Skip to content

Commit

Permalink
Update Palo_Alto_Autofocus snapshots
Browse files Browse the repository at this point in the history
  • Loading branch information
actions-user committed Jul 26, 2024
1 parent e5348d1 commit 7f32a6e
Show file tree
Hide file tree
Showing 5 changed files with 5 additions and 5 deletions.
2 changes: 1 addition & 1 deletion Palo_Alto_Autofocus/Snapshot-with-domain.json

Large diffs are not rendered by default.

2 changes: 1 addition & 1 deletion Palo_Alto_Autofocus/Snapshot-with-ip.json
Original file line number Diff line number Diff line change
@@ -1 +1 @@
{"description": "Palo Alto ip", "searchHistory": {"selectedObservables": [{"uuid": "92a9ab7d-68ed-43c9-93ac-f86e87d91446", "observable": {"key": "342910f7-347d-4d0c-b4c5-7c097d023825", "value": "103.110.84.196", "indicators": [], "type": "ip", "state": "investigated", "targets": [], "disposition": 2, "verdicts": [{"valid_time": {"start_time": "2021-03-05T10:34:58.685Z", "end_time": "2021-03-12T10:34:58.685Z"}, "observable": {"value": "103.110.84.196", "type": "ip"}, "type": "verdict", "disposition": 2, "module": "Palo Alto Networks AutoFocus (ITR-TESTING) ConfTokenTest", "module-type": null, "disposition_name": "Malicious", "id": "verdict:Palo Alto Networks AutoFocus (ITR-TESTING) ConfTokenTest:311e2c3c", "action": "9d4015c3-aa5d-4658-9914-bc1c8dcd032d", "judgement_id": "transient:judgement-28a9685d-0690-463b-98d1-4362a4b2adc2"}], "notifications": [], "disposition_name": "Malicious", "obsListSortOrder": 1, "listOrder": 0, "label": "103.110.84.196", "id": "311e2c3c", "judgements": [{"valid_time": {"start_time": "2021-03-05T10:34:58.685Z", "end_time": "2021-03-12T10:34:58.685Z"}, "schema_version": "1.0.22", "observable": {"value": "103.110.84.196", "type": "ip"}, "type": "judgement", "source": "Palo Alto AutoFocus", "disposition": 2, "module": "Palo Alto Networks AutoFocus (ITR-TESTING) ConfTokenTest", "module-type": null, "reason": "MALWARE in AutoFocus", "source_uri": "https://autofocus.paloaltonetworks.com/#/search/indicator/ipv4_address/103.110.84.196", "disposition_name": "Malicious", "priority": 85, "id": "transient:judgement-28a9685d-0690-463b-98d1-4362a4b2adc2", "severity": "High", "action": "9d4015c3-aa5d-4658-9914-bc1c8dcd032d", "confidence": "High"}], "sightings": [], "revListOrder": 1}, "notifications": [], "disposition_name": "Malicious", "disposition": 2, "type": "ip", "value": "103.110.84.196", "id": "311e2c3c"}], "omittedObservables": [], "archivedObservables": [{"key": "342910f7-347d-4d0c-b4c5-7c097d023825", "value": "103.110.84.196", "indicators": [], "type": "ip", "state": "investigated", "targets": [], "disposition": 2, "verdicts": [{"valid_time": {"start_time": "2021-03-05T10:34:58.685Z", "end_time": "2021-03-12T10:34:58.685Z"}, "observable": {"value": "103.110.84.196", "type": "ip"}, "type": "verdict", "disposition": 2, "module": "Palo Alto Networks AutoFocus (ITR-TESTING) ConfTokenTest", "module-type": null, "disposition_name": "Malicious", "id": "verdict:Palo Alto Networks AutoFocus (ITR-TESTING) ConfTokenTest:311e2c3c", "action": "9d4015c3-aa5d-4658-9914-bc1c8dcd032d", "judgement_id": "transient:judgement-28a9685d-0690-463b-98d1-4362a4b2adc2"}], "notifications": [], "disposition_name": "Malicious", "obsListSortOrder": 1, "listOrder": 0, "label": "103.110.84.196", "id": "311e2c3c", "judgements": [{"valid_time": {"start_time": "2021-03-05T10:34:58.685Z", "end_time": "2021-03-12T10:34:58.685Z"}, "schema_version": "1.0.22", "observable": {"value": "103.110.84.196", "type": "ip"}, "type": "judgement", "source": "Palo Alto AutoFocus", "disposition": 2, "module": "Palo Alto Networks AutoFocus (ITR-TESTING) ConfTokenTest", "module-type": null, "reason": "MALWARE in AutoFocus", "source_uri": "https://autofocus.paloaltonetworks.com/#/search/indicator/ipv4_address/103.110.84.196", "disposition_name": "Malicious", "priority": 85, "id": "transient:judgement-28a9685d-0690-463b-98d1-4362a4b2adc2", "severity": "High", "action": "9d4015c3-aa5d-4658-9914-bc1c8dcd032d", "confidence": "High"}], "sightings": [], "revListOrder": 1}]}, "schema_version": "1.1.3", "type": "investigation", "search-txt": "ip:\"103.110.84.196\"", "source": "Test_company Company_test", "actions": "[{\"created-perf\":7622505000.093952,\"updated-perf\":7622510000.132025,\"type\":\"collect\",\"created\":\"2021-03-05T10:34:56.842Z\",\"state\":\"ok\",\"arg\":\"ip:103.110.84.196\",\"result\":[{\"value\":\"103.110.84.196\",\"type\":\"ip\"}],\"id\":\"collect-311e2c3c\",\"uuid\":\"94215c2a-a229-4798-b239-3759fed5a9a1\"},{\"created-perf\":9517359999.9398,\"updated-perf\":9517359999.9398,\"type\":\"investigate\",\"created\":\"2021-03-05T10:34:58.737Z\",\"state\":\"ok\",\"arg\":{\"type\":\"ip\",\"value\":\"103.110.84.196\"},\"result\":{\"data\":[{\"module\":\"Palo Alto Networks AutoFocus (ITR-TESTING) ConfTokenTest\",\"module_instance_id\":\"15802a02-e1c8-499a-beb5-27a1efe71a44\",\"module_type_id\":\"79343c94-d267-4c3f-b6d3-de96871c406a\",\"data\":{\"verdicts\":{\"count\":1,\"docs\":[{\"type\":\"verdict\",\"disposition\":2,\"observable\":{\"value\":\"103.110.84.196\",\"type\":\"ip\"},\"judgement_id\":\"transient:judgement-28a9685d-0690-463b-98d1-4362a4b2adc2\",\"disposition_name\":\"Malicious\",\"valid_time\":{\"start_time\":\"2024-07-19T10:34:58.685Z\",\"end_time\":\"2024-07-26T10:34:58.685Z\"}}]},\"judgements\":{\"count\":1,\"docs\":[{\"valid_time\":{\"start_time\":\"2024-07-19T10:34:58.685Z\",\"end_time\":\"2024-07-26T10:34:58.685Z\"},\"schema_version\":\"1.0.22\",\"observable\":{\"value\":\"103.110.84.196\",\"type\":\"ip\"},\"type\":\"judgement\",\"source\":\"Palo Alto AutoFocus\",\"disposition\":2,\"reason\":\"MALWARE in AutoFocus\",\"source_uri\":\"https://autofocus.paloaltonetworks.com/#/search/indicator/ipv4_address/103.110.84.196\",\"disposition_name\":\"Malicious\",\"priority\":85,\"id\":\"transient:judgement-28a9685d-0690-463b-98d1-4362a4b2adc2\",\"severity\":\"High\",\"confidence\":\"High\"}]}}}]},\"id\":\"investigate-ec463033\",\"uuid\":\"9d4015c3-aa5d-4658-9914-bc1c8dcd032d\"}]", "short_description": "Snapshot @ 20210305 10:35:21", "omittedObservables": [], "archivedObservables": [{"key": "342910f7-347d-4d0c-b4c5-7c097d023825", "value": "103.110.84.196", "indicators": [], "type": "ip", "state": "investigated", "targets": [], "disposition": 2, "verdicts": [{"valid_time": {"start_time": "2021-03-05T10:34:58.685Z", "end_time": "2021-03-12T10:34:58.685Z"}, "observable": {"value": "103.110.84.196", "type": "ip"}, "type": "verdict", "disposition": 2, "module": "Palo Alto Networks AutoFocus (ITR-TESTING) ConfTokenTest", "module-type": null, "disposition_name": "Malicious", "id": "verdict:Palo Alto Networks AutoFocus (ITR-TESTING) ConfTokenTest:311e2c3c", "action": "9d4015c3-aa5d-4658-9914-bc1c8dcd032d", "judgement_id": "transient:judgement-28a9685d-0690-463b-98d1-4362a4b2adc2"}], "notifications": [], "disposition_name": "Malicious", "obsListSortOrder": 1, "listOrder": 0, "label": "103.110.84.196", "id": "311e2c3c", "judgements": [{"valid_time": {"start_time": "2021-03-05T10:34:58.685Z", "end_time": "2021-03-12T10:34:58.685Z"}, "schema_version": "1.0.22", "observable": {"value": "103.110.84.196", "type": "ip"}, "type": "judgement", "source": "Palo Alto AutoFocus", "disposition": 2, "module": "Palo Alto Networks AutoFocus (ITR-TESTING) ConfTokenTest", "module-type": null, "reason": "MALWARE in AutoFocus", "source_uri": "https://autofocus.paloaltonetworks.com/#/search/indicator/ipv4_address/103.110.84.196", "disposition_name": "Malicious", "priority": 85, "id": "transient:judgement-28a9685d-0690-463b-98d1-4362a4b2adc2", "severity": "High", "action": "9d4015c3-aa5d-4658-9914-bc1c8dcd032d", "confidence": "High"}], "sightings": [], "revListOrder": 1}], "selectedObservables": [{"uuid": "92a9ab7d-68ed-43c9-93ac-f86e87d91446", "observable": {"key": "342910f7-347d-4d0c-b4c5-7c097d023825", "value": "103.110.84.196", "indicators": [], "type": "ip", "state": "investigated", "targets": [], "disposition": 2, "verdicts": [{"valid_time": {"start_time": "2021-03-05T10:34:58.685Z", "end_time": "2021-03-12T10:34:58.685Z"}, "observable": {"value": "103.110.84.196", "type": "ip"}, "type": "verdict", "disposition": 2, "module": "Palo Alto Networks AutoFocus (ITR-TESTING) ConfTokenTest", "module-type": null, "disposition_name": "Malicious", "id": "verdict:Palo Alto Networks AutoFocus (ITR-TESTING) ConfTokenTest:311e2c3c", "action": "9d4015c3-aa5d-4658-9914-bc1c8dcd032d", "judgement_id": "transient:judgement-28a9685d-0690-463b-98d1-4362a4b2adc2"}], "notifications": [], "disposition_name": "Malicious", "obsListSortOrder": 1, "listOrder": 0, "label": "103.110.84.196", "id": "311e2c3c", "judgements": [{"valid_time": {"start_time": "2021-03-05T10:34:58.685Z", "end_time": "2021-03-12T10:34:58.685Z"}, "schema_version": "1.0.22", "observable": {"value": "103.110.84.196", "type": "ip"}, "type": "judgement", "source": "Palo Alto AutoFocus", "disposition": 2, "module": "Palo Alto Networks AutoFocus (ITR-TESTING) ConfTokenTest", "module-type": null, "reason": "MALWARE in AutoFocus", "source_uri": "https://autofocus.paloaltonetworks.com/#/search/indicator/ipv4_address/103.110.84.196", "disposition_name": "Malicious", "priority": 85, "id": "transient:judgement-28a9685d-0690-463b-98d1-4362a4b2adc2", "severity": "High", "action": "9d4015c3-aa5d-4658-9914-bc1c8dcd032d", "confidence": "High"}], "sightings": [], "revListOrder": 1}, "notifications": [], "disposition_name": "Malicious", "disposition": 2, "type": "ip", "value": "103.110.84.196", "id": "311e2c3c"}], "id": "https://private.intel.amp.cisco.com:443/ctia/investigation/investigation-18646001-117f-41d0-81d1-61b9a00a49ea", "tlp": "amber", "groups": ["60c63e6e-a341-4990-8da8-9d432e8be7c0"], "timestamp": "2021-03-05T10:35:30.768Z", "owner": "d67071e5-7738-49a4-b315-4117b30a086b"}
{"description": "Palo Alto ip", "searchHistory": {"selectedObservables": [{"uuid": "92a9ab7d-68ed-43c9-93ac-f86e87d91446", "observable": {"key": "342910f7-347d-4d0c-b4c5-7c097d023825", "value": "103.110.84.196", "indicators": [], "type": "ip", "state": "investigated", "targets": [], "disposition": 2, "verdicts": [{"valid_time": {"start_time": "2021-03-05T10:34:58.685Z", "end_time": "2021-03-12T10:34:58.685Z"}, "observable": {"value": "103.110.84.196", "type": "ip"}, "type": "verdict", "disposition": 2, "module": "Palo Alto Networks AutoFocus (ITR-TESTING) ConfTokenTest", "module-type": null, "disposition_name": "Malicious", "id": "verdict:Palo Alto Networks AutoFocus (ITR-TESTING) ConfTokenTest:311e2c3c", "action": "9d4015c3-aa5d-4658-9914-bc1c8dcd032d", "judgement_id": "transient:judgement-28a9685d-0690-463b-98d1-4362a4b2adc2"}], "notifications": [], "disposition_name": "Malicious", "obsListSortOrder": 1, "listOrder": 0, "label": "103.110.84.196", "id": "311e2c3c", "judgements": [{"valid_time": {"start_time": "2021-03-05T10:34:58.685Z", "end_time": "2021-03-12T10:34:58.685Z"}, "schema_version": "1.0.22", "observable": {"value": "103.110.84.196", "type": "ip"}, "type": "judgement", "source": "Palo Alto AutoFocus", "disposition": 2, "module": "Palo Alto Networks AutoFocus (ITR-TESTING) ConfTokenTest", "module-type": null, "reason": "MALWARE in AutoFocus", "source_uri": "https://autofocus.paloaltonetworks.com/#/search/indicator/ipv4_address/103.110.84.196", "disposition_name": "Malicious", "priority": 85, "id": "transient:judgement-28a9685d-0690-463b-98d1-4362a4b2adc2", "severity": "High", "action": "9d4015c3-aa5d-4658-9914-bc1c8dcd032d", "confidence": "High"}], "sightings": [], "revListOrder": 1}, "notifications": [], "disposition_name": "Malicious", "disposition": 2, "type": "ip", "value": "103.110.84.196", "id": "311e2c3c"}], "omittedObservables": [], "archivedObservables": [{"key": "342910f7-347d-4d0c-b4c5-7c097d023825", "value": "103.110.84.196", "indicators": [], "type": "ip", "state": "investigated", "targets": [], "disposition": 2, "verdicts": [{"valid_time": {"start_time": "2021-03-05T10:34:58.685Z", "end_time": "2021-03-12T10:34:58.685Z"}, "observable": {"value": "103.110.84.196", "type": "ip"}, "type": "verdict", "disposition": 2, "module": "Palo Alto Networks AutoFocus (ITR-TESTING) ConfTokenTest", "module-type": null, "disposition_name": "Malicious", "id": "verdict:Palo Alto Networks AutoFocus (ITR-TESTING) ConfTokenTest:311e2c3c", "action": "9d4015c3-aa5d-4658-9914-bc1c8dcd032d", "judgement_id": "transient:judgement-28a9685d-0690-463b-98d1-4362a4b2adc2"}], "notifications": [], "disposition_name": "Malicious", "obsListSortOrder": 1, "listOrder": 0, "label": "103.110.84.196", "id": "311e2c3c", "judgements": [{"valid_time": {"start_time": "2021-03-05T10:34:58.685Z", "end_time": "2021-03-12T10:34:58.685Z"}, "schema_version": "1.0.22", "observable": {"value": "103.110.84.196", "type": "ip"}, "type": "judgement", "source": "Palo Alto AutoFocus", "disposition": 2, "module": "Palo Alto Networks AutoFocus (ITR-TESTING) ConfTokenTest", "module-type": null, "reason": "MALWARE in AutoFocus", "source_uri": "https://autofocus.paloaltonetworks.com/#/search/indicator/ipv4_address/103.110.84.196", "disposition_name": "Malicious", "priority": 85, "id": "transient:judgement-28a9685d-0690-463b-98d1-4362a4b2adc2", "severity": "High", "action": "9d4015c3-aa5d-4658-9914-bc1c8dcd032d", "confidence": "High"}], "sightings": [], "revListOrder": 1}]}, "schema_version": "1.1.3", "type": "investigation", "search-txt": "ip:\"103.110.84.196\"", "source": "Test_company Company_test", "actions": "[{\"created-perf\":7622505000.093952,\"updated-perf\":7622510000.132025,\"type\":\"collect\",\"created\":\"2021-03-05T10:34:56.842Z\",\"state\":\"ok\",\"arg\":\"ip:103.110.84.196\",\"result\":[{\"value\":\"103.110.84.196\",\"type\":\"ip\"}],\"id\":\"collect-311e2c3c\",\"uuid\":\"94215c2a-a229-4798-b239-3759fed5a9a1\"},{\"created-perf\":9517359999.9398,\"updated-perf\":9517359999.9398,\"type\":\"investigate\",\"created\":\"2021-03-05T10:34:58.737Z\",\"state\":\"ok\",\"arg\":{\"type\":\"ip\",\"value\":\"103.110.84.196\"},\"result\":{\"data\":[{\"module\":\"Palo Alto Networks AutoFocus (ITR-TESTING) ConfTokenTest\",\"module_instance_id\":\"15802a02-e1c8-499a-beb5-27a1efe71a44\",\"module_type_id\":\"79343c94-d267-4c3f-b6d3-de96871c406a\",\"data\":{\"verdicts\":{\"count\":1,\"docs\":[{\"type\":\"verdict\",\"disposition\":2,\"observable\":{\"value\":\"103.110.84.196\",\"type\":\"ip\"},\"judgement_id\":\"transient:judgement-28a9685d-0690-463b-98d1-4362a4b2adc2\",\"disposition_name\":\"Malicious\",\"valid_time\":{\"start_time\":\"2024-07-26T10:34:58.685Z\",\"end_time\":\"2024-08-02T10:34:58.685Z\"}}]},\"judgements\":{\"count\":1,\"docs\":[{\"valid_time\":{\"start_time\":\"2024-07-26T10:34:58.685Z\",\"end_time\":\"2024-08-02T10:34:58.685Z\"},\"schema_version\":\"1.0.22\",\"observable\":{\"value\":\"103.110.84.196\",\"type\":\"ip\"},\"type\":\"judgement\",\"source\":\"Palo Alto AutoFocus\",\"disposition\":2,\"reason\":\"MALWARE in AutoFocus\",\"source_uri\":\"https://autofocus.paloaltonetworks.com/#/search/indicator/ipv4_address/103.110.84.196\",\"disposition_name\":\"Malicious\",\"priority\":85,\"id\":\"transient:judgement-28a9685d-0690-463b-98d1-4362a4b2adc2\",\"severity\":\"High\",\"confidence\":\"High\"}]}}}]},\"id\":\"investigate-ec463033\",\"uuid\":\"9d4015c3-aa5d-4658-9914-bc1c8dcd032d\"}]", "short_description": "Snapshot @ 20210305 10:35:21", "omittedObservables": [], "archivedObservables": [{"key": "342910f7-347d-4d0c-b4c5-7c097d023825", "value": "103.110.84.196", "indicators": [], "type": "ip", "state": "investigated", "targets": [], "disposition": 2, "verdicts": [{"valid_time": {"start_time": "2021-03-05T10:34:58.685Z", "end_time": "2021-03-12T10:34:58.685Z"}, "observable": {"value": "103.110.84.196", "type": "ip"}, "type": "verdict", "disposition": 2, "module": "Palo Alto Networks AutoFocus (ITR-TESTING) ConfTokenTest", "module-type": null, "disposition_name": "Malicious", "id": "verdict:Palo Alto Networks AutoFocus (ITR-TESTING) ConfTokenTest:311e2c3c", "action": "9d4015c3-aa5d-4658-9914-bc1c8dcd032d", "judgement_id": "transient:judgement-28a9685d-0690-463b-98d1-4362a4b2adc2"}], "notifications": [], "disposition_name": "Malicious", "obsListSortOrder": 1, "listOrder": 0, "label": "103.110.84.196", "id": "311e2c3c", "judgements": [{"valid_time": {"start_time": "2021-03-05T10:34:58.685Z", "end_time": "2021-03-12T10:34:58.685Z"}, "schema_version": "1.0.22", "observable": {"value": "103.110.84.196", "type": "ip"}, "type": "judgement", "source": "Palo Alto AutoFocus", "disposition": 2, "module": "Palo Alto Networks AutoFocus (ITR-TESTING) ConfTokenTest", "module-type": null, "reason": "MALWARE in AutoFocus", "source_uri": "https://autofocus.paloaltonetworks.com/#/search/indicator/ipv4_address/103.110.84.196", "disposition_name": "Malicious", "priority": 85, "id": "transient:judgement-28a9685d-0690-463b-98d1-4362a4b2adc2", "severity": "High", "action": "9d4015c3-aa5d-4658-9914-bc1c8dcd032d", "confidence": "High"}], "sightings": [], "revListOrder": 1}], "selectedObservables": [{"uuid": "92a9ab7d-68ed-43c9-93ac-f86e87d91446", "observable": {"key": "342910f7-347d-4d0c-b4c5-7c097d023825", "value": "103.110.84.196", "indicators": [], "type": "ip", "state": "investigated", "targets": [], "disposition": 2, "verdicts": [{"valid_time": {"start_time": "2021-03-05T10:34:58.685Z", "end_time": "2021-03-12T10:34:58.685Z"}, "observable": {"value": "103.110.84.196", "type": "ip"}, "type": "verdict", "disposition": 2, "module": "Palo Alto Networks AutoFocus (ITR-TESTING) ConfTokenTest", "module-type": null, "disposition_name": "Malicious", "id": "verdict:Palo Alto Networks AutoFocus (ITR-TESTING) ConfTokenTest:311e2c3c", "action": "9d4015c3-aa5d-4658-9914-bc1c8dcd032d", "judgement_id": "transient:judgement-28a9685d-0690-463b-98d1-4362a4b2adc2"}], "notifications": [], "disposition_name": "Malicious", "obsListSortOrder": 1, "listOrder": 0, "label": "103.110.84.196", "id": "311e2c3c", "judgements": [{"valid_time": {"start_time": "2021-03-05T10:34:58.685Z", "end_time": "2021-03-12T10:34:58.685Z"}, "schema_version": "1.0.22", "observable": {"value": "103.110.84.196", "type": "ip"}, "type": "judgement", "source": "Palo Alto AutoFocus", "disposition": 2, "module": "Palo Alto Networks AutoFocus (ITR-TESTING) ConfTokenTest", "module-type": null, "reason": "MALWARE in AutoFocus", "source_uri": "https://autofocus.paloaltonetworks.com/#/search/indicator/ipv4_address/103.110.84.196", "disposition_name": "Malicious", "priority": 85, "id": "transient:judgement-28a9685d-0690-463b-98d1-4362a4b2adc2", "severity": "High", "action": "9d4015c3-aa5d-4658-9914-bc1c8dcd032d", "confidence": "High"}], "sightings": [], "revListOrder": 1}, "notifications": [], "disposition_name": "Malicious", "disposition": 2, "type": "ip", "value": "103.110.84.196", "id": "311e2c3c"}], "id": "https://private.intel.amp.cisco.com:443/ctia/investigation/investigation-18646001-117f-41d0-81d1-61b9a00a49ea", "tlp": "amber", "groups": ["60c63e6e-a341-4990-8da8-9d432e8be7c0"], "timestamp": "2021-03-05T10:35:30.768Z", "owner": "d67071e5-7738-49a4-b315-4117b30a086b"}
Loading

0 comments on commit 7f32a6e

Please sign in to comment.