diff --git a/detections/endpoint/hunting_3cxdesktopapp_software.yml b/detections/endpoint/hunting_3cxdesktopapp_software.yml index c62351c051..222d705591 100644 --- a/detections/endpoint/hunting_3cxdesktopapp_software.yml +++ b/detections/endpoint/hunting_3cxdesktopapp_software.yml @@ -31,6 +31,8 @@ tags: - CIS 5 - CIS 16 confidence: 50 + cve: + - CVE-2023-29059 context: - Source:Endpoint - Stage:Execution diff --git a/detections/endpoint/windows_vulnerable_3cx_software.yml b/detections/endpoint/windows_vulnerable_3cx_software.yml index efea7e4664..961bd9c285 100644 --- a/detections/endpoint/windows_vulnerable_3cx_software.yml +++ b/detections/endpoint/windows_vulnerable_3cx_software.yml @@ -31,6 +31,8 @@ tags: - CIS 5 - CIS 16 confidence: 90 + cve: + - CVE-2023-29059 context: - Source:Endpoint - Stage:Execution diff --git a/detections/experimental/network/3cx_supply_chain_attack_network_indicators.yml b/detections/experimental/network/3cx_supply_chain_attack_network_indicators.yml index 0003fb7371..98499a303b 100644 --- a/detections/experimental/network/3cx_supply_chain_attack_network_indicators.yml +++ b/detections/experimental/network/3cx_supply_chain_attack_network_indicators.yml @@ -31,6 +31,8 @@ tags: - CIS 5 - CIS 16 confidence: 100 + cve: + - CVE-2023-29059 context: - Scope:Network dataset: diff --git a/requirements.txt b/requirements.txt index 23bf31c951..7ed9e914ea 100644 --- a/requirements.txt +++ b/requirements.txt @@ -6,13 +6,13 @@ jsonschema==4.17.3 mock==4.0.3 psutil==5.9.4 pycvesearch==1.2 -pydantic==1.10.5 +pydantic==1.10.7 pytest==7.2.1 PyYAML==5.4.1 questionary==1.10.0 requests==2.28.2 six==1.16.0 -splunk-appinspect==2.33.0 +splunk-appinspect==2.34.0 splunk-sdk==1.7.3 wrapt-timeout-decorator==1.3.12.2 xmltodict==0.13.0 diff --git a/stories/3cx_supply_chain_attack.yml b/stories/3cx_supply_chain_attack.yml index 537d3880ef..fae44ccf52 100644 --- a/stories/3cx_supply_chain_attack.yml +++ b/stories/3cx_supply_chain_attack.yml @@ -15,6 +15,8 @@ references: - https://www.volexity.com/blog/2023/03/30/3cx-supply-chain-compromise-leads-to-iconic-incident/ tags: analytic_story: 3CX Supply Chain Attack + cve: + - CVE-2023-29059 category: - Adversary Tactics product: