Mitre COA - MITRE Layout
MITRE ATT&CK - Courses of Action Incident
Details
| ID | Mitre COA - MITRE Layout |
|---|---|
| Group | incident |
| Version | -1 |
| From Version | 6.5.0 |
Layout Structure
Legacy Summary 0 sections
No sections defined.
Incident Info 14 sections
Case Details
| Field ID | Position |
|---|---|
| type | Col 0-2, Height: 22 |
| severity | Col 0-2, Height: 22 |
| owner | Col 0-2, Height: 22 |
| dbotsource | Col 0-2, Height: 22 |
| sourcebrand | Col 0-2, Height: 22 |
| sourceinstance | Col 0-2, Height: 22 |
| playbookid | Col 0-2, Height: 22 |
Notes
Linked Incidents
Child Incidents
Evidence
Team Members
Indicators
Timeline Information
| Field ID | Position |
|---|---|
| occurred | Col 0-1, Height: 53 |
| dbotduedate | Col 0-2, Height: 53 |
| dbotcreated | Col 0-2, Height: 53 |
| dbotmodified | Col 0-2, Height: 53 |
| dbotclosed | Col 1-2, Height: 53 |
Closing Information
| Field ID | Position |
|---|---|
| dbotclosed | Col 0-2, Height: 22 |
| closereason | Col 0-2, Height: 22 |
| closenotes | Col 0-2, Height: 22 |
Techniques to Handle
Handled Techniques
Work Plan
Handled Techniques
This section dynamically displays the handled techniques in a MITRE ATT&CK - Courses of Action investigation.
| Field ID | Position |
|---|---|
| remediatedtechniques | Col 0-2, Height: 22 |
Techniques to Handle
This section dynamically displays the list of MITRE ATT&CK techniques that were not yet handled using the Courses of Action playbook.
| Field ID | Position |
|---|---|
| techniquestohandle | Col 0-2, Height: 22 |
Executed Remediation Summary 13 sections
1. Initial Access Remediation
Initial Access consists of techniques that use various entry vectors to gain their initial foothold within a network.
| Field ID | Position |
|---|---|
| initialaccessremediationproducts | Col 0-2, Height: 22 |
2. Execution Remediation
Execution consists of techniques that result in adversary-controlled code running on a local or remote system.
| Field ID | Position |
|---|---|
| executionremediationproducts | Col 0-2, Height: 22 |
6. Credential Access Remediation
Credential Access consists of techniques for stealing credentials like account names and passwords.
| Field ID | Position |
|---|---|
| credentialaccessremediationproducts | Col 0-2, Height: 22 |
5. Defense Evasion Remediation
Defense Evasion consists of techniques that adversaries use to avoid detection throughout their compromise.
| Field ID | Position |
|---|---|
| defenseevasionremediationproducts | Col 0-2, Height: 22 |
9. Collection Remediation
Collection consists of techniques adversaries may use to gather information and the sources information is collected from that are relevant to following through on the adversary’s objectives.
| Field ID | Position |
|---|---|
| collectionremediationproducts | Col 0-2, Height: 22 |
3. Persistence Remediation
Persistence consists of techniques that adversaries use to keep access to systems across restarts, changed credentials, and other interruptions that could cut off their access.
| Field ID | Position |
|---|---|
| persistenceremediationproducts | Col 0-2, Height: 22 |
8. Lateral Movement Remediation
Lateral Movement consists of techniques that adversaries use to enter and control remote systems on a network.
| Field ID | Position |
|---|---|
| lateralmovementremediationproducts | Col 0-2, Height: 106 |
7. Discovery Remediation
Discovery consists of techniques an adversary may use to gain knowledge about the system and internal network.
| Field ID | Position |
|---|---|
| discoveryremediationproducts | Col 0-2, Height: 106 |
4. Privilege Escalation Remediation
Privilege Escalation consists of techniques that adversaries use to gain higher-level permissions on a system or network.
| Field ID | Position |
|---|---|
| privilegeescalationremediationproducts | Col 0-2, Height: 22 |
12. Impact Remediation
Impact consists of techniques that adversaries use to disrupt availability or compromise integrity by manipulating business and operational processes.
| Field ID | Position |
|---|---|
| impactremediationproducts | Col 0-2, Height: 22 |
11. Exfiltration Remediation
Exfiltration consists of techniques that adversaries may use to steal data from your network.
| Field ID | Position |
|---|---|
| exfiltrationremediationproducts | Col 0-2, Height: 22 |
10. Command and Control Remediation
Command and Control consists of techniques that adversaries may use to communicate with systems under their control within a victim network.
| Field ID | Position |
|---|---|
| commandandcontrolremediationproducts | Col 0-2, Height: 22 |
Tab Description
| Field ID | Position |
|---|---|
| executedremediationsummarydescription | Col 0-6, Height: 44 |
Best Practices 19 sections
Anti-Spyware Best Practices
You can attach an Anti-Spyware profile to a Security policy rule to detect connections initiated by spyware and command-and-control (C2) malware installed on systems on your network.
| Field ID | Position |
|---|---|
| antispywareprofilename | Col 0-2, Height: 53 |
| antispywareprofilestatus | Col 0-2, Height: 53 |
| antispywarerules | Col 0-2, Height: 53 |
Anti-Spyware Best Practices
Anti-Spyware related passed BPA checks results.
| Field ID | Position |
|---|---|
| bpapassedchecksantispyware | Col 0-4, Height: 106 |
Tab Description
| Field ID | Position |
|---|---|
| bestpracticesdescription | Col 0-6, Height: 44 |
WildFire Best Practices
Use a WildFire Analysis profile to specify for WildFire file analysis to be performed locally on the WildFire appliance or in the WildFire cloud. You can specify traffic to be forwarded to the public cloud or private cloud based on file type, application, or the transmission direction of the file (upload or download).
| Field ID | Position |
|---|---|
| wildfireprofilename | Col 0-2, Height: 22 |
| wildfireprofilestatus | Col 0-2, Height: 22 |
| wildfirerules | Col 0-2, Height: 22 |
WildFire Best Practices
WildFire related passed BPA checks results.
| Field ID | Position |
|---|---|
| bpapassedcheckswildfire | Col 0-4, Height: 106 |
Anti-Virus Best Practices
Use the Antivirus Profiles page to configure options to have the firewall scan for viruses on the defined traffic. Set the applications that should be inspected for viruses and the action to take when a virus is detected.
| Field ID | Position |
|---|---|
| antivirusprofilename | Col 0-2, Height: 53 |
| antivirusprofilestatus | Col 0-2, Height: 53 |
| antivirusrules | Col 0-2, Height: 53 |
Anti-Virus Best Practices
Anti-Virus related passed BPA checks results.
| Field ID | Position |
|---|---|
| bpapassedchecksantivirus | Col 0-4, Height: 106 |
File Blocking Best Practices
You can attach a File Blocking profile to a Security policy rule to block users from uploading or downloading specified file types or to generate an alert when a user attempts to upload or download specified file types.
| Field ID | Position |
|---|---|
| fileblockingprofilename | Col 0-2, Height: 53 |
| fileblockingprofilestatus | Col 0-2, Height: 53 |
| fileblockingrules | Col 0-2, Height: 53 |
File Blocking Best Practices
File Blocking related passed BPA checks results.
| Field ID | Position |
|---|---|
| bpapassedchecksfileblocking | Col 0-4, Height: 106 |
URL Filtering Best Practices
You can use URL filtering profiles to control access to web content.
| Field ID | Position |
|---|---|
| urlfilteringprofilename | Col 0-2, Height: 53 |
| urlfilteringprofilestatus | Col 0-2, Height: 53 |
| urlfilteringrules | Col 0-2, Height: 53 |
URL Filtering Best Practices
URL Filtering related passed BPA checks results.
| Field ID | Position |
|---|---|
| bpapassedchecksurlfiltering | Col 0-4, Height: 106 |
Vulnerability Protection Best Practices
A Security policy rule can include specification of a Vulnerability Protection profile that determines the level of protection against buffer overflows, illegal code execution, and other attempts to exploit system vulnerabilities.
| Field ID | Position |
|---|---|
| vulnerabilityprotectionprofilename | Col 0-2, Height: 53 |
| vulnerabilityprotectionprofilestatus | Col 0-2, Height: 53 |
| vulnerabilityprotectionrules | Col 0-2, Height: 22 |
Vulnerability Protection Best Practices
Vulnerability Protection related passed BPA checks results.
| Field ID | Position |
|---|---|
| bpapassedchecksvulnerabilityprotection | Col 0-4, Height: 106 |
New Section
Anti-Spyware related failed BPA checks results.
| Field ID | Position |
|---|---|
| bpafailedchecksantispyware | Col 0-4, Height: 106 |
New Section
Anti-Virus related failed BPA checks results.
| Field ID | Position |
|---|---|
| bpafailedchecksantivirus | Col 0-4, Height: 106 |
New Section
File Blocking related failed BPA checks results.
| Field ID | Position |
|---|---|
| bpafailedchecksfileblocking | Col 0-4, Height: 106 |
New Section
URL Filtering related failed BPA checks results.
| Field ID | Position |
|---|---|
| bpafailedchecksurlfiltering | Col 0-4, Height: 106 |
New Section
Vulnerability Protection related failed BPA checks results.
| Field ID | Position |
|---|---|
| bpafailedchecksvulnerabilityprotection | Col 0-4, Height: 106 |
New Section
WildFire related failed BPA checks results.
| Field ID | Position |
|---|---|
| bpafailedcheckswildfire | Col 0-4, Height: 106 |
War Room 0 sections
No sections defined.
Work Plan 0 sections
No sections defined.
Evidence Board 0 sections
No sections defined.
Related Incidents 0 sections
No sections defined.
Canvas 0 sections
No sections defined.
{ "detailsV2": { "tabs": [ { "id": "summary", "name": "Legacy Summary", "type": "summary" }, { "id": "caseinfoid", "name": "Incident Info", "sections": [ { "displayType": "ROW", "h": 2, "i": "caseinfoid-field-changed-caseinfoid-fce71720-98b0-11e9-97d7-ed26ef9e46c8", "isVisible": true, "items": [ { "endCol": 2, "fieldId": "type", "height": 22, "id": "incident-type-field", "index": 0, "sectionItemType": "field", "startCol": 0 }, { "endCol": 2, "fieldId": "severity", "height": 22, "id": "incident-severity-field", "index": 1, "sectionItemType": "field", "startCol": 0 }, { "endCol": 2, "fieldId": "owner", "height": 22, "id": "incident-owner-field", "index": 2, "sectionItemType": "field", "startCol": 0 }, { "endCol": 2, "fieldId": "dbotsource", "height": 22, "id": "incident-source-field", "index": 3, "sectionItemType": "field", "startCol": 0 }, { "endCol": 2, "fieldId": "sourcebrand", "height": 22, "id": "incident-sourceBrand-field", "index": 4, "sectionItemType": "field", "startCol": 0 }, { "endCol": 2, "fieldId": "sourceinstance", "height": 22, "id": "incident-sourceInstance-field", "index": 5, "sectionItemType": "field", "startCol": 0 }, { "endCol": 2, "fieldId": "playbookid", "height": 22, "id": "incident-playbookId-field", "index": 6, "sectionItemType": "field", "startCol": 0 } ], "maxW": 3, "minH": 1, "minW": 1, "moved": false, "name": "Case Details", "static": false, "w": 1, "x": 0, "y": 0 }, { "h": 3, "i": "caseinfoid-field-changed-caseinfoid-61263cc0-98b1-11e9-97d7-ed26ef9e46c8", "maxW": 3, "minH": 1, "minW": 1, "moved": false, "name": "Notes", "static": false, "type": "notes", "w": 1, "x": 2, "y": 6 }, { "displayType": "ROW", "h": 2, "i": "caseinfoid-field-changed-caseinfoid-770ec200-98b1-11e9-97d7-ed26ef9e46c8", "isVisible": true, "maxW": 3, "minH": 1, "minW": 1, "moved": false, "name": "Linked Incidents", "static": false, "type": "linkedIncidents", "w": 2, "x": 0, "y": 9 }, { "displayType": "ROW", "h": 2, "i": "caseinfoid-field-changed-caseinfoid-842632c0-98b1-11e9-97d7-ed26ef9e46c8", "maxW": 3, "minH": 1, "minW": 1, "moved": false, "name": "Child Incidents", "static": false, "type": "childInv", "w": 2, "x": 0, "y": 11 }, { "displayType": "ROW", "h": 2, "i": "caseinfoid-field-changed-caseinfoid-4a31afa0-98ba-11e9-a519-93a53c759fe0", "maxW": 3, "minH": 1, "minW": 1, "moved": false, "name": "Evidence", "static": false, "type": "evidence", "w": 1, "x": 2, "y": 4 }, { "displayType": "ROW", "h": 2, "hideName": false, "i": "caseinfoid-field-changed-caseinfoid-7717e580-9bed-11e9-9a3f-8b4b2158e260", "maxW": 3, "minH": 1, "minW": 1, "moved": false, "name": "Team Members", "static": false, "type": "team", "w": 1, "x": 2, "y": 9 }, { "displayType": "ROW", "h": 3, "i": "caseinfoid-field-changed-caseinfoid-7ce69dd0-a07f-11e9-936c-5395a1acf11e", "maxW": 3, "minH": 1, "minW": 2, "moved": false, "name": "Indicators", "query": "", "queryType": "input", "static": false, "type": "indicators", "w": 2, "x": 0, "y": 6 }, { "displayType": "CARD", "h": 2, "i": "caseinfoid-field-changed-caseinfoid-ac32f620-a0b0-11e9-b27f-13ae1773d289", "items": [ { "endCol": 1, "fieldId": "occurred", "height": 53, "id": "incident-occurred-field", "index": 0, "sectionItemType": "field", "startCol": 0 }, { "endCol": 2, "fieldId": "dbotduedate", "height": 53, "id": "incident-dueDate-field", "index": 1, "sectionItemType": "field", "startCol": 0 }, { "dropEffect": "move", "endCol": 2, "fieldId": "dbotcreated", "height": 53, "id": "incident-created-field", "index": 2, "listId": "caseinfoid-ac32f620-a0b0-11e9-b27f-13ae1773d289", "sectionItemType": "field", "startCol": 0 }, { "endCol": 2, "fieldId": "dbotmodified", "height": 53, "id": "incident-modified-field", "index": 3, "sectionItemType": "field", "startCol": 0 }, { "endCol": 2, "fieldId": "dbotclosed", "height": 53, "id": "incident-closed-field", "index": 0, "sectionItemType": "field", "startCol": 1 } ], "maxW": 3, "minH": 1, "minW": 1, "moved": false, "name": "Timeline Information", "static": false, "w": 1, "x": 1, "y": 0 }, { "displayType": "ROW", "h": 2, "i": "caseinfoid-field-changed-caseinfoid-88e6bf70-a0b1-11e9-b27f-13ae1773d289", "isVisible": true, "items": [ { "endCol": 2, "fieldId": "dbotclosed", "height": 22, "id": "incident-dbotClosed-field", "index": 0, "sectionItemType": "field", "startCol": 0 }, { "endCol": 2, "fieldId": "closereason", "height": 22, "id": "incident-closeReason-field", "index": 1, "sectionItemType": "field", "startCol": 0 }, { "endCol": 2, "fieldId": "closenotes", "height": 22, "id": "incident-closeNotes-field", "index": 2, "sectionItemType": "field", "startCol": 0 } ], "maxW": 3, "minH": 1, "minW": 1, "moved": false, "name": "Closing Information", "static": false, "w": 1, "x": 2, "y": 11 }, { "h": 1, "hideName": true, "i": "caseinfoid-field-changed-caseinfoid-89efee40-4eb2-11eb-bfdd-39a03a974056", "items": [], "maxW": 3, "minH": 1, "minW": 1, "moved": false, "name": "Techniques to Handle", "query": "EntryWidgetCoATechniquesList", "queryType": "script", "static": false, "type": "dynamic", "w": 1, "x": 1, "y": 2 }, { "description": "", "h": 1, "hideName": true, "i": "caseinfoid-field-changed-caseinfoid-b4ad2250-4eb3-11eb-bfdd-39a03a974056", "items": [], "maxW": 3, "minH": 1, "minW": 1, "moved": false, "name": "Handled Techniques", "query": "EntryWidgetCoAHandled", "queryType": "script", "static": false, "type": "dynamic", "w": 1, "x": 0, "y": 2 }, { "h": 4, "i": "caseinfoid-field-changed-caseinfoid-319baec0-4f4b-11eb-8d81-d73a55635d33", "items": [], "maxW": 3, "minH": 1, "minW": 1, "moved": false, "name": "Work Plan", "static": false, "type": "workplan", "w": 1, "x": 2, "y": 0 }, { "description": "This section dynamically displays the handled techniques in a MITRE ATT\u0026CK - Courses of Action investigation.", "displayType": "CARD", "h": 3, "hideItemTitleOnlyOne": true, "hideName": false, "i": "caseinfoid-a0fa40d0-fb51-11eb-ab8f-07c378a6996b", "items": [ { "endCol": 2, "fieldId": "remediatedtechniques", "height": 22, "id": "38b424c0-00ea-11ec-a6a7-29a1f691fdd8", "index": 0, "sectionItemType": "field", "startCol": 0 } ], "maxW": 3, "minH": 1, "moved": false, "name": "Handled Techniques", "static": false, "w": 1, "x": 0, "y": 3 }, { "description": "This section dynamically displays the list of MITRE ATT\u0026CK techniques that were not yet handled using the Courses of Action playbook.", "displayType": "CARD", "h": 3, "hideItemTitleOnlyOne": true, "hideName": false, "i": "caseinfoid-a6cf0540-fb51-11eb-ab8f-07c378a6996b", "items": [ { "endCol": 2, "fieldId": "techniquestohandle", "height": 22, "id": "3cc1bdc0-00ea-11ec-a6a7-29a1f691fdd8", "index": 0, "sectionItemType": "field", "startCol": 0 } ], "maxW": 3, "minH": 1, "moved": false, "name": "Techniques to Handle", "static": false, "w": 1, "x": 1, "y": 3 } ], "type": "custom" }, { "hidden": false, "id": "kun8sgpfut", "name": "Executed Remediation Summary", "sections": [ { "description": "Initial Access consists of techniques that use various entry vectors to gain their initial foothold within a network.", "displayType": "CARD", "h": 3, "hideItemTitleOnlyOne": true, "hideName": false, "i": "caseinfoid-iu7vqsykkr-45452f50-9b90-11eb-b7cc-01480a639de2", "items": [ { "endCol": 2, "fieldId": "initialaccessremediationproducts", "height": 22, "id": "74815aa0-cebc-11eb-8aa5-5bace041f776", "index": 0, "sectionItemType": "field", "startCol": 0 } ], "maxW": 3, "minH": 1, "minW": 1, "moved": false, "name": "1. Initial Access Remediation", "static": false, "w": 1, "x": 0, "y": 1 }, { "description": "Execution consists of techniques that result in adversary-controlled code running on a local or remote system.", "displayType": "ROW", "h": 3, "hideItemTitleOnlyOne": true, "hideName": false, "i": "caseinfoid-iu7vqsykkr-562b8260-9b90-11eb-b7cc-01480a639de2", "items": [ { "endCol": 2, "fieldId": "executionremediationproducts", "height": 22, "id": "752c3a20-cdcb-11eb-a582-e785b47b3136", "index": 0, "sectionItemType": "field", "startCol": 0 } ], "maxW": 3, "minH": 1, "minW": 1, "moved": false, "name": "2. Execution Remediation", "static": false, "w": 1, "x": 1, "y": 1 }, { "description": "Credential Access consists of techniques for stealing credentials like account names and passwords.", "displayType": "ROW", "h": 3, "hideItemTitleOnlyOne": true, "hideName": false, "i": "caseinfoid-iu7vqsykkr-57e28130-9b90-11eb-b7cc-01480a639de2", "items": [ { "endCol": 2, "fieldId": "credentialaccessremediationproducts", "height": 22, "id": "870b1e00-cdcb-11eb-a582-e785b47b3136", "index": 0, "sectionItemType": "field", "startCol": 0 } ], "maxW": 3, "minH": 1, "minW": 1, "moved": false, "name": "6. Credential Access Remediation", "static": false, "w": 1, "x": 2, "y": 4 }, { "description": "Defense Evasion consists of techniques that adversaries use to avoid detection throughout their compromise.", "displayType": "ROW", "h": 3, "hideItemTitleOnlyOne": true, "hideName": false, "i": "caseinfoid-iu7vqsykkr-594a9cb0-9b90-11eb-b7cc-01480a639de2", "items": [ { "endCol": 2, "fieldId": "defenseevasionremediationproducts", "height": 22, "id": "6c8f5500-cdcb-11eb-a582-e785b47b3136", "index": 0, "sectionItemType": "field", "startCol": 0 } ], "maxW": 3, "minH": 1, "minW": 1, "moved": false, "name": "5. Defense Evasion Remediation", "static": false, "w": 1, "x": 1, "y": 4 }, { "description": "Collection consists of techniques adversaries may use to gather information and the sources information is collected from that are relevant to following through on the adversary’s objectives.", "displayType": "ROW", "h": 3, "hideItemTitleOnlyOne": true, "hideName": false, "i": "caseinfoid-iu7vqsykkr-59e6b5a0-9b90-11eb-b7cc-01480a639de2", "items": [ { "endCol": 2, "fieldId": "collectionremediationproducts", "height": 22, "id": "afc3a460-cebc-11eb-8aa5-5bace041f776", "index": 0, "sectionItemType": "field", "startCol": 0 } ], "maxW": 3, "minH": 1, "minW": 1, "moved": false, "name": "9. Collection Remediation", "static": false, "w": 1, "x": 2, "y": 7 }, { "description": "Persistence consists of techniques that adversaries use to keep access to systems across restarts, changed credentials, and other interruptions that could cut off their access.", "displayType": "ROW", "h": 3, "hideItemTitleOnlyOne": true, "hideName": false, "i": "caseinfoid-iu7vqsykkr-5a89d370-9b90-11eb-b7cc-01480a639de2", "items": [ { "endCol": 2, "fieldId": "persistenceremediationproducts", "height": 22, "id": "7d0cd420-cdcb-11eb-a582-e785b47b3136", "index": 0, "sectionItemType": "field", "startCol": 0 } ], "maxW": 3, "minH": 1, "minW": 1, "moved": false, "name": "3. Persistence Remediation", "static": false, "w": 1, "x": 2, "y": 1 }, { "description": "Lateral Movement consists of techniques that adversaries use to enter and control remote systems on a network.", "displayType": "ROW", "h": 3, "hideItemTitleOnlyOne": true, "hideName": false, "i": "caseinfoid-iu7vqsykkr-5fbd9cf0-9b90-11eb-b7cc-01480a639de2", "items": [ { "endCol": 2, "fieldId": "lateralmovementremediationproducts", "height": 106, "id": "abf8e0c0-cebc-11eb-8aa5-5bace041f776", "index": 0, "sectionItemType": "field", "startCol": 0 } ], "maxW": 3, "minH": 1, "minW": 1, "moved": false, "name": "8. Lateral Movement Remediation", "static": false, "w": 1, "x": 1, "y": 7 }, { "description": "Discovery consists of techniques an adversary may use to gain knowledge about the system and internal network.", "displayType": "ROW", "h": 3, "hideItemTitleOnlyOne": true, "hideName": false, "i": "caseinfoid-iu7vqsykkr-60565a80-9b90-11eb-b7cc-01480a639de2", "items": [ { "endCol": 2, "fieldId": "discoveryremediationproducts", "height": 106, "id": "a8fc69a0-cebc-11eb-8aa5-5bace041f776", "index": 0, "sectionItemType": "field", "startCol": 0 } ], "maxW": 3, "minH": 1, "minW": 1, "moved": false, "name": "7. Discovery Remediation", "static": false, "w": 1, "x": 0, "y": 7 }, { "description": "Privilege Escalation consists of techniques that adversaries use to gain higher-level permissions on a system or network.", "displayType": "ROW", "h": 3, "hideItemTitleOnlyOne": true, "hideName": false, "i": "caseinfoid-iu7vqsykkr-610e86f0-9b90-11eb-b7cc-01480a639de2", "items": [ { "endCol": 2, "fieldId": "privilegeescalationremediationproducts", "height": 22, "id": "8248b3f0-cdcb-11eb-a582-e785b47b3136", "index": 0, "sectionItemType": "field", "startCol": 0 } ], "maxW": 3, "minH": 1, "minW": 1, "moved": false, "name": "4. Privilege Escalation Remediation", "static": false, "w": 1, "x": 0, "y": 4 }, { "description": "Impact consists of techniques that adversaries use to disrupt availability or compromise integrity by manipulating business and operational processes. ", "displayType": "ROW", "h": 3, "hideItemTitleOnlyOne": true, "hideName": false, "i": "caseinfoid-iu7vqsykkr-c45b5d50-9b90-11eb-b7cc-01480a639de2", "items": [ { "endCol": 2, "fieldId": "impactremediationproducts", "height": 22, "id": "b83f9400-cebc-11eb-8aa5-5bace041f776", "index": 0, "sectionItemType": "field", "startCol": 0 } ], "maxW": 3, "minH": 1, "minW": 1, "moved": false, "name": "12. Impact Remediation", "static": false, "w": 1, "x": 2, "y": 10 }, { "description": "Exfiltration consists of techniques that adversaries may use to steal data from your network.", "displayType": "ROW", "h": 3, "hideItemTitleOnlyOne": true, "hideName": false, "i": "caseinfoid-iu7vqsykkr-ccaeb650-9b90-11eb-b7cc-01480a639de2", "items": [ { "endCol": 2, "fieldId": "exfiltrationremediationproducts", "height": 22, "id": "b5927560-cebc-11eb-8aa5-5bace041f776", "index": 0, "sectionItemType": "field", "startCol": 0 } ], "maxW": 3, "minH": 1, "minW": 1, "moved": false, "name": "11. Exfiltration Remediation", "static": false, "w": 1, "x": 1, "y": 10 }, { "description": "Command and Control consists of techniques that adversaries may use to communicate with systems under their control within a victim network. ", "displayType": "ROW", "h": 3, "hideItemTitleOnlyOne": true, "hideName": false, "i": "caseinfoid-iu7vqsykkr-d1851d90-9b90-11eb-b7cc-01480a639de2", "items": [ { "endCol": 2, "fieldId": "commandandcontrolremediationproducts", "height": 22, "id": "b2df8a60-cebc-11eb-8aa5-5bace041f776", "index": 0, "sectionItemType": "field", "startCol": 0 } ], "maxW": 3, "minH": 1, "minW": 1, "moved": false, "name": "10. Command and Control Remediation", "static": false, "w": 1, "x": 0, "y": 10 }, { "description": "", "displayType": "ROW", "h": 1, "hideItemTitleOnlyOne": true, "hideName": true, "i": "caseinfoid-5b295fc0-cdcd-11eb-a582-e785b47b3136", "items": [ { "endCol": 6, "fieldId": "executedremediationsummarydescription", "height": 44, "id": "d8a0f460-00cf-11ec-a8c6-87757aa092b3", "index": 0, "sectionItemType": "field", "startCol": 0 } ], "maxW": 3, "minH": 1, "minW": 1, "moved": false, "name": "Tab Description", "static": false, "w": 3, "x": 0, "y": 0 } ], "type": "custom" }, { "hidden": false, "id": "ywkkezjqu7", "name": "Best Practices", "sections": [ { "description": "You can attach an Anti-Spyware profile to a Security policy rule to detect connections initiated by spyware and command-and-control (C2) malware installed on systems on your network.", "displayType": "CARD", "h": 4, "hideName": false, "i": "caseinfoid-field-changed-caseinfoid-1149e420-cd13-11eb-9c43-ffd2cc199f95", "items": [ { "endCol": 2, "fieldId": "antispywareprofilename", "height": 53, "id": "20268480-cd13-11eb-9c43-ffd2cc199f95", "index": 0, "sectionItemType": "field", "startCol": 0 }, { "endCol": 2, "fieldId": "antispywareprofilestatus", "height": 53, "id": "0b2c3630-cd1b-11eb-9c43-ffd2cc199f95", "index": 1, "sectionItemType": "field", "startCol": 0 }, { "endCol": 2, "fieldId": "antispywarerules", "height": 53, "id": "2285d140-cd13-11eb-9c43-ffd2cc199f95", "index": 2, "sectionItemType": "field", "startCol": 0 } ], "maxW": 3, "minH": 1, "minW": 1, "moved": false, "name": "Anti-Spyware Best Practices", "static": false, "w": 1, "x": 0, "y": 1 }, { "description": "Anti-Spyware related passed BPA checks results.", "displayType": "CARD", "h": 2, "hideName": true, "i": "caseinfoid-field-changed-caseinfoid-350e1480-cd13-11eb-9c43-ffd2cc199f95", "items": [ { "endCol": 4, "fieldId": "bpapassedchecksantispyware", "height": 106, "id": "b38b0fc0-cd13-11eb-9c43-ffd2cc199f95", "index": 0, "sectionItemType": "field", "startCol": 0 } ], "maxW": 3, "minH": 1, "minW": 1, "moved": false, "name": "Anti-Spyware Best Practices", "static": false, "w": 2, "x": 1, "y": 1 }, { "description": "", "displayType": "ROW", "h": 1, "hideItemTitleOnlyOne": true, "hideName": true, "i": "caseinfoid-field-changed-caseinfoid-3c4ac600-cd16-11eb-9c43-ffd2cc199f95", "items": [ { "dropEffect": "move", "endCol": 6, "fieldId": "bestpracticesdescription", "height": 44, "id": "e3a64e00-00cf-11ec-a8c6-87757aa092b3", "index": 0, "listId": "caseinfoid-field-changed-caseinfoid-3c4ac600-cd16-11eb-9c43-ffd2cc199f95", "sectionItemType": "field", "startCol": 0 } ], "maxW": 3, "minH": 1, "minW": 1, "moved": false, "name": "Tab Description", "static": false, "w": 3, "x": 0, "y": 0 }, { "description": "Use a WildFire Analysis profile to specify for WildFire file analysis to be performed locally on the WildFire appliance or in the WildFire cloud. You can specify traffic to be forwarded to the public cloud or private cloud based on file type, application, or the transmission direction of the file (upload or download).", "displayType": "CARD", "h": 4, "hideName": false, "i": "caseinfoid-field-changed-caseinfoid-003bf5c0-cd1c-11eb-8766-35d3e4cb24da", "items": [ { "endCol": 2, "fieldId": "wildfireprofilename", "height": 22, "id": "29e4a200-cd1c-11eb-8766-35d3e4cb24da", "index": 0, "sectionItemType": "field", "startCol": 0 }, { "endCol": 2, "fieldId": "wildfireprofilestatus", "height": 22, "id": "2a9c0b20-cd1c-11eb-8766-35d3e4cb24da", "index": 1, "sectionItemType": "field", "startCol": 0 }, { "endCol": 2, "fieldId": "wildfirerules", "height": 22, "id": "2b541080-cd1c-11eb-8766-35d3e4cb24da", "index": 2, "sectionItemType": "field", "startCol": 0 } ], "maxW": 3, "minH": 1, "minW": 1, "moved": false, "name": "WildFire Best Practices", "static": false, "w": 1, "x": 0, "y": 21 }, { "description": "WildFire related passed BPA checks results.", "displayType": "CARD", "h": 2, "hideName": true, "i": "caseinfoid-field-changed-caseinfoid-2fa12380-cd1c-11eb-8766-35d3e4cb24da", "items": [ { "dropEffect": "move", "endCol": 4, "fieldId": "bpapassedcheckswildfire", "height": 106, "id": "40a16730-cd1c-11eb-8766-35d3e4cb24da", "index": 0, "listId": "caseinfoid-2fa12380-cd1c-11eb-8766-35d3e4cb24da", "sectionItemType": "field", "startCol": 0 } ], "maxW": 3, "minH": 1, "minW": 1, "moved": false, "name": "WildFire Best Practices", "static": false, "w": 2, "x": 1, "y": 21 }, { "description": "Use the Antivirus Profiles page to configure options to have the firewall scan for viruses on the defined traffic. Set the applications that should be inspected for viruses and the action to take when a virus is detected.", "displayType": "CARD", "h": 4, "hideName": false, "i": "caseinfoid-53e833f0-cd26-11eb-8ee9-7b77bae6a305", "items": [ { "endCol": 2, "fieldId": "antivirusprofilename", "height": 53, "id": "839c6c10-cd26-11eb-8ee9-7b77bae6a305", "index": 0, "sectionItemType": "field", "startCol": 0 }, { "endCol": 2, "fieldId": "antivirusprofilestatus", "height": 53, "id": "84e7fee0-cd26-11eb-8ee9-7b77bae6a305", "index": 1, "sectionItemType": "field", "startCol": 0 }, { "endCol": 2, "fieldId": "antivirusrules", "height": 53, "id": "85aef860-cd26-11eb-8ee9-7b77bae6a305", "index": 2, "sectionItemType": "field", "startCol": 0 } ], "maxW": 3, "minH": 1, "minW": 1, "moved": false, "name": "Anti-Virus Best Practices", "static": false, "w": 1, "x": 0, "y": 5 }, { "description": "Anti-Virus related passed BPA checks results.", "displayType": "CARD", "h": 2, "hideName": true, "i": "caseinfoid-56b02d90-cd26-11eb-8ee9-7b77bae6a305", "items": [ { "dropEffect": "move", "endCol": 4, "fieldId": "bpapassedchecksantivirus", "height": 106, "id": "8d55bdb0-cd26-11eb-8ee9-7b77bae6a305", "index": 0, "listId": "caseinfoid-56b02d90-cd26-11eb-8ee9-7b77bae6a305", "sectionItemType": "field", "startCol": 0 } ], "maxW": 3, "minH": 1, "minW": 1, "moved": false, "name": "Anti-Virus Best Practices", "static": false, "w": 2, "x": 1, "y": 5 }, { "description": "You can attach a File Blocking profile to a Security policy rule to block users from uploading or downloading specified file types or to generate an alert when a user attempts to upload or download specified file types.", "displayType": "CARD", "h": 4, "hideName": false, "i": "caseinfoid-258e6640-cd27-11eb-8ee9-7b77bae6a305", "items": [ { "endCol": 2, "fieldId": "fileblockingprofilename", "height": 53, "id": "65b6ceb0-cd27-11eb-8ee9-7b77bae6a305", "index": 0, "sectionItemType": "field", "startCol": 0 }, { "endCol": 2, "fieldId": "fileblockingprofilestatus", "height": 53, "id": "67012900-cd27-11eb-8ee9-7b77bae6a305", "index": 1, "sectionItemType": "field", "startCol": 0 }, { "endCol": 2, "fieldId": "fileblockingrules", "height": 53, "id": "67ab72c0-cd27-11eb-8ee9-7b77bae6a305", "index": 2, "sectionItemType": "field", "startCol": 0 } ], "maxW": 3, "minH": 1, "minW": 1, "moved": false, "name": "File Blocking Best Practices", "static": false, "w": 1, "x": 0, "y": 9 }, { "description": "File Blocking related passed BPA checks results.", "displayType": "CARD", "h": 2, "hideName": true, "i": "caseinfoid-29a749e0-cd27-11eb-8ee9-7b77bae6a305", "items": [ { "endCol": 4, "fieldId": "bpapassedchecksfileblocking", "height": 106, "id": "695c3000-cd27-11eb-8ee9-7b77bae6a305", "index": 0, "sectionItemType": "field", "startCol": 0 } ], "maxW": 3, "minH": 1, "minW": 1, "moved": false, "name": "File Blocking Best Practices", "static": false, "w": 2, "x": 1, "y": 9 }, { "description": "You can use URL filtering profiles to control access to web content.", "displayType": "CARD", "h": 4, "hideName": false, "i": "caseinfoid-5572d620-cd27-11eb-8ee9-7b77bae6a305", "items": [ { "endCol": 2, "fieldId": "urlfilteringprofilename", "height": 53, "id": "387e5a10-cd29-11eb-b1f3-911e8cb48678", "index": 0, "sectionItemType": "field", "startCol": 0 }, { "endCol": 2, "fieldId": "urlfilteringprofilestatus", "height": 53, "id": "398542c0-cd29-11eb-b1f3-911e8cb48678", "index": 1, "sectionItemType": "field", "startCol": 0 }, { "endCol": 2, "fieldId": "urlfilteringrules", "height": 53, "id": "3aafb900-cd29-11eb-b1f3-911e8cb48678", "index": 2, "sectionItemType": "field", "startCol": 0 } ], "maxW": 3, "minH": 1, "minW": 1, "moved": false, "name": "URL Filtering Best Practices", "static": false, "w": 1, "x": 0, "y": 13 }, { "description": "URL Filtering related passed BPA checks results.", "displayType": "CARD", "h": 2, "hideName": true, "i": "caseinfoid-5d17c6b0-cd27-11eb-8ee9-7b77bae6a305", "items": [ { "endCol": 4, "fieldId": "bpapassedchecksurlfiltering", "height": 106, "id": "3cffc380-cd29-11eb-b1f3-911e8cb48678", "index": 0, "sectionItemType": "field", "startCol": 0 } ], "maxW": 3, "minH": 1, "minW": 1, "moved": false, "name": "URL Filtering Best Practices", "static": false, "w": 2, "x": 1, "y": 13 }, { "description": "A Security policy rule can include specification of a Vulnerability Protection profile that determines the level of protection against buffer overflows, illegal code execution, and other attempts to exploit system vulnerabilities.", "displayType": "CARD", "h": 4, "hideName": false, "i": "caseinfoid-bbc32880-cd27-11eb-8ee9-7b77bae6a305", "items": [ { "endCol": 2, "fieldId": "vulnerabilityprotectionprofilename", "height": 53, "id": "5cbb3ce0-cd29-11eb-b1f3-911e8cb48678", "index": 0, "sectionItemType": "field", "startCol": 0 }, { "endCol": 2, "fieldId": "vulnerabilityprotectionprofilestatus", "height": 53, "id": "5d6b04e0-cd29-11eb-b1f3-911e8cb48678", "index": 1, "sectionItemType": "field", "startCol": 0 }, { "endCol": 2, "fieldId": "vulnerabilityprotectionrules", "height": 22, "id": "5e010350-cd29-11eb-b1f3-911e8cb48678", "index": 2, "sectionItemType": "field", "startCol": 0 } ], "maxW": 3, "minH": 1, "minW": 1, "moved": false, "name": "Vulnerability Protection Best Practices", "static": false, "w": 1, "x": 0, "y": 17 }, { "description": "Vulnerability Protection related passed BPA checks results.", "displayType": "CARD", "h": 2, "hideName": true, "i": "caseinfoid-bd364080-cd27-11eb-8ee9-7b77bae6a305", "items": [ { "endCol": 4, "fieldId": "bpapassedchecksvulnerabilityprotection", "height": 106, "id": "5f920390-cd29-11eb-b1f3-911e8cb48678", "index": 0, "sectionItemType": "field", "startCol": 0 } ], "maxW": 3, "minH": 1, "minW": 1, "moved": false, "name": "Vulnerability Protection Best Practices", "static": false, "w": 2, "x": 1, "y": 17 }, { "description": "Anti-Spyware related failed BPA checks results.", "displayType": "CARD", "h": 2, "hideName": true, "i": "caseinfoid-db43a230-cdcb-11eb-a582-e785b47b3136", "items": [ { "endCol": 4, "fieldId": "bpafailedchecksantispyware", "height": 106, "id": "b1006d40-cd13-11eb-9c43-ffd2cc199f95", "index": 0, "sectionItemType": "field", "startCol": 0 } ], "maxW": 3, "minH": 1, "minW": 1, "moved": false, "name": "New Section", "static": false, "w": 2, "x": 1, "y": 3 }, { "description": "Anti-Virus related failed BPA checks results.", "displayType": "CARD", "h": 2, "hideName": true, "i": "caseinfoid-02c46560-cdcc-11eb-a582-e785b47b3136", "items": [ { "dropEffect": "move", "endCol": 4, "fieldId": "bpafailedchecksantivirus", "height": 106, "id": "92ff7a80-cd26-11eb-8ee9-7b77bae6a305", "index": 0, "listId": "caseinfoid-56b02d90-cd26-11eb-8ee9-7b77bae6a305", "sectionItemType": "field", "startCol": 0 } ], "maxW": 3, "minH": 1, "minW": 1, "moved": false, "name": "New Section", "static": false, "w": 2, "x": 1, "y": 7 }, { "description": "File Blocking related failed BPA checks results.", "displayType": "CARD", "h": 2, "hideName": true, "i": "caseinfoid-2ded4901-cdcc-11eb-a582-e785b47b3136", "items": [ { "endCol": 4, "fieldId": "bpafailedchecksfileblocking", "height": 106, "id": "6a1df960-cd27-11eb-8ee9-7b77bae6a305", "index": 0, "sectionItemType": "field", "startCol": 0 } ], "maxW": 3, "minH": 1, "minW": 1, "moved": false, "name": "New Section", "static": false, "w": 2, "x": 1, "y": 11 }, { "description": "URL Filtering related failed BPA checks results.", "displayType": "CARD", "h": 2, "hideName": true, "i": "caseinfoid-6f948940-cdcc-11eb-a582-e785b47b3136", "items": [ { "endCol": 4, "fieldId": "bpafailedchecksurlfiltering", "height": 106, "id": "3dfdf9a0-cd29-11eb-b1f3-911e8cb48678", "index": 0, "sectionItemType": "field", "startCol": 0 } ], "maxW": 3, "minH": 1, "minW": 1, "moved": false, "name": "New Section", "static": false, "w": 2, "x": 1, "y": 15 }, { "description": "Vulnerability Protection related failed BPA checks results.", "displayType": "CARD", "h": 2, "hideName": true, "i": "caseinfoid-9550b911-cdcc-11eb-a582-e785b47b3136", "items": [ { "endCol": 4, "fieldId": "bpafailedchecksvulnerabilityprotection", "height": 106, "id": "60862790-cd29-11eb-b1f3-911e8cb48678", "index": 0, "sectionItemType": "field", "startCol": 0 } ], "maxW": 3, "minH": 1, "minW": 1, "moved": false, "name": "New Section", "static": false, "w": 2, "x": 1, "y": 19 }, { "description": "WildFire related failed BPA checks results.", "displayType": "CARD", "h": 2, "hideName": true, "i": "caseinfoid-b682cce1-cdcc-11eb-a582-e785b47b3136", "items": [ { "dropEffect": "move", "endCol": 4, "fieldId": "bpafailedcheckswildfire", "height": 106, "id": "3eaa2b10-cd1c-11eb-8766-35d3e4cb24da", "index": 0, "listId": "caseinfoid-2fa12380-cd1c-11eb-8766-35d3e4cb24da", "sectionItemType": "field", "startCol": 0 } ], "maxW": 3, "minH": 1, "minW": 1, "moved": false, "name": "New Section", "static": false, "w": 2, "x": 1, "y": 23 } ], "type": "custom" }, { "id": "warRoom", "name": "War Room", "type": "warRoom" }, { "id": "workPlan", "name": "Work Plan", "type": "workPlan" }, { "id": "evidenceBoard", "name": "Evidence Board", "type": "evidenceBoard" }, { "id": "relatedIncidents", "name": "Related Incidents", "type": "relatedIncidents" }, { "id": "canvas", "name": "Canvas", "type": "canvas" } ] }, "edit": { "sections": [ { "description": "Enter a list of comma-separated techniques you wish to handle with this incident type.", "fields": [ { "fieldId": "incident_techniqueslist", "isVisible": true } ], "isVisible": true, "name": "Techniques List", "query": null, "queryType": "", "readOnly": false, "type": "" }, { "description": "", "fields": [ { "fieldId": "incident_name", "isVisible": true }, { "fieldId": "incident_occurred", "isVisible": true }, { "fieldId": "incident_reminder", "isVisible": true }, { "fieldId": "incident_owner", "isVisible": true }, { "fieldId": "incident_roles", "isVisible": true }, { "fieldId": "incident_type", "isVisible": true }, { "fieldId": "incident_severity", "isVisible": true }, { "fieldId": "incident_playbookid", "isVisible": true }, { "fieldId": "incident_labels", "isVisible": true }, { "fieldId": "incident_phase", "isVisible": true }, { "fieldId": "incident_details", "isVisible": true }, { "fieldId": "incident_attachment", "isVisible": true } ], "isVisible": true, "name": "Basic Information", "query": null, "queryType": "", "readOnly": false, "type": "" }, { "description": "", "fields": [ { "fieldId": "incident_agentid", "isVisible": true }, { "fieldId": "incident_alertid", "isVisible": true }, { "fieldId": "incident_alertname", "isVisible": true }, { "fieldId": "incident_app", "isVisible": true }, { "fieldId": "incident_assigneduser", "isVisible": true }, { "fieldId": "incident_assignmentgroup", "isVisible": true }, { "fieldId": "incident_caller", "isVisible": true }, { "fieldId": "incident_commandline", "isVisible": true }, { "fieldId": "incident_country", "isVisible": true }, { "fieldId": "incident_dbotprediction", "isVisible": true }, { "fieldId": "incident_dbotpredictionprobability", "isVisible": true }, { "fieldId": "incident_destinationhostname", "isVisible": true }, { "fieldId": "incident_destinationip", "isVisible": true }, { "fieldId": "incident_destinationnetwork", "isVisible": true }, { "fieldId": "incident_destinationport", "isVisible": true }, { "fieldId": "incident_detectionurl", "isVisible": true }, { "fieldId": "incident_deviceexternalip", "isVisible": true }, { "fieldId": "incident_devicehash", "isVisible": true }, { "fieldId": "incident_devicelocalip", "isVisible": true }, { "fieldId": "incident_devicemodel", "isVisible": true }, { "fieldId": "incident_devicename", "isVisible": true }, { "fieldId": "incident_escalation", "isVisible": true }, { "fieldId": "incident_eventid", "isVisible": true }, { "fieldId": "incident_eventtype", "isVisible": true }, { "fieldId": "incident_filehash", "isVisible": true }, { "fieldId": "incident_filename", "isVisible": true }, { "fieldId": "incident_filepath", "isVisible": true }, { "fieldId": "incident_filesize", "isVisible": true }, { "fieldId": "incident_firstname", "isVisible": true }, { "fieldId": "incident_incomingmirrorerror", "isVisible": true }, { "fieldId": "incident_investigationstage", "isVisible": true }, { "fieldId": "incident_lastname", "isVisible": true }, { "fieldId": "incident_logsource", "isVisible": true }, { "fieldId": "incident_lowlevelcategoriesevents", "isVisible": true }, { "fieldId": "incident_macaddress", "isVisible": true }, { "fieldId": "incident_md5", "isVisible": true }, { "fieldId": "incident_mobiledevicemodel", "isVisible": true }, { "fieldId": "incident_os", "isVisible": true }, { "fieldId": "incident_osversion", "isVisible": true }, { "fieldId": "incident_outgoingmirrorerror", "isVisible": true }, { "fieldId": "incident_phonenumber", "isVisible": true }, { "fieldId": "incident_pid", "isVisible": true }, { "fieldId": "incident_protocol", "isVisible": true }, { "fieldId": "incident_sha256", "isVisible": true }, { "fieldId": "incident_sourcehostname", "isVisible": true }, { "fieldId": "incident_sourceip", "isVisible": true }, { "fieldId": "incident_sourcenetwork", "isVisible": true }, { "fieldId": "incident_sourceport", "isVisible": true }, { "fieldId": "incident_sourceusername", "isVisible": true }, { "fieldId": "incident_state", "isVisible": true }, { "fieldId": "incident_subcategory", "isVisible": true }, { "fieldId": "incident_tenantname", "isVisible": true }, { "fieldId": "incident_ticketcloseddate", "isVisible": true }, { "fieldId": "incident_ticketnumber", "isVisible": true }, { "fieldId": "incident_ticketopeneddate", "isVisible": true }, { "fieldId": "incident_urlsslverification", "isVisible": true }, { "fieldId": "incident_useraccountcontrol", "isVisible": true } ], "isVisible": true, "name": "Custom Fields", "query": null, "queryType": "", "readOnly": false, "type": "" } ] }, "group": "incident", "id": "Mitre COA - MITRE Layout", "name": "Mitre COA - MITRE Layout", "system": false, "version": -1, "fromVersion": "6.5.0", "description": "", "marketplaces": ["xsoar"] }