From 2771afae029dd140683100a695ee010aed11ea97 Mon Sep 17 00:00:00 2001 From: kkarolenko Date: Tue, 4 Jun 2024 16:04:17 -0400 Subject: [PATCH 1/2] Add files via upload --- .../revision_3/BehaviorBundle.json | 156 ++++++++++++++---- .../schemas/sdos/x-oca-behavior.json | 69 ++++++++ .../schemas/sdos/x-oca-coa-playbook-ext.json | 44 +++++ .../schemas/sdos/x-oca-detection.json | 60 +++++++ .../schemas/sdos/x-oca-detector.json | 94 +++++++++++ .../schemas/sdos/x-oca-playbook.json | 110 ++++++++++++ .../schemas/sdos/x-oca-tool-hvt-ext.json | 91 ++++++++++ 7 files changed, 589 insertions(+), 35 deletions(-) create mode 100644 apl_reference_implementation_bundle/revision_3/schemas/sdos/x-oca-behavior.json create mode 100644 apl_reference_implementation_bundle/revision_3/schemas/sdos/x-oca-coa-playbook-ext.json create mode 100644 apl_reference_implementation_bundle/revision_3/schemas/sdos/x-oca-detection.json create mode 100644 apl_reference_implementation_bundle/revision_3/schemas/sdos/x-oca-detector.json create mode 100644 apl_reference_implementation_bundle/revision_3/schemas/sdos/x-oca-playbook.json create mode 100644 apl_reference_implementation_bundle/revision_3/schemas/sdos/x-oca-tool-hvt-ext.json diff --git a/apl_reference_implementation_bundle/revision_3/BehaviorBundle.json b/apl_reference_implementation_bundle/revision_3/BehaviorBundle.json index 369eefd..ad1923a 100644 --- a/apl_reference_implementation_bundle/revision_3/BehaviorBundle.json +++ b/apl_reference_implementation_bundle/revision_3/BehaviorBundle.json @@ -925,7 +925,7 @@ "modified": "2022-03-31T13:00:00.000Z", "name": "x-oca-behavior Extension Definition", "description": "This schema creates a new object type called x-oca-behavior. x-oca-behavior objects describe higher-level functionality than can be described using SCOs.", - "schema": "https://raw.githubusercontent.com/opencybersecurityalliance/oca-iob/main/apl_reference_implementation_bundle/revision_2/schemas/sdos/behavior.json", + "schema": "https://raw.githubusercontent.com/opencybersecurityalliance/stix-extensions/main/2.x/schemas/x-oca-behavior.json", "version": "1.0.0", "extension_types": [ "new-sdo" @@ -940,7 +940,7 @@ "modified": "2023-05-01T12:00:00.000Z", "name": "x-oca-detector Extension Definition", "description": "This schema creates a new object type called detector, which describes software that is capable of performing detections.", - "schema": "https://raw.githubusercontent.com/opencybersecurityalliance/oca-iob/main/apl_reference_implementation_bundle/revision_2/schemas/sdos/detector.json", + "schema": "https://raw.githubusercontent.com/opencybersecurityalliance/stix-extensions/main/2.x/schemas/x-oca-detector.json", "version": "1.0.0", "extension_types": [ "new-sdo" @@ -955,7 +955,7 @@ "modified": "2022-03-31T13:00:00.000Z", "name": "x-oca-detection Extension Definition", "description": "This schema creates a new object type called detection, which contain queries or other actionable information that can identify an event or behavior.", - "schema": "https://raw.githubusercontent.com/opencybersecurityalliance/oca-iob/main/apl_reference_implementation_bundle/revision_2/schemas/sdos/detection.json", + "schema": "https://raw.githubusercontent.com/opencybersecurityalliance/stix-extensions/main/2.x/schemas/x-oca-detection.json", "version": "1.0.0", "extension_types": [ "new-sdo" @@ -1284,11 +1284,11 @@ "name": "Correlate and Score Behaviors", "description": "This course of action investigates an observed behavior by correlating it with related behaviors.", "extensions": { - "extension-definition--BBC1D5C8-7DDC-4E89-BE9C-F33AD02D71DD": { + "extension-definition--bbc1d5c8-7ddc-4e89-be9c-f33ad02d71dd": { "extension_type": "property-extension", "playbooks": { - "CACAO": "x-oca-playbook--8fc70cce-8293-4076-ad9b-e8bc4fd12845", - "BPMN": "x-oca-playbook--cab95b33-7770-4891-94f2-f2c640f2408a" + "x-oca-playbook--8fc70cce-8293-4076-ad9b-e8bc4fd12845": "application/cacao+json", + "x-oca-playbook--cab95b33-7770-4891-94f2-f2c640f2408a": "BPMN" } } } @@ -1320,7 +1320,7 @@ "notification" ], "playbook_bin": "{
  "type": "playbook",
  "spec_version": "cacao-2.0",
  "id": "playbook--d912ca3f-3512-433c-93ba-bceb06275a06",
  "name": "Correlate and Score Alert",
  "created_by": "identity--b085a68a-bf48-4316-9667-37af78cba894",
  "created": "2024-03-15T11:07:00.013Z",
  "modified": "2024-04-15T08:47:00.014Z",
  "revoked": false,
  "derived_from": [
    "playbook--8864f889-a5d2-4a62-915e-1ef445bb1618"
  ],
  "priority": 0,
  "severity": 0,
  "impact": 0,
  "playbook_variables": {
    "__did_that_exe_or_dll_spawn_a_process_that_modded_registry__": {
      "type": "integer",
      "description": "Did that EXE or DLL spawn a process that modded Registry?",
      "value": "0",
      "constant": false
    },
    "__did_the_host_with_priv_escalation_run_dcsync__": {
      "type": "integer",
      "description": "Did the host with Priv Escalation run DCsync?",
      "value": "0",
      "constant": false
    },
    "__did_the_office_process_create_an_exe_or_dll__": {
      "type": "integer",
      "description": "Did the Office Process Create an exe or DLL?",
      "value": "0",
      "constant": false
    },
    "__has_internal_host_been_associated_with_other_alerts_recently__": {
      "type": "integer",
      "description": "Has Internal host been associated with other alerts recently?",
      "value": "0",
      "constant": false
    },
    "__is_destination_where_exfil_occurs__": {
      "type": "integer",
      "description": "Is Destination where Exfil occurs?",
      "value": "0",
      "constant": false
    },
    "__is_host_or_user_account_associated_with_other_alerts_recently__": {
      "type": "integer",
      "description": "Is host or User account associated with other alerts recently?",
      "value": "0",
      "constant": false
    },
    "__is_the_source_of_lateral_movement_the_host_conducting_dc_sync__": {
      "type": "integer",
      "description": "Is the source of Lateral Movement the Host conducting DC Sync?",
      "value": "0",
      "constant": false
    },
    "__is_the_spawned_process_name_different_than_the_office_app_for_created_process__": {
      "type": "integer",
      "description": "Is the spawned process name different than the Office App for Created Process?",
      "value": "0",
      "constant": false
    },
    "__is_there_an_email_to_web_and_web_to_office_activity_on_host_in_short_timeframe__": {
      "type": "integer",
      "description": "Is there an Email to Web and Web to Office activity on host in short timeframe?",
      "value": "0",
      "constant": false
    },
    "__set_correlation_for_behavior_set_based_on_point_tally__": {
      "type": "integer",
      "description": "Set Correlation for Behavior Set based on Point Tally",
      "value": "0",
      "constant": false
    },
    "__was_priv_esc_from_nonnormal_activity__": {
      "type": "integer",
      "description": "Was Priv Esc from Non-Normal Activity?",
      "value": "0",
      "constant": false
    },
    "__was_request_from_abnormal_timeplace__": {
      "type": "integer",
      "description": "Was request from abnormal time/place?",
      "value": "0",
      "constant": false
    },
    "__check_alert_type__": {
      "type": "string",
      "description": "Alert type that triggered the playbook",
      "constant": true,
      "external": true
    }
  },
  "workflow_start": "step--2d56120c-44eb-578a-a2af-43b9ca29eeb9",
  "workflow": {
    "action--01df3b29-8200-5c7d-bb6f-d0b703886683": {
      "name": "Query Against Lateral Movement Alerts",
      "on_completion": "if-condition--a3938ab5-748d-54b3-8f6a-1fbeb8dcec6d",
      "step_extensions": {
        "": "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f",
        "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f": {
          "type": "coordinates",
          "x": 415,
          "y": 2480,
          "width": 150,
          "height": 60,
          "outgoing_connections": [
            {
              "type": "on-completion",
              "x": [
                565,
                690
              ],
              "y": [
                2510,
                2510
              ]
            }
          ]
        }
      },
      "type": "action",
      "commands": [
        {
          "type": "manual",
          "command": "Query Against Lateral Movement Alerts"
        }
      ]
    },
    "action--04499870-8083-573b-8159-42b09c73995d": {
      "name": "Query Against Exfil Alerts",
      "on_completion": "if-condition--a3938ab5-748d-54b3-8f6a-1fbeb8dcec6d",
      "step_extensions": {
        "": "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f",
        "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f": {
          "type": "coordinates",
          "x": 415,
          "y": 2360,
          "width": 150,
          "height": 60,
          "outgoing_connections": [
            {
              "type": "on-completion",
              "x": [
                565,
                750,
                750
              ],
              "y": [
                2390,
                2390,
                2480
              ]
            }
          ]
        }
      },
      "type": "action",
      "commands": [
        {
          "type": "manual",
          "command": "Query Against Exfil Alerts"
        }
      ]
    },
    "if-condition--094a3664-919a-59f8-9271-d6a52e059048": {
      "name": "Was Priv Esc from Non-Normal Activity?",
      "step_extensions": {
        "": "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f",
        "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f": {
          "type": "coordinates",
          "x": 690,
          "y": 1670,
          "width": 120,
          "height": 60,
          "outgoing_connections": [
            {
              "type": "on-true",
              "x": [
                810,
                955
              ],
              "y": [
                1700,
                1700
              ]
            },
            {
              "type": "on-false",
              "x": [
                750,
                750,
                830
              ],
              "y": [
                1730,
                1760,
                1760
              ]
            }
          ]
        }
      },
      "type": "if-condition",
      "condition": "__was_priv_esc_from_nonnormal_activity__ == 1",
      "on_true": "action--b9405597-ab73-5f60-875e-985dc529e04e",
      "on_false": "end--3a4978fc-9bfa-4e21-b08d-d7ddb5aa1cbe"
    },
    "action--09e58dac-b6da-594a-a6f7-0d3eb4620de1": {
      "name": "Query against PrivEsc Alerts",
      "on_completion": "if-condition--468c9c60-6091-4e4f-b048-f8b686f5eb0c",
      "step_extensions": {
        "": "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f",
        "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f": {
          "type": "coordinates",
          "x": 955,
          "y": 1960,
          "width": 150,
          "height": 60,
          "outgoing_connections": [
            {
              "type": "on-completion",
              "x": [
                1105,
                1210,
                1210,
                730,
                730
              ],
              "y": [
                1990,
                1990,
                1940,
                1940,
                1870
              ]
            }
          ]
        }
      },
      "type": "action",
      "commands": [
        {
          "type": "manual",
          "command": "Query against PrivEsc Alerts"
        }
      ]
    },
    "if-condition--468c9c60-6091-4e4f-b048-f8b686f5eb0c": {
      "name": "Did the host with Priv Escalation run DCsync?",
      "step_extensions": {
        "": "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f",
        "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f": {
          "type": "coordinates",
          "x": 690,
          "y": 1810,
          "width": 120,
          "height": 60,
          "outgoing_connections": [
            {
              "type": "on-true",
              "x": [
                810,
                975
              ],
              "y": [
                1840,
                1840
              ]
            },
            {
              "type": "on-false",
              "x": [
                750,
                750,
                830
              ],
              "y": [
                1870,
                1900,
                1900
              ]
            }
          ]
        }
      },
      "type": "if-condition",
      "on_true": "action--b4c3ca75-364e-5ec7-8fa0-329f1f221027",
      "on_false": "end--c1f3cd70-1343-413a-b13f-2b18eb79014e"
    },
    "end--0a7a04f1-5702-58fc-bc68-53e5e4d2b595": {
      "name": "End",
      "step_extensions": {
        "": "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f",
        "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f": {
          "type": "coordinates",
          "x": 830,
          "y": 1510,
          "width": 60,
          "height": 40
        }
      },
      "type": "end"
    },
    "if-condition--0c6367bb-7a19-56ab-a613-bde5710ba0f8": {
      "name": "Did that EXE or DLL spawn a process that modded Registry?",
      "step_extensions": {
        "": "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f",
        "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f": {
          "type": "coordinates",
          "x": 690,
          "y": 1310,
          "width": 120,
          "height": 60,
          "outgoing_connections": [
            {
              "type": "on-true",
              "x": [
                810,
                955
              ],
              "y": [
                1340,
                1340
              ]
            },
            {
              "type": "on-false",
              "x": [
                750,
                750,
                830
              ],
              "y": [
                1370,
                1400,
                1400
              ]
            }
          ]
        }
      },
      "type": "if-condition",
      "condition": "__did_that_exe_or_dll_spawn_a_process_that_modded_registry__ == 1",
      "on_true": "action--7edd1148-0500-5e53-a7ee-3a8c9613794b",
      "on_false": "end--81f3b418-9ea9-563d-9948-577acafb4591"
    },
    "action--0d4fd047-0ef1-5f27-8dbb-8be336cc432c": {
      "name": "Query Against Spearphish 2 Alerts",
      "on_completion": "if-condition--12279fb7-1e51-5141-a6fd-c68420bbe2ac",
      "step_extensions": {
        "": "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f",
        "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f": {
          "type": "coordinates",
          "x": 675,
          "y": 1070,
          "width": 150,
          "height": 60,
          "outgoing_connections": [
            {
              "type": "on-completion",
              "x": [
                720,
                720
              ],
              "y": [
                1070,
                990
              ]
            }
          ]
        }
      },
      "type": "action",
      "commands": [
        {
          "type": "manual",
          "command": "Query Against Spearphish 2 Alerts"
        }
      ]
    },
    "action--1169afb8-09ae-5e70-8ae0-3c4b3ee47ebb": {
      "name": "Record Lat Move Led to Exfil (Add 1 Point)",
      "on_completion": "action--5a992339-37da-5e3e-bb8f-5e3b06c35f11",
      "step_extensions": {
        "": "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f",
        "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f": {
          "type": "coordinates",
          "x": 955,
          "y": 2480,
          "width": 150,
          "height": 60,
          "outgoing_connections": [
            {
              "type": "on-completion",
              "x": [
                1105,
                1600,
                1600
              ],
              "y": [
                2510,
                2510,
                1790
              ]
            }
          ]
        }
      },
      "type": "action",
      "commands": [
        {
          "type": "manual",
          "command": "Record Lat Move Led to Exfil (Add 1 Point)"
        }
      ]
    },
    "if-condition--12279fb7-1e51-5141-a6fd-c68420bbe2ac": {
      "name": "Did the Office Process Create an exe or DLL?",
      "step_extensions": {
        "": "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f",
        "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f": {
          "type": "coordinates",
          "x": 690,
          "y": 930,
          "width": 120,
          "height": 60,
          "outgoing_connections": [
            {
              "type": "on-true",
              "x": [
                810,
                955
              ],
              "y": [
                960,
                960
              ]
            },
            {
              "type": "on-false",
              "x": [
                750,
                750,
                840
              ],
              "y": [
                990,
                1020,
                1020
              ]
            }
          ]
        }
      },
      "type": "if-condition",
      "condition": "__did_the_office_process_create_an_exe_or_dll__ == 1",
      "on_true": "action--cc7f3650-c731-5723-92d7-96e0d5e270f9",
      "on_false": "end--c3cbbd9d-3358-5f0e-9800-e488be2532e3"
    },
    "if-condition--1a99e08d-7628-51bc-966f-b4059c385b79": {
      "name": "Was request from abnormal time/place?",
      "step_extensions": {
        "": "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f",
        "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f": {
          "type": "coordinates",
          "x": 170,
          "y": 2050,
          "width": 120,
          "height": 60,
          "outgoing_connections": [
            {
              "type": "on-true",
              "x": [
                290,
                430
              ],
              "y": [
                2080,
                2080
              ]
            },
            {
              "type": "on-false",
              "x": [
                230,
                230,
                303
              ],
              "y": [
                2110,
                2140,
                2140
              ]
            }
          ]
        }
      },
      "type": "if-condition",
      "condition": "__was_request_from_abnormal_timeplace__ == 1",
      "on_true": "parallel--cff6c610-6493-589f-a20f-50f209f6461d",
      "on_false": "end--c8a3d080-505a-529b-979f-90b4b7ddf30a"
    },
    "end--2874e922-bbd1-5df4-9a61-ff20fc5e61c8": {
      "name": "End",
      "step_extensions": {
        "": "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f",
        "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f": {
          "type": "coordinates",
          "x": 840,
          "y": 810,
          "width": 60,
          "height": 40
        }
      },
      "type": "end"
    },
    "action--29040088-a6ee-5f79-9da3-9abee1c8a4db": {
      "name": "Collect Time, Process Name, Process ID, Host",
      "on_completion": "if-condition--77a6ca6c-6917-57ec-8209-00b04bd4510e",
      "step_extensions": {
        "": "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f",
        "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f": {
          "type": "coordinates",
          "x": -105,
          "y": 1130,
          "width": 150,
          "height": 60,
          "outgoing_connections": [
            {
              "type": "on-completion",
              "x": [
                45,
                170
              ],
              "y": [
                1160,
                1160
              ]
            }
          ]
        }
      },
      "type": "action",
      "commands": [
        {
          "type": "manual",
          "command": "Collect Time, Process Name, Process ID, Host"
        }
      ]
    },
    "action--2c0bfc3a-b069-5862-aa7a-5b8822d6a0f2": {
      "name": "Set Correlation to Low",
      "on_completion": "action--6e4a7bae-b71d-53fa-80ca-e457eea80b6d",
      "step_extensions": {
        "": "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f",
        "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f": {
          "type": "coordinates",
          "x": 2055,
          "y": 1620,
          "width": 150,
          "height": 60,
          "outgoing_connections": [
            {
              "type": "on-completion",
              "x": [
                2205,
                2310,
                2310,
                2345
              ],
              "y": [
                1650,
                1650,
                1760,
                1760
              ]
            }
          ]
        }
      },
      "type": "action",
      "commands": [
        {
          "type": "manual",
          "command": "Set Correlation to Low"
        }
      ]
    },
    "start--2d56120c-44eb-578a-a2af-43b9ca29eeb9": {
      "name": "Receive Alert",
      "on_completion": "switch-condition--e9ab6683-97e7-455c-aa4e-f9153ec1e548",
      "step_extensions": {
        "": "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f",
        "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f": {
          "type": "coordinates",
          "x": -580,
          "y": 1740,
          "width": 60,
          "height": 40,
          "outgoing_connections": [
            {
              "type": "on-completion",
              "x": [
                -520,
                -420
              ],
              "y": [
                1760,
                1760
              ]
            }
          ]
        }
      },
      "type": "start"
    },
    "switch-condition--e9ab6683-97e7-455c-aa4e-f9153ec1e548": {
      "name": "Check alert type",
      "step_extensions": {
        "": "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f",
        "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f": {
          "type": "coordinates",
          "x": -420,
          "y": 1730,
          "width": 120,
          "height": 60,
          "outgoing_connections": [
            {
              "type": "cases",
              "x": [
                -340,
                -340,
                -105
              ],
              "y": [
                1730,
                1340,
                1340
              ],
              "case": "Registry Modification"
            },
            {
              "type": "cases",
              "x": [
                -400,
                -400,
                -105
              ],
              "y": [
                1730,
                770,
                770
              ],
              "case": "Office Macro Spearphishing 1"
            },
            {
              "type": "cases",
              "x": [
                -380,
                -380,
                -105
              ],
              "y": [
                1730,
                900,
                900
              ],
              "case": "Office Macro Spearphishing 2"
            },
            {
              "type": "cases",
              "x": [
                -300,
                -30,
                -30
              ],
              "y": [
                1760,
                1760,
                1190
              ],
              "case": "0"
            },
            {
              "type": "cases",
              "x": [
                -320,
                -320,
                -105
              ],
              "y": [
                1730,
                1530,
                1530
              ],
              "case": "Beaconing"
            },
            {
              "type": "cases",
              "x": [
                -300,
                -105
              ],
              "y": [
                1760,
                1760
              ],
              "case": "Privilege Escalation"
            },
            {
              "type": "cases",
              "x": [
                -340,
                -340,
                -105
              ],
              "y": [
                1790,
                2080,
                2080
              ],
              "case": "DC Sync Attack"
            },
            {
              "type": "cases",
              "x": [
                -360,
                -360,
                -105
              ],
              "y": [
                1790,
                2330,
                2330
              ],
              "case": "Lateral Movement"
            },
            {
              "type": "cases",
              "x": [
                -380,
                -380,
                -105
              ],
              "y": [
                1790,
                2640,
                2640
              ],
              "case": "Data Exfiltration"
            }
          ]
        }
      },
      "type": "switch-condition",
      "switch": "__check_alert_type__",
      "cases": {        
        "Registry Modification": "action--86f582bd-d312-5524-9158-371ed2609248",
        "Office Macro Spearphishing 1": "action--79d1af48-e3f6-5b2a-a771-ea49216458f1",
        "Office Macro Spearphishing 2": "action--e1e6a9d6-9916-535e-a792-838ffda98115",
        "Office Macro Execution": "action--29040088-a6ee-5f79-9da3-9abee1c8a4db",
        "Beaconing": "action--c2b6b202-8eaa-537b-b8fb-55e3dc7ebd56",
        "Privilege Escalation": "action--8e22b060-b468-5fe9-8c2e-0032327fdad4",
        "DC Sync Attack": "action--58558f31-d0a7-5f4c-a49c-601cb348bda3",
        "Lateral Movement": "action--2ee87d25-82ea-575f-97e5-81af80eab5d5",
        "Data Exfiltration": "action--ef235bca-6aba-5187-92cb-4410c7784de3"
      }
    },
    "action--2e7a1b16-0cf3-51bd-9157-6a6a55dbc9c0": {
      "name": "Create case/notification to investigate Priv Esc",
      "on_completion": "if-condition--094a3664-919a-59f8-9271-d6a52e059048",
      "step_extensions": {
        "": "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f",
        "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f": {
          "type": "coordinates",
          "x": 415,
          "y": 1670,
          "width": 150,
          "height": 60,
          "outgoing_connections": [
            {
              "type": "on-completion",
              "x": [
                565,
                690
              ],
              "y": [
                1700,
                1700
              ]
            }
          ]
        }
      },
      "type": "action",
      "commands": [
        {
          "type": "http-api",
          "command": "Create case/notification to investigate Priv Esc"
        }
      ]
    },
    "action--2ee87d25-82ea-575f-97e5-81af80eab5d5": {
      "name": "Collect time, source, and destination for movement",
      "on_completion": "parallel--70da1338-2575-5f38-b378-226ebe95e23d",
      "step_extensions": {
        "": "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f",
        "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f": {
          "type": "coordinates",
          "x": -105,
          "y": 2300,
          "width": 150,
          "height": 60,
          "outgoing_connections": [
            {
              "type": "on-completion",
              "x": [
                45,
                170
              ],
              "y": [
                2330,
                2330
              ]
            }
          ]
        }
      },
      "type": "action",
      "commands": [
        {
          "type": "manual",
          "command": "Collect time, source, and destination for movement"
        }
      ]
    },
    "end--30fb02c4-8b75-524a-b5bc-e7a42d8bccb9": {
      "name": "End",
      "step_extensions": {
        "": "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f",
        "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f": {
          "type": "coordinates",
          "x": 810,
          "y": 2680,
          "width": 60,
          "height": 40
        }
      },
      "type": "end"
    },
    "action--369cd36f-557b-5280-bdfb-bafe4853cb1b": {
      "name": "Query Against Lateral Movement Alerts",
      "on_completion": "if-condition--69641257-91d1-5316-aa9e-83fc5ca6a2d4",
      "step_extensions": {
        "": "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f",
        "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f": {
          "type": "coordinates",
          "x": 675,
          "y": 2140,
          "width": 150,
          "height": 60,
          "outgoing_connections": [
            {
              "type": "on-completion",
              "x": [
                825,
                970
              ],
              "y": [
                2170,
                2170
              ]
            }
          ]
        }
      },
      "type": "action",
      "commands": [
        {
          "type": "manual",
          "command": "Query Against Lateral Movement Alerts"
        }
      ]
    },
    "action--38fed2e8-2dff-51b9-a512-d6cef6a96368": {
      "name": "Pull User ID and Hashes from request",
      "on_completion": "action--09e58dac-b6da-594a-a6f7-0d3eb4620de1",
      "step_extensions": {
        "": "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f",
        "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f": {
          "type": "coordinates",
          "x": 675,
          "y": 1960,
          "width": 150,
          "height": 60,
          "outgoing_connections": [
            {
              "type": "on-completion",
              "x": [
                825,
                955
              ],
              "y": [
                1990,
                1990
              ]
            }
          ]
        }
      },
      "type": "action",
      "commands": [
        {
          "type": "http-api",
          "command": "Pull User ID and Hashes from request"
        }
      ]
    },
    "end--3a4978fc-9bfa-4e21-b08d-d7ddb5aa1cbe": {
      "name": "End",
      "step_extensions": {
        "": "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f",
        "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f": {
          "type": "coordinates",
          "x": 830,
          "y": 1740,
          "width": 60,
          "height": 40
        }
      },
      "type": "end"
    },
    "parallel--41747c89-a295-54f5-9975-3eef34601331": {
      "step_extensions": {
        "": "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f",
        "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f": {
          "type": "coordinates",
          "x": 170,
          "y": 870,
          "width": 120,
          "height": 60,
          "outgoing_connections": [
            {
              "type": "next-steps",
              "x": [
                230,
                230,
                415
              ],
              "y": [
                930,
                960,
                960
              ]
            }
          ]
        }
      },
      "type": "parallel",
      "next_steps": [
        "action--4861325b-3e02-507b-80b5-accb1e46127e",
        "action--41f22ad7-86ec-5a00-8b64-f383f676cbcd"
      ]
    },
    "action--41f22ad7-86ec-5a00-8b64-f383f676cbcd": {
      "name": "Query against Macro Execution Alerts",
      "on_completion": "if-condition--12279fb7-1e51-5141-a6fd-c68420bbe2ac",
      "step_extensions": {
        "": "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f",
        "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f": {
          "type": "coordinates",
          "x": 415,
          "y": 930,
          "width": 150,
          "height": 60,
          "outgoing_connections": [
            {
              "type": "on-completion",
              "x": [
                565,
                690
              ],
              "y": [
                960,
                960
              ]
            }
          ]
        }
      },
      "type": "action",
      "commands": [
        {
          "type": "manual",
          "command": "Query against Macro Execution Alerts"
        }
      ]
    },
    "action--4861325b-3e02-507b-80b5-accb1e46127e": {
      "name": "Query against Spearphish 1 Alerts",
      "on_completion": "if-condition--a927f9c5-d9f7-5fe4-8d48-79f8e004ec3b",
      "step_extensions": {
        "": "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f",
        "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f": {
          "type": "coordinates",
          "x": 415,
          "y": 800,
          "width": 150,
          "height": 60,
          "outgoing_connections": [
            {
              "type": "on-completion",
              "x": [
                565,
                670,
                670,
                690
              ],
              "y": [
                830,
                830,
                790,
                790
              ]
            }
          ]
        }
      },
      "type": "action",
      "commands": [
        {
          "type": "manual",
          "command": "Query against Spearphish 1 Alerts"
        }
      ]
    },
    "end--4f18b820-c8cf-5bf1-b04c-69a769bb83f8": {
      "name": "End",
      "step_extensions": {
        "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f": {
          "type": "coordinates",
          "x": 2605,
          "y": 1740,
          "width": 60,
          "height": 40
        }
      },
      "type": "end"
    },
    "parallel--526ccaa1-8ed8-5856-b1c1-e4450088143c": {
      "step_extensions": {
        "": "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f",
        "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f": {
          "type": "coordinates",
          "x": 430,
          "y": 1130,
          "width": 120,
          "height": 60,
          "outgoing_connections": [
            {
              "type": "next-steps",
              "x": [
                490,
                490,
                675
              ],
              "y": [
                1190,
                1220,
                1220
              ]
            }
          ]
        }
      },
      "type": "parallel",
      "next_steps": [
        "action--0d4fd047-0ef1-5f27-8dbb-8be336cc432c",
        "action--84d76ac7-abae-5199-8a3e-ed563139ce6c"
      ]
    },
    "action--58558f31-d0a7-5f4c-a49c-601cb348bda3": {
      "name": "Collect Time, account requestingHost sending, traffic to DC(Multiple Logs)",
      "on_completion": "if-condition--1a99e08d-7628-51bc-966f-b4059c385b79",
      "step_extensions": {
        "": "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f",
        "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f": {
          "type": "coordinates",
          "x": -105,
          "y": 2050,
          "width": 150,
          "height": 60,
          "outgoing_connections": [
            {
              "type": "on-completion",
              "x": [
                45,
                170
              ],
              "y": [
                2080,
                2080
              ]
            }
          ]
        }
      },
      "type": "action",
      "commands": [
        {
          "type": "manual",
          "command": "Collect Time, account requesting\nHost sending, traffic to DC\n(Multiple Logs)"
        }
      ]
    },
    "action--58a39aa9-5334-54fc-8842-a304d8f95e08": {
      "name": "Query Against other alerts",
      "on_completion": "if-condition--c0206596-8e15-5489-b008-e00538bed168",
      "step_extensions": {
        "": "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f",
        "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f": {
          "type": "coordinates",
          "x": 415,
          "y": 2610,
          "width": 150,
          "height": 60,
          "outgoing_connections": [
            {
              "type": "on-completion",
              "x": [
                565,
                690
              ],
              "y": [
                2640,
                2640
              ]
            }
          ]
        }
      },
      "type": "action",
      "commands": [
        {
          "type": "manual",
          "command": "Query Against other alerts"
        }
      ]
    },
    "action--5a992339-37da-5e3e-bb8f-5e3b06c35f11": {
      "name": "Tally Points",
      "on_completion": "switch-condition--94e2c0f1-5195-5d57-9ba3-d9cfa58bf3ec",
      "step_extensions": {
        "": "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f",
        "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f": {
          "type": "coordinates",
          "x": 1515,
          "y": 1730,
          "width": 150,
          "height": 60,
          "outgoing_connections": [
            {
              "type": "on-completion",
              "x": [
                1665,
                1780
              ],
              "y": [
                1760,
                1760
              ]
            }
          ]
        }
      },
      "type": "action",
      "commands": [
        {
          "type": "manual",
          "command": "Tally Points"
        }
      ]
    },
    "parallel--604ef8f0-1677-54cc-80a1-d297ed9a557b": {
      "step_extensions": {
        "": "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f",
        "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f": {
          "type": "coordinates",
          "x": 170,
          "y": 1730,
          "width": 120,
          "height": 60,
          "outgoing_connections": [
            {
              "type": "next-steps",
              "x": [
                230,
                230,
                415
              ],
              "y": [
                1790,
                1840,
                1840
              ]
            }
          ]
        }
      },
      "type": "parallel",
      "next_steps": [
        "action--2e7a1b16-0cf3-51bd-9157-6a6a55dbc9c0",
        "action--db0e73fe-a2d3-5860-82be-113e1701b939"
      ]
    },
    "if-condition--69641257-91d1-5316-aa9e-83fc5ca6a2d4": {
      "name": "Is the source of Lateral Movement the Host conducting DC Sync?",
      "step_extensions": {
        "": "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f",
        "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f": {
          "type": "coordinates",
          "x": 970,
          "y": 2140,
          "width": 120,
          "height": 60,
          "outgoing_connections": [
            {
              "type": "on-true",
              "x": [
                1090,
                1235
              ],
              "y": [
                2170,
                2170
              ]
            },
            {
              "type": "on-false",
              "x": [
                1030,
                1030,
                1110
              ],
              "y": [
                2200,
                2230,
                2230
              ]
            }
          ]
        }
      },
      "type": "if-condition",
      "condition": "__is_the_source_of_lateral_movement_the_host_conducting_dc_sync__ == 1",
      "on_true": "action--fe316b17-d857-57fb-93ce-be2dc81439e0",
      "on_false": "end--ad05d8f0-6cb4-53b9-877e-0bfdfc3b01e3"
    },
    "if-condition--6b8ac5fd-678d-500c-a4d0-efc6339b5879": {
      "name": "Has Internal host been associated with other alerts recently?",
      "step_extensions": {
        "": "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f",
        "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f": {
          "type": "coordinates",
          "x": 690,
          "y": 1440,
          "width": 120,
          "height": 60,
          "outgoing_connections": [
            {
              "type": "on-true",
              "x": [
                810,
                955
              ],
              "y": [
                1470,
                1470
              ]
            },
            {
              "type": "on-false",
              "x": [
                750,
                750,
                830
              ],
              "y": [
                1500,
                1530,
                1530
              ]
            }
          ]
        }
      },
      "type": "if-condition",
      "condition": "__has_internal_host_been_associated_with_other_alerts_recently__ == 1",
      "on_true": "action--aa706614-0e3f-59dd-a2b1-5c08003e2303",
      "on_false": "end--0a7a04f1-5702-58fc-bc68-53e5e4d2b595"
    },
    "action--6e4a7bae-b71d-53fa-80ca-e457eea80b6d": {
      "name": "Generate Correlated Behavior Notification",
      "on_completion": "end--4f18b820-c8cf-5bf1-b04c-69a769bb83f8",
      "step_extensions": {
        "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f": {
          "type": "coordinates",
          "x": 2345,
          "y": 1730,
          "width": 150,
          "height": 60,
          "outgoing_connections": [
            {
              "type": "on-completion",
              "x": [
                2495,
                2605
              ],
              "y": [
                1760,
                1760
              ]
            }
          ]
        }
      },
      "type": "action",
      "commands": [
        {
          "type": "http-api",
          "command": "Generate Correlated Behavior Notification"
        }
      ]
    },
    "parallel--70da1338-2575-5f38-b378-226ebe95e23d": {
      "step_extensions": {
        "": "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f",
        "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f": {
          "type": "coordinates",
          "x": 170,
          "y": 2300,
          "width": 120,
          "height": 60,
          "outgoing_connections": [
            {
              "type": "next-steps",
              "x": [
                230,
                230,
                415
              ],
              "y": [
                2360,
                2390,
                2390
              ]
            }
          ]
        }
      },
      "type": "parallel",
      "next_steps": [
        "action--ed570a0b-f0dd-5541-945c-4e897802194d",
        "action--04499870-8083-573b-8159-42b09c73995d"
      ]
    },
    "action--710e1e69-2475-5d66-a385-5e6fc06d657e": {
      "name": "Record potential Exfil (Add 1 Point)",
      "on_completion": "action--5a992339-37da-5e3e-bb8f-5e3b06c35f11",
      "step_extensions": {
        "": "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f",
        "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f": {
          "type": "coordinates",
          "x": 415,
          "y": 2710,
          "width": 150,
          "height": 60,
          "outgoing_connections": [
            {
              "type": "on-completion",
              "x": [
                565,
                1640,
                1640
              ],
              "y": [
                2740,
                2740,
                1790
              ]
            }
          ]
        }
      },
      "type": "action",
      "commands": [
        {
          "type": "manual",
          "command": "Record potential Exfil (Add 1 Point)"
        }
      ]
    },
    "if-condition--77a6ca6c-6917-57ec-8209-00b04bd4510e": {
      "name": "Is the spawned process name different than the Office App for Created Process?",
      "step_extensions": {
        "": "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f",
        "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f": {
          "type": "coordinates",
          "x": 170,
          "y": 1130,
          "width": 120,
          "height": 60,
          "outgoing_connections": [
            {
              "type": "on-true",
              "x": [
                290,
                430
              ],
              "y": [
                1160,
                1160
              ]
            },
            {
              "type": "on-false",
              "x": [
                230,
                230,
                310
              ],
              "y": [
                1190,
                1220,
                1220
              ]
            }
          ]
        }
      },
      "type": "if-condition",
      "condition": "__is_the_spawned_process_name_different_than_the_office_app_for_created_process__ == 1",
      "on_true": "parallel--526ccaa1-8ed8-5856-b1c1-e4450088143c",
      "on_false": "end--78d558cc-5353-5581-99bc-41db876690bc"
    },
    "end--78d558cc-5353-5581-99bc-41db876690bc": {
      "name": "End",
      "step_extensions": {
        "": "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f",
        "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f": {
          "type": "coordinates",
          "x": 310,
          "y": 1200,
          "width": 60,
          "height": 40
        }
      },
      "type": "end"
    },
    "action--79d1af48-e3f6-5b2a-a771-ea49216458f1": {
      "name": "Collect (Time, Host, Process ID) for Web Browser called from Email",
      "on_completion": "action--f4a1ffdc-6f08-5ab2-ba30-f1314348d92e",
      "step_extensions": {
        "": "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f",
        "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f": {
          "type": "coordinates",
          "x": -105,
          "y": 740,
          "width": 150,
          "height": 60,
          "outgoing_connections": [
            {
              "type": "on-completion",
              "x": [
                45,
                155
              ],
              "y": [
                770,
                770
              ]
            }
          ]
        }
      },
      "type": "action",
      "commands": [
        {
          "type": "manual",
          "command": "Collect (Time, Host, Process ID) for Web Browser called from Email"
        }
      ]
    },
    "action--7edd1148-0500-5e53-a7ee-3a8c9613794b": {
      "name": "Record Macro spawned process that modded Reg (Add 1 point)",
      "on_completion": "action--5a992339-37da-5e3e-bb8f-5e3b06c35f11",
      "step_extensions": {
        "": "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f",
        "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f": {
          "type": "coordinates",
          "x": 955,
          "y": 1310,
          "width": 150,
          "height": 60,
          "outgoing_connections": [
            {
              "type": "on-completion",
              "x": [
                1105,
                1590,
                1590
              ],
              "y": [
                1340,
                1340,
                1730
              ]
            }
          ]
        }
      },
      "type": "action",
      "commands": [
        {
          "type": "manual",
          "command": "Record Macro spawned process that modded Reg (Add 1 point)"
        }
      ]
    },
    "end--81f3b418-9ea9-563d-9948-577acafb4591": {
      "name": "End",
      "step_extensions": {
        "": "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f",
        "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f": {
          "type": "coordinates",
          "x": 830,
          "y": 1380,
          "width": 60,
          "height": 40
        }
      },
      "type": "end"
    },
    "action--84d76ac7-abae-5199-8a3e-ed563139ce6c": {
      "name": "Record Office App creating EXE or DLL (Add 1 Point)",
      "on_completion": "parallel--8adc616e-01a3-5c9f-a47e-8ba89e4000e8",
      "step_extensions": {
        "": "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f",
        "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f": {
          "type": "coordinates",
          "x": 675,
          "y": 1190,
          "width": 150,
          "height": 60,
          "outgoing_connections": [
            {
              "type": "on-completion",
              "x": [
                825,
                970
              ],
              "y": [
                1220,
                1220
              ]
            }
          ]
        }
      },
      "type": "action",
      "commands": [
        {
          "type": "manual",
          "command": "Record Office App creating EXE or DLL \n(Add 1 Point)"
        }
      ]
    },
    "action--86f582bd-d312-5524-9158-371ed2609248": {
      "name": "Collect Time, Host, PID, New_Value",
      "on_completion": "action--d007d70e-7e50-5a8b-87ef-c76695e9e7b1",
      "step_extensions": {
        "": "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f",
        "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f": {
          "type": "coordinates",
          "x": -105,
          "y": 1310,
          "width": 150,
          "height": 60,
          "outgoing_connections": [
            {
              "type": "on-completion",
              "x": [
                45,
                155
              ],
              "y": [
                1340,
                1340
              ]
            }
          ]
        }
      },
      "type": "action",
      "commands": [
        {
          "type": "manual",
          "command": "Collect Time, Host, PID, New_Value"
        }
      ]
    },
    "parallel--8adc616e-01a3-5c9f-a47e-8ba89e4000e8": {
      "step_extensions": {
        "": "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f",
        "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f": {
          "type": "coordinates",
          "x": 970,
          "y": 1190,
          "width": 120,
          "height": 60,
          "outgoing_connections": [
            {
              "type": "next-steps",
              "x": [
                1030,
                1030,
                1610,
                1610
              ],
              "y": [
                1190,
                1160,
                1160,
                1730
              ]
            }
          ]
        }
      },
      "type": "parallel",
      "next_steps": [
        "action--d7ccde78-fef0-5c3e-8063-4b813c96e597",
        "action--5a992339-37da-5e3e-bb8f-5e3b06c35f11"
      ]
    },
    "action--8e22b060-b468-5fe9-8c2e-0032327fdad4": {
      "name": "Collect Time, Host, token info, account info",
      "on_completion": "parallel--604ef8f0-1677-54cc-80a1-d297ed9a557b",
      "step_extensions": {
        "": "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f",
        "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f": {
          "type": "coordinates",
          "x": -105,
          "y": 1730,
          "width": 150,
          "height": 60,
          "outgoing_connections": [
            {
              "type": "on-completion",
              "x": [
                45,
                170
              ],
              "y": [
                1760,
                1760
              ]
            }
          ]
        }
      },
      "type": "action",
      "commands": [
        {
          "type": "manual",
          "command": "Collect Time, Host, token info, account info"
        }
      ]
    },
    "switch-condition--94e2c0f1-5195-5d57-9ba3-d9cfa58bf3ec": {
      "name": "Set Correlation for Behavior Set based on Point Tally",
      "step_extensions": {
        "": "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f",
        "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f": {
          "type": "coordinates",
          "x": 1780,
          "y": 1730,
          "width": 120,
          "height": 60,
          "outgoing_connections": [
            {
              "type": "cases",
              "x": [
                1890,
                1890,
                2055
              ],
              "y": [
                1730,
                1650,
                1650
              ],
              "case": "BETWEEN 0 AND 3 POINTS"
            },
            {
              "type": "cases",
              "x": [
                1900,
                2055
              ],
              "y": [
                1760,
                1760
              ],
              "case": "BETWEEN 3 AND 8 POINTS"
            },
            {
              "type": "cases",
              "x": [
                1890,
                1890,
                2055
              ],
              "y": [
                1790,
                1870,
                1870
              ],
              "case": "MORE THAN 8 POINTS"
            }
          ]
        }
      },
      "type": "switch-condition",
      "switch": "__set_correlation_for_behavior_set_based_on_point_tally__",
      "cases": {
        "BETWEEN 0 AND 3 POINTS": "action--2c0bfc3a-b069-5862-aa7a-5b8822d6a0f2",
        "BETWEEN 3 AND 8 POINTS": "action--d165e3e5-1577-500b-b91e-90f803c97c34",
        "MORE THAN 8 POINTS": "action--f3eb1f1d-e557-5cfb-bde8-3e4a547a250a"
      }
    },
    "if-condition--a3938ab5-748d-54b3-8f6a-1fbeb8dcec6d": {
      "name": "Is Destination where Exfil occurs?",
      "step_extensions": {
        "": "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f",
        "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f": {
          "type": "coordinates",
          "x": 690,
          "y": 2480,
          "width": 120,
          "height": 60,
          "outgoing_connections": [
            {
              "type": "on-true",
              "x": [
                810,
                955
              ],
              "y": [
                2510,
                2510
              ]
            },
            {
              "type": "on-false",
              "x": [
                750,
                750,
                810
              ],
              "y": [
                2540,
                2570,
                2570
              ]
            }
          ]
        }
      },
      "type": "if-condition",
      "condition": "__is_destination_where_exfil_occurs__ == 1",
      "on_true": "action--1169afb8-09ae-5e70-8ae0-3c4b3ee47ebb",
      "on_false": "end--f2b4e2c0-a423-5ad6-b39e-597ddcb6d1a0"
    },
    "if-condition--a927f9c5-d9f7-5fe4-8d48-79f8e004ec3b": {
      "name": "Is there an Email to Web and Web to Office activity on host in short timeframe?",
      "step_extensions": {
        "": "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f",
        "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f": {
          "type": "coordinates",
          "x": 690,
          "y": 740,
          "width": 120,
          "height": 60,
          "outgoing_connections": [
            {
              "type": "on-true",
              "x": [
                810,
                955
              ],
              "y": [
                770,
                770
              ]
            },
            {
              "type": "on-false",
              "x": [
                750,
                750,
                840
              ],
              "y": [
                800,
                830,
                830
              ]
            }
          ]
        }
      },
      "type": "if-condition",
      "condition": "__is_there_an_email_to_web_and_web_to_office_activity_on_host_in_short_timeframe__ == 1",
      "on_true": "action--aef1c9e7-e01b-5f13-abe9-5747306d7e45",
      "on_false": "end--2874e922-bbd1-5df4-9a61-ff20fc5e61c8"
    },
    "parallel--a92a3efd-7519-5625-b319-27267bc6687d": {
      "step_extensions": {
        "": "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f",
        "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f": {
          "type": "coordinates",
          "x": 170,
          "y": 1500,
          "width": 120,
          "height": 60,
          "outgoing_connections": [
            {
              "type": "next-steps",
              "x": [
                230,
                230,
                415
              ],
              "y": [
                1500,
                1470,
                1470
              ]
            }
          ]
        }
      },
      "type": "parallel",
      "next_steps": [
        "action--e914a173-0abf-5b4a-b806-9867d1f0790b",
        "action--dfb5ae17-9dfc-591c-a2ee-2dd7cd377d40"
      ]
    },
    "action--aa706614-0e3f-59dd-a2b1-5c08003e2303": {
      "name": "Record Beaconing Associated with other behaviors (add 1 point)",
      "on_completion": "action--5a992339-37da-5e3e-bb8f-5e3b06c35f11",
      "step_extensions": {
        "": "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f",
        "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f": {
          "type": "coordinates",
          "x": 955,
          "y": 1440,
          "width": 150,
          "height": 60,
          "outgoing_connections": [
            {
              "type": "on-completion",
              "x": [
                1105,
                1570,
                1570
              ],
              "y": [
                1470,
                1470,
                1730
              ]
            }
          ]
        }
      },
      "type": "action",
      "commands": [
        {
          "type": "manual",
          "command": "Record Beaconing Associated with other behaviors (add 1 point)"
        }
      ]
    },
    "end--ad05d8f0-6cb4-53b9-877e-0bfdfc3b01e3": {
      "name": "End",
      "step_extensions": {
        "": "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f",
        "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f": {
          "type": "coordinates",
          "x": 1110,
          "y": 2210,
          "width": 60,
          "height": 40
        }
      },
      "type": "end"
    },
    "action--aef1c9e7-e01b-5f13-abe9-5747306d7e45": {
      "name": "Record a potential Macro SpearPhish detection (Add 1 point?)",
      "on_completion": "action--5a992339-37da-5e3e-bb8f-5e3b06c35f11",
      "step_extensions": {
        "": "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f",
        "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f": {
          "type": "coordinates",
          "x": 955,
          "y": 740,
          "width": 150,
          "height": 60,
          "outgoing_connections": [
            {
              "type": "on-completion",
              "x": [
                1105,
                1650,
                1650
              ],
              "y": [
                770,
                770,
                1730
              ]
            }
          ]
        }
      },
      "type": "action",
      "commands": [
        {
          "type": "manual",
          "command": "Record a potential Macro SpearPhish detection (Add 1 point?)"
        }
      ]
    },
    "action--b4c3ca75-364e-5ec7-8fa0-329f1f221027": {
      "name": "Record PrivEsc Account accessing Hashes (add 1 point)",
      "on_completion": "action--5a992339-37da-5e3e-bb8f-5e3b06c35f11",
      "step_extensions": {
        "": "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f",
        "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f": {
          "type": "coordinates",
          "x": 975,
          "y": 1810,
          "width": 150,
          "height": 60,
          "outgoing_connections": [
            {
              "type": "on-completion",
              "x": [
                1125,
                1540,
                1540
              ],
              "y": [
                1840,
                1840,
                1790
              ]
            }
          ]
        }
      },
      "type": "action",
      "commands": [
        {
          "type": "manual",
          "command": "Record PrivEsc Account accessing Hashes (add 1 point)"
        }
      ]
    },
    "action--b9405597-ab73-5f60-875e-985dc529e04e": {
      "name": "Record Abnormal Priv Esc (Add 1 Point)",
      "on_completion": "action--5a992339-37da-5e3e-bb8f-5e3b06c35f11",
      "step_extensions": {
        "": "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f",
        "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f": {
          "type": "coordinates",
          "x": 955,
          "y": 1670,
          "width": 150,
          "height": 60,
          "outgoing_connections": [
            {
              "type": "on-completion",
              "x": [
                1105,
                1530,
                1530
              ],
              "y": [
                1700,
                1700,
                1730
              ]
            }
          ]
        }
      },
      "type": "action",
      "commands": [
        {
          "type": "manual",
          "command": "Record Abnormal Priv Esc (Add 1 Point)"
        }
      ]
    },
    "if-condition--c0206596-8e15-5489-b008-e00538bed168": {
      "name": "Is host or User account associated with other alerts recently?",
      "step_extensions": {
        "": "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f",
        "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f": {
          "type": "coordinates",
          "x": 690,
          "y": 2610,
          "width": 120,
          "height": 60,
          "outgoing_connections": [
            {
              "type": "on-true",
              "x": [
                810,
                955
              ],
              "y": [
                2640,
                2640
              ]
            },
            {
              "type": "on-false",
              "x": [
                750,
                750,
                810
              ],
              "y": [
                2670,
                2700,
                2700
              ]
            }
          ]
        }
      },
      "type": "if-condition",
      "condition": "__is_host_or_user_account_associated_with_other_alerts_recently__ == 1",
      "on_true": "action--c7092f19-1dd9-5d73-ab63-e4eee7844ada",
      "on_false": "end--30fb02c4-8b75-524a-b5bc-e7a42d8bccb9"
    },
    "end--c1f3cd70-1343-413a-b13f-2b18eb79014e": {
      "name": "End",
      "step_extensions": {
        "": "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f",
        "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f": {
          "type": "coordinates",
          "x": 830,
          "y": 1880,
          "width": 60,
          "height": 40
        }
      },
      "type": "end"
    },
    "action--c2b6b202-8eaa-537b-b8fb-55e3dc7ebd56": {
      "name": "Collect Internal and External Host Info",
      "on_completion": "parallel--a92a3efd-7519-5625-b319-27267bc6687d",
      "step_extensions": {
        "": "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f",
        "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f": {
          "type": "coordinates",
          "x": -105,
          "y": 1500,
          "width": 150,
          "height": 60,
          "outgoing_connections": [
            {
              "type": "on-completion",
              "x": [
                45,
                170
              ],
              "y": [
                1530,
                1530
              ]
            }
          ]
        }
      },
      "type": "action",
      "commands": [
        {
          "type": "manual",
          "command": "Collect Internal and External Host Info"
        }
      ]
    },
    "end--c3cbbd9d-3358-5f0e-9800-e488be2532e3": {
      "name": "End",
      "step_extensions": {
        "": "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f",
        "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f": {
          "type": "coordinates",
          "x": 840,
          "y": 1000,
          "width": 60,
          "height": 40
        }
      },
      "type": "end"
    },
    "action--c7092f19-1dd9-5d73-ab63-e4eee7844ada": {
      "name": "Record Exfil associated with other activity (Add 1 point)",
      "on_completion": "action--5a992339-37da-5e3e-bb8f-5e3b06c35f11",
      "step_extensions": {
        "": "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f",
        "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f": {
          "type": "coordinates",
          "x": 955,
          "y": 2610,
          "width": 150,
          "height": 60,
          "outgoing_connections": [
            {
              "type": "on-completion",
              "x": [
                1105,
                1620,
                1620
              ],
              "y": [
                2640,
                2640,
                1790
              ]
            }
          ]
        }
      },
      "type": "action",
      "commands": [
        {
          "type": "manual",
          "command": "Record Exfil associated with other activity (Add 1 point)"
        }
      ]
    },
    "end--c8a3d080-505a-529b-979f-90b4b7ddf30a": {
      "name": "End",
      "step_extensions": {
        "": "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f",
        "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f": {
          "type": "coordinates",
          "x": 303,
          "y": 2120,
          "width": 60,
          "height": 40
        }
      },
      "type": "end"
    },
    "action--ca0ab10e-8c3c-582a-b57b-7e9fef9edb45": {
      "name": "Query Against Macro Execution Alert",
      "on_completion": "if-condition--0c6367bb-7a19-56ab-a613-bde5710ba0f8",
      "step_extensions": {
        "": "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f",
        "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f": {
          "type": "coordinates",
          "x": 415,
          "y": 1310,
          "width": 150,
          "height": 60,
          "outgoing_connections": [
            {
              "type": "on-completion",
              "x": [
                565,
                690
              ],
              "y": [
                1340,
                1340
              ]
            }
          ]
        }
      },
      "type": "action",
      "commands": [
        {
          "type": "manual",
          "command": "Query Against Macro Execution Alert"
        }
      ]
    },
    "action--cc7f3650-c731-5723-92d7-96e0d5e270f9": {
      "name": "Record Downloaded File Creating Exe (Add 1 Point)",
      "on_completion": "action--5a992339-37da-5e3e-bb8f-5e3b06c35f11",
      "step_extensions": {
        "": "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f",
        "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f": {
          "type": "coordinates",
          "x": 955,
          "y": 930,
          "width": 150,
          "height": 60,
          "outgoing_connections": [
            {
              "type": "on-completion",
              "x": [
                1105,
                1630,
                1630
              ],
              "y": [
                960,
                960,
                1730
              ]
            }
          ]
        }
      },
      "type": "action",
      "commands": [
        {
          "type": "manual",
          "command": "Record Downloaded File Creating Exe (Add 1 Point)"
        }
      ]
    },
    "parallel--cff6c610-6493-589f-a20f-50f209f6461d": {
      "step_extensions": {
        "": "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f",
        "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f": {
          "type": "coordinates",
          "x": 430,
          "y": 2050,
          "width": 120,
          "height": 60,
          "outgoing_connections": [
            {
              "type": "next-steps",
              "x": [
                490,
                490,
                675
              ],
              "y": [
                2110,
                2170,
                2170
              ]
            }
          ]
        }
      },
      "type": "parallel",
      "next_steps": [
        "action--fc58dd2b-e932-5714-87e1-f0cc4993b045",
        "action--38fed2e8-2dff-51b9-a512-d6cef6a96368",
        "action--369cd36f-557b-5280-bdfb-bafe4853cb1b"
      ]
    },
    "action--d007d70e-7e50-5a8b-87ef-c76695e9e7b1": {
      "name": "Search for PID that created this process",
      "on_completion": "action--ca0ab10e-8c3c-582a-b57b-7e9fef9edb45",
      "step_extensions": {
        "": "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f",
        "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f": {
          "type": "coordinates",
          "x": 155,
          "y": 1310,
          "width": 150,
          "height": 60,
          "outgoing_connections": [
            {
              "type": "on-completion",
              "x": [
                305,
                415
              ],
              "y": [
                1340,
                1340
              ]
            }
          ]
        }
      },
      "type": "action",
      "commands": [
        {
          "type": "http-api",
          "command": "Search for PID that created this process"
        }
      ]
    },
    "action--d165e3e5-1577-500b-b91e-90f803c97c34": {
      "name": "Set Correlation to Medium",
      "on_completion": "action--6e4a7bae-b71d-53fa-80ca-e457eea80b6d",
      "step_extensions": {
        "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f": {
          "type": "coordinates",
          "x": 2055,
          "y": 1730,
          "width": 150,
          "height": 60,
          "outgoing_connections": [
            {
              "type": "on-completion",
              "x": [
                2205,
                2345
              ],
              "y": [
                1760,
                1760
              ]
            }
          ]
        }
      },
      "type": "action",
      "commands": [
        {
          "type": "manual",
          "command": "Set Correlation to Medium"
        }
      ]
    },
    "action--d7ccde78-fef0-5c3e-8063-4b813c96e597": {
      "name": "Query against Registry Mod Alert",
      "on_completion": "if-condition--0c6367bb-7a19-56ab-a613-bde5710ba0f8",
      "step_extensions": {
        "": "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f",
        "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f": {
          "type": "coordinates",
          "x": 1235,
          "y": 1190,
          "width": 150,
          "height": 60,
          "outgoing_connections": [
            {
              "type": "on-completion",
              "x": [
                1385,
                1490,
                1490,
                750,
                750
              ],
              "y": [
                1220,
                1220,
                1280,
                1280,
                1310
              ]
            }
          ]
        }
      },
      "type": "action",
      "commands": [
        {
          "type": "manual",
          "command": "Query against Registry Mod Alert"
        }
      ]
    },
    "action--db0e73fe-a2d3-5860-82be-113e1701b939": {
      "name": "Query Against DCSync Alerts",
      "on_completion": "if-condition--468c9c60-6091-4e4f-b048-f8b686f5eb0c",
      "step_extensions": {
        "": "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f",
        "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f": {
          "type": "coordinates",
          "x": 415,
          "y": 1810,
          "width": 150,
          "height": 60,
          "outgoing_connections": [
            {
              "type": "on-completion",
              "x": [
                565,
                690
              ],
              "y": [
                1840,
                1840
              ]
            }
          ]
        }
      },
      "type": "action",
      "commands": [
        {
          "type": "manual",
          "command": "Query Against DCSync Alerts"
        }
      ]
    },
    "action--dfb5ae17-9dfc-591c-a2ee-2dd7cd377d40": {
      "name": "Query against other alerts",
      "on_completion": "if-condition--6b8ac5fd-678d-500c-a4d0-efc6339b5879",
      "step_extensions": {
        "": "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f",
        "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f": {
          "type": "coordinates",
          "x": 415,
          "y": 1440,
          "width": 150,
          "height": 60,
          "outgoing_connections": [
            {
              "type": "on-completion",
              "x": [
                565,
                690
              ],
              "y": [
                1470,
                1470
              ]
            }
          ]
        }
      },
      "type": "action",
      "commands": [
        {
          "type": "manual",
          "command": "Query against other alerts"
        }
      ]
    },
    "action--e1e6a9d6-9916-535e-a792-838ffda98115": {
      "name": "Collect (Time, Host, Process IDs) from browser opening macro doc",
      "on_completion": "parallel--41747c89-a295-54f5-9975-3eef34601331",
      "step_extensions": {
        "": "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f",
        "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f": {
          "type": "coordinates",
          "x": -105,
          "y": 870,
          "width": 150,
          "height": 60,
          "outgoing_connections": [
            {
              "type": "on-completion",
              "x": [
                45,
                170
              ],
              "y": [
                900,
                900
              ]
            }
          ]
        }
      },
      "type": "action",
      "commands": [
        {
          "type": "manual",
          "command": "Collect (Time, Host, Process IDs) from browser opening macro doc"
        }
      ]
    },
    "action--e914a173-0abf-5b4a-b806-9867d1f0790b": {
      "name": "Record Potential Beaconing (Add 1 point)",
      "on_completion": "action--5a992339-37da-5e3e-bb8f-5e3b06c35f11",
      "step_extensions": {
        "": "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f",
        "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f": {
          "type": "coordinates",
          "x": 415,
          "y": 1560,
          "width": 150,
          "height": 60,
          "outgoing_connections": [
            {
              "type": "on-completion",
              "x": [
                565,
                1550,
                1550
              ],
              "y": [
                1590,
                1590,
                1730
              ]
            }
          ]
        }
      },
      "type": "action",
      "commands": [
        {
          "type": "manual",
          "command": "Record Potential Beaconing (Add 1 point)"
        }
      ]
    },
    "action--ed570a0b-f0dd-5541-945c-4e897802194d": {
      "name": "Query Against DC Sync Alerts",
      "on_completion": "if-condition--69641257-91d1-5316-aa9e-83fc5ca6a2d4",
      "step_extensions": {
        "": "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f",
        "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f": {
          "type": "coordinates",
          "x": 415,
          "y": 2240,
          "width": 150,
          "height": 60,
          "outgoing_connections": [
            {
              "type": "on-completion",
              "x": [
                565,
                940,
                940,
                970
              ],
              "y": [
                2270,
                2270,
                2190,
                2190
              ]
            }
          ]
        }
      },
      "type": "action",
      "commands": [
        {
          "type": "manual",
          "command": "Query Against DC Sync Alerts"
        }
      ]
    },
    "action--ef235bca-6aba-5187-92cb-4410c7784de3": {
      "name": "Collect time, host, user account associated with exfil",
      "on_completion": "parallel--f21e3309-f95b-52ee-a963-d6ed41d3cca8",
      "step_extensions": {
        "": "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f",
        "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f": {
          "type": "coordinates",
          "x": -105,
          "y": 2610,
          "width": 150,
          "height": 60,
          "outgoing_connections": [
            {
              "type": "on-completion",
              "x": [
                45,
                170
              ],
              "y": [
                2640,
                2640
              ]
            }
          ]
        }
      },
      "type": "action",
      "commands": [
        {
          "type": "manual",
          "command": "Collect time, host, user account associated with exfil"
        }
      ]
    },
    "parallel--f21e3309-f95b-52ee-a963-d6ed41d3cca8": {
      "step_extensions": {
        "": "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f",
        "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f": {
          "type": "coordinates",
          "x": 170,
          "y": 2610,
          "width": 120,
          "height": 60,
          "outgoing_connections": [
            {
              "type": "next-steps",
              "x": [
                230,
                230,
                415
              ],
              "y": [
                2610,
                2510,
                2510
              ]
            }
          ]
        }
      },
      "type": "parallel",
      "next_steps": [
        "action--58a39aa9-5334-54fc-8842-a304d8f95e08",
        "action--710e1e69-2475-5d66-a385-5e6fc06d657e",
        "action--01df3b29-8200-5c7d-bb6f-d0b703886683"
      ]
    },
    "end--f2b4e2c0-a423-5ad6-b39e-597ddcb6d1a0": {
      "name": "End",
      "step_extensions": {
        "": "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f",
        "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f": {
          "type": "coordinates",
          "x": 810,
          "y": 2550,
          "width": 60,
          "height": 40
        }
      },
      "type": "end"
    },
    "action--f3eb1f1d-e557-5cfb-bde8-3e4a547a250a": {
      "name": "Set Correlation to High",
      "on_completion": "action--6e4a7bae-b71d-53fa-80ca-e457eea80b6d",
      "step_extensions": {
        "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f": {
          "type": "coordinates",
          "x": 2055,
          "y": 1840,
          "width": 150,
          "height": 60,
          "outgoing_connections": [
            {
              "type": "on-completion",
              "x": [
                2205,
                2310,
                2310,
                2345
              ],
              "y": [
                1870,
                1870,
                1760,
                1760
              ]
            }
          ]
        }
      },
      "type": "action",
      "commands": [
        {
          "type": "manual",
          "command": "Set Correlation to High"
        }
      ]
    },
    "action--f4a1ffdc-6f08-5ab2-ba30-f1314348d92e": {
      "name": "Query against Spearphish 2 Alerts",
      "on_completion": "if-condition--a927f9c5-d9f7-5fe4-8d48-79f8e004ec3b",
      "step_extensions": {
        "": "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f",
        "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f": {
          "type": "coordinates",
          "x": 155,
          "y": 740,
          "width": 150,
          "height": 60,
          "outgoing_connections": [
            {
              "type": "on-completion",
              "x": [
                305,
                690
              ],
              "y": [
                770,
                770
              ]
            }
          ]
        }
      },
      "type": "action",
      "commands": [
        {
          "type": "manual",
          "command": "Query against Spearphish 2 Alerts"
        }
      ]
    },
    "action--fc58dd2b-e932-5714-87e1-f0cc4993b045": {
      "name": "Record Potential Hash compromise (Add 1 Point)",
      "on_completion": "action--5a992339-37da-5e3e-bb8f-5e3b06c35f11",
      "step_extensions": {
        "": "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f",
        "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f": {
          "type": "coordinates",
          "x": 675,
          "y": 2050,
          "width": 150,
          "height": 60,
          "outgoing_connections": [
            {
              "type": "on-completion",
              "x": [
                825,
                1560,
                1560
              ],
              "y": [
                2080,
                2080,
                1790
              ]
            }
          ]
        }
      },
      "type": "action",
      "commands": [
        {
          "type": "manual",
          "command": "Record Potential Hash compromise (Add 1 Point)"
        }
      ]
    },
    "action--fe316b17-d857-57fb-93ce-be2dc81439e0": {
      "name": "Record DC Sync led to Lateral Movement (Add 1 Point)",
      "on_completion": "action--5a992339-37da-5e3e-bb8f-5e3b06c35f11",
      "step_extensions": {
        "": "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f",
        "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f": {
          "type": "coordinates",
          "x": 1235,
          "y": 2140,
          "width": 150,
          "height": 60,
          "outgoing_connections": [
            {
              "type": "on-completion",
              "x": [
                1385,
                1580,
                1580
              ],
              "y": [
                2170,
                2170,
                1790
              ]
            }
          ]
        }
      },
      "type": "action",
      "commands": [
        {
          "type": "manual",
          "command": "Record DC Sync led to Lateral Movement (Add 1 Point)"
        }
      ]
    }
  },
  "extension_definitions": {
    "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f": {
      "type": "extension-definition",
      "name": "coordinates extension",
      "description": "Coordinates extension for CACAO constructs for visualization purposes.",
      "created_by": "identity--5abe695c-7bd5-4c31-8824-2528696cdbf1",
      "schema": "https://raw.githubusercontent.com/cyentific-rni/cacao-coordinates-extension/main/schemas/coordinates.json",
      "version": "1.0.0"
    }
  }
}", - "playbook_abstraction": "template", + "is_playbook_template": true, "playbook_creation_time": "2022-03-31T13:00:00.000Z", "playbook_modification_time": "2022-03-31T13:00:00.000Z", "revoked": false, @@ -1346,7 +1346,7 @@ "notification" ], "playbook_bin": "<?xml version="1.0" encoding="UTF-8"?>
<bpmn:definitions xmlns:bpmn="http://www.omg.org/spec/BPMN/20100524/MODEL" xmlns:bpmndi="http://www.omg.org/spec/BPMN/20100524/DI" xmlns:dc="http://www.omg.org/spec/DD/20100524/DC" xmlns:di="http://www.omg.org/spec/DD/20100524/DI" xmlns:bioc="http://bpmn.io/schema/bpmn/biocolor/1.0" xmlns:color="http://www.omg.org/spec/BPMN/non-normative/color/1.0" id="Definitions_1ll7fmz" targetNamespace="http://bpmn.io/schema/bpmn" exporter="Camunda Modeler" exporterVersion="5.5.1">
  <bpmn:process id="Process_1qnegtj" isExecutable="true">
    <bpmn:startEvent id="StartEvent_1" name="Office Macro Spearphish 1 Alert">
      <bpmn:outgoing>Flow_17jrn7z</bpmn:outgoing>
      <bpmn:signalEventDefinition id="SignalEventDefinition_1webtlp" />
    </bpmn:startEvent>
    <bpmn:startEvent id="Event_144r6zj" name="Office Macro Execution Alert">
      <bpmn:outgoing>Flow_0z520fi</bpmn:outgoing>
      <bpmn:signalEventDefinition id="SignalEventDefinition_1o5rnqv" />
    </bpmn:startEvent>
    <bpmn:startEvent id="Event_130qlt1" name="Office Macro Spearphish 2 Alert">
      <bpmn:outgoing>Flow_1k7mthp</bpmn:outgoing>
      <bpmn:signalEventDefinition id="SignalEventDefinition_0uttt23" />
    </bpmn:startEvent>
    <bpmn:startEvent id="Event_1pp8kgr" name="Registry Mod Alert">
      <bpmn:outgoing>Flow_13wfs08</bpmn:outgoing>
      <bpmn:signalEventDefinition id="SignalEventDefinition_1pytnjm" />
    </bpmn:startEvent>
    <bpmn:startEvent id="Event_0lavc91" name="DCSync Alert">
      <bpmn:outgoing>Flow_1lk5v0x</bpmn:outgoing>
      <bpmn:signalEventDefinition id="SignalEventDefinition_0la3kc4" />
    </bpmn:startEvent>
    <bpmn:startEvent id="Event_1r7y8v8" name="Exfil Alert">
      <bpmn:outgoing>Flow_0dl9ybr</bpmn:outgoing>
      <bpmn:signalEventDefinition id="SignalEventDefinition_0re9gqg" />
    </bpmn:startEvent>
    <bpmn:sequenceFlow id="Flow_17jrn7z" sourceRef="StartEvent_1" targetRef="Activity_0t9phcm" />
    <bpmn:task id="Activity_0t9phcm" name="Collect (Time, Host, Process ID) for Web Browser called from Email">
      <bpmn:incoming>Flow_17jrn7z</bpmn:incoming>
      <bpmn:outgoing>Flow_0bvkuk3</bpmn:outgoing>
    </bpmn:task>
    <bpmn:task id="Activity_0ptc937" name="Query against Spearphish 2 Alerts">
      <bpmn:incoming>Flow_0bvkuk3</bpmn:incoming>
      <bpmn:outgoing>Flow_1080lyi</bpmn:outgoing>
    </bpmn:task>
    <bpmn:sequenceFlow id="Flow_0bvkuk3" sourceRef="Activity_0t9phcm" targetRef="Activity_0ptc937" />
    <bpmn:task id="Activity_1qdssbv" name="Collect (Time, Host, Process IDs) from browser opening macro doc">
      <bpmn:incoming>Flow_1k7mthp</bpmn:incoming>
      <bpmn:outgoing>Flow_0woh0jt</bpmn:outgoing>
    </bpmn:task>
    <bpmn:sequenceFlow id="Flow_1k7mthp" sourceRef="Event_130qlt1" targetRef="Activity_1qdssbv" />
    <bpmn:exclusiveGateway id="Gateway_17ffsxe" name="Is there an Email to Web and Web to Office activity on host in short timeframe?">
      <bpmn:incoming>Flow_1080lyi</bpmn:incoming>
      <bpmn:incoming>Flow_0h8x3zt</bpmn:incoming>
      <bpmn:outgoing>Flow_1viyo66</bpmn:outgoing>
      <bpmn:outgoing>Flow_1ru70dh</bpmn:outgoing>
    </bpmn:exclusiveGateway>
    <bpmn:sequenceFlow id="Flow_1080lyi" sourceRef="Activity_0ptc937" targetRef="Gateway_17ffsxe" />
    <bpmn:endEvent id="Event_0j8xdvr" name="Stop">
      <bpmn:incoming>Flow_1viyo66</bpmn:incoming>
    </bpmn:endEvent>
    <bpmn:sequenceFlow id="Flow_1viyo66" name="NO" sourceRef="Gateway_17ffsxe" targetRef="Event_0j8xdvr" />
    <bpmn:parallelGateway id="Gateway_1f34cp4">
      <bpmn:incoming>Flow_0woh0jt</bpmn:incoming>
      <bpmn:outgoing>Flow_1rclzph</bpmn:outgoing>
      <bpmn:outgoing>Flow_14fgq7q</bpmn:outgoing>
    </bpmn:parallelGateway>
    <bpmn:task id="Activity_0j861nm" name="Query against Spearphish 1 Alerts">
      <bpmn:incoming>Flow_1rclzph</bpmn:incoming>
      <bpmn:outgoing>Flow_0h8x3zt</bpmn:outgoing>
    </bpmn:task>
    <bpmn:sequenceFlow id="Flow_1rclzph" sourceRef="Gateway_1f34cp4" targetRef="Activity_0j861nm" />
    <bpmn:sequenceFlow id="Flow_0h8x3zt" sourceRef="Activity_0j861nm" targetRef="Gateway_17ffsxe" />
    <bpmn:sequenceFlow id="Flow_1ru70dh" name="YES" sourceRef="Gateway_17ffsxe" targetRef="Activity_1tw9hbu" />
    <bpmn:task id="Activity_1tw9hbu" name="Record a potential Macro SpearPhish detection (Add 1 point?)">
      <bpmn:incoming>Flow_1ru70dh</bpmn:incoming>
      <bpmn:outgoing>Flow_0vee046</bpmn:outgoing>
    </bpmn:task>
    <bpmn:task id="Activity_1fg10zt" name="Collect Time, Process Name, Process ID, Host">
      <bpmn:incoming>Flow_0z520fi</bpmn:incoming>
      <bpmn:outgoing>Flow_14cwe2n</bpmn:outgoing>
    </bpmn:task>
    <bpmn:sequenceFlow id="Flow_0z520fi" sourceRef="Event_144r6zj" targetRef="Activity_1fg10zt" />
    <bpmn:sequenceFlow id="Flow_0woh0jt" sourceRef="Activity_1qdssbv" targetRef="Gateway_1f34cp4" />
    <bpmn:task id="Activity_1tcctjs" name="Query against Macro Execution Alerts">
      <bpmn:incoming>Flow_14fgq7q</bpmn:incoming>
      <bpmn:outgoing>Flow_0s11qy2</bpmn:outgoing>
    </bpmn:task>
    <bpmn:sequenceFlow id="Flow_14fgq7q" sourceRef="Gateway_1f34cp4" targetRef="Activity_1tcctjs" />
    <bpmn:exclusiveGateway id="Gateway_0y8j1bb" name="Is the spawned process name different than the Office App for Created Process?">
      <bpmn:incoming>Flow_14cwe2n</bpmn:incoming>
      <bpmn:outgoing>Flow_1tz9g6w</bpmn:outgoing>
      <bpmn:outgoing>Flow_0wgefx9</bpmn:outgoing>
    </bpmn:exclusiveGateway>
    <bpmn:sequenceFlow id="Flow_14cwe2n" sourceRef="Activity_1fg10zt" targetRef="Gateway_0y8j1bb" />
    <bpmn:endEvent id="Event_0tlhv9f" name="Stop">
      <bpmn:incoming>Flow_1tz9g6w</bpmn:incoming>
    </bpmn:endEvent>
    <bpmn:sequenceFlow id="Flow_1tz9g6w" name="No" sourceRef="Gateway_0y8j1bb" targetRef="Event_0tlhv9f" />
    <bpmn:sequenceFlow id="Flow_0wgefx9" sourceRef="Gateway_0y8j1bb" targetRef="Gateway_1nihtb8" />
    <bpmn:parallelGateway id="Gateway_1nihtb8">
      <bpmn:incoming>Flow_0wgefx9</bpmn:incoming>
      <bpmn:outgoing>Flow_11rxx1e</bpmn:outgoing>
      <bpmn:outgoing>Flow_0rly60l</bpmn:outgoing>
    </bpmn:parallelGateway>
    <bpmn:task id="Activity_15iycn9" name="Query Against Spearphish 2 Alerts">
      <bpmn:incoming>Flow_11rxx1e</bpmn:incoming>
      <bpmn:outgoing>Flow_1lep759</bpmn:outgoing>
    </bpmn:task>
    <bpmn:sequenceFlow id="Flow_11rxx1e" sourceRef="Gateway_1nihtb8" targetRef="Activity_15iycn9" />
    <bpmn:exclusiveGateway id="Gateway_1k38a2q" name="Did the Office Process Create an exe or DLL?">
      <bpmn:incoming>Flow_0s11qy2</bpmn:incoming>
      <bpmn:incoming>Flow_1lep759</bpmn:incoming>
      <bpmn:outgoing>Flow_05rae4p</bpmn:outgoing>
      <bpmn:outgoing>Flow_0osj3oj</bpmn:outgoing>
    </bpmn:exclusiveGateway>
    <bpmn:sequenceFlow id="Flow_0s11qy2" sourceRef="Activity_1tcctjs" targetRef="Gateway_1k38a2q" />
    <bpmn:sequenceFlow id="Flow_1lep759" sourceRef="Activity_15iycn9" targetRef="Gateway_1k38a2q" />
    <bpmn:endEvent id="Event_1lf8v9c" name="Stop">
      <bpmn:incoming>Flow_05rae4p</bpmn:incoming>
    </bpmn:endEvent>
    <bpmn:sequenceFlow id="Flow_05rae4p" name="No" sourceRef="Gateway_1k38a2q" targetRef="Event_1lf8v9c" />
    <bpmn:task id="Activity_1drq0e2" name="Record Downloaded File Creating Exe (Add 1 Point)">
      <bpmn:incoming>Flow_0osj3oj</bpmn:incoming>
      <bpmn:outgoing>Flow_0sqc3xr</bpmn:outgoing>
    </bpmn:task>
    <bpmn:sequenceFlow id="Flow_0osj3oj" name="Yes" sourceRef="Gateway_1k38a2q" targetRef="Activity_1drq0e2" />
    <bpmn:task id="Activity_12ekoqu" name="Record Office App creating EXE or DLL &#10;(Add 1 Point)">
      <bpmn:incoming>Flow_0rly60l</bpmn:incoming>
      <bpmn:outgoing>Flow_044o2rg</bpmn:outgoing>
    </bpmn:task>
    <bpmn:sequenceFlow id="Flow_0rly60l" sourceRef="Gateway_1nihtb8" targetRef="Activity_12ekoqu" />
    <bpmn:task id="Activity_0t9p0u3" name="Query against Registry Mod Alert">
      <bpmn:incoming>Flow_12198ke</bpmn:incoming>
      <bpmn:outgoing>Flow_193eylw</bpmn:outgoing>
    </bpmn:task>
    <bpmn:sequenceFlow id="Flow_044o2rg" sourceRef="Activity_12ekoqu" targetRef="Gateway_0fsnbj1" />
    <bpmn:task id="Activity_0om5u1d" name="Collect Time, Host, PID, New_Value">
      <bpmn:incoming>Flow_13wfs08</bpmn:incoming>
      <bpmn:outgoing>Flow_1jvyqnb</bpmn:outgoing>
    </bpmn:task>
    <bpmn:sequenceFlow id="Flow_13wfs08" sourceRef="Event_1pp8kgr" targetRef="Activity_0om5u1d" />
    <bpmn:sequenceFlow id="Flow_1jvyqnb" sourceRef="Activity_0om5u1d" targetRef="Activity_10qfxr3" />
    <bpmn:serviceTask id="Activity_10qfxr3" name="Search for PID that created this process">
      <bpmn:incoming>Flow_1jvyqnb</bpmn:incoming>
      <bpmn:outgoing>Flow_08nlduk</bpmn:outgoing>
    </bpmn:serviceTask>
    <bpmn:sequenceFlow id="Flow_08nlduk" sourceRef="Activity_10qfxr3" targetRef="Activity_1b5texm" />
    <bpmn:task id="Activity_1b5texm" name="Query Against Macro Execution Alert">
      <bpmn:incoming>Flow_08nlduk</bpmn:incoming>
      <bpmn:outgoing>Flow_0a1iosz</bpmn:outgoing>
    </bpmn:task>
    <bpmn:exclusiveGateway id="Gateway_15o34c9" name="Did that EXE or DLL spawn a process that modded Registry?">
      <bpmn:incoming>Flow_193eylw</bpmn:incoming>
      <bpmn:incoming>Flow_0a1iosz</bpmn:incoming>
      <bpmn:outgoing>Flow_1p4k292</bpmn:outgoing>
      <bpmn:outgoing>Flow_1qwikvc</bpmn:outgoing>
    </bpmn:exclusiveGateway>
    <bpmn:sequenceFlow id="Flow_193eylw" sourceRef="Activity_0t9p0u3" targetRef="Gateway_15o34c9" />
    <bpmn:sequenceFlow id="Flow_0a1iosz" sourceRef="Activity_1b5texm" targetRef="Gateway_15o34c9" />
    <bpmn:task id="Activity_1kc9aah" name="Record Macro spawned process that modded Reg (Add 1 point)">
      <bpmn:incoming>Flow_1p4k292</bpmn:incoming>
      <bpmn:outgoing>Flow_1f9dl2m</bpmn:outgoing>
    </bpmn:task>
    <bpmn:sequenceFlow id="Flow_1p4k292" name="Yes" sourceRef="Gateway_15o34c9" targetRef="Activity_1kc9aah" />
    <bpmn:sequenceFlow id="Flow_12198ke" sourceRef="Gateway_0fsnbj1" targetRef="Activity_0t9p0u3" />
    <bpmn:parallelGateway id="Gateway_0fsnbj1">
      <bpmn:incoming>Flow_044o2rg</bpmn:incoming>
      <bpmn:outgoing>Flow_12198ke</bpmn:outgoing>
      <bpmn:outgoing>Flow_1m1rrpj</bpmn:outgoing>
    </bpmn:parallelGateway>
    <bpmn:endEvent id="Event_1dnmb4u" name="Stop">
      <bpmn:incoming>Flow_1qwikvc</bpmn:incoming>
    </bpmn:endEvent>
    <bpmn:sequenceFlow id="Flow_1qwikvc" name="No" sourceRef="Gateway_15o34c9" targetRef="Event_1dnmb4u" />
    <bpmn:startEvent id="Event_04ehzao" name="BeaconAlert">
      <bpmn:outgoing>Flow_1mhtid7</bpmn:outgoing>
      <bpmn:signalEventDefinition id="SignalEventDefinition_0ud6gpr" />
    </bpmn:startEvent>
    <bpmn:startEvent id="Event_19ykd0w" name="PrivEsc Alert">
      <bpmn:outgoing>Flow_1p2v8sb</bpmn:outgoing>
      <bpmn:signalEventDefinition id="SignalEventDefinition_1mbsmi1" />
    </bpmn:startEvent>
    <bpmn:task id="Activity_1v9mspd" name="Collect Time, Host, token info, account info">
      <bpmn:incoming>Flow_1p2v8sb</bpmn:incoming>
      <bpmn:outgoing>Flow_1m42qns</bpmn:outgoing>
    </bpmn:task>
    <bpmn:sequenceFlow id="Flow_1p2v8sb" sourceRef="Event_19ykd0w" targetRef="Activity_1v9mspd" />
    <bpmn:sequenceFlow id="Flow_1m42qns" sourceRef="Activity_1v9mspd" targetRef="Gateway_014p4fq" />
    <bpmn:parallelGateway id="Gateway_014p4fq">
      <bpmn:incoming>Flow_1m42qns</bpmn:incoming>
      <bpmn:outgoing>Flow_1ps1s9o</bpmn:outgoing>
      <bpmn:outgoing>Flow_0bjwo6v</bpmn:outgoing>
    </bpmn:parallelGateway>
    <bpmn:sequenceFlow id="Flow_1ps1s9o" sourceRef="Gateway_014p4fq" targetRef="Activity_0if31rc" />
    <bpmn:serviceTask id="Activity_0if31rc" name="Create case/notification to investigate Priv Esc">
      <bpmn:incoming>Flow_1ps1s9o</bpmn:incoming>
      <bpmn:outgoing>Flow_0yo7x12</bpmn:outgoing>
    </bpmn:serviceTask>
    <bpmn:exclusiveGateway id="Gateway_0t9fc7m" name="Was Priv Esc from Non-Normal Activity?">
      <bpmn:incoming>Flow_0yo7x12</bpmn:incoming>
      <bpmn:outgoing>Flow_1u5deps</bpmn:outgoing>
      <bpmn:outgoing>Flow_0ycljw4</bpmn:outgoing>
    </bpmn:exclusiveGateway>
    <bpmn:sequenceFlow id="Flow_0yo7x12" sourceRef="Activity_0if31rc" targetRef="Gateway_0t9fc7m" />
    <bpmn:task id="Activity_0u1v0q6" name="Record Abnormal Priv Esc (Add 1 Point)">
      <bpmn:incoming>Flow_1u5deps</bpmn:incoming>
      <bpmn:outgoing>Flow_1wu1eo2</bpmn:outgoing>
    </bpmn:task>
    <bpmn:sequenceFlow id="Flow_1u5deps" name="Yes" sourceRef="Gateway_0t9fc7m" targetRef="Activity_0u1v0q6" />
    <bpmn:endEvent id="Event_00up263" name="Stop">
      <bpmn:incoming>Flow_0ycljw4</bpmn:incoming>
    </bpmn:endEvent>
    <bpmn:sequenceFlow id="Flow_0ycljw4" name="No/Unknown" sourceRef="Gateway_0t9fc7m" targetRef="Event_00up263" />
    <bpmn:task id="Activity_0ut05wn" name="Query Against DCSync Alerts">
      <bpmn:incoming>Flow_0bjwo6v</bpmn:incoming>
      <bpmn:outgoing>Flow_1f0ru3c</bpmn:outgoing>
    </bpmn:task>
    <bpmn:sequenceFlow id="Flow_0bjwo6v" sourceRef="Gateway_014p4fq" targetRef="Activity_0ut05wn" />
    <bpmn:task id="Activity_1x7a8ee" name="Collect Time, account requesting&#10;Host sending, traffic to DC&#10;(Multiple Logs)">
      <bpmn:incoming>Flow_1lk5v0x</bpmn:incoming>
      <bpmn:outgoing>Flow_1y5nhb8</bpmn:outgoing>
    </bpmn:task>
    <bpmn:sequenceFlow id="Flow_1lk5v0x" sourceRef="Event_0lavc91" targetRef="Activity_1x7a8ee" />
    <bpmn:sequenceFlow id="Flow_1y5nhb8" sourceRef="Activity_1x7a8ee" targetRef="Gateway_0w9iplv" />
    <bpmn:exclusiveGateway id="Gateway_0w9iplv" name="Was request from abnormal time/place?">
      <bpmn:incoming>Flow_1y5nhb8</bpmn:incoming>
      <bpmn:outgoing>Flow_0x26xca</bpmn:outgoing>
      <bpmn:outgoing>Flow_097e3ma</bpmn:outgoing>
    </bpmn:exclusiveGateway>
    <bpmn:sequenceFlow id="Flow_0x26xca" name="Yes" sourceRef="Gateway_0w9iplv" targetRef="Gateway_1wnimx5" />
    <bpmn:parallelGateway id="Gateway_1wnimx5">
      <bpmn:incoming>Flow_0x26xca</bpmn:incoming>
      <bpmn:outgoing>Flow_12gzzo8</bpmn:outgoing>
      <bpmn:outgoing>Flow_05gxnsl</bpmn:outgoing>
      <bpmn:outgoing>Flow_1ubbuku</bpmn:outgoing>
    </bpmn:parallelGateway>
    <bpmn:endEvent id="Event_1creujc" name="Stop">
      <bpmn:incoming>Flow_097e3ma</bpmn:incoming>
    </bpmn:endEvent>
    <bpmn:sequenceFlow id="Flow_097e3ma" name="No" sourceRef="Gateway_0w9iplv" targetRef="Event_1creujc" />
    <bpmn:task id="Activity_13ow8ar" name="Record Potential Hash compromise (Add 1 Point)">
      <bpmn:incoming>Flow_12gzzo8</bpmn:incoming>
      <bpmn:outgoing>Flow_1o5y0ou</bpmn:outgoing>
    </bpmn:task>
    <bpmn:sequenceFlow id="Flow_12gzzo8" sourceRef="Gateway_1wnimx5" targetRef="Activity_13ow8ar" />
    <bpmn:sequenceFlow id="Flow_05gxnsl" sourceRef="Gateway_1wnimx5" targetRef="Activity_1hf3gwc" />
    <bpmn:serviceTask id="Activity_1hf3gwc" name="Pull User ID and Hashes from request">
      <bpmn:incoming>Flow_05gxnsl</bpmn:incoming>
      <bpmn:outgoing>Flow_1gw5xl5</bpmn:outgoing>
    </bpmn:serviceTask>
    <bpmn:task id="Activity_0t5hj9f" name="Query against PrivEsc Alerts">
      <bpmn:incoming>Flow_1gw5xl5</bpmn:incoming>
      <bpmn:outgoing>Flow_1c2aobq</bpmn:outgoing>
    </bpmn:task>
    <bpmn:sequenceFlow id="Flow_1gw5xl5" sourceRef="Activity_1hf3gwc" targetRef="Activity_0t5hj9f" />
    <bpmn:exclusiveGateway id="Gateway_07bherc" name="Did the host with Priv Escalation run DCsync?">
      <bpmn:incoming>Flow_1c2aobq</bpmn:incoming>
      <bpmn:incoming>Flow_1f0ru3c</bpmn:incoming>
      <bpmn:outgoing>Flow_0okcc4z</bpmn:outgoing>
      <bpmn:outgoing>Flow_0ilr85g</bpmn:outgoing>
    </bpmn:exclusiveGateway>
    <bpmn:sequenceFlow id="Flow_1c2aobq" sourceRef="Activity_0t5hj9f" targetRef="Gateway_07bherc" />
    <bpmn:sequenceFlow id="Flow_1f0ru3c" sourceRef="Activity_0ut05wn" targetRef="Gateway_07bherc" />
    <bpmn:task id="Activity_1rwrm8y" name="Record PrivEsc Account accessing Hashes (add 1 point)">
      <bpmn:incoming>Flow_0okcc4z</bpmn:incoming>
      <bpmn:outgoing>Flow_1wx22pe</bpmn:outgoing>
    </bpmn:task>
    <bpmn:sequenceFlow id="Flow_0okcc4z" name="Yes" sourceRef="Gateway_07bherc" targetRef="Activity_1rwrm8y" />
    <bpmn:task id="Activity_0jzgmwj" name="Collect Internal and External Host Info">
      <bpmn:incoming>Flow_1mhtid7</bpmn:incoming>
      <bpmn:outgoing>Flow_0gs7prb</bpmn:outgoing>
    </bpmn:task>
    <bpmn:sequenceFlow id="Flow_1mhtid7" sourceRef="Event_04ehzao" targetRef="Activity_0jzgmwj" />
    <bpmn:sequenceFlow id="Flow_0gs7prb" sourceRef="Activity_0jzgmwj" targetRef="Gateway_1slz29c" />
    <bpmn:task id="Activity_1rjxr4e" name="Record Potential Beaconing (Add 1 point)">
      <bpmn:incoming>Flow_0tv084j</bpmn:incoming>
      <bpmn:outgoing>Flow_1kmdjhb</bpmn:outgoing>
    </bpmn:task>
    <bpmn:parallelGateway id="Gateway_1slz29c">
      <bpmn:incoming>Flow_0gs7prb</bpmn:incoming>
      <bpmn:outgoing>Flow_0tv084j</bpmn:outgoing>
      <bpmn:outgoing>Flow_0p7f7t3</bpmn:outgoing>
    </bpmn:parallelGateway>
    <bpmn:sequenceFlow id="Flow_0tv084j" sourceRef="Gateway_1slz29c" targetRef="Activity_1rjxr4e" />
    <bpmn:task id="Activity_0jva4bo" name="Query against other alerts">
      <bpmn:incoming>Flow_0p7f7t3</bpmn:incoming>
      <bpmn:outgoing>Flow_1oqoezn</bpmn:outgoing>
    </bpmn:task>
    <bpmn:sequenceFlow id="Flow_0p7f7t3" sourceRef="Gateway_1slz29c" targetRef="Activity_0jva4bo" />
    <bpmn:exclusiveGateway id="Gateway_1glkdnb" name="Has Internal host been associated with other alerts recently?">
      <bpmn:incoming>Flow_1oqoezn</bpmn:incoming>
      <bpmn:outgoing>Flow_1vokk4z</bpmn:outgoing>
      <bpmn:outgoing>Flow_1bbb7kd</bpmn:outgoing>
    </bpmn:exclusiveGateway>
    <bpmn:sequenceFlow id="Flow_1oqoezn" sourceRef="Activity_0jva4bo" targetRef="Gateway_1glkdnb" />
    <bpmn:task id="Activity_0lk86yf" name="Record Beaconing Associated with other behaviors (add 1 point)">
      <bpmn:incoming>Flow_1vokk4z</bpmn:incoming>
      <bpmn:outgoing>Flow_1414l69</bpmn:outgoing>
    </bpmn:task>
    <bpmn:sequenceFlow id="Flow_1vokk4z" name="Yes" sourceRef="Gateway_1glkdnb" targetRef="Activity_0lk86yf" />
    <bpmn:endEvent id="Event_0pckj4u" name="Stop">
      <bpmn:incoming>Flow_1bbb7kd</bpmn:incoming>
    </bpmn:endEvent>
    <bpmn:sequenceFlow id="Flow_1bbb7kd" name="No" sourceRef="Gateway_1glkdnb" targetRef="Event_0pckj4u" />
    <bpmn:task id="Activity_03t2q8t" name="Collect time, host, user account associated with exfil">
      <bpmn:incoming>Flow_0dl9ybr</bpmn:incoming>
      <bpmn:outgoing>Flow_1ck8pj8</bpmn:outgoing>
    </bpmn:task>
    <bpmn:sequenceFlow id="Flow_0dl9ybr" sourceRef="Event_1r7y8v8" targetRef="Activity_03t2q8t" />
    <bpmn:sequenceFlow id="Flow_1ck8pj8" sourceRef="Activity_03t2q8t" targetRef="Gateway_1dfcsc1" />
    <bpmn:parallelGateway id="Gateway_1dfcsc1">
      <bpmn:incoming>Flow_1ck8pj8</bpmn:incoming>
      <bpmn:outgoing>Flow_1t1abd5</bpmn:outgoing>
      <bpmn:outgoing>Flow_1xq33v7</bpmn:outgoing>
      <bpmn:outgoing>Flow_150aw2w</bpmn:outgoing>
    </bpmn:parallelGateway>
    <bpmn:task id="Activity_1rnp8h8" name="Record potential Exfil (Add 1 Point)">
      <bpmn:incoming>Flow_1xq33v7</bpmn:incoming>
      <bpmn:outgoing>Flow_0ceai1o</bpmn:outgoing>
    </bpmn:task>
    <bpmn:task id="Activity_1qbhliu" name="Query Against other alerts">
      <bpmn:incoming>Flow_1t1abd5</bpmn:incoming>
      <bpmn:outgoing>Flow_0jd7iml</bpmn:outgoing>
    </bpmn:task>
    <bpmn:sequenceFlow id="Flow_1t1abd5" sourceRef="Gateway_1dfcsc1" targetRef="Activity_1qbhliu" />
    <bpmn:exclusiveGateway id="Gateway_0w0j02k" name="Is host or User account associated with other alerts recently?">
      <bpmn:incoming>Flow_0jd7iml</bpmn:incoming>
      <bpmn:outgoing>Flow_0m5h15c</bpmn:outgoing>
      <bpmn:outgoing>Flow_0hwtgmc</bpmn:outgoing>
    </bpmn:exclusiveGateway>
    <bpmn:sequenceFlow id="Flow_0jd7iml" sourceRef="Activity_1qbhliu" targetRef="Gateway_0w0j02k" />
    <bpmn:task id="Activity_1etelb4" name="Record Exfil associated with other activity (Add 1 point)">
      <bpmn:incoming>Flow_0m5h15c</bpmn:incoming>
      <bpmn:outgoing>Flow_130ovwm</bpmn:outgoing>
    </bpmn:task>
    <bpmn:sequenceFlow id="Flow_0m5h15c" name="Yes" sourceRef="Gateway_0w0j02k" targetRef="Activity_1etelb4" />
    <bpmn:endEvent id="Event_17g7vh0" name="Stop">
      <bpmn:incoming>Flow_0hwtgmc</bpmn:incoming>
    </bpmn:endEvent>
    <bpmn:sequenceFlow id="Flow_0hwtgmc" name="No" sourceRef="Gateway_0w0j02k" targetRef="Event_17g7vh0" />
    <bpmn:task id="Activity_1imths9" name="Tally Points">
      <bpmn:incoming>Flow_0vee046</bpmn:incoming>
      <bpmn:incoming>Flow_0sqc3xr</bpmn:incoming>
      <bpmn:incoming>Flow_1m1rrpj</bpmn:incoming>
      <bpmn:incoming>Flow_1f9dl2m</bpmn:incoming>
      <bpmn:incoming>Flow_1o5y0ou</bpmn:incoming>
      <bpmn:incoming>Flow_1wx22pe</bpmn:incoming>
      <bpmn:incoming>Flow_1wu1eo2</bpmn:incoming>
      <bpmn:incoming>Flow_1kmdjhb</bpmn:incoming>
      <bpmn:incoming>Flow_1414l69</bpmn:incoming>
      <bpmn:incoming>Flow_0ceai1o</bpmn:incoming>
      <bpmn:incoming>Flow_130ovwm</bpmn:incoming>
      <bpmn:incoming>Flow_0q6h3j9</bpmn:incoming>
      <bpmn:incoming>Flow_1nyniw3</bpmn:incoming>
      <bpmn:outgoing>Flow_1gvq9cp</bpmn:outgoing>
    </bpmn:task>
    <bpmn:sequenceFlow id="Flow_0vee046" sourceRef="Activity_1tw9hbu" targetRef="Activity_1imths9" />
    <bpmn:sequenceFlow id="Flow_0sqc3xr" sourceRef="Activity_1drq0e2" targetRef="Activity_1imths9" />
    <bpmn:sequenceFlow id="Flow_1m1rrpj" sourceRef="Gateway_0fsnbj1" targetRef="Activity_1imths9" />
    <bpmn:sequenceFlow id="Flow_1f9dl2m" sourceRef="Activity_1kc9aah" targetRef="Activity_1imths9" />
    <bpmn:sequenceFlow id="Flow_1o5y0ou" sourceRef="Activity_13ow8ar" targetRef="Activity_1imths9" />
    <bpmn:sequenceFlow id="Flow_1wx22pe" sourceRef="Activity_1rwrm8y" targetRef="Activity_1imths9" />
    <bpmn:sequenceFlow id="Flow_1wu1eo2" sourceRef="Activity_0u1v0q6" targetRef="Activity_1imths9" />
    <bpmn:sequenceFlow id="Flow_1kmdjhb" sourceRef="Activity_1rjxr4e" targetRef="Activity_1imths9" />
    <bpmn:sequenceFlow id="Flow_1414l69" sourceRef="Activity_0lk86yf" targetRef="Activity_1imths9" />
    <bpmn:sequenceFlow id="Flow_0ceai1o" sourceRef="Activity_1rnp8h8" targetRef="Activity_1imths9" />
    <bpmn:sequenceFlow id="Flow_130ovwm" sourceRef="Activity_1etelb4" targetRef="Activity_1imths9" />
    <bpmn:sequenceFlow id="Flow_1gvq9cp" sourceRef="Activity_1imths9" targetRef="Gateway_0r8ba09" />
    <bpmn:inclusiveGateway id="Gateway_0r8ba09" name="Set Correlation for Behavior Set based on Point Tally">
      <bpmn:incoming>Flow_1gvq9cp</bpmn:incoming>
      <bpmn:outgoing>Flow_1y2k0v3</bpmn:outgoing>
      <bpmn:outgoing>Flow_0g3fytd</bpmn:outgoing>
      <bpmn:outgoing>Flow_0jpn8j2</bpmn:outgoing>
    </bpmn:inclusiveGateway>
    <bpmn:task id="Activity_17m8478" name="Set Correlation to Medium">
      <bpmn:incoming>Flow_1y2k0v3</bpmn:incoming>
      <bpmn:outgoing>Flow_174u7s2</bpmn:outgoing>
    </bpmn:task>
    <bpmn:sequenceFlow id="Flow_1y2k0v3" name="Between 3 and 8 points" sourceRef="Gateway_0r8ba09" targetRef="Activity_17m8478" />
    <bpmn:task id="Activity_100m1uf" name="Set Correlation to Low">
      <bpmn:incoming>Flow_0g3fytd</bpmn:incoming>
      <bpmn:outgoing>Flow_1azis9b</bpmn:outgoing>
    </bpmn:task>
    <bpmn:sequenceFlow id="Flow_0g3fytd" name="Between 0 and 3 points" sourceRef="Gateway_0r8ba09" targetRef="Activity_100m1uf" />
    <bpmn:task id="Activity_14pujso" name="Set Correlation to High">
      <bpmn:incoming>Flow_0jpn8j2</bpmn:incoming>
      <bpmn:outgoing>Flow_1g4cx8z</bpmn:outgoing>
    </bpmn:task>
    <bpmn:sequenceFlow id="Flow_0jpn8j2" name="More than 8 points" sourceRef="Gateway_0r8ba09" targetRef="Activity_14pujso" />
    <bpmn:sequenceFlow id="Flow_174u7s2" sourceRef="Activity_17m8478" targetRef="Activity_13spve3" />
    <bpmn:serviceTask id="Activity_13spve3" name="Generate Correlated Behavior Notification">
      <bpmn:incoming>Flow_174u7s2</bpmn:incoming>
      <bpmn:incoming>Flow_1azis9b</bpmn:incoming>
      <bpmn:incoming>Flow_1g4cx8z</bpmn:incoming>
      <bpmn:outgoing>Flow_078v55k</bpmn:outgoing>
    </bpmn:serviceTask>
    <bpmn:sequenceFlow id="Flow_1azis9b" sourceRef="Activity_100m1uf" targetRef="Activity_13spve3" />
    <bpmn:sequenceFlow id="Flow_1g4cx8z" sourceRef="Activity_14pujso" targetRef="Activity_13spve3" />
    <bpmn:endEvent id="Event_0b9snr5" name="Stop">
      <bpmn:incoming>Flow_078v55k</bpmn:incoming>
    </bpmn:endEvent>
    <bpmn:sequenceFlow id="Flow_078v55k" sourceRef="Activity_13spve3" targetRef="Event_0b9snr5" />
    <bpmn:startEvent id="Event_0twz620" name="LateralMovement Alert">
      <bpmn:outgoing>Flow_0rsaukt</bpmn:outgoing>
      <bpmn:signalEventDefinition id="SignalEventDefinition_1o2rcfk" />
    </bpmn:startEvent>
    <bpmn:task id="Activity_1qyqzwf" name="Collect time, source, and destination for movement">
      <bpmn:incoming>Flow_0rsaukt</bpmn:incoming>
      <bpmn:outgoing>Flow_02gs0uo</bpmn:outgoing>
    </bpmn:task>
    <bpmn:sequenceFlow id="Flow_0rsaukt" sourceRef="Event_0twz620" targetRef="Activity_1qyqzwf" />
    <bpmn:sequenceFlow id="Flow_02gs0uo" sourceRef="Activity_1qyqzwf" targetRef="Gateway_1tq5o60" />
    <bpmn:parallelGateway id="Gateway_1tq5o60">
      <bpmn:incoming>Flow_02gs0uo</bpmn:incoming>
      <bpmn:outgoing>Flow_0rz6ot9</bpmn:outgoing>
      <bpmn:outgoing>Flow_10jspnp</bpmn:outgoing>
    </bpmn:parallelGateway>
    <bpmn:task id="Activity_0t6hbzp" name="Query Against DC Sync Alerts">
      <bpmn:incoming>Flow_0rz6ot9</bpmn:incoming>
      <bpmn:outgoing>Flow_1dl0t4i</bpmn:outgoing>
    </bpmn:task>
    <bpmn:sequenceFlow id="Flow_0rz6ot9" sourceRef="Gateway_1tq5o60" targetRef="Activity_0t6hbzp" />
    <bpmn:exclusiveGateway id="Gateway_18uidys" name="Is the source of Lateral Movement the Host conducting DC Sync?">
      <bpmn:incoming>Flow_1dl0t4i</bpmn:incoming>
      <bpmn:incoming>Flow_1m57k60</bpmn:incoming>
      <bpmn:outgoing>Flow_0scl6kt</bpmn:outgoing>
      <bpmn:outgoing>Flow_0yt4o87</bpmn:outgoing>
    </bpmn:exclusiveGateway>
    <bpmn:sequenceFlow id="Flow_1dl0t4i" sourceRef="Activity_0t6hbzp" targetRef="Gateway_18uidys" />
    <bpmn:task id="Activity_1qqcd5n" name="Query Against Exfil Alerts">
      <bpmn:incoming>Flow_10jspnp</bpmn:incoming>
      <bpmn:outgoing>Flow_0vjhroi</bpmn:outgoing>
    </bpmn:task>
    <bpmn:sequenceFlow id="Flow_10jspnp" sourceRef="Gateway_1tq5o60" targetRef="Activity_1qqcd5n" />
    <bpmn:task id="Activity_0rv3anq" name="Query Against Lateral Movement Alerts">
      <bpmn:incoming>Flow_1ubbuku</bpmn:incoming>
      <bpmn:outgoing>Flow_1m57k60</bpmn:outgoing>
    </bpmn:task>
    <bpmn:sequenceFlow id="Flow_1ubbuku" sourceRef="Gateway_1wnimx5" targetRef="Activity_0rv3anq" />
    <bpmn:sequenceFlow id="Flow_1m57k60" sourceRef="Activity_0rv3anq" targetRef="Gateway_18uidys" />
    <bpmn:task id="Activity_01ai6kd" name="Record DC Sync led to Lateral Movement (Add 1 Point)">
      <bpmn:incoming>Flow_0scl6kt</bpmn:incoming>
      <bpmn:outgoing>Flow_0q6h3j9</bpmn:outgoing>
    </bpmn:task>
    <bpmn:sequenceFlow id="Flow_0scl6kt" name="Yes" sourceRef="Gateway_18uidys" targetRef="Activity_01ai6kd" />
    <bpmn:sequenceFlow id="Flow_0q6h3j9" sourceRef="Activity_01ai6kd" targetRef="Activity_1imths9" />
    <bpmn:endEvent id="Event_125gwjb" name="Stop">
      <bpmn:incoming>Flow_0yt4o87</bpmn:incoming>
    </bpmn:endEvent>
    <bpmn:sequenceFlow id="Flow_0yt4o87" name="No" sourceRef="Gateway_18uidys" targetRef="Event_125gwjb" />
    <bpmn:exclusiveGateway id="Gateway_0gy54ty" name="Is Destination where Exfil occurs?">
      <bpmn:incoming>Flow_0vjhroi</bpmn:incoming>
      <bpmn:incoming>Flow_0em1esl</bpmn:incoming>
      <bpmn:outgoing>Flow_1cfx2p8</bpmn:outgoing>
      <bpmn:outgoing>Flow_0bk8j9f</bpmn:outgoing>
    </bpmn:exclusiveGateway>
    <bpmn:sequenceFlow id="Flow_0vjhroi" sourceRef="Activity_1qqcd5n" targetRef="Gateway_0gy54ty" />
    <bpmn:task id="Activity_0cl648e" name="Record Lat Move Led to Exfil (Add 1 Point)">
      <bpmn:incoming>Flow_1cfx2p8</bpmn:incoming>
      <bpmn:outgoing>Flow_1nyniw3</bpmn:outgoing>
    </bpmn:task>
    <bpmn:sequenceFlow id="Flow_1cfx2p8" name="Yes" sourceRef="Gateway_0gy54ty" targetRef="Activity_0cl648e" />
    <bpmn:sequenceFlow id="Flow_1nyniw3" sourceRef="Activity_0cl648e" targetRef="Activity_1imths9" />
    <bpmn:task id="Activity_0eafknt" name="Query Against Lateral Movement Alerts">
      <bpmn:incoming>Flow_150aw2w</bpmn:incoming>
      <bpmn:outgoing>Flow_0em1esl</bpmn:outgoing>
    </bpmn:task>
    <bpmn:sequenceFlow id="Flow_0em1esl" sourceRef="Activity_0eafknt" targetRef="Gateway_0gy54ty" />
    <bpmn:endEvent id="Event_1eln72h" name="Stop">
      <bpmn:incoming>Flow_0bk8j9f</bpmn:incoming>
    </bpmn:endEvent>
    <bpmn:sequenceFlow id="Flow_0bk8j9f" name="No" sourceRef="Gateway_0gy54ty" targetRef="Event_1eln72h" />
    <bpmn:sequenceFlow id="Flow_1xq33v7" sourceRef="Gateway_1dfcsc1" targetRef="Activity_1rnp8h8" />
    <bpmn:sequenceFlow id="Flow_150aw2w" sourceRef="Gateway_1dfcsc1" targetRef="Activity_0eafknt" />
    <bpmn:endEvent id="Event_1fc99py" name="Stop">
      <bpmn:incoming>Flow_0ilr85g</bpmn:incoming>
    </bpmn:endEvent>
    <bpmn:sequenceFlow id="Flow_0ilr85g" name="No" sourceRef="Gateway_07bherc" targetRef="Event_1fc99py" />
    <bpmn:textAnnotation id="TextAnnotation_0i43w39">
      <bpmn:text>Check internal host against Spearphish, Macro, Registry Mod, PrivEsc, DCSync, and Lateral Movement</bpmn:text>
    </bpmn:textAnnotation>
    <bpmn:association id="Association_15rpsk0" sourceRef="Activity_0jva4bo" targetRef="TextAnnotation_0i43w39" />
  </bpmn:process>
  <bpmndi:BPMNDiagram id="BPMNDiagram_1">
    <bpmndi:BPMNPlane id="BPMNPlane_1" bpmnElement="Process_1qnegtj">
      <bpmndi:BPMNShape id="Event_1w5iqk6_di" bpmnElement="StartEvent_1" bioc:stroke="rgb(67, 160, 71)" bioc:fill="rgb(200, 230, 201)">
        <dc:Bounds x="172" y="152" width="36" height="36" />
        <bpmndi:BPMNLabel>
          <dc:Bounds x="158" y="195" width="65" height="40" />
        </bpmndi:BPMNLabel>
      </bpmndi:BPMNShape>
      <bpmndi:BPMNShape id="Event_144r6zj_di" bpmnElement="Event_144r6zj" bioc:stroke="rgb(67, 160, 71)" bioc:fill="rgb(200, 230, 201)">
        <dc:Bounds x="172" y="609" width="36" height="36" />
        <bpmndi:BPMNLabel>
          <dc:Bounds x="154" y="652" width="74" height="27" />
        </bpmndi:BPMNLabel>
      </bpmndi:BPMNShape>
      <bpmndi:BPMNShape id="Event_130qlt1_di" bpmnElement="Event_130qlt1" bioc:stroke="rgb(67, 160, 71)" bioc:fill="rgb(200, 230, 201)">
        <dc:Bounds x="172" y="432" width="36" height="36" />
        <bpmndi:BPMNLabel>
          <dc:Bounds x="158" y="475" width="65" height="40" />
        </bpmndi:BPMNLabel>
      </bpmndi:BPMNShape>
      <bpmndi:BPMNShape id="Event_1pp8kgr_di" bpmnElement="Event_1pp8kgr" bioc:stroke="rgb(67, 160, 71)" bioc:fill="rgb(200, 230, 201)">
        <dc:Bounds x="172" y="802" width="36" height="36" />
        <bpmndi:BPMNLabel>
          <dc:Bounds x="159" y="845" width="65" height="27" />
        </bpmndi:BPMNLabel>
      </bpmndi:BPMNShape>
      <bpmndi:BPMNShape id="Event_0lavc91_di" bpmnElement="Event_0lavc91" bioc:stroke="rgb(67, 160, 71)" bioc:fill="rgb(200, 230, 201)">
        <dc:Bounds x="172" y="1272" width="36" height="36" />
        <bpmndi:BPMNLabel>
          <dc:Bounds x="158" y="1315" width="67" height="14" />
        </bpmndi:BPMNLabel>
      </bpmndi:BPMNShape>
      <bpmndi:BPMNShape id="Event_1r7y8v8_di" bpmnElement="Event_1r7y8v8" bioc:stroke="rgb(67, 160, 71)" bioc:fill="rgb(200, 230, 201)">
        <dc:Bounds x="182" y="2082" width="36" height="36" />
        <bpmndi:BPMNLabel>
          <dc:Bounds x="179" y="2125" width="47" height="14" />
        </bpmndi:BPMNLabel>
      </bpmndi:BPMNShape>
      <bpmndi:BPMNShape id="Activity_1f23h1o_di" bpmnElement="Activity_0t9phcm">
        <dc:Bounds x="250" y="130" width="100" height="80" />
      </bpmndi:BPMNShape>
      <bpmndi:BPMNShape id="Activity_0ptc937_di" bpmnElement="Activity_0ptc937">
        <dc:Bounds x="480" y="130" width="100" height="80" />
      </bpmndi:BPMNShape>
      <bpmndi:BPMNShape id="Activity_1qdssbv_di" bpmnElement="Activity_1qdssbv">
        <dc:Bounds x="260" y="410" width="100" height="80" />
      </bpmndi:BPMNShape>
      <bpmndi:BPMNShape id="Gateway_17ffsxe_di" bpmnElement="Gateway_17ffsxe" isMarkerVisible="true">
        <dc:Bounds x="625" y="145" width="50" height="50" />
        <bpmndi:BPMNLabel>
          <dc:Bounds x="608" y="77" width="83" height="66" />
        </bpmndi:BPMNLabel>
      </bpmndi:BPMNShape>
      <bpmndi:BPMNShape id="Event_0j8xdvr_di" bpmnElement="Event_0j8xdvr" bioc:stroke="rgb(229, 57, 53)" bioc:fill="rgb(255, 205, 210)">
        <dc:Bounds x="782" y="222" width="36" height="36" />
        <bpmndi:BPMNLabel>
          <dc:Bounds x="789" y="265" width="23" height="14" />
        </bpmndi:BPMNLabel>
      </bpmndi:BPMNShape>
      <bpmndi:BPMNShape id="Gateway_0rbdxp2_di" bpmnElement="Gateway_1f34cp4">
        <dc:Bounds x="605" y="425" width="50" height="50" />
      </bpmndi:BPMNShape>
      <bpmndi:BPMNShape id="Activity_0j861nm_di" bpmnElement="Activity_0j861nm">
        <dc:Bounds x="580" y="310" width="100" height="80" />
      </bpmndi:BPMNShape>
      <bpmndi:BPMNShape id="Activity_1tw9hbu_di" bpmnElement="Activity_1tw9hbu" bioc:stroke="rgb(30, 136, 229)" bioc:fill="rgb(187, 222, 251)">
        <dc:Bounds x="750" y="130" width="100" height="80" />
      </bpmndi:BPMNShape>
      <bpmndi:BPMNShape id="Activity_1fg10zt_di" bpmnElement="Activity_1fg10zt">
        <dc:Bounds x="260" y="587" width="100" height="80" />
      </bpmndi:BPMNShape>
      <bpmndi:BPMNShape id="Activity_1tcctjs_di" bpmnElement="Activity_1tcctjs">
        <dc:Bounds x="740" y="410" width="100" height="80" />
      </bpmndi:BPMNShape>
      <bpmndi:BPMNShape id="Gateway_0y8j1bb_di" bpmnElement="Gateway_0y8j1bb" isMarkerVisible="true">
        <dc:Bounds x="415" y="602" width="50" height="50" />
        <bpmndi:BPMNLabel>
          <dc:Bounds x="395" y="527" width="89" height="66" />
        </bpmndi:BPMNLabel>
      </bpmndi:BPMNShape>
      <bpmndi:BPMNShape id="Event_0tlhv9f_di" bpmnElement="Event_0tlhv9f" bioc:stroke="rgb(229, 57, 53)" bioc:fill="rgb(255, 205, 210)">
        <dc:Bounds x="522" y="692" width="36" height="36" />
        <bpmndi:BPMNLabel>
          <dc:Bounds x="529" y="735" width="23" height="14" />
        </bpmndi:BPMNLabel>
      </bpmndi:BPMNShape>
      <bpmndi:BPMNShape id="Gateway_0bbry8h_di" bpmnElement="Gateway_1nihtb8">
        <dc:Bounds x="605" y="602" width="50" height="50" />
      </bpmndi:BPMNShape>
      <bpmndi:BPMNShape id="Activity_15iycn9_di" bpmnElement="Activity_15iycn9">
        <dc:Bounds x="740" y="587" width="100" height="80" />
      </bpmndi:BPMNShape>
      <bpmndi:BPMNShape id="Gateway_1k38a2q_di" bpmnElement="Gateway_1k38a2q" isMarkerVisible="true">
        <dc:Bounds x="925" y="425" width="50" height="50" />
        <bpmndi:BPMNLabel>
          <dc:Bounds x="912" y="380" width="76" height="40" />
        </bpmndi:BPMNLabel>
      </bpmndi:BPMNShape>
      <bpmndi:BPMNShape id="Event_1lf8v9c_di" bpmnElement="Event_1lf8v9c" bioc:stroke="rgb(229, 57, 53)" bioc:fill="rgb(255, 205, 210)">
        <dc:Bounds x="1012" y="492" width="36" height="36" />
        <bpmndi:BPMNLabel>
          <dc:Bounds x="1019" y="535" width="23" height="14" />
        </bpmndi:BPMNLabel>
      </bpmndi:BPMNShape>
      <bpmndi:BPMNShape id="Activity_1drq0e2_di" bpmnElement="Activity_1drq0e2" bioc:stroke="rgb(30, 136, 229)" bioc:fill="rgb(187, 222, 251)">
        <dc:Bounds x="1150" y="410" width="100" height="80" />
      </bpmndi:BPMNShape>
      <bpmndi:BPMNShape id="Activity_12ekoqu_di" bpmnElement="Activity_12ekoqu" bioc:stroke="rgb(30, 136, 229)" bioc:fill="rgb(187, 222, 251)">
        <dc:Bounds x="950" y="587" width="100" height="80" />
      </bpmndi:BPMNShape>
      <bpmndi:BPMNShape id="Activity_0t9p0u3_di" bpmnElement="Activity_0t9p0u3">
        <dc:Bounds x="1150" y="587" width="100" height="80" />
      </bpmndi:BPMNShape>
      <bpmndi:BPMNShape id="Activity_0om5u1d_di" bpmnElement="Activity_0om5u1d">
        <dc:Bounds x="260" y="780" width="100" height="80" />
      </bpmndi:BPMNShape>
      <bpmndi:BPMNShape id="Activity_01iydso_di" bpmnElement="Activity_10qfxr3">
        <dc:Bounds x="420" y="780" width="100" height="80" />
      </bpmndi:BPMNShape>
      <bpmndi:BPMNShape id="Activity_1b5texm_di" bpmnElement="Activity_1b5texm">
        <dc:Bounds x="700" y="780" width="100" height="80" />
      </bpmndi:BPMNShape>
      <bpmndi:BPMNShape id="Gateway_15o34c9_di" bpmnElement="Gateway_15o34c9" isMarkerVisible="true">
        <dc:Bounds x="1305" y="602" width="50" height="50" />
        <bpmndi:BPMNLabel>
          <dc:Bounds x="1285" y="543" width="90" height="53" />
        </bpmndi:BPMNLabel>
      </bpmndi:BPMNShape>
      <bpmndi:BPMNShape id="Activity_1kc9aah_di" bpmnElement="Activity_1kc9aah" bioc:stroke="rgb(30, 136, 229)" bioc:fill="rgb(187, 222, 251)">
        <dc:Bounds x="1410" y="587" width="100" height="80" />
      </bpmndi:BPMNShape>
      <bpmndi:BPMNShape id="Gateway_1o85zm8_di" bpmnElement="Gateway_0fsnbj1">
        <dc:Bounds x="1075" y="602" width="50" height="50" />
      </bpmndi:BPMNShape>
      <bpmndi:BPMNShape id="Event_1dnmb4u_di" bpmnElement="Event_1dnmb4u" bioc:stroke="rgb(229, 57, 53)" bioc:fill="rgb(255, 205, 210)">
        <dc:Bounds x="1442" y="682" width="36" height="36" />
        <bpmndi:BPMNLabel>
          <dc:Bounds x="1449" y="725" width="23" height="14" />
        </bpmndi:BPMNLabel>
      </bpmndi:BPMNShape>
      <bpmndi:BPMNShape id="Event_04ehzao_di" bpmnElement="Event_04ehzao" bioc:stroke="rgb(67, 160, 71)" bioc:fill="rgb(200, 230, 201)">
        <dc:Bounds x="182" y="2402" width="36" height="36" />
        <bpmndi:BPMNLabel>
          <dc:Bounds x="172" y="2445" width="60" height="14" />
        </bpmndi:BPMNLabel>
      </bpmndi:BPMNShape>
      <bpmndi:BPMNShape id="Event_19ykd0w_di" bpmnElement="Event_19ykd0w" bioc:stroke="rgb(67, 160, 71)" bioc:fill="rgb(200, 230, 201)">
        <dc:Bounds x="172" y="962" width="36" height="36" />
        <bpmndi:BPMNLabel>
          <dc:Bounds x="160" y="1005" width="63" height="14" />
        </bpmndi:BPMNLabel>
      </bpmndi:BPMNShape>
      <bpmndi:BPMNShape id="Activity_1v9mspd_di" bpmnElement="Activity_1v9mspd">
        <dc:Bounds x="260" y="940" width="100" height="80" />
      </bpmndi:BPMNShape>
      <bpmndi:BPMNShape id="Gateway_1nkfi4e_di" bpmnElement="Gateway_014p4fq">
        <dc:Bounds x="445" y="955" width="50" height="50" />
      </bpmndi:BPMNShape>
      <bpmndi:BPMNShape id="Activity_12vlho8_di" bpmnElement="Activity_0if31rc">
        <dc:Bounds x="560" y="940" width="100" height="80" />
      </bpmndi:BPMNShape>
      <bpmndi:BPMNShape id="Gateway_0t9fc7m_di" bpmnElement="Gateway_0t9fc7m" isMarkerVisible="true">
        <dc:Bounds x="745" y="955" width="50" height="50" />
        <bpmndi:BPMNLabel>
          <dc:Bounds x="727.5" y="905" width="85" height="40" />
        </bpmndi:BPMNLabel>
      </bpmndi:BPMNShape>
      <bpmndi:BPMNShape id="Activity_0u1v0q6_di" bpmnElement="Activity_0u1v0q6" bioc:stroke="rgb(30, 136, 229)" bioc:fill="rgb(187, 222, 251)">
        <dc:Bounds x="930" y="940" width="100" height="80" />
      </bpmndi:BPMNShape>
      <bpmndi:BPMNShape id="Event_00up263_di" bpmnElement="Event_00up263" bioc:stroke="rgb(229, 57, 53)" bioc:fill="rgb(255, 205, 210)">
        <dc:Bounds x="892" y="1052" width="36" height="36" />
        <bpmndi:BPMNLabel>
          <dc:Bounds x="899" y="1095" width="23" height="14" />
        </bpmndi:BPMNLabel>
      </bpmndi:BPMNShape>
      <bpmndi:BPMNShape id="Activity_0ut05wn_di" bpmnElement="Activity_0ut05wn">
        <dc:Bounds x="1130" y="1100" width="100" height="80" />
      </bpmndi:BPMNShape>
      <bpmndi:BPMNShape id="Activity_1x7a8ee_di" bpmnElement="Activity_1x7a8ee">
        <dc:Bounds x="260" y="1250" width="100" height="80" />
      </bpmndi:BPMNShape>
      <bpmndi:BPMNShape id="Gateway_0w9iplv_di" bpmnElement="Gateway_0w9iplv" isMarkerVisible="true">
        <dc:Bounds x="425" y="1265" width="50" height="50" />
        <bpmndi:BPMNLabel>
          <dc:Bounds x="406" y="1220" width="87" height="40" />
        </bpmndi:BPMNLabel>
      </bpmndi:BPMNShape>
      <bpmndi:BPMNShape id="Gateway_0r5ntqn_di" bpmnElement="Gateway_1wnimx5">
        <dc:Bounds x="585" y="1265" width="50" height="50" />
      </bpmndi:BPMNShape>
      <bpmndi:BPMNShape id="Event_1creujc_di" bpmnElement="Event_1creujc" bioc:stroke="rgb(229, 57, 53)" bioc:fill="rgb(255, 205, 210)">
        <dc:Bounds x="512" y="1382" width="36" height="36" />
        <bpmndi:BPMNLabel>
          <dc:Bounds x="519" y="1425" width="23" height="14" />
        </bpmndi:BPMNLabel>
      </bpmndi:BPMNShape>
      <bpmndi:BPMNShape id="Activity_13ow8ar_di" bpmnElement="Activity_13ow8ar" bioc:stroke="rgb(30, 136, 229)" bioc:fill="rgb(187, 222, 251)">
        <dc:Bounds x="750" y="1390" width="100" height="80" />
      </bpmndi:BPMNShape>
      <bpmndi:BPMNShape id="Activity_03dtwk1_di" bpmnElement="Activity_1hf3gwc">
        <dc:Bounds x="750" y="1250" width="100" height="80" />
      </bpmndi:BPMNShape>
      <bpmndi:BPMNShape id="Activity_0t5hj9f_di" bpmnElement="Activity_0t5hj9f">
        <dc:Bounds x="950" y="1250" width="100" height="80" />
      </bpmndi:BPMNShape>
      <bpmndi:BPMNShape id="Gateway_07bherc_di" bpmnElement="Gateway_07bherc" isMarkerVisible="true">
        <dc:Bounds x="1155" y="1265" width="50" height="50" />
        <bpmndi:BPMNLabel>
          <dc:Bounds x="1139" y="1330" width="82" height="40" />
        </bpmndi:BPMNLabel>
      </bpmndi:BPMNShape>
      <bpmndi:BPMNShape id="Activity_1rwrm8y_di" bpmnElement="Activity_1rwrm8y" bioc:stroke="rgb(30, 136, 229)" bioc:fill="rgb(187, 222, 251)">
        <dc:Bounds x="1400" y="1250" width="100" height="80" />
      </bpmndi:BPMNShape>
      <bpmndi:BPMNShape id="Activity_0jzgmwj_di" bpmnElement="Activity_0jzgmwj">
        <dc:Bounds x="300" y="2380" width="100" height="80" />
      </bpmndi:BPMNShape>
      <bpmndi:BPMNShape id="Activity_1rjxr4e_di" bpmnElement="Activity_1rjxr4e" bioc:stroke="rgb(30, 136, 229)" bioc:fill="rgb(187, 222, 251)">
        <dc:Bounds x="990" y="2380" width="100" height="80" />
      </bpmndi:BPMNShape>
      <bpmndi:BPMNShape id="Gateway_0sfffj4_di" bpmnElement="Gateway_1slz29c">
        <dc:Bounds x="505" y="2395" width="50" height="50" />
      </bpmndi:BPMNShape>
      <bpmndi:BPMNShape id="Activity_0jva4bo_di" bpmnElement="Activity_0jva4bo">
        <dc:Bounds x="600" y="2490" width="100" height="80" />
      </bpmndi:BPMNShape>
      <bpmndi:BPMNShape id="Gateway_1glkdnb_di" bpmnElement="Gateway_1glkdnb" isMarkerVisible="true">
        <dc:Bounds x="1195" y="2505" width="50" height="50" />
        <bpmndi:BPMNLabel>
          <dc:Bounds x="1178" y="2453" width="84" height="53" />
        </bpmndi:BPMNLabel>
      </bpmndi:BPMNShape>
      <bpmndi:BPMNShape id="Activity_0lk86yf_di" bpmnElement="Activity_0lk86yf" bioc:stroke="rgb(30, 136, 229)" bioc:fill="rgb(187, 222, 251)">
        <dc:Bounds x="1340" y="2490" width="100" height="80" />
      </bpmndi:BPMNShape>
      <bpmndi:BPMNShape id="Event_0pckj4u_di" bpmnElement="Event_0pckj4u" bioc:stroke="rgb(229, 57, 53)" bioc:fill="rgb(255, 205, 210)">
        <dc:Bounds x="1282" y="2592" width="36" height="36" />
        <bpmndi:BPMNLabel>
          <dc:Bounds x="1289" y="2635" width="23" height="14" />
        </bpmndi:BPMNLabel>
      </bpmndi:BPMNShape>
      <bpmndi:BPMNShape id="Activity_03t2q8t_di" bpmnElement="Activity_03t2q8t">
        <dc:Bounds x="290" y="2060" width="100" height="80" />
      </bpmndi:BPMNShape>
      <bpmndi:BPMNShape id="Gateway_00y3xse_di" bpmnElement="Gateway_1dfcsc1">
        <dc:Bounds x="525" y="2075" width="50" height="50" />
      </bpmndi:BPMNShape>
      <bpmndi:BPMNShape id="Activity_1rnp8h8_di" bpmnElement="Activity_1rnp8h8" bioc:stroke="rgb(30, 136, 229)" bioc:fill="rgb(187, 222, 251)">
        <dc:Bounds x="790" y="2060" width="100" height="80" />
      </bpmndi:BPMNShape>
      <bpmndi:BPMNShape id="Activity_1qbhliu_di" bpmnElement="Activity_1qbhliu">
        <dc:Bounds x="630" y="2170" width="100" height="80" />
      </bpmndi:BPMNShape>
      <bpmndi:BPMNShape id="Gateway_0w0j02k_di" bpmnElement="Gateway_0w0j02k" isMarkerVisible="true">
        <dc:Bounds x="1165" y="2185" width="50" height="50" />
        <bpmndi:BPMNLabel>
          <dc:Bounds x="1152" y="2107" width="76" height="66" />
        </bpmndi:BPMNLabel>
      </bpmndi:BPMNShape>
      <bpmndi:BPMNShape id="Activity_1etelb4_di" bpmnElement="Activity_1etelb4" bioc:stroke="rgb(30, 136, 229)" bioc:fill="rgb(187, 222, 251)">
        <dc:Bounds x="1360" y="2170" width="100" height="80" />
      </bpmndi:BPMNShape>
      <bpmndi:BPMNShape id="Event_17g7vh0_di" bpmnElement="Event_17g7vh0" bioc:stroke="rgb(229, 57, 53)" bioc:fill="rgb(255, 205, 210)">
        <dc:Bounds x="1272" y="2302" width="36" height="36" />
        <bpmndi:BPMNLabel>
          <dc:Bounds x="1279" y="2345" width="23" height="14" />
        </bpmndi:BPMNLabel>
      </bpmndi:BPMNShape>
      <bpmndi:BPMNShape id="Activity_1imths9_di" bpmnElement="Activity_1imths9">
        <dc:Bounds x="2260" y="1000" width="100" height="80" />
      </bpmndi:BPMNShape>
      <bpmndi:BPMNShape id="Gateway_0ma6a8h_di" bpmnElement="Gateway_0r8ba09">
        <dc:Bounds x="2495" y="1015" width="50" height="50" />
        <bpmndi:BPMNLabel>
          <dc:Bounds x="2410" y="973" width="79" height="53" />
        </bpmndi:BPMNLabel>
      </bpmndi:BPMNShape>
      <bpmndi:BPMNShape id="Activity_17m8478_di" bpmnElement="Activity_17m8478">
        <dc:Bounds x="2680" y="1000" width="100" height="80" />
      </bpmndi:BPMNShape>
      <bpmndi:BPMNShape id="Activity_100m1uf_di" bpmnElement="Activity_100m1uf">
        <dc:Bounds x="2680" y="860" width="100" height="80" />
      </bpmndi:BPMNShape>
      <bpmndi:BPMNShape id="Activity_14pujso_di" bpmnElement="Activity_14pujso">
        <dc:Bounds x="2680" y="1120" width="100" height="80" />
      </bpmndi:BPMNShape>
      <bpmndi:BPMNShape id="Activity_0gg8q1y_di" bpmnElement="Activity_13spve3">
        <dc:Bounds x="2920" y="1000" width="100" height="80" />
      </bpmndi:BPMNShape>
      <bpmndi:BPMNShape id="Event_0b9snr5_di" bpmnElement="Event_0b9snr5" bioc:stroke="rgb(229, 57, 53)" bioc:fill="rgb(255, 205, 210)">
        <dc:Bounds x="3162" y="1022" width="36" height="36" />
        <bpmndi:BPMNLabel>
          <dc:Bounds x="3169" y="1065" width="23" height="14" />
        </bpmndi:BPMNLabel>
      </bpmndi:BPMNShape>
      <bpmndi:BPMNShape id="Event_0twz620_di" bpmnElement="Event_0twz620" bioc:stroke="rgb(67, 160, 71)" bioc:fill="rgb(200, 230, 201)">
        <dc:Bounds x="172" y="1632" width="36" height="36" />
        <bpmndi:BPMNLabel>
          <dc:Bounds x="150" y="1675" width="85" height="27" />
        </bpmndi:BPMNLabel>
      </bpmndi:BPMNShape>
      <bpmndi:BPMNShape id="Activity_1qyqzwf_di" bpmnElement="Activity_1qyqzwf">
        <dc:Bounds x="260" y="1610" width="100" height="80" />
      </bpmndi:BPMNShape>
      <bpmndi:BPMNShape id="Gateway_0o9ywmm_di" bpmnElement="Gateway_1tq5o60">
        <dc:Bounds x="415" y="1625" width="50" height="50" />
      </bpmndi:BPMNShape>
      <bpmndi:BPMNShape id="Activity_0t6hbzp_di" bpmnElement="Activity_0t6hbzp">
        <dc:Bounds x="520" y="1610" width="100" height="80" />
      </bpmndi:BPMNShape>
      <bpmndi:BPMNShape id="Gateway_18uidys_di" bpmnElement="Gateway_18uidys" isMarkerVisible="true">
        <dc:Bounds x="675" y="1625" width="50" height="50" />
        <bpmndi:BPMNLabel>
          <dc:Bounds x="715" y="1567" width="89" height="66" />
        </bpmndi:BPMNLabel>
      </bpmndi:BPMNShape>
      <bpmndi:BPMNShape id="Activity_1qqcd5n_di" bpmnElement="Activity_1qqcd5n">
        <dc:Bounds x="390" y="1770" width="100" height="80" />
      </bpmndi:BPMNShape>
      <bpmndi:BPMNShape id="Activity_0rv3anq_di" bpmnElement="Activity_0rv3anq">
        <dc:Bounds x="560" y="1460" width="100" height="80" />
      </bpmndi:BPMNShape>
      <bpmndi:BPMNShape id="Activity_01ai6kd_di" bpmnElement="Activity_01ai6kd" bioc:stroke="#1e88e5" bioc:fill="#bbdefb" color:background-color="#bbdefb" color:border-color="#1e88e5">
        <dc:Bounds x="860" y="1610" width="100" height="80" />
      </bpmndi:BPMNShape>
      <bpmndi:BPMNShape id="Event_125gwjb_di" bpmnElement="Event_125gwjb" bioc:stroke="#e53935" bioc:fill="#ffcdd2" color:background-color="#ffcdd2" color:border-color="#e53935">
        <dc:Bounds x="862" y="1722" width="36" height="36" />
        <bpmndi:BPMNLabel>
          <dc:Bounds x="869" y="1765" width="23" height="14" />
        </bpmndi:BPMNLabel>
      </bpmndi:BPMNShape>
      <bpmndi:BPMNShape id="Gateway_0gy54ty_di" bpmnElement="Gateway_0gy54ty" isMarkerVisible="true">
        <dc:Bounds x="545" y="1785" width="50" height="50" />
        <bpmndi:BPMNLabel>
          <dc:Bounds x="536" y="1740" width="67" height="40" />
        </bpmndi:BPMNLabel>
      </bpmndi:BPMNShape>
      <bpmndi:BPMNShape id="Activity_0cl648e_di" bpmnElement="Activity_0cl648e" bioc:stroke="#1e88e5" bioc:fill="#bbdefb" color:background-color="#bbdefb" color:border-color="#1e88e5">
        <dc:Bounds x="650" y="1770" width="100" height="80" />
      </bpmndi:BPMNShape>
      <bpmndi:BPMNShape id="Activity_0eafknt_di" bpmnElement="Activity_0eafknt">
        <dc:Bounds x="500" y="1940" width="100" height="80" />
      </bpmndi:BPMNShape>
      <bpmndi:BPMNShape id="Event_1eln72h_di" bpmnElement="Event_1eln72h" bioc:stroke="#e53935" bioc:fill="#ffcdd2" color:background-color="#ffcdd2" color:border-color="#e53935">
        <dc:Bounds x="652" y="1862" width="36" height="36" />
        <bpmndi:BPMNLabel>
          <dc:Bounds x="659" y="1905" width="23" height="14" />
        </bpmndi:BPMNLabel>
      </bpmndi:BPMNShape>
      <bpmndi:BPMNShape id="BPMNShape_09imc5i" bpmnElement="Event_1fc99py" bioc:stroke="rgb(229, 57, 53)" bioc:fill="rgb(255, 205, 210)">
        <dc:Bounds x="1302" y="1352" width="36" height="36" />
        <bpmndi:BPMNLabel>
          <dc:Bounds x="1309" y="1395" width="23" height="14" />
        </bpmndi:BPMNLabel>
      </bpmndi:BPMNShape>
      <bpmndi:BPMNShape id="TextAnnotation_0i43w39_di" bpmnElement="TextAnnotation_0i43w39">
        <dc:Bounds x="450" y="2595" width="100" height="124" />
      </bpmndi:BPMNShape>
      <bpmndi:BPMNEdge id="Flow_17jrn7z_di" bpmnElement="Flow_17jrn7z">
        <di:waypoint x="208" y="170" />
        <di:waypoint x="250" y="170" />
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Flow_0bvkuk3_di" bpmnElement="Flow_0bvkuk3">
        <di:waypoint x="350" y="170" />
        <di:waypoint x="480" y="170" />
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Flow_1k7mthp_di" bpmnElement="Flow_1k7mthp">
        <di:waypoint x="208" y="450" />
        <di:waypoint x="260" y="450" />
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Flow_1080lyi_di" bpmnElement="Flow_1080lyi">
        <di:waypoint x="580" y="170" />
        <di:waypoint x="625" y="170" />
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Flow_1viyo66_di" bpmnElement="Flow_1viyo66">
        <di:waypoint x="650" y="195" />
        <di:waypoint x="650" y="240" />
        <di:waypoint x="782" y="240" />
        <bpmndi:BPMNLabel>
          <dc:Bounds x="657" y="215" width="17" height="14" />
        </bpmndi:BPMNLabel>
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Flow_1rclzph_di" bpmnElement="Flow_1rclzph">
        <di:waypoint x="630" y="425" />
        <di:waypoint x="630" y="390" />
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Flow_0h8x3zt_di" bpmnElement="Flow_0h8x3zt">
        <di:waypoint x="630" y="310" />
        <di:waypoint x="630" y="175" />
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Flow_1ru70dh_di" bpmnElement="Flow_1ru70dh">
        <di:waypoint x="675" y="170" />
        <di:waypoint x="750" y="170" />
        <bpmndi:BPMNLabel>
          <dc:Bounds x="689" y="153" width="23" height="14" />
        </bpmndi:BPMNLabel>
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Flow_0z520fi_di" bpmnElement="Flow_0z520fi">
        <di:waypoint x="208" y="627" />
        <di:waypoint x="260" y="627" />
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Flow_0woh0jt_di" bpmnElement="Flow_0woh0jt">
        <di:waypoint x="360" y="450" />
        <di:waypoint x="605" y="450" />
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Flow_14fgq7q_di" bpmnElement="Flow_14fgq7q">
        <di:waypoint x="655" y="450" />
        <di:waypoint x="740" y="450" />
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Flow_14cwe2n_di" bpmnElement="Flow_14cwe2n">
        <di:waypoint x="360" y="627" />
        <di:waypoint x="415" y="627" />
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Flow_1tz9g6w_di" bpmnElement="Flow_1tz9g6w">
        <di:waypoint x="440" y="652" />
        <di:waypoint x="440" y="710" />
        <di:waypoint x="522" y="710" />
        <bpmndi:BPMNLabel>
          <dc:Bounds x="448" y="678" width="15" height="14" />
        </bpmndi:BPMNLabel>
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Flow_0wgefx9_di" bpmnElement="Flow_0wgefx9">
        <di:waypoint x="465" y="627" />
        <di:waypoint x="605" y="627" />
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Flow_11rxx1e_di" bpmnElement="Flow_11rxx1e">
        <di:waypoint x="655" y="627" />
        <di:waypoint x="740" y="627" />
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Flow_0s11qy2_di" bpmnElement="Flow_0s11qy2">
        <di:waypoint x="840" y="450" />
        <di:waypoint x="925" y="450" />
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Flow_1lep759_di" bpmnElement="Flow_1lep759">
        <di:waypoint x="840" y="627" />
        <di:waypoint x="930" y="627" />
        <di:waypoint x="930" y="455" />
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Flow_05rae4p_di" bpmnElement="Flow_05rae4p">
        <di:waypoint x="950" y="475" />
        <di:waypoint x="950" y="510" />
        <di:waypoint x="1012" y="510" />
        <bpmndi:BPMNLabel>
          <dc:Bounds x="951" y="490" width="15" height="14" />
        </bpmndi:BPMNLabel>
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Flow_0osj3oj_di" bpmnElement="Flow_0osj3oj">
        <di:waypoint x="975" y="450" />
        <di:waypoint x="1150" y="450" />
        <bpmndi:BPMNLabel>
          <dc:Bounds x="1054" y="432" width="18" height="14" />
        </bpmndi:BPMNLabel>
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Flow_0rly60l_di" bpmnElement="Flow_0rly60l">
        <di:waypoint x="630" y="652" />
        <di:waypoint x="630" y="710" />
        <di:waypoint x="1000" y="710" />
        <di:waypoint x="1000" y="667" />
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Flow_044o2rg_di" bpmnElement="Flow_044o2rg">
        <di:waypoint x="1050" y="627" />
        <di:waypoint x="1075" y="627" />
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Flow_13wfs08_di" bpmnElement="Flow_13wfs08">
        <di:waypoint x="208" y="820" />
        <di:waypoint x="260" y="820" />
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Flow_1jvyqnb_di" bpmnElement="Flow_1jvyqnb">
        <di:waypoint x="360" y="820" />
        <di:waypoint x="420" y="820" />
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Flow_08nlduk_di" bpmnElement="Flow_08nlduk">
        <di:waypoint x="520" y="820" />
        <di:waypoint x="700" y="820" />
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Flow_193eylw_di" bpmnElement="Flow_193eylw">
        <di:waypoint x="1250" y="627" />
        <di:waypoint x="1305" y="627" />
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Flow_0a1iosz_di" bpmnElement="Flow_0a1iosz">
        <di:waypoint x="800" y="820" />
        <di:waypoint x="1310" y="820" />
        <di:waypoint x="1310" y="632" />
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Flow_1p4k292_di" bpmnElement="Flow_1p4k292">
        <di:waypoint x="1355" y="627" />
        <di:waypoint x="1410" y="627" />
        <bpmndi:BPMNLabel>
          <dc:Bounds x="1374" y="609" width="18" height="14" />
        </bpmndi:BPMNLabel>
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Flow_12198ke_di" bpmnElement="Flow_12198ke">
        <di:waypoint x="1125" y="627" />
        <di:waypoint x="1150" y="627" />
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Flow_1qwikvc_di" bpmnElement="Flow_1qwikvc">
        <di:waypoint x="1330" y="652" />
        <di:waypoint x="1330" y="700" />
        <di:waypoint x="1442" y="700" />
        <bpmndi:BPMNLabel>
          <dc:Bounds x="1338" y="673" width="15" height="14" />
        </bpmndi:BPMNLabel>
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Flow_1p2v8sb_di" bpmnElement="Flow_1p2v8sb">
        <di:waypoint x="208" y="980" />
        <di:waypoint x="260" y="980" />
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Flow_1m42qns_di" bpmnElement="Flow_1m42qns">
        <di:waypoint x="360" y="980" />
        <di:waypoint x="445" y="980" />
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Flow_1ps1s9o_di" bpmnElement="Flow_1ps1s9o">
        <di:waypoint x="495" y="980" />
        <di:waypoint x="560" y="980" />
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Flow_0yo7x12_di" bpmnElement="Flow_0yo7x12">
        <di:waypoint x="660" y="980" />
        <di:waypoint x="745" y="980" />
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Flow_1u5deps_di" bpmnElement="Flow_1u5deps">
        <di:waypoint x="795" y="980" />
        <di:waypoint x="930" y="980" />
        <bpmndi:BPMNLabel>
          <dc:Bounds x="841" y="963" width="18" height="14" />
        </bpmndi:BPMNLabel>
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Flow_0ycljw4_di" bpmnElement="Flow_0ycljw4">
        <di:waypoint x="770" y="1005" />
        <di:waypoint x="770" y="1070" />
        <di:waypoint x="892" y="1070" />
        <bpmndi:BPMNLabel>
          <dc:Bounds x="699" y="1038" width="63" height="14" />
        </bpmndi:BPMNLabel>
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Flow_0bjwo6v_di" bpmnElement="Flow_0bjwo6v">
        <di:waypoint x="470" y="1005" />
        <di:waypoint x="470" y="1140" />
        <di:waypoint x="1130" y="1140" />
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Flow_1lk5v0x_di" bpmnElement="Flow_1lk5v0x">
        <di:waypoint x="208" y="1290" />
        <di:waypoint x="260" y="1290" />
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Flow_1y5nhb8_di" bpmnElement="Flow_1y5nhb8">
        <di:waypoint x="360" y="1290" />
        <di:waypoint x="425" y="1290" />
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Flow_0x26xca_di" bpmnElement="Flow_0x26xca">
        <di:waypoint x="475" y="1290" />
        <di:waypoint x="585" y="1290" />
        <bpmndi:BPMNLabel>
          <dc:Bounds x="549" y="1272" width="18" height="14" />
        </bpmndi:BPMNLabel>
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Flow_097e3ma_di" bpmnElement="Flow_097e3ma">
        <di:waypoint x="450" y="1315" />
        <di:waypoint x="450" y="1400" />
        <di:waypoint x="512" y="1400" />
        <bpmndi:BPMNLabel>
          <dc:Bounds x="458" y="1351" width="15" height="14" />
        </bpmndi:BPMNLabel>
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Flow_12gzzo8_di" bpmnElement="Flow_12gzzo8">
        <di:waypoint x="620" y="1305" />
        <di:waypoint x="620" y="1430" />
        <di:waypoint x="750" y="1430" />
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Flow_05gxnsl_di" bpmnElement="Flow_05gxnsl">
        <di:waypoint x="635" y="1290" />
        <di:waypoint x="750" y="1290" />
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Flow_1gw5xl5_di" bpmnElement="Flow_1gw5xl5">
        <di:waypoint x="850" y="1290" />
        <di:waypoint x="950" y="1290" />
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Flow_1c2aobq_di" bpmnElement="Flow_1c2aobq">
        <di:waypoint x="1050" y="1290" />
        <di:waypoint x="1155" y="1290" />
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Flow_1f0ru3c_di" bpmnElement="Flow_1f0ru3c">
        <di:waypoint x="1180" y="1180" />
        <di:waypoint x="1180" y="1265" />
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Flow_0okcc4z_di" bpmnElement="Flow_0okcc4z">
        <di:waypoint x="1205" y="1290" />
        <di:waypoint x="1400" y="1290" />
        <bpmndi:BPMNLabel>
          <dc:Bounds x="1294" y="1272" width="18" height="14" />
        </bpmndi:BPMNLabel>
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Flow_1mhtid7_di" bpmnElement="Flow_1mhtid7">
        <di:waypoint x="218" y="2420" />
        <di:waypoint x="300" y="2420" />
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Flow_0gs7prb_di" bpmnElement="Flow_0gs7prb">
        <di:waypoint x="400" y="2420" />
        <di:waypoint x="505" y="2420" />
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Flow_0tv084j_di" bpmnElement="Flow_0tv084j">
        <di:waypoint x="555" y="2420" />
        <di:waypoint x="990" y="2420" />
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Flow_0p7f7t3_di" bpmnElement="Flow_0p7f7t3">
        <di:waypoint x="530" y="2445" />
        <di:waypoint x="530" y="2530" />
        <di:waypoint x="600" y="2530" />
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Flow_1oqoezn_di" bpmnElement="Flow_1oqoezn">
        <di:waypoint x="700" y="2530" />
        <di:waypoint x="1195" y="2530" />
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Flow_1vokk4z_di" bpmnElement="Flow_1vokk4z">
        <di:waypoint x="1245" y="2530" />
        <di:waypoint x="1340" y="2530" />
        <bpmndi:BPMNLabel>
          <dc:Bounds x="1284" y="2512" width="18" height="14" />
        </bpmndi:BPMNLabel>
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Flow_1bbb7kd_di" bpmnElement="Flow_1bbb7kd">
        <di:waypoint x="1220" y="2555" />
        <di:waypoint x="1220" y="2610" />
        <di:waypoint x="1282" y="2610" />
        <bpmndi:BPMNLabel>
          <dc:Bounds x="1228" y="2580" width="15" height="14" />
        </bpmndi:BPMNLabel>
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Flow_0dl9ybr_di" bpmnElement="Flow_0dl9ybr">
        <di:waypoint x="218" y="2100" />
        <di:waypoint x="290" y="2100" />
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Flow_1ck8pj8_di" bpmnElement="Flow_1ck8pj8">
        <di:waypoint x="390" y="2100" />
        <di:waypoint x="525" y="2100" />
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Flow_1t1abd5_di" bpmnElement="Flow_1t1abd5">
        <di:waypoint x="550" y="2125" />
        <di:waypoint x="550" y="2210" />
        <di:waypoint x="630" y="2210" />
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Flow_0jd7iml_di" bpmnElement="Flow_0jd7iml">
        <di:waypoint x="730" y="2210" />
        <di:waypoint x="1165" y="2210" />
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Flow_0m5h15c_di" bpmnElement="Flow_0m5h15c">
        <di:waypoint x="1215" y="2210" />
        <di:waypoint x="1360" y="2210" />
        <bpmndi:BPMNLabel>
          <dc:Bounds x="1279" y="2192" width="18" height="14" />
        </bpmndi:BPMNLabel>
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Flow_0hwtgmc_di" bpmnElement="Flow_0hwtgmc">
        <di:waypoint x="1190" y="2235" />
        <di:waypoint x="1190" y="2320" />
        <di:waypoint x="1272" y="2320" />
        <bpmndi:BPMNLabel>
          <dc:Bounds x="1202" y="2243" width="15" height="14" />
        </bpmndi:BPMNLabel>
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Flow_0vee046_di" bpmnElement="Flow_0vee046">
        <di:waypoint x="850" y="170" />
        <di:waypoint x="2350" y="170" />
        <di:waypoint x="2350" y="1000" />
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Flow_0sqc3xr_di" bpmnElement="Flow_0sqc3xr">
        <di:waypoint x="1250" y="450" />
        <di:waypoint x="2330" y="450" />
        <di:waypoint x="2330" y="1000" />
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Flow_1m1rrpj_di" bpmnElement="Flow_1m1rrpj">
        <di:waypoint x="1100" y="602" />
        <di:waypoint x="1100" y="520" />
        <di:waypoint x="2310" y="520" />
        <di:waypoint x="2310" y="1000" />
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Flow_1f9dl2m_di" bpmnElement="Flow_1f9dl2m">
        <di:waypoint x="1510" y="627" />
        <di:waypoint x="2280" y="627" />
        <di:waypoint x="2280" y="1000" />
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Flow_1o5y0ou_di" bpmnElement="Flow_1o5y0ou">
        <di:waypoint x="850" y="1430" />
        <di:waypoint x="1890" y="1430" />
        <di:waypoint x="1890" y="1060" />
        <di:waypoint x="2260" y="1060" />
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Flow_1wx22pe_di" bpmnElement="Flow_1wx22pe">
        <di:waypoint x="1500" y="1290" />
        <di:waypoint x="1875" y="1290" />
        <di:waypoint x="1875" y="1040" />
        <di:waypoint x="2260" y="1040" />
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Flow_1wu1eo2_di" bpmnElement="Flow_1wu1eo2">
        <di:waypoint x="1030" y="980" />
        <di:waypoint x="1900" y="980" />
        <di:waypoint x="1900" y="1020" />
        <di:waypoint x="2260" y="1020" />
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Flow_1kmdjhb_di" bpmnElement="Flow_1kmdjhb">
        <di:waypoint x="1090" y="2420" />
        <di:waypoint x="2340" y="2420" />
        <di:waypoint x="2340" y="1080" />
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Flow_1414l69_di" bpmnElement="Flow_1414l69">
        <di:waypoint x="1440" y="2530" />
        <di:waypoint x="2350" y="2530" />
        <di:waypoint x="2350" y="1080" />
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Flow_0ceai1o_di" bpmnElement="Flow_0ceai1o">
        <di:waypoint x="890" y="2100" />
        <di:waypoint x="2310" y="2100" />
        <di:waypoint x="2310" y="1080" />
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Flow_130ovwm_di" bpmnElement="Flow_130ovwm">
        <di:waypoint x="1460" y="2210" />
        <di:waypoint x="2320" y="2210" />
        <di:waypoint x="2320" y="1080" />
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Flow_1gvq9cp_di" bpmnElement="Flow_1gvq9cp">
        <di:waypoint x="2360" y="1040" />
        <di:waypoint x="2495" y="1040" />
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Flow_1y2k0v3_di" bpmnElement="Flow_1y2k0v3">
        <di:waypoint x="2545" y="1040" />
        <di:waypoint x="2680" y="1040" />
        <bpmndi:BPMNLabel>
          <dc:Bounds x="2572" y="1006" width="83" height="27" />
        </bpmndi:BPMNLabel>
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Flow_0g3fytd_di" bpmnElement="Flow_0g3fytd">
        <di:waypoint x="2520" y="1015" />
        <di:waypoint x="2520" y="900" />
        <di:waypoint x="2680" y="900" />
        <bpmndi:BPMNLabel>
          <dc:Bounds x="2572" y="873" width="83" height="27" />
        </bpmndi:BPMNLabel>
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Flow_0jpn8j2_di" bpmnElement="Flow_0jpn8j2">
        <di:waypoint x="2520" y="1065" />
        <di:waypoint x="2520" y="1160" />
        <di:waypoint x="2680" y="1160" />
        <bpmndi:BPMNLabel>
          <dc:Bounds x="2584" y="1133" width="59" height="27" />
        </bpmndi:BPMNLabel>
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Flow_174u7s2_di" bpmnElement="Flow_174u7s2">
        <di:waypoint x="2780" y="1040" />
        <di:waypoint x="2920" y="1040" />
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Flow_1azis9b_di" bpmnElement="Flow_1azis9b">
        <di:waypoint x="2780" y="900" />
        <di:waypoint x="2850" y="900" />
        <di:waypoint x="2850" y="1010" />
        <di:waypoint x="2920" y="1010" />
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Flow_1g4cx8z_di" bpmnElement="Flow_1g4cx8z">
        <di:waypoint x="2780" y="1160" />
        <di:waypoint x="2850" y="1160" />
        <di:waypoint x="2850" y="1070" />
        <di:waypoint x="2920" y="1070" />
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Flow_078v55k_di" bpmnElement="Flow_078v55k">
        <di:waypoint x="3020" y="1040" />
        <di:waypoint x="3162" y="1040" />
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Flow_0rsaukt_di" bpmnElement="Flow_0rsaukt">
        <di:waypoint x="208" y="1650" />
        <di:waypoint x="260" y="1650" />
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Flow_02gs0uo_di" bpmnElement="Flow_02gs0uo">
        <di:waypoint x="360" y="1650" />
        <di:waypoint x="415" y="1650" />
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Flow_0rz6ot9_di" bpmnElement="Flow_0rz6ot9">
        <di:waypoint x="465" y="1650" />
        <di:waypoint x="520" y="1650" />
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Flow_1dl0t4i_di" bpmnElement="Flow_1dl0t4i">
        <di:waypoint x="620" y="1650" />
        <di:waypoint x="675" y="1650" />
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Flow_10jspnp_di" bpmnElement="Flow_10jspnp">
        <di:waypoint x="440" y="1675" />
        <di:waypoint x="440" y="1770" />
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Flow_1ubbuku_di" bpmnElement="Flow_1ubbuku">
        <di:waypoint x="610" y="1315" />
        <di:waypoint x="610" y="1460" />
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Flow_1m57k60_di" bpmnElement="Flow_1m57k60">
        <di:waypoint x="660" y="1500" />
        <di:waypoint x="700" y="1500" />
        <di:waypoint x="700" y="1625" />
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Flow_0scl6kt_di" bpmnElement="Flow_0scl6kt">
        <di:waypoint x="725" y="1650" />
        <di:waypoint x="860" y="1650" />
        <bpmndi:BPMNLabel>
          <dc:Bounds x="784" y="1632" width="18" height="14" />
        </bpmndi:BPMNLabel>
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Flow_0q6h3j9_di" bpmnElement="Flow_0q6h3j9">
        <di:waypoint x="960" y="1650" />
        <di:waypoint x="2270" y="1650" />
        <di:waypoint x="2270" y="1080" />
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Flow_0yt4o87_di" bpmnElement="Flow_0yt4o87">
        <di:waypoint x="700" y="1675" />
        <di:waypoint x="700" y="1740" />
        <di:waypoint x="862" y="1740" />
        <bpmndi:BPMNLabel>
          <dc:Bounds x="708" y="1704" width="15" height="14" />
        </bpmndi:BPMNLabel>
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Flow_0vjhroi_di" bpmnElement="Flow_0vjhroi">
        <di:waypoint x="490" y="1810" />
        <di:waypoint x="545" y="1810" />
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Flow_1cfx2p8_di" bpmnElement="Flow_1cfx2p8">
        <di:waypoint x="595" y="1810" />
        <di:waypoint x="650" y="1810" />
        <bpmndi:BPMNLabel>
          <dc:Bounds x="611" y="1793" width="18" height="14" />
        </bpmndi:BPMNLabel>
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Flow_1nyniw3_di" bpmnElement="Flow_1nyniw3">
        <di:waypoint x="750" y="1810" />
        <di:waypoint x="2290" y="1810" />
        <di:waypoint x="2290" y="1080" />
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Flow_0em1esl_di" bpmnElement="Flow_0em1esl">
        <di:waypoint x="550" y="1940" />
        <di:waypoint x="550" y="1815" />
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Flow_0bk8j9f_di" bpmnElement="Flow_0bk8j9f">
        <di:waypoint x="570" y="1835" />
        <di:waypoint x="570" y="1880" />
        <di:waypoint x="652" y="1880" />
        <bpmndi:BPMNLabel>
          <dc:Bounds x="578" y="1853" width="15" height="14" />
        </bpmndi:BPMNLabel>
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Flow_1xq33v7_di" bpmnElement="Flow_1xq33v7">
        <di:waypoint x="575" y="2100" />
        <di:waypoint x="790" y="2100" />
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Flow_150aw2w_di" bpmnElement="Flow_150aw2w">
        <di:waypoint x="550" y="2075" />
        <di:waypoint x="550" y="2020" />
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Flow_0ilr85g_di" bpmnElement="Flow_0ilr85g">
        <di:waypoint x="1180" y="1315" />
        <di:waypoint x="1180" y="1370" />
        <di:waypoint x="1302" y="1370" />
        <bpmndi:BPMNLabel>
          <dc:Bounds x="1188" y="1340" width="15" height="14" />
        </bpmndi:BPMNLabel>
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Association_15rpsk0_di" bpmnElement="Association_15rpsk0">
        <di:waypoint x="600" y="2557" />
        <di:waypoint x="528" y="2595" />
      </bpmndi:BPMNEdge>
    </bpmndi:BPMNPlane>
  </bpmndi:BPMNDiagram>
</bpmn:definitions>
", - "playbook_abstraction": "template", + "is_playbook_template": true, "playbook_creation_time": "2022-03-31T13:00:00.000Z", "playbook_modification_time": "2022-03-31T13:00:00.000Z", "revoked": false, @@ -1407,6 +1407,96 @@ "source_ref": "x-oca-playbook--cab95b33-7770-4891-94f2-f2c640f2408a", "target_ref": "course-of-action--40e5bff2-e763-4834-953c-a197ac44466c" }, + { + "type": "relationship", + "spec_version": "2.1", + "id": "relationship--aedd1c00-a01d-440c-94c6-1d7b417eff32", + "created": "2022-03-31T13:00:00.000Z", + "modified": "2022-03-31T13:00:00.000Z", + "relationship_type": "uses", + "source_ref": "course-of-action--40e5bff2-e763-4834-953c-a197ac44466c", + "target_ref": "x-oca-detection--58834c29-4ceb-42a1-a218-336103021111" + }, + { + "type": "relationship", + "spec_version": "2.1", + "id": "relationship--1411953a-b4e2-4f59-a5f5-2ca14196a067", + "created": "2022-03-31T13:00:00.000Z", + "modified": "2022-03-31T13:00:00.000Z", + "relationship_type": "uses", + "source_ref": "course-of-action--40e5bff2-e763-4834-953c-a197ac44466c", + "target_ref": "x-oca-detection--58834c29-4ceb-42a1-a218-336103021222" + }, + { + "type": "relationship", + "spec_version": "2.1", + "id": "relationship--7ac06f6c-668c-441b-b54f-e7dd9ce7b6a8", + "created": "2022-03-31T13:00:00.000Z", + "modified": "2022-03-31T13:00:00.000Z", + "relationship_type": "uses", + "source_ref": "course-of-action--40e5bff2-e763-4834-953c-a197ac44466c", + "target_ref": "x-oca-detection--58834c29-4ceb-42a1-a218-336103021000" + }, + { + "type": "relationship", + "spec_version": "2.1", + "id": "relationship--0e323e09-c70c-4aa2-ac06-9fd3d429aa6d", + "created": "2022-03-31T13:00:00.000Z", + "modified": "2022-03-31T13:00:00.000Z", + "relationship_type": "uses", + "source_ref": "course-of-action--40e5bff2-e763-4834-953c-a197ac44466c", + "target_ref": "x-oca-detection--458c02c9-3635-42e4-8873-6785e00517e7" + }, + { + "type": "relationship", + "spec_version": "2.1", + "id": "relationship--8b413984-a69c-4923-8f91-bc01a73f06cb", + "created": "2022-03-31T13:00:00.000Z", + "modified": "2022-03-31T13:00:00.000Z", + "relationship_type": "uses", + "source_ref": "course-of-action--40e5bff2-e763-4834-953c-a197ac44466c", + "target_ref": "x-oca-detection--5899C5CC-CE20-44EE-806E-9F64EBA0B29F" + }, + { + "type": "relationship", + "spec_version": "2.1", + "id": "relationship--475547ac-502b-4e93-9c69-8895784e049d", + "created": "2022-03-31T13:00:00.000Z", + "modified": "2022-03-31T13:00:00.000Z", + "relationship_type": "uses", + "source_ref": "course-of-action--40e5bff2-e763-4834-953c-a197ac44466c", + "target_ref": "x-oca-detection--f27cb358-d747-47ba-a6c4-e5b8debab157" + }, + { + "type": "relationship", + "spec_version": "2.1", + "id": "relationship--4b6e9b4f-e14d-4b79-ac3e-2007f1cd025c", + "created": "2022-03-31T13:00:00.000Z", + "modified": "2022-03-31T13:00:00.000Z", + "relationship_type": "uses", + "source_ref": "course-of-action--40e5bff2-e763-4834-953c-a197ac44466c", + "target_ref": "x-oca-detection--275bf485-736d-4aa5-b172-e34d28faa58c" + }, + { + "type": "relationship", + "spec_version": "2.1", + "id": "relationship--b45b6957-9798-4e10-af42-0a00450041dc", + "created": "2022-03-31T13:00:00.000Z", + "modified": "2022-03-31T13:00:00.000Z", + "relationship_type": "uses", + "source_ref": "course-of-action--40e5bff2-e763-4834-953c-a197ac44466c", + "target_ref": "x-oca-detection--40a941cc-42df-4b2e-b607-6d74168084b9" + }, + { + "type": "relationship", + "spec_version": "2.1", + "id": "relationship--fc91bfc0-54bf-46fa-b372-9d60ab483b91", + "created": "2022-03-31T13:00:00.000Z", + "modified": "2022-03-31T13:00:00.000Z", + "relationship_type": "uses", + "source_ref": "course-of-action--40e5bff2-e763-4834-953c-a197ac44466c", + "target_ref": "x-oca-detection--66aa9c25-8b56-4121-8630-dbe457393b27" + }, { "type": "relationship", "spec_version": "2.1", @@ -1541,7 +1631,7 @@ "remediation" ], "playbook_bin": "{
  "type": "playbook",
  "spec_version": "cacao-2.0",
  "id": "playbook--76344d27-f69a-4f05-be77-dab887538464",
  "name": "Process_0rwiify: Mitigate",
  "playbook_types": [
    "mitigation",
    "remediation"
  ],
  "created_by": "identity--b085a68a-bf48-4316-9667-37af78cba894",
  "created": "2024-03-13T13:56:26.144Z",
  "modified": "2024-04-15T08:56:26.144Z",
  "revoked": false,
  "derived_from": [
    "playbook--7b444e9d-9e22-469c-95de-347bf8a5ba4d",
    "playbook--05783b5d-42fb-4157-9861-424d470f0cd3"
  ],
  "workflow_start": "start--c47075ae-b737-445c-966a-ebab177c2369",
  "workflow": {
    "start--c47075ae-b737-445c-966a-ebab177c2369": {
      "name": "StartEvent_1: Start",
      "on_completion": "action--2b697cc2-0ec8-4539-b29f-74f6d7c46d1b",
      "step_extensions": {
        "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f": {
          "type": "coordinates",
          "x": 380,
          "y": 840,
          "width": 60,
          "height": 40,
          "outgoing_connections": [
            {
              "type": "on-completion",
              "x": [
                440,
                455
              ],
              "y": [
                860,
                860
              ]
            }
          ]
        }
      },
      "type": "start"
    },
    "end--d1cb2da6-0576-4d42-ac55-dbd4f5153a34": {
      "name": "Event_0u4cpm8: End",
      "step_extensions": {
        "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f": {
          "type": "coordinates",
          "x": 2190,
          "y": 840,
          "width": 60,
          "height": 40
        }
      },
      "type": "end"
    },
    "parallel--ee13bb1f-3f96-4165-a91e-f2a196325f70": {
      "name": "Activity_14rui20: Send email to SOC analyst with ticket URL",
      "step_extensions": {
        "": [
          "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f"
        ],
        "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f": {
          "type": "coordinates",
          "x": 710,
          "y": 830,
          "width": 120,
          "height": 60,
          "outgoing_connections": [
            {
              "type": "next-steps",
              "x": [
                770,
                770,
                865
              ],
              "y": [
                890,
                1010,
                1010
              ]
            }
          ]
        }
      },
      "type": "parallel",
      "next_steps": [
        "action--adacef3e-f30d-4ea3-8233-87c047ff1ebe",
        "action--16eab865-1b7d-4386-ada5-2b995a678033",
        "action--51020c34-aeea-4a5c-bab1-4c1cbb45f8f2",
        "action--330ed75e-650b-425e-8c8e-00936ef8169c"
      ]
    },
    "if-condition--dac4c8ad-986e-454f-82e6-7e070e51fbdf": {
      "name": "Gateway_1q36atg: Blocking needed?",
      "step_extensions": {
        "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f": {
          "type": "coordinates",
          "x": 1120,
          "y": 680,
          "width": 120,
          "height": 60,
          "outgoing_connections": [
            {
              "type": "on-true",
              "x": [
                1240,
                1315
              ],
              "y": [
                710,
                710
              ]
            },
            {
              "type": "on-false",
              "x": [
                1180,
                1180,
                1750,
                1750
              ],
              "y": [
                680,
                660,
                660,
                830
              ]
            }
          ]
        }
      },
      "type": "if-condition",
      "on_true": "action--ac472fe0-a2f1-4633-b753-b1602467362d",
      "on_false": "action--5da74252-e04d-4532-a44c-9af403915768"
    },
    "if-condition--22e9e463-b714-4dff-83fb-b319947d8731": {
      "name": "Gateway_18ywy9j: Share event?",
      "step_extensions": {
        "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f": {
          "type": "coordinates",
          "x": 1120,
          "y": 980,
          "width": 120,
          "height": 60,
          "outgoing_connections": [
            {
              "type": "on-true",
              "x": [
                1240,
                1315
              ],
              "y": [
                1010,
                1010
              ]
            },
            {
              "type": "on-false",
              "x": [
                1180,
                1180,
                1750,
                1750
              ],
              "y": [
                1040,
                1060,
                1060,
                890
              ]
            }
          ]
        }
      },
      "type": "if-condition",
      "on_true": "action--1bf683a5-5cda-4ee1-8d1f-cef61d4665e0",
      "on_false": "action--5da74252-e04d-4532-a44c-9af403915768"
    },
    "if-condition--ff87247d-765b-423a-baa5-50c446dacd28": {
      "name": "Gateway_0e55p2y: Additional tasks needed?",
      "step_extensions": {
        "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f": {
          "type": "coordinates",
          "x": 1120,
          "y": 880,
          "width": 120,
          "height": 60,
          "outgoing_connections": [
            {
              "type": "on-true",
              "x": [
                1240,
                1315
              ],
              "y": [
                910,
                910
              ]
            },
            {
              "type": "on-false",
              "x": [
                1180,
                1180,
                1680,
                1680
              ],
              "y": [
                940,
                960,
                960,
                890
              ]
            }
          ]
        }
      },
      "type": "if-condition",
      "on_true": "action--d31f2c09-8126-4290-9699-c9f929ea54f5",
      "on_false": "action--5da74252-e04d-4532-a44c-9af403915768"
    },
    "if-condition--adf7b288-b4c4-4322-8292-792a92d69ece": {
      "name": "Gateway_1741pe0: Remediation needed?",
      "step_extensions": {
        "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f": {
          "type": "coordinates",
          "x": 1120,
          "y": 780,
          "width": 120,
          "height": 60,
          "outgoing_connections": [
            {
              "type": "on-true",
              "x": [
                1240,
                1330
              ],
              "y": [
                810,
                810
              ]
            },
            {
              "type": "on-false",
              "x": [
                1180,
                1180,
                1680,
                1680
              ],
              "y": [
                780,
                760,
                760,
                830
              ]
            }
          ]
        }
      },
      "type": "if-condition",
      "on_true": "playbook-action--d57a532b-e353-4ca4-9c28-85f07c7ecc89",
      "on_false": "action--5da74252-e04d-4532-a44c-9af403915768"
    },
    "action--2b697cc2-0ec8-4539-b29f-74f6d7c46d1b": {
      "name": "Activity_0i6qxv4: Create ticket",
      "on_completion": "parallel--ee13bb1f-3f96-4165-a91e-f2a196325f70",
      "step_extensions": {
        "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f": {
          "type": "coordinates",
          "x": 455,
          "y": 830,
          "width": 150,
          "height": 60,
          "outgoing_connections": [
            {
              "type": "on-completion",
              "x": [
                605,
                710
              ],
              "y": [
                860,
                860
              ]
            }
          ]
        }
      },
      "type": "action",
      "commands": [
        {
          "type": "http-api"
        }
      ]
    },
    "action--adacef3e-f30d-4ea3-8233-87c047ff1ebe": {
      "name": "Activity_1xrsq3p: Prompt analyst if blocking is needed",
      "on_completion": "if-condition--dac4c8ad-986e-454f-82e6-7e070e51fbdf",
      "step_extensions": {
        "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f": {
          "type": "coordinates",
          "x": 865,
          "y": 680,
          "width": 150,
          "height": 60,
          "outgoing_connections": [
            {
              "type": "on-completion",
              "x": [
                1015,
                1120
              ],
              "y": [
                710,
                710
              ]
            }
          ]
        }
      },
      "type": "action",
      "commands": [
        {
          "type": "manual"
        }
      ]
    },
    "action--ac472fe0-a2f1-4633-b753-b1602467362d": {
      "name": "Activity_1t8x5d5: Block IP in Firewall",
      "on_completion": "action--5da74252-e04d-4532-a44c-9af403915768",
      "step_extensions": {
        "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f": {
          "type": "coordinates",
          "x": 1315,
          "y": 680,
          "width": 150,
          "height": 60,
          "outgoing_connections": [
            {
              "type": "on-completion",
              "x": [
                1465,
                1610,
                1610,
                1675
              ],
              "y": [
                710,
                710,
                860,
                860
              ]
            }
          ]
        }
      },
      "type": "action",
      "commands": [
        {
          "type": "http-api"
        }
      ]
    },
    "action--330ed75e-650b-425e-8c8e-00936ef8169c": {
      "name": "Activity_0j0scw4: Prompt analyst if event can be shared",
      "on_completion": "if-condition--22e9e463-b714-4dff-83fb-b319947d8731",
      "step_extensions": {
        "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f": {
          "type": "coordinates",
          "x": 865,
          "y": 980,
          "width": 150,
          "height": 60,
          "outgoing_connections": [
            {
              "type": "on-completion",
              "x": [
                1015,
                1120
              ],
              "y": [
                1010,
                1010
              ]
            }
          ]
        }
      },
      "type": "action",
      "commands": [
        {
          "type": "manual"
        }
      ]
    },
    "action--16eab865-1b7d-4386-ada5-2b995a678033": {
      "name": "Activity_05xs8h2: Prompt analyst if remediation is needed",
      "on_completion": "if-condition--adf7b288-b4c4-4322-8292-792a92d69ece",
      "step_extensions": {
        "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f": {
          "type": "coordinates",
          "x": 865,
          "y": 780,
          "width": 150,
          "height": 60,
          "outgoing_connections": [
            {
              "type": "on-completion",
              "x": [
                1015,
                1120
              ],
              "y": [
                810,
                810
              ]
            }
          ]
        }
      },
      "type": "action",
      "commands": [
        {
          "type": "manual"
        }
      ]
    },
    "action--51020c34-aeea-4a5c-bab1-4c1cbb45f8f2": {
      "name": "Activity_1gi6cid: Prompt analyst if additional tasks need to be performed",
      "on_completion": "if-condition--ff87247d-765b-423a-baa5-50c446dacd28",
      "step_extensions": {
        "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f": {
          "type": "coordinates",
          "x": 865,
          "y": 880,
          "width": 150,
          "height": 60,
          "outgoing_connections": [
            {
              "type": "on-completion",
              "x": [
                1015,
                1120
              ],
              "y": [
                910,
                910
              ]
            }
          ]
        }
      },
      "type": "action",
      "commands": [
        {
          "type": "manual"
        }
      ]
    },
    "action--c0faa24e-b2a2-41fb-aa19-b59ae5a25e58": {
      "name": "Activity_1arg5f6: Close ticket",
      "on_completion": "end--d1cb2da6-0576-4d42-ac55-dbd4f5153a34",
      "step_extensions": {
        "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f": {
          "type": "coordinates",
          "x": 1935,
          "y": 830,
          "width": 150,
          "height": 60,
          "outgoing_connections": [
            {
              "type": "on-completion",
              "x": [
                2085,
                2190
              ],
              "y": [
                860,
                860
              ]
            }
          ]
        }
      },
      "type": "action",
      "commands": [
        {
          "type": "http-api"
        }
      ]
    },
    "action--1bf683a5-5cda-4ee1-8d1f-cef61d4665e0": {
      "name": "Activity_0x1am58: Mark event for sharing submission",
      "on_completion": "action--5da74252-e04d-4532-a44c-9af403915768",
      "step_extensions": {
        "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f": {
          "type": "coordinates",
          "x": 1315,
          "y": 980,
          "width": 150,
          "height": 60,
          "outgoing_connections": [
            {
              "type": "on-completion",
              "x": [
                1465,
                1610,
                1610,
                1675
              ],
              "y": [
                1010,
                1010,
                860,
                860
              ]
            }
          ]
        }
      },
      "type": "action",
      "commands": [
        {
          "type": "http-api"
        }
      ]
    },
    "action--d31f2c09-8126-4290-9699-c9f929ea54f5": {
      "name": "Activity_1qnpwn4: SOC analyst performs additional tasks",
      "on_completion": "action--5da74252-e04d-4532-a44c-9af403915768",
      "step_extensions": {
        "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f": {
          "type": "coordinates",
          "x": 1315,
          "y": 880,
          "width": 150,
          "height": 60,
          "outgoing_connections": [
            {
              "type": "on-completion",
              "x": [
                1465,
                1610,
                1610,
                1675
              ],
              "y": [
                920,
                920,
                860,
                860
              ]
            }
          ]
        }
      },
      "type": "action",
      "commands": [
        {
          "type": "manual"
        }
      ]
    },
    "action--5da74252-e04d-4532-a44c-9af403915768": {
      "name": "Event_0j39mxm: All gateways finish",
      "on_completion": "action--c0faa24e-b2a2-41fb-aa19-b59ae5a25e58",
      "step_extensions": {
        "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f": {
          "type": "coordinates",
          "x": 1675,
          "y": 830,
          "width": 150,
          "height": 60,
          "outgoing_connections": [
            {
              "type": "on-completion",
              "x": [
                1825,
                1935
              ],
              "y": [
                860,
                860
              ]
            }
          ]
        }
      },
      "type": "action",
      "commands": [
        {
          "type": "manual"
        }
      ]
    },
    "playbook-action--d57a532b-e353-4ca4-9c28-85f07c7ecc89": {
      "name": "Activity_1lf0pw5: Remediate system",
      "on_completion": "action--5da74252-e04d-4532-a44c-9af403915768",
      "step_extensions": {
        "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f": {
          "type": "coordinates",
          "x": 1330,
          "y": 780,
          "width": 120,
          "height": 60,
          "outgoing_connections": [
            {
              "type": "on-completion",
              "x": [
                1450,
                1610,
                1610,
                1675
              ],
              "y": [
                810,
                810,
                860,
                860
              ]
            }
          ]
        }
      },
      "type": "playbook-action",
      "playbook_id": "playbook--767d859e-7387-4e0c-95c0-458ca369486f"
    }
  },
  "extension_definitions": {
    "extension-definition--418ee24c-9cb1-46d9-afa5-309e01aabc7f": {
      "type": "extension-definition",
      "name": "coordinates extension",
      "description": "Coordinates extension for CACAO constructs for visualization purposes.",
      "created_by": "identity--5abe695c-7bd5-4c31-8824-2528696cdbf1",
      "schema": "https://raw.githubusercontent.com/cyentific-rni/cacao-coordinates-extension/main/schemas/coordinates.json",
      "version": "1.0.0"
    }
  }
}", - "playbook_abstraction": "template", + "is_playbook_template": true, "playbook_creation_time": "2022-03-31T13:00:00.000Z", "playbook_modification_time": "2022-03-31T13:00:00.000Z", "revoked": false, @@ -1566,7 +1656,7 @@ "remediation" ], "playbook_bin": "<?xml version="1.0" encoding="UTF-8"?>
<bpmn:definitions xmlns:bpmn="http://www.omg.org/spec/BPMN/20100524/MODEL" xmlns:bpmndi="http://www.omg.org/spec/BPMN/20100524/DI" xmlns:dc="http://www.omg.org/spec/DD/20100524/DC" xmlns:zeebe="http://camunda.org/schema/zeebe/1.0" xmlns:di="http://www.omg.org/spec/DD/20100524/DI" xmlns:modeler="http://camunda.org/schema/modeler/1.0" id="Definitions_174dn05" targetNamespace="http://bpmn.io/schema/bpmn" exporter="Camunda Modeler" exporterVersion="5.5.1" modeler:executionPlatform="Camunda Cloud" modeler:executionPlatformVersion="8.1.0">
  <bpmn:process id="Process_0rwiify" isExecutable="true">
    <bpmn:startEvent id="StartEvent_1">
      <bpmn:outgoing>Flow_0d5ijy4</bpmn:outgoing>
    </bpmn:startEvent>
    <bpmn:sequenceFlow id="Flow_0d5ijy4" sourceRef="StartEvent_1" targetRef="Activity_0i6qxv4" />
    <bpmn:serviceTask id="Activity_0i6qxv4" name="Create ticket">
      <bpmn:extensionElements>
        <zeebe:taskDefinition type="ticketing" />
      </bpmn:extensionElements>
      <bpmn:incoming>Flow_0d5ijy4</bpmn:incoming>
      <bpmn:outgoing>Flow_0cm17qi</bpmn:outgoing>
    </bpmn:serviceTask>
    <bpmn:sequenceFlow id="Flow_0cm17qi" sourceRef="Activity_0i6qxv4" targetRef="Activity_14rui20" />
    <bpmn:sendTask id="Activity_14rui20" name="Send email to SOC analyst with ticket URL">
      <bpmn:extensionElements>
        <zeebe:taskDefinition type="email" />
      </bpmn:extensionElements>
      <bpmn:incoming>Flow_0cm17qi</bpmn:incoming>
      <bpmn:outgoing>Flow_1ubazj5</bpmn:outgoing>
    </bpmn:sendTask>
    <bpmn:serviceTask id="Activity_1xrsq3p" name="Prompt analyst if blocking is needed">
      <bpmn:extensionElements>
        <zeebe:taskDefinition type="soar" />
      </bpmn:extensionElements>
      <bpmn:incoming>Flow_0yrea6c</bpmn:incoming>
      <bpmn:outgoing>Flow_0qhjsdo</bpmn:outgoing>
    </bpmn:serviceTask>
    <bpmn:exclusiveGateway id="Gateway_1q36atg" name="Blocking needed?">
      <bpmn:incoming>Flow_0qhjsdo</bpmn:incoming>
      <bpmn:outgoing>Flow_003k9rd</bpmn:outgoing>
      <bpmn:outgoing>Flow_1tjsr8g</bpmn:outgoing>
    </bpmn:exclusiveGateway>
    <bpmn:sequenceFlow id="Flow_0qhjsdo" sourceRef="Activity_1xrsq3p" targetRef="Gateway_1q36atg" />
    <bpmn:sequenceFlow id="Flow_003k9rd" name="Yes" sourceRef="Gateway_1q36atg" targetRef="Activity_1t8x5d5" />
    <bpmn:serviceTask id="Activity_1t8x5d5" name="Block IP in Firewall">
      <bpmn:extensionElements>
        <zeebe:taskDefinition type="firewall" />
      </bpmn:extensionElements>
      <bpmn:incoming>Flow_003k9rd</bpmn:incoming>
      <bpmn:outgoing>Flow_02txek1</bpmn:outgoing>
    </bpmn:serviceTask>
    <bpmn:sequenceFlow id="Flow_0yrea6c" sourceRef="Gateway_1dbrh0h" targetRef="Activity_1xrsq3p" />
    <bpmn:serviceTask id="Activity_0j0scw4" name="Prompt analyst if event can be shared">
      <bpmn:extensionElements>
        <zeebe:taskDefinition type="soar" />
      </bpmn:extensionElements>
      <bpmn:incoming>Flow_0he4kdx</bpmn:incoming>
      <bpmn:outgoing>Flow_0l5ibo6</bpmn:outgoing>
    </bpmn:serviceTask>
    <bpmn:exclusiveGateway id="Gateway_18ywy9j" name="Share event?">
      <bpmn:incoming>Flow_0l5ibo6</bpmn:incoming>
      <bpmn:outgoing>Flow_0vk6j62</bpmn:outgoing>
      <bpmn:outgoing>Flow_00emzc4</bpmn:outgoing>
    </bpmn:exclusiveGateway>
    <bpmn:sequenceFlow id="Flow_0l5ibo6" sourceRef="Activity_0j0scw4" targetRef="Gateway_18ywy9j" />
    <bpmn:sequenceFlow id="Flow_0vk6j62" name="Yes" sourceRef="Gateway_18ywy9j" targetRef="Activity_0x1am58" />
    <bpmn:sequenceFlow id="Flow_1i1c2gw" sourceRef="Gateway_1dbrh0h" targetRef="Activity_05xs8h2" />
    <bpmn:serviceTask id="Activity_05xs8h2" name="Prompt analyst if remediation is needed">
      <bpmn:extensionElements>
        <zeebe:taskDefinition type="soar" />
      </bpmn:extensionElements>
      <bpmn:incoming>Flow_1i1c2gw</bpmn:incoming>
      <bpmn:outgoing>Flow_18fz62t</bpmn:outgoing>
    </bpmn:serviceTask>
    <bpmn:sequenceFlow id="Flow_1e2onuk" sourceRef="Gateway_1dbrh0h" targetRef="Activity_1gi6cid" />
    <bpmn:serviceTask id="Activity_1gi6cid" name="Prompt analyst if additional tasks need to be performed">
      <bpmn:extensionElements>
        <zeebe:taskDefinition type="soar" />
      </bpmn:extensionElements>
      <bpmn:incoming>Flow_1e2onuk</bpmn:incoming>
      <bpmn:outgoing>Flow_1wxjk4z</bpmn:outgoing>
    </bpmn:serviceTask>
    <bpmn:exclusiveGateway id="Gateway_0e55p2y" name="Additional tasks needed?">
      <bpmn:incoming>Flow_1wxjk4z</bpmn:incoming>
      <bpmn:outgoing>Flow_03c6yay</bpmn:outgoing>
      <bpmn:outgoing>Flow_1rqtcpj</bpmn:outgoing>
    </bpmn:exclusiveGateway>
    <bpmn:sequenceFlow id="Flow_1wxjk4z" sourceRef="Activity_1gi6cid" targetRef="Gateway_0e55p2y" />
    <bpmn:userTask id="Activity_1qnpwn4" name="SOC analyst performs additional tasks">
      <bpmn:incoming>Flow_03c6yay</bpmn:incoming>
      <bpmn:outgoing>Flow_0kupuz3</bpmn:outgoing>
    </bpmn:userTask>
    <bpmn:exclusiveGateway id="Gateway_1741pe0" name="Remediation needed?">
      <bpmn:incoming>Flow_18fz62t</bpmn:incoming>
      <bpmn:incoming>Flow_11ewen6</bpmn:incoming>
      <bpmn:outgoing>Flow_1xgua59</bpmn:outgoing>
      <bpmn:outgoing>Flow_0vctmxd</bpmn:outgoing>
    </bpmn:exclusiveGateway>
    <bpmn:sequenceFlow id="Flow_18fz62t" sourceRef="Activity_05xs8h2" targetRef="Gateway_1741pe0" />
    <bpmn:sequenceFlow id="Flow_1ubazj5" sourceRef="Activity_14rui20" targetRef="Gateway_1dbrh0h" />
    <bpmn:parallelGateway id="Gateway_1dbrh0h">
      <bpmn:incoming>Flow_1ubazj5</bpmn:incoming>
      <bpmn:outgoing>Flow_0yrea6c</bpmn:outgoing>
      <bpmn:outgoing>Flow_1e2onuk</bpmn:outgoing>
      <bpmn:outgoing>Flow_1i1c2gw</bpmn:outgoing>
      <bpmn:outgoing>Flow_0he4kdx</bpmn:outgoing>
    </bpmn:parallelGateway>
    <bpmn:sequenceFlow id="Flow_1xgua59" name="Yes" sourceRef="Gateway_1741pe0" targetRef="Activity_1lf0pw5" />
    <bpmn:callActivity id="Activity_1lf0pw5" name="Remediate system">
      <bpmn:extensionElements>
        <zeebe:calledElement processId="Process_1811f8w" propagateAllChildVariables="false" />
      </bpmn:extensionElements>
      <bpmn:incoming>Flow_1xgua59</bpmn:incoming>
      <bpmn:outgoing>Flow_11ewen6</bpmn:outgoing>
      <bpmn:outgoing>Flow_1nofqpf</bpmn:outgoing>
    </bpmn:callActivity>
    <bpmn:serviceTask id="Activity_1arg5f6" name="Close ticket">
      <bpmn:extensionElements>
        <zeebe:taskDefinition type="ticketing" />
      </bpmn:extensionElements>
      <bpmn:incoming>Flow_0qbp2y4</bpmn:incoming>
      <bpmn:outgoing>Flow_17sr46s</bpmn:outgoing>
    </bpmn:serviceTask>
    <bpmn:sequenceFlow id="Flow_0kupuz3" sourceRef="Activity_1qnpwn4" targetRef="Event_0j39mxm" />
    <bpmn:endEvent id="Event_0u4cpm8">
      <bpmn:incoming>Flow_17sr46s</bpmn:incoming>
    </bpmn:endEvent>
    <bpmn:sequenceFlow id="Flow_17sr46s" sourceRef="Activity_1arg5f6" targetRef="Event_0u4cpm8" />
    <bpmn:intermediateThrowEvent id="Event_0j39mxm" name="All gateways finish">
      <bpmn:incoming>Flow_1tjsr8g</bpmn:incoming>
      <bpmn:incoming>Flow_00emzc4</bpmn:incoming>
      <bpmn:incoming>Flow_0v3lig2</bpmn:incoming>
      <bpmn:incoming>Flow_02txek1</bpmn:incoming>
      <bpmn:incoming>Flow_0kupuz3</bpmn:incoming>
      <bpmn:incoming>Flow_1nofqpf</bpmn:incoming>
      <bpmn:incoming>Flow_1rqtcpj</bpmn:incoming>
      <bpmn:incoming>Flow_0vctmxd</bpmn:incoming>
      <bpmn:outgoing>Flow_0qbp2y4</bpmn:outgoing>
    </bpmn:intermediateThrowEvent>
    <bpmn:sequenceFlow id="Flow_1tjsr8g" name="No" sourceRef="Gateway_1q36atg" targetRef="Event_0j39mxm" />
    <bpmn:sequenceFlow id="Flow_00emzc4" name="No" sourceRef="Gateway_18ywy9j" targetRef="Event_0j39mxm" />
    <bpmn:sequenceFlow id="Flow_03c6yay" name="Yes" sourceRef="Gateway_0e55p2y" targetRef="Activity_1qnpwn4" />
    <bpmn:sequenceFlow id="Flow_0he4kdx" sourceRef="Gateway_1dbrh0h" targetRef="Activity_0j0scw4" />
    <bpmn:sequenceFlow id="Flow_0v3lig2" sourceRef="Activity_0x1am58" targetRef="Event_0j39mxm" />
    <bpmn:sequenceFlow id="Flow_02txek1" sourceRef="Activity_1t8x5d5" targetRef="Event_0j39mxm" />
    <bpmn:sequenceFlow id="Flow_0qbp2y4" sourceRef="Event_0j39mxm" targetRef="Activity_1arg5f6" />
    <bpmn:serviceTask id="Activity_0x1am58" name="Mark event for sharing submission">
      <bpmn:extensionElements>
        <zeebe:taskDefinition type="sharing" />
      </bpmn:extensionElements>
      <bpmn:incoming>Flow_0vk6j62</bpmn:incoming>
      <bpmn:outgoing>Flow_0v3lig2</bpmn:outgoing>
    </bpmn:serviceTask>
    <bpmn:sequenceFlow id="Flow_11ewen6" sourceRef="Activity_1lf0pw5" targetRef="Gateway_1741pe0" />
    <bpmn:sequenceFlow id="Flow_1nofqpf" sourceRef="Activity_1lf0pw5" targetRef="Event_0j39mxm" />
    <bpmn:sequenceFlow id="Flow_1rqtcpj" name="No" sourceRef="Gateway_0e55p2y" targetRef="Event_0j39mxm" />
    <bpmn:sequenceFlow id="Flow_0vctmxd" name="No" sourceRef="Gateway_1741pe0" targetRef="Event_0j39mxm" />
    <bpmn:textAnnotation id="TextAnnotation_1v908s7">
      <bpmn:text>Wait until all previous gateways are complete.</bpmn:text>
    </bpmn:textAnnotation>
    <bpmn:association id="Association_1sp8otf" sourceRef="Event_0j39mxm" targetRef="TextAnnotation_1v908s7" />
  </bpmn:process>
  <bpmndi:BPMNDiagram id="BPMNDiagram_1">
    <bpmndi:BPMNPlane id="BPMNPlane_1" bpmnElement="Process_0rwiify">
      <bpmndi:BPMNShape id="_BPMNShape_StartEvent_2" bpmnElement="StartEvent_1">
        <dc:Bounds x="152" y="652" width="36" height="36" />
      </bpmndi:BPMNShape>
      <bpmndi:BPMNShape id="Activity_0izg76k_di" bpmnElement="Activity_0i6qxv4">
        <dc:Bounds x="260" y="630" width="100" height="80" />
      </bpmndi:BPMNShape>
      <bpmndi:BPMNShape id="Activity_1lm3dlw_di" bpmnElement="Activity_14rui20">
        <dc:Bounds x="454" y="630" width="100" height="80" />
      </bpmndi:BPMNShape>
      <bpmndi:BPMNShape id="Activity_0awioqd_di" bpmnElement="Activity_1xrsq3p">
        <dc:Bounds x="810" y="980" width="100" height="80" />
        <bpmndi:BPMNLabel />
      </bpmndi:BPMNShape>
      <bpmndi:BPMNShape id="Gateway_1q36atg_di" bpmnElement="Gateway_1q36atg" isMarkerVisible="true">
        <dc:Bounds x="1065" y="995" width="50" height="50" />
        <bpmndi:BPMNLabel>
          <dc:Bounds x="1046" y="971" width="88" height="14" />
        </bpmndi:BPMNLabel>
      </bpmndi:BPMNShape>
      <bpmndi:BPMNShape id="Activity_1tod2se_di" bpmnElement="Activity_1t8x5d5">
        <dc:Bounds x="1040" y="1110" width="100" height="80" />
      </bpmndi:BPMNShape>
      <bpmndi:BPMNShape id="Activity_1eviz3u_di" bpmnElement="Activity_0j0scw4">
        <dc:Bounds x="810" y="710" width="100" height="80" />
      </bpmndi:BPMNShape>
      <bpmndi:BPMNShape id="Gateway_18ywy9j_di" bpmnElement="Gateway_18ywy9j" isMarkerVisible="true">
        <dc:Bounds x="1065" y="725" width="50" height="50" />
        <bpmndi:BPMNLabel>
          <dc:Bounds x="1057" y="701" width="66" height="14" />
        </bpmndi:BPMNLabel>
      </bpmndi:BPMNShape>
      <bpmndi:BPMNShape id="Activity_1eji150_di" bpmnElement="Activity_05xs8h2">
        <dc:Bounds x="810" y="350" width="100" height="80" />
      </bpmndi:BPMNShape>
      <bpmndi:BPMNShape id="Activity_1qghkq8_di" bpmnElement="Activity_1gi6cid">
        <dc:Bounds x="810" y="100" width="100" height="80" />
      </bpmndi:BPMNShape>
      <bpmndi:BPMNShape id="Gateway_0e55p2y_di" bpmnElement="Gateway_0e55p2y" isMarkerVisible="true">
        <dc:Bounds x="1065" y="115" width="50" height="50" />
        <bpmndi:BPMNLabel>
          <dc:Bounds x="1051" y="77.5" width="78" height="27" />
        </bpmndi:BPMNLabel>
      </bpmndi:BPMNShape>
      <bpmndi:BPMNShape id="Activity_1phg19v_di" bpmnElement="Activity_1qnpwn4">
        <dc:Bounds x="1040" y="230" width="100" height="80" />
        <bpmndi:BPMNLabel />
      </bpmndi:BPMNShape>
      <bpmndi:BPMNShape id="Gateway_1741pe0_di" bpmnElement="Gateway_1741pe0" isMarkerVisible="true">
        <dc:Bounds x="1065" y="365" width="50" height="50" />
        <bpmndi:BPMNLabel>
          <dc:Bounds x="1059" y="327.5" width="62" height="27" />
        </bpmndi:BPMNLabel>
      </bpmndi:BPMNShape>
      <bpmndi:BPMNShape id="Gateway_1fusbbu_di" bpmnElement="Gateway_1dbrh0h">
        <dc:Bounds x="645" y="645" width="50" height="50" />
      </bpmndi:BPMNShape>
      <bpmndi:BPMNShape id="Activity_06md8et_di" bpmnElement="Activity_1lf0pw5">
        <dc:Bounds x="1040" y="490" width="100" height="80" />
        <bpmndi:BPMNLabel />
      </bpmndi:BPMNShape>
      <bpmndi:BPMNShape id="Activity_0wr7cxo_di" bpmnElement="Activity_1arg5f6">
        <dc:Bounds x="1610" y="630" width="100" height="80" />
        <bpmndi:BPMNLabel />
      </bpmndi:BPMNShape>
      <bpmndi:BPMNShape id="Event_0u4cpm8_di" bpmnElement="Event_0u4cpm8">
        <dc:Bounds x="1772" y="652" width="36" height="36" />
      </bpmndi:BPMNShape>
      <bpmndi:BPMNShape id="Event_0j39mxm_di" bpmnElement="Event_0j39mxm">
        <dc:Bounds x="1472" y="652" width="36" height="36" />
        <bpmndi:BPMNLabel>
          <dc:Bounds x="1400" y="656" width="62" height="27" />
        </bpmndi:BPMNLabel>
      </bpmndi:BPMNShape>
      <bpmndi:BPMNShape id="Activity_1ivchg6_di" bpmnElement="Activity_0x1am58">
        <dc:Bounds x="1040" y="840" width="100" height="80" />
        <bpmndi:BPMNLabel />
      </bpmndi:BPMNShape>
      <bpmndi:BPMNShape id="TextAnnotation_1v908s7_di" bpmnElement="TextAnnotation_1v908s7">
        <dc:Bounds x="1510" y="575" width="100" height="70" />
        <bpmndi:BPMNLabel />
      </bpmndi:BPMNShape>
      <bpmndi:BPMNEdge id="Flow_0d5ijy4_di" bpmnElement="Flow_0d5ijy4">
        <di:waypoint x="188" y="670" />
        <di:waypoint x="260" y="670" />
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Flow_0cm17qi_di" bpmnElement="Flow_0cm17qi">
        <di:waypoint x="360" y="670" />
        <di:waypoint x="454" y="670" />
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Flow_0qhjsdo_di" bpmnElement="Flow_0qhjsdo">
        <di:waypoint x="910" y="1020" />
        <di:waypoint x="1065" y="1020" />
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Flow_003k9rd_di" bpmnElement="Flow_003k9rd">
        <di:waypoint x="1090" y="1045" />
        <di:waypoint x="1090" y="1110" />
        <bpmndi:BPMNLabel>
          <dc:Bounds x="1097" y="1044" width="18" height="14" />
        </bpmndi:BPMNLabel>
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Flow_0yrea6c_di" bpmnElement="Flow_0yrea6c">
        <di:waypoint x="670" y="695" />
        <di:waypoint x="670" y="1020" />
        <di:waypoint x="810" y="1020" />
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Flow_0l5ibo6_di" bpmnElement="Flow_0l5ibo6">
        <di:waypoint x="910" y="750" />
        <di:waypoint x="1065" y="750" />
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Flow_0vk6j62_di" bpmnElement="Flow_0vk6j62">
        <di:waypoint x="1090" y="775" />
        <di:waypoint x="1090" y="840" />
        <bpmndi:BPMNLabel>
          <dc:Bounds x="1097" y="779" width="18" height="14" />
        </bpmndi:BPMNLabel>
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Flow_1i1c2gw_di" bpmnElement="Flow_1i1c2gw">
        <di:waypoint x="670" y="645" />
        <di:waypoint x="670" y="390" />
        <di:waypoint x="810" y="390" />
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Flow_1e2onuk_di" bpmnElement="Flow_1e2onuk">
        <di:waypoint x="670" y="645" />
        <di:waypoint x="670" y="140" />
        <di:waypoint x="810" y="140" />
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Flow_1wxjk4z_di" bpmnElement="Flow_1wxjk4z">
        <di:waypoint x="910" y="140" />
        <di:waypoint x="1065" y="140" />
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Flow_18fz62t_di" bpmnElement="Flow_18fz62t">
        <di:waypoint x="910" y="390" />
        <di:waypoint x="1065" y="390" />
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Flow_1ubazj5_di" bpmnElement="Flow_1ubazj5">
        <di:waypoint x="554" y="670" />
        <di:waypoint x="645" y="670" />
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Flow_1xgua59_di" bpmnElement="Flow_1xgua59">
        <di:waypoint x="1090" y="415" />
        <di:waypoint x="1090" y="490" />
        <bpmndi:BPMNLabel>
          <dc:Bounds x="1096" y="450" width="18" height="14" />
        </bpmndi:BPMNLabel>
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Flow_0kupuz3_di" bpmnElement="Flow_0kupuz3">
        <di:waypoint x="1140" y="270" />
        <di:waypoint x="1490" y="270" />
        <di:waypoint x="1490" y="650" />
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Flow_17sr46s_di" bpmnElement="Flow_17sr46s">
        <di:waypoint x="1710" y="670" />
        <di:waypoint x="1772" y="670" />
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Flow_1tjsr8g_di" bpmnElement="Flow_1tjsr8g">
        <di:waypoint x="1115" y="1020" />
        <di:waypoint x="1490" y="1020" />
        <di:waypoint x="1490" y="688" />
        <bpmndi:BPMNLabel>
          <dc:Bounds x="1122" y="1005" width="15" height="14" />
        </bpmndi:BPMNLabel>
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Flow_00emzc4_di" bpmnElement="Flow_00emzc4">
        <di:waypoint x="1115" y="750" />
        <di:waypoint x="1490" y="750" />
        <di:waypoint x="1490" y="688" />
        <bpmndi:BPMNLabel>
          <dc:Bounds x="1126" y="728" width="15" height="14" />
        </bpmndi:BPMNLabel>
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Flow_03c6yay_di" bpmnElement="Flow_03c6yay">
        <di:waypoint x="1090" y="165" />
        <di:waypoint x="1090" y="230" />
        <bpmndi:BPMNLabel>
          <dc:Bounds x="1097" y="197" width="18" height="14" />
        </bpmndi:BPMNLabel>
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Flow_0he4kdx_di" bpmnElement="Flow_0he4kdx">
        <di:waypoint x="670" y="695" />
        <di:waypoint x="670" y="750" />
        <di:waypoint x="810" y="750" />
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Flow_0v3lig2_di" bpmnElement="Flow_0v3lig2">
        <di:waypoint x="1140" y="880" />
        <di:waypoint x="1490" y="880" />
        <di:waypoint x="1490" y="688" />
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Flow_02txek1_di" bpmnElement="Flow_02txek1">
        <di:waypoint x="1140" y="1150" />
        <di:waypoint x="1490" y="1150" />
        <di:waypoint x="1490" y="688" />
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Flow_0qbp2y4_di" bpmnElement="Flow_0qbp2y4">
        <di:waypoint x="1508" y="670" />
        <di:waypoint x="1610" y="670" />
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Flow_11ewen6_di" bpmnElement="Flow_11ewen6">
        <di:waypoint x="1090" y="490" />
        <di:waypoint x="1090" y="415" />
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Flow_1nofqpf_di" bpmnElement="Flow_1nofqpf">
        <di:waypoint x="1140" y="530" />
        <di:waypoint x="1490" y="530" />
        <di:waypoint x="1490" y="652" />
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Flow_1rqtcpj_di" bpmnElement="Flow_1rqtcpj">
        <di:waypoint x="1115" y="140" />
        <di:waypoint x="1490" y="140" />
        <di:waypoint x="1490" y="652" />
        <bpmndi:BPMNLabel>
          <dc:Bounds x="1127" y="122" width="15" height="14" />
        </bpmndi:BPMNLabel>
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Flow_0vctmxd_di" bpmnElement="Flow_0vctmxd">
        <di:waypoint x="1115" y="390" />
        <di:waypoint x="1490" y="390" />
        <di:waypoint x="1490" y="652" />
        <bpmndi:BPMNLabel>
          <dc:Bounds x="1122" y="372" width="15" height="14" />
        </bpmndi:BPMNLabel>
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Association_1sp8otf_di" bpmnElement="Association_1sp8otf">
        <di:waypoint x="1502" y="657" />
        <di:waypoint x="1512" y="645" />
      </bpmndi:BPMNEdge>
    </bpmndi:BPMNPlane>
  </bpmndi:BPMNDiagram>
</bpmn:definitions>
", - "playbook_abstraction": "template", + "is_playbook_template": true, "playbook_creation_time": "2022-03-31T13:00:00.000Z", "playbook_modification_time": "2022-03-31T13:00:00.000Z", "revoked": false, @@ -1598,11 +1688,11 @@ "name": "Mitigate Incident", "description": "Analyst mitigates the alert by blocking malicious IPs, sharing data, and/or remediating the affected system.", "extensions": { - "extension-definition--BBC1D5C8-7DDC-4E89-BE9C-F33AD02D71DD": { + "extension-definition--bbc1d5c8-7ddc-4e89-be9c-f33ad02d71dd": { "extension_type": "property-extension", "playbooks": { - "CACAO": "x-oca-playbook--AE16A784-BAC9-4334-A09F-7CB63053A6D7", - "BPMN": "x-oca-playbook--720E5E68-3959-4EE0-99DE-87A4EAA39F44" + "x-oca-playbook--AE16A784-BAC9-4334-A09F-7CB63053A6D7": "application/cacao+json", + "x-oca-playbook--720E5E68-3959-4EE0-99DE-87A4EAA39F44": "BPMN" } } } @@ -1676,7 +1766,7 @@ "remediation" ], "playbook_bin": "ewogICAgInR5cGUiOiAicGxheWJvb2siLAogICAgInNwZWNfdmVyc2lvbiI6ICJjYWNhby0yLjAiLAogICAgImlkIjogInBsYXlib29rLS03NjdkODU5ZS03Mzg3LTRlMGMtOTVjMC00NThjYTM2OTQ4NmYiLAogICAgIm5hbWUiOiAiUHJvY2Vzc18xODExZjh3OiBRdWFyYW50aW5lIGFuZCBSZW1lZGlhdGUiLAogICAgImRlc2NyaXB0aW9uIjogIiIsCiAgICAicGxheWJvb2tfdHlwZXMiOiBbCiAgICAgICAgIm1pdGlnYXRpb24iLAogICAgICAgICJyZW1lZGlhdGlvbiIKICAgIF0sCiAgICAiY3JlYXRlZF9ieSI6ICJpZGVudGl0eS0tYjA4NWE2OGEtYmY0OC00MzE2LTk2NjctMzdhZjc4Y2JhODk0IiwKICAgICJjcmVhdGVkIjogIjIwMjItMDMtMzFUMTM6MDA6MDAuMDAwWiIsCiAgICAibW9kaWZpZWQiOiAiMjAyNC0wNC0xNVQwODo0MDowMC4wMDBaIiwKICAgICJ3b3JrZmxvd19zdGFydCI6ICJzdGFydC0tZWNlNTMyZGYtOTcwYS00MTdjLWExMjUtNWU3NzEzZTEwZjdjIiwKICAgICJ3b3JrZmxvdyI6IHsKICAgICAgICAic3RhcnQtLWVjZTUzMmRmLTk3MGEtNDE3Yy1hMTI1LTVlNzcxM2UxMGY3YyI6IHsKICAgICAgICAgICAgInR5cGUiOiAic3RhcnQiLAogICAgICAgICAgICAibmFtZSI6ICJTdGFydEV2ZW50XzE6IFN5c3RlbSBDb3Vyc2Ugb2YgQWN0aW9uIEFsZXJ0IiwKICAgICAgICAgICAgIm9uX2NvbXBsZXRpb24iOiAiYWN0aW9uLS1kMjI0MDhmYy1hOTljLTRjNDUtODc3MC0yN2RhYzZkZjI5M2EiCiAgICAgICAgfSwKICAgICAgICAiZW5kLS00ZDMxMzRkOS02OGQyLTRiZGUtODdjYS1hNWJmZTg0NjhhYTYiOiB7CiAgICAgICAgICAgICJ0eXBlIjogImVuZCIsCiAgICAgICAgICAgICJuYW1lIjogIkV2ZW50XzE3enBzbjU6IEVuZCIKICAgICAgICB9LAogICAgICAgICJhY3Rpb24tLWQyMjQwOGZjLWE5OWMtNGM0NS04NzcwLTI3ZGFjNmRmMjkzYSI6IHsKICAgICAgICAgICAgInR5cGUiOiAiYWN0aW9uIiwKICAgICAgICAgICAgIm5hbWUiOiAiQWN0aXZpdHlfMXZ2OHl5ejogUXVhcmFudGluZSBzeXN0ZW0iLAogICAgICAgICAgICAiY29tbWFuZHMiOiBbCiAgICAgICAgICAgICAgICB7CiAgICAgICAgICAgICAgICAgICAgInR5cGUiOiAiaHR0cC1hcGkiCiAgICAgICAgICAgICAgICB9CiAgICAgICAgICAgIF0sCiAgICAgICAgICAgICJvbl9jb21wbGV0aW9uIjogImFjdGlvbi0tZDFkMTVhYjctYjU1Ny00ZjgyLThkOWItNDk1NDM4YTVjOWE5IgogICAgICAgIH0sCiAgICAgICAgImFjdGlvbi0tZDFkMTVhYjctYjU1Ny00ZjgyLThkOWItNDk1NDM4YTVjOWE5IjogewogICAgICAgICAgICAidHlwZSI6ICJhY3Rpb24iLAogICAgICAgICAgICAibmFtZSI6ICJBY3Rpdml0eV8waTkxZ2VuOiBDcmVhdGUgdGlja2V0IiwKICAgICAgICAgICAgImNvbW1hbmRzIjogWwogICAgICAgICAgICAgICAgewogICAgICAgICAgICAgICAgICAgICJ0eXBlIjogImh0dHAtYXBpIgogICAgICAgICAgICAgICAgfQogICAgICAgICAgICBdLAogICAgICAgICAgICAib25fY29tcGxldGlvbiI6ICJhY3Rpb24tLTNlZmJlMDU2LTZkMWUtNDQwNy04OWJiLWJiNTQwMTZkOWRlYSIKICAgICAgICB9LAogICAgICAgICJhY3Rpb24tLTNlZmJlMDU2LTZkMWUtNDQwNy04OWJiLWJiNTQwMTZkOWRlYSI6IHsKICAgICAgICAgICAgInR5cGUiOiAiYWN0aW9uIiwKICAgICAgICAgICAgIm5hbWUiOiAiQWN0aXZpdHlfMWpmeWcweTogQ29tbWVudCBpbiB0aWNrZXQgdGhhdCBzeXN0ZW0gaXMgcXVhcmFudGluZWQiLAogICAgICAgICAgICAiY29tbWFuZHMiOiBbCiAgICAgICAgICAgICAgICB7CiAgICAgICAgICAgICAgICAgICAgInR5cGUiOiAiaHR0cC1hcGkiCiAgICAgICAgICAgICAgICB9CiAgICAgICAgICAgIF0sCiAgICAgICAgICAgICJvbl9jb21wbGV0aW9uIjogImFjdGlvbi0tMjdmODI3OGMtOGI4Ny00ODE1LThmNDAtOWM2YWY2MTAyMDNlIgogICAgICAgIH0sCiAgICAgICAgImFjdGlvbi0tZmVjNTZkM2QtNDdhNC00ZjRiLWEwYTctZWI0MjY5OGMxZThiIjogewogICAgICAgICAgICAidHlwZSI6ICJhY3Rpb24iLAogICAgICAgICAgICAibmFtZSI6ICJBY3Rpdml0eV8wdXZtY25lOiBSZW1vdmUgcXVhcmFudGluZSBmcm9tIHN5c3RlbSIsCiAgICAgICAgICAgICJjb21tYW5kcyI6IFsKICAgICAgICAgICAgICAgIHsKICAgICAgICAgICAgICAgICAgICAidHlwZSI6ICJodHRwLWFwaSIKICAgICAgICAgICAgICAgIH0KICAgICAgICAgICAgXSwKICAgICAgICAgICAgIm9uX2NvbXBsZXRpb24iOiAiYWN0aW9uLS0zZjBlODNkYS01YzM3LTQ4MTYtOWQ4ZS03ZjU1ZWY0Yjc3YTQiCiAgICAgICAgfSwKICAgICAgICAiYWN0aW9uLS0zZjBlODNkYS01YzM3LTQ4MTYtOWQ4ZS03ZjU1ZWY0Yjc3YTQiOiB7CiAgICAgICAgICAgICJ0eXBlIjogImFjdGlvbiIsCiAgICAgICAgICAgICJuYW1lIjogIkFjdGl2aXR5XzF1ZnUwZHM6IENvbW1lbnQgaW4gdGlja2V0IHRoYXQgc3lzdGVtIGlzIHJlc3RvcmVkIGFuZCB0aGUgcXVhcmFudGluZSBpcyByZW1vdmVkIiwKICAgICAgICAgICAgImNvbW1hbmRzIjogWwogICAgICAgICAgICAgICAgewogICAgICAgICAgICAgICAgICAgICJ0eXBlIjogImh0dHAtYXBpIgogICAgICAgICAgICAgICAgfQogICAgICAgICAgICBdLAogICAgICAgICAgICAib25fY29tcGxldGlvbiI6ICJhY3Rpb24tLWI3OTE4MTM0LTM4MDctNDQzMi1iNDdlLThhNGZlZjI2ODAzNSIKICAgICAgICB9LAogICAgICAgICJhY3Rpb24tLWI3OTE4MTM0LTM4MDctNDQzMi1iNDdlLThhNGZlZjI2ODAzNSI6IHsKICAgICAgICAgICAgInR5cGUiOiAiYWN0aW9uIiwKICAgICAgICAgICAgIm5hbWUiOiAiQWN0aXZpdHlfMDd2cmlleTogQ2xvc2UgdGlja2V0IiwKICAgICAgICAgICAgImNvbW1hbmRzIjogWwogICAgICAgICAgICAgICAgewogICAgICAgICAgICAgICAgICAgICJ0eXBlIjogImh0dHAtYXBpIgogICAgICAgICAgICAgICAgfQogICAgICAgICAgICBdLAogICAgICAgICAgICAib25fY29tcGxldGlvbiI6ICJlbmQtLTRkMzEzNGQ5LTY4ZDItNGJkZS04N2NhLWE1YmZlODQ2OGFhNiIKICAgICAgICB9LAogICAgICAgICJhY3Rpb24tLTczZmNiZWQ0LTM5M2ItNGJjZC04OGUyLTY5MzE0YzhlODI3YyI6IHsKICAgICAgICAgICAgInR5cGUiOiAiYWN0aW9uIiwKICAgICAgICAgICAgIm5hbWUiOiAiQWN0aXZpdHlfMTUyNjY4bjogU09DIGFuYWx5c3QgcmVzdG9yZXMgYWZmZWN0ZWQgc3lzdGVtIiwKICAgICAgICAgICAgImNvbW1hbmRzIjogWwogICAgICAgICAgICAgICAgewogICAgICAgICAgICAgICAgICAgICJ0eXBlIjogIm1hbnVhbCIKICAgICAgICAgICAgICAgIH0KICAgICAgICAgICAgXSwKICAgICAgICAgICAgIm9uX2NvbXBsZXRpb24iOiAiYWN0aW9uLS1mZWM1NmQzZC00N2E0LTRmNGItYTBhNy1lYjQyNjk4YzFlOGIiCiAgICAgICAgfSwKICAgICAgICAiYWN0aW9uLS0yN2Y4Mjc4Yy04Yjg3LTQ4MTUtOGY0MC05YzZhZjYxMDIwM2UiOiB7CiAgICAgICAgICAgICJ0eXBlIjogImFjdGlvbiIsCiAgICAgICAgICAgICJuYW1lIjogIkFjdGl2aXR5XzEybG4xb3M6IFNlbmQgZW1haWwgdG8gU09DIGFuYWx5c3QgdG8gcmV2aWV3IHRpY2tldCIsCiAgICAgICAgICAgICJjb21tYW5kcyI6IFsKICAgICAgICAgICAgICAgIHsKICAgICAgICAgICAgICAgICAgICAidHlwZSI6ICJodHRwLWFwaSIKICAgICAgICAgICAgICAgIH0KICAgICAgICAgICAgXSwKICAgICAgICAgICAgIm9uX2NvbXBsZXRpb24iOiAiYWN0aW9uLS03M2ZjYmVkNC0zOTNiLTRiY2QtODhlMi02OTMxNGM4ZTgyN2MiCiAgICAgICAgfQogICAgfQp9", - "playbook_abstraction": "template", + "is_playbook_template": true, "playbook_creation_time": "2022-03-31T13:00:00.000Z", "playbook_modification_time": "2022-03-31T13:00:00.000Z", "revoked": false, @@ -1701,7 +1791,7 @@ "remediation" ], "playbook_bin": "<?xml version="1.0" encoding="UTF-8"?>
<bpmn:definitions xmlns:bpmn="http://www.omg.org/spec/BPMN/20100524/MODEL" xmlns:bpmndi="http://www.omg.org/spec/BPMN/20100524/DI" xmlns:dc="http://www.omg.org/spec/DD/20100524/DC" xmlns:zeebe="http://camunda.org/schema/zeebe/1.0" xmlns:di="http://www.omg.org/spec/DD/20100524/DI" xmlns:modeler="http://camunda.org/schema/modeler/1.0" id="Definitions_13utk9b" targetNamespace="http://bpmn.io/schema/bpmn" exporter="Camunda Modeler" exporterVersion="5.5.1" modeler:executionPlatform="Camunda Cloud" modeler:executionPlatformVersion="8.1.0">
  <bpmn:process id="Process_1811f8w" name="System course of action alert" isExecutable="true">
    <bpmn:startEvent id="StartEvent_1" name="System Course of Action Alert">
      <bpmn:outgoing>Flow_1j1g7dh</bpmn:outgoing>
    </bpmn:startEvent>
    <bpmn:sequenceFlow id="Flow_1rqtirl" sourceRef="Activity_0i91gen" targetRef="Activity_1jfyg0y" />
    <bpmn:sequenceFlow id="Flow_1j1g7dh" sourceRef="StartEvent_1" targetRef="Activity_1vv8yyz" />
    <bpmn:serviceTask id="Activity_1vv8yyz" name="Quarantine system">
      <bpmn:extensionElements>
        <zeebe:taskDefinition type="edr" />
      </bpmn:extensionElements>
      <bpmn:incoming>Flow_1j1g7dh</bpmn:incoming>
      <bpmn:outgoing>Flow_0gl1nqo</bpmn:outgoing>
    </bpmn:serviceTask>
    <bpmn:serviceTask id="Activity_0i91gen" name="Create ticket">
      <bpmn:extensionElements>
        <zeebe:taskDefinition type="ticketing" />
      </bpmn:extensionElements>
      <bpmn:incoming>Flow_0gl1nqo</bpmn:incoming>
      <bpmn:outgoing>Flow_1rqtirl</bpmn:outgoing>
    </bpmn:serviceTask>
    <bpmn:serviceTask id="Activity_1jfyg0y" name="Comment in ticket that system is quarantined">
      <bpmn:extensionElements>
        <zeebe:taskDefinition type="ticketing" />
      </bpmn:extensionElements>
      <bpmn:incoming>Flow_1rqtirl</bpmn:incoming>
      <bpmn:outgoing>Flow_00721h8</bpmn:outgoing>
    </bpmn:serviceTask>
    <bpmn:sequenceFlow id="Flow_00721h8" sourceRef="Activity_1jfyg0y" targetRef="Activity_12ln1os" />
    <bpmn:sequenceFlow id="Flow_0ear087" sourceRef="Activity_12ln1os" targetRef="Activity_152668n" />
    <bpmn:sequenceFlow id="Flow_1csb0ol" sourceRef="Activity_152668n" targetRef="Activity_0uvmcne" />
    <bpmn:serviceTask id="Activity_0uvmcne" name="Remove quarantine from system">
      <bpmn:extensionElements>
        <zeebe:taskDefinition type="edr" />
      </bpmn:extensionElements>
      <bpmn:incoming>Flow_1csb0ol</bpmn:incoming>
      <bpmn:outgoing>Flow_1ce8qul</bpmn:outgoing>
    </bpmn:serviceTask>
    <bpmn:sendTask id="Activity_12ln1os" name="Send email to SOC analyst to review ticket">
      <bpmn:extensionElements>
        <zeebe:taskDefinition type="email" />
      </bpmn:extensionElements>
      <bpmn:incoming>Flow_00721h8</bpmn:incoming>
      <bpmn:outgoing>Flow_0ear087</bpmn:outgoing>
    </bpmn:sendTask>
    <bpmn:userTask id="Activity_152668n" name="SOC analyst restores affected system">
      <bpmn:incoming>Flow_0ear087</bpmn:incoming>
      <bpmn:outgoing>Flow_1csb0ol</bpmn:outgoing>
    </bpmn:userTask>
    <bpmn:sequenceFlow id="Flow_1ce8qul" sourceRef="Activity_0uvmcne" targetRef="Activity_1ufu0ds" />
    <bpmn:serviceTask id="Activity_1ufu0ds" name="Comment in ticket that system is restored and the quarantine is removed">
      <bpmn:extensionElements>
        <zeebe:taskDefinition type="ticketing" />
      </bpmn:extensionElements>
      <bpmn:incoming>Flow_1ce8qul</bpmn:incoming>
      <bpmn:outgoing>Flow_0h0stnb</bpmn:outgoing>
    </bpmn:serviceTask>
    <bpmn:sequenceFlow id="Flow_0h0stnb" sourceRef="Activity_1ufu0ds" targetRef="Activity_07vriey" />
    <bpmn:serviceTask id="Activity_07vriey" name="Close ticket">
      <bpmn:extensionElements>
        <zeebe:taskDefinition type="ticketing" />
      </bpmn:extensionElements>
      <bpmn:incoming>Flow_0h0stnb</bpmn:incoming>
      <bpmn:outgoing>Flow_0vij8zg</bpmn:outgoing>
    </bpmn:serviceTask>
    <bpmn:endEvent id="Event_17zpsn5">
      <bpmn:incoming>Flow_0vij8zg</bpmn:incoming>
    </bpmn:endEvent>
    <bpmn:sequenceFlow id="Flow_0vij8zg" sourceRef="Activity_07vriey" targetRef="Event_17zpsn5" />
    <bpmn:sequenceFlow id="Flow_0gl1nqo" sourceRef="Activity_1vv8yyz" targetRef="Activity_0i91gen" />
  </bpmn:process>
  <bpmndi:BPMNDiagram id="BPMNDiagram_1">
    <bpmndi:BPMNPlane id="BPMNPlane_1" bpmnElement="Process_1811f8w">
      <bpmndi:BPMNShape id="Event_17zpsn5_di" bpmnElement="Event_17zpsn5">
        <dc:Bounds x="1432" y="112" width="36" height="36" />
      </bpmndi:BPMNShape>
      <bpmndi:BPMNShape id="Activity_10ax69p_di" bpmnElement="Activity_07vriey">
        <dc:Bounds x="1280" y="90" width="100" height="80" />
      </bpmndi:BPMNShape>
      <bpmndi:BPMNShape id="Activity_0l0an5u_di" bpmnElement="Activity_1ufu0ds">
        <dc:Bounds x="1130" y="90" width="100" height="80" />
      </bpmndi:BPMNShape>
      <bpmndi:BPMNShape id="Activity_0kkfmu7_di" bpmnElement="Activity_0uvmcne">
        <dc:Bounds x="990" y="90" width="100" height="80" />
        <bpmndi:BPMNLabel />
      </bpmndi:BPMNShape>
      <bpmndi:BPMNShape id="Activity_0phah95_di" bpmnElement="Activity_152668n">
        <dc:Bounds x="850" y="90" width="100" height="80" />
      </bpmndi:BPMNShape>
      <bpmndi:BPMNShape id="Activity_1esedms_di" bpmnElement="Activity_12ln1os">
        <dc:Bounds x="700" y="90" width="100" height="80" />
      </bpmndi:BPMNShape>
      <bpmndi:BPMNShape id="Activity_001did5_di" bpmnElement="Activity_1jfyg0y">
        <dc:Bounds x="540" y="90" width="100" height="80" />
      </bpmndi:BPMNShape>
      <bpmndi:BPMNShape id="Activity_0swry56_di" bpmnElement="Activity_0i91gen">
        <dc:Bounds x="380" y="90" width="100" height="80" />
        <bpmndi:BPMNLabel />
      </bpmndi:BPMNShape>
      <bpmndi:BPMNShape id="Activity_05x6d93_di" bpmnElement="Activity_1vv8yyz">
        <dc:Bounds x="230" y="90" width="100" height="80" />
        <bpmndi:BPMNLabel />
      </bpmndi:BPMNShape>
      <bpmndi:BPMNShape id="_BPMNShape_StartEvent_2" bpmnElement="StartEvent_1">
        <dc:Bounds x="142" y="112" width="36" height="36" />
        <bpmndi:BPMNLabel>
          <dc:Bounds x="116" y="82" width="88" height="27" />
        </bpmndi:BPMNLabel>
      </bpmndi:BPMNShape>
      <bpmndi:BPMNEdge id="Flow_1rqtirl_di" bpmnElement="Flow_1rqtirl">
        <di:waypoint x="480" y="130" />
        <di:waypoint x="540" y="130" />
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Flow_1j1g7dh_di" bpmnElement="Flow_1j1g7dh">
        <di:waypoint x="178" y="130" />
        <di:waypoint x="230" y="130" />
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Flow_00721h8_di" bpmnElement="Flow_00721h8">
        <di:waypoint x="640" y="130" />
        <di:waypoint x="700" y="130" />
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Flow_0ear087_di" bpmnElement="Flow_0ear087">
        <di:waypoint x="800" y="130" />
        <di:waypoint x="850" y="130" />
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Flow_1csb0ol_di" bpmnElement="Flow_1csb0ol">
        <di:waypoint x="950" y="130" />
        <di:waypoint x="990" y="130" />
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Flow_1ce8qul_di" bpmnElement="Flow_1ce8qul">
        <di:waypoint x="1090" y="130" />
        <di:waypoint x="1130" y="130" />
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Flow_0h0stnb_di" bpmnElement="Flow_0h0stnb">
        <di:waypoint x="1230" y="130" />
        <di:waypoint x="1280" y="130" />
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Flow_0vij8zg_di" bpmnElement="Flow_0vij8zg">
        <di:waypoint x="1380" y="130" />
        <di:waypoint x="1432" y="130" />
      </bpmndi:BPMNEdge>
      <bpmndi:BPMNEdge id="Flow_0gl1nqo_di" bpmnElement="Flow_0gl1nqo">
        <di:waypoint x="330" y="130" />
        <di:waypoint x="380" y="130" />
      </bpmndi:BPMNEdge>
    </bpmndi:BPMNPlane>
  </bpmndi:BPMNDiagram>
</bpmn:definitions>
", - "playbook_abstraction": "template", + "is_playbook_template": true, "playbook_creation_time": "2022-03-31T13:00:00.000Z", "playbook_modification_time": "2022-03-31T13:00:00.000Z", "revoked": false, @@ -1721,11 +1811,11 @@ "name": "Quarantine and remediate", "description": "Remediate by quarantining and performing analyst guided steps", "extensions": { - "extension-definition--BBC1D5C8-7DDC-4E89-BE9C-F33AD02D71DD": { + "extension-definition--bbc1d5c8-7ddc-4e89-be9c-f33ad02d71dd": { "extension_type": "property-extension", "playbooks": { - "CACAO": "x-oca-playbook--9880DF48-09A7-4E99-8070-0DB8F4C946D0", - "BPMN": "x-oca-playbook--32F52089-9943-4231-BBA3-5C02BA654755" + "x-oca-playbook--9880DF48-09A7-4E99-8070-0DB8F4C946D0": "application/cacao+json", + "x-oca-playbook--32F52089-9943-4231-BBA3-5C02BA654755": "BPMN" } } } @@ -1773,32 +1863,28 @@ { "type": "extension-definition", "spec_version": "2.1", - "id": "extension-definition--809C4D84-7A6E-4039-97B4-DA9FEA03FCF9", + "id": "extension-definition--809c4d84-7a6e-4039-97b4-da9fea03fcf9", "created_by_ref": "identity--b085a68a-bf48-4316-9667-37af78cba894", "created": "2022-03-31T13:00:00.000Z", - "modified": "2022-03-31T13:00:00.000Z", + "modified": "2024-05-16T12:44:08.273Z", "name": "x-oca-playbook Extension Definition", - "description": "This schema creates a new object type called x-oca-playbook.", - "schema": "https://raw.githubusercontent.com/opencybersecurityalliance/oca-iob/main/apl_reference_implementation_bundle/revision_2/schemas/sdos/playbook.json", - "version": "1.0.0", - "extension_types": [ - "new-sdo" - ] + "description": "This definition introduces a new object type, x-oca-playbook, for sharing security playbooks.", + "schema": "https://raw.githubusercontent.com/opencybersecurityalliance/stix-extensions/main/2.x/schemas/x-oca-playbook.json", + "version": "4.0.0", + "extension_types": ["new-sdo"] }, { "type": "extension-definition", "spec_version": "2.1", - "id": "extension-definition--BBC1D5C8-7DDC-4E89-BE9C-F33AD02D71DD", + "id": "extension-definition--bbc1d5c8-7ddc-4e89-be9c-f33ad02d71dd", "created_by_ref": "identity--b085a68a-bf48-4316-9667-37af78cba894", "created": "2022-03-31T13:00:00.000Z", - "modified": "2022-03-31T13:00:00.000Z", - "name": "x-oca-coa-playbook Extension Definition", - "description": "This schema extends the Course of Action SDO with playbook information.", - "schema": "https://raw.githubusercontent.com/opencybersecurityalliance/oca-iob/main/apl_reference_implementation_bundle/revision_2/schemas/sdos/course-of-action.json", - "version": "1.0.0", - "extension_types": [ - "property-extension" - ] + "modified": "2024-05-16T12:44:08.273Z", + "name": "x-oca-coa-playbook-ext Extension Definition", + "description": "This definition extends the COA SDO with playbook references.", + "schema": "https://raw.githubusercontent.com/opencybersecurityalliance/stix-extensions/main/2.x/schemas/x-oca-coa-playbook-ext.json", + "version": "4.0.0", + "extension_types": ["property-extension"] }, { "type": "extension-definition", diff --git a/apl_reference_implementation_bundle/revision_3/schemas/sdos/x-oca-behavior.json b/apl_reference_implementation_bundle/revision_3/schemas/sdos/x-oca-behavior.json new file mode 100644 index 0000000..2489699 --- /dev/null +++ b/apl_reference_implementation_bundle/revision_3/schemas/sdos/x-oca-behavior.json @@ -0,0 +1,69 @@ +{ + "$id": "https://raw.githubusercontent.com/opencybersecurityalliance/stix-extensions/main/2.x/schemas/x-oca-behavior.json", + "$schema": "http://json-schema.org/draft/2020-12/schema#", + "title": "x-oca-behavior", + "description": "Behavior objects define adversary behaviors associated with higher level MITRE ATT&CK tactics and techniques. The Attack Pattern SDO may have multiple behaviors associated with it. For example, a spearphishing attack may employ multiple behaviors (usage of email attachments, process modifying a registry key, network patterns, etc.).", + "type": "object", + "allOf": [ + { + "$ref": "https://raw.githubusercontent.com/oasis-open/cti-stix2-json-schemas/master/schemas/common/core.json" + }, + { + "properties": { + "type": { + "type": "string", + "description": "The type of this object, which MUST be the literal `x-oca-behavior`.", + "enum": [ + "x-oca-behavior" + ] + }, + "id": { + "title": "id", + "pattern": "^x-oca-behavior--" + }, + "name": { + "type": "string", + "description": "The name used to identify the Behavior." + }, + "description": { + "type": "string", + "description": "Description of Behavior." + }, + "behavior_class": { + "type": "string", + "description": "The class of behavior. The value for this property SHOULD come from the behavior-class-ov open vocabulary." + }, + "tactic": { + "type": "string", + "description": "MITRE ATT&CK tactic of the Behavior." + }, + "technique": { + "type": "string", + "description": "MITRE ATT&CK technique of the Behavior." + }, + "first_seen": { + "description": "The first_seen property represents the time that this behavior was first seen. The timstamp value MUST be precise to the nearest millisecond.", + "allOf": [ + { + "$ref": "https://raw.githubusercontent.com/oasis-open/cti-stix2-json-schemas/master/schemas/common/timestamp.json" + }, + { + "title": "timestamp_millis", + "pattern": "T\\d{2}:\\d{2}:\\d{2}\\.\\d{3,}Z$" + } + ] + }, + "platforms": { + "type": "array", + "description": "Platforms the Behavior was seen on. Each entry may list contextual data about the platform such as the OS and OS version number.", + "items": { + "$ref": "https://raw.githubusercontent.com/oasis-open/cti-stix2-json-schemas/master/schemas/common/dictionary.json" + } + } + } + } + ], + "required": [ + "name" + ] +} \ No newline at end of file diff --git a/apl_reference_implementation_bundle/revision_3/schemas/sdos/x-oca-coa-playbook-ext.json b/apl_reference_implementation_bundle/revision_3/schemas/sdos/x-oca-coa-playbook-ext.json new file mode 100644 index 0000000..3aa9a69 --- /dev/null +++ b/apl_reference_implementation_bundle/revision_3/schemas/sdos/x-oca-coa-playbook-ext.json @@ -0,0 +1,44 @@ +{ + "$id": "https://raw.githubusercontent.com/opencybersecurityalliance/stix-extensions/main/2.x/schemas/x-oca-coa-playbook-ext.json", + "$schema": "http://json-schema.org/draft/2020-12/schema#", + "title": "x-oca-coa-playbook-ext", + "description": "A property extension for the Course of Action SDO for sharing automated courses of action (i.e., orchestration workflows or playbooks).", + "type": "object", + "allOf": [ + { + "$ref": "https://github.com/oasis-open/cti-stix2-json-schemas/blob/master/schemas/sdos/course-of-action.json" + }, + { + "properties": { + "extensions": { + "type": "object", + "properties": { + "extension-definition--bbc1d5c8-7ddc-4e89-be9c-f33ad02d71dd": { + "type": "object", + "properties": { + "extension_type": { + "type": "string", + "description": "The value of this property MUST be 'property-extension'.", + "enum": ["property-extension"] + }, + "playbooks": { + "type": "object", + "description": "The dictionary key is the UUID of a STIX 2.1 playbook object. The dictionary value is the playbook format (e.g., application/cacao+json, bpmn).\n\n When possible, this value SHOULD come from the values defined in the Template column of the IANA media type registry [Media Types]. For example, if a playbook is provided as an image in png format, the value following the IANA media type registry MUST be 'image/png'. Another example is CACAO security playbooks, where in [CACAO-Security-Playbooks-v2.0] Appendix C. IANA Considerations, the following media type is defined: 'application/cacao+json'", + "minProperties": 1, + "patternProperties": { + "^x-oca-playbook--[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-5][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}$": { + "type": "string" + } + } + } + }, + "required": ["extension_type"] + } + }, + "required": ["extension-definition--bbc1d5c8-7ddc-4e89-be9c-f33ad02d71dd"] + } + } + } + ], + "required": ["extensions"] + } \ No newline at end of file diff --git a/apl_reference_implementation_bundle/revision_3/schemas/sdos/x-oca-detection.json b/apl_reference_implementation_bundle/revision_3/schemas/sdos/x-oca-detection.json new file mode 100644 index 0000000..cc96027 --- /dev/null +++ b/apl_reference_implementation_bundle/revision_3/schemas/sdos/x-oca-detection.json @@ -0,0 +1,60 @@ +{ + "$id": "https://raw.githubusercontent.com/opencybersecurityalliance/stix-extensions/main/2.x/schemas/x-oca-detection.json", + "$schema": "http://json-schema.org/draft/2020-12/schema#", + "title": "x-oca-detection", + "description": "Detections contain logic to detect an adversary behavior.", + "type": "object", + "allOf": [ + { + "$ref": "https://raw.githubusercontent.com/oasis-open/cti-stix2-json-schemas/master/schemas/common/core.json" + }, + { + "properties": { + "type": { + "type": "string", + "description": "The type of this object, which MUST be the literal `x-oca-detection`.", + "enum": [ + "x-oca-detection" + ] + + }, + "id": { + "type": "string", + "pattern": "^x-oca-detection--" + }, + "name": { + "type": "string", + "description": "The name used to identify the detection." + }, + "data_sources": { + "type": "array", + "description": "Information about the data event that the detection targets.", + "items": { + "$ref": "https://raw.githubusercontent.com/oasis-open/cti-stix2-json-schemas/master/schemas/common/dictionary.json" + } + }, + "analytic": { + "type": "object", + "description": "Base64 encoded logic defining the detection along with the type of rule (e.g. Sigma rule).", + "properties": { + "rule": { + "type": "string" + }, + "type": { + "type": "string" + } + }, + "required": [ + "rule", + "type" + ] + } + } + } + ], + "required": [ + "name", + "data_sources", + "analytic" + ] +} \ No newline at end of file diff --git a/apl_reference_implementation_bundle/revision_3/schemas/sdos/x-oca-detector.json b/apl_reference_implementation_bundle/revision_3/schemas/sdos/x-oca-detector.json new file mode 100644 index 0000000..4026527 --- /dev/null +++ b/apl_reference_implementation_bundle/revision_3/schemas/sdos/x-oca-detector.json @@ -0,0 +1,94 @@ +{ + "$id": "https://raw.githubusercontent.com/opencybersecurityalliance/stix-extensions/main/2.x/schemas/x-oca-detector.json", + "$schema": "http://json-schema.org/draft/2020-12/schema#", + "title": "x-oca-detector", + "description": "Detector objects define tools, software, products, etc. that are capable of performing detection. They should likely be related to one or more Detection obects.", + "type": "object", + "allOf": [ + { + "$ref": "https://raw.githubusercontent.com/oasis-open/cti-stix2-json-schemas/master/schemas/common/core.json" + }, + { + "properties": { + "type": { + "type": "string", + "description": "The type of this object, which MUST be the literal `x-oca-detector`.", + "enum": [ + "x-oca-detector" + ] + }, + "id": { + "title": "id", + "pattern": "^x-oca-detector--" + }, + "name": { + "type": "string", + "description": "The name used to identify the Detector." + }, + "description": { + "type": "string", + "description": "Description of Detector." + }, + "cpe": { + "type": "string", + "description": "A valid CPE string." + }, + "valid_until": { + "description": "The time at which this Detector should no longer be considered valuable intelligence.", + "allOf": [ + { + "$ref": "https://raw.githubusercontent.com/oasis-open/cti-stix2-json-schemas/master/schemas/common/timestamp.json" + }, + { + "title": "timestamp_millis", + "pattern": "T\\d{2}:\\d{2}:\\d{2}\\.\\d{3,}Z$" + } + ] + }, + "vendor": { + "type": "string", + "description": "The vendor name of the Detector." + }, + "vendor_url": { + "type": "string", + "description": "A URL that links to the vendor of the Detector's primary website." + }, + "product": { + "type": "string", + "description": "The product name of the Detector." + }, + "product_url": { + "type": "string", + "description": "A URL that links to an official download of the Detector product or a primary website describing the Detector product." + }, + "detection_types": { + "type": "array", + "description": "A list of the types of detections the detector can perform. For example: beacon, phishing, exfiltration.", + "items": { + "type": "string" + }, + "minItems": 1 + }, + "detector_data_categories": { + "type": "array", + "description": "A list of the general categories of data the detector uses. For example: network, endpoint, etc.", + "items": { + "type": "string" + }, + "minItems": 1 + }, + "detector_data_sources": { + "type": "array", + "description": "A list of the specific data sources the detector uses. For example: pcap, windows security event logs, sysmon, etc.", + "items": { + "type": "string" + }, + "minItems": 1 + } + } + } + ], + "required": [ + "name" + ] +} \ No newline at end of file diff --git a/apl_reference_implementation_bundle/revision_3/schemas/sdos/x-oca-playbook.json b/apl_reference_implementation_bundle/revision_3/schemas/sdos/x-oca-playbook.json new file mode 100644 index 0000000..2d3e3e9 --- /dev/null +++ b/apl_reference_implementation_bundle/revision_3/schemas/sdos/x-oca-playbook.json @@ -0,0 +1,110 @@ +{ + "$id": "https://raw.githubusercontent.com/opencybersecurityalliance/stix-extensions/main/2.x/schemas/x-oca-playbook.json", + "$schema": "http://json-schema.org/draft/2020-12/schema#", + "title": "x-oca-playbook", + "description": "A Playbook object represents a structured process, such as an orchestration workflow, alongside associated metadata.", + "type": "object", + "allOf": [ + { + "$ref": "https://raw.githubusercontent.com/oasis-open/cti-stix2-json-schemas/master/schemas/common/core.json" + }, + { + "properties": { + "type": { + "type": "string", + "description": "The value of this property MUST be 'x-oca-playbook'.", + "enum": ["x-oca-playbook"] + }, + "id": { + "type": "string", + "pattern": "^x-oca-playbook--" + }, + "name": { + "type": "string", + "description": "The name used to identify the playbook." + }, + "description": { + "type": "string", + "description": "An explanation, details, and more context about what this playbook does and tries to accomplish." + }, + "playbook_id": { + "type": "string", + "description": "A value that identifies the playbook. \n\nIf the playbook (itself) includes an identifier, then 'playbook_id' SHOULD use the same identifier for correlation purposes. It is recommended to use either UUIDv4 or deterministic UUIDv5 identifiers — if supported." + }, + "playbook_creator": { + "$ref": "https://raw.githubusercontent.com/oasis-open/cti-stix2-json-schemas/master/schemas/common/identifier.json", + "description": "The identifier of SDO identity that created the playbook. \n\nIf this object references a CACAO v2.0 playbook, then the value of this property SHOULD match the value of the created_by property in the CACAO playbook." + }, + "playbook_creation_time": { + "$ref": "https://raw.githubusercontent.com/oasis-open/cti-stix2-json-schemas/master/schemas/common/timestamp.json", + "description": "The time at which the playbook was originally created. \n\nIf this object references a CACAO v2.0 playbook, then the value of this property SHOULD match the value of the created property in the CACAO playbook." + }, + "playbook_modification_time": { + "$ref": "https://raw.githubusercontent.com/oasis-open/cti-stix2-json-schemas/master/schemas/common/timestamp.json", + "description": "The time at which the playbook was last modified. \n\nIf this object references a CACAO v2.0 playbook, then the value of this property SHOULD match the value of the modified property in the CACAO playbook." + }, + "organization_type": { + "type": "array", + "items": { + "type": "string" + }, + "minItems": 1, + "description": "The type of organization that the playbook is intended for. \n\nThe value for this property SHOULD come from the 'industry-sector-ov' open vocabulary as defined in [STIX-v2.1]. If this object references a CACAO v2.0 playbook, then the value of this property SHOULD match the value of the (if populated) industry_sectors property in the CACAO playbook. \n\nNote that the [CACAO-Security-Playbooks-v2.0] extends the 'industry-sector-ov' of [STIX-v2.1] with more sectors." + }, + "playbook_format": { + "type": "string", + "description": "The standard / format / notation the playbook conforms to (e.g., cacao, bpmn, ansible), or when not available, its encoding (e.g., .png or .pptx). \n\nWhen possible, this value SHOULD come from the values defined in the Template column of the IANA media type registry [Media Types]. For example, if a playbook is provided as an image in png format, the value following the IANA media type registry should be 'image/png'. Another example is CACAO security playbooks, where in [CACAO-Security-Playbooks-v2.0] Appendix C. IANA Considerations, the following media type is defined: 'application/cacao+json'." + }, + "is_playbook_template": { + "type": "boolean", + "description": "This property verifies whether the playbook is a template or includes details for machine execution. \n\nA playbook could abstractly define and describe a structured process to be performed by cybersecurity personnel following up on a specific incident type or could detail actions up to the command level for an orchestrator to consume and execute it automatically by integrating and interacting with a set of systems and system components. Generally, playbooks for exchange will be vetted for confidential information and infrastructure details. Organizations and sharing parties and communities MAY define rules for what exactly constitutes a template playbook." + }, + "playbook_type": { + "type": "array", + "description": "A list of playbook types that specifies the operational roles this playbook addresses. \n\nThe value for this property SHOULD come from the playbook-type-ov open vocabulary. If this object references a CACAO v2.0 playbook, then the value of this property SHOULD match the value of the (if populated) playbook_types property in the CACAO playbook.", + "items": { + "type": "string" + }, + "minItems": 1 + }, + "playbook_impact": { + "type": "integer", + "minimum": 0, + "maximum": 100, + "description": "A number (𝕎 - whole number) from 0 to 100 that represents the potential impact (as determined subjectively by the producer) the execution of the playbook might have on the organization and its infrastructure.\n\nOrganizations and sharing parties and communities MAY establish clear rules for assigning this property. \n\nIf specified, the value of this property MUST be between 0 and 100. When left blank, this means unspecified. A value of 0 means specifically undefined or benign. Impact values range from 1, the lowest impact, to a value of 100, the highest. \n\nNote that CACAO v2.0 playbooks also share the same property (impact) but producers of this SDO MAY assign different impact values based on their own rules." + }, + "playbook_severity": { + "type": "integer", + "minimum": 0, + "maximum": 100, + "description": "A number (𝕎 - whole number) that represents the seriousness of the conditions that this playbook addresses. This is highly dependent on whether the playbook is a response to an incident (in which case the severity could be mapped to an incident category defined in some solution), a response to a threat (in which case the severity would likely be mapped to the severity of the threat faced or captured by threat intelligence), or a response to something else. \n\nOrganizations and sharing parties and communities MAY establish clear rules for assigning this property. \n\nIf specified, the value of this property MUST be between 0 and 100. \n\nWhen left blank, this means unspecified. A value of 0 means specifically undefined. Values range from 1, the lowest severity, to 100, the highest. \n\nNote that CACAO v2.0 playbooks also share the same property (severity) but producers of this SDO MAY assign different impact values based on their own rules." + }, + "playbook_priority": { + "type": "integer", + "minimum": 0, + "maximum": 100, + "description": "A number (𝕎 - whole number) that represents the priority of this playbook relative to other defined playbooks. \n\nPriority in this context is a subjective assessment; thus, organizations, and sharing parties and communities of playbooks MAY define rules on how priority should be assessed and assigned. This specification does not address how this assessment is determined. This property is primarily to allow such usage without requiring the addition of a custom property for such practices. This property can support different use cases and requirements of a producing or consuming entity. For example, two playbook objects focused on the same malware could use the priority property to indicate that the execution of a remediation playbook is preferred compared to a mitigation playbook. \n\nIf specified, the value of this property MUST be between 0 and 100. \n\nWhen left blank this means unspecified. A value of 0 means specifically undefined. Values range from 1, the highest priority, to a value of 100, the lowest. \n\nThe values of 1-100 in this property are inverted from playbook_severity and playbook_impact based on how the concept of priority is used today. For example, in a SOC a P1 ticket is a higher priority than a P4 ticket. \n\nNote that CACAO playbooks also share the same property (priority) but producers of this SDO MAY assign different impact values based on their own rules." + }, + "playbook_bin": { + "type": "string", + "description": "The entire playbook encoded in base64. \n\nThis property allows sharing and retrieving entire playbooks. \n\nThis property MUST NOT be present if the playbook_url property is populated. \n\nAs playbooks can become quite large, implementers MAY decide to use the playbook_url property to support lightweight message exchange." + }, + "playbook_url": { + "type": "string", + "description": "The value of this property MUST be a valid URL that resolves to a non-encoded playbook (playbook in its native format). \n\nThis property MUST NOT be present if the playbook_bin property is populated." + }, + "playbook_hashes": { + "type": "hashes", + "description": "Specifies a dictionary of hashes for the playbook itself. The hashes MUST be calculated by using the playbook in its native format. \n\nThis property can be used to ensure the integrity of the playbook retrieved from the playbook_url property. \n\nThis property MUST be present when the playbook_url property is present. \n\nDictionary keys MUST come from the hash-algorithm-ov open vocabulary." + } + } + } + ], + "required": ["name", "is_playbook_template"], + "if": { + "properties": { "playbook_bin": { "type": "string" } } + }, + "then": { + "not": { "required": ["playbook_url"] } + } + } \ No newline at end of file diff --git a/apl_reference_implementation_bundle/revision_3/schemas/sdos/x-oca-tool-hvt-ext.json b/apl_reference_implementation_bundle/revision_3/schemas/sdos/x-oca-tool-hvt-ext.json new file mode 100644 index 0000000..9825658 --- /dev/null +++ b/apl_reference_implementation_bundle/revision_3/schemas/sdos/x-oca-tool-hvt-ext.json @@ -0,0 +1,91 @@ +{ + "$id": "https://raw.githubusercontent.com/opencybersecurityalliance/stix-extensions/main/2.x/schemas/x-oca-tool-hvt-ext.json", + "$schema": "http://json-schema.org/draft/2020-12/schema#", + "title": "x-oca-tool-hvt-ext", + "description": "Tools are legitimate software that can be used by threat actors to perform attacks.", + "type": "object", + "allOf": [ + { + "$ref": "https://github.com/oasis-open/cti-stix2-json-schemas/blob/master/schemas/sdos/tool.json" + }, + { + "properties": { + "extensions": { + "type": "object", + "properties": { + "extension-definition--fb58a27d-32d2-4b8d-9705-e3cfd2d3dcdf": { + "type": "object", + "properties": { + "extension_type": { + "type": "string", + "description": "extension_type, which MUST be the literal `property-extension`.", + "enum": [ + "property-extension" + ] + }, + "high_value_target_attributes": { + "type": "array", + "description": "Array of High Value Target attributes. Elements SHOULD come from the open vocab high-value-target-attribute-ov.", + "items": { + "type": "string" + }, + "minItems": 1 + }, + "required": [ + "extension_type" + ] + } + }, + "required": [ + "extension-definition--fb58a27d-32d2-4b8d-9705-e3cfd2d3dcdf" + ] + } + } + } + } + ], + "required": [ + "extensions" + ], + "definitions": { + "tool-type-ov": { + "type": "string", + "enum": [ + "denial-of-service", + "exploitation", + "information-gathering", + "network-capture", + "credential-exploitation", + "remote-access", + "vulnerability-scanning", + "unknown", + "hypervisors-virtualization", + "identity-access-management", + "security-monitoring", + "backup-storage", + "endpoint-management", + "endpoint-security", + "network-management", + "network-security", + "office-productivity", + "crisis-management", + "business-data-repository" + ] + }, + "high-value-target-attribute-ov": { + "type": "string", + "enum": [ + "tamper-prone", + "internal-prospecting", + "stores-secrets", + "stealthiness", + "external-exposure", + "infiltrate-comms", + "blindside-defense", + "inhibit-restoration", + "stores-data", + "widespread-presence" + ] + } + } +} \ No newline at end of file From c1ca7674e6d5c4b0d3307fa43a5415b6eca7ed18 Mon Sep 17 00:00:00 2001 From: kkarolenko Date: Tue, 4 Jun 2024 20:11:52 +0000 Subject: [PATCH 2/2] removing old schemas --- .../revision_3/schemas/sdos/behavior.json | 69 -------------- .../revision_3/schemas/sdos/detection.json | 60 ------------ .../revision_3/schemas/sdos/detector.json | 95 ------------------- .../sdos/extended-course-of-action.json | 52 ---------- .../revision_3/schemas/sdos/playbook.json | 90 ------------------ .../schemas/sdos/x-oca-tool-hvt-ext.json | 91 ------------------ 6 files changed, 457 deletions(-) delete mode 100644 apl_reference_implementation_bundle/revision_3/schemas/sdos/behavior.json delete mode 100644 apl_reference_implementation_bundle/revision_3/schemas/sdos/detection.json delete mode 100644 apl_reference_implementation_bundle/revision_3/schemas/sdos/detector.json delete mode 100644 apl_reference_implementation_bundle/revision_3/schemas/sdos/extended-course-of-action.json delete mode 100644 apl_reference_implementation_bundle/revision_3/schemas/sdos/playbook.json delete mode 100644 apl_reference_implementation_bundle/revision_3/schemas/sdos/x-oca-tool-hvt-ext.json diff --git a/apl_reference_implementation_bundle/revision_3/schemas/sdos/behavior.json b/apl_reference_implementation_bundle/revision_3/schemas/sdos/behavior.json deleted file mode 100644 index 12b7b4b..0000000 --- a/apl_reference_implementation_bundle/revision_3/schemas/sdos/behavior.json +++ /dev/null @@ -1,69 +0,0 @@ -{ - "$id": "https://raw.githubusercontent.com/opencybersecurityalliance/oca-iob/main/apl_reference_implementation_bundle/revision_2/schemas/sdos/behavior.json", - "$schema": "http://json-schema.org/draft/2020-12/schema#", - "title": "behavior", - "description": "Behavior objects define adversary behaviors associated with higher level MITRE ATT&CK tactics and techniques. The Attack Pattern SDO may have multiple behaviors associated with it. For example, a spearphishing attack may employ multiple behaviors (usage of email attachments, process modifying a registry key, network patterns, etc.).", - "type": "object", - "allOf": [ - { - "$ref": "https://raw.githubusercontent.com/oasis-open/cti-stix2-json-schemas/master/schemas/common/core.json" - }, - { - "properties": { - "type": { - "type": "string", - "description": "The type of this object, which MUST be the literal `x-oca-behavior`.", - "enum": [ - "x-oca-behavior" - ] - }, - "id": { - "title": "id", - "pattern": "^x-oca-behavior--" - }, - "name": { - "type": "string", - "description": "The name used to identify the Behavior." - }, - "description": { - "type": "string", - "description": "Description of Behavior." - }, - "behavior_class": { - "type": "string", - "description": "The class of behavior. The value for this property SHOULD come from the behavior-class-ov open vocabulary." - }, - "tactic": { - "type": "string", - "description": "MITRE ATT&CK tactic of the Behavior." - }, - "technique": { - "type": "string", - "description": "MITRE ATT&CK technique of the Behavior." - }, - "first_seen": { - "description": "The first_seen property represents the time that this behavior was first seen. The timstamp value MUST be precise to the nearest millisecond.", - "allOf": [ - { - "$ref": "https://raw.githubusercontent.com/oasis-open/cti-stix2-json-schemas/master/schemas/common/timestamp.json" - }, - { - "title": "timestamp_millis", - "pattern": "T\\d{2}:\\d{2}:\\d{2}\\.\\d{3,}Z$" - } - ] - }, - "platforms": { - "type": "array", - "description": "Platforms the Behavior was seen on. Each entry may list contextual data about the platform such as the OS and OS version number.", - "items": { - "$ref": "https://raw.githubusercontent.com/oasis-open/cti-stix2-json-schemas/master/schemas/common/dictionary.json" - } - } - } - } - ], - "required": [ - "name" - ] -} diff --git a/apl_reference_implementation_bundle/revision_3/schemas/sdos/detection.json b/apl_reference_implementation_bundle/revision_3/schemas/sdos/detection.json deleted file mode 100644 index 5f416fb..0000000 --- a/apl_reference_implementation_bundle/revision_3/schemas/sdos/detection.json +++ /dev/null @@ -1,60 +0,0 @@ -{ - "$id": "https://raw.githubusercontent.com/opencybersecurityalliance/oca-iob/main/apl_reference_implementation_bundle/revision_2/schemas/sdos/detection.json", - "$schema": "http://json-schema.org/draft/2020-12/schema#", - "title": "detection", - "description": "Detections contain logic to detect an adversary behavior.", - "type": "object", - "allOf": [ - { - "$ref": "https://raw.githubusercontent.com/oasis-open/cti-stix2-json-schemas/master/schemas/common/core.json" - }, - { - "properties": { - "type": { - "type": "string", - "description": "The type of this object, which MUST be the literal `x-oca-detection`.", - "enum": [ - "x-oca-detection" - ] - - }, - "id": { - "type": "string", - "pattern": "^x-oca-detection--" - }, - "name": { - "type": "string", - "description": "The name used to identify the detection." - }, - "data_sources": { - "type": "array", - "description": "Information about the data event that the detection targets.", - "items": { - "$ref": "https://raw.githubusercontent.com/oasis-open/cti-stix2-json-schemas/master/schemas/common/dictionary.json" - } - }, - "analytic": { - "type": "object", - "description": "Base64 encoded logic defining the detection along with the type of rule (e.g. Sigma rule).", - "properties": { - "rule": { - "type": "string" - }, - "type": { - "type": "string" - } - }, - "required": [ - "rule", - "type" - ] - } - } - } - ], - "required": [ - "name", - "data_sources", - "analytic" - ] -} diff --git a/apl_reference_implementation_bundle/revision_3/schemas/sdos/detector.json b/apl_reference_implementation_bundle/revision_3/schemas/sdos/detector.json deleted file mode 100644 index dca2e75..0000000 --- a/apl_reference_implementation_bundle/revision_3/schemas/sdos/detector.json +++ /dev/null @@ -1,95 +0,0 @@ -{ - "$id": "https://raw.githubusercontent.com/opencybersecurityalliance/oca-iob/main/apl_reference_implementation_bundle/revision_2/schemas/sdos/detector.json", - "$schema": "http://json-schema.org/draft/2020-12/schema#", - "title": "detector", - "description": "Detector objects define tools, software, products, etc. that are capable of performing detection. They should likely be related to one or more Detection obects.", - "type": "object", - "allOf": [ - { - "$ref": "https://raw.githubusercontent.com/oasis-open/cti-stix2-json-schemas/master/schemas/common/core.json" - }, - { - "properties": { - "type": { - "type": "string", - "description": "The type of this object, which MUST be the literal `x-oca-detector`.", - "enum": [ - "x-oca-detector" - ] - }, - "id": { - "title": "id", - "pattern": "^x-oca-detector--" - }, - "name": { - "type": "string", - "description": "The name used to identify the Detector." - }, - "description": { - "type": "string", - "description": "Description of Detector." - }, - "cpe": { - "type": "string", - "description": "A valid CPE string." - }, - "valid_until": { - "description": "The time at which this Detector should no longer be considered valuable intelligence.", - "allOf": [ - { - "$ref": "https://raw.githubusercontent.com/oasis-open/cti-stix2-json-schemas/master/schemas/common/timestamp.json" - }, - { - "title": "timestamp_millis", - "pattern": "T\\d{2}:\\d{2}:\\d{2}\\.\\d{3,}Z$" - } - ] - }, - "vendor": { - "type": "string", - "description": "The vendor name of the Detector." - }, - "vendor_url": { - "type": "string", - "description": "A URL that links to the vendor of the Detector's primary website." - }, - "product": { - "type": "string", - "description": "The product name of the Detector." - }, - "product_url": { - "type": "string", - "description": "A URL that links to an official download of the Detector product or a primary website describing the Detector product." - }, - "detection_types": { - "type": "array", - "description": "A list of the types of detections the detector can perform. For example: beacon, phishing, exfiltration.", - "items": { - "type": "string" - }, - "minItems": 1 - }, - "detector_data_categories": { - "type": "array", - "description": "A list of the general categories of data the detector uses. For example: network, endpoint, etc.", - "items": { - "type": "string" - }, - "minItems": 1 - }, - "detector_data_sources": { - "type": "array", - "description": "A list of the specific data sources the detector uses. For example: pcap, windows security event logs, sysmon, etc.", - "items": { - "type": "string" - }, - "minItems": 1 - } - } - } - ], - "required": [ - "name" - ] -} - diff --git a/apl_reference_implementation_bundle/revision_3/schemas/sdos/extended-course-of-action.json b/apl_reference_implementation_bundle/revision_3/schemas/sdos/extended-course-of-action.json deleted file mode 100644 index 286813a..0000000 --- a/apl_reference_implementation_bundle/revision_3/schemas/sdos/extended-course-of-action.json +++ /dev/null @@ -1,52 +0,0 @@ -{ - "$id": "https://raw.githubusercontent.com/opencybersecurityalliance/oca-iob/main/apl_reference_implementation_bundle/revision_2/schemas/sdos/course-of-action.json", - "$schema": "http://json-schema.org/draft/2020-12/schema#", - "title": "course-of-action", - "description": "A Course of Action is an action taken either to prevent an attack or to respond to an attack that is in progress. ", - "type": "object", - "allOf": [ - { - "$ref": "https://github.com/oasis-open/cti-stix2-json-schemas/blob/master/schemas/sdos/course-of-action.json" - }, - { - "properties": { - "extensions": { - "type": "object", - "properties": { - "extension-definition--BBC1D5C8-7DDC-4E89-BE9C-F33AD02D71DD": { - "type": "object", - "properties": { - "extension_type": { - "type": "string", - "description": "extension_type, which MUST be the literal `property-extension`", - "enum": [ - "property-extension" - ] - }, - "playbooks": { - "type": "object", - "description": "A dictionary where each key is a format of the playbook (CACAO, BPMN, etc.) and the value is the id of the playbook SDO.", - "minProperties": 1, - "patternProperties": { - "^.*$": { - "$ref": "https://github.com/oasis-open/cti-stix2-json-schemas/blob/master/schemas/common/identifier.json" - } - } - } - }, - "required": [ - "extension_type" - ] - } - }, - "required": [ - "extension-definition--BBC1D5C8-7DDC-4E89-BE9C-F33AD02D71DD" - ] - } - } - } - ], - "required": [ - "extensions" - ] -} \ No newline at end of file diff --git a/apl_reference_implementation_bundle/revision_3/schemas/sdos/playbook.json b/apl_reference_implementation_bundle/revision_3/schemas/sdos/playbook.json deleted file mode 100644 index 43cfcff..0000000 --- a/apl_reference_implementation_bundle/revision_3/schemas/sdos/playbook.json +++ /dev/null @@ -1,90 +0,0 @@ -{ - "$id": "https://raw.githubusercontent.com/opencybersecurityalliance/oca-iob/main/apl_reference_implementation_bundle/revision_2/schemas/sdos/playbook.json", - "$schema": "http://json-schema.org/draft/2020-12/schema#", - "title": "playbook", - "description": "A Playbook object represents a structured process, such as an orchestration workflow, alongside associated metadata.", - "type": "object", - "allOf": [ - { - "$ref": "https://raw.githubusercontent.com/oasis-open/cti-stix2-json-schemas/master/schemas/common/core.json" - }, - { - "properties": { - "type": { - "type": "string", - "description": "The type of this object, which MUST be the literal `x-oca-playbook`.", - "enum": [ - "x-oca-playbook" - ] - }, - "id": { - "type": "string", - "pattern": "^x-oca-playbook--" - }, - "name": { - "type": "string", - "description": "The name used to identify the playbook." - }, - "description": { - "type": "string", - "description": "An explanation, details, and more context about what this playbook does and tries to accomplish." - }, - "playbook_id": { - "type": "string", - "description": "A value that identifies the playbook. If the playbook itself includes a unique identifier (e.g., CACAO playbooks may include UUIDv4 or deterministic UUIDv5 identifiers), then playbook_id SHOULD use the same identifier for correlation purposes. Otherwise, the sharing entity MAY generate a UUIDv4 identifier." - }, - "playbook_format": { - "type": "string", - "description": "The standard/format/notation the playbook conforms to (e.g., CACAO, BPMN, Ansible)." - }, - "playbook_type": { - "type": "array", - "description": "A list of playbook types that specifies the operational roles this playbook addresses. Each element SHOULD be from open vocab - playbook-type-ov.", - "items": { - "type": "string" - }, - "minItems": 1 - }, - "playbook_bin": { - "type": "string", - "description": "The entire playbook encoded in base64." - }, - "playbook_abstraction": { - "type": "string", - "description": "The playbook’s level of abstraction. For example, a playbook can contain descriptions of processes for cybersecurity personnel or specific commands for an orchestrator to consume and execute. The value SHOULD come from open vocab playbook-abstraction-ov." - }, - "playbook_creation_time": { - "description": "The time at which the first version of this playbook was created. The timstamp value MUST be precise to the nearest millisecond.", - "allOf": [ - { - "$ref": "https://raw.githubusercontent.com/oasis-open/cti-stix2-json-schemas/master/schemas/common/timestamp.json" - }, - { - "title": "timestamp_millis", - "pattern": "T\\d{2}:\\d{2}:\\d{2}\\.\\d{3,}Z$" - } - ] - }, - "playbook_modification_time": { - "description": "The time that this particular version of this playbook was modified. The timstamp value MUST be precise to the nearest millisecond.", - "allOf": [ - { - "$ref": "https://raw.githubusercontent.com/oasis-open/cti-stix2-json-schemas/master/schemas/common/timestamp.json" - }, - { - "title": "timestamp_millis", - "pattern": "T\\d{2}:\\d{2}:\\d{2}\\.\\d{3,}Z$" - } - ] - }, - "playbook_creator": { - "$ref": "https://raw.githubusercontent.com/oasis-open/cti-stix2-json-schemas/master/schemas/common/identifier.json", - "description": "The identifier of the entity that created the playbook." - } - } - } - ], - "required": [ - "name" - ] -} diff --git a/apl_reference_implementation_bundle/revision_3/schemas/sdos/x-oca-tool-hvt-ext.json b/apl_reference_implementation_bundle/revision_3/schemas/sdos/x-oca-tool-hvt-ext.json deleted file mode 100644 index 9825658..0000000 --- a/apl_reference_implementation_bundle/revision_3/schemas/sdos/x-oca-tool-hvt-ext.json +++ /dev/null @@ -1,91 +0,0 @@ -{ - "$id": "https://raw.githubusercontent.com/opencybersecurityalliance/stix-extensions/main/2.x/schemas/x-oca-tool-hvt-ext.json", - "$schema": "http://json-schema.org/draft/2020-12/schema#", - "title": "x-oca-tool-hvt-ext", - "description": "Tools are legitimate software that can be used by threat actors to perform attacks.", - "type": "object", - "allOf": [ - { - "$ref": "https://github.com/oasis-open/cti-stix2-json-schemas/blob/master/schemas/sdos/tool.json" - }, - { - "properties": { - "extensions": { - "type": "object", - "properties": { - "extension-definition--fb58a27d-32d2-4b8d-9705-e3cfd2d3dcdf": { - "type": "object", - "properties": { - "extension_type": { - "type": "string", - "description": "extension_type, which MUST be the literal `property-extension`.", - "enum": [ - "property-extension" - ] - }, - "high_value_target_attributes": { - "type": "array", - "description": "Array of High Value Target attributes. Elements SHOULD come from the open vocab high-value-target-attribute-ov.", - "items": { - "type": "string" - }, - "minItems": 1 - }, - "required": [ - "extension_type" - ] - } - }, - "required": [ - "extension-definition--fb58a27d-32d2-4b8d-9705-e3cfd2d3dcdf" - ] - } - } - } - } - ], - "required": [ - "extensions" - ], - "definitions": { - "tool-type-ov": { - "type": "string", - "enum": [ - "denial-of-service", - "exploitation", - "information-gathering", - "network-capture", - "credential-exploitation", - "remote-access", - "vulnerability-scanning", - "unknown", - "hypervisors-virtualization", - "identity-access-management", - "security-monitoring", - "backup-storage", - "endpoint-management", - "endpoint-security", - "network-management", - "network-security", - "office-productivity", - "crisis-management", - "business-data-repository" - ] - }, - "high-value-target-attribute-ov": { - "type": "string", - "enum": [ - "tamper-prone", - "internal-prospecting", - "stores-secrets", - "stealthiness", - "external-exposure", - "infiltrate-comms", - "blindside-defense", - "inhibit-restoration", - "stores-data", - "widespread-presence" - ] - } - } -} \ No newline at end of file