From ecb51ccc1700645116d921ccc1cd7d3d1c47e381 Mon Sep 17 00:00:00 2001 From: Michael Haag <5632822+MHaggis@users.noreply.github.com> Date: Thu, 20 Jul 2023 16:57:57 -0700 Subject: [PATCH 1/3] Create citrix_netscaler_adc_cve_2023_3519.yml --- .../citrix_netscaler_adc_cve_2023_3519.yml | 29 +++++++++++++++++++ 1 file changed, 29 insertions(+) create mode 100644 stories/citrix_netscaler_adc_cve_2023_3519.yml diff --git a/stories/citrix_netscaler_adc_cve_2023_3519.yml b/stories/citrix_netscaler_adc_cve_2023_3519.yml new file mode 100644 index 0000000000..1f0b194441 --- /dev/null +++ b/stories/citrix_netscaler_adc_cve_2023_3519.yml @@ -0,0 +1,29 @@ +name: Citrix Netscaler ADC CVE-2023-3519 +id: 094df1fe-4345-4c01-8a0f-c65cf7b758bd +version: 1 +date: '2023-07-20' +author: Michael Haag, Splunk +description: The CVE-2023-3519 vulnerability in NetScaler (formerly Citrix) Application Delivery Controller (ADC) and NetScaler Gateway has been exploited by threat actors, as detailed in a recent advisory. The unauthenticated remote code execution vulnerability was utilized as a zero-day to establish a webshell on a non-production environment NetScaler ADC appliance within a critical infrastructure organization. This facilitated the execution of discovery on the victim's active directory and the collection and exfiltration of data. The advisory offers a comprehensive examination of the threat actors' tactics, techniques, and procedures (TTPs), alongside recommended detection methods and incident response guidelines. Immediate patch application from Citrix and the use of the detection guidance in the advisory is strongly recommended for critical infrastructure organizations to mitigate system compromises. +narrative: Recent advisories have highlighted the exploitation of CVE-2023-3519, a vulnerability in NetScaler (Citrix) Application Delivery Controller (ADC) and NetScaler Gateway. In June 2023, this vulnerability was leveraged as a zero-day by threat actors to implant a webshell on a non-production environment NetScaler ADC appliance belonging to a critical infrastructure organization. This allowed the threat actors to perform active directory discovery and data collection and exfiltration. Despite attempts to move laterally to a domain controller, network-segmentation controls hindered further movement. \ + + The compromised organization identified the breach and reported it to the relevant authorities, resulting in Citrix issuing a patch for this vulnerability on July 18, 2023. Multiple advisories have outlined the tactics, techniques, and procedures (TTPs) deployed by the threat actors, along with detection methods to help organizations identify potential compromises. Organizations are urged to implement the recommended incident response measures if a compromise is detected, and to promptly apply the provided patches by Citrix if no compromise is detected. \ + + The threat actors undertook several actions in the course of their attack. These included uploading a TGZ file containing a generic webshell, discovery script, and setuid binary on the ADC appliance, conducting SMB scanning on the subnet, and utilizing the webshell for active directory enumeration and data exfiltration. They accessed NetScaler configuration files and decryption keys, decrypted an active directory credential, and queried the active directory for various information types. Additionally, they encrypted collected data, exfiltrated it as an image file, and attempted to erase their artifacts. Efforts for further discovery and lateral movement were unsuccessful due to the network-segmentation controls of the compromised organization. \ + + The advisories provide a detailed mapping of the threat actors' activities to MITRE ATT&CK® tactics and techniques. These include techniques for initial access, persistence, privilege escalation, defense evasion, credential access, discovery, collection, command and control, and impact. \ + + Advisories suggest executing specific checks on the ADC shell interface to detect signs of compromise. These include seeking files newer than the last installation, checking http error logs for abnormalities, reviewing shell logs for unusual post-ex commands, locating dropped setuid binaries, and reviewing various types of logs for signs of unusual activity. \ + + If a compromise is detected, organizations should quarantine or take offline potentially affected hosts, reimage compromised hosts, provision new account credentials, collect and review artifacts, and report the compromise to the relevant authorities. To mitigate the threat, organizations are advised to install the relevant updated version of NetScaler ADC and NetScaler Gateway as soon as possible, adhere to the best cybersecurity practices, and apply robust network-segmentation controls on NetScaler appliances and other internet-facing devices. \ +references: + - https://attackerkb.com/topics/si09VNJhHh/cve-2023-3519 + - https://www.cisa.gov/sites/default/files/2023-07/aa23-201a_csa_threat_actors_exploiting_citrix-cve-2023-3519_to_implant_webshells.pdf +tags: + analytic_story: Citrix Netscaler ADC CVE-2023-3519 + category: + - Adversary Tactics + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + usecase: Advanced Threat Detection From 05d32c6c3d85f509472a2fd16f64321cff4ea212 Mon Sep 17 00:00:00 2001 From: Michael Haag <5632822+MHaggis@users.noreply.github.com> Date: Fri, 21 Jul 2023 14:47:56 -0700 Subject: [PATCH 2/3] analytic + text update --- .../citrix_adc_exploitation_cve_2023_3519.yml | 63 +++++++++++++++++++ .../citrix_netscaler_adc_cve_2023_3519.yml | 12 ++-- 2 files changed, 67 insertions(+), 8 deletions(-) create mode 100644 detections/web/citrix_adc_exploitation_cve_2023_3519.yml diff --git a/detections/web/citrix_adc_exploitation_cve_2023_3519.yml b/detections/web/citrix_adc_exploitation_cve_2023_3519.yml new file mode 100644 index 0000000000..b4c58c6a73 --- /dev/null +++ b/detections/web/citrix_adc_exploitation_cve_2023_3519.yml @@ -0,0 +1,63 @@ +name: Citrix ADC Exploitation CVE-2023-3519 +id: 76ac2dcb-333c-4a77-8ae9-2720cfae47a8 +version: 1 +date: '2023-07-21' +author: Michael Haag, Splunk +status: production +type: Hunting +data_source: [] +description: This analytic is designed to assist in hunting for potential exploitation attempts against Citrix ADC in relation to CVE-2023-3519. This vulnerability, identified within Citrix ADC and NetScaler Gateway, appears to be linked with SAML processing components, with an overflow issue allowing for possible memory corruption. Preliminary findings indicate that for the exploit to be viable, SAML has to be enabled. The analytic targets POST requests to certain web endpoints which have been associated with the exploitation process. \ + + Given the specific nature of the vulnerability, upon deploying this analytic it is recommended to filter and narrow the focus towards your ADC assets to reduce potential noise and improve the signal of the analytic. Please note that the exploitation of this vulnerability has been reported in the wild, therefore monitoring for potential signs of exploitation should be considered high priority. \ + + The search query provided examines web data for POST requests made to specific URLs associated with the exploitation of this vulnerability. It aggregates and presents data to highlight potential exploitation attempts, taking into account elements like user agent, HTTP method, URL length, source, and destination. \ + + Please be aware that this analytic is based on current understanding of the vulnerability, and adjustments may be required as more information becomes available. +search: '| tstats count min(_time) as firstTime max(_time) + as lastTime from datamodel=Web where Web.url IN ("*/saml/login","/cgi/samlauth","*/saml/activelogin","/cgi/samlart?samlart=*","*/cgi/logout") Web.http_method=POST + by Web.http_user_agent, Web.status Web.http_method, Web.url, Web.url_length, Web.src, Web.dest, sourcetype + | `drop_dm_object_name("Web")` + | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` | `citrix_adc_exploitation_cve_2023_3519_filter`' +how_to_implement: This detection requires the Web datamodel to be populated from a + supported Technology Add-On like Splunk for Apache, Splunk for Nginx, or Splunk + for Palo Alto. +known_false_positives: False positives may be present based on organization use of SAML utilities. Filter, or restrict the analytic to Citrix devices only. +references: +- https://blog.assetnote.io/2023/07/21/citrix-CVE-2023-3519-analysis/ +tags: + analytic_story: + - Citrix Netscaler ADC CVE-2023-3519 + cve: + - CVE-2023-3519 + asset_type: Network + atomic_guid: [] + confidence: 50 + impact: 90 + message: Possible expliotation of CVE-2023-3519 against $dest$. + mitre_attack_id: + - T1190 + observable: + - name: dest + type: Hostname + role: + - Victim + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + risk_score: 45 + required_fields: + - _time + - Web.http_method + - Web.url + - Web.url_length + - Web.src + - Web.dest + security_domain: endpoint +tests: +- name: True Positive Test + attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1190/citrix/citrix-cve20233519.log + source: pan:threat + sourcetype: pan:threat diff --git a/stories/citrix_netscaler_adc_cve_2023_3519.yml b/stories/citrix_netscaler_adc_cve_2023_3519.yml index 1f0b194441..3c676cccfc 100644 --- a/stories/citrix_netscaler_adc_cve_2023_3519.yml +++ b/stories/citrix_netscaler_adc_cve_2023_3519.yml @@ -4,17 +4,13 @@ version: 1 date: '2023-07-20' author: Michael Haag, Splunk description: The CVE-2023-3519 vulnerability in NetScaler (formerly Citrix) Application Delivery Controller (ADC) and NetScaler Gateway has been exploited by threat actors, as detailed in a recent advisory. The unauthenticated remote code execution vulnerability was utilized as a zero-day to establish a webshell on a non-production environment NetScaler ADC appliance within a critical infrastructure organization. This facilitated the execution of discovery on the victim's active directory and the collection and exfiltration of data. The advisory offers a comprehensive examination of the threat actors' tactics, techniques, and procedures (TTPs), alongside recommended detection methods and incident response guidelines. Immediate patch application from Citrix and the use of the detection guidance in the advisory is strongly recommended for critical infrastructure organizations to mitigate system compromises. -narrative: Recent advisories have highlighted the exploitation of CVE-2023-3519, a vulnerability in NetScaler (Citrix) Application Delivery Controller (ADC) and NetScaler Gateway. In June 2023, this vulnerability was leveraged as a zero-day by threat actors to implant a webshell on a non-production environment NetScaler ADC appliance belonging to a critical infrastructure organization. This allowed the threat actors to perform active directory discovery and data collection and exfiltration. Despite attempts to move laterally to a domain controller, network-segmentation controls hindered further movement. \ +narrative: Recent advisories have highlighted the exploitation of CVE-2023-3519, a critical vulnerability in Citrix's NetScaler Application Delivery Controller (ADC) and NetScaler Gateway. In June 2023, threat actors utilized this vulnerability to implant a webshell on a NetScaler ADC appliance within a critical infrastructure organization's non-production environment. This action granted them the ability to perform active directory discovery, data collection, and exfiltration. Notably, attempts for lateral movement to a domain controller were obstructed by network-segmentation controls. \ - The compromised organization identified the breach and reported it to the relevant authorities, resulting in Citrix issuing a patch for this vulnerability on July 18, 2023. Multiple advisories have outlined the tactics, techniques, and procedures (TTPs) deployed by the threat actors, along with detection methods to help organizations identify potential compromises. Organizations are urged to implement the recommended incident response measures if a compromise is detected, and to promptly apply the provided patches by Citrix if no compromise is detected. \ + The compromised organization reported the breach, leading Citrix to issue a patch on July 18, 2023. Multiple advisories have since outlined the threat actors' tactics, techniques, and procedures (TTPs), including their initial access, persistence, privilege escalation, defense evasion, credential access, discovery, collection, command and control, and impact. These advisories also provide detection methods and recommend incident response measures. \ - The threat actors undertook several actions in the course of their attack. These included uploading a TGZ file containing a generic webshell, discovery script, and setuid binary on the ADC appliance, conducting SMB scanning on the subnet, and utilizing the webshell for active directory enumeration and data exfiltration. They accessed NetScaler configuration files and decryption keys, decrypted an active directory credential, and queried the active directory for various information types. Additionally, they encrypted collected data, exfiltrated it as an image file, and attempted to erase their artifacts. Efforts for further discovery and lateral movement were unsuccessful due to the network-segmentation controls of the compromised organization. \ + The threat actors executed several activities during their attack, such as uploading a TGZ file with a generic webshell, discovery script, and setuid binary on the ADC appliance; conducting SMB scanning on the subnet; using the webshell for active directory enumeration and data exfiltration; and accessing NetScaler configuration files and decryption keys. They also decrypted an active directory credential, queried the active directory for various information, encrypted collected data, exfiltrated it as an image file, and attempted to erase their artifacts. Despite these actions, further discovery and lateral movement were impeded due to the organization's network-segmentation controls. \ - The advisories provide a detailed mapping of the threat actors' activities to MITRE ATT&CK® tactics and techniques. These include techniques for initial access, persistence, privilege escalation, defense evasion, credential access, discovery, collection, command and control, and impact. \ - - Advisories suggest executing specific checks on the ADC shell interface to detect signs of compromise. These include seeking files newer than the last installation, checking http error logs for abnormalities, reviewing shell logs for unusual post-ex commands, locating dropped setuid binaries, and reviewing various types of logs for signs of unusual activity. \ - - If a compromise is detected, organizations should quarantine or take offline potentially affected hosts, reimage compromised hosts, provision new account credentials, collect and review artifacts, and report the compromise to the relevant authorities. To mitigate the threat, organizations are advised to install the relevant updated version of NetScaler ADC and NetScaler Gateway as soon as possible, adhere to the best cybersecurity practices, and apply robust network-segmentation controls on NetScaler appliances and other internet-facing devices. \ + Advisories suggest conducting specific checks on the ADC shell interface to detect signs of compromise. If a compromise is detected, organizations should isolate potentially affected hosts, reimage compromised hosts, provide new account credentials, collect and review artifacts, and report the compromise. To mitigate the threat, organizations are advised to promptly install the relevant updates for NetScaler ADC and NetScaler Gateway, adhere to cybersecurity best practices, and apply robust network-segmentation controls on NetScaler appliances and other internet-facing devices. \ references: - https://attackerkb.com/topics/si09VNJhHh/cve-2023-3519 - https://www.cisa.gov/sites/default/files/2023-07/aa23-201a_csa_threat_actors_exploiting_citrix-cve-2023-3519_to_implant_webshells.pdf From 449a12a1a7a4bedf8b9cf6c21125b8371bd14de9 Mon Sep 17 00:00:00 2001 From: pyth0n1c <87383215+pyth0n1c@users.noreply.github.com> Date: Fri, 21 Jul 2023 15:13:31 -0700 Subject: [PATCH 3/3] Add ref link to story and detection. Ref link is official documentation and guidance from citirx. --- detections/web/citrix_adc_exploitation_cve_2023_3519.yml | 1 + stories/citrix_netscaler_adc_cve_2023_3519.yml | 1 + 2 files changed, 2 insertions(+) diff --git a/detections/web/citrix_adc_exploitation_cve_2023_3519.yml b/detections/web/citrix_adc_exploitation_cve_2023_3519.yml index b4c58c6a73..ae8de91722 100644 --- a/detections/web/citrix_adc_exploitation_cve_2023_3519.yml +++ b/detections/web/citrix_adc_exploitation_cve_2023_3519.yml @@ -25,6 +25,7 @@ how_to_implement: This detection requires the Web datamodel to be populated from known_false_positives: False positives may be present based on organization use of SAML utilities. Filter, or restrict the analytic to Citrix devices only. references: - https://blog.assetnote.io/2023/07/21/citrix-CVE-2023-3519-analysis/ +- https://support.citrix.com/article/CTX561482/citrix-adc-and-citrix-gateway-security-bulletin-for-cve20233519-cve20233466-cve20233467 tags: analytic_story: - Citrix Netscaler ADC CVE-2023-3519 diff --git a/stories/citrix_netscaler_adc_cve_2023_3519.yml b/stories/citrix_netscaler_adc_cve_2023_3519.yml index 3c676cccfc..3f5fbe3fdd 100644 --- a/stories/citrix_netscaler_adc_cve_2023_3519.yml +++ b/stories/citrix_netscaler_adc_cve_2023_3519.yml @@ -14,6 +14,7 @@ narrative: Recent advisories have highlighted the exploitation of CVE-2023-3519, references: - https://attackerkb.com/topics/si09VNJhHh/cve-2023-3519 - https://www.cisa.gov/sites/default/files/2023-07/aa23-201a_csa_threat_actors_exploiting_citrix-cve-2023-3519_to_implant_webshells.pdf + - https://support.citrix.com/article/CTX561482/citrix-adc-and-citrix-gateway-security-bulletin-for-cve20233519-cve20233466-cve20233467 tags: analytic_story: Citrix Netscaler ADC CVE-2023-3519 category: