Files
splunk-security_content/docs/_stories/proxyshell.md
T
2021-09-20 20:45:22 -04:00

2.2 KiB

title, last_modified_at, toc, tags
title last_modified_at toc tags
ProxyShell 2021-08-24 true
Splunk Enterprise
Splunk Enterprise Security
Splunk Cloud
Endpoint

Description

ProxyShell is a chain of exploits targeting on-premise Microsoft Exchange Server - CVE-2021-34473, CVE-2021-34523, and CVE-2021-31207.

  • ID: 413bb68e-04e2-11ec-a835-acde48001122
  • Product: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud
  • Datamodel: Endpoint
  • Last Updated: 2021-08-24
  • Author: Michael Haag, Teoderick Contreras, Mauricio Velazco, Splunk

Detection profiles

Name Technique Type
Detect Exchange Web Shell None TTP
Exchange PowerShell Abuse via SSRF None TTP
Exchange PowerShell Module Usage None TTP
W3WP Spawning Shell None TTP

Reference

source | version: 1