CVE-2021-22893 - Pulse Connect Secure RCE

On April 20th, a new Remote Code Execution vulnerability in Pulse Connect Secure was disclosed. The reference number for the vulnerability is CVE-2021-22893 with the CVSS Score of 10.0. This playbook should be trigger manually and includes the following tasks: * Enrich related known CVEs and Malware Hashes used by the suspected APT actor. * Search for unpatched endpoints vulnerable to the exploits. * Search network facing system using Expanse for relevant issues. * Indicators and known webshells hunting using SIEM products. * Block indicators automatically or manually. * Provide different mitigations that has been publicly published such as: * Patches * Workarounds * Yara and Snort Rules Note: This is a beta playbook, which lets you implement and test pre-release software. Since the playbook is beta, it might contain bugs. Updates to the pack during the beta phase might include non-backward compatible features. We appreciate your feedback on the quality and usability of the pack to help us identify issues, fix them, and continually improve. More information: [Exploitation of Pulse Connect Secure Vulnerabilities](https://us-cert.cisa.gov/ncas/alerts/aa21-110a)

Pack
MajorBreachesInvestigationandResponse
Tasks
35

Inputs

Commands used