CVE-2022-30190 - MSDT RCE
On **May 27th**, a new Microsoft Office Zero-Day was discovered by [Nao_sec](https://twitter.com/nao_sec). The new Zero-Day is a remote code execution vulnerability that exists when MSDT is called using the URL protocol from a calling application such as Word. On **May 30th**, Microsoft assigned **CVE-2022-30190** to the MSDT vulnerability, aka **Follina vulnerability**. This playbook includes the following tasks: * Collect detection rules. * Exploitation patterns hunting using Cortex XDR - XQL Engine and 3rd party SIEM products. * Cortex XDR BIOCs coverage. * Provides Microsoft workarounds and detection capabilities. **More information:** [Guidance for CVE-2022-30190 Microsoft Support Diagnostic Tool Vulnerability ](https://msrc-blog.microsoft.com/2022/05/30/guidance-for-cve-2022-30190-microsoft-support-diagnostic-tool-vulnerability/) **Note:** This is a beta playbook, which lets you implement and test pre-release software. Since the playbook is beta, it might contain bugs. Updates to the pack during the beta phase might include non-backward compatible features. We appreciate your feedback on the quality and usability of the pack to help us identify issues, fix them, and continually improve.
CVE-2022-30190 - MSDT RCE · 45 tasks · 8 inputs · 0 outputs
Details
| ID | CVE-2022-30190 - MSDT RCE |
|---|---|
| From Version | 6.2.0 |
| Tasks | 45 |
README
On May 27th, a new Microsoft Office Zero-Day was discovered by Nao_sec.
The new Zero-Day is a remote code execution vulnerability that exists when MSDT is called using the URL protocol from a calling application such as Word.
On May 30th, Microsoft assigned CVE-2022-30190 to the MSDT vulnerability, aka Follina vulnerability.
This playbook includes the following tasks:
- Collect detection rules.
- Exploitation patterns hunting using Cortex XDR - XQL Engine and 3rd party SIEM products.
- Cortex XDR BIOCs coverage.
- Provides Microsoft workarounds and detection capabilities.
More information:
Guidance for CVE-2022-30190 Microsoft Support Diagnostic Tool Vulnerability
Note: This is a beta playbook, which lets you implement and test pre-release software. Since the playbook is beta, it might contain bugs. Updates to the pack during the beta phase might include non-backward compatible features. We appreciate your feedback on the quality and usability of the pack to help us identify issues, fix them, and continually improve.
Dependencies
This playbook uses the following sub-playbooks, integrations, and scripts.
Sub-playbooks
- Rapid Breach Response - Set Incident Info
- QRadar Indicator Hunting V2
- Splunk Indicator Hunting
- QRadar search for new Lolbin process by Office applications
- QRadar search for msdt.exe launching via the command line
Integrations
- Elasticsearch v2
Scripts
- ParseHTMLIndicators
- http
- IsIntegrationAvailable
Commands
- xdr-get-alerts
- splunk-search
- search
- createNewIndicator
- associateIndicatorsToIncident
- closeInvestigation
- extractIndicators
- xdr-xql-generic-query
Playbook Inputs
| Name | Description | Default Value | Required |
|---|---|---|---|
| SplunkIndex | Splunk’s index name in which to search. Default is “*” - All. | * | Optional |
| SplunkEarliestTime | Splunk’s earliest time to search. | now | Optional |
| SplunkLatestTime | Splunk’s latest time to search. | -1d@d | Optional |
| ElasticIndex | Elastic’s index name in which to search. | Optional | |
| QRadarTimeRange | QRadar’s query time range. | Last 1 DAYS | Optional |
| PlaybookDescription | The playbook’s description. | On May 27th, a new Microsoft Office Zero-Day was discovered by Nao_sec. The new Zero-Day is a remote code execution vulnerability that exists when MSDT is called using the URL protocol from a calling application such as Word. On May 30th, Microsoft assigned CVE-2022-30190 to the MSDT vulnerability, aka Follina vulnerability. This playbook includes the following tasks: * Collect detection rules. * Exploitation patterns hunting using Cortex XDR - XQL Engine and 3rd party SIEM products. * Cortex XDR BIOCs coverage. * Provides Microsoft workarounds and detection capabilities. More information: Guidance for CVE-2022-30190 Microsoft Support Diagnostic Tool Vulnerability Note: This is a beta playbook, which lets you implement and test pre-release software. Since the playbook is beta, it might contain bugs. Updates to the pack during the beta phase might include non-backward compatible features. We appreciate your feedback on the quality and usability of the pack to help us identify issues, fix them, and continually improve. |
Optional |
| RunXQLHuntingQueries | Whether to execute the XQL queries. | False | Optional |
| RelatedCVEs | Follina vulnerability CVE reference. | CVE-2022-30190 | Optional |
Playbook Outputs
There are no outputs for this playbook.
Playbook Image

Inputs
SplunkIndex— Splunk's index name in which to search. Default is "*" - All.SplunkEarliestTime— Splunk's earliest time to search.SplunkLatestTime— Splunk's latest time to search.ElasticIndex— Elastic's index name in which to search.QRadarTimeRange— QRadar's query time range.PlaybookDescription— The playbook's description.RunXQLHuntingQueries— Whether to execute the XQL queries.RelatedCVEs— Follina vulnerability CVE reference.
Commands used
associateIndicatorsToIncident
closeInvestigation
createNewIndicator
extractIndicators
search
splunk-search
xdr-get-alerts
xdr-xql-generic-query
Flowchart
id: CVE-2022-30190 - MSDT RCE version: -1 name: CVE-2022-30190 - MSDT RCE description: "On **May 27th**, a new Microsoft Office Zero-Day was discovered by [Nao_sec](https://twitter.com/nao_sec). \n\nThe new Zero-Day is a remote code execution vulnerability that exists when MSDT is called using the URL protocol from a calling application such as Word. \n\nOn **May 30th**, Microsoft assigned **CVE-2022-30190** to the MSDT vulnerability, aka **Follina vulnerability**.\n\nThis playbook includes the following tasks:\n\n* Collect detection rules.\n* Exploitation patterns hunting using Cortex XDR - XQL Engine and 3rd party SIEM products.\n* Cortex XDR BIOCs coverage.\n* Provides Microsoft workarounds and detection capabilities.\n\n**More information:**\n\n[Guidance for CVE-2022-30190 Microsoft Support Diagnostic Tool Vulnerability\n](https://msrc-blog.microsoft.com/2022/05/30/guidance-for-cve-2022-30190-microsoft-support-diagnostic-tool-vulnerability/)\n\n**Note:** This is a beta playbook, which lets you implement and test pre-release software. Since the playbook is beta, it might contain bugs. Updates to the pack during the beta phase might include non-backward compatible features. We appreciate your feedback on the quality and usability of the pack to help us identify issues, fix them, and continually improve." starttaskid: '0' tasks: '0': id: '0' taskid: 29e9be36-5408-4613-8ee4-3664ceaa8949 type: start task: id: 29e9be36-5408-4613-8ee4-3664ceaa8949 version: -1 name: '' iscommand: false brand: '' description: '' nexttasks: '#none#': - '5' - '46' separatecontext: false view: |- { "position": { "x": 0, "y": -780 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false '4': id: '4' taskid: 1949e9f6-3ea3-48ef-8684-e6f620e304d9 type: regular task: id: 1949e9f6-3ea3-48ef-8684-e6f620e304d9 version: -1 name: Download Sigma Rules description: Download Sigma Rules scriptName: http type: regular iscommand: false brand: '' nexttasks: '#none#': - '49' scriptarguments: filename: simple: SigmaRules.yml method: simple: GET saveAsFile: simple: yes url: simple: https://raw.githubusercontent.com/SigmaHQ/sigma/master/rules/windows/process_creation/proc_creation_win_lolbins_by_office_applications.yml separatecontext: false view: |- { "position": { "x": -240, "y": -480 } } note: false timertriggers: [] ignoreworker: false skipunavailable: true quietmode: 0 isoversize: false isautoswitchedtoquietmode: false '5': id: '5' taskid: c0578c3d-340d-424c-8b4b-96ce6e83b2ba type: title task: id: c0578c3d-340d-424c-8b4b-96ce6e83b2ba version: -1 name: Collect Detection Rules type: title iscommand: false brand: '' description: '' nexttasks: '#none#': - '4' separatecontext: false view: |- { "position": { "x": -240, "y": -620 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false '9': id: '9' taskid: b232b0b2-75c9-40a4-83bc-d338f8929152 type: title task: id: b232b0b2-75c9-40a4-83bc-d338f8929152 version: -1 name: Threat Hunting type: title iscommand: false brand: '' description: '' nexttasks: '#none#': - '22' - '10' - '18' separatecontext: false view: |- { "position": { "x": 0, "y": 810 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false '10': id: '10' taskid: fb93d407-750a-4153-850c-8a7240d23001 type: title task: id: fb93d407-750a-4153-850c-8a7240d23001 version: -1 name: SIEM Advanced Hunting type: title iscommand: false brand: '' description: '' nexttasks: '#none#': - '11' - '12' - '21' separatecontext: false view: |- { "position": { "x": -510, "y": 970 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false '11': id: '11' taskid: 9b0a5d0e-775f-4158-8f78-83b285100268 type: condition task: id: 9b0a5d0e-775f-4158-8f78-83b285100268 version: -1 name: Is Splunk Enabled? description: Returns 'yes' if integration brand is available. Otherwise returns 'no' scriptName: IsIntegrationAvailable type: condition iscommand: false brand: '' nexttasks: Yes: - '14' no: - '29' yes: - '42' scriptarguments: brandname: simple: SplunkPy results: - brandInstances separatecontext: false view: |- { "position": { "x": -510, "y": 1110 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false '12': id: '12' taskid: a45bb94f-ff7f-446b-86f9-0fc0fea1a0c3 type: condition task: id: a45bb94f-ff7f-446b-86f9-0fc0fea1a0c3 version: -1 name: Is QRadar Enabled? description: Check whether the values provided in arguments are equal. If either of the arguments are missing, no is returned. type: condition iscommand: false brand: '' nexttasks: '#default#': - '29' Yes: - '56' - '15' separatecontext: false conditions: - label: Yes condition: - - operator: isExists left: value: complex: root: modules filters: - - operator: containsGeneral left: value: simple: modules.brand iscontext: true right: value: simple: QRadar ignorecase: true - - operator: isEqualString left: value: simple: modules.state iscontext: true right: value: simple: active iscontext: true right: value: {} view: |- { "position": { "x": -1440, "y": 1110 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false '14': id: '14' taskid: 0e74bfaf-a85e-45a9-8580-84fdda99f353 type: regular task: id: 0e74bfaf-a85e-45a9-8580-84fdda99f353 version: -1 name: Splunk search for new Lolbin process by Office applications description: Searches Splunk for suspicious file creation where the file path is under INETCACHE. script: '|||splunk-search' type: regular iscommand: true brand: '' nexttasks: '#none#': - '27' scriptarguments: earliest_time: complex: root: inputs.SplunkEarliestTime latest_time: complex: root: inputs.SplunkLatestTime query: simple: (source="WinEventLog:*" AND (Image="*regsvr32.exe" OR Image="*rundll32.exe" OR Image="*msiexec.exe" OR Image="*mshta.exe" OR Image="*verclsid.exe" OR Image="*msdt.exe") AND (ParentImage="*winword.exe" OR ParentImage="*excel.exe" OR ParentImage="*powerpnt.exe")) separatecontext: false view: |- { "position": { "x": -640, "y": 1300 } } note: false timertriggers: [] ignoreworker: false skipunavailable: true quietmode: 0 isoversize: false isautoswitchedtoquietmode: false '15': id: '15' taskid: b895f310-ff5c-448f-8389-344b3cf2f9f9 type: playbook task: id: b895f310-ff5c-448f-8389-344b3cf2f9f9 version: -1 name: QRadar search for new Lolbin process by Office applications description: This playbook runs a QRadar query and return its results to the context. playbookName: QRadarFullSearch type: playbook iscommand: false brand: '' nexttasks: '#none#': - '28' scriptarguments: interval: simple: '1' query_expression: simple: SELECT UTF8(payload) from events where LOGSOURCETYPENAME(devicetype)='Microsoft Windows Security Event Log' and ("Image" ilike '%regsvr32.exe' or "Image" ilike '%rundll32.exe' or "Image" ilike '%msiexec.exe' or "Image" ilike '%mshta.exe' or "Image" ilike '%verclsid.exe' or "Image" ilike '%msdt.exe') and ("ParentImage" ilike '%winword.exe' or "ParentImage" ilike '%excel.exe' or "ParentImage" ilike '%powerpnt.exe') timeout: simple: '600' separatecontext: true loop: iscommand: false exitCondition: '' wait: 1 max: 0 view: |- { "position": { "x": -1590, "y": 1300 } } note: false timertriggers: [] ignoreworker: false skipunavailable: true quietmode: 0 isoversize: false isautoswitchedtoquietmode: false '17': id: '17' taskid: 3d006b27-3ab0-44f8-8f12-c7dc87048b68 type: regular task: id: 3d006b27-3ab0-44f8-8f12-c7dc87048b68 version: -1 name: Elastic search for new Lolbin process by Office applications description: Searches an index. script: Elasticsearch v2|||search type: regular iscommand: true brand: Elasticsearch v2 nexttasks: '#none#': - '29' scriptarguments: index: complex: root: inputs.ElasticIndex query: simple: (process.executable:(*regsvr32.exe OR *rundll32.exe OR *msiexec.exe OR *mshta.exe OR *verclsid.exe OR *msdt.exe) AND process.parent.executable:(*winword.exe OR *excel.exe OR *powerpnt.exe)) separatecontext: false view: |- { "position": { "x": 0, "y": 1300 } } note: false timertriggers: [] ignoreworker: false skipunavailable: true quietmode: 0 isoversize: false isautoswitchedtoquietmode: false '18': id: '18' taskid: 36a70bfa-3960-4f34-8eb3-0f1e16c476b9 type: title task: id: 36a70bfa-3960-4f34-8eb3-0f1e16c476b9 version: -1 name: 'Cortex XDR - XQL Hunting Queries ' type: title iscommand: false brand: '' description: '' nexttasks: '#none#': - '19' separatecontext: false view: |- { "position": { "x": 1020, "y": 970 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false '19': id: '19' taskid: 535cb6cd-a8b6-4361-8844-31160c01ad77 type: condition task: id: 535cb6cd-a8b6-4361-8844-31160c01ad77 version: -1 name: Should run XQL hunting queries? description: Checks whether to execute XDR shell script for exploitation hunting. type: condition iscommand: false brand: '' nexttasks: '#default#': - '29' yes: - '20' separatecontext: false conditions: - label: yes condition: - - operator: isEqualString left: value: complex: root: inputs.RunXQLHuntingQueries iscontext: true right: value: simple: 'True' ignorecase: true view: |- { "position": { "x": 1020, "y": 1110 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false '20': id: '20' taskid: 81f635b0-0b8f-46f9-8827-426e5c93038a type: condition task: id: 81f635b0-0b8f-46f9-8827-426e5c93038a version: -1 name: Check if Cortex XDR - XQL Query Engine is Enabled description: Returns 'yes' if integration brand is available. Otherwise returns 'no' scriptName: IsIntegrationAvailable type: condition iscommand: false brand: '' nexttasks: no: - '29' yes: - '33' - '43' scriptarguments: brandname: simple: Cortex XDR - XQL Query Engine results: - brandInstances separatecontext: false view: |- { "position": { "x": 1180, "y": 1290 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false '21': id: '21' taskid: e623f69d-b6b8-45c8-8108-0fbc14181c0c type: condition task: id: e623f69d-b6b8-45c8-8108-0fbc14181c0c version: -1 name: Is Elastic Enabled? description: Returns 'yes' if integration brand is available. Otherwise returns 'no' scriptName: IsIntegrationAvailable type: condition iscommand: false brand: '' nexttasks: Yes: - '17' no: - '29' scriptarguments: brandname: simple: Elasticsearch v2 results: - brandInstances separatecontext: false view: |- { "position": { "x": 0, "y": 1110 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false '22': id: '22' taskid: 08d20ba0-de6c-47cd-85f4-327b075202bc type: title task: id: 08d20ba0-de6c-47cd-85f4-327b075202bc version: -1 name: Cortex XDR - Post-Detection Hunting type: title iscommand: false brand: '' description: '' nexttasks: '#none#': - '23' separatecontext: false view: |- { "position": { "x": 470, "y": 970 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false '23': id: '23' taskid: 35f23f89-273b-4374-83f9-15ab5e84bfb1 type: condition task: id: 35f23f89-273b-4374-83f9-15ab5e84bfb1 version: -1 name: Is Cortex XDR - Investigation and Response enabled? description: Returns 'yes' if integration brand is available. Otherwise returns 'no' scriptName: IsIntegrationAvailable type: condition iscommand: false brand: '' nexttasks: no: - '29' yes: - '24' scriptarguments: brandname: simple: Cortex XDR - XQL Query Engine results: - brandInstances separatecontext: false view: |- { "position": { "x": 470, "y": 1110 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false '24': id: '24' taskid: 847c68d4-9954-48bd-8945-b0275b71ed52 type: regular task: id: 847c68d4-9954-48bd-8945-b0275b71ed52 version: -1 name: Hunt for detected MSDT signatures description: "Returns a list of alerts and their metadata, which you can filter by built-in arguments or use the custom_filter to input a JSON filter object. \nMultiple filter arguments will be concatenated using the AND operator, while arguments that support a comma-separated list of values will use an OR operator between each value." script: '|||xdr-get-alerts' type: regular iscommand: true brand: '' nexttasks: '#none#': - '29' scriptarguments: custom_filter: simple: "{\n \"AND\": [\n \n {\n \"SEARCH_FIELD\": \"source_insert_ts\",\n \"SEARCH_TYPE\": \"RELATIVE_TIMESTAMP\",\n \"SEARCH_VALUE\": 86400000\n },\n {\n \"SEARCH_FIELD\": \"alert_description\",\n \"SEARCH_TYPE\": \"CONTAINS\",\n \"SEARCH_VALUE\": \"bioc.msdt_exploit\"\n }\n ]\n \n}" separatecontext: false view: |- { "position": { "x": 610, "y": 1300 } } note: false timertriggers: [] ignoreworker: false skipunavailable: true quietmode: 0 isoversize: false isautoswitchedtoquietmode: false '27': id: '27' taskid: d3909367-dfce-4a4e-8876-6f31463ac64e type: playbook task: id: d3909367-dfce-4a4e-8876-6f31463ac64e version: -1 name: Splunk Indicator Hunting description: This playbook queries Splunk for indicators such as file hashes, IP addresses, domains, or urls. It outputs detected users, ip addresses, and hostnames related to the indicators. playbookName: Splunk Indicator Hunting type: playbook iscommand: false brand: '' nexttasks: '#none#': - '29' scriptarguments: IPAddress: complex: root: ExtractedIndicators accessor: IP transformers: - operator: uniq IndexName: complex: root: inputs.SplunkIndex SelectFields: simple: source,timestamp URLDomain: complex: root: ExtractedIndicators accessor: Domain transformers: - operator: uniq earliest_time: complex: root: inputs.SplunkEarliestTime event_limit: simple: '100' latest_time: complex: root: inputs.SplunkLatestTime separatecontext: true loop: iscommand: false scriptArguments: IPAddress: complex: root: ExtractedIndicators accessor: IP transformers: - operator: uniq IndexName: simple: index=* MD5: complex: root: ExtractedIndicators filters: - - operator: stringHasLength left: value: simple: ExtractedIndicators iscontext: true right: value: simple: '32' accessor: File transformers: - operator: uniq SHA1: complex: root: ExtractedIndicators filters: - - operator: stringHasLength left: value: simple: ExtractedIndicators iscontext: true right: value: simple: '40' accessor: File transformers: - operator: uniq SHA256: complex: root: ExtractedIndicators filters: - - operator: stringHasLength left: value: simple: ExtractedIndicators iscontext: true right: value: simple: '64' accessor: File transformers: - operator: uniq SelectFields: simple: source,timestamp URLDomain: complex: root: ExtractedIndicators accessor: Domain transformers: - operator: uniq earliest_time: complex: root: inputs.SplunkEarliestTime event_limit: simple: '100' latest_time: complex: root: inputs.SplunkLatestTime exitCondition: '' wait: 1 max: 100 view: |- { "position": { "x": -640, "y": 1470 } } note: false timertriggers: [] ignoreworker: false skipunavailable: true quietmode: 0 isoversize: false isautoswitchedtoquietmode: false '28': id: '28' taskid: 13472933-52b6-45f3-8f21-d21e1b3c8158 type: playbook task: id: 13472933-52b6-45f3-8f21-d21e1b3c8158 version: -1 name: QRadar Indicator Hunting V2 description: 'The Playbook queries QRadar SIEM for indicators such as file hashes, IP addresses, domains, or urls. ' playbookName: QRadar Indicator Hunting V2 type: playbook iscommand: false brand: '' nexttasks: '#none#': - '29' scriptarguments: IPAddress: complex: root: ExtractedIndicators accessor: IP transformers: - operator: uniq InvestigationIPFields: simple: sourceip,destinationip InvestigationUserFields: simple: username QradarIPfield: simple: sourceip,destinationip TimeFrame: complex: root: inputs.QRadarTimeRange URLDomain: complex: root: ExtractedIndicators accessor: Domain transformers: - operator: uniq separatecontext: true loop: iscommand: false scriptArguments: IPAddress: complex: root: ExtractedIndicators accessor: IP transformers: - operator: uniq InvestigationIPFields: simple: sourceip,destinationip InvestigationUserFields: simple: username MD5: complex: root: ExtractedIndicators.File filters: - - operator: stringHasLength left: value: simple: ExtractedIndicators.File iscontext: true right: value: simple: '32' transformers: - operator: uniq QradarIPfield: simple: sourceip,destinationip SHA1: complex: root: ExtractedIndicators.File filters: - - operator: stringHasLength left: value: simple: ExtractedIndicators.File iscontext: true right: value: simple: '40' transformers: - operator: uniq SHA256: complex: root: ExtractedIndicators.File filters: - - operator: stringHasLength left: value: simple: ExtractedIndicators.File iscontext: true right: value: simple: '64' transformers: - operator: uniq TimeFrame: complex: root: inputs.QRadarTimeRange URLDomain: complex: root: ExtractedIndicators accessor: Domain transformers: - operator: uniq exitCondition: '' wait: 1 max: 100 view: |- { "position": { "x": -1590, "y": 1470 } } note: false timertriggers: [] ignoreworker: false skipunavailable: true quietmode: 0 isoversize: false isautoswitchedtoquietmode: false '29': id: '29' taskid: 7da3fe61-f81c-4be3-86d8-1097cef66ba3 type: title task: id: 7da3fe61-f81c-4be3-86d8-1097cef66ba3 version: -1 name: Mitigation type: title iscommand: false brand: '' description: '' nexttasks: '#none#': - '30' - '32' separatecontext: false view: |- { "position": { "x": 0, "y": 1640 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false '30': id: '30' taskid: 652c77ce-7949-44c8-8aa1-3ad05901293a type: title task: id: 652c77ce-7949-44c8-8aa1-3ad05901293a version: -1 name: Recommended Workarounds type: title iscommand: false brand: '' description: '' nexttasks: '#none#': - '34' - '35' separatecontext: false view: |- { "position": { "x": 220, "y": 1790 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false '32': id: '32' taskid: ea976d7e-f7bc-47a5-885f-0fdc04f8e88c type: title task: id: ea976d7e-f7bc-47a5-885f-0fdc04f8e88c version: -1 name: Deploy Detection Rules type: title iscommand: false brand: '' description: '' nexttasks: '#none#': - '36' separatecontext: false view: |- { "position": { "x": -440, "y": 1790 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false '33': id: '33' taskid: f090b81e-e568-442d-8a82-913a5769596d type: regular task: id: f090b81e-e568-442d-8a82-913a5769596d version: -1 name: 'Office spawns a child process with a protocol handler path traversal ' description: |- Execute an XQL query and retrieve results of an executed XQL query API. The command will be executed every 10 seconds until results are retrieved or until a timeout error is raised. When more than 1000 results are retrieved, the command will return a compressed gzipped JSON format file, unless the argument 'parse_result_file_to_context' is set to true and then the results will be extracted to the context. script: '|||xdr-xql-generic-query' type: regular iscommand: true brand: '' nexttasks: '#none#': - '29' scriptarguments: query: simple: |- config case_sensitive = false timeframe=30d |dataset = xdr_data |filter actor_process_image_name in ("winword.exe","powerpnt.exe","excel.exe") and action_process_image_command_line ~= "\.[a-z0-9]+:\.\.(\\|\/)" |fields _time, agent_hostname, agent_version,actor_effective_username, actor_process_image_name, actor_process_command_line, action_process_image_name, action_process_image_command_line separatecontext: false view: |- { "position": { "x": 1340, "y": 1470 } } note: false timertriggers: [] ignoreworker: false skipunavailable: true quietmode: 0 isoversize: false isautoswitchedtoquietmode: false '34': id: '34' taskid: 8da42030-a9ec-4feb-8887-158467b0477a type: regular task: id: 8da42030-a9ec-4feb-8887-158467b0477a version: -1 name: Disable the MSDT URL Protocol description: |- 1. Run Command Prompt as Administrator. 2. Backup your registry key before deletion using the following command: “reg export HKEY_CLASSES_ROOT\ms-msdt filename“ 3. Remove the registry key using the following command: “reg delete HKEY_CLASSES_ROOT\ms-msdt /f”. type: regular iscommand: false brand: '' nexttasks: '#none#': - '41' separatecontext: false view: |- { "position": { "x": 0, "y": 1930 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false '35': id: '35' taskid: 7e1c7292-87ee-4de5-8682-7662905e952f type: regular task: id: 7e1c7292-87ee-4de5-8682-7662905e952f version: -1 name: Create an ASL rule to prevent Office child-processes creation description: |- To prevent office from spawning child processes execute the following command: " Set-MpPreference -AttackSurfaceReductionRules_Ids d4f940ab-401b-4efc-aadc-ad5f3c50688a -AttackSurfaceReductionRules_Actions Enabled" type: regular iscommand: false brand: '' nexttasks: '#none#': - '41' separatecontext: false view: |- { "position": { "x": 440, "y": 1930 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false '36': id: '36' taskid: 714c5220-8abb-4f17-8c6e-4d313190170f type: regular task: id: 714c5220-8abb-4f17-8c6e-4d313190170f version: -1 name: Sigma Rules description: Sigma rules file has been downloaded as SigmaRules.yml and is available for download directly from XSOAR. type: regular iscommand: false brand: '' nexttasks: '#none#': - '41' separatecontext: false view: |- { "position": { "x": -440, "y": 1930 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false '37': id: '37' taskid: 57c2a1ab-f177-4905-8baa-8153f39b5234 type: condition task: id: 57c2a1ab-f177-4905-8baa-8153f39b5234 version: -1 name: Analysis resolution - Should continue with the investigation? description: Check with the analyst whether to continue with the investigation. type: condition iscommand: false brand: '' nexttasks: No: - '40' Yes: - '39' separatecontext: false view: |- { "position": { "x": 0, "y": 2240 } } note: false timertriggers: [] ignoreworker: false message: to: subject: body: simple: Do you need to continue with the investigation? methods: [] format: '' bcc: cc: timings: retriescount: 2 retriesinterval: 360 completeafterreplies: 1 completeafterv2: false completeaftersla: false replyOptions: - Yes - No skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false '38': id: '38' taskid: 6cfaa7b1-4e31-4416-895d-63207cf92943 type: title task: id: 6cfaa7b1-4e31-4416-895d-63207cf92943 version: -1 name: Done type: title iscommand: false brand: '' description: '' separatecontext: false view: |- { "position": { "x": 0, "y": 2610 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false '39': id: '39' taskid: 777f4470-dce6-4a3e-84f6-dab4eebdd0e9 type: regular task: id: 777f4470-dce6-4a3e-84f6-dab4eebdd0e9 version: -1 name: Investigate Further description: Manual step for further incident investigation. CISA released an open-source detection and scanning tool for discovering and fuzzing for Log4J RCE CVE-2021-44228 vulnerability. For more information , [CISA GitHub](https://github.com/cisagov/log4j-scanner/tree/master/log4-scanner) type: regular iscommand: false brand: '' nexttasks: '#none#': - '38' separatecontext: false view: |- { "position": { "x": -450, "y": 2440 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false '40': id: '40' taskid: 151be857-a390-4633-8da5-16f0bd06639a type: regular task: id: 151be857-a390-4633-8da5-16f0bd06639a version: -1 name: Close Investigation description: Close the current incident script: Builtin|||closeInvestigation type: regular iscommand: true brand: Builtin nexttasks: '#none#': - '38' scriptarguments: closeReason: simple: No further actions are required. separatecontext: false view: |- { "position": { "x": 0, "y": 2440 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false '41': id: '41' taskid: 706858e1-9d91-4a9a-88f7-8479f62aa1a9 type: title task: id: 706858e1-9d91-4a9a-88f7-8479f62aa1a9 version: -1 name: Resolution type: title iscommand: false brand: '' description: '' nexttasks: '#none#': - '37' separatecontext: false view: |- { "position": { "x": 0, "y": 2110 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false '42': id: '42' taskid: e081bb18-a7c7-4036-88a6-ede73e58503e type: regular task: id: e081bb18-a7c7-4036-88a6-ede73e58503e version: -1 name: 'Splunk search for msdt.exe launching via the command line. ' description: Searches Splunk for suspicious file creation where the file path is under INETCACHE. script: '|||splunk-search' type: regular iscommand: true brand: '' nexttasks: '#none#': - '27' scriptarguments: earliest_time: complex: root: inputs.SplunkEarliestTime latest_time: complex: root: inputs.SplunkLatestTime query: simple: |- index=${inputs.SplunkIndex} source="xmlwineventlog:microsoft-windows-sysmon/operational" process_name=msdt.exe | where (like(CommandLine, "%PCWDiagnostic%") AND like(CommandLine, "%ms-msdt:/id%") OR like(CommandLine, "%ms-msdt:-id%")) OR (like(CommandLine, "%invoke%")) | table host CommandLine parent_process_name parent_process_id process_name process_id separatecontext: false view: |- { "position": { "x": -1040, "y": 1300 } } note: false timertriggers: [] ignoreworker: false skipunavailable: true quietmode: 0 isoversize: false isautoswitchedtoquietmode: false '43': id: '43' taskid: ede94e96-e35e-4c2d-874c-21409504d7c3 type: regular task: id: ede94e96-e35e-4c2d-874c-21409504d7c3 version: -1 name: msdt.exe execution with a suspicious argument description: |- Execute an XQL query and retrieve results of an executed XQL query API. The command will be executed every 10 seconds until results are retrieved or until a timeout error is raised. When more than 1000 results are retrieved, the command will return a compressed gzipped JSON format file, unless the argument 'parse_result_file_to_context' is set to true and then the results will be extracted to the context. script: '|||xdr-xql-generic-query' type: regular iscommand: true brand: '' nexttasks: '#none#': - '29' scriptarguments: query: simple: |- config case_sensitive = false timeframe = 30d | dataset = xdr_data | filter event_type = ENUM.PROCESS and action_process_image_command_line contains "msdt.exe" and action_process_image_command_line contains "it_browseforfile" | fields agent_hostname , action_process_image_command_line , action_process_image_path , actor_process_command_line , actor_process_image_path , causality_actor_process_image_path query_name: simple: msdt.exe execution with a suspicious argument separatecontext: false view: |- { "position": { "x": 1750, "y": 1470 } } note: false timertriggers: [] ignoreworker: false skipunavailable: true quietmode: 0 isoversize: false isautoswitchedtoquietmode: false '46': id: '46' taskid: c7843151-1642-4eee-879e-f351fdb0215b type: title task: id: c7843151-1642-4eee-879e-f351fdb0215b version: -1 name: Collect Indicators type: title iscommand: false brand: '' description: '' nexttasks: '#none#': - '47' separatecontext: false view: |- { "position": { "x": 230, "y": -620 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false '47': id: '47' taskid: d364fb30-5de8-4dc7-86ee-a685f4de770e type: regular task: id: d364fb30-5de8-4dc7-86ee-a685f4de770e version: -1 name: Collect indicators from TALOS description: This script will extract indicators from HTML and will handle bad TLDs to avoid file extensions false positives. scriptName: ParseHTMLIndicators type: regular iscommand: false brand: '' nexttasks: '#none#': - '49' scriptarguments: unescape_domain: simple: 'False' url: simple: https://blog.talosintelligence.com/2022/06/msdt-follina-coverage.html#more separatecontext: false continueonerror: true view: |- { "position": { "x": 230, "y": -480 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false '49': id: '49' taskid: 0974739c-7588-4297-8b16-5dc3c348d232 type: title task: id: 0974739c-7588-4297-8b16-5dc3c348d232 version: -1 name: Extract Indicators type: title iscommand: false brand: '' description: '' nexttasks: '#none#': - '50' separatecontext: false view: |- { "position": { "x": 0, "y": -290 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false '50': id: '50' taskid: 697d4322-9394-4d7a-85e2-a583b40d2375 type: regular task: id: 697d4322-9394-4d7a-85e2-a583b40d2375 version: -1 name: Extract Indicators From Data Collected description: commands.local.cmd.extract.indicators script: Builtin|||extractIndicators type: regular iscommand: true brand: Builtin nexttasks: '#none#': - '51' scriptarguments: text: complex: root: http.parsedBlog accessor: indicators separatecontext: false continueonerror: true view: |- { "position": { "x": 0, "y": -160 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false '51': id: '51' taskid: f48258c7-6d91-4831-8bc4-5f2ef807b525 type: title task: id: f48258c7-6d91-4831-8bc4-5f2ef807b525 version: -1 name: Tag and Link Indicators type: title iscommand: false brand: '' description: '' nexttasks: '#none#': - '53' - '54' - '55' separatecontext: false view: |- { "position": { "x": 0, "y": -10 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false '52': id: '52' taskid: e4487ba3-a245-41b4-8210-d7f15910d3a7 type: regular task: id: e4487ba3-a245-41b4-8210-d7f15910d3a7 version: -1 name: Link Indicators To Incident description: commands.local.cmd.associate.indicators script: Builtin|||associateIndicatorsToIncident type: regular iscommand: true brand: Builtin nexttasks: '#none#': - "57" scriptarguments: incidentId: complex: root: incident accessor: id indicatorsValues: complex: root: ExtractedIndicators.IP filters: - - operator: isNotEmpty left: value: simple: ExtractedIndicators.IP iscontext: true transformers: - operator: append args: item: value: simple: ExtractedIndicators.Domain iscontext: true - operator: append args: item: value: simple: ExtractedIndicators.URL iscontext: true - operator: append args: item: value: simple: ExtractedIndicators.CVE iscontext: true - operator: append args: item: value: simple: ExtractedIndicators.File iscontext: true separatecontext: false view: |- { "position": { "x": 0, "y": 330 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false '53': id: '53' taskid: bb84dbc9-c8c3-4f8d-8801-7d200ab431c8 type: regular task: id: bb84dbc9-c8c3-4f8d-8801-7d200ab431c8 version: -1 name: Tag File indicators description: commands.local.cmd.new.indicator script: Builtin|||createNewIndicator type: regular iscommand: true brand: Builtin nexttasks: '#none#': - '52' scriptarguments: retry-count: simple: '3' retry-interval: simple: '2' tags: simple: CVE-2022-30190 type: simple: File value: complex: root: ExtractedIndicators.File filters: - - operator: isNotEmpty left: value: simple: ExtractedIndicators.File iscontext: true transformers: - operator: uniq separatecontext: false continueonerror: true view: |- { "position": { "x": 0, "y": 140 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false '54': id: '54' taskid: e2dbc165-dc88-431d-81be-daa4b67b65d2 type: regular task: id: e2dbc165-dc88-431d-81be-daa4b67b65d2 version: -1 name: Tag CVE indicators description: commands.local.cmd.new.indicator script: Builtin|||createNewIndicator type: regular iscommand: true brand: Builtin nexttasks: '#none#': - '52' scriptarguments: retry-count: simple: '3' retry-interval: simple: '2' tags: simple: Follina, MSDT type: simple: CVE value: complex: root: inputs.RelatedCVEs transformers: - operator: split args: delimiter: value: simple: ', ' separatecontext: false continueonerror: true view: |- { "position": { "x": 440, "y": 140 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false '55': id: '55' taskid: d7532ae2-4403-4b51-840b-395a955870ca type: regular task: id: d7532ae2-4403-4b51-840b-395a955870ca version: -1 name: Tag Domain indicators description: commands.local.cmd.new.indicator script: Builtin|||createNewIndicator type: regular iscommand: true brand: Builtin nexttasks: '#none#': - '52' scriptarguments: retry-count: simple: '3' retry-interval: simple: '2' tags: simple: CVE-2022-30190 type: simple: URL value: complex: root: ExtractedIndicators.Domain filters: - - operator: isNotEmpty left: value: simple: ExtractedIndicators.Domain iscontext: true transformers: - operator: uniq separatecontext: false continueonerror: true view: |- { "position": { "x": -450, "y": 140 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false '56': id: '56' taskid: 7f27889c-5916-47a1-8731-154b05fd82b1 type: playbook task: id: 7f27889c-5916-47a1-8731-154b05fd82b1 version: -1 name: QRadar search for msdt.exe launching via the command line description: This playbook runs a QRadar query and return its results to the context. playbookName: QRadarFullSearch type: playbook iscommand: false brand: '' nexttasks: '#none#': - '29' scriptarguments: interval: simple: '1' query_expression: simple: SELECT UTF8(payload) from events where LOGSOURCETYPENAME(devicetype)='Microsoft Windows Security Event Log' and ("Process CommandLine" ilike '%PCWDiagnostic%' and ("Process CommandLine" ilike '%ms-msdt:/id%' OR "Process CommandLine" ilike '%ms-msdt:-id%') OR "Process CommandLine" ilike '%invoke%') timeout: simple: '600' separatecontext: true loop: iscommand: false exitCondition: '' wait: 1 max: 0 view: |- { "position": { "x": -1990, "y": 1300 } } note: false timertriggers: [] ignoreworker: false skipunavailable: true quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "57": id: "57" taskid: d46c5404-0fe3-49c6-84bc-3b789a215bb3 type: title task: id: d46c5404-0fe3-49c6-84bc-3b789a215bb3 version: -1 name: Handle Rapid Breach Response Layout type: title iscommand: false brand: "" description: '' nexttasks: '#none#': - "58" separatecontext: false continueonerrortype: "" view: |- { "position": { "x": 0, "y": 510 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "58": id: "58" taskid: fae48ca5-0cde-4a0f-8568-8822f2613327 type: playbook task: id: fae48ca5-0cde-4a0f-8568-8822f2613327 version: -1 name: Rapid Breach Response - Set Incident Info playbookName: Rapid Breach Response - Set Incident Info type: playbook iscommand: false brand: "" description: '' nexttasks: '#none#': - "9" scriptarguments: SourceOfIndicators: complex: root: http.parsedBlog accessor: sourceLink countTotalIndicators: complex: root: ExtractedIndicators accessor: Domain transformers: - operator: append args: item: value: simple: ExtractedIndicators.IP - operator: append args: item: value: simple: ExtractedIndicators.URL - operator: append args: item: value: simple: ExtractedIndicators.File - operator: append args: item: value: simple: ExtractedIndicators.CVE - operator: uniq - operator: count playbookDescription: complex: root: inputs.PlaybookDescription separatecontext: true continueonerrortype: "" loop: iscommand: false exitCondition: "" wait: 1 max: 100 view: |- { "position": { "x": 0, "y": 640 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false system: true view: |- { "linkLabelsPosition": { "11_14_Yes": 0.37, "11_29_no": 0.25, "12_15_Yes": 0.38, "12_29_#default#": 0.11, "12_56_Yes": 0.69, "19_20_yes": 0.4, "19_29_#default#": 0.32, "20_29_no": 0.12, "21_17_Yes": 0.47, "21_29_no": 0.3, "23_24_yes": 0.37, "23_29_no": 0.29, "37_40_No": 0.63 }, "paper": { "dimensions": { "height": 3455, "width": 4120, "x": -1990, "y": -780 } } } inputs: - key: SplunkIndex value: simple: '*' required: false description: Splunk's index name in which to search. Default is "*" - All. playbookInputQuery: - key: SplunkEarliestTime value: simple: now required: false description: Splunk's earliest time to search. playbookInputQuery: - key: SplunkLatestTime value: simple: -1d@d required: false description: Splunk's latest time to search. playbookInputQuery: - key: ElasticIndex value: {} required: false description: Elastic's index name in which to search. playbookInputQuery: - key: QRadarTimeRange value: simple: Last 1 DAYS required: false description: QRadar's query time range. playbookInputQuery: - key: PlaybookDescription value: simple: "On **May 27th**, a new Microsoft Office Zero-Day was discovered by [Nao_sec](https://twitter.com/nao_sec). \n\nThe new Zero-Day is a remote code execution vulnerability that exists when MSDT is called using the URL protocol from a calling application such as Word. \n\nOn **May 30th**, Microsoft assigned **CVE-2022-30190** to the MSDT vulnerability, aka **Follina vulnerability**.\n\nThis playbook includes the following tasks:\n\n* Collect detection rules.\n* Exploitation patterns hunting using Cortex XDR - XQL Engine and 3rd party SIEM products.\n* Cortex XDR BIOCs coverage.\n* Provides Microsoft workarounds and detection capabilities.\n\n**More information:**\n\n[Guidance for CVE-2022-30190 Microsoft Support Diagnostic Tool Vulnerability\n](https://msrc-blog.microsoft.com/2022/05/30/guidance-for-cve-2022-30190-microsoft-support-diagnostic-tool-vulnerability/)\n\n**Note:** This is a beta playbook, which lets you implement and test pre-release software. Since the playbook is beta, it might contain bugs. Updates to the pack during the beta phase might include non-backward compatible features. We appreciate your feedback on the quality and usability of the pack to help us identify issues, fix them, and continually improve." required: false description: The playbook's description. playbookInputQuery: - key: RunXQLHuntingQueries value: simple: 'False' required: false description: Whether to execute the XQL queries. playbookInputQuery: - key: RelatedCVEs value: simple: CVE-2022-30190 required: false description: Follina vulnerability CVE reference. playbookInputQuery: outputs: [] tests: - No tests (auto formatted) fromversion: 6.2.0