CVE-2021-40444 - MSHTML RCE
CVE-2021-4044 refers to the MSHTML engine, that has been found vulnerable to arbitrary code execution by a specially crafted Microsoft Office document or rich text format file. Mitigations: * Microsoft official patch addressing CVE-2021-40444 * Several workarounds suggested by Microsoft. Researchers have validated this attack triggered in Windows Explorer with “Preview Mode” enabled, even in just a rich-text format RTF file (not an Office file and without ActiveX). This indicates it can be exploited even without opening the file and this invalidates Microsoft’s workaround mitigation mentioned above. This playbook should be trigger manually and includes the following tasks: * Collect related known indicators from several sources. * Indicators, Files and Process creation patterns hunting using PAN-OS, Cortex XDR and SIEM products. * Block indicators automatically or manually. * Provide workarounds and detection capabilities. * Microsoft official CVE-2021-40444 patch. More information: [Microsoft MSHTML Remote Code Execution Vulnerability](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-40444) Note: This is a beta playbook, which lets you implement and test pre-release software. Since the playbook is beta, it might contain bugs. Updates to the pack during the beta phase might include non-backward compatible features. We appreciate your feedback on the quality and usability of the pack to help us identify issues, fix them, and continually improve.
CVE-2021-40444 - MSHTML RCE · 56 tasks · 6 inputs · 0 outputs
Details
| ID | CVE-2021-40444 - MSHTML RCE |
|---|---|
| From Version | 5.5.0 |
| To Version | 6.4.9 |
| Tasks | 56 |
README
CVE-2021-4044 refers to the MSHTML engine, that has been found vulnerable to arbitrary code execution by a specially crafted Microsoft Office document or rich text format file.
Mitigations:
- Microsoft official patch addressing CVE-2021-40444
- Several workarounds suggested by Microsoft.
Researchers have validated this attack triggered in Windows Explorer with “Preview Mode” enabled, even in just a rich-text format RTF file (not an Office file and without ActiveX). This indicates it can be exploited even without opening the file and this invalidates Microsoft’s workaround mitigation mentioned above.
This playbook should be trigger manually and includes the following tasks:
- Collect related known indicators from several sources.
- Indicators, Files and Process creation patterns hunting using PAN-OS, Cortex XDR and SIEM products.
- Block indicators automatically or manually.
- Provide workarounds and detection capabilities.
- Microsoft official CVE-2021-40444 patch.
More information:
Microsoft MSHTML Remote Code Execution Vulnerability
Note: This is a beta playbook, which lets you implement and test pre-release software. Since the playbook is beta, it might contain bugs. Updates to the pack during the beta phase might include non-backward compatible features. We appreciate your feedback on the quality and usability of the pack to help us identify issues, fix them, and continually improve.
Dependencies
This playbook uses the following sub-playbooks, integrations, and scripts.
Sub-playbooks
- Block Indicators - Generic v2
- Splunk Indicator Hunting
- Palo Alto Networks - Hunting And Threat Detection
- QRadar Indicator Hunting V2
- Search Endpoints By Hash - Generic V2
- Endpoint Enrichment - Generic v2.1
Integrations
This playbook does not use any integrations.
Scripts
- ParseHTMLIndicators
- http
- SearchIncidentsV2
Commands
- qradar-searches
- associateIndicatorsToIncident
- splunk-search
- linkIncidents
- closeInvestigation
- extractIndicators
- setIndicators
Playbook Inputs
| Name | Description | Default Value | Required |
|---|---|---|---|
| YaraRulesSource | The source of the Yara rules | https://github.com/Neo23x0/signature-base/blob/master/yara/expl_cve_2021_40444.yar | Optional |
| SigmaRulesSource | The source of the Sigma rules | https://github.com/SigmaHQ/sigma/blob/master/rules/windows/file_event/win_file_winword_cve_2021_40444.yml | Optional |
| SplunkEarliestTime | The earliest time for the Splunk search query. | -7d | Optional |
| SplunkLatestTime | The latest time for the Splunk search query. | now | Optional |
| BlockIndicatorsAutomatically | Whether to automatically block the indicators involved. | False | Optional |
| EDLDomainBlocklist | The name of the EDL Domain Block List. | Demisto Remediation - Domain EDL | Optional |
| QRadarTimeRange | The time range for the QRadar search query. | LAST 7 DAYS | Optional |
Playbook Outputs
There are no outputs for this playbook.
Playbook Image

Inputs
YaraRulesSource— The source of the Yara rulesSigmaRulesSource— The source of the Sigma rulesSplunkEarliestTime— The earliest time for the Splunk search query.SplunkLatestTime— The latest time for the Splunk search query.BlockIndicatorsAutomatically— Whether to automatically block the indicators involved.QRadarTimeRange— The time range for the QRadar search query.
Commands used
associateIndicatorsToIncident
closeInvestigation
extractIndicators
linkIncidents
qradar-searches
setIndicators
splunk-search
Flowchart
id: CVE-2021-40444 - MSHTML RCE version: -1 contentitemexportablefields: contentitemfields: {} name: CVE-2021-40444 - MSHTML RCE description: "CVE-2021-4044 refers to the MSHTML engine, that has been found vulnerable to arbitrary code execution by a specially crafted Microsoft Office document or rich text format file. \n\nMitigations:\n* Microsoft official patch addressing CVE-2021-40444 \n* Several workarounds suggested by Microsoft.\n\nResearchers have validated this attack triggered in Windows Explorer with “Preview Mode” enabled, even in just a rich-text format RTF file (not an Office file and without ActiveX). This indicates it can be exploited even without opening the file and this invalidates Microsoft’s workaround mitigation mentioned above.\n\nThis playbook should be trigger manually and includes the following tasks: \n\n* Collect related known indicators from several sources.\n* Indicators, Files and Process creation patterns hunting using PAN-OS, Cortex XDR and SIEM products.\n* Block indicators automatically or manually.\n* Provide workarounds and detection capabilities.\n* Microsoft official CVE-2021-40444 patch.\n\nMore information:\n[Microsoft MSHTML Remote Code Execution Vulnerability](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-40444)\n\nNote: This is a beta playbook, which lets you implement and test pre-release software. Since the playbook is beta, it might contain bugs. Updates to the pack during the beta phase might include non-backward compatible features. We appreciate your feedback on the quality and usability of the pack to help us identify issues, fix them, and continually improve.\n" starttaskid: "0" tasks: "0": id: "0" taskid: d9491876-263a-477a-8475-91403cac3b49 type: start task: id: d9491876-263a-477a-8475-91403cac3b49 version: -1 name: "" iscommand: false brand: "" description: '' nexttasks: '#none#': - "1" separatecontext: false continueonerrortype: "" view: |- { "position": { "x": 450, "y": 210 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "1": id: "1" taskid: 798307f4-2509-4219-8b8c-a2eb7f15dd7e type: title task: id: 798307f4-2509-4219-8b8c-a2eb7f15dd7e version: -1 name: Collect Indicators type: title iscommand: false brand: "" description: '' nexttasks: '#none#': - "2" - "3" - "6" - "7" separatecontext: false continueonerrortype: "" view: |- { "position": { "x": 450, "y": 390 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "2": id: "2" taskid: 16746ed3-7c08-4dd7-8f6f-a6c95efd16f3 type: regular task: id: 16746ed3-7c08-4dd7-8f6f-a6c95efd16f3 version: -1 name: Collect indicators from HUNTRESS description: This script will extract indicators from HTML and will handle bad TLD to avoid file extensions false positives. scriptName: ParseHTMLIndicators type: regular iscommand: false brand: "" nexttasks: '#none#': - "4" scriptarguments: unescape_domain: simple: "False" url: simple: https://www.huntress.com/blog/cybersecurity-advisory-hackers-are-exploiting-cve-2021-40444 separatecontext: false continueonerror: true continueonerrortype: "" view: |- { "position": { "x": 680, "y": 550 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "3": id: "3" taskid: 75903636-13f3-4075-8bb3-f3b9a218deb7 type: regular task: id: 75903636-13f3-4075-8bb3-f3b9a218deb7 version: -1 name: Collect indicators from Picussecurity description: This script will extract indicators from HTML and will handle bad TLD to avoid file extensions false positives. scriptName: ParseHTMLIndicators type: regular iscommand: false brand: "" nexttasks: '#none#': - "4" scriptarguments: unescape_domain: simple: "True" url: simple: https://www.picussecurity.com/resource/blog/simulating-microsoft-mshtml-cve-2021-40444-zero-day-exploit separatecontext: false continueonerror: true continueonerrortype: "" view: |- { "position": { "x": 1130, "y": 550 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "4": id: "4" taskid: 473a14c9-e496-43a6-82ab-145a06e6d53e type: title task: id: 473a14c9-e496-43a6-82ab-145a06e6d53e version: -1 name: Extract Indicators type: title iscommand: false brand: "" description: '' nexttasks: '#none#': - "5" separatecontext: false continueonerrortype: "" view: |- { "position": { "x": 450, "y": 750 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "5": id: "5" taskid: 6a0bb4c9-2fd7-4652-880f-b0862bdac364 type: regular task: id: 6a0bb4c9-2fd7-4652-880f-b0862bdac364 version: -1 name: Extract Indicators From Data Collected description: commands.local.cmd.extract.indicators script: Builtin|||extractIndicators type: regular iscommand: true brand: Builtin nexttasks: '#none#': - "8" scriptarguments: text: complex: root: http.parsedBlog accessor: indicators separatecontext: false continueonerror: true continueonerrortype: "" view: |- { "position": { "x": 450, "y": 910 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "6": id: "6" taskid: 61b5267b-6383-4ea3-88d7-49b456ea337e type: regular task: id: 61b5267b-6383-4ea3-88d7-49b456ea337e version: -1 name: Download Yara Rules description: Download Yara Rules scriptName: http type: regular iscommand: false brand: "" nexttasks: '#none#': - "4" scriptarguments: filename: simple: YaraRules.yar method: simple: GET saveAsFile: simple: "yes" url: complex: root: inputs.YaraRulesSource separatecontext: false continueonerrortype: "" view: |- { "position": { "x": 220, "y": 550 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "7": id: "7" taskid: d58ba3ce-5712-4767-8c17-4f4a9f6c3f3b type: regular task: id: d58ba3ce-5712-4767-8c17-4f4a9f6c3f3b version: -1 name: Download Sigma Rules description: Download Sigma Rules scriptName: http type: regular iscommand: false brand: "" nexttasks: '#none#': - "4" scriptarguments: filename: simple: SigmaRules.yml method: simple: GET saveAsFile: simple: "yes" url: complex: root: inputs.SigmaRulesSource separatecontext: false continueonerrortype: "" view: |- { "position": { "x": -240, "y": 550 } } note: false timertriggers: [] ignoreworker: false skipunavailable: true quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "8": id: "8" taskid: 73873cf8-7144-42cf-8447-d4d27857b163 type: title task: id: 73873cf8-7144-42cf-8447-d4d27857b163 version: -1 name: Tag and Link Indicators type: title iscommand: false brand: "" description: '' nexttasks: '#none#': - "9" - "10" - "11" - "16" - "12" separatecontext: false continueonerrortype: "" view: |- { "position": { "x": 450, "y": 1120 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "9": id: "9" taskid: 7abac14d-7446-44d1-8947-1cad4db9ef75 type: regular task: id: 7abac14d-7446-44d1-8947-1cad4db9ef75 version: -1 name: Tag File indicators description: commands.local.cmd.set.indicators script: Builtin|||setIndicators type: regular iscommand: true brand: Builtin nexttasks: '#none#': - "41" scriptarguments: indicatorsValues: complex: root: ExtractedIndicators accessor: File transformers: - operator: uniq retry-count: simple: "3" retry-interval: simple: "2" tags: simple: CVE-2021-40444 separatecontext: false continueonerrortype: "" view: |- { "position": { "x": 1330, "y": 1310 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "10": id: "10" taskid: 325d9ade-cdc1-431f-842b-900f7e62d26f type: regular task: id: 325d9ade-cdc1-431f-842b-900f7e62d26f version: -1 name: Tag IP indicators description: commands.local.cmd.set.indicators script: Builtin|||setIndicators type: regular iscommand: true brand: Builtin nexttasks: '#none#': - "41" scriptarguments: indicatorsValues: complex: root: ExtractedIndicators accessor: IP transformers: - operator: uniq retry-count: simple: "3" retry-interval: simple: "2" tags: simple: CVE-2021-40444 separatecontext: false continueonerrortype: "" view: |- { "position": { "x": 870, "y": 1310 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "11": id: "11" taskid: fa4fc38b-789e-4e2e-8007-5e8b3f07abfb type: regular task: id: fa4fc38b-789e-4e2e-8007-5e8b3f07abfb version: -1 name: Tag Domain indicators description: commands.local.cmd.set.indicators script: Builtin|||setIndicators type: regular iscommand: true brand: Builtin nexttasks: '#none#': - "41" scriptarguments: indicatorsValues: complex: root: ExtractedIndicators accessor: Domain transformers: - operator: uniq retry-count: simple: "3" retry-interval: simple: "2" tags: simple: CVE-2021-40444 separatecontext: false continueonerrortype: "" view: |- { "position": { "x": 30, "y": 1310 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "12": id: "12" taskid: 79a6f066-6868-4b3d-8e5a-25d509fda412 type: regular task: id: 79a6f066-6868-4b3d-8e5a-25d509fda412 version: -1 name: Tag URL indicators description: commands.local.cmd.set.indicators script: Builtin|||setIndicators type: regular iscommand: true brand: Builtin nexttasks: '#none#': - "41" scriptarguments: indicatorsValues: complex: root: ExtractedIndicators accessor: URL transformers: - operator: uniq retry-count: simple: "3" retry-interval: simple: "2" tags: simple: CVE-2021-40444 separatecontext: false continueonerrortype: "" view: |- { "position": { "x": -420, "y": 1310 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "16": id: "16" taskid: 4c87bc95-376f-45a5-89df-7982fb85b9fe type: regular task: id: 4c87bc95-376f-45a5-89df-7982fb85b9fe version: -1 name: Link Indicators To Incident description: commands.local.cmd.associate.indicators script: Builtin|||associateIndicatorsToIncident type: regular iscommand: true brand: Builtin nexttasks: '#none#': - "41" scriptarguments: incidentId: complex: root: incident accessor: id indicatorsValues: complex: root: ExtractedIndicators.IP filters: - - operator: isNotEmpty left: value: simple: ExtractedIndicators.IP iscontext: true transformers: - operator: append args: item: value: simple: ExtractedIndicators.Domain iscontext: true - operator: append args: item: value: simple: ExtractedIndicators.URL iscontext: true - operator: append args: item: value: simple: ExtractedIndicators.CVE iscontext: true - operator: append args: item: value: simple: ExtractedIndicators.File iscontext: true separatecontext: false continueonerrortype: "" view: |- { "position": { "x": 450, "y": 1310 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "17": id: "17" taskid: 5e235ae1-6cd0-4a41-87e3-e62f070ad5d8 type: title task: id: 5e235ae1-6cd0-4a41-87e3-e62f070ad5d8 version: -1 name: SIEM Hunting type: title iscommand: false brand: "" description: '' nexttasks: '#none#': - "20" - "21" separatecontext: false continueonerrortype: "" view: |- { "position": { "x": -410, "y": 1720 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "18": id: "18" taskid: 344ec931-c791-43d3-86f8-4ca2c945093f type: title task: id: 344ec931-c791-43d3-86f8-4ca2c945093f version: -1 name: Palo Alto Networks Hunting type: title iscommand: false brand: "" description: '' nexttasks: '#none#': - "19" separatecontext: false continueonerrortype: "" view: |- { "position": { "x": 450, "y": 1720 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "19": id: "19" taskid: ffbdaaaa-fac0-456c-8250-ddaa71b209ef type: playbook task: id: ffbdaaaa-fac0-456c-8250-ddaa71b209ef version: -1 name: Palo Alto Networks - Hunting And Threat Detection description: "This is a multipurpose playbook used for hunting and threat detection. The playbook receives inputs based on hashes, IP addresses, or domain names provided manually or from outputs by other playbooks. \nWith the received indicators, the playbook leverages data received by PANW products including, Cortex Data Lake, Autofocus and Pan-OS to search for IP addresses, host names and users related to the provided indicators.\nThe output provided by the playbook facilitates pivoting searches for possibly affected IP addresses or users." playbookName: Palo Alto Networks - Hunting And Threat Detection type: playbook iscommand: false brand: "" nexttasks: '#none#': - "48" scriptarguments: IPAddresses: complex: root: ExtractedIndicators accessor: IP MD5: complex: root: ExtractedIndicators.File filters: - - operator: stringHasLength left: value: simple: ExtractedIndicators.File iscontext: true right: value: simple: "32" transformers: - operator: uniq SHA1: complex: root: ExtractedIndicators.File filters: - - operator: stringHasLength left: value: simple: ExtractedIndicators.File iscontext: true right: value: simple: "40" transformers: - operator: uniq SHA256: complex: root: ExtractedIndicators.File filters: - - operator: stringHasLength left: value: simple: ExtractedIndicators.File iscontext: true right: value: simple: "64" transformers: - operator: uniq URLDomain: complex: root: ExtractedIndicators accessor: Domain transformers: - operator: uniq separatecontext: true continueonerrortype: "" loop: iscommand: false scriptArguments: IPAddresses: complex: root: ExtractedIndicators accessor: IP MD5: complex: root: ExtractedIndicators.File filters: - - operator: hasLength left: value: simple: ExtractedIndicators.File iscontext: true right: value: simple: "32" transformers: - operator: uniq SHA1: complex: root: ExtractedIndicators.File filters: - - operator: hasLength left: value: simple: ExtractedIndicators.File iscontext: true right: value: simple: "40" transformers: - operator: uniq SHA256: complex: root: ExtractedIndicators.File filters: - - operator: hasLength left: value: simple: ExtractedIndicators.File iscontext: true right: value: simple: "64" transformers: - operator: uniq URLDomain: complex: root: ExtractedIndicators accessor: Domain transformers: - operator: uniq - operator: slice args: from: value: simple: "0" to: value: simple: "50" exitCondition: "" wait: 1 max: 100 view: |- { "position": { "x": 450, "y": 1880 } } note: false timertriggers: [] ignoreworker: false skipunavailable: true quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "20": id: "20" taskid: 27deb938-34b9-4b3c-86c7-1ad6186b053a type: playbook task: id: 27deb938-34b9-4b3c-86c7-1ad6186b053a version: -1 name: Splunk Indicator Hunting description: This playbook queries Splunk for indicators such as file hashes, IP addresses, domains, or urls. It outputs detected users, ip addresses, and hostnames related to the indicators. playbookName: Splunk Indicator Hunting type: playbook iscommand: false brand: "" nexttasks: '#none#': - "48" scriptarguments: IPAddress: complex: root: ExtractedIndicators accessor: IP transformers: - operator: uniq IndexName: simple: index=* MD5: complex: root: ExtractedIndicators filters: - - operator: stringHasLength left: value: simple: ExtractedIndicators iscontext: true right: value: simple: "32" accessor: File transformers: - operator: uniq SHA1: complex: root: ExtractedIndicators filters: - - operator: stringHasLength left: value: simple: ExtractedIndicators iscontext: true right: value: simple: "40" accessor: File transformers: - operator: uniq SHA256: complex: root: ExtractedIndicators filters: - - operator: stringHasLength left: value: simple: ExtractedIndicators iscontext: true right: value: simple: "64" accessor: File transformers: - operator: uniq SelectFields: simple: source,timestamp URLDomain: complex: root: ExtractedIndicators accessor: Domain transformers: - operator: uniq earliest_time: complex: root: inputs.SplunkEarliestTime event_limit: simple: "100" latest_time: complex: root: inputs.SplunkLatestTime separatecontext: false continueonerrortype: "" loop: iscommand: false scriptArguments: IPAddress: complex: root: ExtractedIndicators accessor: IP transformers: - operator: uniq IndexName: simple: index=* MD5: complex: root: ExtractedIndicators filters: - - operator: hasLength left: value: simple: ExtractedIndicators iscontext: true right: value: simple: "32" accessor: File transformers: - operator: uniq SHA1: complex: root: ExtractedIndicators filters: - - operator: hasLength left: value: simple: ExtractedIndicators iscontext: true right: value: simple: "40" accessor: File transformers: - operator: uniq SHA256: complex: root: ExtractedIndicators filters: - - operator: hasLength left: value: simple: ExtractedIndicators iscontext: true right: value: simple: "64" accessor: File transformers: - operator: uniq SelectFields: simple: source,timestamp URLDomain: complex: root: ExtractedIndicators accessor: Domain transformers: - operator: uniq earliest_time: complex: root: inputs.SplunkEarliestTime event_limit: simple: "100" latest_time: complex: root: inputs.SplunkLatestTime exitCondition: "" wait: 1 max: 100 view: |- { "position": { "x": -180, "y": 1880 } } note: false timertriggers: [] ignoreworker: false skipunavailable: true quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "21": id: "21" taskid: 052c6d5c-c523-4dc2-8bb7-18d2715e1df4 type: playbook task: id: 052c6d5c-c523-4dc2-8bb7-18d2715e1df4 version: -1 name: QRadar Indicator Hunting V2 description: 'The Playbook queries QRadar SIEM for indicators such as file hashes, IP addresses, domains, or urls. ' playbookName: QRadar Indicator Hunting V2 type: playbook iscommand: false brand: "" nexttasks: '#none#': - "48" scriptarguments: IPAddress: complex: root: ExtractedIndicators accessor: IP transformers: - operator: uniq InvestigationIPFields: simple: sourceip,destinationip InvestigationUserFields: simple: username MD5: complex: root: ExtractedIndicators.File filters: - - operator: stringHasLength left: value: simple: ExtractedIndicators.File iscontext: true right: value: simple: "32" transformers: - operator: uniq QradarIPfield: simple: sourceip,destinationip SHA1: complex: root: ExtractedIndicators.File filters: - - operator: stringHasLength left: value: simple: ExtractedIndicators.File iscontext: true right: value: simple: "40" transformers: - operator: uniq SHA256: complex: root: ExtractedIndicators.File filters: - - operator: stringHasLength left: value: simple: ExtractedIndicators.File iscontext: true right: value: simple: "64" transformers: - operator: uniq TimeFrame: complex: root: inputs.QRadarTimeRange URLDomain: complex: root: ExtractedIndicators accessor: Domain transformers: - operator: uniq separatecontext: true continueonerrortype: "" loop: iscommand: false scriptArguments: IPAddress: complex: root: ExtractedIndicators accessor: IP transformers: - operator: uniq InvestigationIPFields: simple: sourceip,destinationip InvestigationUserFields: simple: username MD5: complex: root: ExtractedIndicators filters: - - operator: hasLength left: value: simple: ExtractedIndicators iscontext: true right: value: simple: "32" accessor: File transformers: - operator: uniq QradarIPfield: simple: sourceip,destinationip SHA1: complex: root: ExtractedIndicators filters: - - operator: hasLength left: value: simple: ExtractedIndicators iscontext: true right: value: simple: "40" accessor: File transformers: - operator: uniq SHA256: complex: root: ExtractedIndicators filters: - - operator: hasLength left: value: simple: ExtractedIndicators iscontext: true right: value: simple: "64" accessor: File transformers: - operator: uniq URLDomain: complex: root: ExtractedIndicators accessor: Domain transformers: - operator: uniq - operator: slice args: from: value: simple: "0" to: value: simple: "50" exitCondition: "" wait: 1 max: 100 view: |- { "position": { "x": -640, "y": 1880 } } note: false timertriggers: [] ignoreworker: false skipunavailable: true quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "22": id: "22" taskid: 80a68fb3-1afc-438f-81b7-b16b923ff31f type: playbook task: id: 80a68fb3-1afc-438f-81b7-b16b923ff31f version: -1 name: Search Endpoints By Hash - Generic V2 description: Hunt using available tools playbookName: Search Endpoints By Hash - Generic V2 type: playbook iscommand: false brand: "" nexttasks: '#none#': - "39" scriptarguments: MD5Hash: complex: root: ExtractedIndicators.File filters: - - operator: hasLength left: value: simple: ExtractedIndicators.File iscontext: true right: value: simple: "32" transformers: - operator: uniq - operator: append args: item: value: simple: db349b97c37d22f5ea1d1841e3c89eb4 SHA1Hash: complex: root: ExtractedIndicators.File filters: - - operator: hasLength left: value: simple: ExtractedIndicators.File iscontext: true right: value: simple: "40" transformers: - operator: uniq SHA256Hash: complex: root: ExtractedIndicators.File filters: - - operator: hasLength left: value: simple: ExtractedIndicators.File iscontext: true right: value: simple: "64" transformers: - operator: uniq separatecontext: false continueonerrortype: "" view: |- { "position": { "x": 2190, "y": 1870 } } note: false timertriggers: [] ignoreworker: false skipunavailable: true quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "23": id: "23" taskid: 55c97f5e-8265-4abd-8047-38d5c879f903 type: title task: id: 55c97f5e-8265-4abd-8047-38d5c879f903 version: -1 name: Hunting For Endpoint IoCs type: title iscommand: false brand: "" description: '' nexttasks: '#none#': - "22" separatecontext: false continueonerrortype: "" view: |- { "position": { "x": 2190, "y": 1720 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "24": id: "24" taskid: 73ec3b28-2a92-4b51-85dd-bf8917c55f53 type: regular task: id: 73ec3b28-2a92-4b51-85dd-bf8917c55f53 version: -1 name: 'Search XDR incidents for CVE-2021-40444 related behavior ' description: Search XDR incidents for MSHTML Remote Code Execution related behaviour. scriptName: SearchIncidentsV2 type: regular iscommand: false brand: "" nexttasks: '#none#': - "71" scriptarguments: query: simple: 'xdralerts.name:"bioc.cve_2021_40444" OR xdralerts.description: *bioc.cve_2021_40444* OR xdralerts.description: *bioc.cve_2021_40444.3* OR xdralerts.name: *bioc.cve_2021_40444.3*' separatecontext: false continueonerrortype: "" view: |- { "position": { "x": 1160, "y": 2140 } } note: false timertriggers: [] ignoreworker: false skipunavailable: true quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "25": id: "25" taskid: 425ad867-0c52-4569-83a7-e45e456bcfbb type: condition task: id: 425ad867-0c52-4569-83a7-e45e456bcfbb version: -1 name: 'Is Cortex XDR enabled? ' description: Checks if the Cortex XDR instance is enabled. type: condition iscommand: false brand: "" nexttasks: '#default#': - "48" "yes": - "24" separatecontext: false conditions: - label: "yes" condition: - - operator: isEqualString left: value: complex: root: modules filters: - - operator: isEqualString left: value: simple: modules.brand iscontext: true right: value: simple: Cortex XDR - IR accessor: state iscontext: true right: value: simple: active ignorecase: true continueonerrortype: "" view: |- { "position": { "x": 1160, "y": 1870 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "28": id: "28" taskid: 154ca692-c715-4c09-8123-4976239ae26f type: title task: id: 154ca692-c715-4c09-8123-4976239ae26f version: -1 name: SIEM Advanced Hunting type: title iscommand: false brand: "" description: '' nexttasks: '#none#': - "30" - "43" separatecontext: false continueonerrortype: "" view: |- { "position": { "x": -1420, "y": 1720 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "30": id: "30" taskid: ac59b63e-9057-4337-8107-01ec2d2945cc type: condition task: id: ac59b63e-9057-4337-8107-01ec2d2945cc version: -1 name: Is Splunk Enabled? description: Check if Splunk instance is enabled. type: condition iscommand: false brand: "" nexttasks: '#default#': - "48" "Yes": - "45" separatecontext: false conditions: - label: "Yes" condition: - - operator: isExists left: value: complex: root: modules filters: - - operator: isEqualString left: value: simple: modules.brand iscontext: true right: value: simple: SplunkPy - - operator: isEqualString left: value: simple: modules.state iscontext: true right: value: simple: active iscontext: true continueonerrortype: "" view: |- { "position": { "x": -1180, "y": 1870 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "39": id: "39" taskid: 1ff6936a-e271-4603-82cf-4374a541a555 type: playbook task: id: 1ff6936a-e271-4603-82cf-4374a541a555 version: -1 name: Endpoint Enrichment - Generic v2.1 description: |- Enrich an endpoint by hostname using one or more integrations. Supported integrations: - Active Directory Query v2 - McAfee ePolicy Orchestrator - Carbon Black Enterprise Response v2 - Cylance Protect v2 - CrowdStrike Falcon Host - ExtraHop Reveal(x) playbookName: Endpoint Enrichment - Generic v2.1 type: playbook iscommand: false brand: "" nexttasks: '#none#': - "48" scriptarguments: Hostname: complex: root: Endpoint accessor: Hostname transformers: - operator: uniq separatecontext: true continueonerrortype: "" loop: iscommand: false scriptArguments: Hostname: complex: root: Endpoint accessor: Hostname transformers: - operator: uniq exitCondition: "" wait: 1 max: 0 view: |- { "position": { "x": 2190, "y": 2140 } } note: false timertriggers: [] ignoreworker: false skipunavailable: true quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "41": id: "41" taskid: db2922d3-5c1b-40b8-8302-b23a7c13b7ac type: title task: id: db2922d3-5c1b-40b8-8302-b23a7c13b7ac version: -1 name: Threat Hunting type: title iscommand: false brand: "" description: '' nexttasks: '#none#': - "18" - "23" - "28" - "17" - "42" - "69" separatecontext: false continueonerrortype: "" view: |- { "position": { "x": 450, "y": 1550 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "42": id: "42" taskid: 0ebd72d0-7dd6-4877-820b-e8aba5bf8e2c type: title task: id: 0ebd72d0-7dd6-4877-820b-e8aba5bf8e2c version: -1 name: Hunting Cortex XDR Signatures type: title iscommand: false brand: "" description: '' nexttasks: '#none#': - "25" separatecontext: false continueonerrortype: "" view: |- { "position": { "x": 1160, "y": 1720 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "43": id: "43" taskid: 56939041-875d-440a-8642-17a7a6e5401b type: condition task: id: 56939041-875d-440a-8642-17a7a6e5401b version: -1 name: Is QRadar Enabled? description: Check if Splunk instance is enabled. type: condition iscommand: false brand: "" nexttasks: '#default#': - "48" "Yes": - "44" separatecontext: false conditions: - label: "Yes" condition: - - operator: isExists left: value: complex: root: modules filters: - - operator: isEqualString left: value: simple: modules.brand iscontext: true right: value: simple: QRadar_v2 - - operator: isEqualString left: value: simple: modules.state iscontext: true right: value: simple: active iscontext: true continueonerrortype: "" view: |- { "position": { "x": -1650, "y": 1870 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "44": id: "44" taskid: 30e47296-6d53-4814-8110-305870649d1c type: regular task: id: 30e47296-6d53-4814-8110-305870649d1c version: -1 name: Search for suspicious file creation under INETCACHE description: Searches QRadar for suspicious file creation where the file path is under INETCACHE. script: '|||qradar-searches' type: regular iscommand: true brand: "" nexttasks: '#none#': - "47" scriptarguments: query_expression: simple: SELECT UTF8(payload) as search_payload, "Filename" from events where LOGSOURCETYPENAME(devicetype)='Microsoft Windows Security Event Log' and (CATEGORYNAME(category) ILIKE 'File Created' or CATEGORYNAME(category) ILIKE 'Successful File Modification') and UTF8(payload) ILIKE '%\winword.exe' and "Filename" ilike '%\Windows\INetCache%' and "Filename" ilike '%.cab' ${inputs.QRadarTimeRange} separatecontext: false continueonerrortype: "" view: |- { "position": { "x": -1650, "y": 2140 } } note: false timertriggers: [] ignoreworker: false skipunavailable: true quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "45": id: "45" taskid: 30031679-a6d2-4904-824c-1428ef514dff type: regular task: id: 30031679-a6d2-4904-824c-1428ef514dff version: -1 name: Search for suspicious file creation under INETCACHE description: Searches Splunk for suspicious file creation where the file path is under INETCACHE. script: '|||splunk-search' type: regular iscommand: true brand: "" nexttasks: '#none#': - "46" scriptarguments: earliest_time: complex: root: inputs.SplunkEarliestTime query: simple: index=* (Image="\\winword.exe" TargetFilename="*\\Windows\\INetCache*" TargetFilename="*.cab") | table TargetFilename separatecontext: false continueonerrortype: "" view: |- { "position": { "x": -1180, "y": 2140 } } note: false timertriggers: [] ignoreworker: false skipunavailable: true quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "46": id: "46" taskid: 76b52ade-1b84-47f0-8914-181232c6c75a type: regular task: id: 76b52ade-1b84-47f0-8914-181232c6c75a version: -1 name: Search for suspicious process creation pattern description: Searches Splunk for suspicious process creation patterns. script: '|||splunk-search' type: regular iscommand: true brand: "" nexttasks: '#none#': - "48" scriptarguments: earliest_time: complex: root: inputs.SplunkEarliestTime query: simple: index=* ((Image="*\\control.exe" (ParentImage="*\\winword.exe" OR ParentImage="*\\powerpnt.exe" OR ParentImage="*\\excel.exe")) NOT (CommandLine="*\\control.exe input.dll")) separatecontext: false continueonerrortype: "" view: |- { "position": { "x": -1180, "y": 2340 } } note: false timertriggers: [] ignoreworker: false skipunavailable: true quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "47": id: "47" taskid: cd97b6d2-c2b6-4440-81f8-cb0ef555c03c type: regular task: id: cd97b6d2-c2b6-4440-81f8-cb0ef555c03c version: -1 name: Search for suspicious process creation pattern description: Searches QRadar for suspicious process creation patterns. script: '|||qradar-searches' type: regular iscommand: true brand: "" nexttasks: '#none#': - "48" scriptarguments: query_expression: simple: SELECT UTF8(payload) as search_payload from events where LOGSOURCETYPENAME(devicetype)='Microsoft Windows Security Event Log' and (UTF8(payload) ILIKE '%\control.exe' and (UTF8(payload) ILIKE '%\winword.exe' or UTF8(payload) ILIKE '%\powerpnt.exe' or UTF8(payload) ILIKE '%\excel.exe')) and UTF8(payload) NOT ILIKE '%\control.exe input.dll' LAST 7 DAYS separatecontext: false continueonerrortype: "" view: |- { "position": { "x": -1650, "y": 2340 } } note: false timertriggers: [] ignoreworker: false skipunavailable: true quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "48": id: "48" taskid: 2f5be5bc-e4b2-4081-8d80-c1e0cac4a100 type: title task: id: 2f5be5bc-e4b2-4081-8d80-c1e0cac4a100 version: -1 name: Remediation type: title iscommand: false brand: "" description: '' nexttasks: '#none#': - "50" separatecontext: false continueonerrortype: "" view: |- { "position": { "x": 450, "y": 2730 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "50": id: "50" taskid: 06bc0669-6bc8-44c2-8247-548d16d958f8 type: condition task: id: 06bc0669-6bc8-44c2-8247-548d16d958f8 version: -1 name: Block indicators automatically? description: Checks whether IOCs associated with the incident can be blocked automatically. type: condition iscommand: false brand: "" nexttasks: '#default#': - "51" "yes": - "74" separatecontext: false conditions: - label: "yes" condition: - - operator: isEqualString left: value: complex: root: inputs.BlockIndicatorsAutomatically iscontext: true right: value: simple: "True" ignorecase: true continueonerrortype: "" view: |- { "position": { "x": 450, "y": 2910 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "51": id: "51" taskid: eee4033d-5f33-4c4d-853a-ba1146aeb977 type: regular task: id: eee4033d-5f33-4c4d-853a-ba1146aeb977 version: -1 name: Block indicators manually description: Manually block the IOCs in the relevant systems. type: regular iscommand: false brand: "" nexttasks: '#none#': - "67" separatecontext: false continueonerrortype: "" view: |- { "position": { "x": 660, "y": 3120 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "53": id: "53" taskid: f9ba804c-5f2d-4c36-80f2-bfb5309784a0 type: regular task: id: f9ba804c-5f2d-4c36-80f2-bfb5309784a0 version: -1 name: Deploy YARA rules description: Yara rules file has been downloaded as YaraRules.yar and is available for download directly from XSOAR. type: regular iscommand: false brand: "" nexttasks: '#none#': - "58" separatecontext: false continueonerrortype: "" view: |- { "position": { "x": 0, "y": 3660 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "54": id: "54" taskid: a3830206-f5dd-4cf8-818e-dee982caf6ce type: regular task: id: a3830206-f5dd-4cf8-818e-dee982caf6ce version: -1 name: Deploy Sigma rules description: Sigma rules file has been downloaded as SigmaRules.yml and is available for download directly from XSOAR. type: regular iscommand: false brand: "" nexttasks: '#none#': - "58" separatecontext: false continueonerrortype: "" view: |- { "position": { "x": -440, "y": 3660 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "57": id: "57" taskid: cc1451e0-5217-42fc-864c-e28175c43509 type: title task: id: cc1451e0-5217-42fc-864c-e28175c43509 version: -1 name: Deploy Detection Rules type: title iscommand: false brand: "" description: '' nexttasks: '#none#': - "54" - "53" separatecontext: false continueonerrortype: "" view: |- { "position": { "x": -220, "y": 3520 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "58": id: "58" taskid: 4f94be40-f923-498a-8266-2cc8918ceb19 type: title task: id: 4f94be40-f923-498a-8266-2cc8918ceb19 version: -1 name: Mitigation type: title iscommand: false brand: "" description: '' nexttasks: '#none#': - "73" separatecontext: false continueonerrortype: "" view: |- { "position": { "x": 440, "y": 3870 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "59": id: "59" taskid: 65a955a9-1419-46d4-8ca0-d8c13503f0df type: condition task: id: 65a955a9-1419-46d4-8ca0-d8c13503f0df version: -1 name: Analysis resolution - Should continue with the investigation? description: Check with the analyst whether to continue with the investigation. type: condition iscommand: false brand: "" nexttasks: "No": - "62" "Yes": - "61" separatecontext: false continueonerrortype: "" view: |- { "position": { "x": 440, "y": 4370 } } note: false timertriggers: [] ignoreworker: false message: to: subject: body: simple: Do you need to continue with the investigation? methods: [] format: "" bcc: cc: timings: retriescount: 2 retriesinterval: 360 completeafterreplies: 1 completeafterv2: false completeaftersla: false replyOptions: - "Yes" - "No" skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "60": id: "60" taskid: 66646cc6-2fdc-40f0-8a18-291a7b302d63 type: title task: id: 66646cc6-2fdc-40f0-8a18-291a7b302d63 version: -1 name: Done type: title iscommand: false brand: "" description: '' separatecontext: false continueonerrortype: "" view: |- { "position": { "x": 440, "y": 4830 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "61": id: "61" taskid: b3af0661-2286-4b07-8981-5d86ebf7b663 type: regular task: id: b3af0661-2286-4b07-8981-5d86ebf7b663 version: -1 name: Investigate Further description: Manual step for further incident investigation. type: regular iscommand: false brand: "" nexttasks: '#none#': - "60" separatecontext: false continueonerrortype: "" view: |- { "position": { "x": -10, "y": 4620 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "62": id: "62" taskid: f7c2fefe-eede-455e-821e-be63237d9685 type: regular task: id: f7c2fefe-eede-455e-821e-be63237d9685 version: -1 name: Close Investigation description: Close the current incident script: Builtin|||closeInvestigation type: regular iscommand: true brand: Builtin nexttasks: '#none#': - "60" scriptarguments: closeReason: simple: No further actions are required. separatecontext: false continueonerrortype: "" view: |- { "position": { "x": 440, "y": 4620 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "63": id: "63" taskid: babef611-e638-4cc7-80d3-1e33714640c3 type: regular task: id: babef611-e638-4cc7-80d3-1e33714640c3 version: -1 name: Disable ActiveX controls via Group Policy description: |- **To disable ActiveX controls via Group Policy** In Group Policy settings, navigate to Computer Configuration > Administrative Templates > Windows Components > Internet Explorer > Internet Control Panel > Security Page For each zone: Select the zone (Internet Zone, Intranet Zone, Local Machine Zone, or Trusted Sites Zone). Double-click Download signed ActiveX controls and Enable the policy. Then set the option in the policy to Disable. Double-click Download unsigned ActiveX controls and Enable the policy. Then set the option in the policy to Disable. We recommend applying this setting to all zones to fully protect your system. **Impact of workaround.** This sets the URLACTION_DOWNLOAD_SIGNED_ACTIVEX (0x1001) and URLACTION_DOWNLOAD_UNSIGNED_ACTIVEX (0x1004) to DISABLED (3) for all internet zones for 64-bit and 32-bit processes. New ActiveX controls will not be installed. Previously-installed ActiveX controls will continue to run. **How to undo the workaround** Set the option in the policy to Enable. type: regular iscommand: false brand: "" nexttasks: '#none#': - "58" separatecontext: false continueonerrortype: "" view: |- { "position": { "x": 440, "y": 3660 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "64": id: "64" taskid: 865b4b57-0d19-4b92-844b-2f78b7daeecc type: regular task: id: 865b4b57-0d19-4b92-844b-2f78b7daeecc version: -1 name: Disable ActiveX controls on an individual system via regkey description: "**To disable ActiveX controls on an individual system via regkey:**\n\n**Warning** If you use Registry Editor incorrectly, you may cause serious problems that may require you to reinstall your operating system. Microsoft cannot guarantee that you can solve problems that result from using Registry Editor incorrectly. Use Registry Editor at your own risk.\n\n1. To disable installing ActiveX controls in Internet Explorer in all zones, paste the \nfollowing into a text file and save it with the .reg file extension:\nWindows Registry Editor Version 5.00\n\n[HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\0]\n\"1001\"=dword:00000003\n\"1004\"=dword:00000003\n\n[HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\1]\n\"1001\"=dword:00000003\n\"1004\"=dword:00000003\n\n[HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\2]\n\"1001\"=dword:00000003\n\"1004\"=dword:00000003\n\n[HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\3]\n\"1001\"=dword:00000003\n\"1004\"=dword:00000003\n\n2. Double-click the .reg file to apply it to your Policy hive.\n3. Reboot the system to ensure the new configuration is applied.\n\n**Impact of workaround.**\n\nThis sets the URLACTION_DOWNLOAD_SIGNED_ACTIVEX (0x1001) and URLACTION_DOWNLOAD_UNSIGNED_ACTIVEX (0x1004) to DISABLED (3) for all internet zones for 64-bit and 32-bit processes. New ActiveX controls will not be installed. Previously-installed ActiveX controls will continue to run.\n\n**How to undo the workaround**\n\nDelete the registry keys that were added in implementing this workaround." type: regular iscommand: false brand: "" nexttasks: '#none#': - "58" separatecontext: false continueonerrortype: "" view: |- { "position": { "x": 870, "y": 3660 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "65": id: "65" taskid: a963ada9-2053-4c45-8917-ef591d4f02de type: regular task: id: a963ada9-2053-4c45-8917-ef591d4f02de version: -1 name: Disable preview in Windows Explore description: |- **To disable preview in Windows Explorer** Disabling Shell Preview prevents a user from previewing documents in Windows Explorer. Follow these steps for each type of document you want to prevent being previewed: In Registry Editor, navigate to the appropriate registry key: For Word documents: HKEY_CLASSES_ROOT.docx\ShellEx{8895b1c6-b41f-4c1c-a562-0d564250836f} HKEY_CLASSES_ROOT.doc\ShellEx{8895b1c6-b41f-4c1c-a562-0d564250836f} HKEY_CLASSES_ROOT.docm\ShellEx{8895b1c6-b41f-4c1c-a562-0d564250836f} For rich text files: HKEY_CLASSES_ROOT.rtf\ShellEx{8895b1c6-b41f-4c1c-a562-0d564250836f} Export a copy of the regkey for backup. Double-click Name and in the Edit String dialog box, delete the Value Data. Click OK, **Impact of workaround** Users will not be able to preview documents in Windows Explorer. **How to undo the workaround** Double-click the .reg file you created in step two of the workaround. type: regular iscommand: false brand: "" nexttasks: '#none#': - "58" separatecontext: false continueonerrortype: "" view: |- { "position": { "x": 1300, "y": 3660 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "66": id: "66" taskid: f9e53cf4-7bd4-4860-85e1-4eeeea9b87ac type: title task: id: f9e53cf4-7bd4-4860-85e1-4eeeea9b87ac version: -1 name: Deploy Microsoft Workarounds type: title iscommand: false brand: "" description: '' nexttasks: '#none#': - "63" - "64" - "65" separatecontext: false continueonerrortype: "" view: |- { "position": { "x": 870, "y": 3510 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "67": id: "67" taskid: 6d5dafba-abd4-4e0b-8990-785637634c9a type: title task: id: 6d5dafba-abd4-4e0b-8990-785637634c9a version: -1 name: Detections & Workarounds type: title iscommand: false brand: "" description: '' nexttasks: '#none#': - "66" - "57" separatecontext: false continueonerrortype: "" view: |- { "position": { "x": 450, "y": 3340 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "68": id: "68" taskid: b7569713-0b82-440a-8a6a-8576ba14e0fb type: regular task: id: b7569713-0b82-440a-8a6a-8576ba14e0fb version: -1 name: Link related incidents description: Link related Xpanse and Cortex XDR incident to Kaseya VSA incident, script: Builtin|||linkIncidents type: regular iscommand: true brand: Builtin nexttasks: '#none#': - "48" scriptarguments: linkedIncidentIDs: complex: root: foundIncidents.id filters: - - operator: isNotEmpty left: value: simple: foundIncidents.id iscontext: true separatecontext: false continueonerrortype: "" view: |- { "position": { "x": 1160, "y": 2535 } } note: false timertriggers: [] ignoreworker: false skipunavailable: true quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "69": id: "69" taskid: 4012b969-fe15-4a74-823a-7d6bdfca07af type: title task: id: 4012b969-fe15-4a74-823a-7d6bdfca07af version: -1 name: Hunting Cortex XDR XQL Queries type: title iscommand: false brand: "" description: '' nexttasks: '#none#': - "70" separatecontext: false continueonerrortype: "" view: |- { "position": { "x": 1670, "y": 1720 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "70": id: "70" taskid: 3f93a3eb-f232-49f6-8e59-60bc38f01374 type: regular task: id: 3f93a3eb-f232-49f6-8e59-60bc38f01374 version: -1 name: Look for potential CVE-2021-40444 exploitation attempts description: | **//Description: Look for potential CVE-2021-40444 exploitation attempts // Author: Ryan Tracey // Last Updated: 9/9/2021 // Version 1.1 //REF: [https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-40444](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-40444) //REF: [https://www.joesandbox.com/analysis/476188/1/html](https://www.joesandbox.com/analysis/476188/1/html) //REF: [https://twitter.com/RedDrip7/status/1435551886145310722/photo/2](https://twitter.com/RedDrip7/status/1435551886145310722/photo/2)** config case_sensitive = false timeframe=30d |dataset = xdr_data |filter actor_process_image_name in ("winword.exe","powerpnt.exe","excel.exe") and action_process_image_name = "control.exe" and action_process_image_command_line contains ".cpl:" |fields _time, agent_hostname, agent_version,actor_effective_username, actor_process_image_name, actor_process_command_line, action_process_image_name, action_process_image_command_line type: regular iscommand: false brand: "" nexttasks: '#none#': - "48" separatecontext: false continueonerrortype: "" view: |- { "position": { "x": 1670, "y": 1870 } } note: false timertriggers: [] ignoreworker: false skipunavailable: true quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "71": id: "71" taskid: d550631e-c6fe-4b1c-8242-952f320f738d type: condition task: id: d550631e-c6fe-4b1c-8242-952f320f738d version: -1 name: Are there incidents to link? description: Check for found XDR incidents in XSOAR type: condition iscommand: false brand: "" nexttasks: '#default#': - "48" "yes": - "68" separatecontext: false conditions: - label: "yes" condition: - - operator: isNotEmpty left: value: complex: root: foundIncidents accessor: id iscontext: true continueonerrortype: "" view: |- { "position": { "x": 1160, "y": 2340 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "72": id: "72" taskid: f3ee2d04-f755-4353-89f7-a8b046c7ca1f type: title task: id: f3ee2d04-f755-4353-89f7-a8b046c7ca1f version: -1 name: Resolution type: title iscommand: false brand: "" description: '' nexttasks: '#none#': - "59" separatecontext: false continueonerrortype: "" view: |- { "position": { "x": 440, "y": 4210 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "73": id: "73" taskid: c90b4a57-87eb-4367-8e56-ee35c1e92041 type: regular task: id: c90b4a57-87eb-4367-8e56-ee35c1e92041 version: -1 name: Install Microsoft official patch description: '[Microsoft patch for CVE-2021-40444](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-40444)' type: regular iscommand: false brand: "" nexttasks: '#none#': - "72" separatecontext: false continueonerrortype: "" view: |- { "position": { "x": 440, "y": 4020 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "74": id: "74" taskid: fc2083e7-a623-40ce-8b59-70c1cef97363 type: playbook task: id: fc2083e7-a623-40ce-8b59-70c1cef97363 version: -1 name: Block Indicators - Generic v3 description: |+ This playbook blocks malicious Indicators using all integrations that are enabled, using the following sub-playbooks: - Block URL - Generic v2 - Block Account - Generic v2 - Block IP - Generic v3 - Block File - Generic v2 - Block Email - Generic - Block Domain - Generic playbookName: Block Indicators - Generic v3 type: playbook iscommand: false brand: "" nexttasks: '#none#': - "67" scriptarguments: AutoBlockIndicators: complex: root: inputs.AutoBlockIndicator AutoCommit: simple: "No" CustomBlockRule: simple: "True" CustomURLCategory: simple: XSOAR Remediation - Malicious URLs IP: complex: root: ExtractedIndicators.IP transformers: - operator: uniq InputEnrichment: simple: "False" MD5: complex: root: ExtractedIndicators.File filters: - - operator: stringHasLength left: value: simple: ExtractedIndicators.File iscontext: true right: value: simple: "32" transformers: - operator: uniq RuleDirection: simple: outbound RuleName: simple: XSOAR - Block Indicators playbook - ${incident.id} SHA256: complex: root: ExtractedIndicators.File filters: - - operator: stringHasLength left: value: simple: ExtractedIndicators.File iscontext: true right: value: simple: "64" transformers: - operator: uniq URL: complex: root: ExtractedIndicators.URL transformers: - operator: uniq UserVerification: complex: root: 'inputs.UserVerification' Username: complex: root: DBotScore filters: - - operator: isEqualString left: value: simple: DBotScore.Type iscontext: true right: value: simple: username ignorecase: true - - operator: greaterThanOrEqual left: value: simple: DBotScore.Score iscontext: true right: value: simple: "3" accessor: Indicator transformers: - operator: uniq separatecontext: true continueonerrortype: "" loop: iscommand: false exitCondition: "" wait: 1 max: 100 view: |- { "position": { "x": 220, "y": 3120 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false view: |- { "linkLabelsPosition": { "25_24_yes": 0.46, "25_48_#default#": 0.21, "30_45_Yes": 0.46, "30_48_#default#": 0.12, "43_44_Yes": 0.45, "43_48_#default#": 0.1, "71_48_#default#": 0.27, "71_68_yes": 0.53 }, "paper": { "dimensions": { "height": 4685, "width": 4220, "x": -1650, "y": 210 } } } inputs: - key: YaraRulesSource value: simple: https://github.com/Neo23x0/signature-base/blob/master/yara/expl_cve_2021_40444.yar required: false description: The source of the Yara rules playbookInputQuery: - key: SigmaRulesSource value: simple: https://github.com/SigmaHQ/sigma/blob/master/rules/windows/file_event/win_file_winword_cve_2021_40444.yml required: false description: The source of the Sigma rules playbookInputQuery: - key: SplunkEarliestTime value: simple: -7d required: false description: The earliest time for the Splunk search query. playbookInputQuery: - key: SplunkLatestTime value: simple: now required: false description: The latest time for the Splunk search query. playbookInputQuery: - key: BlockIndicatorsAutomatically value: simple: "False" required: false description: Whether to automatically block the indicators involved. playbookInputQuery: - key: EDLDomainBlocklist value: simple: Demisto Remediation - Domain EDL required: false description: The name of the EDL Domain Block List. playbookInputQuery: - key: QRadarTimeRange value: simple: LAST 7 DAYS required: false description: The time range for the QRadar search query. playbookInputQuery: - key: AutoBlockIndicator value: simple: "True" required: false description: If set to True Indicators will be blocked automatically. Default:False playbookInputQuery: - key: 'UserVerification' value: simple: "False" required: false description: The User Need to verify the indicators before blocking Default:True playbookInputQuery: outputs: [] tests: - No tests (auto formatted) fromversion: 6.5.0