Vulnerability Response assignment rules overview
welcome everyone my name is Anthony Ramos and today we're going to be talking about assignment rules overview tips tricks within vulnerability response let's get started so what is an assignment rule assignment role gives you an automated triage method that if a vulnerability does come in it allows you to send that vulnerability to an appropriate group automatically how it does that is by the data Within the the vit and Associated CI so let's let's go through and create one and then we can troubleshoot that rule as well so I'm going to go in and create and vulnerability assignment rules I am currently logged in as a vulnerability admin or I have that role I'm going to go ahead and click new and today we are going to be sending an events to the windows server team server support team so for the top area up here for the name I'm going to server assignment roles and it's automatically set to actively create new the execution order I'm going to set this to 500 right now we'll get into that here in a minute on what the purpose of the execution order is description you do not have to put anything in here but we do recommend that you fill it in with pertinent information here is the bread and butter of any rules are the conditions and for this one for the Windows Server we want the configuration item class let's go down here and find class foreign is quite a few in here but we're going to go ahead and select windows domain controller first because I saw two in there so configuration class is Windows domain controller or same thing configuration item class is going back into the windows here Windows server and if it meets these two criteria or one of the other criteria we want to send this to a user group and for this instance we are going to send it to the windows server support group now let me go ahead and just submit this and then we'll come back here and talk about some of the other options okay and I'm going to apply those changes so if we see first the Windows Server assignment rule is set at 500. so the lower the number the it runs first higher number runs last there are a couple major topics in here which is one the catch-all assignment rule should run absolutely last and this one is going to catch anything that any of these rules do not get us moved over the assignment rule the catch-all sign role is going to send it to this group here which is the vulnerability Response Group and that will allow them to create additional groups based upon the data they receive so going back into our Windows server assignment rule so you we send it to a group you could send it to a user group field and that is actually being utilized go back here into the assigned to support group so if we open up this one here the user group field configuration item support group so if that if that configuration item is there it will send it based upon the order that it's in right and then the last one is a scripting field which allows you to do put your own logic in there criterias it's kind of your playground if you you decide that you want to use some Scripts to leave because I don't want any changes so uh going into our vulnerable items now I went ahead and sorted um by I filtered out anything that was closed and I grouped by assignment rule refresh this and here is one of the issues and I created it on purpose because I wanted to demonstrate how we can fix it um right now there's a total of 700 phone abilities but they're only assigned to two rules but I have a whole bunch of rules in here well what we're going to do because this starts first in the start second we're going to go in and change our Windows Server assignment role and I'm going to bump that down to 99 and then rerun it and see what we come up with and this is one of the tools you do you as the admin can definitely use if you're finding that a group is getting too many or unwanted fits assigned to them so 49 to update and then reapply that then I'm going to come back and show you what's going on so I'll be right back okay so let's go back and check on our Windows Server assignment rule all right awesome so now before it was just getting assigned to these two and now we're actually adding the server cycle in here click on that you can see the bits Associated and the rule push that along this is going to be really really important and what's going to happen is as you start creating these based upon you have you really want to understand what's in there don't make a rule complicated if you don't have to and always because these run in order always push your rules that are the simplest to the most complex so this one this rule was relatively simple we wanted to go ahead and first the more complicated rules if you can run it later in the run run it later and all right some best practices around the rules here is keep your logic inside of your rule clear and concise and I had mentioned that if you're going to um create any kind of scripting you want it to be as clear and concise as you possibly can and that's more for upgrade and performance reasons um now another catch-all is going to be the use of summary versus uh configuration item data you can use information in the vulnerability summary but it's not recommended and the reason for that is your third-party data could change which then in turn could change the rule and make it not valid it's just not set data and even though you can use it and in some cases you might have to use it uh it's not it's not recommended utilizing this catch-all rule to create other rules is in my opinion one of the better ways to create additional roles and figure out what's going on so this rule is super simple anything that's active set to True go ahead and send it to this group now going back to our list here this is where you're going to because that rule ran last and these rules ran first you're not going to have any in there but once you do you can go in here let's just uh let's grab the Windows Server group here and if these start to be different maybe it's Windows Server VM and you want to send that to the VM group you'll find out how many are in here and then you can create a root a rule based upon the information you have in in the data that's listed in this group so that's one way of creating a rule from a rule to help speed things up okay uh that's what I have today for assignment rules we'll be creating an additional content on other parts of vulnerability response but this is just a quick down and dirty and some best tips and practices thank you for listening and watching my name is Anthony Ramos have an awesome day
https://www.youtube.com/watch?v=dg6ayBGhXJw