Added cve tags to detections

This commit is contained in:
P4T12ICK
2023-01-02 10:03:58 +01:00
parent 524766e532
commit 38eef722ea
87 changed files with 294 additions and 0 deletions
@@ -38,6 +38,8 @@ tags:
asset_type: Web Server
atomic_guid: []
confidence: 40
cve:
- CVE-2022-32154
drilldown_search: []
impact: 50
message: A potentially risky Splunk command has been run by $user$, kindly review.
@@ -28,6 +28,8 @@ tags:
asset_type: Endpoint
atomic_guid: []
confidence: 80
cve:
- CVE-2022-26889
drilldown_search: []
impact: 50
message: Path traversal exploitation attempt from $clientip$
@@ -26,6 +26,8 @@ tags:
asset_type: Endpoint
atomic_guid: []
confidence: 80
cve:
- CVE-2022-37438
drilldown_search: []
impact: 50
message: Potential exposure of environment variables from url embedded in dashboard
@@ -30,6 +30,8 @@ tags:
asset_type: Endpoint
atomic_guid: []
confidence: 50
cve:
- CVE-2022-43571
drilldown_search: []
impact: 50
message: Potential exploitation of Code Injection via Dashboard PDF generation.
@@ -30,6 +30,8 @@ tags:
asset_type: Web Server
atomic_guid: []
confidence: 30
cve:
- CVE-2022-32154
drilldown_search: []
impact: 90
message: $user$ executed the 'delete' command, if this is unexpected it should be
@@ -54,6 +54,8 @@ tags:
asset_type: Web Server
atomic_guid: []
confidence: 40
cve:
- CVE-2022-32154
drilldown_search: []
impact: 50
message: A risky Splunk command has ran by $user$ and should be reviewed.
@@ -38,6 +38,8 @@ tags:
asset_type: Web Server
atomic_guid: []
confidence: 40
cve:
- CVE-2022-32154
drilldown_search: []
impact: 50
message: Abnormally long run time for risk SPL command seen by user $(Search_Activity.user).
@@ -31,6 +31,8 @@ tags:
asset_type: Endpoint
atomic_guid: []
confidence: 50
cve:
- CVE-2022-43566
drilldown_search: []
impact: 50
message: Potential data exfiltration attack using SID query by $user$
@@ -36,6 +36,8 @@ tags:
asset_type: Endpoint
atomic_guid: []
confidence: 100
cve:
- CVE-2022-32153
drilldown_search: []
impact: 50
message: $splunk_server$ may not be properly validating TLS Certificates
@@ -38,6 +38,8 @@ tags:
asset_type: endpoint
atomic_guid: []
confidence: 80
cve:
- CVE-2022-32151
drilldown_search: []
impact: 25
message: $hostname$ is not using TLS when forwarding data
@@ -25,6 +25,8 @@ tags:
asset_type: Endpoint
atomic_guid: []
confidence: 100
cve:
- CVE-2021-3422
drilldown_search: []
impact: 50
message: An attempt to exploit CVE-2021-3422 was detected from $src$ against $host$
@@ -27,6 +27,8 @@ tags:
asset_type: Endpoint
atomic_guid: []
confidence: 75
cve:
- CVE-2022-37439
drilldown_search: []
impact: 100
message: Potential exposure of environment variables from url embedded in dashboard
@@ -34,6 +34,8 @@ tags:
asset_type: Endpoint
atomic_guid: []
confidence: 70
cve:
- CVE-2022-32157
drilldown_search: []
impact: 50
message: $peer$ downloaded apps from $host$
@@ -44,6 +44,8 @@ tags:
asset_type: Endpoint
atomic_guid: []
confidence: 100
cve:
- CVE-2022-32151
drilldown_search: []
impact: 50
message: $splunk_server$ may not be properly validating TLS Certificates
@@ -30,6 +30,8 @@ tags:
asset_type: Endpoint
atomic_guid: []
confidence: 80
cve:
- CVE-2022-32152
drilldown_search: []
impact: 50
message: Splunk default issued certificate at $host$
@@ -32,6 +32,8 @@ tags:
asset_type: Endpoint
atomic_guid: []
confidence: 80
cve:
- CVE-2022-32152
drilldown_search: []
impact: 50
message: Failed to validate certificate on $host$
@@ -28,6 +28,8 @@ tags:
asset_type: Endpoint
atomic_guid: []
confidence: 90
cve:
- CVE-2022-43567
drilldown_search: []
impact: 90
message: Possible exploitation attempt from $clientip$
@@ -27,6 +27,8 @@ tags:
asset_type: Endpoint
atomic_guid: []
confidence: 50
cve:
- CVE-2022-43568
drilldown_search: []
impact: 50
message: Potential XSS exploitation against radio template by $user$
@@ -28,6 +28,8 @@ tags:
asset_type: Endpoint
atomic_guid: []
confidence: 50
cve:
- CVE-2022-43569
drilldown_search: []
impact: 50
message: A potential XSS attempt has been detected from $user$
@@ -27,6 +27,8 @@ tags:
asset_type: endpoint
atomic_guid: []
confidence: 80
cve:
- CVE-2021-33845
drilldown_search: []
impact: 50
message: $TotalFailedAuths$ failed authentication events to Splunk from $src$ detected.
@@ -26,6 +26,8 @@ tags:
asset_type: Endpoint
atomic_guid: []
confidence: 80
cve:
- CVE-2022-27183
drilldown_search: []
impact: 50
message: A potential XSS attempt has been detected from $user$
@@ -27,6 +27,8 @@ tags:
asset_type: Endpoint
atomic_guid: []
confidence: 50
cve:
- CVE-2022-43561
drilldown_search: []
impact: 50
message: Possible XSS exploitation attempt from $clientip$
@@ -18,6 +18,8 @@ tags:
asset_type: Splunk Server
atomic_guid: []
confidence: 50
cve:
- CVE-2016-4859
drilldown_search: []
impact: 50
message: tbd
@@ -24,6 +24,8 @@ tags:
asset_type: Endpoint
atomic_guid: []
confidence: 50
cve:
- CVE-2017-5753
drilldown_search: []
impact: 50
message: tbd
@@ -25,6 +25,8 @@ tags:
asset_type: Splunk Server
atomic_guid: []
confidence: 50
cve:
- CVE-2018-11409
drilldown_search: []
impact: 50
message: tbd
@@ -40,6 +40,8 @@ tags:
asset_type: Endpoint
atomic_guid: []
confidence: 70
cve:
- CVE-2021-44228
drilldown_search: []
impact: 80
message: An instance of $parent_process_name$ spawning $process_name$ was identified
@@ -33,6 +33,8 @@ tags:
asset_type: Endpoint
atomic_guid: []
confidence: 50
cve:
- CVE-2018-8440
drilldown_search: []
impact: 50
message: tbd
@@ -44,6 +44,8 @@ tags:
asset_type: Endpoint
atomic_guid: []
confidence: 50
cve:
- CVE-2021-44228
drilldown_search: []
impact: 60
message: An instance of $parent_process_name$ spawning $process_name$ was identified
@@ -39,6 +39,8 @@ tags:
asset_type: Endpoint
atomic_guid: []
confidence: 100
cve:
- CVE-2021-40444
drilldown_search: []
impact: 80
message: An instance of $parent_process_name$ spawning $process_name$ was identified
@@ -36,6 +36,8 @@ tags:
asset_type: Endpoint
atomic_guid: []
confidence: 100
cve:
- CVE-2021-44228
drilldown_search: []
impact: 80
message: An instance of $process_name$ was identified on endpoint $dest$ attempting
@@ -20,6 +20,8 @@ tags:
asset_type: Endpoint
atomic_guid: []
confidence: 50
cve:
- CVE-2021-3156
drilldown_search: []
impact: 50
message: tbd
@@ -23,6 +23,8 @@ tags:
asset_type: Endpoint
atomic_guid: []
confidence: 50
cve:
- CVE-2021-3156
drilldown_search: []
impact: 50
message: tbd
@@ -20,6 +20,8 @@ tags:
asset_type: Endpoint
atomic_guid: []
confidence: 50
cve:
- CVE-2021-3156
drilldown_search: []
impact: 50
message: tbd
@@ -27,6 +27,8 @@ tags:
asset_type: Windows
atomic_guid: []
confidence: 70
cve:
- CVE-2020-1472
drilldown_search: []
impact: 70
message: The following $EventCode$ occurred on $dest$ by $user$ with Logon Type
@@ -40,6 +40,8 @@ tags:
asset_type: Endpoint
atomic_guid: []
confidence: 100
cve:
- CVE-2021-36934
drilldown_search: []
impact: 80
message: PowerShell was identified running a script to capture the SAM hive on endpoint
@@ -0,0 +1,111 @@
name: Hunting for Log4Shell
id: 158b68fa-5d1a-11ec-aac8-acde48001122
version: 1
date: '2021-12-14'
author: Michael Haag, Splunk
status: production
type: Hunting
description: 'The following hunting query assists with quickly assessing CVE-2021-44228,
or Log4Shell, activity mapped to the Web Datamodel. This is a combination query
attempting to identify, score and dashboard. Because the Log4Shell vulnerability
requires the string to be in the logs, this will work to identify the activity anywhere
in the HTTP headers using _raw. Modify the first line to use the same pattern matching
against other log sources. Scoring is based on a simple rubric of 0-5. 5 being the
best match, and less than 5 meant to identify additional patterns that will equate
to a higher total score. \
The first jndi match identifies the standard pattern of `{jndi:` \
jndi_fastmatch is meant to identify any jndi in the logs. The score is set low and
is meant to be the "base" score used later. \
jndi_proto is a protocol match that identifies `jndi` and one of `ldap, ldaps, rmi,
dns, nis, iiop, corba, nds, http, https.` \
all_match is a very well written regex by https://gist.github.com/Schvenn that identifies
nearly all patterns of this attack behavior. \
env works to identify environment variables in the header, meant to capture `AWS_ACCESS_KEY_ID`,
`AWS_SECRET_ACCESS_KEY` and `env`. \
uri_detect is string match looking for the common uri paths currently being scanned/abused
in the wild. \
keywords matches on enumerated values that, like `$ctx:loginId`, that may be found
in the header used by the adversary. \
lookup matching is meant to catch some basic obfuscation that has been identified
using upper, lower and date. \
Scoring will then occur based on any findings. The base score is meant to be 2 ,
created by jndi_fastmatch. Everything else is meant to increase that score. \
Finally, a simple table is created to show the scoring and the _raw field. Sort
based on score or columns of interest.'
data_source: []
search: '| from datamodel Web.Web | eval jndi=if(match(_raw, "(\{|%7B)[jJnNdDiI]{4}:"),4,0)
| eval jndi_fastmatch=if(match(_raw, "[jJnNdDiI]{4}"),2,0) | eval jndi_proto=if(match(_raw,"(?i)jndi:(ldap[s]?|rmi|dns|nis|iiop|corba|nds|http|https):"),5,0)
| eval all_match = if(match(_raw, "(?i)(%(25){0,}20|\s)*(%(25){0,}24|\$)(%(25){0,}20|\s)*(%(25){0,}7B|{)(%(25){0,}20|\s)*(%(25){0,}(6A|4A)|J)(%(25){0,}(6E|4E)|N)(%(25){0,}(64|44)|D)(%(25){0,}(69|49)|I)(%(25){0,}20|\s)*(%(25){0,}3A|:)[\w\%]+(%(25){1,}3A|:)(%(25){1,}2F|\/)[^\n]+"),5,0)
| eval env_var = if(match(_raw, "env:") OR match(_raw, "env:AWS_ACCESS_KEY_ID")
OR match(_raw, "env:AWS_SECRET_ACCESS_KEY"),5,0) | eval uridetect = if(match(_raw,
"(?i)Basic\/Command\/Base64|Basic\/ReverseShell|Basic\/TomcatMemshell|Basic\/JBossMemshell|Basic\/WebsphereMemshell|Basic\/SpringMemshell|Basic\/Command|Deserialization\/CommonsCollectionsK|Deserialization\/CommonsBeanutils|Deserialization\/Jre8u20\/TomcatMemshell|Deserialization\/CVE_2020_2555\/WeblogicMemshell|TomcatBypass|GroovyBypass|WebsphereBypass"),4,0)
| eval keywords = if(match(_raw,"(?i)\$\{ctx\:loginId\}|\$\{map\:type\}|\$\{filename\}|\$\{date\:MM-dd-yyyy\}|\$\{docker\:containerId\}|\$\{docker\:containerName\}|\$\{docker\:imageName\}|\$\{env\:USER\}|\$\{event\:Marker\}|\$\{mdc\:UserId\}|\$\{java\:runtime\}|\$\{java\:vm\}|\$\{java\:os\}|\$\{jndi\:logging/context-name\}|\$\{hostName\}|\$\{docker\:containerId\}|\$\{k8s\:accountName\}|\$\{k8s\:clusterName\}|\$\{k8s\:containerId\}|\$\{k8s\:containerName\}|\$\{k8s\:host\}|\$\{k8s\:labels.app\}|\$\{k8s\:labels.podTemplateHash\}|\$\{k8s\:masterUrl\}|\$\{k8s\:namespaceId\}|\$\{k8s\:namespaceName\}|\$\{k8s\:podId\}|\$\{k8s\:podIp\}|\$\{k8s\:podName\}|\$\{k8s\:imageId\}|\$\{k8s\:imageName\}|\$\{log4j\:configLocation\}|\$\{log4j\:configParentLocation\}|\$\{spring\:spring.application.name\}|\$\{main\:myString\}|\$\{main\:0\}|\$\{main\:1\}|\$\{main\:2\}|\$\{main\:3\}|\$\{main\:4\}|\$\{main\:bar\}|\$\{name\}|\$\{marker\}|\$\{marker\:name\}|\$\{spring\:profiles.active[0]|\$\{sys\:logPath\}|\$\{web\:rootDir\}|\$\{sys\:user.name\}"),4,0)
| eval obf = if(match(_raw, "(\$|%24)[^ /]*({|%7b)[^ /]*(j|%6a)[^ /]*(n|%6e)[^ /]*(d|%64)[^
/]*(i|%69)[^ /]*(:|%3a)[^ /]*(:|%3a)[^ /]*(/|%2f)"),5,0) | eval lookups = if(match(_raw,
"(?i)({|%7b)(main|sys|k8s|spring|lower|upper|env|date|sd)"),4,0) | addtotals fieldname=Score,
jndi, jndi_proto, env_var, uridetect, all_match, jndi_fastmatch, keywords, obf,
lookups | where Score > 2 | stats values(Score) by jndi, jndi_proto, env_var, uridetect,
all_match, jndi_fastmatch, keywords, lookups, obf, _raw | `hunting_for_log4shell_filter`'
how_to_implement: Out of the box, the Web datamodel is required to be pre-filled.
However, tested was performed against raw httpd access logs. Change the first line
to any dataset to pass the regex's against.
known_false_positives: It is highly possible you will find false positives, however,
the base score is set to 2 for _any_ jndi found in raw logs. tune and change as
needed, include any filtering.
references:
- https://gist.github.com/olafhartong/916ebc673ba066537740164f7e7e1d72
- https://gist.github.com/Neo23x0/e4c8b03ff8cdf1fa63b7d15db6e3860b#gistcomment-3994449
- https://regex101.com/r/OSrm0q/1/
- https://github.com/Neo23x0/signature-base/blob/master/yara/expl_log4j_cve_2021_44228.yar
- https://news.sophos.com/en-us/2021/12/12/log4shell-hell-anatomy-of-an-exploit-outbreak/
- https://gist.github.com/MHaggis/1899b8554f38c8692a9fb0ceba60b44c
- https://twitter.com/sasi2103/status/1469764719850442760?s=20
tags:
analytic_story:
- Log4Shell CVE-2021-44228
- CISA AA22-320A
asset_type: Web Server
atomic_guid: []
confidence: 50
cve:
- CVE-2021-44228
drilldown_search: []
impact: 80
message: Hunting for Log4Shell exploitation has occurred.
mitre_attack_id:
- T1190
observable:
- name: dest
type: Hostname
role:
- Victim
- name: http_method
type: Other
role:
- Other
- name: src
type: Other
role:
- Other
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
risk_score: 40
security_domain: network
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1190/java/log4shell-nginx.log
source: /var/log/nginx/access.log
sourcetype: nginx:plus:kv
@@ -27,6 +27,8 @@ tags:
asset_type: Web Server
atomic_guid: []
confidence: 50
cve:
- CVE-2021-44228
drilldown_search: []
impact: 80
message: A Java user agent $http_user_agent$ was performing a $http_method$ to retrieve
@@ -40,6 +40,8 @@ tags:
asset_type: Endpoint
atomic_guid: []
confidence: 70
cve:
- CVE-2022-22965
drilldown_search: []
impact: 60
message: An instance of $process_name$ was identified on endpoint $dest$ writing
@@ -37,6 +37,8 @@ tags:
asset_type: Endpoint
atomic_guid: []
confidence: 50
cve:
- CVE-2021-44228
drilldown_search: []
impact: 80
message: An instance of $parent_process_name$ spawning $process_name$ was identified
@@ -37,6 +37,8 @@ tags:
asset_type: Endpoint
atomic_guid: []
confidence: 70
cve:
- CVE-2021-4034
drilldown_search: []
impact: 80
message: An instance of $parent_process_name$ spawning $process_name$ was identified
@@ -32,6 +32,8 @@ tags:
asset_type: Endpoint
atomic_guid: []
confidence: 100
cve:
- CVE-2021-40444
drilldown_search: []
impact: 80
message: An instance of $process_name$ was identified on endpoint $dest$ loading
@@ -45,6 +45,8 @@ tags:
asset_type: Endpoint
atomic_guid: []
confidence: 70
cve:
- CVE-2021-41379
drilldown_search: []
impact: 80
message: The following module $ImageLoaded$ was loaded by $Image$ outside of the
@@ -42,6 +42,8 @@ tags:
asset_type: Endpoint
atomic_guid: []
confidence: 100
cve:
- CVE-2021-40444
drilldown_search: []
impact: 80
message: An instance of $process_name$ was identified on $dest$ writing an inf or
@@ -41,6 +41,8 @@ tags:
asset_type: Endpoint
atomic_guid: []
confidence: 100
cve:
- CVE-2021-40444
drilldown_search: []
impact: 80
message: An instance of $parent_process_name$ spawning $process_name$ was identified
@@ -39,6 +39,8 @@ tags:
asset_type: Endpoint
atomic_guid: []
confidence: 60
cve:
- CVE-2021-44228
drilldown_search: []
impact: 90
message: Java performed outbound connections to default ports of LDAP or RMI on
@@ -39,6 +39,8 @@ tags:
asset_type: Endpoint
atomic_guid: []
confidence: 70
cve:
- CVE-2021-36942
drilldown_search: []
impact: 80
message: A remote host is enumerating a $dest$ to identify permissions. This is
@@ -34,6 +34,8 @@ tags:
asset_type: Endpoint
atomic_guid: []
confidence: 70
cve:
- CVE-2021-36942
drilldown_search: []
impact: 80
message: A Kerberos TGT was requested in a non-standard manner against $dest$, potentially
@@ -46,6 +46,8 @@ tags:
asset_type: Endpoint
atomic_guid: []
confidence: 90
cve:
- CVE-2021-44228
drilldown_search: []
impact: 90
message: PowerShell processes $process$ started with parameters to modify the execution
@@ -38,6 +38,9 @@ tags:
asset_type: Endpoint
atomic_guid: []
confidence: 90
cve:
- CVE-2021-34527
- CVE-2021-1675
drilldown_search: []
impact: 80
message: Suspicious print driver was loaded on endpoint $ComputerName$.
@@ -36,6 +36,9 @@ tags:
asset_type: Endpoint
atomic_guid: []
confidence: 90
cve:
- CVE-2021-34527
- CVE-2021-1675
drilldown_search: []
impact: 80
message: Suspicious printer spooler errors have occured on endpoint $ComputerName$
@@ -42,6 +42,8 @@ tags:
asset_type: Endpoint
atomic_guid: []
confidence: 50
cve:
- CVE-2021-40444
drilldown_search: []
impact: 30
message: An instance of $parent_process_name$ spawning $process_name$ was identified
@@ -44,6 +44,8 @@ tags:
asset_type: Endpoint
atomic_guid: []
confidence: 100
cve:
- CVE-2021-40444
drilldown_search: []
impact: 80
message: An instance of $parent_process_name$ spawning $process_name$ was identified
@@ -45,6 +45,8 @@ tags:
asset_type: Endpoint
atomic_guid: []
confidence: 100
cve:
- CVE-2021-34527
drilldown_search: []
impact: 70
message: A rundll32 process $process_name$ with no commandline argument like this
@@ -35,6 +35,8 @@ tags:
asset_type: Endpoint
atomic_guid: []
confidence: 100
cve:
- CVE-2021-36934
drilldown_search: []
impact: 80
message: The following process $process_name$ accessed the object $Object_Name$
@@ -36,6 +36,8 @@ tags:
asset_type: Endpoint
atomic_guid: []
confidence: 90
cve:
- CVE-2021-34527
drilldown_search: []
impact: 80
message: $parent_process$ has spawned $process_name$ on endpoint $ComputerName$.
@@ -27,6 +27,8 @@ tags:
asset_type: Endpoint
atomic_guid: []
confidence: 90
cve:
- CVE-2021-34527
drilldown_search: []
impact: 80
message: $Image$ with process id $process_id$ has loaded a driver from $ImageLoaded$
@@ -33,6 +33,8 @@ tags:
asset_type: Endpoint
atomic_guid: []
confidence: 90
cve:
- CVE-2021-34527
drilldown_search: []
impact: 80
message: $SourceImage$ was GrantedAccess open access to $TargetImage$ on endpoint
@@ -38,6 +38,8 @@ tags:
asset_type: Endpoint
atomic_guid: []
confidence: 90
cve:
- CVE-2021-34527
drilldown_search: []
impact: 80
message: $process_name$ has been identified writing dll's to $file_path$ on endpoint
@@ -33,6 +33,8 @@ tags:
asset_type: Endpoint
atomic_guid: []
confidence: 90
cve:
- CVE-2021-34527
drilldown_search: []
impact: 80
message: $process_name$ has been identified writing dll's to $file_path$ on endpoint
@@ -32,6 +32,9 @@ tags:
asset_type: Endpoint
atomic_guid: []
confidence: 70
cve:
- CVE-2021-42287
- CVE-2021-42278
drilldown_search: []
impact: 100
message: A computer account $Old_Account_Name$ was renamed with a suspicious computer
@@ -38,6 +38,9 @@ tags:
asset_type: Endpoint
atomic_guid: []
confidence: 60
cve:
- CVE-2021-42287
- CVE-2021-42278
drilldown_search: []
impact: 100
message: A suspicious Kerberos Service Ticket was requested by $Account_Name$
@@ -38,6 +38,8 @@ tags:
asset_type: Endpoint
atomic_guid: []
confidence: 70
cve:
- CVE-2021-34527
drilldown_search: []
impact: 70
message: Suspicious rundll32.exe process with no command line arguments executed
@@ -45,6 +45,10 @@ tags:
asset_type: Endpoint
atomic_guid: []
confidence: 80
cve:
- CVE-2021-34473
- CVE-2021-34523
- CVE-2021-31207
drilldown_search: []
impact: 70
message: Possible Web Shell execution on $dest$
@@ -36,6 +36,8 @@ tags:
asset_type: Endpoint
atomic_guid: []
confidence: 100
cve:
- CVE-2021-44228
drilldown_search: []
impact: 80
message: An instance of $process_name$ was identified on endpoint $dest$ attempting
@@ -40,6 +40,8 @@ tags:
asset_type: Endpoint
atomic_guid: []
confidence: 100
cve:
- CVE-2022-30190
drilldown_search: []
impact: 100
message: A parent process $parent_process_name$ has spawned a child process $process_name$
@@ -35,6 +35,8 @@ tags:
asset_type: Endpoint
atomic_guid: []
confidence: 50
cve:
- CVE-2021-44228
drilldown_search: []
impact: 80
message: An instance of $parent_process_name$ spawning $process_name$ was identified
@@ -40,6 +40,8 @@ tags:
asset_type: Endpoint
atomic_guid: []
confidence: 100
cve:
- CVE-2022-30190
drilldown_search: []
impact: 100
message: Office parent process $parent_process_name$ has spawned a child process
@@ -34,6 +34,8 @@ tags:
asset_type: Endpoint
atomic_guid: []
confidence: 50
cve:
- CVE-2021-31166
drilldown_search: []
impact: 50
message: tbd
@@ -32,6 +32,8 @@ tags:
asset_type: Endpoint
atomic_guid: []
confidence: 80
cve:
- CVE-2021-44228
drilldown_search: []
impact: 70
message: An outbound LDAP connection from $src_ip$ in your infrastructure connecting
@@ -23,6 +23,8 @@ tags:
asset_type: Endpoint
atomic_guid: []
confidence: 50
cve:
- CVE-2020-1350
drilldown_search: []
impact: 50
message: tbd
@@ -25,6 +25,8 @@ tags:
asset_type: Endpoint
atomic_guid: []
confidence: 50
cve:
- CVE-2020-1350
drilldown_search: []
impact: 50
message: tbd
@@ -28,6 +28,8 @@ tags:
asset_type: Network
atomic_guid: []
confidence: 50
cve:
- CVE-2020-1472
drilldown_search: []
impact: 50
message: tbd
@@ -33,6 +33,8 @@ tags:
asset_type: Web Server
atomic_guid: []
confidence: 70
cve:
- CVE-2022-1388
drilldown_search: []
impact: 100
message: An attempt to exploit CVE-2022-1388 against an F5 appliance $dest$ has
@@ -32,6 +32,9 @@ tags:
asset_type: Proxy
atomic_guid: []
confidence: 70
cve:
- CVE-2022-32151
- CVE-2022-32152
drilldown_search: []
impact: 60
message: The following $dest$ is using the self signed Splunk certificate.
@@ -37,6 +37,8 @@ tags:
asset_type: Web Server
atomic_guid: []
confidence: 100
cve:
- CVE-2022-26134
drilldown_search: []
impact: 100
message: A URL was requested related to CVE-2022-26134, a unauthenticated remote
@@ -26,6 +26,8 @@ tags:
asset_type: Network
atomic_guid: []
confidence: 50
cve:
- CVE-2020-5902
drilldown_search: []
impact: 50
message: tbd
@@ -49,6 +49,8 @@ tags:
asset_type: Web Server
atomic_guid: []
confidence: 70
cve:
- CVE-2022-42889
drilldown_search: []
impact: 70
message: A URL was requested related to Text4Shell on $dest$ by $src$.
@@ -52,6 +52,8 @@ tags:
asset_type: Network
atomic_guid: []
confidence: 90
cve:
- CVE-2022-40684
drilldown_search: []
impact: 90
message: Potential CVE-2022-40684 against a Fortinet appliance may be occurring
@@ -41,6 +41,8 @@ tags:
asset_type: Endpoint
atomic_guid: []
confidence: 30
cve:
- CVE-2021-44228
drilldown_search: []
impact: 50
message: CVE-2021-44228 Log4Shell triggered for host $dest$
@@ -36,6 +36,8 @@ tags:
asset_type: Endpoint
atomic_guid: []
confidence: 30
cve:
- CVE-2021-44228
drilldown_search: []
impact: 50
message: CVE-2021-44228 Log4Shell triggered for host $dest$
@@ -29,6 +29,8 @@ tags:
asset_type: Web Server
atomic_guid: []
confidence: 60
cve:
- CVE-2022-22965
drilldown_search: []
impact: 60
message: A URL was requested related to Spring4Shell POC code on $dest$ by $src$.
@@ -33,6 +33,8 @@ tags:
asset_type: Web Server
atomic_guid: []
confidence: 50
cve:
- CVE-2022-22954
drilldown_search: []
impact: 70
message: An attempt to exploit a VMware Server Side Injection CVE-2022-22954 on
@@ -34,6 +34,8 @@ tags:
asset_type: Web Server
atomic_guid: []
confidence: 70
cve:
- CVE-2022-22954
drilldown_search: []
impact: 70
message: An attempt to exploit a VMware Server Side Injection CVE-2022-22954 on
@@ -29,6 +29,8 @@ tags:
asset_type: Web Server
atomic_guid: []
confidence: 80
cve:
- CVE-2022-22965
drilldown_search: []
impact: 90
message: A suspicious URL has been requested against $dest$ by $src$, related to
@@ -28,6 +28,8 @@ tags:
asset_type: Web Server
atomic_guid: []
confidence: 80
cve:
- CVE-2022-22965
drilldown_search: []
impact: 90
message: A http body request related to Spring4Shell has been sent to $dest$ by
@@ -30,6 +30,8 @@ tags:
asset_type: Web Server
atomic_guid: []
confidence: 60
cve:
- CVE-2022-22963
drilldown_search: []
impact: 70
message: A suspicious URL has been requested against $dest$ by $src$, related to
@@ -44,6 +44,12 @@ tags:
asset_type: Web server
atomic_guid: []
confidence: 80
cve:
- CVE-2021-34523
- CVE-2021-34473
- CVE-2021-31207
- CVE-2022-41040
- CVE-2022-41082
drilldown_search: []
impact: 90
message: Activity related to ProxyShell or ProxyNotShell has been identified on