outbound LDAP Traffic
34-
# MANUAL_REVIEW:
35-
# rationale: detections section contained references to two removed detections.
36-
# They have been remapped to their replacement content.
37-
# unmodified_detections_section:
38-
# - Curl Download and Bash Execution
39-
# - Wget Download and Bash Execution
40-
# - Linux Java Spawning Shell
41-
# - Windows Java Spawning Shells
42-
# - Java Class File download by Java User Agent
43-
# - Outbound Network Connection from Java Using Default Ports
44-
# - Log4Shell JNDI Payload Injection Attempt
45-
# - Log4Shell JNDI Payload Injection with Outbound Connection
46-
# - Detect Outbound LDAP Traffic
47-
# manually_added_detections_from_replacement_content:
48-
# - File Download or Read to Pipe Execution
49-
# - Web or Application Server Spawning a Shell

0 commit comments

Comments
 (0)