Merge branch 'The_Day_After_Log4shell' of github.com:splunk/security_content into The_Day_After_Log4shell

This commit is contained in:
Lou Stella
2021-12-14 18:47:04 -06:00
13 changed files with 29 additions and 7 deletions
@@ -67,6 +67,8 @@ tags:
type: Process
role:
- Child Process
cve:
- CVE-2021-44228
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -54,6 +54,8 @@ tags:
type: User
role:
- Victim
cve:
- CVE-2021-44228
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -29,7 +29,8 @@ tags:
analytic_story:
- Ingress Tool Transfer
- Log4Shell CVE-2021-44228
dataset: []
dataset:
- "https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1105/atomic_red_team/linux-sysmon_curlwget.log"
kill_chain_phases:
- Exploitation
mitre_attack_id:
@@ -71,4 +72,6 @@ tags:
- name: process_name
type: Process
role:
- Child Process
- Child Process
cve:
- CVE-2021-44228
@@ -94,3 +94,5 @@ tags:
type: Other
role:
- other
cve:
- CVE-2021-44228
@@ -65,3 +65,5 @@ tags:
role:
- other
automated_detection_testing: passed
cve:
- CVE-2021-44228
@@ -93,3 +93,5 @@ tags:
- Processes.dest
risk_score: 81
security_domain: endpoint
cve:
- CVE-2021-44228
@@ -29,7 +29,8 @@ tags:
analytic_story:
- Ingress Tool Transfer
- Log4Shell CVE-2021-44228
dataset: []
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1105/atomic_red_team/linux-sysmon_curlwget.log
kill_chain_phases:
- Exploitation
mitre_attack_id:
@@ -71,4 +72,6 @@ tags:
- name: process_name
type: Process
role:
- Child Process
- Child Process
cve:
- CVE-2021-44228
@@ -72,4 +72,6 @@ tags:
- name: process_name
type: Process
role:
- Child Process
- Child Process
cve:
- CVE-2021-44228
@@ -70,4 +70,6 @@ tags:
- name: process_name
type: Process
role:
- Child Process
- Child Process
cve:
- CVE-2021-44228
@@ -61,3 +61,5 @@ tags:
risk_score: 56
security_domain: network
automated_detection_testing: passed
cve:
- CVE-2021-44228
+1 -1
View File
@@ -2,7 +2,7 @@ name: Log4j Investigate And Respond
id: fc0adc96-ff2b-48b0-9a6f-63da6783fd63
version: 1
date: '2021-12-14'
author: Philip Royer, Splunk
author: Phillip Royer, Splunk
type: Response
description: Published in response to CVE-2021-44228, this playbook and its sub-playbooks can be used to investigate and respond to attacks against hosts running vulnerable Java applications which use log4j.
playbook: log4j_investigate_and_respond