mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
web: remove rba from hunting
This commit is contained in:
@@ -29,13 +29,6 @@ references:
|
||||
- https://support.citrix.com/article/CTX561482/citrix-adc-and-citrix-gateway-security-bulletin-for-cve20233519-cve20233466-cve20233467
|
||||
- https://securityintelligence.com/x-force/x-force-uncovers-global-netscaler-gateway-credential-harvesting-campaign/
|
||||
- https://support.citrix.com/article/CTX579459/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve20234966-and-cve20234967
|
||||
rba:
|
||||
message: Possible expliotation of CVE-2023-3519 against $dest$.
|
||||
risk_objects:
|
||||
- field: dest
|
||||
type: system
|
||||
score: 45
|
||||
threat_objects: []
|
||||
tags:
|
||||
analytic_story:
|
||||
- Citrix Netscaler ADC CVE-2023-3519
|
||||
|
||||
@@ -32,13 +32,6 @@ known_false_positives: False positives may be present, filtering may be needed.
|
||||
Hunting to TTP.
|
||||
references:
|
||||
- https://blog.assetnote.io/2023/07/04/citrix-sharefile-rce/
|
||||
rba:
|
||||
message: Possible expliotation of CVE-2023-24489 against $dest$.
|
||||
risk_objects:
|
||||
- field: dest
|
||||
type: system
|
||||
score: 45
|
||||
threat_objects: []
|
||||
tags:
|
||||
analytic_story:
|
||||
- Citrix ShareFile RCE CVE-2023-24489
|
||||
|
||||
@@ -43,15 +43,6 @@ references:
|
||||
- https://news.sophos.com/en-us/2021/12/12/log4shell-hell-anatomy-of-an-exploit-outbreak/
|
||||
- https://gist.github.com/MHaggis/1899b8554f38c8692a9fb0ceba60b44c
|
||||
- https://twitter.com/sasi2103/status/1469764719850442760?s=20
|
||||
rba:
|
||||
message: Hunting for Log4Shell exploitation has occurred.
|
||||
risk_objects:
|
||||
- field: dest
|
||||
type: system
|
||||
score: 40
|
||||
threat_objects:
|
||||
- field: src
|
||||
type: ip_address
|
||||
tags:
|
||||
analytic_story:
|
||||
- Log4Shell CVE-2021-44228
|
||||
|
||||
@@ -33,14 +33,6 @@ references:
|
||||
- https://www.vmware.com/security/advisories/VMSA-2022-0011.html
|
||||
- https://attackerkb.com/topics/BDXyTqY1ld/cve-2022-22954/rapid7-analysis
|
||||
- https://twitter.com/wvuuuuuuuuuuuuu/status/1519476924757778433
|
||||
rba:
|
||||
message: An attempt to exploit a VMware Server Side Injection CVE-2022-22954 on
|
||||
$dest$ has occurred.
|
||||
risk_objects:
|
||||
- field: dest
|
||||
type: system
|
||||
score: 35
|
||||
threat_objects: []
|
||||
tags:
|
||||
analytic_story:
|
||||
- VMware Server Side Injection and Privilege Escalation
|
||||
|
||||
@@ -27,15 +27,6 @@ known_false_positives: False positives may occur if legitimate PSWA processes ar
|
||||
between legitimate and malicious activity.
|
||||
references:
|
||||
- https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-241a
|
||||
rba:
|
||||
message: Access to the PowerShell Web Access (PSWA) console detected from $src$.
|
||||
risk_objects:
|
||||
- field: dest
|
||||
type: system
|
||||
score: 32
|
||||
threat_objects:
|
||||
- field: src
|
||||
type: ip_address
|
||||
tags:
|
||||
analytic_story:
|
||||
- CISA AA24-241A
|
||||
|
||||
Reference in New Issue
Block a user