web: remove rba from hunting

This commit is contained in:
ljstella
2024-11-15 11:01:13 -06:00
parent 4a3bc666ed
commit 8d7aabc2cd
5 changed files with 0 additions and 40 deletions
@@ -29,13 +29,6 @@ references:
- https://support.citrix.com/article/CTX561482/citrix-adc-and-citrix-gateway-security-bulletin-for-cve20233519-cve20233466-cve20233467
- https://securityintelligence.com/x-force/x-force-uncovers-global-netscaler-gateway-credential-harvesting-campaign/
- https://support.citrix.com/article/CTX579459/netscaler-adc-and-netscaler-gateway-security-bulletin-for-cve20234966-and-cve20234967
rba:
message: Possible expliotation of CVE-2023-3519 against $dest$.
risk_objects:
- field: dest
type: system
score: 45
threat_objects: []
tags:
analytic_story:
- Citrix Netscaler ADC CVE-2023-3519
@@ -32,13 +32,6 @@ known_false_positives: False positives may be present, filtering may be needed.
Hunting to TTP.
references:
- https://blog.assetnote.io/2023/07/04/citrix-sharefile-rce/
rba:
message: Possible expliotation of CVE-2023-24489 against $dest$.
risk_objects:
- field: dest
type: system
score: 45
threat_objects: []
tags:
analytic_story:
- Citrix ShareFile RCE CVE-2023-24489
-9
View File
@@ -43,15 +43,6 @@ references:
- https://news.sophos.com/en-us/2021/12/12/log4shell-hell-anatomy-of-an-exploit-outbreak/
- https://gist.github.com/MHaggis/1899b8554f38c8692a9fb0ceba60b44c
- https://twitter.com/sasi2103/status/1469764719850442760?s=20
rba:
message: Hunting for Log4Shell exploitation has occurred.
risk_objects:
- field: dest
type: system
score: 40
threat_objects:
- field: src
type: ip_address
tags:
analytic_story:
- Log4Shell CVE-2021-44228
@@ -33,14 +33,6 @@ references:
- https://www.vmware.com/security/advisories/VMSA-2022-0011.html
- https://attackerkb.com/topics/BDXyTqY1ld/cve-2022-22954/rapid7-analysis
- https://twitter.com/wvuuuuuuuuuuuuu/status/1519476924757778433
rba:
message: An attempt to exploit a VMware Server Side Injection CVE-2022-22954 on
$dest$ has occurred.
risk_objects:
- field: dest
type: system
score: 35
threat_objects: []
tags:
analytic_story:
- VMware Server Side Injection and Privilege Escalation
@@ -27,15 +27,6 @@ known_false_positives: False positives may occur if legitimate PSWA processes ar
between legitimate and malicious activity.
references:
- https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-241a
rba:
message: Access to the PowerShell Web Access (PSWA) console detected from $src$.
risk_objects:
- field: dest
type: system
score: 32
threat_objects:
- field: src
type: ip_address
tags:
analytic_story:
- CISA AA24-241A