{"payload":{"feedbackUrl":"https://github.com/orgs/community/discussions/53140","repo":{"id":41704030,"defaultBranch":"6.2","name":"playbooks","ownerLogin":"phantomcyber","currentUserCanPush":false,"isFork":false,"isEmpty":false,"createdAt":"2015-08-31T22:35:12.000Z","ownerAvatar":"https://avatars.githubusercontent.com/u/11726847?v=4","public":true,"private":false,"isOrgOwned":true},"refInfo":{"name":"","listCacheKey":"v0:1709755021.0","currentOid":""},"activityList":{"items":[{"before":"ba7d4ff79ac73fe26fe2b3edb72493b3e2c5097d","after":"9a23e6d4c535bcc81d64df5d83031a311c63971d","ref":"refs/heads/6.2","pushedAt":"2024-04-03T16:57:15.000Z","pushType":"pr_merge","commitsCount":3,"pusher":{"login":"kelby-shelton","name":"Kelby Shelton","path":"/kelby-shelton","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/69353980?s=80&v=4"},"commit":{"message":"Merge pull request #184 from dfederschmidt/updated_saa_playbook\n\nfix: broader support for global SAA environments","shortMessageHtmlLink":"Merge pull request #184 from dfederschmidt/updated_saa_playbook"}},{"before":"41a0a60f6c7ce3120f4ffac7da8087ac12dfba77","after":"76145dc79c3c1309167d6fcd358ccfd3460baa9e","ref":"refs/heads/latest","pushedAt":"2024-03-06T20:02:36.000Z","pushType":"pr_merge","commitsCount":10,"pusher":{"login":"ljstella","name":"Lou Stella","path":"/ljstella","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/1413514?s=80&v=4"},"commit":{"message":"Merge pull request #183 from phantomcyber/6.2\n\nUpdating `latest`","shortMessageHtmlLink":"Merge pull request #183 from phantomcyber/6.2"}},{"before":"9a6e148c7ab835876c2a6036d889f957ea903bd6","after":null,"ref":"refs/heads/search_and","pushedAt":"2024-03-06T19:57:01.000Z","pushType":"branch_deletion","commitsCount":0,"pusher":{"login":"ljstella","name":"Lou Stella","path":"/ljstella","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/1413514?s=80&v=4"}},{"before":"475aa2fa680c1839ab4f3f8675cf136e557b937c","after":"ba7d4ff79ac73fe26fe2b3edb72493b3e2c5097d","ref":"refs/heads/6.2","pushedAt":"2024-03-06T19:56:53.000Z","pushType":"pr_merge","commitsCount":9,"pusher":{"login":"ljstella","name":"Lou Stella","path":"/ljstella","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/1413514?s=80&v=4"},"commit":{"message":"Merge pull request #182 from phantomcyber/search_and\n\nEmail Search and Purge playbooks","shortMessageHtmlLink":"Merge pull request #182 from phantomcyber/search_and"}},{"before":null,"after":"9a6e148c7ab835876c2a6036d889f957ea903bd6","ref":"refs/heads/search_and","pushedAt":"2024-03-06T19:50:11.000Z","pushType":"branch_creation","commitsCount":0,"pusher":{"login":"ljstella","name":"Lou Stella","path":"/ljstella","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/1413514?s=80&v=4"},"commit":{"message":"MS Graph Search and Restore","shortMessageHtmlLink":"MS Graph Search and Restore"}},{"before":"0cbcddf80103394c54db7e73544937e01f77e8fd","after":"41a0a60f6c7ce3120f4ffac7da8087ac12dfba77","ref":"refs/heads/latest","pushedAt":"2024-02-08T21:50:12.000Z","pushType":"pr_merge","commitsCount":23,"pusher":{"login":"kelby-shelton","name":"Kelby Shelton","path":"/kelby-shelton","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/69353980?s=80&v=4"},"commit":{"message":"Merge pull request #180 from phantomcyber/6.2\n\nSync to latest","shortMessageHtmlLink":"Merge pull request #180 from phantomcyber/6.2"}},{"before":"3b454f04f9bf534035ad992e058e106c8c1cdcbc","after":"475aa2fa680c1839ab4f3f8675cf136e557b937c","ref":"refs/heads/6.2","pushedAt":"2024-01-26T17:19:09.000Z","pushType":"pr_merge","commitsCount":2,"pusher":{"login":"kelby-shelton","name":"Kelby Shelton","path":"/kelby-shelton","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/69353980?s=80&v=4"},"commit":{"message":"Merge pull request #179 from phantomcyber/new-saa-playbooks\n\nNew and updated playbooks for SAA","shortMessageHtmlLink":"Merge pull request #179 from phantomcyber/new-saa-playbooks"}},{"before":"3b454f04f9bf534035ad992e058e106c8c1cdcbc","after":"150cd64968cf979869fdf9c7bb11496ea54affb1","ref":"refs/heads/new-saa-playbooks","pushedAt":"2024-01-26T17:18:42.000Z","pushType":"push","commitsCount":1,"pusher":{"login":"kelby-shelton","name":"Kelby Shelton","path":"/kelby-shelton","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/69353980?s=80&v=4"},"commit":{"message":"New and updated playbooks for SAA\n\n# New\nSplunk Automated Email Investigation incorporates Splunk technologies to detect a .eml or .msg file in the SOAR vault and obtain an automated verdict.\n\n# Modified\n- Adjusted Splunk Attack Analyzer Dynamic Analysis to download the job screenshots and output related observables\n- Adjusted Splunk Identifier Activity Analysis to include more data for matching of users and hostnames and to only look back 30 days. Added ability to parse URL to remove https.\n- Adjusted Splunk Message Identifier Activity Analysis to output Message ID with other fields","shortMessageHtmlLink":"New and updated playbooks for SAA"}},{"before":null,"after":"3b454f04f9bf534035ad992e058e106c8c1cdcbc","ref":"refs/heads/new-saa-playbooks","pushedAt":"2024-01-26T17:06:28.000Z","pushType":"branch_creation","commitsCount":0,"pusher":{"login":"kelby-shelton","name":"Kelby Shelton","path":"/kelby-shelton","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/69353980?s=80&v=4"},"commit":{"message":"Merge pull request #173 from phantomcyber/list_zip\n\nFixed typo","shortMessageHtmlLink":"Merge pull request #173 from phantomcyber/list_zip"}},{"before":"bd22d86d9b8357fdb373ff5e7649a52adf3eccfc","after":"3b454f04f9bf534035ad992e058e106c8c1cdcbc","ref":"refs/heads/6.2","pushedAt":"2023-12-21T14:46:14.000Z","pushType":"pr_merge","commitsCount":2,"pusher":{"login":"kelby-shelton","name":"Kelby Shelton","path":"/kelby-shelton","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/69353980?s=80&v=4"},"commit":{"message":"Merge pull request #173 from phantomcyber/list_zip\n\nFixed typo","shortMessageHtmlLink":"Merge pull request #173 from phantomcyber/list_zip"}},{"before":"5115d480aaf419766368eb3989748fc3c9f5b4b5","after":"bd87d99cd35eb21414e294428fc6dc0498a0de98","ref":"refs/heads/list_zip","pushedAt":"2023-12-21T14:42:03.000Z","pushType":"push","commitsCount":1,"pusher":{"login":"kelby-shelton","name":"Kelby Shelton","path":"/kelby-shelton","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/69353980?s=80&v=4"},"commit":{"message":"Fixed typo\n\nCorrected description.","shortMessageHtmlLink":"Fixed typo"}},{"before":"3272ffa1df5c4ac6534dfbaab9796d071752a01a","after":"bd22d86d9b8357fdb373ff5e7649a52adf3eccfc","ref":"refs/heads/6.2","pushedAt":"2023-12-21T14:38:57.000Z","pushType":"pr_merge","commitsCount":2,"pusher":{"login":"kelby-shelton","name":"Kelby Shelton","path":"/kelby-shelton","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/69353980?s=80&v=4"},"commit":{"message":"Merge pull request #172 from phantomcyber/list_zip\n\nNew custom function - list zip","shortMessageHtmlLink":"Merge pull request #172 from phantomcyber/list_zip"}},{"before":"3272ffa1df5c4ac6534dfbaab9796d071752a01a","after":"5115d480aaf419766368eb3989748fc3c9f5b4b5","ref":"refs/heads/list_zip","pushedAt":"2023-12-21T14:38:31.000Z","pushType":"push","commitsCount":1,"pusher":{"login":"kelby-shelton","name":"Kelby Shelton","path":"/kelby-shelton","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/69353980?s=80&v=4"},"commit":{"message":"New custom function - list zip\n\nNew custom function called \"list_zip\":\n\n\"This function zips two or more lists together to create a list of equal length. This can be useful when multiple upstream blocks are used for a single downstream block with multiple inputs. A maximum of 9 lists can be zipped together. The input lists are intended to be flat lists of strings, not nested lists or dictionaries.\"","shortMessageHtmlLink":"New custom function - list zip"}},{"before":null,"after":"3272ffa1df5c4ac6534dfbaab9796d071752a01a","ref":"refs/heads/list_zip","pushedAt":"2023-12-21T14:37:43.000Z","pushType":"branch_creation","commitsCount":0,"pusher":{"login":"kelby-shelton","name":"Kelby Shelton","path":"/kelby-shelton","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/69353980?s=80&v=4"},"commit":{"message":"Merge pull request #169 from phantomcyber/mc_automated_enrichment\n\nAdded mission control automated enrichment playbook","shortMessageHtmlLink":"Merge pull request #169 from phantomcyber/mc_automated_enrichment"}},{"before":"a0935878187d1d5843f280e1e77ebc41268b9ac8","after":"a7cac71361316017f05b76773f945ce87fe3ca9b","ref":"refs/heads/6.1","pushedAt":"2023-12-21T14:35:14.000Z","pushType":"pr_merge","commitsCount":2,"pusher":{"login":"kelby-shelton","name":"Kelby Shelton","path":"/kelby-shelton","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/69353980?s=80&v=4"},"commit":{"message":"Merge pull request #171 from phantomcyber/list_zip_backmerge\n\nNew custom function - list zip","shortMessageHtmlLink":"Merge pull request #171 from phantomcyber/list_zip_backmerge"}},{"before":"a0935878187d1d5843f280e1e77ebc41268b9ac8","after":"8d17d4b0e429e30b9f24200737c7da41f863be6b","ref":"refs/heads/list_zip_backmerge","pushedAt":"2023-12-21T14:34:50.000Z","pushType":"push","commitsCount":1,"pusher":{"login":"kelby-shelton","name":"Kelby Shelton","path":"/kelby-shelton","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/69353980?s=80&v=4"},"commit":{"message":"New custom function - list zip\n\nNew custom function called \"list_zip\":\n\n\"This function zips two or more lists together to create a list of equal length. This can be useful when multiple upstream blocks are used for a single downstream block with multiple inputs. A maximum of 9 lists can be zipped together. The input lists are intended to be flat lists of strings, not nested lists or dictionaries.\"","shortMessageHtmlLink":"New custom function - list zip"}},{"before":null,"after":"a0935878187d1d5843f280e1e77ebc41268b9ac8","ref":"refs/heads/list_zip_backmerge","pushedAt":"2023-12-21T14:33:23.000Z","pushType":"branch_creation","commitsCount":0,"pusher":{"login":"kelby-shelton","name":"Kelby Shelton","path":"/kelby-shelton","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/69353980?s=80&v=4"},"commit":{"message":"Merge pull request #168 from phantomcyber/mc_automated_enrichment\n\nAdded mission control automated enrichment playbook","shortMessageHtmlLink":"Merge pull request #168 from phantomcyber/mc_automated_enrichment"}},{"before":"a28bacc915128edd5a28e450fa5cffe29d62f5e9","after":"3272ffa1df5c4ac6534dfbaab9796d071752a01a","ref":"refs/heads/6.2","pushedAt":"2023-11-03T23:08:07.000Z","pushType":"pr_merge","commitsCount":2,"pusher":{"login":"kelby-shelton","name":"Kelby Shelton","path":"/kelby-shelton","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/69353980?s=80&v=4"},"commit":{"message":"Merge pull request #169 from phantomcyber/mc_automated_enrichment\n\nAdded mission control automated enrichment playbook","shortMessageHtmlLink":"Merge pull request #169 from phantomcyber/mc_automated_enrichment"}},{"before":"a28bacc915128edd5a28e450fa5cffe29d62f5e9","after":"a0935878187d1d5843f280e1e77ebc41268b9ac8","ref":"refs/heads/6.1","pushedAt":"2023-11-03T23:07:02.000Z","pushType":"pr_merge","commitsCount":2,"pusher":{"login":"kelby-shelton","name":"Kelby Shelton","path":"/kelby-shelton","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/69353980?s=80&v=4"},"commit":{"message":"Merge pull request #168 from phantomcyber/mc_automated_enrichment\n\nAdded mission control automated enrichment playbook","shortMessageHtmlLink":"Merge pull request #168 from phantomcyber/mc_automated_enrichment"}},{"before":"a28bacc915128edd5a28e450fa5cffe29d62f5e9","after":"de14e07b3ffaaac5f5402d93795a91fa3a53ab88","ref":"refs/heads/mc_automated_enrichment","pushedAt":"2023-11-03T23:06:36.000Z","pushType":"push","commitsCount":1,"pusher":{"login":"kelby-shelton","name":"Kelby Shelton","path":"/kelby-shelton","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/69353980?s=80&v=4"},"commit":{"message":"Added mission control automated enrichment playbook","shortMessageHtmlLink":"Added mission control automated enrichment playbook"}},{"before":null,"after":"a28bacc915128edd5a28e450fa5cffe29d62f5e9","ref":"refs/heads/mc_automated_enrichment","pushedAt":"2023-11-03T23:01:20.000Z","pushType":"branch_creation","commitsCount":0,"pusher":{"login":"kelby-shelton","name":"Kelby Shelton","path":"/kelby-shelton","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/69353980?s=80&v=4"},"commit":{"message":"Merge pull request #163 from reversinglabs/6.1\n\nAdd ReversingLabs playbooks to 6.1","shortMessageHtmlLink":"Merge pull request #163 from reversinglabs/6.1"}},{"before":null,"after":"a28bacc915128edd5a28e450fa5cffe29d62f5e9","ref":"refs/heads/6.2","pushedAt":"2023-10-26T16:20:39.000Z","pushType":"branch_creation","commitsCount":0,"pusher":{"login":"kelby-shelton","name":"Kelby Shelton","path":"/kelby-shelton","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/69353980?s=80&v=4"},"commit":{"message":"Merge pull request #163 from reversinglabs/6.1\n\nAdd ReversingLabs playbooks to 6.1","shortMessageHtmlLink":"Merge pull request #163 from reversinglabs/6.1"}},{"before":"3f342fcc49c458ef47d625ec8ef10b9ff152ebf0","after":"a28bacc915128edd5a28e450fa5cffe29d62f5e9","ref":"refs/heads/6.1","pushedAt":"2023-10-02T13:00:07.000Z","pushType":"pr_merge","commitsCount":6,"pusher":{"login":"kelby-shelton","name":"Kelby Shelton","path":"/kelby-shelton","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/69353980?s=80&v=4"},"commit":{"message":"Merge pull request #163 from reversinglabs/6.1\n\nAdd ReversingLabs playbooks to 6.1","shortMessageHtmlLink":"Merge pull request #163 from reversinglabs/6.1"}},{"before":"4db3e1a18fe2de0378f0cbd4d47d8a6b251d92f3","after":"3f342fcc49c458ef47d625ec8ef10b9ff152ebf0","ref":"refs/heads/6.1","pushedAt":"2023-09-26T21:55:38.000Z","pushType":"pr_merge","commitsCount":2,"pusher":{"login":"kelby-shelton","name":"Kelby Shelton","path":"/kelby-shelton","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/69353980?s=80&v=4"},"commit":{"message":"Merge pull request #167 from ericli-splunk/ericli-jira\n\nAdd playbook Jira_Related_Tickets_Search","shortMessageHtmlLink":"Merge pull request #167 from ericli-splunk/ericli-jira"}},{"before":"03485f91aa932cfb0403b0b59b97de2e8e8fcaa4","after":null,"ref":"refs/heads/new-function-comment-list","pushedAt":"2023-09-22T17:26:54.000Z","pushType":"branch_deletion","commitsCount":0,"pusher":{"login":"kelby-shelton","name":"Kelby Shelton","path":"/kelby-shelton","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/69353980?s=80&v=4"}},{"before":"3fbc00da0312517408557616cb39633dc5acae84","after":"4db3e1a18fe2de0378f0cbd4d47d8a6b251d92f3","ref":"refs/heads/6.1","pushedAt":"2023-09-22T17:26:49.000Z","pushType":"pr_merge","commitsCount":2,"pusher":{"login":"kelby-shelton","name":"Kelby Shelton","path":"/kelby-shelton","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/69353980?s=80&v=4"},"commit":{"message":"Merge pull request #166 from phantomcyber/new-function-comment-list\n\nNew custom function: comment list","shortMessageHtmlLink":"Merge pull request #166 from phantomcyber/new-function-comment-list"}},{"before":"7fc959726cd7fb92cf79e5f8b5e1618cb84311c8","after":null,"ref":"refs/heads/fix-automated-enrichment","pushedAt":"2023-09-22T17:06:11.000Z","pushType":"branch_deletion","commitsCount":0,"pusher":{"login":"kelby-shelton","name":"Kelby Shelton","path":"/kelby-shelton","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/69353980?s=80&v=4"}},{"before":"93a66133c530c8d0e4b86035a55c6f9e7aa3de8b","after":"3fbc00da0312517408557616cb39633dc5acae84","ref":"refs/heads/6.1","pushedAt":"2023-09-22T17:06:03.000Z","pushType":"pr_merge","commitsCount":2,"pusher":{"login":"kelby-shelton","name":"Kelby Shelton","path":"/kelby-shelton","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/69353980?s=80&v=4"},"commit":{"message":"Merge pull request #165 from phantomcyber/fix-automated-enrichment\n\nFixed automated enrichment playbooks","shortMessageHtmlLink":"Merge pull request #165 from phantomcyber/fix-automated-enrichment"}},{"before":"277814cde4f0b61e3ae922d5ba61ff1392b8558b","after":"93a66133c530c8d0e4b86035a55c6f9e7aa3de8b","ref":"refs/heads/6.1","pushedAt":"2023-09-14T16:19:07.000Z","pushType":"pr_merge","commitsCount":2,"pusher":{"login":"kelby-shelton","name":"Kelby Shelton","path":"/kelby-shelton","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/69353980?s=80&v=4"},"commit":{"message":"Merge pull request #157 from phantomcyber/classic-cleanup\n\nPurge part 1","shortMessageHtmlLink":"Merge pull request #157 from phantomcyber/classic-cleanup"}},{"before":"277814cde4f0b61e3ae922d5ba61ff1392b8558b","after":"03485f91aa932cfb0403b0b59b97de2e8e8fcaa4","ref":"refs/heads/new-function-comment-list","pushedAt":"2023-09-13T14:16:56.000Z","pushType":"push","commitsCount":1,"pusher":{"login":"kelby-shelton","name":"Kelby Shelton","path":"/kelby-shelton","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/69353980?s=80&v=4"},"commit":{"message":"New custom function: comment list\n\nA new custom function that allows you to list all of the comments on a particular container.\n\nTested against:\n- Invalid container ID\n- Valid container ID\n- Invalid input (string instead of integer)","shortMessageHtmlLink":"New custom function: comment list"}}],"hasNextPage":true,"hasPreviousPage":false,"activityType":"all","actor":null,"timePeriod":"all","sort":"DESC","perPage":30,"cursor":"djE6ks8AAAAEJumhPAA","startCursor":null,"endCursor":null}},"title":"Activity ยท phantomcyber/playbooks"}