Update CVE-2022-26134-Confluence.yaml
This commit is contained in:
Родитель
1df1e4f31e
Коммит
02dc3a90be
|
@ -16,8 +16,8 @@ tactics:
|
||||||
relevantTechniques:
|
relevantTechniques:
|
||||||
- T1203
|
- T1203
|
||||||
query: |
|
query: |
|
||||||
DeviceProcessEvents
|
DeviceProcessEvents
|
||||||
| where InitiatingProcessFileName hasprefix "tomcat" and InitiatingProcessCommandLine has "confluence"
|
| where InitiatingProcessFileName hasprefix "tomcat" and InitiatingProcessCommandLine has "confluence"
|
||||||
| where (ProcessCommandLine has_any("certutil", "whoami", "nltest", " dir ", "curl", "ifconfig", "cat ", "net user",
|
| where (ProcessCommandLine has_any("certutil", "whoami", "nltest", " dir ", "curl", "ifconfig", "cat ", "net user",
|
||||||
"net time /domain","tasklist","-c ls","ipconfig","arp","ping","net view","net group","netstat", "wmic datafile"))
|
"net time /domain","tasklist","-c ls","ipconfig","arp","ping","net view","net group","netstat", "wmic datafile"))
|
||||||
or (FileName =~ "powershell.exe" and ProcessCommandLine hasprefix "-e")
|
or (FileName =~ "powershell.exe" and ProcessCommandLine hasprefix "-e")
|
||||||
|
|
Загрузка…
Ссылка в новой задаче