mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
Branch was auto-updated.
This commit is contained in:
@@ -47,18 +47,13 @@ setup_schema = {
|
||||
"Splunk Add-on for CrowdStrike FDR": {
|
||||
"app_number": 5579,
|
||||
"app_version": "1.3.0",
|
||||
"http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/splunk-add-on-for-crowdstrike-fdr_130.tgz",
|
||||
"http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/splunk-add-on-for-crowdstrike-fdr_140.tgz",
|
||||
},
|
||||
"ADD_ON_FOR_LINUX_SYSMON": {
|
||||
"app_number": 6176,
|
||||
"app_version": "1.0.4",
|
||||
"http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/add-on-for-linux-sysmon_104.tgz",
|
||||
},
|
||||
"SPLUNK_TA_FIX_WINDOWS": {
|
||||
"app_number": 9999,
|
||||
"app_version": "1.0.0",
|
||||
"http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/Splunk_TA_fix_windows.tgz",
|
||||
},
|
||||
"SPLUNK_TA_FOR_IIS": {
|
||||
"app_number": 3185,
|
||||
"app_version": "1.2.0",
|
||||
@@ -72,7 +67,7 @@ setup_schema = {
|
||||
"PALO_ALTO_NETWORKS_ADD_ON_FOR_SPLUNK": {
|
||||
"app_number": 2757,
|
||||
"app_version": "8.0.1",
|
||||
"http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/palo-alto-networks-add-on-for-splunk_801.tgz",
|
||||
"http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/palo-alto-networks-add-on-for-splunk_802.tgz",
|
||||
},
|
||||
"PYTHON_FOR_SCIENTIFIC_COMPUTING_FOR_LINUX_64_BIT": {
|
||||
"app_number": 2882,
|
||||
@@ -87,12 +82,12 @@ setup_schema = {
|
||||
"SPLUNK_ADD_ON_FOR_MICROSOFT_OFFICE_365": {
|
||||
"app_number": 4055,
|
||||
"app_version": "4.2.1",
|
||||
"http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/splunk-add-on-for-microsoft-office-365_421.tgz",
|
||||
"http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/splunk-add-on-for-microsoft-office-365_430.tgz",
|
||||
},
|
||||
"SPLUNK_ADD_ON_FOR_MICROSOFT_WINDOWS": {
|
||||
"app_number": 742,
|
||||
"app_version": "8.5.0",
|
||||
"http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/splunk-add-on-for-microsoft-windows_850.tgz",
|
||||
"http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/splunk-add-on-for-microsoft-windows_870.tgz",
|
||||
},
|
||||
"SPLUNK_ADD_ON_FOR_NGINX": {
|
||||
"app_number": 3258,
|
||||
@@ -117,18 +112,13 @@ setup_schema = {
|
||||
"SPLUNK_ADD_ON_FOR_UNIX_AND_LINUX": {
|
||||
"app_number": 833,
|
||||
"app_version": "8.8.0",
|
||||
"http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/splunk-add-on-for-unix-and-linux_880.tgz",
|
||||
"http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/splunk-add-on-for-unix-and-linux_890.tgz",
|
||||
},
|
||||
"SPLUNK_APP_FOR_STREAM": {
|
||||
"app_number": 1809,
|
||||
"app_version": "8.1.0",
|
||||
"http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/splunk-app-for-stream_810.tgz",
|
||||
},
|
||||
"SPLUNK_COMMON_INFORMATION_MODEL": {
|
||||
"app_number": 1621,
|
||||
"app_version": "5.1.0",
|
||||
"http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/splunk-common-information-model-cim_510.tgz",
|
||||
},
|
||||
"SPLUNK_MACHINE_LEARNING_TOOLKIT": {
|
||||
"app_number": 2890,
|
||||
"app_version": "5.4.0",
|
||||
@@ -152,7 +142,7 @@ setup_schema = {
|
||||
"SPLUNK_TA_MICROSOFT_CLOUD_SERVICES": {
|
||||
"app_number": 3110,
|
||||
"app_version": "4.5.2",
|
||||
"http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/splunk-add-on-for-microsoft-cloud-services_452.tgz",
|
||||
"http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/splunk-add-on-for-microsoft-cloud-services_510.tgz",
|
||||
},
|
||||
"SPLUNK_ADD_ON_FOR_GOOGLE_CLOUD_PLATFORM": {
|
||||
"app_number": 3088,
|
||||
@@ -162,8 +152,18 @@ setup_schema = {
|
||||
"SPLUNK_ADD_ON_FOR_GOOGLE_WORKSPACE": {
|
||||
"app_number": 3110,
|
||||
"app_version": "2.4.1",
|
||||
"http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/splunk-add-on-for-google-workspace_241.tgz",
|
||||
"http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/splunk-add-on-for-google-workspace_251.tgz",
|
||||
},
|
||||
"SPLUNK_TA_FOR_SURICATA": {
|
||||
"app_number": 2760,
|
||||
"app_version": "2.3.3",
|
||||
"http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/ta-for-suricata_234.tgz",
|
||||
},
|
||||
"SPLUNK_COMMON_INFORMATION_MODEL": {
|
||||
"app_number": 1621,
|
||||
"app_version": "5.1.0",
|
||||
"http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/splunk-common-information-model-cim_511.tgz",
|
||||
}
|
||||
},
|
||||
},
|
||||
"mode": {
|
||||
|
||||
@@ -1,221 +1,126 @@
|
||||
{
|
||||
"apps": {
|
||||
"Splunk Add-on for CrowdStrike FDR": {
|
||||
"app_number": 5579,
|
||||
"app_version": "1.2.0",
|
||||
"http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/splunk-add-on-for-crowdstrike-fdr_120.tgz"
|
||||
},
|
||||
"ADD_ON_FOR_LINUX_SYSMON": {
|
||||
"ADD_ON_FOR_LINUX_SYSMON": {
|
||||
"app_number": 6176,
|
||||
"app_version": "1.0.4",
|
||||
"http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/add-on-for-linux-sysmon_104.tgz"
|
||||
},
|
||||
"PALO_ALTO_NETWORKS_ADD_ON_FOR_SPLUNK": {
|
||||
},
|
||||
"PALO_ALTO_NETWORKS_ADD_ON_FOR_SPLUNK": {
|
||||
"app_number": 2757,
|
||||
"app_version": "7.1.0",
|
||||
"http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/palo-alto-networks-add-on-for-splunk_710.tgz"
|
||||
},
|
||||
"PYTHON_FOR_SCIENTIFIC_COMPUTING_FOR_LINUX_64_BIT": {
|
||||
"app_version": "8.0.1",
|
||||
"http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/palo-alto-networks-add-on-for-splunk_802.tgz"
|
||||
},
|
||||
"PYTHON_FOR_SCIENTIFIC_COMPUTING_FOR_LINUX_64_BIT": {
|
||||
"app_number": 2882,
|
||||
"app_version": "3.0.2",
|
||||
"http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/python-for-scientific-computing-for-linux-64-bit_302.tgz"
|
||||
},
|
||||
"SPLUNK_ADD_ON_FOR_AMAZON_KINESIS_FIREHOSE": {
|
||||
"app_version": "4.1.0",
|
||||
"http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/python-for-scientific-computing-for-linux-64-bit_410.tgz"
|
||||
},
|
||||
"SPLUNK_ADD_ON_FOR_AMAZON_KINESIS_FIREHOSE": {
|
||||
"app_number": 3719,
|
||||
"app_version": "1.3.2",
|
||||
"http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/splunk-add-on-for-amazon-kinesis-firehose_132.tgz"
|
||||
},
|
||||
"SPLUNK_ADD_ON_FOR_MICROSOFT_OFFICE_365": {
|
||||
},
|
||||
"SPLUNK_ADD_ON_FOR_GOOGLE_CLOUD_PLATFORM": {
|
||||
"app_number": 3088,
|
||||
"app_version": "4.1.0",
|
||||
"http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/splunk-add-on-for-google-cloud-platform_410.tgz"
|
||||
},
|
||||
"SPLUNK_ADD_ON_FOR_GOOGLE_WORKSPACE": {
|
||||
"app_number": 3110,
|
||||
"app_version": "2.4.1",
|
||||
"http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/splunk-add-on-for-google-workspace_251.tgz"
|
||||
},
|
||||
"SPLUNK_ADD_ON_FOR_MICROSOFT_OFFICE_365": {
|
||||
"app_number": 4055,
|
||||
"app_version": "4.0.0",
|
||||
"http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/splunk-add-on-for-microsoft-office-365_400.tgz"
|
||||
},
|
||||
"SPLUNK_ADD_ON_FOR_MICROSOFT_WINDOWS": {
|
||||
"app_version": "4.2.1",
|
||||
"http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/splunk-add-on-for-microsoft-office-365_430.tgz"
|
||||
},
|
||||
"SPLUNK_ADD_ON_FOR_MICROSOFT_WINDOWS": {
|
||||
"app_number": 742,
|
||||
"app_version": "8.5.0",
|
||||
"http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/splunk-add-on-for-microsoft-windows_850.tgz"
|
||||
},
|
||||
"SPLUNK_ADD_ON_FOR_NGINX": {
|
||||
"http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/splunk-add-on-for-microsoft-windows_870.tgz"
|
||||
},
|
||||
"SPLUNK_ADD_ON_FOR_NGINX": {
|
||||
"app_number": 3258,
|
||||
"app_version": "3.1.0",
|
||||
"http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/splunk-add-on-for-nginx_310.tgz"
|
||||
},
|
||||
"SPLUNK_ADD_ON_FOR_STREAM_FORWARDERS": {
|
||||
"app_version": "3.2.1",
|
||||
"http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/splunk-add-on-for-nginx_321.tgz"
|
||||
},
|
||||
"SPLUNK_ADD_ON_FOR_STREAM_FORWARDERS": {
|
||||
"app_number": 5238,
|
||||
"app_version": "8.1.0",
|
||||
"http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/splunk-add-on-for-stream-forwarders_810.tgz"
|
||||
},
|
||||
"SPLUNK_ADD_ON_FOR_STREAM_WIRE_DATA": {
|
||||
},
|
||||
"SPLUNK_ADD_ON_FOR_STREAM_WIRE_DATA": {
|
||||
"app_number": 5234,
|
||||
"app_version": "8.1.0",
|
||||
"http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/splunk-add-on-for-stream-wire-data_810.tgz"
|
||||
},
|
||||
"SPLUNK_ADD_ON_FOR_SYSMON": {
|
||||
},
|
||||
"SPLUNK_ADD_ON_FOR_SYSMON": {
|
||||
"app_number": 5709,
|
||||
"app_version": "3.0.0",
|
||||
"http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/splunk-add-on-for-sysmon_300.tgz"
|
||||
},
|
||||
"SPLUNK_ADD_ON_FOR_UNIX_AND_LINUX": {
|
||||
"app_version": "3.1.0",
|
||||
"http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/splunk-add-on-for-sysmon_310.tgz"
|
||||
},
|
||||
"SPLUNK_ADD_ON_FOR_UNIX_AND_LINUX": {
|
||||
"app_number": 833,
|
||||
"app_version": "8.6.0",
|
||||
"http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/splunk-add-on-for-unix-and-linux_860.tgz"
|
||||
},
|
||||
"SPLUNK_APP_FOR_STREAM": {
|
||||
"app_version": "8.8.0",
|
||||
"http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/splunk-add-on-for-unix-and-linux_890.tgz"
|
||||
},
|
||||
"SPLUNK_APP_FOR_STREAM": {
|
||||
"app_number": 1809,
|
||||
"app_version": "8.1.0",
|
||||
"http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/splunk-app-for-stream_810.tgz"
|
||||
},
|
||||
"SPLUNK_TA_FIX_WINDOWS":{
|
||||
"app_number": 9999,
|
||||
"app_version": "1.0.0",
|
||||
"http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/Splunk_TA_fix_windows.tgz"
|
||||
},
|
||||
"SPLUNK_COMMON_INFORMATION_MODEL": {
|
||||
},
|
||||
"SPLUNK_COMMON_INFORMATION_MODEL": {
|
||||
"app_number": 1621,
|
||||
"app_version": "5.0.1",
|
||||
"http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/splunk-common-information-model-cim_501.tgz"
|
||||
},
|
||||
"SPLUNK_ES_CONTENT_UPDATE": {
|
||||
"app_version": "5.1.0",
|
||||
"http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/splunk-common-information-model-cim_511.tgz"
|
||||
},
|
||||
"SPLUNK_ES_CONTENT_UPDATE": {
|
||||
"app_number": 3449,
|
||||
"app_version": null,
|
||||
"local_path": null
|
||||
},
|
||||
"SPLUNK_MACHINE_LEARNING_TOOLKIT": {
|
||||
},
|
||||
"SPLUNK_MACHINE_LEARNING_TOOLKIT": {
|
||||
"app_number": 2890,
|
||||
"app_version": "5.3.1",
|
||||
"http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/splunk-machine-learning-toolkit_531.tgz"
|
||||
},
|
||||
"SPLUNK_TA_FOR_ZEEK": {
|
||||
"app_version": "5.4.0",
|
||||
"http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/splunk-machine-learning-toolkit_540.tgz"
|
||||
},
|
||||
"SPLUNK_TA_FIX_WINDOWS": {
|
||||
"app_number": 9999,
|
||||
"app_version": "1.0.0",
|
||||
"http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/Splunk_TA_fix_windows.tgz"
|
||||
},
|
||||
"SPLUNK_TA_FOR_IIS": {
|
||||
"app_number": 3185,
|
||||
"app_version": "1.2.0",
|
||||
"http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/splunk-add-on-for-microsoft-iis_120.tgz"
|
||||
},
|
||||
"SPLUNK_TA_FOR_SURICATA": {
|
||||
"app_number": 2760,
|
||||
"app_version": "2.3.3",
|
||||
"http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/ta-for-suricata_234.tgz"
|
||||
},
|
||||
"SPLUNK_TA_FOR_ZEEK": {
|
||||
"app_number": 5466,
|
||||
"app_version": "1.0.5",
|
||||
"http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/ta-for-zeek_105.tgz"
|
||||
},
|
||||
"URL_TOOLBOX": {
|
||||
},
|
||||
"SPLUNK_TA_MICROSOFT_CLOUD_SERVICES": {
|
||||
"app_number": 3110,
|
||||
"app_version": "4.5.2",
|
||||
"http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/splunk-add-on-for-microsoft-cloud-services_510.tgz"
|
||||
},
|
||||
"Splunk Add-on for CrowdStrike FDR": {
|
||||
"app_number": 5579,
|
||||
"app_version": "1.3.0",
|
||||
"http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/splunk-add-on-for-crowdstrike-fdr_140.tgz"
|
||||
},
|
||||
"URL_TOOLBOX": {
|
||||
"app_number": 2734,
|
||||
"app_version": "1.9.2",
|
||||
"http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/url-toolbox_192.tgz"
|
||||
},
|
||||
"SPLUNK_ADD_ON_FOR_GOOGLE_CLOUD_PLATFORM": {
|
||||
"app_number": 3088,
|
||||
"app_version": "4.0.0",
|
||||
"http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/splunk-add-on-for-google-cloud-platform_400.tgz"
|
||||
},
|
||||
"SPLUNK_ADD_ON_FOR_GOOGLE_WORKSPACE": {
|
||||
"app_number": 3110,
|
||||
"app_version": "2.3.0",
|
||||
"http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/splunk-add-on-for-google-workspace_230.tgz"
|
||||
},
|
||||
"PALO_ALTO_NETWORKS_ADD_ON_FOR_SPLUNK": {
|
||||
"app_number": 2757,
|
||||
"app_version": "8.0.1",
|
||||
"http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/palo-alto-networks-add-on-for-splunk_801.tgz"
|
||||
},
|
||||
"PYTHON_FOR_SCIENTIFIC_COMPUTING_FOR_LINUX_64_BIT": {
|
||||
"app_number": 2882,
|
||||
"app_version": "4.1.0",
|
||||
"http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/python-for-scientific-computing-for-linux-64-bit_410.tgz"
|
||||
},
|
||||
"SPLUNK_ADD_ON_FOR_AMAZON_KINESIS_FIREHOSE": {
|
||||
"app_number": 3719,
|
||||
"app_version": "1.3.2",
|
||||
"http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/splunk-add-on-for-amazon-kinesis-firehose_132.tgz"
|
||||
},
|
||||
"SPLUNK_ADD_ON_FOR_GOOGLE_CLOUD_PLATFORM": {
|
||||
"app_number": 3088,
|
||||
"app_version": "4.1.0",
|
||||
"http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/splunk-add-on-for-google-cloud-platform_410.tgz"
|
||||
},
|
||||
"SPLUNK_ADD_ON_FOR_GOOGLE_WORKSPACE": {
|
||||
"app_number": 3110,
|
||||
"app_version": "2.4.1",
|
||||
"http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/splunk-add-on-for-google-workspace_241.tgz"
|
||||
},
|
||||
"SPLUNK_ADD_ON_FOR_MICROSOFT_OFFICE_365": {
|
||||
"app_number": 4055,
|
||||
"app_version": "4.2.1",
|
||||
"http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/splunk-add-on-for-microsoft-office-365_421.tgz"
|
||||
},
|
||||
"SPLUNK_ADD_ON_FOR_MICROSOFT_WINDOWS": {
|
||||
"app_number": 742,
|
||||
"app_version": "8.5.0",
|
||||
"http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/splunk-add-on-for-microsoft-windows_850.tgz"
|
||||
},
|
||||
"SPLUNK_ADD_ON_FOR_NGINX": {
|
||||
"app_number": 3258,
|
||||
"app_version": "3.2.1",
|
||||
"http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/splunk-add-on-for-nginx_321.tgz"
|
||||
},
|
||||
"SPLUNK_ADD_ON_FOR_STREAM_FORWARDERS": {
|
||||
"app_number": 5238,
|
||||
"app_version": "8.1.0",
|
||||
"http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/splunk-add-on-for-stream-forwarders_810.tgz"
|
||||
},
|
||||
"SPLUNK_ADD_ON_FOR_STREAM_WIRE_DATA": {
|
||||
"app_number": 5234,
|
||||
"app_version": "8.1.0",
|
||||
"http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/splunk-add-on-for-stream-wire-data_810.tgz"
|
||||
},
|
||||
"SPLUNK_ADD_ON_FOR_SYSMON": {
|
||||
"app_number": 5709,
|
||||
"app_version": "3.1.0",
|
||||
"http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/splunk-add-on-for-sysmon_310.tgz"
|
||||
},
|
||||
"SPLUNK_ADD_ON_FOR_UNIX_AND_LINUX": {
|
||||
"app_number": 833,
|
||||
"app_version": "8.8.0",
|
||||
"http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/splunk-add-on-for-unix-and-linux_880.tgz"
|
||||
},
|
||||
"SPLUNK_APP_FOR_STREAM": {
|
||||
"app_number": 1809,
|
||||
"app_version": "8.1.0",
|
||||
"http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/splunk-app-for-stream_810.tgz"
|
||||
},
|
||||
"SPLUNK_COMMON_INFORMATION_MODEL": {
|
||||
"app_number": 1621,
|
||||
"app_version": "5.1.0",
|
||||
"http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/splunk-common-information-model-cim_510.tgz"
|
||||
},
|
||||
"SPLUNK_ES_CONTENT_UPDATE": {
|
||||
"app_number": 3449,
|
||||
"app_version": null,
|
||||
"local_path": null
|
||||
},
|
||||
"SPLUNK_MACHINE_LEARNING_TOOLKIT": {
|
||||
"app_number": 2890,
|
||||
"app_version": "5.4.0",
|
||||
"http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/splunk-machine-learning-toolkit_540.tgz"
|
||||
},
|
||||
"SPLUNK_TA_FIX_WINDOWS": {
|
||||
"app_number": 9999,
|
||||
"app_version": "1.0.0",
|
||||
"http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/Splunk_TA_fix_windows.tgz"
|
||||
},
|
||||
"SPLUNK_TA_FOR_IIS": {
|
||||
"app_number": 3185,
|
||||
"app_version": "1.2.0",
|
||||
"http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/splunk-add-on-for-microsoft-iis_120.tgz"
|
||||
},
|
||||
"SPLUNK_TA_FOR_ZEEK": {
|
||||
"app_number": 5466,
|
||||
"app_version": "1.0.5",
|
||||
"http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/ta-for-zeek_105.tgz"
|
||||
},
|
||||
"SPLUNK_TA_MICROSOFT_CLOUD_SERVICES": {
|
||||
"app_number": 3110,
|
||||
"app_version": "4.5.2",
|
||||
"http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/splunk-add-on-for-microsoft-cloud-services_452.tgz"
|
||||
},
|
||||
"Splunk Add-on for CrowdStrike FDR": {
|
||||
"app_number": 5579,
|
||||
"app_version": "1.3.0",
|
||||
"http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/splunk-add-on-for-crowdstrike-fdr_130.tgz"
|
||||
},
|
||||
"URL_TOOLBOX": {
|
||||
"app_number": 2734,
|
||||
"app_version": "1.9.2",
|
||||
"http_path": "https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/Latest/url-toolbox_192.tgz"
|
||||
}
|
||||
},
|
||||
},
|
||||
"branch": "BRANCH_DOES_NOT_EXIST_USE_CLI_ARGUMENT",
|
||||
"commit_hash": null,
|
||||
"container_tag": "latest",
|
||||
|
||||
@@ -0,0 +1,69 @@
|
||||
name: Windows PaperCut NG Spawn Shell
|
||||
id: a602d9a2-aaea-45f8-bf0f-d851168d61ca
|
||||
version: 1
|
||||
date: '2023-05-15'
|
||||
author: Michael Haag, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
data_source:
|
||||
- Sysmon Event ID 1
|
||||
description: The following analytic is designed to detect instances where the PaperCut NG application (pc-app.exe) spawns a Windows shell, specifically cmd.exe or PowerShell. This behavior may indicate potential malicious activity, such as an attacker attempting to gain unauthorized access or execute harmful commands on the affected system.
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name=pc-app.exe `process_cmd` OR `process_powershell` OR Processes.process_name=java.exe
|
||||
by Processes.dest Processes.user Processes.parent_process_name Processes.process_name
|
||||
Processes.original_file_name Processes.process Processes.process_id Processes.parent_process_id
|
||||
| `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `windows_papercut_ng_spawn_shell_filter`'
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product.
|
||||
known_false_positives: False positives may be present, but most likely not. Filter as needed.
|
||||
references:
|
||||
- https://www.cisa.gov/news-events/alerts/2023/05/11/cisa-and-fbi-release-joint-advisory-response-active-exploitation-papercut-vulnerability
|
||||
- https://www.papercut.com/kb/Main/PO-1216-and-PO-1219
|
||||
tags:
|
||||
analytic_story:
|
||||
- PaperCut MF NG Vulnerability
|
||||
asset_type: Endpoint
|
||||
atomic_guid: []
|
||||
confidence: 90
|
||||
impact: 100
|
||||
message: The PaperCut NG application has spawned a shell $process_name$ on endpoint $dest$ by $user$.
|
||||
mitre_attack_id:
|
||||
- T1059
|
||||
- T1190
|
||||
observable:
|
||||
- name: user
|
||||
type: User
|
||||
role:
|
||||
- Victim
|
||||
- name: dest
|
||||
type: Hostname
|
||||
role:
|
||||
- Victim
|
||||
- name: process_name
|
||||
type: Process
|
||||
role:
|
||||
- Child Process
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
risk_score: 90
|
||||
required_fields:
|
||||
- _time
|
||||
- Processes.dest
|
||||
- Processes.user
|
||||
- Processes.parent_process_name #parent process name
|
||||
- Processes.parent_process #parent cmdline
|
||||
- Processes.original_file_name
|
||||
- Processes.process_name #process name
|
||||
- Processes.process #process cmdline
|
||||
- Processes.process_id
|
||||
- Processes.parent_process_path
|
||||
- Processes.process_path
|
||||
- Processes.parent_process_id
|
||||
security_domain: endpoint
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1190/papercut/papercutng-app-spawn_windows-sysmon.log
|
||||
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
|
||||
sourcetype: xmlwineventlog
|
||||
@@ -0,0 +1,58 @@
|
||||
name: PaperCut NG Suspicious Behavior Debug Log
|
||||
id: 395163b8-689b-444b-86c7-9fe9ad624734
|
||||
version: 1
|
||||
date: '2023-05-15'
|
||||
author: Michael Haag, Splunk
|
||||
status: experimental
|
||||
type: Hunting
|
||||
data_source: []
|
||||
description: The following hunting analytic is designed to monitor and detect potential exploitation attempts targeting a PaperCut NG server by analyzing its debug log data. By focusing on public IP addresses accessing the PaperCut NG instance, this analytic aims to identify unauthorized or suspicious access attempts. Furthermore, it searches for specific URIs that have been discovered in the proof of concept code, which are associated with known exploits or vulnerabilities. The analytic is focused on the user admin. Regex is used mainly because the log is not parsed by Splunk and there is no TA for this debug log.
|
||||
search: '`papercutng` (loginType=Admin OR userName=admin)
|
||||
| eval uri_match=if(match(_raw, "(?i)(\/app\?service=page\/SetupCompleted|\/app|\/app\?service=page\/PrinterList|\/app\?service=direct\/1\/PrinterList\/selectPrinter&sp=l1001|\/app\?service=direct\/1\/PrinterDetails\/printerOptionsTab\.tab)"), "URI matches", null())
|
||||
| eval ip_match=if(match(_raw, "(?i)((25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)\.(25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)\.(25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)\.(25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?))") AND NOT match(_raw, "(?i)(10\.(25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)\.(25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)\.(25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?))|(172\.(1[6-9]|2[0-9]|3[0-1])\.(25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)\.(25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?))|(192\.168\.(25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)\.(25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?))"), "IP matches", null())
|
||||
| where (isnotnull(uri_match) OR isnotnull(ip_match))
|
||||
| stats sparkline, count, values(uri_match) AS uri_match, values(ip_match) AS ip_match latest(_raw)
|
||||
BY host, index, sourcetype | `papercut_ng_suspicious_behavior_debug_log_filter`'
|
||||
how_to_implement: Debug logs must be enabled and shipped to Splunk in order to properly identify behavior with this analytic.
|
||||
known_false_positives: False positives may be present, as this is based on the admin user accessing the Papercut NG instance from a public IP address. Filter as needed.
|
||||
references:
|
||||
- https://www.papercut.com/kb/Main/HowToCollectApplicationServerDebugLogs
|
||||
- https://github.com/inodee/threathunting-spl/blob/master/hunt-queries/HAFNIUM.md
|
||||
- https://www.cisa.gov/news-events/alerts/2023/05/11/cisa-and-fbi-release-joint-advisory-response-active-exploitation-papercut-vulnerability
|
||||
- https://www.papercut.com/kb/Main/PO-1216-and-PO-1219
|
||||
- https://www.horizon3.ai/papercut-cve-2023-27350-deep-dive-and-indicators-of-compromise/
|
||||
- https://www.bleepingcomputer.com/news/security/hackers-actively-exploit-critical-rce-bug-in-papercut-servers/
|
||||
- https://www.huntress.com/blog/critical-vulnerabilities-in-papercut-print-management-software
|
||||
tags:
|
||||
analytic_story:
|
||||
- PaperCut MF NG Vulnerability
|
||||
asset_type: Web Server
|
||||
atomic_guid: []
|
||||
confidence: 80
|
||||
impact: 80
|
||||
message: Behavior related to exploitation of PaperCut NG has been identified on $host$.
|
||||
mitre_attack_id:
|
||||
- T1190
|
||||
observable:
|
||||
- name: host
|
||||
type: Hostname
|
||||
role:
|
||||
- Victim
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
risk_score: 64
|
||||
required_fields:
|
||||
- uri_match
|
||||
- ip_match
|
||||
- index
|
||||
- sourcetype
|
||||
- host
|
||||
security_domain: endpoint
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1190/papercut/server.log
|
||||
source: papercutng
|
||||
sourcetype: papercutng
|
||||
@@ -0,0 +1,57 @@
|
||||
name: PaperCut NG Remote Web Access Attempt
|
||||
id: 9fcb214a-dc42-4ce7-a650-f1d2cab16a6a
|
||||
version: 1
|
||||
date: '2023-05-15'
|
||||
author: Michael Haag, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
data_source: []
|
||||
description: The following analytic is designed to detect potential exploitation attempts on publicly accessible PaperCut NG servers. It identifies connections from public IP addresses to the server and specifically monitors for URI paths commonly found in proof-of-concept (POC) scripts for exploiting PaperCut NG vulnerabilities. These URI paths have been observed in both Metasploit modules and standalone scripts used for attacking PaperCut NG servers.
|
||||
When a public IP address is detected accessing one or more of these suspicious URI paths, an alert may be generated to notify the security team of the potential threat. The team can then investigate the source IP address, the targeted PaperCut NG server, and any other relevant information to determine the nature of the activity and take appropriate actions to mitigate the risk.
|
||||
search: '| tstats count from datamodel=Web where Web.url IN ("/app?service=page/SetupCompleted", "/app", "/app?service=page/PrinterList", "/app?service=direct/1/PrinterList/selectPrinter&sp=*", "/app?service=direct/1/PrinterDetails/printerOptionsTab.tab") NOT (src IN ("10.*.*.*","172.16.*.*", "192.168.*.*", "169.254.*.*", "127.*.*.*", "fc00::*", "fd00::*", "fe80::*")) by Web.http_user_agent Web.http_method, Web.url,Web.url_length Web.src, Web.dest Web.dest_port sourcetype | `drop_dm_object_name("Web")` | `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)` | `papercut_ng_remote_web_access_attempt_filter`'
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information
|
||||
on Web traffic that include fields relavent for traffic into the `Web` datamodel.
|
||||
known_false_positives: False positives may be present, filter as needed.
|
||||
references:
|
||||
- https://www.cisa.gov/news-events/alerts/2023/05/11/cisa-and-fbi-release-joint-advisory-response-active-exploitation-papercut-vulnerability
|
||||
- https://www.papercut.com/kb/Main/PO-1216-and-PO-1219
|
||||
- https://www.horizon3.ai/papercut-cve-2023-27350-deep-dive-and-indicators-of-compromise/
|
||||
- https://www.bleepingcomputer.com/news/security/hackers-actively-exploit-critical-rce-bug-in-papercut-servers/
|
||||
- https://www.huntress.com/blog/critical-vulnerabilities-in-papercut-print-management-software
|
||||
tags:
|
||||
analytic_story:
|
||||
- PaperCut MF NG Vulnerability
|
||||
asset_type: Web Server
|
||||
atomic_guid: []
|
||||
confidence: 70
|
||||
impact: 90
|
||||
message: URIs specific to PaperCut NG have been access by a public IP against $dest$.
|
||||
mitre_attack_id:
|
||||
- T1190
|
||||
observable:
|
||||
- name: dest
|
||||
type: Hostname
|
||||
role:
|
||||
- Victim
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
risk_score: 63
|
||||
required_fields:
|
||||
- _time
|
||||
- Web.http_user_agent
|
||||
- Web.http_method
|
||||
- Web.url
|
||||
- Web.url_length
|
||||
- Web.src
|
||||
- Web.dest
|
||||
- sourcetype
|
||||
security_domain: network
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1190/papercut/papercutng-suricata.log
|
||||
source: suricata
|
||||
sourcetype: suricata
|
||||
@@ -0,0 +1,4 @@
|
||||
definition: sourcetype="papercutng"
|
||||
description: customer specific splunk configurations(eg- index, source, sourcetype).
|
||||
Replace the macro definition with configurations for your Splunk Environmnent.
|
||||
name: papercutng
|
||||
@@ -0,0 +1,32 @@
|
||||
name: PaperCut MF NG Vulnerability
|
||||
id: 2493d270-5665-4fb4-99c7-8f886f260676
|
||||
version: 1
|
||||
date: '2023-05-15'
|
||||
author: Michael Haag, Splunk
|
||||
description: The FBI has issued a joint advisory concerning the exploitation of a PaperCut MF/NG vulnerability (CVE-2023-27350) by malicious actors, which began in mid-April 2023 and has been ongoing. In early May 2023, a group identifying themselves as the Bl00dy Ransomware Gang targeted vulnerable PaperCut servers within the Education Facilities Subsector. The advisory provides information on detecting exploitation attempts and shares known indicators of compromise (IOCs) associated with the group's activities.
|
||||
narrative: 'PaperCut MF/NG versions 19 and older have reached their end-of-life, as documented on the End of Life Policy page. Customers using these older versions are advised to purchase an updated license online for PaperCut NG or through their PaperCut Partner for PaperCut MF. For users with a currently supported version (version 20 or later), they can upgrade to any maintenance release version they are licensed for.
|
||||
If upgrading to a security patch is not possible, there are alternative options to enhance security. Users can lock down network access to their server(s) by blocking all inbound traffic from external IPs to the web management port (port 9191 and 9192 by default) and blocking all inbound traffic to the web management portal on the firewall to the server. Additionally, users can apply "Allow list" restrictions under Options > Advanced > Security > Allowed site server IP addresses, setting this to only allow the IP addresses of verified Site Servers on their network.
|
||||
|
||||
The vulnerabilities CVE-2023-27350 and CVE-2023-27351 have CVSS scores of 9.8 (Critical) and 8.2 (High), respectively. PaperCut and its partner network have activated response teams to assist PaperCut MF and NG customers, with service desks available 24/7 via their support page. The security response team at PaperCut has been working with external security advisors to compile a list of unpatched PaperCut MF/NG servers that have ports open on the public internet. They have been proactively reaching out to potentially exposed customers since Wednesday afternoon (AEST) and are working around the clock through the weekend.
|
||||
|
||||
The exploit was first detected in the wild on April 18th, 2023, at 03:30 AEST / April 17th, 2023, at 17:30 UTC. The earliest signature of suspicious activity on a customer server potentially linked to this vulnerability dates back to April 14th, 2023, at 01:29 AEST / April 13th, 2023, at 15:29 UTC.
|
||||
|
||||
Applying the security fixes should not have any negative impact. Users can follow their usual upgrade procedure to obtain the upgrade. Additional links on the -Check for updates- page (accessed through the Admin interface > About > Version info > Check for updates) allow customers to download fixes for previous major versions that are still supported (e.g., 20.1.7 and 21.2.11) as well as the current version available. PaperCut MF users are advised to follow their regular upgrade process and consult their PaperCut partner or reseller for assistance.'
|
||||
references:
|
||||
- https://www.cisa.gov/news-events/alerts/2023/05/11/cisa-and-fbi-release-joint-advisory-response-active-exploitation-papercut-vulnerability
|
||||
- https://www.papercut.com/kb/Main/PO-1216-and-PO-1219
|
||||
- https://www.horizon3.ai/papercut-cve-2023-27350-deep-dive-and-indicators-of-compromise/
|
||||
- https://www.bleepingcomputer.com/news/security/hackers-actively-exploit-critical-rce-bug-in-papercut-servers/
|
||||
- https://www.huntress.com/blog/critical-vulnerabilities-in-papercut-print-management-software
|
||||
tags:
|
||||
analytic_story: PaperCut MF NG Vulnerability
|
||||
cve:
|
||||
- CVE-2023-27350
|
||||
- CVE-2023-27351
|
||||
category:
|
||||
- Adversary Tactics
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
usecase: Advanced Threat Detection
|
||||
Reference in New Issue
Block a user