mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
Added cve tags to detections
This commit is contained in:
@@ -38,6 +38,8 @@ tags:
|
||||
asset_type: Web Server
|
||||
atomic_guid: []
|
||||
confidence: 40
|
||||
cve:
|
||||
- CVE-2022-32154
|
||||
drilldown_search: []
|
||||
impact: 50
|
||||
message: A potentially risky Splunk command has been run by $user$, kindly review.
|
||||
|
||||
@@ -28,6 +28,8 @@ tags:
|
||||
asset_type: Endpoint
|
||||
atomic_guid: []
|
||||
confidence: 80
|
||||
cve:
|
||||
- CVE-2022-26889
|
||||
drilldown_search: []
|
||||
impact: 50
|
||||
message: Path traversal exploitation attempt from $clientip$
|
||||
|
||||
+2
@@ -26,6 +26,8 @@ tags:
|
||||
asset_type: Endpoint
|
||||
atomic_guid: []
|
||||
confidence: 80
|
||||
cve:
|
||||
- CVE-2022-37438
|
||||
drilldown_search: []
|
||||
impact: 50
|
||||
message: Potential exposure of environment variables from url embedded in dashboard
|
||||
|
||||
+2
@@ -30,6 +30,8 @@ tags:
|
||||
asset_type: Endpoint
|
||||
atomic_guid: []
|
||||
confidence: 50
|
||||
cve:
|
||||
- CVE-2022-43571
|
||||
drilldown_search: []
|
||||
impact: 50
|
||||
message: Potential exploitation of Code Injection via Dashboard PDF generation.
|
||||
|
||||
+2
@@ -30,6 +30,8 @@ tags:
|
||||
asset_type: Web Server
|
||||
atomic_guid: []
|
||||
confidence: 30
|
||||
cve:
|
||||
- CVE-2022-32154
|
||||
drilldown_search: []
|
||||
impact: 90
|
||||
message: $user$ executed the 'delete' command, if this is unexpected it should be
|
||||
|
||||
+2
@@ -54,6 +54,8 @@ tags:
|
||||
asset_type: Web Server
|
||||
atomic_guid: []
|
||||
confidence: 40
|
||||
cve:
|
||||
- CVE-2022-32154
|
||||
drilldown_search: []
|
||||
impact: 50
|
||||
message: A risky Splunk command has ran by $user$ and should be reviewed.
|
||||
|
||||
+2
@@ -38,6 +38,8 @@ tags:
|
||||
asset_type: Web Server
|
||||
atomic_guid: []
|
||||
confidence: 40
|
||||
cve:
|
||||
- CVE-2022-32154
|
||||
drilldown_search: []
|
||||
impact: 50
|
||||
message: Abnormally long run time for risk SPL command seen by user $(Search_Activity.user).
|
||||
|
||||
+2
@@ -31,6 +31,8 @@ tags:
|
||||
asset_type: Endpoint
|
||||
atomic_guid: []
|
||||
confidence: 50
|
||||
cve:
|
||||
- CVE-2022-43566
|
||||
drilldown_search: []
|
||||
impact: 50
|
||||
message: Potential data exfiltration attack using SID query by $user$
|
||||
|
||||
+2
@@ -36,6 +36,8 @@ tags:
|
||||
asset_type: Endpoint
|
||||
atomic_guid: []
|
||||
confidence: 100
|
||||
cve:
|
||||
- CVE-2022-32153
|
||||
drilldown_search: []
|
||||
impact: 50
|
||||
message: $splunk_server$ may not be properly validating TLS Certificates
|
||||
|
||||
@@ -38,6 +38,8 @@ tags:
|
||||
asset_type: endpoint
|
||||
atomic_guid: []
|
||||
confidence: 80
|
||||
cve:
|
||||
- CVE-2022-32151
|
||||
drilldown_search: []
|
||||
impact: 25
|
||||
message: $hostname$ is not using TLS when forwarding data
|
||||
|
||||
@@ -25,6 +25,8 @@ tags:
|
||||
asset_type: Endpoint
|
||||
atomic_guid: []
|
||||
confidence: 100
|
||||
cve:
|
||||
- CVE-2021-3422
|
||||
drilldown_search: []
|
||||
impact: 50
|
||||
message: An attempt to exploit CVE-2021-3422 was detected from $src$ against $host$
|
||||
|
||||
@@ -27,6 +27,8 @@ tags:
|
||||
asset_type: Endpoint
|
||||
atomic_guid: []
|
||||
confidence: 75
|
||||
cve:
|
||||
- CVE-2022-37439
|
||||
drilldown_search: []
|
||||
impact: 100
|
||||
message: Potential exposure of environment variables from url embedded in dashboard
|
||||
|
||||
+2
@@ -34,6 +34,8 @@ tags:
|
||||
asset_type: Endpoint
|
||||
atomic_guid: []
|
||||
confidence: 70
|
||||
cve:
|
||||
- CVE-2022-32157
|
||||
drilldown_search: []
|
||||
impact: 50
|
||||
message: $peer$ downloaded apps from $host$
|
||||
|
||||
+2
@@ -44,6 +44,8 @@ tags:
|
||||
asset_type: Endpoint
|
||||
atomic_guid: []
|
||||
confidence: 100
|
||||
cve:
|
||||
- CVE-2022-32151
|
||||
drilldown_search: []
|
||||
impact: 50
|
||||
message: $splunk_server$ may not be properly validating TLS Certificates
|
||||
|
||||
+2
@@ -30,6 +30,8 @@ tags:
|
||||
asset_type: Endpoint
|
||||
atomic_guid: []
|
||||
confidence: 80
|
||||
cve:
|
||||
- CVE-2022-32152
|
||||
drilldown_search: []
|
||||
impact: 50
|
||||
message: Splunk default issued certificate at $host$
|
||||
|
||||
+2
@@ -32,6 +32,8 @@ tags:
|
||||
asset_type: Endpoint
|
||||
atomic_guid: []
|
||||
confidence: 80
|
||||
cve:
|
||||
- CVE-2022-32152
|
||||
drilldown_search: []
|
||||
impact: 50
|
||||
message: Failed to validate certificate on $host$
|
||||
|
||||
+2
@@ -28,6 +28,8 @@ tags:
|
||||
asset_type: Endpoint
|
||||
atomic_guid: []
|
||||
confidence: 90
|
||||
cve:
|
||||
- CVE-2022-43567
|
||||
drilldown_search: []
|
||||
impact: 90
|
||||
message: Possible exploitation attempt from $clientip$
|
||||
|
||||
@@ -27,6 +27,8 @@ tags:
|
||||
asset_type: Endpoint
|
||||
atomic_guid: []
|
||||
confidence: 50
|
||||
cve:
|
||||
- CVE-2022-43568
|
||||
drilldown_search: []
|
||||
impact: 50
|
||||
message: Potential XSS exploitation against radio template by $user$
|
||||
|
||||
@@ -28,6 +28,8 @@ tags:
|
||||
asset_type: Endpoint
|
||||
atomic_guid: []
|
||||
confidence: 50
|
||||
cve:
|
||||
- CVE-2022-43569
|
||||
drilldown_search: []
|
||||
impact: 50
|
||||
message: A potential XSS attempt has been detected from $user$
|
||||
|
||||
@@ -27,6 +27,8 @@ tags:
|
||||
asset_type: endpoint
|
||||
atomic_guid: []
|
||||
confidence: 80
|
||||
cve:
|
||||
- CVE-2021-33845
|
||||
drilldown_search: []
|
||||
impact: 50
|
||||
message: $TotalFailedAuths$ failed authentication events to Splunk from $src$ detected.
|
||||
|
||||
@@ -26,6 +26,8 @@ tags:
|
||||
asset_type: Endpoint
|
||||
atomic_guid: []
|
||||
confidence: 80
|
||||
cve:
|
||||
- CVE-2022-27183
|
||||
drilldown_search: []
|
||||
impact: 50
|
||||
message: A potential XSS attempt has been detected from $user$
|
||||
|
||||
+2
@@ -27,6 +27,8 @@ tags:
|
||||
asset_type: Endpoint
|
||||
atomic_guid: []
|
||||
confidence: 50
|
||||
cve:
|
||||
- CVE-2022-43561
|
||||
drilldown_search: []
|
||||
impact: 50
|
||||
message: Possible XSS exploitation attempt from $clientip$
|
||||
|
||||
@@ -18,6 +18,8 @@ tags:
|
||||
asset_type: Splunk Server
|
||||
atomic_guid: []
|
||||
confidence: 50
|
||||
cve:
|
||||
- CVE-2016-4859
|
||||
drilldown_search: []
|
||||
impact: 50
|
||||
message: tbd
|
||||
|
||||
@@ -24,6 +24,8 @@ tags:
|
||||
asset_type: Endpoint
|
||||
atomic_guid: []
|
||||
confidence: 50
|
||||
cve:
|
||||
- CVE-2017-5753
|
||||
drilldown_search: []
|
||||
impact: 50
|
||||
message: tbd
|
||||
|
||||
@@ -25,6 +25,8 @@ tags:
|
||||
asset_type: Splunk Server
|
||||
atomic_guid: []
|
||||
confidence: 50
|
||||
cve:
|
||||
- CVE-2018-11409
|
||||
drilldown_search: []
|
||||
impact: 50
|
||||
message: tbd
|
||||
|
||||
@@ -40,6 +40,8 @@ tags:
|
||||
asset_type: Endpoint
|
||||
atomic_guid: []
|
||||
confidence: 70
|
||||
cve:
|
||||
- CVE-2021-44228
|
||||
drilldown_search: []
|
||||
impact: 80
|
||||
message: An instance of $parent_process_name$ spawning $process_name$ was identified
|
||||
|
||||
@@ -33,6 +33,8 @@ tags:
|
||||
asset_type: Endpoint
|
||||
atomic_guid: []
|
||||
confidence: 50
|
||||
cve:
|
||||
- CVE-2018-8440
|
||||
drilldown_search: []
|
||||
impact: 50
|
||||
message: tbd
|
||||
|
||||
@@ -44,6 +44,8 @@ tags:
|
||||
asset_type: Endpoint
|
||||
atomic_guid: []
|
||||
confidence: 50
|
||||
cve:
|
||||
- CVE-2021-44228
|
||||
drilldown_search: []
|
||||
impact: 60
|
||||
message: An instance of $parent_process_name$ spawning $process_name$ was identified
|
||||
|
||||
@@ -39,6 +39,8 @@ tags:
|
||||
asset_type: Endpoint
|
||||
atomic_guid: []
|
||||
confidence: 100
|
||||
cve:
|
||||
- CVE-2021-40444
|
||||
drilldown_search: []
|
||||
impact: 80
|
||||
message: An instance of $parent_process_name$ spawning $process_name$ was identified
|
||||
|
||||
@@ -36,6 +36,8 @@ tags:
|
||||
asset_type: Endpoint
|
||||
atomic_guid: []
|
||||
confidence: 100
|
||||
cve:
|
||||
- CVE-2021-44228
|
||||
drilldown_search: []
|
||||
impact: 80
|
||||
message: An instance of $process_name$ was identified on endpoint $dest$ attempting
|
||||
|
||||
@@ -20,6 +20,8 @@ tags:
|
||||
asset_type: Endpoint
|
||||
atomic_guid: []
|
||||
confidence: 50
|
||||
cve:
|
||||
- CVE-2021-3156
|
||||
drilldown_search: []
|
||||
impact: 50
|
||||
message: tbd
|
||||
|
||||
@@ -23,6 +23,8 @@ tags:
|
||||
asset_type: Endpoint
|
||||
atomic_guid: []
|
||||
confidence: 50
|
||||
cve:
|
||||
- CVE-2021-3156
|
||||
drilldown_search: []
|
||||
impact: 50
|
||||
message: tbd
|
||||
|
||||
@@ -20,6 +20,8 @@ tags:
|
||||
asset_type: Endpoint
|
||||
atomic_guid: []
|
||||
confidence: 50
|
||||
cve:
|
||||
- CVE-2021-3156
|
||||
drilldown_search: []
|
||||
impact: 50
|
||||
message: tbd
|
||||
|
||||
@@ -27,6 +27,8 @@ tags:
|
||||
asset_type: Windows
|
||||
atomic_guid: []
|
||||
confidence: 70
|
||||
cve:
|
||||
- CVE-2020-1472
|
||||
drilldown_search: []
|
||||
impact: 70
|
||||
message: The following $EventCode$ occurred on $dest$ by $user$ with Logon Type
|
||||
|
||||
@@ -40,6 +40,8 @@ tags:
|
||||
asset_type: Endpoint
|
||||
atomic_guid: []
|
||||
confidence: 100
|
||||
cve:
|
||||
- CVE-2021-36934
|
||||
drilldown_search: []
|
||||
impact: 80
|
||||
message: PowerShell was identified running a script to capture the SAM hive on endpoint
|
||||
|
||||
@@ -0,0 +1,111 @@
|
||||
name: Hunting for Log4Shell
|
||||
id: 158b68fa-5d1a-11ec-aac8-acde48001122
|
||||
version: 1
|
||||
date: '2021-12-14'
|
||||
author: Michael Haag, Splunk
|
||||
status: production
|
||||
type: Hunting
|
||||
description: 'The following hunting query assists with quickly assessing CVE-2021-44228,
|
||||
or Log4Shell, activity mapped to the Web Datamodel. This is a combination query
|
||||
attempting to identify, score and dashboard. Because the Log4Shell vulnerability
|
||||
requires the string to be in the logs, this will work to identify the activity anywhere
|
||||
in the HTTP headers using _raw. Modify the first line to use the same pattern matching
|
||||
against other log sources. Scoring is based on a simple rubric of 0-5. 5 being the
|
||||
best match, and less than 5 meant to identify additional patterns that will equate
|
||||
to a higher total score. \
|
||||
|
||||
The first jndi match identifies the standard pattern of `{jndi:` \
|
||||
|
||||
jndi_fastmatch is meant to identify any jndi in the logs. The score is set low and
|
||||
is meant to be the "base" score used later. \
|
||||
|
||||
jndi_proto is a protocol match that identifies `jndi` and one of `ldap, ldaps, rmi,
|
||||
dns, nis, iiop, corba, nds, http, https.` \
|
||||
|
||||
all_match is a very well written regex by https://gist.github.com/Schvenn that identifies
|
||||
nearly all patterns of this attack behavior. \
|
||||
|
||||
env works to identify environment variables in the header, meant to capture `AWS_ACCESS_KEY_ID`,
|
||||
`AWS_SECRET_ACCESS_KEY` and `env`. \
|
||||
|
||||
uri_detect is string match looking for the common uri paths currently being scanned/abused
|
||||
in the wild. \
|
||||
|
||||
keywords matches on enumerated values that, like `$ctx:loginId`, that may be found
|
||||
in the header used by the adversary. \
|
||||
|
||||
lookup matching is meant to catch some basic obfuscation that has been identified
|
||||
using upper, lower and date. \
|
||||
|
||||
Scoring will then occur based on any findings. The base score is meant to be 2 ,
|
||||
created by jndi_fastmatch. Everything else is meant to increase that score. \
|
||||
|
||||
Finally, a simple table is created to show the scoring and the _raw field. Sort
|
||||
based on score or columns of interest.'
|
||||
data_source: []
|
||||
search: '| from datamodel Web.Web | eval jndi=if(match(_raw, "(\{|%7B)[jJnNdDiI]{4}:"),4,0)
|
||||
| eval jndi_fastmatch=if(match(_raw, "[jJnNdDiI]{4}"),2,0) | eval jndi_proto=if(match(_raw,"(?i)jndi:(ldap[s]?|rmi|dns|nis|iiop|corba|nds|http|https):"),5,0)
|
||||
| eval all_match = if(match(_raw, "(?i)(%(25){0,}20|\s)*(%(25){0,}24|\$)(%(25){0,}20|\s)*(%(25){0,}7B|{)(%(25){0,}20|\s)*(%(25){0,}(6A|4A)|J)(%(25){0,}(6E|4E)|N)(%(25){0,}(64|44)|D)(%(25){0,}(69|49)|I)(%(25){0,}20|\s)*(%(25){0,}3A|:)[\w\%]+(%(25){1,}3A|:)(%(25){1,}2F|\/)[^\n]+"),5,0)
|
||||
| eval env_var = if(match(_raw, "env:") OR match(_raw, "env:AWS_ACCESS_KEY_ID")
|
||||
OR match(_raw, "env:AWS_SECRET_ACCESS_KEY"),5,0) | eval uridetect = if(match(_raw,
|
||||
"(?i)Basic\/Command\/Base64|Basic\/ReverseShell|Basic\/TomcatMemshell|Basic\/JBossMemshell|Basic\/WebsphereMemshell|Basic\/SpringMemshell|Basic\/Command|Deserialization\/CommonsCollectionsK|Deserialization\/CommonsBeanutils|Deserialization\/Jre8u20\/TomcatMemshell|Deserialization\/CVE_2020_2555\/WeblogicMemshell|TomcatBypass|GroovyBypass|WebsphereBypass"),4,0)
|
||||
| eval keywords = if(match(_raw,"(?i)\$\{ctx\:loginId\}|\$\{map\:type\}|\$\{filename\}|\$\{date\:MM-dd-yyyy\}|\$\{docker\:containerId\}|\$\{docker\:containerName\}|\$\{docker\:imageName\}|\$\{env\:USER\}|\$\{event\:Marker\}|\$\{mdc\:UserId\}|\$\{java\:runtime\}|\$\{java\:vm\}|\$\{java\:os\}|\$\{jndi\:logging/context-name\}|\$\{hostName\}|\$\{docker\:containerId\}|\$\{k8s\:accountName\}|\$\{k8s\:clusterName\}|\$\{k8s\:containerId\}|\$\{k8s\:containerName\}|\$\{k8s\:host\}|\$\{k8s\:labels.app\}|\$\{k8s\:labels.podTemplateHash\}|\$\{k8s\:masterUrl\}|\$\{k8s\:namespaceId\}|\$\{k8s\:namespaceName\}|\$\{k8s\:podId\}|\$\{k8s\:podIp\}|\$\{k8s\:podName\}|\$\{k8s\:imageId\}|\$\{k8s\:imageName\}|\$\{log4j\:configLocation\}|\$\{log4j\:configParentLocation\}|\$\{spring\:spring.application.name\}|\$\{main\:myString\}|\$\{main\:0\}|\$\{main\:1\}|\$\{main\:2\}|\$\{main\:3\}|\$\{main\:4\}|\$\{main\:bar\}|\$\{name\}|\$\{marker\}|\$\{marker\:name\}|\$\{spring\:profiles.active[0]|\$\{sys\:logPath\}|\$\{web\:rootDir\}|\$\{sys\:user.name\}"),4,0)
|
||||
| eval obf = if(match(_raw, "(\$|%24)[^ /]*({|%7b)[^ /]*(j|%6a)[^ /]*(n|%6e)[^ /]*(d|%64)[^
|
||||
/]*(i|%69)[^ /]*(:|%3a)[^ /]*(:|%3a)[^ /]*(/|%2f)"),5,0) | eval lookups = if(match(_raw,
|
||||
"(?i)({|%7b)(main|sys|k8s|spring|lower|upper|env|date|sd)"),4,0) | addtotals fieldname=Score,
|
||||
jndi, jndi_proto, env_var, uridetect, all_match, jndi_fastmatch, keywords, obf,
|
||||
lookups | where Score > 2 | stats values(Score) by jndi, jndi_proto, env_var, uridetect,
|
||||
all_match, jndi_fastmatch, keywords, lookups, obf, _raw | `hunting_for_log4shell_filter`'
|
||||
how_to_implement: Out of the box, the Web datamodel is required to be pre-filled.
|
||||
However, tested was performed against raw httpd access logs. Change the first line
|
||||
to any dataset to pass the regex's against.
|
||||
known_false_positives: It is highly possible you will find false positives, however,
|
||||
the base score is set to 2 for _any_ jndi found in raw logs. tune and change as
|
||||
needed, include any filtering.
|
||||
references:
|
||||
- https://gist.github.com/olafhartong/916ebc673ba066537740164f7e7e1d72
|
||||
- https://gist.github.com/Neo23x0/e4c8b03ff8cdf1fa63b7d15db6e3860b#gistcomment-3994449
|
||||
- https://regex101.com/r/OSrm0q/1/
|
||||
- https://github.com/Neo23x0/signature-base/blob/master/yara/expl_log4j_cve_2021_44228.yar
|
||||
- https://news.sophos.com/en-us/2021/12/12/log4shell-hell-anatomy-of-an-exploit-outbreak/
|
||||
- https://gist.github.com/MHaggis/1899b8554f38c8692a9fb0ceba60b44c
|
||||
- https://twitter.com/sasi2103/status/1469764719850442760?s=20
|
||||
tags:
|
||||
analytic_story:
|
||||
- Log4Shell CVE-2021-44228
|
||||
- CISA AA22-320A
|
||||
asset_type: Web Server
|
||||
atomic_guid: []
|
||||
confidence: 50
|
||||
cve:
|
||||
- CVE-2021-44228
|
||||
drilldown_search: []
|
||||
impact: 80
|
||||
message: Hunting for Log4Shell exploitation has occurred.
|
||||
mitre_attack_id:
|
||||
- T1190
|
||||
observable:
|
||||
- name: dest
|
||||
type: Hostname
|
||||
role:
|
||||
- Victim
|
||||
- name: http_method
|
||||
type: Other
|
||||
role:
|
||||
- Other
|
||||
- name: src
|
||||
type: Other
|
||||
role:
|
||||
- Other
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
risk_score: 40
|
||||
security_domain: network
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1190/java/log4shell-nginx.log
|
||||
source: /var/log/nginx/access.log
|
||||
sourcetype: nginx:plus:kv
|
||||
@@ -27,6 +27,8 @@ tags:
|
||||
asset_type: Web Server
|
||||
atomic_guid: []
|
||||
confidence: 50
|
||||
cve:
|
||||
- CVE-2021-44228
|
||||
drilldown_search: []
|
||||
impact: 80
|
||||
message: A Java user agent $http_user_agent$ was performing a $http_method$ to retrieve
|
||||
|
||||
@@ -40,6 +40,8 @@ tags:
|
||||
asset_type: Endpoint
|
||||
atomic_guid: []
|
||||
confidence: 70
|
||||
cve:
|
||||
- CVE-2022-22965
|
||||
drilldown_search: []
|
||||
impact: 60
|
||||
message: An instance of $process_name$ was identified on endpoint $dest$ writing
|
||||
|
||||
@@ -37,6 +37,8 @@ tags:
|
||||
asset_type: Endpoint
|
||||
atomic_guid: []
|
||||
confidence: 50
|
||||
cve:
|
||||
- CVE-2021-44228
|
||||
drilldown_search: []
|
||||
impact: 80
|
||||
message: An instance of $parent_process_name$ spawning $process_name$ was identified
|
||||
|
||||
@@ -37,6 +37,8 @@ tags:
|
||||
asset_type: Endpoint
|
||||
atomic_guid: []
|
||||
confidence: 70
|
||||
cve:
|
||||
- CVE-2021-4034
|
||||
drilldown_search: []
|
||||
impact: 80
|
||||
message: An instance of $parent_process_name$ spawning $process_name$ was identified
|
||||
|
||||
@@ -32,6 +32,8 @@ tags:
|
||||
asset_type: Endpoint
|
||||
atomic_guid: []
|
||||
confidence: 100
|
||||
cve:
|
||||
- CVE-2021-40444
|
||||
drilldown_search: []
|
||||
impact: 80
|
||||
message: An instance of $process_name$ was identified on endpoint $dest$ loading
|
||||
|
||||
@@ -45,6 +45,8 @@ tags:
|
||||
asset_type: Endpoint
|
||||
atomic_guid: []
|
||||
confidence: 70
|
||||
cve:
|
||||
- CVE-2021-41379
|
||||
drilldown_search: []
|
||||
impact: 80
|
||||
message: The following module $ImageLoaded$ was loaded by $Image$ outside of the
|
||||
|
||||
@@ -42,6 +42,8 @@ tags:
|
||||
asset_type: Endpoint
|
||||
atomic_guid: []
|
||||
confidence: 100
|
||||
cve:
|
||||
- CVE-2021-40444
|
||||
drilldown_search: []
|
||||
impact: 80
|
||||
message: An instance of $process_name$ was identified on $dest$ writing an inf or
|
||||
|
||||
@@ -41,6 +41,8 @@ tags:
|
||||
asset_type: Endpoint
|
||||
atomic_guid: []
|
||||
confidence: 100
|
||||
cve:
|
||||
- CVE-2021-40444
|
||||
drilldown_search: []
|
||||
impact: 80
|
||||
message: An instance of $parent_process_name$ spawning $process_name$ was identified
|
||||
|
||||
+2
@@ -39,6 +39,8 @@ tags:
|
||||
asset_type: Endpoint
|
||||
atomic_guid: []
|
||||
confidence: 60
|
||||
cve:
|
||||
- CVE-2021-44228
|
||||
drilldown_search: []
|
||||
impact: 90
|
||||
message: Java performed outbound connections to default ports of LDAP or RMI on
|
||||
|
||||
@@ -39,6 +39,8 @@ tags:
|
||||
asset_type: Endpoint
|
||||
atomic_guid: []
|
||||
confidence: 70
|
||||
cve:
|
||||
- CVE-2021-36942
|
||||
drilldown_search: []
|
||||
impact: 80
|
||||
message: A remote host is enumerating a $dest$ to identify permissions. This is
|
||||
|
||||
@@ -34,6 +34,8 @@ tags:
|
||||
asset_type: Endpoint
|
||||
atomic_guid: []
|
||||
confidence: 70
|
||||
cve:
|
||||
- CVE-2021-36942
|
||||
drilldown_search: []
|
||||
impact: 80
|
||||
message: A Kerberos TGT was requested in a non-standard manner against $dest$, potentially
|
||||
|
||||
@@ -46,6 +46,8 @@ tags:
|
||||
asset_type: Endpoint
|
||||
atomic_guid: []
|
||||
confidence: 90
|
||||
cve:
|
||||
- CVE-2021-44228
|
||||
drilldown_search: []
|
||||
impact: 90
|
||||
message: PowerShell processes $process$ started with parameters to modify the execution
|
||||
|
||||
@@ -38,6 +38,9 @@ tags:
|
||||
asset_type: Endpoint
|
||||
atomic_guid: []
|
||||
confidence: 90
|
||||
cve:
|
||||
- CVE-2021-34527
|
||||
- CVE-2021-1675
|
||||
drilldown_search: []
|
||||
impact: 80
|
||||
message: Suspicious print driver was loaded on endpoint $ComputerName$.
|
||||
|
||||
@@ -36,6 +36,9 @@ tags:
|
||||
asset_type: Endpoint
|
||||
atomic_guid: []
|
||||
confidence: 90
|
||||
cve:
|
||||
- CVE-2021-34527
|
||||
- CVE-2021-1675
|
||||
drilldown_search: []
|
||||
impact: 80
|
||||
message: Suspicious printer spooler errors have occured on endpoint $ComputerName$
|
||||
|
||||
@@ -42,6 +42,8 @@ tags:
|
||||
asset_type: Endpoint
|
||||
atomic_guid: []
|
||||
confidence: 50
|
||||
cve:
|
||||
- CVE-2021-40444
|
||||
drilldown_search: []
|
||||
impact: 30
|
||||
message: An instance of $parent_process_name$ spawning $process_name$ was identified
|
||||
|
||||
@@ -44,6 +44,8 @@ tags:
|
||||
asset_type: Endpoint
|
||||
atomic_guid: []
|
||||
confidence: 100
|
||||
cve:
|
||||
- CVE-2021-40444
|
||||
drilldown_search: []
|
||||
impact: 80
|
||||
message: An instance of $parent_process_name$ spawning $process_name$ was identified
|
||||
|
||||
@@ -45,6 +45,8 @@ tags:
|
||||
asset_type: Endpoint
|
||||
atomic_guid: []
|
||||
confidence: 100
|
||||
cve:
|
||||
- CVE-2021-34527
|
||||
drilldown_search: []
|
||||
impact: 70
|
||||
message: A rundll32 process $process_name$ with no commandline argument like this
|
||||
|
||||
@@ -35,6 +35,8 @@ tags:
|
||||
asset_type: Endpoint
|
||||
atomic_guid: []
|
||||
confidence: 100
|
||||
cve:
|
||||
- CVE-2021-36934
|
||||
drilldown_search: []
|
||||
impact: 80
|
||||
message: The following process $process_name$ accessed the object $Object_Name$
|
||||
|
||||
@@ -36,6 +36,8 @@ tags:
|
||||
asset_type: Endpoint
|
||||
atomic_guid: []
|
||||
confidence: 90
|
||||
cve:
|
||||
- CVE-2021-34527
|
||||
drilldown_search: []
|
||||
impact: 80
|
||||
message: $parent_process$ has spawned $process_name$ on endpoint $ComputerName$.
|
||||
|
||||
@@ -27,6 +27,8 @@ tags:
|
||||
asset_type: Endpoint
|
||||
atomic_guid: []
|
||||
confidence: 90
|
||||
cve:
|
||||
- CVE-2021-34527
|
||||
drilldown_search: []
|
||||
impact: 80
|
||||
message: $Image$ with process id $process_id$ has loaded a driver from $ImageLoaded$
|
||||
|
||||
@@ -33,6 +33,8 @@ tags:
|
||||
asset_type: Endpoint
|
||||
atomic_guid: []
|
||||
confidence: 90
|
||||
cve:
|
||||
- CVE-2021-34527
|
||||
drilldown_search: []
|
||||
impact: 80
|
||||
message: $SourceImage$ was GrantedAccess open access to $TargetImage$ on endpoint
|
||||
|
||||
@@ -38,6 +38,8 @@ tags:
|
||||
asset_type: Endpoint
|
||||
atomic_guid: []
|
||||
confidence: 90
|
||||
cve:
|
||||
- CVE-2021-34527
|
||||
drilldown_search: []
|
||||
impact: 80
|
||||
message: $process_name$ has been identified writing dll's to $file_path$ on endpoint
|
||||
|
||||
@@ -33,6 +33,8 @@ tags:
|
||||
asset_type: Endpoint
|
||||
atomic_guid: []
|
||||
confidence: 90
|
||||
cve:
|
||||
- CVE-2021-34527
|
||||
drilldown_search: []
|
||||
impact: 80
|
||||
message: $process_name$ has been identified writing dll's to $file_path$ on endpoint
|
||||
|
||||
@@ -32,6 +32,9 @@ tags:
|
||||
asset_type: Endpoint
|
||||
atomic_guid: []
|
||||
confidence: 70
|
||||
cve:
|
||||
- CVE-2021-42287
|
||||
- CVE-2021-42278
|
||||
drilldown_search: []
|
||||
impact: 100
|
||||
message: A computer account $Old_Account_Name$ was renamed with a suspicious computer
|
||||
|
||||
@@ -38,6 +38,9 @@ tags:
|
||||
asset_type: Endpoint
|
||||
atomic_guid: []
|
||||
confidence: 60
|
||||
cve:
|
||||
- CVE-2021-42287
|
||||
- CVE-2021-42278
|
||||
drilldown_search: []
|
||||
impact: 100
|
||||
message: A suspicious Kerberos Service Ticket was requested by $Account_Name$
|
||||
|
||||
@@ -38,6 +38,8 @@ tags:
|
||||
asset_type: Endpoint
|
||||
atomic_guid: []
|
||||
confidence: 70
|
||||
cve:
|
||||
- CVE-2021-34527
|
||||
drilldown_search: []
|
||||
impact: 70
|
||||
message: Suspicious rundll32.exe process with no command line arguments executed
|
||||
|
||||
@@ -45,6 +45,10 @@ tags:
|
||||
asset_type: Endpoint
|
||||
atomic_guid: []
|
||||
confidence: 80
|
||||
cve:
|
||||
- CVE-2021-34473
|
||||
- CVE-2021-34523
|
||||
- CVE-2021-31207
|
||||
drilldown_search: []
|
||||
impact: 70
|
||||
message: Possible Web Shell execution on $dest$
|
||||
|
||||
@@ -36,6 +36,8 @@ tags:
|
||||
asset_type: Endpoint
|
||||
atomic_guid: []
|
||||
confidence: 100
|
||||
cve:
|
||||
- CVE-2021-44228
|
||||
drilldown_search: []
|
||||
impact: 80
|
||||
message: An instance of $process_name$ was identified on endpoint $dest$ attempting
|
||||
|
||||
@@ -40,6 +40,8 @@ tags:
|
||||
asset_type: Endpoint
|
||||
atomic_guid: []
|
||||
confidence: 100
|
||||
cve:
|
||||
- CVE-2022-30190
|
||||
drilldown_search: []
|
||||
impact: 100
|
||||
message: A parent process $parent_process_name$ has spawned a child process $process_name$
|
||||
|
||||
@@ -35,6 +35,8 @@ tags:
|
||||
asset_type: Endpoint
|
||||
atomic_guid: []
|
||||
confidence: 50
|
||||
cve:
|
||||
- CVE-2021-44228
|
||||
drilldown_search: []
|
||||
impact: 80
|
||||
message: An instance of $parent_process_name$ spawning $process_name$ was identified
|
||||
|
||||
@@ -40,6 +40,8 @@ tags:
|
||||
asset_type: Endpoint
|
||||
atomic_guid: []
|
||||
confidence: 100
|
||||
cve:
|
||||
- CVE-2022-30190
|
||||
drilldown_search: []
|
||||
impact: 100
|
||||
message: Office parent process $parent_process_name$ has spawned a child process
|
||||
|
||||
@@ -34,6 +34,8 @@ tags:
|
||||
asset_type: Endpoint
|
||||
atomic_guid: []
|
||||
confidence: 50
|
||||
cve:
|
||||
- CVE-2021-31166
|
||||
drilldown_search: []
|
||||
impact: 50
|
||||
message: tbd
|
||||
|
||||
@@ -32,6 +32,8 @@ tags:
|
||||
asset_type: Endpoint
|
||||
atomic_guid: []
|
||||
confidence: 80
|
||||
cve:
|
||||
- CVE-2021-44228
|
||||
drilldown_search: []
|
||||
impact: 70
|
||||
message: An outbound LDAP connection from $src_ip$ in your infrastructure connecting
|
||||
|
||||
@@ -23,6 +23,8 @@ tags:
|
||||
asset_type: Endpoint
|
||||
atomic_guid: []
|
||||
confidence: 50
|
||||
cve:
|
||||
- CVE-2020-1350
|
||||
drilldown_search: []
|
||||
impact: 50
|
||||
message: tbd
|
||||
|
||||
@@ -25,6 +25,8 @@ tags:
|
||||
asset_type: Endpoint
|
||||
atomic_guid: []
|
||||
confidence: 50
|
||||
cve:
|
||||
- CVE-2020-1350
|
||||
drilldown_search: []
|
||||
impact: 50
|
||||
message: tbd
|
||||
|
||||
@@ -28,6 +28,8 @@ tags:
|
||||
asset_type: Network
|
||||
atomic_guid: []
|
||||
confidence: 50
|
||||
cve:
|
||||
- CVE-2020-1472
|
||||
drilldown_search: []
|
||||
impact: 50
|
||||
message: tbd
|
||||
|
||||
@@ -33,6 +33,8 @@ tags:
|
||||
asset_type: Web Server
|
||||
atomic_guid: []
|
||||
confidence: 70
|
||||
cve:
|
||||
- CVE-2022-1388
|
||||
drilldown_search: []
|
||||
impact: 100
|
||||
message: An attempt to exploit CVE-2022-1388 against an F5 appliance $dest$ has
|
||||
|
||||
@@ -32,6 +32,9 @@ tags:
|
||||
asset_type: Proxy
|
||||
atomic_guid: []
|
||||
confidence: 70
|
||||
cve:
|
||||
- CVE-2022-32151
|
||||
- CVE-2022-32152
|
||||
drilldown_search: []
|
||||
impact: 60
|
||||
message: The following $dest$ is using the self signed Splunk certificate.
|
||||
|
||||
+2
@@ -37,6 +37,8 @@ tags:
|
||||
asset_type: Web Server
|
||||
atomic_guid: []
|
||||
confidence: 100
|
||||
cve:
|
||||
- CVE-2022-26134
|
||||
drilldown_search: []
|
||||
impact: 100
|
||||
message: A URL was requested related to CVE-2022-26134, a unauthenticated remote
|
||||
|
||||
@@ -26,6 +26,8 @@ tags:
|
||||
asset_type: Network
|
||||
atomic_guid: []
|
||||
confidence: 50
|
||||
cve:
|
||||
- CVE-2020-5902
|
||||
drilldown_search: []
|
||||
impact: 50
|
||||
message: tbd
|
||||
|
||||
@@ -49,6 +49,8 @@ tags:
|
||||
asset_type: Web Server
|
||||
atomic_guid: []
|
||||
confidence: 70
|
||||
cve:
|
||||
- CVE-2022-42889
|
||||
drilldown_search: []
|
||||
impact: 70
|
||||
message: A URL was requested related to Text4Shell on $dest$ by $src$.
|
||||
|
||||
@@ -52,6 +52,8 @@ tags:
|
||||
asset_type: Network
|
||||
atomic_guid: []
|
||||
confidence: 90
|
||||
cve:
|
||||
- CVE-2022-40684
|
||||
drilldown_search: []
|
||||
impact: 90
|
||||
message: Potential CVE-2022-40684 against a Fortinet appliance may be occurring
|
||||
|
||||
@@ -41,6 +41,8 @@ tags:
|
||||
asset_type: Endpoint
|
||||
atomic_guid: []
|
||||
confidence: 30
|
||||
cve:
|
||||
- CVE-2021-44228
|
||||
drilldown_search: []
|
||||
impact: 50
|
||||
message: CVE-2021-44228 Log4Shell triggered for host $dest$
|
||||
|
||||
@@ -36,6 +36,8 @@ tags:
|
||||
asset_type: Endpoint
|
||||
atomic_guid: []
|
||||
confidence: 30
|
||||
cve:
|
||||
- CVE-2021-44228
|
||||
drilldown_search: []
|
||||
impact: 50
|
||||
message: CVE-2021-44228 Log4Shell triggered for host $dest$
|
||||
|
||||
@@ -29,6 +29,8 @@ tags:
|
||||
asset_type: Web Server
|
||||
atomic_guid: []
|
||||
confidence: 60
|
||||
cve:
|
||||
- CVE-2022-22965
|
||||
drilldown_search: []
|
||||
impact: 60
|
||||
message: A URL was requested related to Spring4Shell POC code on $dest$ by $src$.
|
||||
|
||||
@@ -33,6 +33,8 @@ tags:
|
||||
asset_type: Web Server
|
||||
atomic_guid: []
|
||||
confidence: 50
|
||||
cve:
|
||||
- CVE-2022-22954
|
||||
drilldown_search: []
|
||||
impact: 70
|
||||
message: An attempt to exploit a VMware Server Side Injection CVE-2022-22954 on
|
||||
|
||||
+2
@@ -34,6 +34,8 @@ tags:
|
||||
asset_type: Web Server
|
||||
atomic_guid: []
|
||||
confidence: 70
|
||||
cve:
|
||||
- CVE-2022-22954
|
||||
drilldown_search: []
|
||||
impact: 70
|
||||
message: An attempt to exploit a VMware Server Side Injection CVE-2022-22954 on
|
||||
|
||||
@@ -29,6 +29,8 @@ tags:
|
||||
asset_type: Web Server
|
||||
atomic_guid: []
|
||||
confidence: 80
|
||||
cve:
|
||||
- CVE-2022-22965
|
||||
drilldown_search: []
|
||||
impact: 90
|
||||
message: A suspicious URL has been requested against $dest$ by $src$, related to
|
||||
|
||||
@@ -28,6 +28,8 @@ tags:
|
||||
asset_type: Web Server
|
||||
atomic_guid: []
|
||||
confidence: 80
|
||||
cve:
|
||||
- CVE-2022-22965
|
||||
drilldown_search: []
|
||||
impact: 90
|
||||
message: A http body request related to Spring4Shell has been sent to $dest$ by
|
||||
|
||||
@@ -30,6 +30,8 @@ tags:
|
||||
asset_type: Web Server
|
||||
atomic_guid: []
|
||||
confidence: 60
|
||||
cve:
|
||||
- CVE-2022-22963
|
||||
drilldown_search: []
|
||||
impact: 70
|
||||
message: A suspicious URL has been requested against $dest$ by $src$, related to
|
||||
|
||||
@@ -44,6 +44,12 @@ tags:
|
||||
asset_type: Web server
|
||||
atomic_guid: []
|
||||
confidence: 80
|
||||
cve:
|
||||
- CVE-2021-34523
|
||||
- CVE-2021-34473
|
||||
- CVE-2021-31207
|
||||
- CVE-2022-41040
|
||||
- CVE-2022-41082
|
||||
drilldown_search: []
|
||||
impact: 90
|
||||
message: Activity related to ProxyShell or ProxyNotShell has been identified on
|
||||
|
||||
Reference in New Issue
Block a user