CVE-2021-22893 - Pulse Connect Secure RCE
On April 20th, a new Remote Code Execution vulnerability in Pulse Connect Secure was disclosed. The reference number for the vulnerability is CVE-2021-22893 with the CVSS Score of 10.0. This playbook should be trigger manually and includes the following tasks: * Enrich related known CVEs and Malware Hashes used by the suspected APT actor. * Search for unpatched endpoints vulnerable to the exploits. * Search network facing system using Expanse for relevant issues. * Indicators and known webshells hunting using SIEM products. * Block indicators automatically or manually. * Provide different mitigations that has been publicly published such as: * Patches * Workarounds * Yara and Snort Rules Note: This is a beta playbook, which lets you implement and test pre-release software. Since the playbook is beta, it might contain bugs. Updates to the pack during the beta phase might include non-backward compatible features. We appreciate your feedback on the quality and usability of the pack to help us identify issues, fix them, and continually improve. More information: [Exploitation of Pulse Connect Secure Vulnerabilities](https://us-cert.cisa.gov/ncas/alerts/aa21-110a)
Rapid Breach Response · 35 tasks · 11 inputs · 0 outputs
Details
| ID | CVE-2021-22893 - Pulse Connect Secure RCE |
|---|---|
| From Version | 6.0.0 |
| To Version | 6.4.9 |
| Tasks | 35 |
README
On April 20th, a new Remote Code Execution vulnerability in Pulse Connect Secure was disclosed.
The reference number for the vulnerability is CVE-2021-22893 with the CVSS Score of 10.0.
This playbook should be trigger manually and includes the following tasks:
- Enrich related known CVEs and Malware Hashes used by the suspected APT actor.
- Search for unpatched endpoints vulnerable to the exploits.
- Search network facing system using Expanse for relevant issues.
- Indicators and known webshells hunting using SIEM products.
- Block indicators automatically or manually.
- Provide different mitigations that has been publicly published such as:
- Patches
- Workarounds
- Yara and Snort Rules
Note: This is a beta playbook, which lets you implement and test pre-release software. Since the playbook is beta, it might contain bugs. Updates to the pack during the beta phase might include non-backward compatible features. We appreciate your feedback on the quality and usability of the pack to help us identify issues, fix them, and continually improve.
More information:
Exploitation of Pulse Connect Secure Vulnerabilities
Dependencies
This playbook uses the following sub-playbooks, integrations, and scripts.
Sub-playbooks
- QRadar Indicator Hunting V2
- QRadarFullSearch
- Search Endpoint by CVE - Generic
- Palo Alto Networks - Hunting And Threat Detection
- Block Indicators - Generic v2
- Splunk Indicator Hunting
Integrations
This playbook does not use any integrations.
Scripts
This playbook does not use any scripts.
Commands
- expanse-get-issues
- enrichIndicators
- splunk-search
- extractIndicators
Playbook Inputs
| Name | Description | Default Value | Required |
|---|---|---|---|
| Related_Hashes | The known hashes of different malware families associated with the exploitation. | 06c56bd272b19bf7d7207443693cd1fc774408c4ca56744577b11fee550c23f7,64c87520565165ac95b74d6450b3ab8379544933dd3e2f2c4dc9b03a3ec570a7,1322340356018696d853e0ac6f7ce3a2,09956753b5000061524d204000000001,88170125598a4fb801102ad56494a773895059ac8550a983fdd2ef429653f079,9f6ac39707822d243445e30d27b8404466aa69c61119d5308785bf4a464a9ebd,325d6d60e24c7cfc3a782839d85ce08c8d3bb27c,1ab50b77dd9515f6cd9ed07d1d3176ba4627a292dc4a21b16ac9d211353818bd,1741dc0a491fcc8d078220ac9628152668d3370b92a8eae258e34ba28c6473b9,cd09ec795a8f4b6ced003500a44d810f49943514e2f92c81ab96c33e1c0fbd68,d72daafedf41d484f7f9816f7f076a9249a6808f1899649b7daa22c0447bb37b,c9b323b9747659eac25cec078895d75f016e26a8b5858567c7fb945b7321722c,2610d0372e0e107053bc001d278ef71f08562e5610691f18b978123c499a74d8,c774eca633136de35c9d2cd339a3b5d29f00f761657ea2aa438de4f33e4bbba4,224b7c45cf6fe4547d3ea66a12c30f3cb4c601b0a80744154697094e73dbd450,78d7c7c9f800f6824f63a99d935a4ad0112f97953d8c100deb29dae24d7da282,1d3ab04e21cfd40aa8d4300a359a09e3b520d39b1496be1e4bc91ae1f6730ecc,133631957d41eed9496ac2774793283ce26f8772de226e7f520d26667b51481a,68743e17f393d1f85ee937dffacc91e081b5f6f43477111ac96aa9d44826e4d2,7fa71a7f76ef63465cfeacf58217e0b66fc71bc81d37c44380a6f572b8a3ec7a,f2b1bd703c3eb05541ff84ec375573cbdc70309ccb82aac04b72db205d718e90,a1dcdf62aafc36dd8cf64774dea80d79fb4e24ba2a82adf4d944d9186acd1cc1,e63ab6f82c711e4ecc8f5b36046eb7ea216f41eb90158165b82a6c90560ea415,b2350954b9484ae4eac42b95fae6edf7a126169d0b93d79f49d36c5e6497062a,b1c2368773259fbfef425e0bb716be958faa7e74b3282138059f511011d3afd9,b990f79ce80c24625c97810cb8f161eafdcb10f1b8d9d538df4ca9be387c35e4,168976797d5af7071df257e91fcc31ce1d6e59c72ca9e2f50c8b5b3177ad83cc,4c5555955b2e6dc55f52b0c1a3326f3d07b325b112060329c503b294208960ec,705cda7d1ace8f4adeec5502aa311620b8d6c64046a1aed2ae833e2f2835154f | Optional |
| Related_CVEs | The known CVEs associated with the exploitation. | CVE-2019-11510, CVE-2020-8260, CVE-2020-8243, CVE-2021-22893 | Optional |
| BlockAutomatically | Whether to block the indicators automatically. Default: False. |
False | Optional |
| QRadarWebshellsQuery | The QRadar search query used for “Hunt Activity Using QRadar”. Please note that there aren’t specified fields which may cause a longer run time. |
select * from events WHERE LogSourceTypeName(deviceType) = ‘Pulse Secure Pulse Connect Secure’ and ( UTF8(payload) LIKE ‘%Licenseserverproto.cgi%’ or UTF8(payload) LIKE ‘%Secid_canceltoken.cgi%’ or UTF8(payload) LIKE ‘%compcheckresult.cgi%’ or UTF8(payload) LIKE ‘%Login.cgi%’ or UTF8(payload) LIKE ‘%Healthcheck.cgi%’ or UTF8(payload) LIKE ‘%meeting_testjs.cgi%’ or UTF8(payload) LIKE ‘%compcheckjava.cgi%’) | Optional |
| SplunkWebshellsQuery | The Splunk search query used for “Hunt Activity Using Splunk”. Please note that there are two specified fields: msg, message. the query will work for both field names. |
index=* sourcetype=pulse:connectsecure “Licenseserverproto.cgi” OR “Secid_canceltoken.cgi” OR “compcheckresult.cgi” OR “Healthcheck.cgi” OR “meeting_testjs.cgi” OR “compcheckjava.cgi” | Optional |
| RunWebshellsQuery | If you would like to skip “Hunt Activity Using Splunk” OR “Hunt Activity Using Qradar” please change the value to ‘False’. | True | Optional |
| QRadar_MD5_Field | The name of the field for MD5 entries in QRadar. If not configured, QRadar Indicator Hunting may reach timeout. |
Optional | |
| QRadar_SHA1_Field | The name of the field for SHA1 entries in QRadar. If not configured, QRadar Indicator Hunting may reach timeout. |
Optional | |
| QRadar_SHA256_Field | The name of the field for SHA256 entries in QRadar. If not configured, QRadar Indicator Hunting may reach timeout. |
Optional | |
| SplunkEarliestTime | The earliest time for the Splunk search query. | -30d | Optional |
| SplunkLatestTime | The latest time for the Splunk search query. | now | Optional |
Playbook Outputs
There are no outputs for this playbook.
Playbook Image

Inputs
Related_Hashes— The known hashes of different malware families associated with the exploitation.Related_CVEs— The known CVEs associated with the exploitation.BlockAutomatically— Whether to block the indicators automatically. Default: False.QRadarWebshellsQuery— The QRadar search query used for "Hunt Activity Using QRadar". Please note that there aren't specified fields which may cause a longer run time.SplunkWebshellsQuery— The Splunk search query used for "Hunt Activity Using Splunk". Please note that there are two specified fields: msg, message. the query will work for both field names.RunWebshellsQuery— If you would like to skip "Hunt Activity Using Splunk" OR "Hunt Activity Using Qradar" please change the value to 'False'.QRadar_MD5_Field— The name of the field for MD5 entries in QRadar. If not configured, QRadar Indicator Hunting may reach timeout.QRadar_SHA1_Field— The name of the field for SHA1 entries in QRadar. If not configured, QRadar Indicator Hunting may reach timeout.QRadar_SHA256_Field— The name of the field for SHA256 entries in QRadar. If not configured, QRadar Indicator Hunting may reach timeout.SplunkEarliestTime— The earliest time for the Splunk search query.SplunkLatestTime— The latest time for the Splunk search query.
Commands used
enrichIndicators
expanse-get-issues
extractIndicators
splunk-search
Flowchart
id: CVE-2021-22893 - Pulse Connect Secure RCE version: -1 name: CVE-2021-22893 - Pulse Connect Secure RCE description: "On April 20th, a new Remote Code Execution vulnerability in Pulse Connect\ \ Secure was disclosed. \nThe reference number for the vulnerability is CVE-2021-22893\ \ with the CVSS Score of 10.0. \nThis playbook should be trigger manually and includes\ \ the following tasks: \n\n* Enrich related known CVEs and Malware Hashes used by\ \ the suspected APT actor.\n* Search for unpatched endpoints vulnerable to the exploits.\n\ * Search network facing system using Expanse for relevant issues.\n* Indicators\ \ and known webshells hunting using SIEM products.\n* Block indicators automatically\ \ or manually.\n* Provide different mitigations that has been publicly published\ \ such as:\n * Patches\n * Workarounds\n * Yara and Snort Rules\n\nNote:\ \ This is a beta playbook, which lets you implement and test pre-release software.\ \ Since the playbook is beta, it might contain bugs. Updates to the pack during\ \ the beta phase might include non-backward compatible features. We appreciate your\ \ feedback on the quality and usability of the pack to help us identify issues,\ \ fix them, and continually improve.\n\nMore information:\n[Exploitation of Pulse\ \ Connect Secure Vulnerabilities](https://us-cert.cisa.gov/ncas/alerts/aa21-110a)\n" starttaskid: "0" tasks: "0": id: "0" taskid: 8308f76e-de23-4b77-8c7a-0b1b2e734d5e type: start task: id: 8308f76e-de23-4b77-8c7a-0b1b2e734d5e version: -1 name: "" iscommand: false brand: "" description: '' nexttasks: '#none#': - "35" separatecontext: false view: |- { "position": { "x": 770, "y": -270 } } note: false timertriggers: [] ignoreworker: false skipunavailable: true quietmode: 0 "1": id: "1" taskid: 28b3f68d-e04e-4e85-8f3d-677e40a436e4 type: regular task: id: 28b3f68d-e04e-4e85-8f3d-677e40a436e4 version: -1 name: Enrich CVE Indicators description: Enrich CVEs indicators script: Builtin|||enrichIndicators type: regular iscommand: true brand: Builtin nexttasks: '#none#': - "4" scriptarguments: indicatorsValues: complex: root: CVE accessor: ID separatecontext: false view: |- { "position": { "x": 540, "y": 230 } } note: false timertriggers: [] ignoreworker: false skipunavailable: true quietmode: 0 "2": id: "2" taskid: 9cf18652-2511-462e-8623-a41414ff940f type: regular task: id: 9cf18652-2511-462e-8623-a41414ff940f version: -1 name: Enrich Hash Indicators description: commands.local.cmd.enrich.indicators script: Builtin|||enrichIndicators type: regular iscommand: true brand: Builtin nexttasks: '#none#': - "4" scriptarguments: indicatorsValues: complex: root: File accessor: MD5 transformers: - operator: append args: item: value: simple: File.SHA1 iscontext: true - operator: append args: item: value: simple: File.SHA256 iscontext: true retry-count: simple: "3" retry-interval: simple: "5" separatecontext: false view: |- { "position": { "x": 990, "y": 230 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 "3": id: "3" taskid: 9ffb88c1-032f-4403-8e5b-61bdb5cff00f type: title task: id: 9ffb88c1-032f-4403-8e5b-61bdb5cff00f version: -1 name: Enrichment type: title iscommand: false brand: "" description: '' nexttasks: '#none#': - "2" - "1" separatecontext: false view: |- { "position": { "x": 770, "y": 70 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 "4": id: "4" taskid: a69b6038-bc82-43ce-800f-651e192a97f6 type: title task: id: a69b6038-bc82-43ce-800f-651e192a97f6 version: -1 name: Hunting type: title iscommand: false brand: "" description: '' nexttasks: '#none#': - "5" - "6" - "7" - "12" - "25" separatecontext: false view: |- { "position": { "x": 770, "y": 410 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 "5": id: "5" taskid: efe4361d-334c-46f6-8877-2c206718b950 type: title task: id: efe4361d-334c-46f6-8877-2c206718b950 version: -1 name: SIEM Hunt type: title iscommand: false brand: "" description: '' nexttasks: '#none#': - "10" - "37" separatecontext: false view: |- { "position": { "x": -1040, "y": 620 } } note: false timertriggers: [] ignoreworker: false skipunavailable: true quietmode: 0 "6": id: "6" taskid: 9b4033c8-84a0-4fed-8fb0-043bb7d72bac type: title task: id: 9b4033c8-84a0-4fed-8fb0-043bb7d72bac version: -1 name: Vulnerability Scanners Hunt type: title iscommand: false brand: "" description: '' nexttasks: '#none#': - "8" separatecontext: false view: |- { "position": { "x": -300, "y": 620 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 "7": id: "7" taskid: c4a760fc-71bf-46c1-8633-3892e4e5444b type: title task: id: c4a760fc-71bf-46c1-8633-3892e4e5444b version: -1 name: Palo Alto Networks Hunt type: title iscommand: false brand: "" description: '' nexttasks: '#none#': - "9" separatecontext: false view: |- { "position": { "x": 1810, "y": 620 } } note: false timertriggers: [] ignoreworker: false skipunavailable: true quietmode: 0 "8": id: "8" taskid: 704f5545-b3ac-4c1e-898c-b135ddb75438 type: playbook task: id: 704f5545-b3ac-4c1e-898c-b135ddb75438 version: -1 name: Search Endpoint by CVE - Generic description: Hunt for assets with a given CVE using available tools playbookName: Search Endpoint by CVE - Generic type: playbook iscommand: false brand: "" nexttasks: '#none#': - "14" scriptarguments: CVE_ID: complex: root: CVE accessor: ID separatecontext: true loop: iscommand: false exitCondition: "" wait: 1 max: 100 view: |- { "position": { "x": -300, "y": 780 } } note: false timertriggers: [] ignoreworker: false skipunavailable: true quietmode: 0 "9": id: "9" taskid: 6a1b2349-17bb-4286-8337-d962530e44d5 type: playbook task: id: 6a1b2349-17bb-4286-8337-d962530e44d5 version: -1 name: Palo Alto Networks - Hunting And Threat Detection description: "This is a multipurpose playbook used for hunting and threat detection.\ \ The playbook receives inputs based on hashes, IP addresses, or domain names\ \ provided manually or from outputs by other playbooks. \nWith the received\ \ indicators, the playbook leverages data received by PANW products including,\ \ Cortex Data Lake, Autofocus and Pan-OS to search for IP addresses, host\ \ names and users related to the provided indicators.\nThe output provided\ \ by the playbook facilitates pivoting searches for possibly affected IP addresses\ \ or users." playbookName: Palo Alto Networks - Hunting And Threat Detection type: playbook iscommand: false brand: "" nexttasks: '#none#': - "14" scriptarguments: MD5: complex: root: File accessor: MD5 SHA1: complex: root: File accessor: SHA1 SHA256: complex: root: File accessor: SHA256 separatecontext: true loop: iscommand: false exitCondition: "" wait: 1 max: 100 view: |- { "position": { "x": 1810, "y": 780 } } note: false timertriggers: [] ignoreworker: false skipunavailable: true quietmode: 0 "10": id: "10" taskid: 343cde81-c933-4cb0-8ede-1dfd30520d80 type: playbook task: id: 343cde81-c933-4cb0-8ede-1dfd30520d80 version: -1 name: Splunk Indicator Hunting description: This playbook queries Splunk for indicators such as file hashes, IP addresses, domains, or urls. It outputs detected users, ip addresses, and hostnames related to the indicators. playbookName: Splunk Indicator Hunting type: playbook iscommand: false brand: "" nexttasks: '#none#': - "14" scriptarguments: IndexName: simple: '*' MD5: complex: root: File accessor: MD5 SHA1: complex: root: File accessor: SHA1 SHA256: complex: root: File accessor: SHA256 SelectFields: simple: source,timestamp earliest_time: complex: root: inputs.SplunkEarliestTime event_limit: simple: "100" latest_time: complex: root: inputs.SplunkLatestTime separatecontext: true loop: iscommand: false exitCondition: "" wait: 1 max: 100 view: |- { "position": { "x": -810, "y": 780 } } note: false timertriggers: [] ignoreworker: false skipunavailable: true quietmode: 0 "12": id: "12" taskid: 992a51d5-f474-4be4-8e45-a64b0910a80c type: title task: id: 992a51d5-f474-4be4-8e45-a64b0910a80c version: -1 name: Expanse Issues Hunt description: Retrieve issues type: title iscommand: false brand: "" nexttasks: '#none#': - "16" separatecontext: false view: |- { "position": { "x": 2470, "y": 620 } } note: false timertriggers: [] ignoreworker: false skipunavailable: true quietmode: 0 "13": id: "13" taskid: 70a3df35-5318-4938-8124-4f92cdc581ef type: regular task: id: 70a3df35-5318-4938-8124-4f92cdc581ef version: -1 name: Search for Pulse Secure VPN Devices with an open issues description: Retrieve issues related to Pulse Secure VPN. script: '|||expanse-get-issues' type: regular iscommand: true brand: "" nexttasks: '#none#': - "14" scriptarguments: content_search: simple: Pulse Secure SSL VPN issue_type: simple: VPN Device separatecontext: false view: |- { "position": { "x": 2470, "y": 1175 } } note: false timertriggers: [] ignoreworker: false skipunavailable: true quietmode: 0 "14": id: "14" taskid: c2668048-baa6-4a58-8269-4079f1cc126e type: title task: id: c2668048-baa6-4a58-8269-4079f1cc126e version: -1 name: Remediation type: title iscommand: false brand: "" description: '' nexttasks: '#none#': - "15" separatecontext: false view: |- { "position": { "x": 770, "y": 1350 } } note: false timertriggers: [] ignoreworker: false skipunavailable: true quietmode: 0 "15": id: "15" taskid: b728f187-fa54-482c-8046-4351f7f062e8 type: condition task: id: b728f187-fa54-482c-8046-4351f7f062e8 version: -1 name: Block indicators automatically? description: Check the playbook input (True/False) responsible for automatically block indicators. type: condition iscommand: false brand: "" nexttasks: '#default#': - "18" "yes": - "17" separatecontext: false conditions: - label: "yes" condition: - - operator: isEqualString left: value: complex: root: inputs.BlockAutomatically iscontext: true right: value: simple: "True" ignorecase: true view: |- { "position": { "x": 770, "y": 1510 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 "16": id: "16" taskid: 6bbdbffd-9407-43d3-8acb-a65e0b95375c type: condition task: id: 6bbdbffd-9407-43d3-8acb-a65e0b95375c version: -1 name: Is Expanse Enabled? description: Check if Expanse instance is enabled. type: condition iscommand: false brand: "" nexttasks: '#default#': - "14" "yes": - "13" separatecontext: false conditions: - label: "yes" condition: - - operator: isEqualString left: value: complex: root: modules filters: - - operator: isEqualString left: value: simple: modules.brand iscontext: true right: value: simple: ExpanseV2 accessor: state iscontext: true right: value: simple: active ignorecase: true view: |- { "position": { "x": 2470, "y": 780 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 "17": id: "17" taskid: 2398e3b6-387e-4105-8f92-03f7773a0836 type: playbook task: id: 2398e3b6-387e-4105-8f92-03f7773a0836 version: -1 name: Block Indicators - Generic v2 playbookName: Block Indicators - Generic v2 type: playbook iscommand: false brand: "" description: '' nexttasks: '#none#': - "19" separatecontext: true view: |- { "position": { "x": 480, "y": 1700 } } note: false timertriggers: [] ignoreworker: false skipunavailable: true quietmode: 0 "18": id: "18" taskid: ef38604d-2160-4823-8db3-d52e0e775332 type: regular task: id: ef38604d-2160-4823-8db3-d52e0e775332 version: -1 name: Manually block indicators description: Ask the user to manually block the indicators. type: regular iscommand: false brand: "" nexttasks: '#none#': - "19" separatecontext: false view: |- { "position": { "x": 1050, "y": 1700 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 "19": id: "19" taskid: e2ff1be7-6ca6-4cb7-84d0-2de9df314da4 type: title task: id: e2ff1be7-6ca6-4cb7-84d0-2de9df314da4 version: -1 name: Mitigation type: title iscommand: false brand: "" description: '' nexttasks: '#none#': - "20" - "24" separatecontext: false view: |- { "position": { "x": 770, "y": 1890 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 "20": id: "20" taskid: 015fc3b3-5f1d-455f-8d1d-4008e8b05eb1 type: condition task: id: 015fc3b3-5f1d-455f-8d1d-4008e8b05eb1 version: -1 name: Is Pulse Secure is patched? description: Check the data collected manually or automatically and decide whether Pulse Connect Secure is patched or not. type: condition iscommand: false brand: "" nexttasks: "No": - "22" - "23" "Yes": - "21" separatecontext: false view: |- { "position": { "x": 770, "y": 2070 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 "21": id: "21" taskid: 32f4f8dd-9ebe-48a2-813e-b67efad4091b type: regular task: id: 32f4f8dd-9ebe-48a2-813e-b67efad4091b version: -1 name: 'Review all data collected ' description: Request for final review of the data collected. type: regular iscommand: false brand: "" nexttasks: '#none#': - "34" separatecontext: false view: |- { "position": { "x": 770, "y": 2510 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 "22": id: "22" taskid: 413d666b-858a-4dc9-8867-2209d4428bed type: regular task: id: 413d666b-858a-4dc9-8867-2209d4428bed version: -1 name: 'Install related patches and workarounds ' description: |- Related patches and workarounds: [1.CVE-2021-22893](https://kb.pulsesecure.net/pkb_mobile#article/l:en_US/SA44784/s) [2.CVE-2020-8260](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-8260) [3.CVE-2020-8243](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-8243) [4.CVE-2019-11510](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-11510) Deny access to the following URIs: ^/+dana/+meeting ^/+dana/+fb/+smb ^/+dana-cached/+fb/+smb ^/+dana-ws/+namedusers ^/+dana-ws/+metric **Note: SSL decryption is needed in order to deny access to the provided URIs.** type: regular iscommand: false brand: "" nexttasks: '#none#': - "21" separatecontext: false view: |- { "position": { "x": 440, "y": 2310 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 "23": id: "23" taskid: 5ce15d56-9f45-47f8-899c-2b164344b655 type: regular task: id: 5ce15d56-9f45-47f8-899c-2b164344b655 version: -1 name: 'Run Pulse Connect Secure Integrity Tool ' description: |- This tool created by the vendor will assist with determining if systems have been impacted. [Pulse Connect Secure Integrity Tool ](https://kb.pulsesecure.net/articles/Pulse_Secure_Article/KB44755) type: regular iscommand: false brand: "" nexttasks: '#none#': - "21" separatecontext: false view: |- { "position": { "x": 1100, "y": 2310 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 "24": id: "24" taskid: 45027857-c6de-44da-8745-fce6e0a534c0 type: regular task: id: 45027857-c6de-44da-8745-fce6e0a534c0 version: -1 name: Download Yara/Snort rules from FireEye Mandiant GitHub repository description: |- [FireEye Mandiant PulseSecure Exploitation Countermeasures](https://github.com/fireeye/pulsesecure_exploitation_countermeasures) These rules are provided freely to the community without warranty. In this GitHub repository you will find rules in multiple languages: Snort Yara type: regular iscommand: false brand: "" nexttasks: '#none#': - "34" separatecontext: false view: |- { "position": { "x": -40, "y": 2070 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 "25": id: "25" taskid: 8095b0d3-b0b0-4225-83af-81b4cbb0be56 type: title task: id: 8095b0d3-b0b0-4225-83af-81b4cbb0be56 version: -1 name: Webshell Access Attempts Hunt type: title iscommand: false brand: "" description: '' nexttasks: '#none#': - "31" - "38" separatecontext: false view: |- { "position": { "x": 770, "y": 610 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 "26": id: "26" taskid: 709ce95c-f4ec-4d22-86e5-3c9f72d82031 type: title task: id: 709ce95c-f4ec-4d22-86e5-3c9f72d82031 version: -1 name: Hunt Activity Using Splunk type: title iscommand: false brand: "" description: '' nexttasks: '#none#': - "28" separatecontext: false view: |- { "position": { "x": 1200, "y": 930 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 "27": id: "27" taskid: 5ad6e2d8-9dc6-4197-82c2-5c0b911f7137 type: title task: id: 5ad6e2d8-9dc6-4197-82c2-5c0b911f7137 version: -1 name: Hunt Activity Using Qradar type: title iscommand: false brand: "" description: '' nexttasks: '#none#': - "30" separatecontext: false view: |- { "position": { "x": 340, "y": 930 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 "28": id: "28" taskid: 60f33e3c-ce34-4ccd-8b65-34d607b5c407 type: regular task: id: 60f33e3c-ce34-4ccd-8b65-34d607b5c407 version: -1 name: Search access attempts in Pulse Secure Logs description: Searches Splunk for events related to the webshells names. script: '|||splunk-search' type: regular iscommand: true brand: "" nexttasks: '#none#': - "14" scriptarguments: earliest_time: complex: root: inputs.SplunkEarliestTime latest_time: complex: root: inputs.SplunkLatestTime query: complex: root: inputs.SplunkWebshellsQuery separatecontext: false view: |- { "position": { "x": 1200, "y": 1080 } } note: false timertriggers: [] ignoreworker: false skipunavailable: true quietmode: 0 "30": id: "30" taskid: 641c1d63-ed40-4cd5-83b4-31c104ef1237 type: playbook task: id: 641c1d63-ed40-4cd5-83b4-31c104ef1237 version: -1 name: QRadarFullSearch description: This playbook runs a QRadar query and return its results to the context. playbookName: QRadarFullSearch type: playbook iscommand: false brand: "" nexttasks: '#none#': - "14" scriptarguments: interval: simple: "1" query_expression: complex: root: inputs.QRadarWebshellsQuery timeout: simple: "600" separatecontext: true loop: iscommand: false exitCondition: "" wait: 1 max: 100 view: |- { "position": { "x": 340, "y": 1080 } } note: false timertriggers: [] ignoreworker: false skipunavailable: true quietmode: 0 "31": id: "31" taskid: dbc84475-e4c2-48f4-8d45-a7ffdbb42dda type: condition task: id: dbc84475-e4c2-48f4-8d45-a7ffdbb42dda version: -1 name: Is QRadar Enabled? description: Check if QRadar or Splunk instances are enabled. type: condition iscommand: false brand: "" nexttasks: '#default#': - "33" "No": - "14" "Yes": - "27" separatecontext: false conditions: - label: "Yes" condition: - - operator: isExists left: value: complex: root: modules filters: - - operator: inList left: value: simple: modules.brand iscontext: true right: value: simple: QRadar,QRadar_v2 - - operator: isEqualString left: value: simple: modules.state iscontext: true right: value: simple: active iscontext: true - - operator: isEqualString left: value: complex: root: inputs.RunWebshellsQuery iscontext: true right: value: simple: "True" ignorecase: true - - operator: isNotEmpty left: value: complex: root: inputs.QRadarWebshellsQuery iscontext: true - label: "No" condition: - - operator: isExists left: value: complex: root: modules filters: - - operator: isEqualString left: value: simple: modules.brand iscontext: true right: value: simple: SplunkPy - - operator: isEqualString left: value: simple: modules.state iscontext: true right: value: simple: active iscontext: true view: |- { "position": { "x": 550, "y": 760 } } note: false timertriggers: [] ignoreworker: false skipunavailable: true quietmode: 0 "33": id: "33" taskid: a2b23756-19bd-4649-8712-d1d1c40c9158 type: regular task: id: a2b23756-19bd-4649-8712-d1d1c40c9158 version: -1 name: Hunt for the webshells names in PCS logs description: "Search in your Data Lake for access to one of the following URIs:\n\ \n*Licenseserverproto.cgi*\n*Secid_canceltoken.cgi* \n*compcheckresult.cgi*\n\ *Login.cgi*\n*Healthcheck.cgi*\n*meeting_testjs.cgi*\n*compcheckjava.cgi*\n\ \nLook at the following example of Pulse Secure Connect message:\n\n\"Unauthenticated\ \ request url /dana-na/meeting/meeting_testjs.cgi?id=* came from IP XX.XX.XX.XX.\"" type: regular iscommand: false brand: "" nexttasks: '#none#': - "14" separatecontext: false view: |- { "position": { "x": 770, "y": 970 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 "34": id: "34" taskid: bc891459-9fea-4821-88d5-52e29232eabd type: title task: id: bc891459-9fea-4821-88d5-52e29232eabd version: -1 name: Done type: title iscommand: false brand: "" description: '' separatecontext: false view: |- { "position": { "x": 770, "y": 2730 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 "35": id: "35" taskid: 1c5a1902-11df-431c-8106-1e72fab5fa60 type: regular task: id: 1c5a1902-11df-431c-8106-1e72fab5fa60 version: -1 name: Extract Indicators description: commands.local.cmd.extract.indicators script: Builtin|||extractIndicators type: regular iscommand: true brand: Builtin nexttasks: '#none#': - "3" scriptarguments: text: complex: root: inputs.Related_Hashes transformers: - operator: append args: item: value: simple: ${inputs.Related_CVEs} reputationcalc: 2 separatecontext: false view: |- { "position": { "x": 770, "y": -120 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 "37": id: "37" taskid: b75593b1-de06-47ad-8ca7-95ed2525e243 type: playbook task: id: b75593b1-de06-47ad-8ca7-95ed2525e243 version: -1 name: QRadar Indicator Hunting V2 description: 'The Playbook queries QRadar SIEM for indicators such as file hashes, IP addresses, domains, or urls. ' playbookName: QRadar Indicator Hunting V2 type: playbook iscommand: false brand: "" nexttasks: '#none#': - "14" scriptarguments: InvestigationIPFields: simple: sourceip,destinationip InvestigationUserFields: simple: username QradarIPfield: simple: sourceip,destinationip QradarMD5Field: complex: root: inputs.QRadar_MD5_Field QradarSHA1Field: complex: root: inputs.QRadar_SHA1_Field QradarSHA256Field: complex: root: inputs.QRadar_SHA256_Field TimeFrame: simple: LAST 7 DAYS separatecontext: true loop: iscommand: false exitCondition: "" wait: 1 max: 100 view: |- { "position": { "x": -1270, "y": 780 } } note: false timertriggers: [] ignoreworker: false skipunavailable: true quietmode: 0 "38": id: "38" taskid: a365653d-ac37-49d5-80b2-7571d996286d type: condition task: id: a365653d-ac37-49d5-80b2-7571d996286d version: -1 name: Is Splunk Enabled? description: Check if QRadar or Splunk instances are enabled. type: condition iscommand: false brand: "" nexttasks: '#default#': - "33" "No": - "14" "Yes": - "26" separatecontext: false conditions: - label: "Yes" condition: - - operator: isExists left: value: complex: root: modules filters: - - operator: isEqualString left: value: simple: modules.brand iscontext: true right: value: simple: SplunkPy - - operator: isEqualString left: value: simple: modules.state iscontext: true right: value: simple: active iscontext: true - - operator: isEqualString left: value: complex: root: inputs.RunWebshellsQuery iscontext: true right: value: simple: "True" ignorecase: true - - operator: isNotEmpty left: value: complex: root: inputs.SplunkWebshellsQuery iscontext: true - label: "No" condition: - - operator: isExists left: value: complex: root: modules filters: - - operator: inList left: value: simple: modules.brand iscontext: true right: value: simple: Qradar,Qradar_V2 - - operator: isEqualString left: value: simple: modules.state iscontext: true right: value: simple: active iscontext: true view: |- { "position": { "x": 990, "y": 760 } } note: false timertriggers: [] ignoreworker: false skipunavailable: true quietmode: 0 view: |- { "linkLabelsPosition": { "15_18_#default#": 0.77, "16_13_yes": 0.48, "16_14_#default#": 0.11, "20_22_No": 0.64, "31_14_No": 0.26, "38_14_No": 0.25, "38_33_#default#": 0.76 }, "paper": { "dimensions": { "height": 3065, "width": 4120, "x": -1270, "y": -270 } } } inputs: - key: Related_Hashes value: simple: 06c56bd272b19bf7d7207443693cd1fc774408c4ca56744577b11fee550c23f7,64c87520565165ac95b74d6450b3ab8379544933dd3e2f2c4dc9b03a3ec570a7,1322340356018696d853e0ac6f7ce3a2,09956753b5000061524d204000000001,88170125598a4fb801102ad56494a773895059ac8550a983fdd2ef429653f079,9f6ac39707822d243445e30d27b8404466aa69c61119d5308785bf4a464a9ebd,325d6d60e24c7cfc3a782839d85ce08c8d3bb27c,1ab50b77dd9515f6cd9ed07d1d3176ba4627a292dc4a21b16ac9d211353818bd,1741dc0a491fcc8d078220ac9628152668d3370b92a8eae258e34ba28c6473b9,cd09ec795a8f4b6ced003500a44d810f49943514e2f92c81ab96c33e1c0fbd68,d72daafedf41d484f7f9816f7f076a9249a6808f1899649b7daa22c0447bb37b,c9b323b9747659eac25cec078895d75f016e26a8b5858567c7fb945b7321722c,2610d0372e0e107053bc001d278ef71f08562e5610691f18b978123c499a74d8,c774eca633136de35c9d2cd339a3b5d29f00f761657ea2aa438de4f33e4bbba4,224b7c45cf6fe4547d3ea66a12c30f3cb4c601b0a80744154697094e73dbd450,78d7c7c9f800f6824f63a99d935a4ad0112f97953d8c100deb29dae24d7da282,1d3ab04e21cfd40aa8d4300a359a09e3b520d39b1496be1e4bc91ae1f6730ecc,133631957d41eed9496ac2774793283ce26f8772de226e7f520d26667b51481a,68743e17f393d1f85ee937dffacc91e081b5f6f43477111ac96aa9d44826e4d2,7fa71a7f76ef63465cfeacf58217e0b66fc71bc81d37c44380a6f572b8a3ec7a,f2b1bd703c3eb05541ff84ec375573cbdc70309ccb82aac04b72db205d718e90,a1dcdf62aafc36dd8cf64774dea80d79fb4e24ba2a82adf4d944d9186acd1cc1,e63ab6f82c711e4ecc8f5b36046eb7ea216f41eb90158165b82a6c90560ea415,b2350954b9484ae4eac42b95fae6edf7a126169d0b93d79f49d36c5e6497062a,b1c2368773259fbfef425e0bb716be958faa7e74b3282138059f511011d3afd9,b990f79ce80c24625c97810cb8f161eafdcb10f1b8d9d538df4ca9be387c35e4,168976797d5af7071df257e91fcc31ce1d6e59c72ca9e2f50c8b5b3177ad83cc,4c5555955b2e6dc55f52b0c1a3326f3d07b325b112060329c503b294208960ec,705cda7d1ace8f4adeec5502aa311620b8d6c64046a1aed2ae833e2f2835154f required: false description: The known hashes of different malware families associated with the exploitation. playbookInputQuery: - key: Related_CVEs value: simple: CVE-2019-11510, CVE-2020-8260, CVE-2020-8243, CVE-2021-22893 required: false description: The known CVEs associated with the exploitation. playbookInputQuery: - key: BlockAutomatically value: simple: "False" required: false description: |- Whether to block the indicators automatically. Default: False. playbookInputQuery: - key: QRadarWebshellsQuery value: simple: select * from events WHERE LogSourceTypeName(deviceType) = 'Pulse Secure Pulse Connect Secure' and ( UTF8(payload) LIKE '%Licenseserverproto.cgi%' or UTF8(payload) LIKE '%Secid_canceltoken.cgi%' or UTF8(payload) LIKE '%compcheckresult.cgi%' or UTF8(payload) LIKE '%Login.cgi%' or UTF8(payload) LIKE '%Healthcheck.cgi%' or UTF8(payload) LIKE '%meeting_testjs.cgi%' or UTF8(payload) LIKE '%compcheckjava.cgi%') required: false description: |- The QRadar search query used for "Hunt Activity Using QRadar". Please note that there aren't specified fields which may cause a longer run time. playbookInputQuery: - key: SplunkWebshellsQuery value: simple: index=* sourcetype=pulse:connectsecure "Licenseserverproto.cgi" OR "Secid_canceltoken.cgi" OR "compcheckresult.cgi" OR "Healthcheck.cgi" OR "meeting_testjs.cgi" OR "compcheckjava.cgi" required: false description: |- The Splunk search query used for "Hunt Activity Using Splunk". Please note that there are two specified fields: msg, message. the query will work for both field names. playbookInputQuery: - key: RunWebshellsQuery value: simple: "True" required: false description: If you would like to skip "Hunt Activity Using Splunk" OR "Hunt Activity Using Qradar" please change the value to 'False'. playbookInputQuery: - key: QRadar_MD5_Field value: {} required: false description: |- The name of the field for MD5 entries in QRadar. If not configured, QRadar Indicator Hunting may reach timeout. playbookInputQuery: - key: QRadar_SHA1_Field value: {} required: false description: |- The name of the field for SHA1 entries in QRadar. If not configured, QRadar Indicator Hunting may reach timeout. playbookInputQuery: - key: QRadar_SHA256_Field value: {} required: false description: |- The name of the field for SHA256 entries in QRadar. If not configured, QRadar Indicator Hunting may reach timeout. playbookInputQuery: - key: SplunkEarliestTime value: simple: -30d required: false description: The earliest time for the Splunk search query. playbookInputQuery: - key: SplunkLatestTime value: simple: now required: false description: The latest time for the Splunk search query. playbookInputQuery: outputs: [] tests: - No tests (auto formatted) fromversion: 6.0.0 toversion: 6.4.9