mirror of
https://github.com/elastic/detection-rules
synced 2026-06-08 14:00:08 +00:00
c6b312d2d5
* [Tuning/New] Solawrwinds Post Exploit
https://www.huntress.com/blog/active-exploitation-solarwinds-web-help-desk-cve-2025-26399
- new rule for tunneling using QEMU
- added few websvc domains .cloud.es.io, files.catbox.moe and supabase.co
- added javaw to the solarwinds rule
- added ZOHO and Velociraptor to the new term RMM rule.
* Update initial_access_potential_webhelpdesk_exploit.toml
* Update rules/windows/command_and_control_common_webservices.toml
Co-authored-by: Ruben Groenewoud <78494512+Aegrah@users.noreply.github.com>
* ++
---------
Co-authored-by: Ruben Groenewoud <78494512+Aegrah@users.noreply.github.com>
(cherry picked from commit 2b5472a9b3)