{\n",
" "type": "observed-data",\n",
" "id": "observed-data--b67d30ff-02ac-498a-92f9-32f845f448cf",\n",
" "created": "2016-04-06T19:58:16.000Z",\n",
" "modified": "2016-04-06T19:58:16.000Z",\n",
" "first_observed": "2015-12-21T19:00:00Z",\n",
" "last_observed": "2015-12-21T19:00:00Z",\n",
" "number_observed": 50,\n",
" "objects": {\n",
" "0": {\n",
" "type": "file",\n",
" "hashes": {\n",
" "SHA-256": "0969de02ecf8a5f003e3f6d063d848c8a193aada092623f8ce408c15bcb5f038"\n",
" }\n",
" }\n",
" }\n",
"}\n",
"
{\n",
" "type": "identity",\n",
" "id": "identity--311b2d2d-f010-5473-83ec-1edf84858f4c",\n",
" "created": "2015-12-21T19:59:11.000Z",\n",
" "modified": "2015-12-21T19:59:11.000Z",\n",
" "name": "Cole Powers",\n",
" "identity_class": "individual"\n",
"}\n",
"
{\n",
" "type": "course-of-action",\n",
" "id": "course-of-action--d9727aee-48b8-4fdb-89e2-4c49746ba4dd",\n",
" "created_by_ref": "identity--c78cb6e5-0c4b-4611-8297-d1b8b55e40b5",\n",
" "created": "2017-05-31T21:30:41.022Z",\n",
" "modified": "2017-05-31T21:30:41.022Z",\n",
" "name": "Data from Network Shared Drive Mitigation",\n",
" "description": "Identify unnecessary system utilities or potentially malicious software that may be used to collect data from a network share, and audit and/or block them by using whitelisting[[CiteRef::Beechey 2010]] tools, like AppLocker,[[CiteRef::Windows Commands JPCERT]][[CiteRef::NSA MS AppLocker]] or Software Restriction Policies[[CiteRef::Corio 2008]] where appropriate.[[CiteRef::TechNet Applocker vs SRP]]"\n",
"}\n",
"