From 38eef722ea94c6788324613db375c83cfd6ff230 Mon Sep 17 00:00:00 2001 From: P4T12ICK Date: Mon, 2 Jan 2023 10:03:58 +0100 Subject: [PATCH] Added cve tags to detections --- ...ct_risky_spl_using_pretrained_ml_model.yml | 2 + .../path_traversal_spl_injection.yml | 2 + ...scovery_drilldown_dashboard_disclosure.yml | 2 + ...on_via_custom_dashboard_leading_to_rce.yml | 2 + ...and_scripting_interpreter_delete_usage.yml | 2 + ...d_scripting_interpreter_risky_commands.yml | 2 + ...d_scripting_interpreter_risky_spl_mltk.yml | 2 + ...om_analytics_workspace_using_sid_query.yml | 2 + ...al_certificates_infrastructure_version.yml | 2 + ...igital_certificates_lack_of_encryption.yml | 2 + .../splunk_dos_via_malformed_s2s_request.yml | 2 + ...ndpoint_denial_of_service_dos_zip_bomb.yml | 2 + ...s_injection_forwarder_bundle_downloads.yml | 2 + ...sonation_weak_encryption_configuration.yml | 2 + ...personation_weak_encryption_selfsigned.yml | 2 + ...sonation_weak_encryption_simplerequest.yml | 2 + ..._gateway__splunk_mobile_alerts_feature.yml | 2 + ...ected_xss_in_the_templates_lists_radio.yml | 2 + ...ed_xss_via_data_model_objectname_field.yml | 2 + .../splunk_user_enumeration_attempt.yml | 2 + .../splunk_xss_in_monitoring_console.yml | 2 + ...ave_table_dialog_header_in_search_page.yml | 2 + .../open_redirect_in_splunk_web.yml | 2 + ...pectre_and_meltdown_vulnerable_systems.yml | 2 + ...lunk_enterprise_information_disclosure.yml | 2 + .../endpoint/any_powershell_downloadfile.yml | 2 + .../child_processes_of_spoolsv_exe.yml | 2 + ...cmd_carry_out_string_command_parameter.yml | 2 + ..._loading_from_world_writable_directory.yml | 2 + .../curl_download_and_bash_execution.yml | 2 + .../detect_baron_samedit_cve_2021_3156.yml | 2 + ...t_baron_samedit_cve_2021_3156_segfault.yml | 2 + ...aron_samedit_cve_2021_3156_via_osquery.yml | 2 + ...omputer_changed_with_anonymous_account.yml | 2 + ...f_shadowcopy_with_script_block_logging.yml | 2 + .../endpoint/hunting_for_log4shell.yml | 111 ++++++++++++++++++ ...class_file_download_by_java_user_agent.yml | 2 + .../endpoint/java_writing_jsp_file.yml | 2 + .../endpoint/linux_java_spawning_shell.yml | 2 + .../linux_pkexec_privilege_escalation.yml | 2 + .../mshtml_module_load_in_office_product.yml | 2 + ...msi_module_loaded_by_non_system_binary.yml | 2 + .../office_product_writing_cab_or_inf.yml | 2 + .../endpoint/office_spawning_control.yml | 2 + ...nnection_from_java_using_default_ports.yml | 2 + ...etitpotam_network_share_access_request.yml | 2 + ...tpotam_suspicious_kerberos_tgt_request.yml | 2 + ...connect_to_internet_with_hidden_window.yml | 2 + .../print_spooler_adding_a_printer_driver.yml | 3 + ...print_spooler_failed_to_load_a_plug_in.yml | 3 + .../endpoint/rundll32_control_rundll_hunt.yml | 2 + ...ontrol_rundll_world_writable_directory.yml | 2 + ...no_command_line_arguments_with_network.yml | 2 + .../sam_database_file_access_attempt.yml | 2 + .../endpoint/spoolsv_spawning_rundll32.yml | 2 + .../spoolsv_suspicious_loaded_modules.yml | 2 + .../spoolsv_suspicious_process_access.yml | 2 + .../endpoint/spoolsv_writing_a_dll.yml | 2 + .../spoolsv_writing_a_dll___sysmon.yml | 2 + ...uspicious_computer_account_name_change.yml | 3 + ...icious_kerberos_service_ticket_request.yml | 3 + ...ous_rundll32_no_command_line_arguments.yml | 2 + .../endpoint/w3wp_spawning_shell.yml | 4 + .../wget_download_and_bash_execution.yml | 2 + ...s_execute_arbitrary_commands_with_msdt.yml | 2 + .../endpoint/windows_java_spawning_shells.yml | 2 + .../windows_office_product_spawning_msdt.yml | 2 + .../endpoint/winrm_spawning_a_process.yml | 2 + .../network/detect_outbound_ldap_traffic.yml | 2 + ...t_windows_dns_sigred_via_splunk_stream.yml | 2 + .../detect_windows_dns_sigred_via_zeek.yml | 2 + .../network/detect_zerologon_via_zeek.yml | 2 + ...ntrol_rest_vulnerability_cve_2022_1388.yml | 2 + ...splunk_identified_ssl_tls_certificates.yml | 3 + ...d_remote_code_execution_cve_2022_26134.yml | 2 + .../web/detect_f5_tmui_rce_cve_2020_5902.yml | 2 + ...ng_application_via_apache_commons_text.yml | 2 + .../web/fortinet_appliance_auth_bypass.yml | 2 + ...g4shell_jndi_payload_injection_attempt.yml | 2 + ...oad_injection_with_outbound_connection.yml | 2 + .../web/spring4shell_payload_url_request.yml | 2 + ...re_server_side_template_injection_hunt.yml | 2 + ...emarker_server_side_template_injection.yml | 2 + .../web/web_jsp_request_via_url.yml | 2 + ...spring4shell_http_request_class_module.yml | 2 + ...b_spring_cloud_function_functionrouter.yml | 2 + ...ndows_exchange_autodiscover_ssrf_abuse.yml | 6 + 87 files changed, 294 insertions(+) create mode 100644 converted_detections/endpoint/hunting_for_log4shell.yml diff --git a/converted_detections/application/detect_risky_spl_using_pretrained_ml_model.yml b/converted_detections/application/detect_risky_spl_using_pretrained_ml_model.yml index 25b2ea9516..e339b5d76c 100644 --- a/converted_detections/application/detect_risky_spl_using_pretrained_ml_model.yml +++ b/converted_detections/application/detect_risky_spl_using_pretrained_ml_model.yml @@ -38,6 +38,8 @@ tags: asset_type: Web Server atomic_guid: [] confidence: 40 + cve: + - CVE-2022-32154 drilldown_search: [] impact: 50 message: A potentially risky Splunk command has been run by $user$, kindly review. diff --git a/converted_detections/application/path_traversal_spl_injection.yml b/converted_detections/application/path_traversal_spl_injection.yml index 2ffd4b21d1..b48fe7b62e 100644 --- a/converted_detections/application/path_traversal_spl_injection.yml +++ b/converted_detections/application/path_traversal_spl_injection.yml @@ -28,6 +28,8 @@ tags: asset_type: Endpoint atomic_guid: [] confidence: 80 + cve: + - CVE-2022-26889 drilldown_search: [] impact: 50 message: Path traversal exploitation attempt from $clientip$ diff --git a/converted_detections/application/splunk_account_discovery_drilldown_dashboard_disclosure.yml b/converted_detections/application/splunk_account_discovery_drilldown_dashboard_disclosure.yml index af87eedd4e..579a0f2705 100644 --- a/converted_detections/application/splunk_account_discovery_drilldown_dashboard_disclosure.yml +++ b/converted_detections/application/splunk_account_discovery_drilldown_dashboard_disclosure.yml @@ -26,6 +26,8 @@ tags: asset_type: Endpoint atomic_guid: [] confidence: 80 + cve: + - CVE-2022-37438 drilldown_search: [] impact: 50 message: Potential exposure of environment variables from url embedded in dashboard diff --git a/converted_detections/application/splunk_code_injection_via_custom_dashboard_leading_to_rce.yml b/converted_detections/application/splunk_code_injection_via_custom_dashboard_leading_to_rce.yml index 4115c4cb10..fe8b7768e6 100644 --- a/converted_detections/application/splunk_code_injection_via_custom_dashboard_leading_to_rce.yml +++ b/converted_detections/application/splunk_code_injection_via_custom_dashboard_leading_to_rce.yml @@ -30,6 +30,8 @@ tags: asset_type: Endpoint atomic_guid: [] confidence: 50 + cve: + - CVE-2022-43571 drilldown_search: [] impact: 50 message: Potential exploitation of Code Injection via Dashboard PDF generation. diff --git a/converted_detections/application/splunk_command_and_scripting_interpreter_delete_usage.yml b/converted_detections/application/splunk_command_and_scripting_interpreter_delete_usage.yml index f2a45533b6..5cc4d0dc0b 100644 --- a/converted_detections/application/splunk_command_and_scripting_interpreter_delete_usage.yml +++ b/converted_detections/application/splunk_command_and_scripting_interpreter_delete_usage.yml @@ -30,6 +30,8 @@ tags: asset_type: Web Server atomic_guid: [] confidence: 30 + cve: + - CVE-2022-32154 drilldown_search: [] impact: 90 message: $user$ executed the 'delete' command, if this is unexpected it should be diff --git a/converted_detections/application/splunk_command_and_scripting_interpreter_risky_commands.yml b/converted_detections/application/splunk_command_and_scripting_interpreter_risky_commands.yml index e652124a37..d8a11d3d37 100644 --- a/converted_detections/application/splunk_command_and_scripting_interpreter_risky_commands.yml +++ b/converted_detections/application/splunk_command_and_scripting_interpreter_risky_commands.yml @@ -54,6 +54,8 @@ tags: asset_type: Web Server atomic_guid: [] confidence: 40 + cve: + - CVE-2022-32154 drilldown_search: [] impact: 50 message: A risky Splunk command has ran by $user$ and should be reviewed. diff --git a/converted_detections/application/splunk_command_and_scripting_interpreter_risky_spl_mltk.yml b/converted_detections/application/splunk_command_and_scripting_interpreter_risky_spl_mltk.yml index 2f46831ae8..4872d94480 100644 --- a/converted_detections/application/splunk_command_and_scripting_interpreter_risky_spl_mltk.yml +++ b/converted_detections/application/splunk_command_and_scripting_interpreter_risky_spl_mltk.yml @@ -38,6 +38,8 @@ tags: asset_type: Web Server atomic_guid: [] confidence: 40 + cve: + - CVE-2022-32154 drilldown_search: [] impact: 50 message: Abnormally long run time for risk SPL command seen by user $(Search_Activity.user). diff --git a/converted_detections/application/splunk_data_exfiltration_from_analytics_workspace_using_sid_query.yml b/converted_detections/application/splunk_data_exfiltration_from_analytics_workspace_using_sid_query.yml index 20ee3bb2f0..b886a9fad6 100644 --- a/converted_detections/application/splunk_data_exfiltration_from_analytics_workspace_using_sid_query.yml +++ b/converted_detections/application/splunk_data_exfiltration_from_analytics_workspace_using_sid_query.yml @@ -31,6 +31,8 @@ tags: asset_type: Endpoint atomic_guid: [] confidence: 50 + cve: + - CVE-2022-43566 drilldown_search: [] impact: 50 message: Potential data exfiltration attack using SID query by $user$ diff --git a/converted_detections/application/splunk_digital_certificates_infrastructure_version.yml b/converted_detections/application/splunk_digital_certificates_infrastructure_version.yml index 1d85725149..99bb97b616 100644 --- a/converted_detections/application/splunk_digital_certificates_infrastructure_version.yml +++ b/converted_detections/application/splunk_digital_certificates_infrastructure_version.yml @@ -36,6 +36,8 @@ tags: asset_type: Endpoint atomic_guid: [] confidence: 100 + cve: + - CVE-2022-32153 drilldown_search: [] impact: 50 message: $splunk_server$ may not be properly validating TLS Certificates diff --git a/converted_detections/application/splunk_digital_certificates_lack_of_encryption.yml b/converted_detections/application/splunk_digital_certificates_lack_of_encryption.yml index dc4830f244..9fca97e166 100644 --- a/converted_detections/application/splunk_digital_certificates_lack_of_encryption.yml +++ b/converted_detections/application/splunk_digital_certificates_lack_of_encryption.yml @@ -38,6 +38,8 @@ tags: asset_type: endpoint atomic_guid: [] confidence: 80 + cve: + - CVE-2022-32151 drilldown_search: [] impact: 25 message: $hostname$ is not using TLS when forwarding data diff --git a/converted_detections/application/splunk_dos_via_malformed_s2s_request.yml b/converted_detections/application/splunk_dos_via_malformed_s2s_request.yml index c53f5066e4..f925561a7b 100644 --- a/converted_detections/application/splunk_dos_via_malformed_s2s_request.yml +++ b/converted_detections/application/splunk_dos_via_malformed_s2s_request.yml @@ -25,6 +25,8 @@ tags: asset_type: Endpoint atomic_guid: [] confidence: 100 + cve: + - CVE-2021-3422 drilldown_search: [] impact: 50 message: An attempt to exploit CVE-2021-3422 was detected from $src$ against $host$ diff --git a/converted_detections/application/splunk_endpoint_denial_of_service_dos_zip_bomb.yml b/converted_detections/application/splunk_endpoint_denial_of_service_dos_zip_bomb.yml index 2b9d5d694d..d7de6f4f42 100644 --- a/converted_detections/application/splunk_endpoint_denial_of_service_dos_zip_bomb.yml +++ b/converted_detections/application/splunk_endpoint_denial_of_service_dos_zip_bomb.yml @@ -27,6 +27,8 @@ tags: asset_type: Endpoint atomic_guid: [] confidence: 75 + cve: + - CVE-2022-37439 drilldown_search: [] impact: 100 message: Potential exposure of environment variables from url embedded in dashboard diff --git a/converted_detections/application/splunk_process_injection_forwarder_bundle_downloads.yml b/converted_detections/application/splunk_process_injection_forwarder_bundle_downloads.yml index 936182bd16..1284dc2bb3 100644 --- a/converted_detections/application/splunk_process_injection_forwarder_bundle_downloads.yml +++ b/converted_detections/application/splunk_process_injection_forwarder_bundle_downloads.yml @@ -34,6 +34,8 @@ tags: asset_type: Endpoint atomic_guid: [] confidence: 70 + cve: + - CVE-2022-32157 drilldown_search: [] impact: 50 message: $peer$ downloaded apps from $host$ diff --git a/converted_detections/application/splunk_protocol_impersonation_weak_encryption_configuration.yml b/converted_detections/application/splunk_protocol_impersonation_weak_encryption_configuration.yml index afcd534c48..716dc44014 100644 --- a/converted_detections/application/splunk_protocol_impersonation_weak_encryption_configuration.yml +++ b/converted_detections/application/splunk_protocol_impersonation_weak_encryption_configuration.yml @@ -44,6 +44,8 @@ tags: asset_type: Endpoint atomic_guid: [] confidence: 100 + cve: + - CVE-2022-32151 drilldown_search: [] impact: 50 message: $splunk_server$ may not be properly validating TLS Certificates diff --git a/converted_detections/application/splunk_protocol_impersonation_weak_encryption_selfsigned.yml b/converted_detections/application/splunk_protocol_impersonation_weak_encryption_selfsigned.yml index 7867134dda..de10558c98 100644 --- a/converted_detections/application/splunk_protocol_impersonation_weak_encryption_selfsigned.yml +++ b/converted_detections/application/splunk_protocol_impersonation_weak_encryption_selfsigned.yml @@ -30,6 +30,8 @@ tags: asset_type: Endpoint atomic_guid: [] confidence: 80 + cve: + - CVE-2022-32152 drilldown_search: [] impact: 50 message: Splunk default issued certificate at $host$ diff --git a/converted_detections/application/splunk_protocol_impersonation_weak_encryption_simplerequest.yml b/converted_detections/application/splunk_protocol_impersonation_weak_encryption_simplerequest.yml index befc9cb3c9..4e6e0665b6 100644 --- a/converted_detections/application/splunk_protocol_impersonation_weak_encryption_simplerequest.yml +++ b/converted_detections/application/splunk_protocol_impersonation_weak_encryption_simplerequest.yml @@ -32,6 +32,8 @@ tags: asset_type: Endpoint atomic_guid: [] confidence: 80 + cve: + - CVE-2022-32152 drilldown_search: [] impact: 50 message: Failed to validate certificate on $host$ diff --git a/converted_detections/application/splunk_rce_via_splunk_secure_gateway__splunk_mobile_alerts_feature.yml b/converted_detections/application/splunk_rce_via_splunk_secure_gateway__splunk_mobile_alerts_feature.yml index 651e5b6ca5..6b4bbe5918 100644 --- a/converted_detections/application/splunk_rce_via_splunk_secure_gateway__splunk_mobile_alerts_feature.yml +++ b/converted_detections/application/splunk_rce_via_splunk_secure_gateway__splunk_mobile_alerts_feature.yml @@ -28,6 +28,8 @@ tags: asset_type: Endpoint atomic_guid: [] confidence: 90 + cve: + - CVE-2022-43567 drilldown_search: [] impact: 90 message: Possible exploitation attempt from $clientip$ diff --git a/converted_detections/application/splunk_reflected_xss_in_the_templates_lists_radio.yml b/converted_detections/application/splunk_reflected_xss_in_the_templates_lists_radio.yml index bdc0065176..39764577dd 100644 --- a/converted_detections/application/splunk_reflected_xss_in_the_templates_lists_radio.yml +++ b/converted_detections/application/splunk_reflected_xss_in_the_templates_lists_radio.yml @@ -27,6 +27,8 @@ tags: asset_type: Endpoint atomic_guid: [] confidence: 50 + cve: + - CVE-2022-43568 drilldown_search: [] impact: 50 message: Potential XSS exploitation against radio template by $user$ diff --git a/converted_detections/application/splunk_stored_xss_via_data_model_objectname_field.yml b/converted_detections/application/splunk_stored_xss_via_data_model_objectname_field.yml index bcc11dd175..1510a1522d 100644 --- a/converted_detections/application/splunk_stored_xss_via_data_model_objectname_field.yml +++ b/converted_detections/application/splunk_stored_xss_via_data_model_objectname_field.yml @@ -28,6 +28,8 @@ tags: asset_type: Endpoint atomic_guid: [] confidence: 50 + cve: + - CVE-2022-43569 drilldown_search: [] impact: 50 message: A potential XSS attempt has been detected from $user$ diff --git a/converted_detections/application/splunk_user_enumeration_attempt.yml b/converted_detections/application/splunk_user_enumeration_attempt.yml index 853e6fba4a..9c89639edc 100644 --- a/converted_detections/application/splunk_user_enumeration_attempt.yml +++ b/converted_detections/application/splunk_user_enumeration_attempt.yml @@ -27,6 +27,8 @@ tags: asset_type: endpoint atomic_guid: [] confidence: 80 + cve: + - CVE-2021-33845 drilldown_search: [] impact: 50 message: $TotalFailedAuths$ failed authentication events to Splunk from $src$ detected. diff --git a/converted_detections/application/splunk_xss_in_monitoring_console.yml b/converted_detections/application/splunk_xss_in_monitoring_console.yml index 4d7161bf44..a9921aa2bb 100644 --- a/converted_detections/application/splunk_xss_in_monitoring_console.yml +++ b/converted_detections/application/splunk_xss_in_monitoring_console.yml @@ -26,6 +26,8 @@ tags: asset_type: Endpoint atomic_guid: [] confidence: 80 + cve: + - CVE-2022-27183 drilldown_search: [] impact: 50 message: A potential XSS attempt has been detected from $user$ diff --git a/converted_detections/application/splunk_xss_in_save_table_dialog_header_in_search_page.yml b/converted_detections/application/splunk_xss_in_save_table_dialog_header_in_search_page.yml index 035e25ed40..495c078a29 100644 --- a/converted_detections/application/splunk_xss_in_save_table_dialog_header_in_search_page.yml +++ b/converted_detections/application/splunk_xss_in_save_table_dialog_header_in_search_page.yml @@ -27,6 +27,8 @@ tags: asset_type: Endpoint atomic_guid: [] confidence: 50 + cve: + - CVE-2022-43561 drilldown_search: [] impact: 50 message: Possible XSS exploitation attempt from $clientip$ diff --git a/converted_detections/deprecated/open_redirect_in_splunk_web.yml b/converted_detections/deprecated/open_redirect_in_splunk_web.yml index 9c9a48d432..825f93c21c 100644 --- a/converted_detections/deprecated/open_redirect_in_splunk_web.yml +++ b/converted_detections/deprecated/open_redirect_in_splunk_web.yml @@ -18,6 +18,8 @@ tags: asset_type: Splunk Server atomic_guid: [] confidence: 50 + cve: + - CVE-2016-4859 drilldown_search: [] impact: 50 message: tbd diff --git a/converted_detections/deprecated/spectre_and_meltdown_vulnerable_systems.yml b/converted_detections/deprecated/spectre_and_meltdown_vulnerable_systems.yml index 1ed6a57a1c..3037858afb 100644 --- a/converted_detections/deprecated/spectre_and_meltdown_vulnerable_systems.yml +++ b/converted_detections/deprecated/spectre_and_meltdown_vulnerable_systems.yml @@ -24,6 +24,8 @@ tags: asset_type: Endpoint atomic_guid: [] confidence: 50 + cve: + - CVE-2017-5753 drilldown_search: [] impact: 50 message: tbd diff --git a/converted_detections/deprecated/splunk_enterprise_information_disclosure.yml b/converted_detections/deprecated/splunk_enterprise_information_disclosure.yml index 50276b1481..6767a1a900 100644 --- a/converted_detections/deprecated/splunk_enterprise_information_disclosure.yml +++ b/converted_detections/deprecated/splunk_enterprise_information_disclosure.yml @@ -25,6 +25,8 @@ tags: asset_type: Splunk Server atomic_guid: [] confidence: 50 + cve: + - CVE-2018-11409 drilldown_search: [] impact: 50 message: tbd diff --git a/converted_detections/endpoint/any_powershell_downloadfile.yml b/converted_detections/endpoint/any_powershell_downloadfile.yml index 2c88f5cdf4..8c3cb9d389 100644 --- a/converted_detections/endpoint/any_powershell_downloadfile.yml +++ b/converted_detections/endpoint/any_powershell_downloadfile.yml @@ -40,6 +40,8 @@ tags: asset_type: Endpoint atomic_guid: [] confidence: 70 + cve: + - CVE-2021-44228 drilldown_search: [] impact: 80 message: An instance of $parent_process_name$ spawning $process_name$ was identified diff --git a/converted_detections/endpoint/child_processes_of_spoolsv_exe.yml b/converted_detections/endpoint/child_processes_of_spoolsv_exe.yml index 33a2cb4e40..b8caa08252 100644 --- a/converted_detections/endpoint/child_processes_of_spoolsv_exe.yml +++ b/converted_detections/endpoint/child_processes_of_spoolsv_exe.yml @@ -33,6 +33,8 @@ tags: asset_type: Endpoint atomic_guid: [] confidence: 50 + cve: + - CVE-2018-8440 drilldown_search: [] impact: 50 message: tbd diff --git a/converted_detections/endpoint/cmd_carry_out_string_command_parameter.yml b/converted_detections/endpoint/cmd_carry_out_string_command_parameter.yml index e29e3192d7..def59a47cd 100644 --- a/converted_detections/endpoint/cmd_carry_out_string_command_parameter.yml +++ b/converted_detections/endpoint/cmd_carry_out_string_command_parameter.yml @@ -44,6 +44,8 @@ tags: asset_type: Endpoint atomic_guid: [] confidence: 50 + cve: + - CVE-2021-44228 drilldown_search: [] impact: 60 message: An instance of $parent_process_name$ spawning $process_name$ was identified diff --git a/converted_detections/endpoint/control_loading_from_world_writable_directory.yml b/converted_detections/endpoint/control_loading_from_world_writable_directory.yml index 7c4a2feb0e..bf1a8b6849 100644 --- a/converted_detections/endpoint/control_loading_from_world_writable_directory.yml +++ b/converted_detections/endpoint/control_loading_from_world_writable_directory.yml @@ -39,6 +39,8 @@ tags: asset_type: Endpoint atomic_guid: [] confidence: 100 + cve: + - CVE-2021-40444 drilldown_search: [] impact: 80 message: An instance of $parent_process_name$ spawning $process_name$ was identified diff --git a/converted_detections/endpoint/curl_download_and_bash_execution.yml b/converted_detections/endpoint/curl_download_and_bash_execution.yml index 2aac4a3421..900dfb41d0 100644 --- a/converted_detections/endpoint/curl_download_and_bash_execution.yml +++ b/converted_detections/endpoint/curl_download_and_bash_execution.yml @@ -36,6 +36,8 @@ tags: asset_type: Endpoint atomic_guid: [] confidence: 100 + cve: + - CVE-2021-44228 drilldown_search: [] impact: 80 message: An instance of $process_name$ was identified on endpoint $dest$ attempting diff --git a/converted_detections/endpoint/detect_baron_samedit_cve_2021_3156.yml b/converted_detections/endpoint/detect_baron_samedit_cve_2021_3156.yml index 79fe79dfa2..2d98047d4b 100644 --- a/converted_detections/endpoint/detect_baron_samedit_cve_2021_3156.yml +++ b/converted_detections/endpoint/detect_baron_samedit_cve_2021_3156.yml @@ -20,6 +20,8 @@ tags: asset_type: Endpoint atomic_guid: [] confidence: 50 + cve: + - CVE-2021-3156 drilldown_search: [] impact: 50 message: tbd diff --git a/converted_detections/endpoint/detect_baron_samedit_cve_2021_3156_segfault.yml b/converted_detections/endpoint/detect_baron_samedit_cve_2021_3156_segfault.yml index c577b97e87..41f75ecef9 100644 --- a/converted_detections/endpoint/detect_baron_samedit_cve_2021_3156_segfault.yml +++ b/converted_detections/endpoint/detect_baron_samedit_cve_2021_3156_segfault.yml @@ -23,6 +23,8 @@ tags: asset_type: Endpoint atomic_guid: [] confidence: 50 + cve: + - CVE-2021-3156 drilldown_search: [] impact: 50 message: tbd diff --git a/converted_detections/endpoint/detect_baron_samedit_cve_2021_3156_via_osquery.yml b/converted_detections/endpoint/detect_baron_samedit_cve_2021_3156_via_osquery.yml index c98c31c069..c8b622afce 100644 --- a/converted_detections/endpoint/detect_baron_samedit_cve_2021_3156_via_osquery.yml +++ b/converted_detections/endpoint/detect_baron_samedit_cve_2021_3156_via_osquery.yml @@ -20,6 +20,8 @@ tags: asset_type: Endpoint atomic_guid: [] confidence: 50 + cve: + - CVE-2021-3156 drilldown_search: [] impact: 50 message: tbd diff --git a/converted_detections/endpoint/detect_computer_changed_with_anonymous_account.yml b/converted_detections/endpoint/detect_computer_changed_with_anonymous_account.yml index c8eb8a8868..204bfe2abd 100644 --- a/converted_detections/endpoint/detect_computer_changed_with_anonymous_account.yml +++ b/converted_detections/endpoint/detect_computer_changed_with_anonymous_account.yml @@ -27,6 +27,8 @@ tags: asset_type: Windows atomic_guid: [] confidence: 70 + cve: + - CVE-2020-1472 drilldown_search: [] impact: 70 message: The following $EventCode$ occurred on $dest$ by $user$ with Logon Type diff --git a/converted_detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml b/converted_detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml index 9ac631ca24..b77e5e0636 100644 --- a/converted_detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml +++ b/converted_detections/endpoint/detect_copy_of_shadowcopy_with_script_block_logging.yml @@ -40,6 +40,8 @@ tags: asset_type: Endpoint atomic_guid: [] confidence: 100 + cve: + - CVE-2021-36934 drilldown_search: [] impact: 80 message: PowerShell was identified running a script to capture the SAM hive on endpoint diff --git a/converted_detections/endpoint/hunting_for_log4shell.yml b/converted_detections/endpoint/hunting_for_log4shell.yml new file mode 100644 index 0000000000..1b75603edc --- /dev/null +++ b/converted_detections/endpoint/hunting_for_log4shell.yml @@ -0,0 +1,111 @@ +name: Hunting for Log4Shell +id: 158b68fa-5d1a-11ec-aac8-acde48001122 +version: 1 +date: '2021-12-14' +author: Michael Haag, Splunk +status: production +type: Hunting +description: 'The following hunting query assists with quickly assessing CVE-2021-44228, + or Log4Shell, activity mapped to the Web Datamodel. This is a combination query + attempting to identify, score and dashboard. Because the Log4Shell vulnerability + requires the string to be in the logs, this will work to identify the activity anywhere + in the HTTP headers using _raw. Modify the first line to use the same pattern matching + against other log sources. Scoring is based on a simple rubric of 0-5. 5 being the + best match, and less than 5 meant to identify additional patterns that will equate + to a higher total score. \ + + The first jndi match identifies the standard pattern of `{jndi:` \ + + jndi_fastmatch is meant to identify any jndi in the logs. The score is set low and + is meant to be the "base" score used later. \ + + jndi_proto is a protocol match that identifies `jndi` and one of `ldap, ldaps, rmi, + dns, nis, iiop, corba, nds, http, https.` \ + + all_match is a very well written regex by https://gist.github.com/Schvenn that identifies + nearly all patterns of this attack behavior. \ + + env works to identify environment variables in the header, meant to capture `AWS_ACCESS_KEY_ID`, + `AWS_SECRET_ACCESS_KEY` and `env`. \ + + uri_detect is string match looking for the common uri paths currently being scanned/abused + in the wild. \ + + keywords matches on enumerated values that, like `$ctx:loginId`, that may be found + in the header used by the adversary. \ + + lookup matching is meant to catch some basic obfuscation that has been identified + using upper, lower and date. \ + + Scoring will then occur based on any findings. The base score is meant to be 2 , + created by jndi_fastmatch. Everything else is meant to increase that score. \ + + Finally, a simple table is created to show the scoring and the _raw field. Sort + based on score or columns of interest.' +data_source: [] +search: '| from datamodel Web.Web | eval jndi=if(match(_raw, "(\{|%7B)[jJnNdDiI]{4}:"),4,0) + | eval jndi_fastmatch=if(match(_raw, "[jJnNdDiI]{4}"),2,0) | eval jndi_proto=if(match(_raw,"(?i)jndi:(ldap[s]?|rmi|dns|nis|iiop|corba|nds|http|https):"),5,0) + | eval all_match = if(match(_raw, "(?i)(%(25){0,}20|\s)*(%(25){0,}24|\$)(%(25){0,}20|\s)*(%(25){0,}7B|{)(%(25){0,}20|\s)*(%(25){0,}(6A|4A)|J)(%(25){0,}(6E|4E)|N)(%(25){0,}(64|44)|D)(%(25){0,}(69|49)|I)(%(25){0,}20|\s)*(%(25){0,}3A|:)[\w\%]+(%(25){1,}3A|:)(%(25){1,}2F|\/)[^\n]+"),5,0) + | eval env_var = if(match(_raw, "env:") OR match(_raw, "env:AWS_ACCESS_KEY_ID") + OR match(_raw, "env:AWS_SECRET_ACCESS_KEY"),5,0) | eval uridetect = if(match(_raw, + "(?i)Basic\/Command\/Base64|Basic\/ReverseShell|Basic\/TomcatMemshell|Basic\/JBossMemshell|Basic\/WebsphereMemshell|Basic\/SpringMemshell|Basic\/Command|Deserialization\/CommonsCollectionsK|Deserialization\/CommonsBeanutils|Deserialization\/Jre8u20\/TomcatMemshell|Deserialization\/CVE_2020_2555\/WeblogicMemshell|TomcatBypass|GroovyBypass|WebsphereBypass"),4,0) + | eval keywords = if(match(_raw,"(?i)\$\{ctx\:loginId\}|\$\{map\:type\}|\$\{filename\}|\$\{date\:MM-dd-yyyy\}|\$\{docker\:containerId\}|\$\{docker\:containerName\}|\$\{docker\:imageName\}|\$\{env\:USER\}|\$\{event\:Marker\}|\$\{mdc\:UserId\}|\$\{java\:runtime\}|\$\{java\:vm\}|\$\{java\:os\}|\$\{jndi\:logging/context-name\}|\$\{hostName\}|\$\{docker\:containerId\}|\$\{k8s\:accountName\}|\$\{k8s\:clusterName\}|\$\{k8s\:containerId\}|\$\{k8s\:containerName\}|\$\{k8s\:host\}|\$\{k8s\:labels.app\}|\$\{k8s\:labels.podTemplateHash\}|\$\{k8s\:masterUrl\}|\$\{k8s\:namespaceId\}|\$\{k8s\:namespaceName\}|\$\{k8s\:podId\}|\$\{k8s\:podIp\}|\$\{k8s\:podName\}|\$\{k8s\:imageId\}|\$\{k8s\:imageName\}|\$\{log4j\:configLocation\}|\$\{log4j\:configParentLocation\}|\$\{spring\:spring.application.name\}|\$\{main\:myString\}|\$\{main\:0\}|\$\{main\:1\}|\$\{main\:2\}|\$\{main\:3\}|\$\{main\:4\}|\$\{main\:bar\}|\$\{name\}|\$\{marker\}|\$\{marker\:name\}|\$\{spring\:profiles.active[0]|\$\{sys\:logPath\}|\$\{web\:rootDir\}|\$\{sys\:user.name\}"),4,0) + | eval obf = if(match(_raw, "(\$|%24)[^ /]*({|%7b)[^ /]*(j|%6a)[^ /]*(n|%6e)[^ /]*(d|%64)[^ + /]*(i|%69)[^ /]*(:|%3a)[^ /]*(:|%3a)[^ /]*(/|%2f)"),5,0) | eval lookups = if(match(_raw, + "(?i)({|%7b)(main|sys|k8s|spring|lower|upper|env|date|sd)"),4,0) | addtotals fieldname=Score, + jndi, jndi_proto, env_var, uridetect, all_match, jndi_fastmatch, keywords, obf, + lookups | where Score > 2 | stats values(Score) by jndi, jndi_proto, env_var, uridetect, + all_match, jndi_fastmatch, keywords, lookups, obf, _raw | `hunting_for_log4shell_filter`' +how_to_implement: Out of the box, the Web datamodel is required to be pre-filled. + However, tested was performed against raw httpd access logs. Change the first line + to any dataset to pass the regex's against. +known_false_positives: It is highly possible you will find false positives, however, + the base score is set to 2 for _any_ jndi found in raw logs. tune and change as + needed, include any filtering. +references: +- https://gist.github.com/olafhartong/916ebc673ba066537740164f7e7e1d72 +- https://gist.github.com/Neo23x0/e4c8b03ff8cdf1fa63b7d15db6e3860b#gistcomment-3994449 +- https://regex101.com/r/OSrm0q/1/ +- https://github.com/Neo23x0/signature-base/blob/master/yara/expl_log4j_cve_2021_44228.yar +- https://news.sophos.com/en-us/2021/12/12/log4shell-hell-anatomy-of-an-exploit-outbreak/ +- https://gist.github.com/MHaggis/1899b8554f38c8692a9fb0ceba60b44c +- https://twitter.com/sasi2103/status/1469764719850442760?s=20 +tags: + analytic_story: + - Log4Shell CVE-2021-44228 + - CISA AA22-320A + asset_type: Web Server + atomic_guid: [] + confidence: 50 + cve: + - CVE-2021-44228 + drilldown_search: [] + impact: 80 + message: Hunting for Log4Shell exploitation has occurred. + mitre_attack_id: + - T1190 + observable: + - name: dest + type: Hostname + role: + - Victim + - name: http_method + type: Other + role: + - Other + - name: src + type: Other + role: + - Other + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + risk_score: 40 + security_domain: network +tests: +- name: True Positive Test + attack_data: + - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1190/java/log4shell-nginx.log + source: /var/log/nginx/access.log + sourcetype: nginx:plus:kv diff --git a/converted_detections/endpoint/java_class_file_download_by_java_user_agent.yml b/converted_detections/endpoint/java_class_file_download_by_java_user_agent.yml index f3c4567877..70b8150025 100644 --- a/converted_detections/endpoint/java_class_file_download_by_java_user_agent.yml +++ b/converted_detections/endpoint/java_class_file_download_by_java_user_agent.yml @@ -27,6 +27,8 @@ tags: asset_type: Web Server atomic_guid: [] confidence: 50 + cve: + - CVE-2021-44228 drilldown_search: [] impact: 80 message: A Java user agent $http_user_agent$ was performing a $http_method$ to retrieve diff --git a/converted_detections/endpoint/java_writing_jsp_file.yml b/converted_detections/endpoint/java_writing_jsp_file.yml index dba5876a12..3a80d1d8eb 100644 --- a/converted_detections/endpoint/java_writing_jsp_file.yml +++ b/converted_detections/endpoint/java_writing_jsp_file.yml @@ -40,6 +40,8 @@ tags: asset_type: Endpoint atomic_guid: [] confidence: 70 + cve: + - CVE-2022-22965 drilldown_search: [] impact: 60 message: An instance of $process_name$ was identified on endpoint $dest$ writing diff --git a/converted_detections/endpoint/linux_java_spawning_shell.yml b/converted_detections/endpoint/linux_java_spawning_shell.yml index fd05f66dab..ff6d30ec3c 100644 --- a/converted_detections/endpoint/linux_java_spawning_shell.yml +++ b/converted_detections/endpoint/linux_java_spawning_shell.yml @@ -37,6 +37,8 @@ tags: asset_type: Endpoint atomic_guid: [] confidence: 50 + cve: + - CVE-2021-44228 drilldown_search: [] impact: 80 message: An instance of $parent_process_name$ spawning $process_name$ was identified diff --git a/converted_detections/endpoint/linux_pkexec_privilege_escalation.yml b/converted_detections/endpoint/linux_pkexec_privilege_escalation.yml index b61f586880..cf38e76990 100644 --- a/converted_detections/endpoint/linux_pkexec_privilege_escalation.yml +++ b/converted_detections/endpoint/linux_pkexec_privilege_escalation.yml @@ -37,6 +37,8 @@ tags: asset_type: Endpoint atomic_guid: [] confidence: 70 + cve: + - CVE-2021-4034 drilldown_search: [] impact: 80 message: An instance of $parent_process_name$ spawning $process_name$ was identified diff --git a/converted_detections/endpoint/mshtml_module_load_in_office_product.yml b/converted_detections/endpoint/mshtml_module_load_in_office_product.yml index 7012ddc594..2c9f036ff8 100644 --- a/converted_detections/endpoint/mshtml_module_load_in_office_product.yml +++ b/converted_detections/endpoint/mshtml_module_load_in_office_product.yml @@ -32,6 +32,8 @@ tags: asset_type: Endpoint atomic_guid: [] confidence: 100 + cve: + - CVE-2021-40444 drilldown_search: [] impact: 80 message: An instance of $process_name$ was identified on endpoint $dest$ loading diff --git a/converted_detections/endpoint/msi_module_loaded_by_non_system_binary.yml b/converted_detections/endpoint/msi_module_loaded_by_non_system_binary.yml index 856afe9782..a86afeca3b 100644 --- a/converted_detections/endpoint/msi_module_loaded_by_non_system_binary.yml +++ b/converted_detections/endpoint/msi_module_loaded_by_non_system_binary.yml @@ -45,6 +45,8 @@ tags: asset_type: Endpoint atomic_guid: [] confidence: 70 + cve: + - CVE-2021-41379 drilldown_search: [] impact: 80 message: The following module $ImageLoaded$ was loaded by $Image$ outside of the diff --git a/converted_detections/endpoint/office_product_writing_cab_or_inf.yml b/converted_detections/endpoint/office_product_writing_cab_or_inf.yml index 1f3b7b9783..16f34eadc2 100644 --- a/converted_detections/endpoint/office_product_writing_cab_or_inf.yml +++ b/converted_detections/endpoint/office_product_writing_cab_or_inf.yml @@ -42,6 +42,8 @@ tags: asset_type: Endpoint atomic_guid: [] confidence: 100 + cve: + - CVE-2021-40444 drilldown_search: [] impact: 80 message: An instance of $process_name$ was identified on $dest$ writing an inf or diff --git a/converted_detections/endpoint/office_spawning_control.yml b/converted_detections/endpoint/office_spawning_control.yml index da02afe1c5..9595687a3d 100644 --- a/converted_detections/endpoint/office_spawning_control.yml +++ b/converted_detections/endpoint/office_spawning_control.yml @@ -41,6 +41,8 @@ tags: asset_type: Endpoint atomic_guid: [] confidence: 100 + cve: + - CVE-2021-40444 drilldown_search: [] impact: 80 message: An instance of $parent_process_name$ spawning $process_name$ was identified diff --git a/converted_detections/endpoint/outbound_network_connection_from_java_using_default_ports.yml b/converted_detections/endpoint/outbound_network_connection_from_java_using_default_ports.yml index 1395c49e1c..6ac5484a06 100644 --- a/converted_detections/endpoint/outbound_network_connection_from_java_using_default_ports.yml +++ b/converted_detections/endpoint/outbound_network_connection_from_java_using_default_ports.yml @@ -39,6 +39,8 @@ tags: asset_type: Endpoint atomic_guid: [] confidence: 60 + cve: + - CVE-2021-44228 drilldown_search: [] impact: 90 message: Java performed outbound connections to default ports of LDAP or RMI on diff --git a/converted_detections/endpoint/petitpotam_network_share_access_request.yml b/converted_detections/endpoint/petitpotam_network_share_access_request.yml index 54b8534d8d..8d908b2833 100644 --- a/converted_detections/endpoint/petitpotam_network_share_access_request.yml +++ b/converted_detections/endpoint/petitpotam_network_share_access_request.yml @@ -39,6 +39,8 @@ tags: asset_type: Endpoint atomic_guid: [] confidence: 70 + cve: + - CVE-2021-36942 drilldown_search: [] impact: 80 message: A remote host is enumerating a $dest$ to identify permissions. This is diff --git a/converted_detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml b/converted_detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml index 5d0d500cc0..89e2c397f2 100644 --- a/converted_detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml +++ b/converted_detections/endpoint/petitpotam_suspicious_kerberos_tgt_request.yml @@ -34,6 +34,8 @@ tags: asset_type: Endpoint atomic_guid: [] confidence: 70 + cve: + - CVE-2021-36942 drilldown_search: [] impact: 80 message: A Kerberos TGT was requested in a non-standard manner against $dest$, potentially diff --git a/converted_detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml b/converted_detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml index 5716fabf66..0465162625 100644 --- a/converted_detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml +++ b/converted_detections/endpoint/powershell___connect_to_internet_with_hidden_window.yml @@ -46,6 +46,8 @@ tags: asset_type: Endpoint atomic_guid: [] confidence: 90 + cve: + - CVE-2021-44228 drilldown_search: [] impact: 90 message: PowerShell processes $process$ started with parameters to modify the execution diff --git a/converted_detections/endpoint/print_spooler_adding_a_printer_driver.yml b/converted_detections/endpoint/print_spooler_adding_a_printer_driver.yml index b637438bd3..4eac89636c 100644 --- a/converted_detections/endpoint/print_spooler_adding_a_printer_driver.yml +++ b/converted_detections/endpoint/print_spooler_adding_a_printer_driver.yml @@ -38,6 +38,9 @@ tags: asset_type: Endpoint atomic_guid: [] confidence: 90 + cve: + - CVE-2021-34527 + - CVE-2021-1675 drilldown_search: [] impact: 80 message: Suspicious print driver was loaded on endpoint $ComputerName$. diff --git a/converted_detections/endpoint/print_spooler_failed_to_load_a_plug_in.yml b/converted_detections/endpoint/print_spooler_failed_to_load_a_plug_in.yml index 0267a32501..8bd647e675 100644 --- a/converted_detections/endpoint/print_spooler_failed_to_load_a_plug_in.yml +++ b/converted_detections/endpoint/print_spooler_failed_to_load_a_plug_in.yml @@ -36,6 +36,9 @@ tags: asset_type: Endpoint atomic_guid: [] confidence: 90 + cve: + - CVE-2021-34527 + - CVE-2021-1675 drilldown_search: [] impact: 80 message: Suspicious printer spooler errors have occured on endpoint $ComputerName$ diff --git a/converted_detections/endpoint/rundll32_control_rundll_hunt.yml b/converted_detections/endpoint/rundll32_control_rundll_hunt.yml index 42f0fe3999..ff862d529f 100644 --- a/converted_detections/endpoint/rundll32_control_rundll_hunt.yml +++ b/converted_detections/endpoint/rundll32_control_rundll_hunt.yml @@ -42,6 +42,8 @@ tags: asset_type: Endpoint atomic_guid: [] confidence: 50 + cve: + - CVE-2021-40444 drilldown_search: [] impact: 30 message: An instance of $parent_process_name$ spawning $process_name$ was identified diff --git a/converted_detections/endpoint/rundll32_control_rundll_world_writable_directory.yml b/converted_detections/endpoint/rundll32_control_rundll_world_writable_directory.yml index f229062188..4a80eee892 100644 --- a/converted_detections/endpoint/rundll32_control_rundll_world_writable_directory.yml +++ b/converted_detections/endpoint/rundll32_control_rundll_world_writable_directory.yml @@ -44,6 +44,8 @@ tags: asset_type: Endpoint atomic_guid: [] confidence: 100 + cve: + - CVE-2021-40444 drilldown_search: [] impact: 80 message: An instance of $parent_process_name$ spawning $process_name$ was identified diff --git a/converted_detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml b/converted_detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml index a1d0feae4c..b8fc708d5d 100644 --- a/converted_detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml +++ b/converted_detections/endpoint/rundll32_with_no_command_line_arguments_with_network.yml @@ -45,6 +45,8 @@ tags: asset_type: Endpoint atomic_guid: [] confidence: 100 + cve: + - CVE-2021-34527 drilldown_search: [] impact: 70 message: A rundll32 process $process_name$ with no commandline argument like this diff --git a/converted_detections/endpoint/sam_database_file_access_attempt.yml b/converted_detections/endpoint/sam_database_file_access_attempt.yml index 87c10b5c2c..0d18959b64 100644 --- a/converted_detections/endpoint/sam_database_file_access_attempt.yml +++ b/converted_detections/endpoint/sam_database_file_access_attempt.yml @@ -35,6 +35,8 @@ tags: asset_type: Endpoint atomic_guid: [] confidence: 100 + cve: + - CVE-2021-36934 drilldown_search: [] impact: 80 message: The following process $process_name$ accessed the object $Object_Name$ diff --git a/converted_detections/endpoint/spoolsv_spawning_rundll32.yml b/converted_detections/endpoint/spoolsv_spawning_rundll32.yml index 21a2f7e0e1..605080b911 100644 --- a/converted_detections/endpoint/spoolsv_spawning_rundll32.yml +++ b/converted_detections/endpoint/spoolsv_spawning_rundll32.yml @@ -36,6 +36,8 @@ tags: asset_type: Endpoint atomic_guid: [] confidence: 90 + cve: + - CVE-2021-34527 drilldown_search: [] impact: 80 message: $parent_process$ has spawned $process_name$ on endpoint $ComputerName$. diff --git a/converted_detections/endpoint/spoolsv_suspicious_loaded_modules.yml b/converted_detections/endpoint/spoolsv_suspicious_loaded_modules.yml index 448619e784..5302fefa2a 100644 --- a/converted_detections/endpoint/spoolsv_suspicious_loaded_modules.yml +++ b/converted_detections/endpoint/spoolsv_suspicious_loaded_modules.yml @@ -27,6 +27,8 @@ tags: asset_type: Endpoint atomic_guid: [] confidence: 90 + cve: + - CVE-2021-34527 drilldown_search: [] impact: 80 message: $Image$ with process id $process_id$ has loaded a driver from $ImageLoaded$ diff --git a/converted_detections/endpoint/spoolsv_suspicious_process_access.yml b/converted_detections/endpoint/spoolsv_suspicious_process_access.yml index ecba9d7fb4..d9bbca771e 100644 --- a/converted_detections/endpoint/spoolsv_suspicious_process_access.yml +++ b/converted_detections/endpoint/spoolsv_suspicious_process_access.yml @@ -33,6 +33,8 @@ tags: asset_type: Endpoint atomic_guid: [] confidence: 90 + cve: + - CVE-2021-34527 drilldown_search: [] impact: 80 message: $SourceImage$ was GrantedAccess open access to $TargetImage$ on endpoint diff --git a/converted_detections/endpoint/spoolsv_writing_a_dll.yml b/converted_detections/endpoint/spoolsv_writing_a_dll.yml index d1283d40dd..307b67e753 100644 --- a/converted_detections/endpoint/spoolsv_writing_a_dll.yml +++ b/converted_detections/endpoint/spoolsv_writing_a_dll.yml @@ -38,6 +38,8 @@ tags: asset_type: Endpoint atomic_guid: [] confidence: 90 + cve: + - CVE-2021-34527 drilldown_search: [] impact: 80 message: $process_name$ has been identified writing dll's to $file_path$ on endpoint diff --git a/converted_detections/endpoint/spoolsv_writing_a_dll___sysmon.yml b/converted_detections/endpoint/spoolsv_writing_a_dll___sysmon.yml index 390a1238fa..ad4f151448 100644 --- a/converted_detections/endpoint/spoolsv_writing_a_dll___sysmon.yml +++ b/converted_detections/endpoint/spoolsv_writing_a_dll___sysmon.yml @@ -33,6 +33,8 @@ tags: asset_type: Endpoint atomic_guid: [] confidence: 90 + cve: + - CVE-2021-34527 drilldown_search: [] impact: 80 message: $process_name$ has been identified writing dll's to $file_path$ on endpoint diff --git a/converted_detections/endpoint/suspicious_computer_account_name_change.yml b/converted_detections/endpoint/suspicious_computer_account_name_change.yml index 64b01b62c0..b8344c2d40 100644 --- a/converted_detections/endpoint/suspicious_computer_account_name_change.yml +++ b/converted_detections/endpoint/suspicious_computer_account_name_change.yml @@ -32,6 +32,9 @@ tags: asset_type: Endpoint atomic_guid: [] confidence: 70 + cve: + - CVE-2021-42287 + - CVE-2021-42278 drilldown_search: [] impact: 100 message: A computer account $Old_Account_Name$ was renamed with a suspicious computer diff --git a/converted_detections/endpoint/suspicious_kerberos_service_ticket_request.yml b/converted_detections/endpoint/suspicious_kerberos_service_ticket_request.yml index 655d2ddab5..4f8014f343 100644 --- a/converted_detections/endpoint/suspicious_kerberos_service_ticket_request.yml +++ b/converted_detections/endpoint/suspicious_kerberos_service_ticket_request.yml @@ -38,6 +38,9 @@ tags: asset_type: Endpoint atomic_guid: [] confidence: 60 + cve: + - CVE-2021-42287 + - CVE-2021-42278 drilldown_search: [] impact: 100 message: A suspicious Kerberos Service Ticket was requested by $Account_Name$ diff --git a/converted_detections/endpoint/suspicious_rundll32_no_command_line_arguments.yml b/converted_detections/endpoint/suspicious_rundll32_no_command_line_arguments.yml index 00e4682c3d..2df759e4a4 100644 --- a/converted_detections/endpoint/suspicious_rundll32_no_command_line_arguments.yml +++ b/converted_detections/endpoint/suspicious_rundll32_no_command_line_arguments.yml @@ -38,6 +38,8 @@ tags: asset_type: Endpoint atomic_guid: [] confidence: 70 + cve: + - CVE-2021-34527 drilldown_search: [] impact: 70 message: Suspicious rundll32.exe process with no command line arguments executed diff --git a/converted_detections/endpoint/w3wp_spawning_shell.yml b/converted_detections/endpoint/w3wp_spawning_shell.yml index c831e50774..333ffabd81 100644 --- a/converted_detections/endpoint/w3wp_spawning_shell.yml +++ b/converted_detections/endpoint/w3wp_spawning_shell.yml @@ -45,6 +45,10 @@ tags: asset_type: Endpoint atomic_guid: [] confidence: 80 + cve: + - CVE-2021-34473 + - CVE-2021-34523 + - CVE-2021-31207 drilldown_search: [] impact: 70 message: Possible Web Shell execution on $dest$ diff --git a/converted_detections/endpoint/wget_download_and_bash_execution.yml b/converted_detections/endpoint/wget_download_and_bash_execution.yml index 16ab654dec..df36bddd7c 100644 --- a/converted_detections/endpoint/wget_download_and_bash_execution.yml +++ b/converted_detections/endpoint/wget_download_and_bash_execution.yml @@ -36,6 +36,8 @@ tags: asset_type: Endpoint atomic_guid: [] confidence: 100 + cve: + - CVE-2021-44228 drilldown_search: [] impact: 80 message: An instance of $process_name$ was identified on endpoint $dest$ attempting diff --git a/converted_detections/endpoint/windows_execute_arbitrary_commands_with_msdt.yml b/converted_detections/endpoint/windows_execute_arbitrary_commands_with_msdt.yml index b31b25601a..a4ae65919a 100644 --- a/converted_detections/endpoint/windows_execute_arbitrary_commands_with_msdt.yml +++ b/converted_detections/endpoint/windows_execute_arbitrary_commands_with_msdt.yml @@ -40,6 +40,8 @@ tags: asset_type: Endpoint atomic_guid: [] confidence: 100 + cve: + - CVE-2022-30190 drilldown_search: [] impact: 100 message: A parent process $parent_process_name$ has spawned a child process $process_name$ diff --git a/converted_detections/endpoint/windows_java_spawning_shells.yml b/converted_detections/endpoint/windows_java_spawning_shells.yml index 045d6693a2..17ee1797b2 100644 --- a/converted_detections/endpoint/windows_java_spawning_shells.yml +++ b/converted_detections/endpoint/windows_java_spawning_shells.yml @@ -35,6 +35,8 @@ tags: asset_type: Endpoint atomic_guid: [] confidence: 50 + cve: + - CVE-2021-44228 drilldown_search: [] impact: 80 message: An instance of $parent_process_name$ spawning $process_name$ was identified diff --git a/converted_detections/endpoint/windows_office_product_spawning_msdt.yml b/converted_detections/endpoint/windows_office_product_spawning_msdt.yml index 2413982d09..61ea5248e1 100644 --- a/converted_detections/endpoint/windows_office_product_spawning_msdt.yml +++ b/converted_detections/endpoint/windows_office_product_spawning_msdt.yml @@ -40,6 +40,8 @@ tags: asset_type: Endpoint atomic_guid: [] confidence: 100 + cve: + - CVE-2022-30190 drilldown_search: [] impact: 100 message: Office parent process $parent_process_name$ has spawned a child process diff --git a/converted_detections/endpoint/winrm_spawning_a_process.yml b/converted_detections/endpoint/winrm_spawning_a_process.yml index a8a540e2f1..a1b3a9e2ab 100644 --- a/converted_detections/endpoint/winrm_spawning_a_process.yml +++ b/converted_detections/endpoint/winrm_spawning_a_process.yml @@ -34,6 +34,8 @@ tags: asset_type: Endpoint atomic_guid: [] confidence: 50 + cve: + - CVE-2021-31166 drilldown_search: [] impact: 50 message: tbd diff --git a/converted_detections/network/detect_outbound_ldap_traffic.yml b/converted_detections/network/detect_outbound_ldap_traffic.yml index 59d067cd26..6d6c461b8d 100644 --- a/converted_detections/network/detect_outbound_ldap_traffic.yml +++ b/converted_detections/network/detect_outbound_ldap_traffic.yml @@ -32,6 +32,8 @@ tags: asset_type: Endpoint atomic_guid: [] confidence: 80 + cve: + - CVE-2021-44228 drilldown_search: [] impact: 70 message: An outbound LDAP connection from $src_ip$ in your infrastructure connecting diff --git a/converted_detections/network/detect_windows_dns_sigred_via_splunk_stream.yml b/converted_detections/network/detect_windows_dns_sigred_via_splunk_stream.yml index 033faa55d2..7da9fa1f26 100644 --- a/converted_detections/network/detect_windows_dns_sigred_via_splunk_stream.yml +++ b/converted_detections/network/detect_windows_dns_sigred_via_splunk_stream.yml @@ -23,6 +23,8 @@ tags: asset_type: Endpoint atomic_guid: [] confidence: 50 + cve: + - CVE-2020-1350 drilldown_search: [] impact: 50 message: tbd diff --git a/converted_detections/network/detect_windows_dns_sigred_via_zeek.yml b/converted_detections/network/detect_windows_dns_sigred_via_zeek.yml index 65bb11e598..f6d66f5b42 100644 --- a/converted_detections/network/detect_windows_dns_sigred_via_zeek.yml +++ b/converted_detections/network/detect_windows_dns_sigred_via_zeek.yml @@ -25,6 +25,8 @@ tags: asset_type: Endpoint atomic_guid: [] confidence: 50 + cve: + - CVE-2020-1350 drilldown_search: [] impact: 50 message: tbd diff --git a/converted_detections/network/detect_zerologon_via_zeek.yml b/converted_detections/network/detect_zerologon_via_zeek.yml index 98d8f9860e..d334df58fc 100644 --- a/converted_detections/network/detect_zerologon_via_zeek.yml +++ b/converted_detections/network/detect_zerologon_via_zeek.yml @@ -28,6 +28,8 @@ tags: asset_type: Network atomic_guid: [] confidence: 50 + cve: + - CVE-2020-1472 drilldown_search: [] impact: 50 message: tbd diff --git a/converted_detections/network/f5_big_ip_icontrol_rest_vulnerability_cve_2022_1388.yml b/converted_detections/network/f5_big_ip_icontrol_rest_vulnerability_cve_2022_1388.yml index 0f8ba21d63..1975b85af6 100644 --- a/converted_detections/network/f5_big_ip_icontrol_rest_vulnerability_cve_2022_1388.yml +++ b/converted_detections/network/f5_big_ip_icontrol_rest_vulnerability_cve_2022_1388.yml @@ -33,6 +33,8 @@ tags: asset_type: Web Server atomic_guid: [] confidence: 70 + cve: + - CVE-2022-1388 drilldown_search: [] impact: 100 message: An attempt to exploit CVE-2022-1388 against an F5 appliance $dest$ has diff --git a/converted_detections/network/splunk_identified_ssl_tls_certificates.yml b/converted_detections/network/splunk_identified_ssl_tls_certificates.yml index b5235b6f26..dea303e0e7 100644 --- a/converted_detections/network/splunk_identified_ssl_tls_certificates.yml +++ b/converted_detections/network/splunk_identified_ssl_tls_certificates.yml @@ -32,6 +32,9 @@ tags: asset_type: Proxy atomic_guid: [] confidence: 70 + cve: + - CVE-2022-32151 + - CVE-2022-32152 drilldown_search: [] impact: 60 message: The following $dest$ is using the self signed Splunk certificate. diff --git a/converted_detections/web/confluence_unauthenticated_remote_code_execution_cve_2022_26134.yml b/converted_detections/web/confluence_unauthenticated_remote_code_execution_cve_2022_26134.yml index 03ab03b533..efffdb5b24 100644 --- a/converted_detections/web/confluence_unauthenticated_remote_code_execution_cve_2022_26134.yml +++ b/converted_detections/web/confluence_unauthenticated_remote_code_execution_cve_2022_26134.yml @@ -37,6 +37,8 @@ tags: asset_type: Web Server atomic_guid: [] confidence: 100 + cve: + - CVE-2022-26134 drilldown_search: [] impact: 100 message: A URL was requested related to CVE-2022-26134, a unauthenticated remote diff --git a/converted_detections/web/detect_f5_tmui_rce_cve_2020_5902.yml b/converted_detections/web/detect_f5_tmui_rce_cve_2020_5902.yml index 634cb0ecd7..970f1b8948 100644 --- a/converted_detections/web/detect_f5_tmui_rce_cve_2020_5902.yml +++ b/converted_detections/web/detect_f5_tmui_rce_cve_2020_5902.yml @@ -26,6 +26,8 @@ tags: asset_type: Network atomic_guid: [] confidence: 50 + cve: + - CVE-2020-5902 drilldown_search: [] impact: 50 message: tbd diff --git a/converted_detections/web/exploit_public_facing_application_via_apache_commons_text.yml b/converted_detections/web/exploit_public_facing_application_via_apache_commons_text.yml index 8f0e2b4c8b..472a3d7304 100644 --- a/converted_detections/web/exploit_public_facing_application_via_apache_commons_text.yml +++ b/converted_detections/web/exploit_public_facing_application_via_apache_commons_text.yml @@ -49,6 +49,8 @@ tags: asset_type: Web Server atomic_guid: [] confidence: 70 + cve: + - CVE-2022-42889 drilldown_search: [] impact: 70 message: A URL was requested related to Text4Shell on $dest$ by $src$. diff --git a/converted_detections/web/fortinet_appliance_auth_bypass.yml b/converted_detections/web/fortinet_appliance_auth_bypass.yml index c224547960..54930077b9 100644 --- a/converted_detections/web/fortinet_appliance_auth_bypass.yml +++ b/converted_detections/web/fortinet_appliance_auth_bypass.yml @@ -52,6 +52,8 @@ tags: asset_type: Network atomic_guid: [] confidence: 90 + cve: + - CVE-2022-40684 drilldown_search: [] impact: 90 message: Potential CVE-2022-40684 against a Fortinet appliance may be occurring diff --git a/converted_detections/web/log4shell_jndi_payload_injection_attempt.yml b/converted_detections/web/log4shell_jndi_payload_injection_attempt.yml index c139ff5515..1cfa501510 100644 --- a/converted_detections/web/log4shell_jndi_payload_injection_attempt.yml +++ b/converted_detections/web/log4shell_jndi_payload_injection_attempt.yml @@ -41,6 +41,8 @@ tags: asset_type: Endpoint atomic_guid: [] confidence: 30 + cve: + - CVE-2021-44228 drilldown_search: [] impact: 50 message: CVE-2021-44228 Log4Shell triggered for host $dest$ diff --git a/converted_detections/web/log4shell_jndi_payload_injection_with_outbound_connection.yml b/converted_detections/web/log4shell_jndi_payload_injection_with_outbound_connection.yml index 2b6171f2aa..45d5d08665 100644 --- a/converted_detections/web/log4shell_jndi_payload_injection_with_outbound_connection.yml +++ b/converted_detections/web/log4shell_jndi_payload_injection_with_outbound_connection.yml @@ -36,6 +36,8 @@ tags: asset_type: Endpoint atomic_guid: [] confidence: 30 + cve: + - CVE-2021-44228 drilldown_search: [] impact: 50 message: CVE-2021-44228 Log4Shell triggered for host $dest$ diff --git a/converted_detections/web/spring4shell_payload_url_request.yml b/converted_detections/web/spring4shell_payload_url_request.yml index 297f90b55a..a695e991f9 100644 --- a/converted_detections/web/spring4shell_payload_url_request.yml +++ b/converted_detections/web/spring4shell_payload_url_request.yml @@ -29,6 +29,8 @@ tags: asset_type: Web Server atomic_guid: [] confidence: 60 + cve: + - CVE-2022-22965 drilldown_search: [] impact: 60 message: A URL was requested related to Spring4Shell POC code on $dest$ by $src$. diff --git a/converted_detections/web/vmware_server_side_template_injection_hunt.yml b/converted_detections/web/vmware_server_side_template_injection_hunt.yml index 951d6072c7..9664010cbb 100644 --- a/converted_detections/web/vmware_server_side_template_injection_hunt.yml +++ b/converted_detections/web/vmware_server_side_template_injection_hunt.yml @@ -33,6 +33,8 @@ tags: asset_type: Web Server atomic_guid: [] confidence: 50 + cve: + - CVE-2022-22954 drilldown_search: [] impact: 70 message: An attempt to exploit a VMware Server Side Injection CVE-2022-22954 on diff --git a/converted_detections/web/vmware_workspace_one_freemarker_server_side_template_injection.yml b/converted_detections/web/vmware_workspace_one_freemarker_server_side_template_injection.yml index 519e7cd647..37e54e2052 100644 --- a/converted_detections/web/vmware_workspace_one_freemarker_server_side_template_injection.yml +++ b/converted_detections/web/vmware_workspace_one_freemarker_server_side_template_injection.yml @@ -34,6 +34,8 @@ tags: asset_type: Web Server atomic_guid: [] confidence: 70 + cve: + - CVE-2022-22954 drilldown_search: [] impact: 70 message: An attempt to exploit a VMware Server Side Injection CVE-2022-22954 on diff --git a/converted_detections/web/web_jsp_request_via_url.yml b/converted_detections/web/web_jsp_request_via_url.yml index fbb29e3f72..0dbb21cf58 100644 --- a/converted_detections/web/web_jsp_request_via_url.yml +++ b/converted_detections/web/web_jsp_request_via_url.yml @@ -29,6 +29,8 @@ tags: asset_type: Web Server atomic_guid: [] confidence: 80 + cve: + - CVE-2022-22965 drilldown_search: [] impact: 90 message: A suspicious URL has been requested against $dest$ by $src$, related to diff --git a/converted_detections/web/web_spring4shell_http_request_class_module.yml b/converted_detections/web/web_spring4shell_http_request_class_module.yml index cfeb4ea1e5..2b60af81c0 100644 --- a/converted_detections/web/web_spring4shell_http_request_class_module.yml +++ b/converted_detections/web/web_spring4shell_http_request_class_module.yml @@ -28,6 +28,8 @@ tags: asset_type: Web Server atomic_guid: [] confidence: 80 + cve: + - CVE-2022-22965 drilldown_search: [] impact: 90 message: A http body request related to Spring4Shell has been sent to $dest$ by diff --git a/converted_detections/web/web_spring_cloud_function_functionrouter.yml b/converted_detections/web/web_spring_cloud_function_functionrouter.yml index ebcc01275b..e5842ec528 100644 --- a/converted_detections/web/web_spring_cloud_function_functionrouter.yml +++ b/converted_detections/web/web_spring_cloud_function_functionrouter.yml @@ -30,6 +30,8 @@ tags: asset_type: Web Server atomic_guid: [] confidence: 60 + cve: + - CVE-2022-22963 drilldown_search: [] impact: 70 message: A suspicious URL has been requested against $dest$ by $src$, related to diff --git a/converted_detections/web/windows_exchange_autodiscover_ssrf_abuse.yml b/converted_detections/web/windows_exchange_autodiscover_ssrf_abuse.yml index 223a7f6f7b..9eef25699d 100644 --- a/converted_detections/web/windows_exchange_autodiscover_ssrf_abuse.yml +++ b/converted_detections/web/windows_exchange_autodiscover_ssrf_abuse.yml @@ -44,6 +44,12 @@ tags: asset_type: Web server atomic_guid: [] confidence: 80 + cve: + - CVE-2021-34523 + - CVE-2021-34473 + - CVE-2021-31207 + - CVE-2022-41040 + - CVE-2022-41082 drilldown_search: [] impact: 90 message: Activity related to ProxyShell or ProxyNotShell has been identified on