CVE-2021-22893 - Pulse Connect Secure RCE

On April 20th, a new Remote Code Execution vulnerability in Pulse Connect Secure was disclosed. The reference number for the vulnerability is CVE-2021-22893 with the CVSS Score of 10.0. This playbook should be trigger manually and includes the following tasks: * Enrich related known CVEs and Malware Hashes used by the suspected APT actor. * Search for unpatched endpoints vulnerable to the exploits. * Search network facing system using Expanse for relevant issues. * Indicators and known webshells hunting using SIEM products. * Block indicators automatically or manually. * Provide different mitigations that has been publicly published such as: * Patches * Workarounds * Yara and Snort Rules Note: This is a beta playbook, which lets you implement and test pre-release software. Since the playbook is beta, it might contain bugs. Updates to the pack during the beta phase might include non-backward compatible features. We appreciate your feedback on the quality and usability of the pack to help us identify issues, fix them, and continually improve. More information: [Exploitation of Pulse Connect Secure Vulnerabilities](https://us-cert.cisa.gov/ncas/alerts/aa21-110a)

Rapid Breach Response · 35 tasks · 11 inputs · 0 outputs

Details

IDCVE-2021-22893 - Pulse Connect Secure RCE
From Version6.0.0
To Version6.4.9
Tasks35

README

On April 20th, a new Remote Code Execution vulnerability in Pulse Connect Secure was disclosed.
The reference number for the vulnerability is CVE-2021-22893 with the CVSS Score of 10.0.
This playbook should be trigger manually and includes the following tasks:

  • Enrich related known CVEs and Malware Hashes used by the suspected APT actor.
  • Search for unpatched endpoints vulnerable to the exploits.
  • Search network facing system using Expanse for relevant issues.
  • Indicators and known webshells hunting using SIEM products.
  • Block indicators automatically or manually.
  • Provide different mitigations that has been publicly published such as:
    • Patches
    • Workarounds
    • Yara and Snort Rules

Note: This is a beta playbook, which lets you implement and test pre-release software. Since the playbook is beta, it might contain bugs. Updates to the pack during the beta phase might include non-backward compatible features. We appreciate your feedback on the quality and usability of the pack to help us identify issues, fix them, and continually improve.

More information:
Exploitation of Pulse Connect Secure Vulnerabilities

Dependencies

This playbook uses the following sub-playbooks, integrations, and scripts.

Sub-playbooks

  • QRadar Indicator Hunting V2
  • QRadarFullSearch
  • Search Endpoint by CVE - Generic
  • Palo Alto Networks - Hunting And Threat Detection
  • Block Indicators - Generic v2
  • Splunk Indicator Hunting

Integrations

This playbook does not use any integrations.

Scripts

This playbook does not use any scripts.

Commands

  • expanse-get-issues
  • enrichIndicators
  • splunk-search
  • extractIndicators

Playbook Inputs


Name Description Default Value Required
Related_Hashes The known hashes of different malware families associated with the exploitation. 06c56bd272b19bf7d7207443693cd1fc774408c4ca56744577b11fee550c23f7,64c87520565165ac95b74d6450b3ab8379544933dd3e2f2c4dc9b03a3ec570a7,1322340356018696d853e0ac6f7ce3a2,09956753b5000061524d204000000001,88170125598a4fb801102ad56494a773895059ac8550a983fdd2ef429653f079,9f6ac39707822d243445e30d27b8404466aa69c61119d5308785bf4a464a9ebd,325d6d60e24c7cfc3a782839d85ce08c8d3bb27c,1ab50b77dd9515f6cd9ed07d1d3176ba4627a292dc4a21b16ac9d211353818bd,1741dc0a491fcc8d078220ac9628152668d3370b92a8eae258e34ba28c6473b9,cd09ec795a8f4b6ced003500a44d810f49943514e2f92c81ab96c33e1c0fbd68,d72daafedf41d484f7f9816f7f076a9249a6808f1899649b7daa22c0447bb37b,c9b323b9747659eac25cec078895d75f016e26a8b5858567c7fb945b7321722c,2610d0372e0e107053bc001d278ef71f08562e5610691f18b978123c499a74d8,c774eca633136de35c9d2cd339a3b5d29f00f761657ea2aa438de4f33e4bbba4,224b7c45cf6fe4547d3ea66a12c30f3cb4c601b0a80744154697094e73dbd450,78d7c7c9f800f6824f63a99d935a4ad0112f97953d8c100deb29dae24d7da282,1d3ab04e21cfd40aa8d4300a359a09e3b520d39b1496be1e4bc91ae1f6730ecc,133631957d41eed9496ac2774793283ce26f8772de226e7f520d26667b51481a,68743e17f393d1f85ee937dffacc91e081b5f6f43477111ac96aa9d44826e4d2,7fa71a7f76ef63465cfeacf58217e0b66fc71bc81d37c44380a6f572b8a3ec7a,f2b1bd703c3eb05541ff84ec375573cbdc70309ccb82aac04b72db205d718e90,a1dcdf62aafc36dd8cf64774dea80d79fb4e24ba2a82adf4d944d9186acd1cc1,e63ab6f82c711e4ecc8f5b36046eb7ea216f41eb90158165b82a6c90560ea415,b2350954b9484ae4eac42b95fae6edf7a126169d0b93d79f49d36c5e6497062a,b1c2368773259fbfef425e0bb716be958faa7e74b3282138059f511011d3afd9,b990f79ce80c24625c97810cb8f161eafdcb10f1b8d9d538df4ca9be387c35e4,168976797d5af7071df257e91fcc31ce1d6e59c72ca9e2f50c8b5b3177ad83cc,4c5555955b2e6dc55f52b0c1a3326f3d07b325b112060329c503b294208960ec,705cda7d1ace8f4adeec5502aa311620b8d6c64046a1aed2ae833e2f2835154f Optional
Related_CVEs The known CVEs associated with the exploitation. CVE-2019-11510, CVE-2020-8260, CVE-2020-8243, CVE-2021-22893 Optional
BlockAutomatically Whether to block the indicators automatically.
Default: False.
False Optional
QRadarWebshellsQuery The QRadar search query used for “Hunt Activity Using QRadar”.
Please note that there aren’t specified fields which may cause a longer run time.
select * from events WHERE LogSourceTypeName(deviceType) = ‘Pulse Secure Pulse Connect Secure’ and ( UTF8(payload) LIKE ‘%Licenseserverproto.cgi%’ or UTF8(payload) LIKE ‘%Secid_canceltoken.cgi%’ or UTF8(payload) LIKE ‘%compcheckresult.cgi%’ or UTF8(payload) LIKE ‘%Login.cgi%’ or UTF8(payload) LIKE ‘%Healthcheck.cgi%’ or UTF8(payload) LIKE ‘%meeting_testjs.cgi%’ or UTF8(payload) LIKE ‘%compcheckjava.cgi%’) Optional
SplunkWebshellsQuery The Splunk search query used for “Hunt Activity Using Splunk”.
Please note that there are two specified fields: msg, message. the query will work for both field names.
index=* sourcetype=pulse:connectsecure “Licenseserverproto.cgi” OR “Secid_canceltoken.cgi” OR “compcheckresult.cgi” OR “Healthcheck.cgi” OR “meeting_testjs.cgi” OR “compcheckjava.cgi” Optional
RunWebshellsQuery If you would like to skip “Hunt Activity Using Splunk” OR “Hunt Activity Using Qradar” please change the value to ‘False’. True Optional
QRadar_MD5_Field The name of the field for MD5 entries in QRadar.
If not configured, QRadar Indicator Hunting may reach timeout.
  Optional
QRadar_SHA1_Field The name of the field for SHA1 entries in QRadar.
If not configured, QRadar Indicator Hunting may reach timeout.
  Optional
QRadar_SHA256_Field The name of the field for SHA256 entries in QRadar.
If not configured, QRadar Indicator Hunting may reach timeout.
  Optional
SplunkEarliestTime The earliest time for the Splunk search query. -30d Optional
SplunkLatestTime The latest time for the Splunk search query. now Optional

Playbook Outputs


There are no outputs for this playbook.

Playbook Image


CVE-2021-22893 - Pulse Connect Secure RCE

Inputs

  • Related_Hashes — The known hashes of different malware families associated with the exploitation.
  • Related_CVEs — The known CVEs associated with the exploitation.
  • BlockAutomatically — Whether to block the indicators automatically. Default: False.
  • QRadarWebshellsQuery — The QRadar search query used for "Hunt Activity Using QRadar". Please note that there aren't specified fields which may cause a longer run time.
  • SplunkWebshellsQuery — The Splunk search query used for "Hunt Activity Using Splunk". Please note that there are two specified fields: msg, message. the query will work for both field names.
  • RunWebshellsQuery — If you would like to skip "Hunt Activity Using Splunk" OR "Hunt Activity Using Qradar" please change the value to 'False'.
  • QRadar_MD5_Field — The name of the field for MD5 entries in QRadar. If not configured, QRadar Indicator Hunting may reach timeout.
  • QRadar_SHA1_Field — The name of the field for SHA1 entries in QRadar. If not configured, QRadar Indicator Hunting may reach timeout.
  • QRadar_SHA256_Field — The name of the field for SHA256 entries in QRadar. If not configured, QRadar Indicator Hunting may reach timeout.
  • SplunkEarliestTime — The earliest time for the Splunk search query.
  • SplunkLatestTime — The latest time for the Splunk search query.

Commands used

enrichIndicators expanse-get-issues extractIndicators splunk-search

Flowchart

yes yes No No Yes No Yes No Yes Start Start Enrich CVE Indicators - enrichIndicators Enrich CVE Indicators enrichIndicators Enrich Hash Indicators - enrichIndicators Enrich Hash Indicators enrichIndicators Enrichment Enrichment Hunting Hunting SIEM Hunt SIEM Hunt Vulnerability Scanners Hunt Vulnerability Scanners Hunt Palo Alto Networks Hunt Palo Alto Networks Hunt Search Endpoint by CVE - Generic - Search Endpoint by CVE - Generic Search Endpoint by CVE - ... Search Endpoint by CVE - Generic Palo Alto Networks - Hunting And Threat Detection - Palo Alto Networks - Hunting And Threat Detection Palo Alto Networks - Hunt... Palo Alto Networks - Hunting ... Splunk Indicator Hunting - Splunk Indicator Hunting Splunk Indicator Hunting Splunk Indicator Hunting Expanse Issues Hunt Expanse Issues Hunt Search for Pulse Secure VPN Devices with an open issues - expanse-get-issues Search for Pulse Secure V... expanse-get-issues Remediation Remediation Block indicators automatically? Block indicators automati... Is Expanse Enabled? Is Expanse Enabled? Block Indicators - Generic v2 - Block Indicators - Generic v2 Block Indicators - Generi... Block Indicators - Generic v2 Manually block indicators Manually block indicators Mitigation Mitigation Is Pulse Secure is patched? Is Pulse Secure is patched? Review all data collected Review all data collected Install related patches and workarounds Install related patches a... Run Pulse Connect Secure Integrity Tool Run Pulse Connect Secure ... Download Yara/Snort rules from FireEye Mandiant GitHub repository Download Yara/Snort rules... Webshell Access Attempts Hunt Webshell Access Attempts ... Hunt Activity Using Splunk Hunt Activity Using Splunk Hunt Activity Using Qradar Hunt Activity Using Qradar Search access attempts in Pulse Secure Logs - splunk-search Search access attempts in... splunk-search QRadarFullSearch - QRadarFullSearch QRadarFullSearch QRadarFullSearch Is QRadar Enabled? Is QRadar Enabled? Hunt for the webshells names in PCS logs Hunt for the webshells na... Done Done Extract Indicators - extractIndicators Extract Indicators extractIndicators QRadar Indicator Hunting V2 - QRadar Indicator Hunting V2 QRadar Indicator Hunting V2 QRadar Indicator Hunting V2 Is Splunk Enabled? Is Splunk Enabled?
id: CVE-2021-22893 - Pulse Connect Secure RCE
version: -1
name: CVE-2021-22893 - Pulse Connect Secure RCE
description: "On April 20th, a new Remote Code Execution vulnerability in Pulse Connect\
  \ Secure was disclosed. \nThe reference number for the vulnerability is CVE-2021-22893\
  \ with the CVSS Score of 10.0. \nThis playbook should be trigger manually and includes\
  \ the following tasks: \n\n* Enrich related known CVEs and Malware Hashes used by\
  \ the suspected APT actor.\n* Search for unpatched endpoints vulnerable to the exploits.\n\
  * Search network facing system using Expanse for relevant issues.\n* Indicators\
  \ and known webshells hunting using SIEM products.\n* Block indicators automatically\
  \ or manually.\n* Provide different mitigations that has been publicly published\
  \ such as:\n    * Patches\n    * Workarounds\n    * Yara and Snort Rules\n\nNote:\
  \ This is a beta playbook, which lets you implement and test pre-release software.\
  \ Since the playbook is beta, it might contain bugs. Updates to the pack during\
  \ the beta phase might include non-backward compatible features. We appreciate your\
  \ feedback on the quality and usability of the pack to help us identify issues,\
  \ fix them, and continually improve.\n\nMore information:\n[Exploitation of Pulse\
  \ Connect Secure Vulnerabilities](https://us-cert.cisa.gov/ncas/alerts/aa21-110a)\n"
starttaskid: "0"
tasks:
  "0":
    id: "0"
    taskid: 8308f76e-de23-4b77-8c7a-0b1b2e734d5e
    type: start
    task:
      id: 8308f76e-de23-4b77-8c7a-0b1b2e734d5e
      version: -1
      name: ""
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "35"
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 770,
          "y": -270
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: true
    quietmode: 0
  "1":
    id: "1"
    taskid: 28b3f68d-e04e-4e85-8f3d-677e40a436e4
    type: regular
    task:
      id: 28b3f68d-e04e-4e85-8f3d-677e40a436e4
      version: -1
      name: Enrich CVE Indicators
      description: Enrich CVEs indicators
      script: Builtin|||enrichIndicators
      type: regular
      iscommand: true
      brand: Builtin
    nexttasks:
      '#none#':
      - "4"
    scriptarguments:
      indicatorsValues:
        complex:
          root: CVE
          accessor: ID
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 540,
          "y": 230
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: true
    quietmode: 0
  "2":
    id: "2"
    taskid: 9cf18652-2511-462e-8623-a41414ff940f
    type: regular
    task:
      id: 9cf18652-2511-462e-8623-a41414ff940f
      version: -1
      name: Enrich Hash Indicators
      description: commands.local.cmd.enrich.indicators
      script: Builtin|||enrichIndicators
      type: regular
      iscommand: true
      brand: Builtin
    nexttasks:
      '#none#':
      - "4"
    scriptarguments:
      indicatorsValues:
        complex:
          root: File
          accessor: MD5
          transformers:
          - operator: append
            args:
              item:
                value:
                  simple: File.SHA1
                iscontext: true
          - operator: append
            args:
              item:
                value:
                  simple: File.SHA256
                iscontext: true
      retry-count:
        simple: "3"
      retry-interval:
        simple: "5"
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 990,
          "y": 230
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
  "3":
    id: "3"
    taskid: 9ffb88c1-032f-4403-8e5b-61bdb5cff00f
    type: title
    task:
      id: 9ffb88c1-032f-4403-8e5b-61bdb5cff00f
      version: -1
      name: Enrichment
      type: title
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "2"
      - "1"
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 770,
          "y": 70
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
  "4":
    id: "4"
    taskid: a69b6038-bc82-43ce-800f-651e192a97f6
    type: title
    task:
      id: a69b6038-bc82-43ce-800f-651e192a97f6
      version: -1
      name: Hunting
      type: title
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "5"
      - "6"
      - "7"
      - "12"
      - "25"
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 770,
          "y": 410
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
  "5":
    id: "5"
    taskid: efe4361d-334c-46f6-8877-2c206718b950
    type: title
    task:
      id: efe4361d-334c-46f6-8877-2c206718b950
      version: -1
      name: SIEM Hunt
      type: title
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "10"
      - "37"
    separatecontext: false
    view: |-
      {
        "position": {
          "x": -1040,
          "y": 620
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: true
    quietmode: 0
  "6":
    id: "6"
    taskid: 9b4033c8-84a0-4fed-8fb0-043bb7d72bac
    type: title
    task:
      id: 9b4033c8-84a0-4fed-8fb0-043bb7d72bac
      version: -1
      name: Vulnerability Scanners Hunt
      type: title
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "8"
    separatecontext: false
    view: |-
      {
        "position": {
          "x": -300,
          "y": 620
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
  "7":
    id: "7"
    taskid: c4a760fc-71bf-46c1-8633-3892e4e5444b
    type: title
    task:
      id: c4a760fc-71bf-46c1-8633-3892e4e5444b
      version: -1
      name: Palo Alto Networks Hunt
      type: title
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "9"
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 1810,
          "y": 620
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: true
    quietmode: 0
  "8":
    id: "8"
    taskid: 704f5545-b3ac-4c1e-898c-b135ddb75438
    type: playbook
    task:
      id: 704f5545-b3ac-4c1e-898c-b135ddb75438
      version: -1
      name: Search Endpoint by CVE - Generic
      description: Hunt for assets with a given CVE using available tools
      playbookName: Search Endpoint by CVE - Generic
      type: playbook
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "14"
    scriptarguments:
      CVE_ID:
        complex:
          root: CVE
          accessor: ID
    separatecontext: true
    loop:
      iscommand: false
      exitCondition: ""
      wait: 1
      max: 100
    view: |-
      {
        "position": {
          "x": -300,
          "y": 780
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: true
    quietmode: 0
  "9":
    id: "9"
    taskid: 6a1b2349-17bb-4286-8337-d962530e44d5
    type: playbook
    task:
      id: 6a1b2349-17bb-4286-8337-d962530e44d5
      version: -1
      name: Palo Alto Networks - Hunting And Threat Detection
      description: "This is a multipurpose playbook used for hunting and threat detection.\
        \ The playbook receives inputs based on hashes, IP addresses, or domain names\
        \ provided manually or from outputs by other playbooks. \nWith the received\
        \ indicators, the playbook leverages data received by PANW products including,\
        \ Cortex Data Lake, Autofocus and Pan-OS to search for IP addresses, host\
        \ names and users related to the provided indicators.\nThe output provided\
        \ by the playbook facilitates pivoting searches for possibly affected IP addresses\
        \ or users."
      playbookName: Palo Alto Networks - Hunting And Threat Detection
      type: playbook
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "14"
    scriptarguments:
      MD5:
        complex:
          root: File
          accessor: MD5
      SHA1:
        complex:
          root: File
          accessor: SHA1
      SHA256:
        complex:
          root: File
          accessor: SHA256
    separatecontext: true
    loop:
      iscommand: false
      exitCondition: ""
      wait: 1
      max: 100
    view: |-
      {
        "position": {
          "x": 1810,
          "y": 780
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: true
    quietmode: 0
  "10":
    id: "10"
    taskid: 343cde81-c933-4cb0-8ede-1dfd30520d80
    type: playbook
    task:
      id: 343cde81-c933-4cb0-8ede-1dfd30520d80
      version: -1
      name: Splunk Indicator Hunting
      description: This playbook queries Splunk for indicators such as file hashes,
        IP addresses, domains, or urls. It outputs detected users, ip addresses, and
        hostnames related to the indicators.
      playbookName: Splunk Indicator Hunting
      type: playbook
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "14"
    scriptarguments:
      IndexName:
        simple: '*'
      MD5:
        complex:
          root: File
          accessor: MD5
      SHA1:
        complex:
          root: File
          accessor: SHA1
      SHA256:
        complex:
          root: File
          accessor: SHA256
      SelectFields:
        simple: source,timestamp
      earliest_time:
        complex:
          root: inputs.SplunkEarliestTime
      event_limit:
        simple: "100"
      latest_time:
        complex:
          root: inputs.SplunkLatestTime
    separatecontext: true
    loop:
      iscommand: false
      exitCondition: ""
      wait: 1
      max: 100
    view: |-
      {
        "position": {
          "x": -810,
          "y": 780
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: true
    quietmode: 0
  "12":
    id: "12"
    taskid: 992a51d5-f474-4be4-8e45-a64b0910a80c
    type: title
    task:
      id: 992a51d5-f474-4be4-8e45-a64b0910a80c
      version: -1
      name: Expanse Issues Hunt
      description: Retrieve issues
      type: title
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "16"
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 2470,
          "y": 620
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: true
    quietmode: 0
  "13":
    id: "13"
    taskid: 70a3df35-5318-4938-8124-4f92cdc581ef
    type: regular
    task:
      id: 70a3df35-5318-4938-8124-4f92cdc581ef
      version: -1
      name: Search for Pulse Secure VPN Devices with an open issues
      description: Retrieve issues related to Pulse Secure VPN.
      script: '|||expanse-get-issues'
      type: regular
      iscommand: true
      brand: ""
    nexttasks:
      '#none#':
      - "14"
    scriptarguments:
      content_search:
        simple: Pulse Secure SSL VPN
      issue_type:
        simple: VPN Device
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 2470,
          "y": 1175
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: true
    quietmode: 0
  "14":
    id: "14"
    taskid: c2668048-baa6-4a58-8269-4079f1cc126e
    type: title
    task:
      id: c2668048-baa6-4a58-8269-4079f1cc126e
      version: -1
      name: Remediation
      type: title
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "15"
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 770,
          "y": 1350
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: true
    quietmode: 0
  "15":
    id: "15"
    taskid: b728f187-fa54-482c-8046-4351f7f062e8
    type: condition
    task:
      id: b728f187-fa54-482c-8046-4351f7f062e8
      version: -1
      name: Block indicators automatically?
      description: Check the playbook input (True/False) responsible for automatically
        block indicators.
      type: condition
      iscommand: false
      brand: ""
    nexttasks:
      '#default#':
      - "18"
      "yes":
      - "17"
    separatecontext: false
    conditions:
    - label: "yes"
      condition:
      - - operator: isEqualString
          left:
            value:
              complex:
                root: inputs.BlockAutomatically
            iscontext: true
          right:
            value:
              simple: "True"
          ignorecase: true
    view: |-
      {
        "position": {
          "x": 770,
          "y": 1510
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
  "16":
    id: "16"
    taskid: 6bbdbffd-9407-43d3-8acb-a65e0b95375c
    type: condition
    task:
      id: 6bbdbffd-9407-43d3-8acb-a65e0b95375c
      version: -1
      name: Is Expanse Enabled?
      description: Check if Expanse instance is enabled.
      type: condition
      iscommand: false
      brand: ""
    nexttasks:
      '#default#':
      - "14"
      "yes":
      - "13"
    separatecontext: false
    conditions:
    - label: "yes"
      condition:
      - - operator: isEqualString
          left:
            value:
              complex:
                root: modules
                filters:
                - - operator: isEqualString
                    left:
                      value:
                        simple: modules.brand
                      iscontext: true
                    right:
                      value:
                        simple: ExpanseV2
                accessor: state
            iscontext: true
          right:
            value:
              simple: active
          ignorecase: true
    view: |-
      {
        "position": {
          "x": 2470,
          "y": 780
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
  "17":
    id: "17"
    taskid: 2398e3b6-387e-4105-8f92-03f7773a0836
    type: playbook
    task:
      id: 2398e3b6-387e-4105-8f92-03f7773a0836
      version: -1
      name: Block Indicators - Generic v2
      playbookName: Block Indicators - Generic v2
      type: playbook
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "19"
    separatecontext: true
    view: |-
      {
        "position": {
          "x": 480,
          "y": 1700
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: true
    quietmode: 0
  "18":
    id: "18"
    taskid: ef38604d-2160-4823-8db3-d52e0e775332
    type: regular
    task:
      id: ef38604d-2160-4823-8db3-d52e0e775332
      version: -1
      name: Manually block indicators
      description: Ask the user to manually block the indicators.
      type: regular
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "19"
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 1050,
          "y": 1700
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
  "19":
    id: "19"
    taskid: e2ff1be7-6ca6-4cb7-84d0-2de9df314da4
    type: title
    task:
      id: e2ff1be7-6ca6-4cb7-84d0-2de9df314da4
      version: -1
      name: Mitigation
      type: title
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "20"
      - "24"
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 770,
          "y": 1890
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
  "20":
    id: "20"
    taskid: 015fc3b3-5f1d-455f-8d1d-4008e8b05eb1
    type: condition
    task:
      id: 015fc3b3-5f1d-455f-8d1d-4008e8b05eb1
      version: -1
      name: Is Pulse Secure is patched?
      description: Check the data collected manually or automatically and decide whether
        Pulse Connect Secure is patched or not.
      type: condition
      iscommand: false
      brand: ""
    nexttasks:
      "No":
      - "22"
      - "23"
      "Yes":
      - "21"
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 770,
          "y": 2070
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
  "21":
    id: "21"
    taskid: 32f4f8dd-9ebe-48a2-813e-b67efad4091b
    type: regular
    task:
      id: 32f4f8dd-9ebe-48a2-813e-b67efad4091b
      version: -1
      name: 'Review all data collected '
      description: Request for final review of the data collected.
      type: regular
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "34"
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 770,
          "y": 2510
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
  "22":
    id: "22"
    taskid: 413d666b-858a-4dc9-8867-2209d4428bed
    type: regular
    task:
      id: 413d666b-858a-4dc9-8867-2209d4428bed
      version: -1
      name: 'Install related patches and workarounds '
      description: |-
        Related patches and workarounds:

        [1.CVE-2021-22893](https://kb.pulsesecure.net/pkb_mobile#article/l:en_US/SA44784/s)
        [2.CVE-2020-8260](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-8260)
        [3.CVE-2020-8243](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-8243)
        [4.CVE-2019-11510](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-11510)

        Deny access to the following URIs:
        ^/+dana/+meeting
        ^/+dana/+fb/+smb
        ^/+dana-cached/+fb/+smb
        ^/+dana-ws/+namedusers
        ^/+dana-ws/+metric

        **Note: SSL decryption is needed in order to deny access to the provided URIs.**
      type: regular
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "21"
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 440,
          "y": 2310
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
  "23":
    id: "23"
    taskid: 5ce15d56-9f45-47f8-899c-2b164344b655
    type: regular
    task:
      id: 5ce15d56-9f45-47f8-899c-2b164344b655
      version: -1
      name: 'Run Pulse Connect Secure Integrity Tool '
      description: |-
        This tool created by the vendor will assist with determining if systems have been impacted.

        [Pulse Connect Secure Integrity Tool ](https://kb.pulsesecure.net/articles/Pulse_Secure_Article/KB44755)
      type: regular
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "21"
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 1100,
          "y": 2310
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
  "24":
    id: "24"
    taskid: 45027857-c6de-44da-8745-fce6e0a534c0
    type: regular
    task:
      id: 45027857-c6de-44da-8745-fce6e0a534c0
      version: -1
      name: Download Yara/Snort rules from FireEye Mandiant GitHub repository
      description: |-
        [FireEye Mandiant PulseSecure Exploitation Countermeasures](https://github.com/fireeye/pulsesecure_exploitation_countermeasures)

        These rules are provided freely to the community without warranty.

        In this GitHub repository you will find rules in multiple languages:

        Snort
        Yara
      type: regular
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "34"
    separatecontext: false
    view: |-
      {
        "position": {
          "x": -40,
          "y": 2070
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
  "25":
    id: "25"
    taskid: 8095b0d3-b0b0-4225-83af-81b4cbb0be56
    type: title
    task:
      id: 8095b0d3-b0b0-4225-83af-81b4cbb0be56
      version: -1
      name: Webshell Access Attempts Hunt
      type: title
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "31"
      - "38"
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 770,
          "y": 610
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
  "26":
    id: "26"
    taskid: 709ce95c-f4ec-4d22-86e5-3c9f72d82031
    type: title
    task:
      id: 709ce95c-f4ec-4d22-86e5-3c9f72d82031
      version: -1
      name: Hunt Activity Using Splunk
      type: title
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "28"
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 1200,
          "y": 930
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
  "27":
    id: "27"
    taskid: 5ad6e2d8-9dc6-4197-82c2-5c0b911f7137
    type: title
    task:
      id: 5ad6e2d8-9dc6-4197-82c2-5c0b911f7137
      version: -1
      name: Hunt Activity Using Qradar
      type: title
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "30"
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 340,
          "y": 930
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
  "28":
    id: "28"
    taskid: 60f33e3c-ce34-4ccd-8b65-34d607b5c407
    type: regular
    task:
      id: 60f33e3c-ce34-4ccd-8b65-34d607b5c407
      version: -1
      name: Search access attempts in Pulse Secure Logs
      description: Searches Splunk for events related to the webshells names.
      script: '|||splunk-search'
      type: regular
      iscommand: true
      brand: ""
    nexttasks:
      '#none#':
      - "14"
    scriptarguments:
      earliest_time:
        complex:
          root: inputs.SplunkEarliestTime
      latest_time:
        complex:
          root: inputs.SplunkLatestTime
      query:
        complex:
          root: inputs.SplunkWebshellsQuery
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 1200,
          "y": 1080
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: true
    quietmode: 0
  "30":
    id: "30"
    taskid: 641c1d63-ed40-4cd5-83b4-31c104ef1237
    type: playbook
    task:
      id: 641c1d63-ed40-4cd5-83b4-31c104ef1237
      version: -1
      name: QRadarFullSearch
      description: This playbook runs a QRadar query and return its results to the
        context.
      playbookName: QRadarFullSearch
      type: playbook
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "14"
    scriptarguments:
      interval:
        simple: "1"
      query_expression:
        complex:
          root: inputs.QRadarWebshellsQuery
      timeout:
        simple: "600"
    separatecontext: true
    loop:
      iscommand: false
      exitCondition: ""
      wait: 1
      max: 100
    view: |-
      {
        "position": {
          "x": 340,
          "y": 1080
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: true
    quietmode: 0
  "31":
    id: "31"
    taskid: dbc84475-e4c2-48f4-8d45-a7ffdbb42dda
    type: condition
    task:
      id: dbc84475-e4c2-48f4-8d45-a7ffdbb42dda
      version: -1
      name: Is QRadar Enabled?
      description: Check if QRadar or Splunk instances are enabled.
      type: condition
      iscommand: false
      brand: ""
    nexttasks:
      '#default#':
      - "33"
      "No":
      - "14"
      "Yes":
      - "27"
    separatecontext: false
    conditions:
    - label: "Yes"
      condition:
      - - operator: isExists
          left:
            value:
              complex:
                root: modules
                filters:
                - - operator: inList
                    left:
                      value:
                        simple: modules.brand
                      iscontext: true
                    right:
                      value:
                        simple: QRadar,QRadar_v2
                - - operator: isEqualString
                    left:
                      value:
                        simple: modules.state
                      iscontext: true
                    right:
                      value:
                        simple: active
            iscontext: true
      - - operator: isEqualString
          left:
            value:
              complex:
                root: inputs.RunWebshellsQuery
            iscontext: true
          right:
            value:
              simple: "True"
          ignorecase: true
      - - operator: isNotEmpty
          left:
            value:
              complex:
                root: inputs.QRadarWebshellsQuery
            iscontext: true
    - label: "No"
      condition:
      - - operator: isExists
          left:
            value:
              complex:
                root: modules
                filters:
                - - operator: isEqualString
                    left:
                      value:
                        simple: modules.brand
                      iscontext: true
                    right:
                      value:
                        simple: SplunkPy
                - - operator: isEqualString
                    left:
                      value:
                        simple: modules.state
                      iscontext: true
                    right:
                      value:
                        simple: active
            iscontext: true
    view: |-
      {
        "position": {
          "x": 550,
          "y": 760
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: true
    quietmode: 0
  "33":
    id: "33"
    taskid: a2b23756-19bd-4649-8712-d1d1c40c9158
    type: regular
    task:
      id: a2b23756-19bd-4649-8712-d1d1c40c9158
      version: -1
      name: Hunt for the webshells names in PCS logs
      description: "Search in your Data Lake for access to one of the following URIs:\n\
        \n*Licenseserverproto.cgi*\n*Secid_canceltoken.cgi* \n*compcheckresult.cgi*\n\
        *Login.cgi*\n*Healthcheck.cgi*\n*meeting_testjs.cgi*\n*compcheckjava.cgi*\n\
        \nLook at the following example of Pulse Secure Connect message:\n\n\"Unauthenticated\
        \ request url /dana-na/meeting/meeting_testjs.cgi?id=* came from IP XX.XX.XX.XX.\""
      type: regular
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "14"
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 770,
          "y": 970
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
  "34":
    id: "34"
    taskid: bc891459-9fea-4821-88d5-52e29232eabd
    type: title
    task:
      id: bc891459-9fea-4821-88d5-52e29232eabd
      version: -1
      name: Done
      type: title
      iscommand: false
      brand: ""
      description: ''
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 770,
          "y": 2730
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
  "35":
    id: "35"
    taskid: 1c5a1902-11df-431c-8106-1e72fab5fa60
    type: regular
    task:
      id: 1c5a1902-11df-431c-8106-1e72fab5fa60
      version: -1
      name: Extract Indicators
      description: commands.local.cmd.extract.indicators
      script: Builtin|||extractIndicators
      type: regular
      iscommand: true
      brand: Builtin
    nexttasks:
      '#none#':
      - "3"
    scriptarguments:
      text:
        complex:
          root: inputs.Related_Hashes
          transformers:
          - operator: append
            args:
              item:
                value:
                  simple: ${inputs.Related_CVEs}
    reputationcalc: 2
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 770,
          "y": -120
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
  "37":
    id: "37"
    taskid: b75593b1-de06-47ad-8ca7-95ed2525e243
    type: playbook
    task:
      id: b75593b1-de06-47ad-8ca7-95ed2525e243
      version: -1
      name: QRadar Indicator Hunting V2
      description: 'The Playbook queries QRadar SIEM for indicators such as file hashes,
        IP addresses, domains, or urls. '
      playbookName: QRadar Indicator Hunting V2
      type: playbook
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "14"
    scriptarguments:
      InvestigationIPFields:
        simple: sourceip,destinationip
      InvestigationUserFields:
        simple: username
      QradarIPfield:
        simple: sourceip,destinationip
      QradarMD5Field:
        complex:
          root: inputs.QRadar_MD5_Field
      QradarSHA1Field:
        complex:
          root: inputs.QRadar_SHA1_Field
      QradarSHA256Field:
        complex:
          root: inputs.QRadar_SHA256_Field
      TimeFrame:
        simple: LAST 7 DAYS
    separatecontext: true
    loop:
      iscommand: false
      exitCondition: ""
      wait: 1
      max: 100
    view: |-
      {
        "position": {
          "x": -1270,
          "y": 780
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: true
    quietmode: 0
  "38":
    id: "38"
    taskid: a365653d-ac37-49d5-80b2-7571d996286d
    type: condition
    task:
      id: a365653d-ac37-49d5-80b2-7571d996286d
      version: -1
      name: Is Splunk Enabled?
      description: Check if QRadar or Splunk instances are enabled.
      type: condition
      iscommand: false
      brand: ""
    nexttasks:
      '#default#':
      - "33"
      "No":
      - "14"
      "Yes":
      - "26"
    separatecontext: false
    conditions:
    - label: "Yes"
      condition:
      - - operator: isExists
          left:
            value:
              complex:
                root: modules
                filters:
                - - operator: isEqualString
                    left:
                      value:
                        simple: modules.brand
                      iscontext: true
                    right:
                      value:
                        simple: SplunkPy
                - - operator: isEqualString
                    left:
                      value:
                        simple: modules.state
                      iscontext: true
                    right:
                      value:
                        simple: active
            iscontext: true
      - - operator: isEqualString
          left:
            value:
              complex:
                root: inputs.RunWebshellsQuery
            iscontext: true
          right:
            value:
              simple: "True"
          ignorecase: true
      - - operator: isNotEmpty
          left:
            value:
              complex:
                root: inputs.SplunkWebshellsQuery
            iscontext: true
    - label: "No"
      condition:
      - - operator: isExists
          left:
            value:
              complex:
                root: modules
                filters:
                - - operator: inList
                    left:
                      value:
                        simple: modules.brand
                      iscontext: true
                    right:
                      value:
                        simple: Qradar,Qradar_V2
                - - operator: isEqualString
                    left:
                      value:
                        simple: modules.state
                      iscontext: true
                    right:
                      value:
                        simple: active
            iscontext: true
    view: |-
      {
        "position": {
          "x": 990,
          "y": 760
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: true
    quietmode: 0
view: |-
  {
    "linkLabelsPosition": {
      "15_18_#default#": 0.77,
      "16_13_yes": 0.48,
      "16_14_#default#": 0.11,
      "20_22_No": 0.64,
      "31_14_No": 0.26,
      "38_14_No": 0.25,
      "38_33_#default#": 0.76
    },
    "paper": {
      "dimensions": {
        "height": 3065,
        "width": 4120,
        "x": -1270,
        "y": -270
      }
    }
  }
inputs:
- key: Related_Hashes
  value:
    simple: 06c56bd272b19bf7d7207443693cd1fc774408c4ca56744577b11fee550c23f7,64c87520565165ac95b74d6450b3ab8379544933dd3e2f2c4dc9b03a3ec570a7,1322340356018696d853e0ac6f7ce3a2,09956753b5000061524d204000000001,88170125598a4fb801102ad56494a773895059ac8550a983fdd2ef429653f079,9f6ac39707822d243445e30d27b8404466aa69c61119d5308785bf4a464a9ebd,325d6d60e24c7cfc3a782839d85ce08c8d3bb27c,1ab50b77dd9515f6cd9ed07d1d3176ba4627a292dc4a21b16ac9d211353818bd,1741dc0a491fcc8d078220ac9628152668d3370b92a8eae258e34ba28c6473b9,cd09ec795a8f4b6ced003500a44d810f49943514e2f92c81ab96c33e1c0fbd68,d72daafedf41d484f7f9816f7f076a9249a6808f1899649b7daa22c0447bb37b,c9b323b9747659eac25cec078895d75f016e26a8b5858567c7fb945b7321722c,2610d0372e0e107053bc001d278ef71f08562e5610691f18b978123c499a74d8,c774eca633136de35c9d2cd339a3b5d29f00f761657ea2aa438de4f33e4bbba4,224b7c45cf6fe4547d3ea66a12c30f3cb4c601b0a80744154697094e73dbd450,78d7c7c9f800f6824f63a99d935a4ad0112f97953d8c100deb29dae24d7da282,1d3ab04e21cfd40aa8d4300a359a09e3b520d39b1496be1e4bc91ae1f6730ecc,133631957d41eed9496ac2774793283ce26f8772de226e7f520d26667b51481a,68743e17f393d1f85ee937dffacc91e081b5f6f43477111ac96aa9d44826e4d2,7fa71a7f76ef63465cfeacf58217e0b66fc71bc81d37c44380a6f572b8a3ec7a,f2b1bd703c3eb05541ff84ec375573cbdc70309ccb82aac04b72db205d718e90,a1dcdf62aafc36dd8cf64774dea80d79fb4e24ba2a82adf4d944d9186acd1cc1,e63ab6f82c711e4ecc8f5b36046eb7ea216f41eb90158165b82a6c90560ea415,b2350954b9484ae4eac42b95fae6edf7a126169d0b93d79f49d36c5e6497062a,b1c2368773259fbfef425e0bb716be958faa7e74b3282138059f511011d3afd9,b990f79ce80c24625c97810cb8f161eafdcb10f1b8d9d538df4ca9be387c35e4,168976797d5af7071df257e91fcc31ce1d6e59c72ca9e2f50c8b5b3177ad83cc,4c5555955b2e6dc55f52b0c1a3326f3d07b325b112060329c503b294208960ec,705cda7d1ace8f4adeec5502aa311620b8d6c64046a1aed2ae833e2f2835154f
  required: false
  description: The known hashes of different malware families associated with the
    exploitation.
  playbookInputQuery:
- key: Related_CVEs
  value:
    simple: CVE-2019-11510, CVE-2020-8260, CVE-2020-8243, CVE-2021-22893
  required: false
  description: The known CVEs associated with the exploitation.
  playbookInputQuery:
- key: BlockAutomatically
  value:
    simple: "False"
  required: false
  description: |-
    Whether to block the indicators automatically.
    Default: False.
  playbookInputQuery:
- key: QRadarWebshellsQuery
  value:
    simple: select * from events WHERE LogSourceTypeName(deviceType) = 'Pulse Secure
      Pulse Connect Secure' and ( UTF8(payload) LIKE '%Licenseserverproto.cgi%' or
      UTF8(payload) LIKE '%Secid_canceltoken.cgi%' or UTF8(payload) LIKE '%compcheckresult.cgi%'
      or UTF8(payload) LIKE '%Login.cgi%' or UTF8(payload) LIKE '%Healthcheck.cgi%'
      or UTF8(payload) LIKE '%meeting_testjs.cgi%' or UTF8(payload) LIKE '%compcheckjava.cgi%')
  required: false
  description: |-
    The QRadar search query used for "Hunt Activity Using QRadar".
    Please note that there aren't specified fields which may cause a longer run time.
  playbookInputQuery:
- key: SplunkWebshellsQuery
  value:
    simple: index=* sourcetype=pulse:connectsecure "Licenseserverproto.cgi" OR "Secid_canceltoken.cgi"
      OR "compcheckresult.cgi" OR "Healthcheck.cgi" OR "meeting_testjs.cgi" OR "compcheckjava.cgi"
  required: false
  description: |-
    The Splunk search query used for "Hunt Activity Using Splunk".
    Please note that there are two specified fields: msg, message. the query will work for both field names.
  playbookInputQuery:
- key: RunWebshellsQuery
  value:
    simple: "True"
  required: false
  description: If you would like to skip "Hunt Activity Using Splunk" OR "Hunt Activity
    Using Qradar" please change the value to 'False'.
  playbookInputQuery:
- key: QRadar_MD5_Field
  value: {}
  required: false
  description: |-
    The name of the field for MD5 entries in QRadar.
    If not configured, QRadar Indicator Hunting may reach timeout.
  playbookInputQuery:
- key: QRadar_SHA1_Field
  value: {}
  required: false
  description: |-
    The name of the field for SHA1 entries in QRadar.
    If not configured, QRadar Indicator Hunting may reach timeout.
  playbookInputQuery:
- key: QRadar_SHA256_Field
  value: {}
  required: false
  description: |-
    The name of the field for SHA256 entries in QRadar.
    If not configured, QRadar Indicator Hunting may reach timeout.
  playbookInputQuery:
- key: SplunkEarliestTime
  value:
    simple: -30d
  required: false
  description: The earliest time for the Splunk search query.
  playbookInputQuery:
- key: SplunkLatestTime
  value:
    simple: now
  required: false
  description: The latest time for the Splunk search query.
  playbookInputQuery:
outputs: []
tests:
- No tests (auto formatted)
fromversion: 6.0.0
toversion: 6.4.9