CVE-2022-30190 - MSDT RCE

On **May 27th**, a new Microsoft Office Zero-Day was discovered by [Nao_sec](https://twitter.com/nao_sec). The new Zero-Day is a remote code execution vulnerability that exists when MSDT is called using the URL protocol from a calling application such as Word. On **May 30th**, Microsoft assigned **CVE-2022-30190** to the MSDT vulnerability, aka **Follina vulnerability**. This playbook includes the following tasks: * Collect detection rules. * Exploitation patterns hunting using Cortex XDR - XQL Engine and 3rd party SIEM products. * Cortex XDR BIOCs coverage. * Provides Microsoft workarounds and detection capabilities. **More information:** [Guidance for CVE-2022-30190 Microsoft Support Diagnostic Tool Vulnerability ](https://msrc-blog.microsoft.com/2022/05/30/guidance-for-cve-2022-30190-microsoft-support-diagnostic-tool-vulnerability/) **Note:** This is a beta playbook, which lets you implement and test pre-release software. Since the playbook is beta, it might contain bugs. Updates to the pack during the beta phase might include non-backward compatible features. We appreciate your feedback on the quality and usability of the pack to help us identify issues, fix them, and continually improve.

CVE-2022-30190 - MSDT RCE · 45 tasks · 8 inputs · 0 outputs

Details

IDCVE-2022-30190 - MSDT RCE
From Version6.2.0
Tasks45

README

On May 27th, a new Microsoft Office Zero-Day was discovered by Nao_sec.

The new Zero-Day is a remote code execution vulnerability that exists when MSDT is called using the URL protocol from a calling application such as Word.

On May 30th, Microsoft assigned CVE-2022-30190 to the MSDT vulnerability, aka Follina vulnerability.

This playbook includes the following tasks:

  • Collect detection rules.
  • Exploitation patterns hunting using Cortex XDR - XQL Engine and 3rd party SIEM products.
  • Cortex XDR BIOCs coverage.
  • Provides Microsoft workarounds and detection capabilities.

More information:

Guidance for CVE-2022-30190 Microsoft Support Diagnostic Tool Vulnerability

Note: This is a beta playbook, which lets you implement and test pre-release software. Since the playbook is beta, it might contain bugs. Updates to the pack during the beta phase might include non-backward compatible features. We appreciate your feedback on the quality and usability of the pack to help us identify issues, fix them, and continually improve.

Dependencies

This playbook uses the following sub-playbooks, integrations, and scripts.

Sub-playbooks

  • Rapid Breach Response - Set Incident Info
  • QRadar Indicator Hunting V2
  • Splunk Indicator Hunting
  • QRadar search for new Lolbin process by Office applications
  • QRadar search for msdt.exe launching via the command line

Integrations

  • Elasticsearch v2

Scripts

  • ParseHTMLIndicators
  • http
  • IsIntegrationAvailable

Commands

  • xdr-get-alerts
  • splunk-search
  • search
  • createNewIndicator
  • associateIndicatorsToIncident
  • closeInvestigation
  • extractIndicators
  • xdr-xql-generic-query

Playbook Inputs


Name Description Default Value Required
SplunkIndex Splunk’s index name in which to search. Default is “*” - All. * Optional
SplunkEarliestTime Splunk’s earliest time to search. now Optional
SplunkLatestTime Splunk’s latest time to search. -1d@d Optional
ElasticIndex Elastic’s index name in which to search.   Optional
QRadarTimeRange QRadar’s query time range. Last 1 DAYS Optional
PlaybookDescription The playbook’s description. On May 27th, a new Microsoft Office Zero-Day was discovered by Nao_sec.

The new Zero-Day is a remote code execution vulnerability that exists when MSDT is called using the URL protocol from a calling application such as Word.

On May 30th, Microsoft assigned CVE-2022-30190 to the MSDT vulnerability, aka Follina vulnerability.

This playbook includes the following tasks:

* Collect detection rules.
* Exploitation patterns hunting using Cortex XDR - XQL Engine and 3rd party SIEM products.
* Cortex XDR BIOCs coverage.
* Provides Microsoft workarounds and detection capabilities.

More information:

Guidance for CVE-2022-30190 Microsoft Support Diagnostic Tool Vulnerability


Note: This is a beta playbook, which lets you implement and test pre-release software. Since the playbook is beta, it might contain bugs. Updates to the pack during the beta phase might include non-backward compatible features. We appreciate your feedback on the quality and usability of the pack to help us identify issues, fix them, and continually improve.
Optional
RunXQLHuntingQueries Whether to execute the XQL queries. False Optional
RelatedCVEs Follina vulnerability CVE reference. CVE-2022-30190 Optional

Playbook Outputs


There are no outputs for this playbook.

Playbook Image


CVE-2022-30190 - MSDT RCE

Inputs

  • SplunkIndex — Splunk's index name in which to search. Default is "*" - All.
  • SplunkEarliestTime — Splunk's earliest time to search.
  • SplunkLatestTime — Splunk's latest time to search.
  • ElasticIndex — Elastic's index name in which to search.
  • QRadarTimeRange — QRadar's query time range.
  • PlaybookDescription — The playbook's description.
  • RunXQLHuntingQueries — Whether to execute the XQL queries.
  • RelatedCVEs — Follina vulnerability CVE reference.

Commands used

associateIndicatorsToIncident closeInvestigation createNewIndicator extractIndicators search splunk-search xdr-get-alerts xdr-xql-generic-query

Flowchart

true false true true true false true true true false false true false true Start Start Download Sigma Rules - http Download Sigma Rules http Collect Detection Rules Collect Detection Rules Threat Hunting Threat Hunting SIEM Advanced Hunting SIEM Advanced Hunting Is Splunk Enabled? - IsIntegrationAvailable Is Splunk Enabled? IsIntegrationAvailable Is QRadar Enabled? Is QRadar Enabled? Splunk search for new Lolbin process by Office applications - splunk-search Splunk search for new Lol... splunk-search QRadar search for new Lolbin process by Office applications - QRadarFullSearch QRadar search for new Lol... QRadarFullSearch Elastic search for new Lolbin process by Office applications - search Elastic search for new Lo... search Cortex XDR - XQL Hunting Queries Cortex XDR - XQL Hunting ... Should run XQL hunting queries? Should run XQL hunting qu... Check if Cortex XDR - XQL Query Engine is Enabled - IsIntegrationAvailable Check if Cortex XDR - XQL... IsIntegrationAvailable Is Elastic Enabled? - IsIntegrationAvailable Is Elastic Enabled? IsIntegrationAvailable Cortex XDR - Post-Detection Hunting Cortex XDR - Post-Detecti... Is Cortex XDR - Investigation and Response enabled? - IsIntegrationAvailable Is Cortex XDR - Investiga... IsIntegrationAvailable Hunt for detected MSDT signatures - xdr-get-alerts Hunt for detected MSDT si... xdr-get-alerts Splunk Indicator Hunting - Splunk Indicator Hunting Splunk Indicator Hunting Splunk Indicator Hunting QRadar Indicator Hunting V2 - QRadar Indicator Hunting V2 QRadar Indicator Hunting V2 QRadar Indicator Hunting V2 Mitigation Mitigation Recommended Workarounds Recommended Workarounds Deploy Detection Rules Deploy Detection Rules Office spawns a child process with a protocol handler path traversal - xdr-xql-generic-query Office spawns a child pro... xdr-xql-generic-query Disable the MSDT URL Protocol Disable the MSDT URL Prot... Create an ASL rule to prevent Office child-processes creation Create an ASL rule to pre... Sigma Rules Sigma Rules Analysis resolution - Should continue with the investigation? Analysis resolution - Sho... Done Done Investigate Further Investigate Further Close Investigation - closeInvestigation Close Investigation closeInvestigation Resolution Resolution Splunk search for msdt.exe launching via the command line. - splunk-search Splunk search for msdt.ex... splunk-search msdt.exe execution with a suspicious argument - xdr-xql-generic-query msdt.exe execution with a... xdr-xql-generic-query Collect Indicators Collect Indicators Collect indicators from TALOS - ParseHTMLIndicators Collect indicators from T... ParseHTMLIndicators Extract Indicators Extract Indicators Extract Indicators From Data Collected - extractIndicators Extract Indicators From D... extractIndicators Tag and Link Indicators Tag and Link Indicators Link Indicators To Incident - associateIndicatorsToIncident Link Indicators To Incident associateIndicatorsToIncident Tag File indicators - createNewIndicator Tag File indicators createNewIndicator Tag CVE indicators - createNewIndicator Tag CVE indicators createNewIndicator Tag Domain indicators - createNewIndicator Tag Domain indicators createNewIndicator QRadar search for msdt.exe launching via the command line - QRadarFullSearch QRadar search for msdt.ex... QRadarFullSearch Handle Rapid Breach Response Layout Handle Rapid Breach Respo... Rapid Breach Response - Set Incident Info - Rapid Breach Response - Set Incident Info Rapid Breach Response - S... Rapid Breach Response - Set I...
id: CVE-2022-30190 - MSDT RCE
version: -1
name: CVE-2022-30190 - MSDT RCE
description: "On **May 27th**, a new Microsoft Office Zero-Day was discovered by [Nao_sec](https://twitter.com/nao_sec). \n\nThe new Zero-Day is a remote code execution vulnerability that exists when MSDT is called using the URL protocol from a calling application such as Word. \n\nOn **May 30th**, Microsoft assigned **CVE-2022-30190** to the MSDT vulnerability, aka **Follina vulnerability**.\n\nThis playbook includes the following tasks:\n\n* Collect detection rules.\n* Exploitation patterns hunting using Cortex XDR - XQL Engine and 3rd party SIEM products.\n* Cortex XDR BIOCs coverage.\n* Provides Microsoft workarounds and detection capabilities.\n\n**More information:**\n\n[Guidance for CVE-2022-30190 Microsoft Support Diagnostic Tool Vulnerability\n](https://msrc-blog.microsoft.com/2022/05/30/guidance-for-cve-2022-30190-microsoft-support-diagnostic-tool-vulnerability/)\n\n**Note:** This is a beta playbook, which lets you implement and test pre-release software. Since the playbook is beta, it might contain bugs. Updates to the pack during the beta phase might include non-backward compatible features. We appreciate your feedback on the quality and usability of the pack to help us identify issues, fix them, and continually improve."
starttaskid: '0'
tasks:
  '0':
    id: '0'
    taskid: 29e9be36-5408-4613-8ee4-3664ceaa8949
    type: start
    task:
      id: 29e9be36-5408-4613-8ee4-3664ceaa8949
      version: -1
      name: ''
      iscommand: false
      brand: ''
      description: ''
    nexttasks:
      '#none#':
      - '5'
      - '46'
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 0,
          "y": -780
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  '4':
    id: '4'
    taskid: 1949e9f6-3ea3-48ef-8684-e6f620e304d9
    type: regular
    task:
      id: 1949e9f6-3ea3-48ef-8684-e6f620e304d9
      version: -1
      name: Download Sigma Rules
      description: Download Sigma Rules
      scriptName: http
      type: regular
      iscommand: false
      brand: ''
    nexttasks:
      '#none#':
      - '49'
    scriptarguments:
      filename:
        simple: SigmaRules.yml
      method:
        simple: GET
      saveAsFile:
        simple: yes
      url:
        simple: https://raw.githubusercontent.com/SigmaHQ/sigma/master/rules/windows/process_creation/proc_creation_win_lolbins_by_office_applications.yml
    separatecontext: false
    view: |-
      {
        "position": {
          "x": -240,
          "y": -480
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: true
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  '5':
    id: '5'
    taskid: c0578c3d-340d-424c-8b4b-96ce6e83b2ba
    type: title
    task:
      id: c0578c3d-340d-424c-8b4b-96ce6e83b2ba
      version: -1
      name: Collect Detection Rules
      type: title
      iscommand: false
      brand: ''
      description: ''
    nexttasks:
      '#none#':
      - '4'
    separatecontext: false
    view: |-
      {
        "position": {
          "x": -240,
          "y": -620
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  '9':
    id: '9'
    taskid: b232b0b2-75c9-40a4-83bc-d338f8929152
    type: title
    task:
      id: b232b0b2-75c9-40a4-83bc-d338f8929152
      version: -1
      name: Threat Hunting
      type: title
      iscommand: false
      brand: ''
      description: ''
    nexttasks:
      '#none#':
      - '22'
      - '10'
      - '18'
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 0,
          "y": 810
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  '10':
    id: '10'
    taskid: fb93d407-750a-4153-850c-8a7240d23001
    type: title
    task:
      id: fb93d407-750a-4153-850c-8a7240d23001
      version: -1
      name: SIEM Advanced Hunting
      type: title
      iscommand: false
      brand: ''
      description: ''
    nexttasks:
      '#none#':
      - '11'
      - '12'
      - '21'
    separatecontext: false
    view: |-
      {
        "position": {
          "x": -510,
          "y": 970
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  '11':
    id: '11'
    taskid: 9b0a5d0e-775f-4158-8f78-83b285100268
    type: condition
    task:
      id: 9b0a5d0e-775f-4158-8f78-83b285100268
      version: -1
      name: Is Splunk Enabled?
      description: Returns 'yes' if integration brand is available. Otherwise returns 'no'
      scriptName: IsIntegrationAvailable
      type: condition
      iscommand: false
      brand: ''
    nexttasks:
      Yes:
      - '14'
      no:
      - '29'
      yes:
      - '42'
    scriptarguments:
      brandname:
        simple: SplunkPy
    results:
    - brandInstances
    separatecontext: false
    view: |-
      {
        "position": {
          "x": -510,
          "y": 1110
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  '12':
    id: '12'
    taskid: a45bb94f-ff7f-446b-86f9-0fc0fea1a0c3
    type: condition
    task:
      id: a45bb94f-ff7f-446b-86f9-0fc0fea1a0c3
      version: -1
      name: Is QRadar Enabled?
      description: Check whether the values provided in arguments are equal. If either of the arguments are missing, no is returned.
      type: condition
      iscommand: false
      brand: ''
    nexttasks:
      '#default#':
      - '29'
      Yes:
      - '56'
      - '15'
    separatecontext: false
    conditions:
    - label: Yes
      condition:
      - - operator: isExists
          left:
            value:
              complex:
                root: modules
                filters:
                - - operator: containsGeneral
                    left:
                      value:
                        simple: modules.brand
                      iscontext: true
                    right:
                      value:
                        simple: QRadar
                    ignorecase: true
                - - operator: isEqualString
                    left:
                      value:
                        simple: modules.state
                      iscontext: true
                    right:
                      value:
                        simple: active
            iscontext: true
          right:
            value: {}
    view: |-
      {
        "position": {
          "x": -1440,
          "y": 1110
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  '14':
    id: '14'
    taskid: 0e74bfaf-a85e-45a9-8580-84fdda99f353
    type: regular
    task:
      id: 0e74bfaf-a85e-45a9-8580-84fdda99f353
      version: -1
      name: Splunk search for new Lolbin process by Office applications
      description: Searches Splunk for suspicious file creation where the file path is under INETCACHE.
      script: '|||splunk-search'
      type: regular
      iscommand: true
      brand: ''
    nexttasks:
      '#none#':
      - '27'
    scriptarguments:
      earliest_time:
        complex:
          root: inputs.SplunkEarliestTime
      latest_time:
        complex:
          root: inputs.SplunkLatestTime
      query:
        simple: (source="WinEventLog:*" AND (Image="*regsvr32.exe" OR Image="*rundll32.exe" OR Image="*msiexec.exe" OR Image="*mshta.exe" OR Image="*verclsid.exe" OR Image="*msdt.exe") AND (ParentImage="*winword.exe" OR ParentImage="*excel.exe" OR ParentImage="*powerpnt.exe"))
    separatecontext: false
    view: |-
      {
        "position": {
          "x": -640,
          "y": 1300
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: true
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  '15':
    id: '15'
    taskid: b895f310-ff5c-448f-8389-344b3cf2f9f9
    type: playbook
    task:
      id: b895f310-ff5c-448f-8389-344b3cf2f9f9
      version: -1
      name: QRadar search for new Lolbin process by Office applications
      description: This playbook runs a QRadar query and return its results to the context.
      playbookName: QRadarFullSearch
      type: playbook
      iscommand: false
      brand: ''
    nexttasks:
      '#none#':
      - '28'
    scriptarguments:
      interval:
        simple: '1'
      query_expression:
        simple: SELECT UTF8(payload) from events where LOGSOURCETYPENAME(devicetype)='Microsoft Windows Security Event Log' and ("Image" ilike '%regsvr32.exe' or "Image" ilike '%rundll32.exe' or "Image" ilike '%msiexec.exe' or "Image" ilike '%mshta.exe' or "Image" ilike '%verclsid.exe' or "Image" ilike '%msdt.exe') and ("ParentImage" ilike '%winword.exe' or "ParentImage" ilike '%excel.exe' or "ParentImage" ilike '%powerpnt.exe')
      timeout:
        simple: '600'
    separatecontext: true
    loop:
      iscommand: false
      exitCondition: ''
      wait: 1
      max: 0
    view: |-
      {
        "position": {
          "x": -1590,
          "y": 1300
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: true
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  '17':
    id: '17'
    taskid: 3d006b27-3ab0-44f8-8f12-c7dc87048b68
    type: regular
    task:
      id: 3d006b27-3ab0-44f8-8f12-c7dc87048b68
      version: -1
      name: Elastic search for new Lolbin process by Office applications
      description: Searches an index.
      script: Elasticsearch v2|||search
      type: regular
      iscommand: true
      brand: Elasticsearch v2
    nexttasks:
      '#none#':
      - '29'
    scriptarguments:
      index:
        complex:
          root: inputs.ElasticIndex
      query:
        simple: (process.executable:(*regsvr32.exe OR *rundll32.exe OR *msiexec.exe OR *mshta.exe OR *verclsid.exe OR *msdt.exe) AND process.parent.executable:(*winword.exe OR *excel.exe OR *powerpnt.exe))
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 0,
          "y": 1300
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: true
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  '18':
    id: '18'
    taskid: 36a70bfa-3960-4f34-8eb3-0f1e16c476b9
    type: title
    task:
      id: 36a70bfa-3960-4f34-8eb3-0f1e16c476b9
      version: -1
      name: 'Cortex XDR - XQL Hunting Queries '
      type: title
      iscommand: false
      brand: ''
      description: ''
    nexttasks:
      '#none#':
      - '19'
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 1020,
          "y": 970
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  '19':
    id: '19'
    taskid: 535cb6cd-a8b6-4361-8844-31160c01ad77
    type: condition
    task:
      id: 535cb6cd-a8b6-4361-8844-31160c01ad77
      version: -1
      name: Should run XQL hunting queries?
      description: Checks whether to execute XDR shell script for exploitation hunting.
      type: condition
      iscommand: false
      brand: ''
    nexttasks:
      '#default#':
      - '29'
      yes:
      - '20'
    separatecontext: false
    conditions:
    - label: yes
      condition:
      - - operator: isEqualString
          left:
            value:
              complex:
                root: inputs.RunXQLHuntingQueries
            iscontext: true
          right:
            value:
              simple: 'True'
          ignorecase: true
    view: |-
      {
        "position": {
          "x": 1020,
          "y": 1110
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  '20':
    id: '20'
    taskid: 81f635b0-0b8f-46f9-8827-426e5c93038a
    type: condition
    task:
      id: 81f635b0-0b8f-46f9-8827-426e5c93038a
      version: -1
      name: Check if Cortex XDR - XQL Query Engine is Enabled
      description: Returns 'yes' if integration brand is available. Otherwise returns 'no'
      scriptName: IsIntegrationAvailable
      type: condition
      iscommand: false
      brand: ''
    nexttasks:
      no:
      - '29'
      yes:
      - '33'
      - '43'
    scriptarguments:
      brandname:
        simple: Cortex XDR - XQL Query Engine
    results:
    - brandInstances
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 1180,
          "y": 1290
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  '21':
    id: '21'
    taskid: e623f69d-b6b8-45c8-8108-0fbc14181c0c
    type: condition
    task:
      id: e623f69d-b6b8-45c8-8108-0fbc14181c0c
      version: -1
      name: Is Elastic Enabled?
      description: Returns 'yes' if integration brand is available. Otherwise returns 'no'
      scriptName: IsIntegrationAvailable
      type: condition
      iscommand: false
      brand: ''
    nexttasks:
      Yes:
      - '17'
      no:
      - '29'
    scriptarguments:
      brandname:
        simple: Elasticsearch v2
    results:
    - brandInstances
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 0,
          "y": 1110
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  '22':
    id: '22'
    taskid: 08d20ba0-de6c-47cd-85f4-327b075202bc
    type: title
    task:
      id: 08d20ba0-de6c-47cd-85f4-327b075202bc
      version: -1
      name: Cortex XDR - Post-Detection Hunting
      type: title
      iscommand: false
      brand: ''
      description: ''
    nexttasks:
      '#none#':
      - '23'
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 470,
          "y": 970
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  '23':
    id: '23'
    taskid: 35f23f89-273b-4374-83f9-15ab5e84bfb1
    type: condition
    task:
      id: 35f23f89-273b-4374-83f9-15ab5e84bfb1
      version: -1
      name: Is Cortex XDR - Investigation and Response enabled?
      description: Returns 'yes' if integration brand is available. Otherwise returns 'no'
      scriptName: IsIntegrationAvailable
      type: condition
      iscommand: false
      brand: ''
    nexttasks:
      no:
      - '29'
      yes:
      - '24'
    scriptarguments:
      brandname:
        simple: Cortex XDR - XQL Query Engine
    results:
    - brandInstances
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 470,
          "y": 1110
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  '24':
    id: '24'
    taskid: 847c68d4-9954-48bd-8945-b0275b71ed52
    type: regular
    task:
      id: 847c68d4-9954-48bd-8945-b0275b71ed52
      version: -1
      name: Hunt for detected MSDT signatures
      description: "Returns a list of alerts and their metadata, which you can filter by built-in arguments or use the custom_filter to input a JSON filter object. \nMultiple filter arguments will be concatenated using the AND operator, while arguments that support a comma-separated list of values will use an OR operator between each value."
      script: '|||xdr-get-alerts'
      type: regular
      iscommand: true
      brand: ''
    nexttasks:
      '#none#':
      - '29'
    scriptarguments:
      custom_filter:
        simple: "{\n        \"AND\": [\n          \n            {\n              \"SEARCH_FIELD\": \"source_insert_ts\",\n              \"SEARCH_TYPE\": \"RELATIVE_TIMESTAMP\",\n              \"SEARCH_VALUE\": 86400000\n            },\n            {\n              \"SEARCH_FIELD\": \"alert_description\",\n              \"SEARCH_TYPE\": \"CONTAINS\",\n              \"SEARCH_VALUE\": \"bioc.msdt_exploit\"\n            }\n            ]\n          \n}"
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 610,
          "y": 1300
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: true
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  '27':
    id: '27'
    taskid: d3909367-dfce-4a4e-8876-6f31463ac64e
    type: playbook
    task:
      id: d3909367-dfce-4a4e-8876-6f31463ac64e
      version: -1
      name: Splunk Indicator Hunting
      description: This playbook queries Splunk for indicators such as file hashes, IP addresses, domains, or urls. It outputs detected users, ip addresses, and hostnames related to the indicators.
      playbookName: Splunk Indicator Hunting
      type: playbook
      iscommand: false
      brand: ''
    nexttasks:
      '#none#':
      - '29'
    scriptarguments:
      IPAddress:
        complex:
          root: ExtractedIndicators
          accessor: IP
          transformers:
          - operator: uniq
      IndexName:
        complex:
          root: inputs.SplunkIndex
      SelectFields:
        simple: source,timestamp
      URLDomain:
        complex:
          root: ExtractedIndicators
          accessor: Domain
          transformers:
          - operator: uniq
      earliest_time:
        complex:
          root: inputs.SplunkEarliestTime
      event_limit:
        simple: '100'
      latest_time:
        complex:
          root: inputs.SplunkLatestTime
    separatecontext: true
    loop:
      iscommand: false
      scriptArguments:
        IPAddress:
          complex:
            root: ExtractedIndicators
            accessor: IP
            transformers:
            - operator: uniq
        IndexName:
          simple: index=*
        MD5:
          complex:
            root: ExtractedIndicators
            filters:
            - - operator: stringHasLength
                left:
                  value:
                    simple: ExtractedIndicators
                  iscontext: true
                right:
                  value:
                    simple: '32'
            accessor: File
            transformers:
            - operator: uniq
        SHA1:
          complex:
            root: ExtractedIndicators
            filters:
            - - operator: stringHasLength
                left:
                  value:
                    simple: ExtractedIndicators
                  iscontext: true
                right:
                  value:
                    simple: '40'
            accessor: File
            transformers:
            - operator: uniq
        SHA256:
          complex:
            root: ExtractedIndicators
            filters:
            - - operator: stringHasLength
                left:
                  value:
                    simple: ExtractedIndicators
                  iscontext: true
                right:
                  value:
                    simple: '64'
            accessor: File
            transformers:
            - operator: uniq
        SelectFields:
          simple: source,timestamp
        URLDomain:
          complex:
            root: ExtractedIndicators
            accessor: Domain
            transformers:
            - operator: uniq
        earliest_time:
          complex:
            root: inputs.SplunkEarliestTime
        event_limit:
          simple: '100'
        latest_time:
          complex:
            root: inputs.SplunkLatestTime
      exitCondition: ''
      wait: 1
      max: 100
    view: |-
      {
        "position": {
          "x": -640,
          "y": 1470
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: true
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  '28':
    id: '28'
    taskid: 13472933-52b6-45f3-8f21-d21e1b3c8158
    type: playbook
    task:
      id: 13472933-52b6-45f3-8f21-d21e1b3c8158
      version: -1
      name: QRadar Indicator Hunting V2
      description: 'The Playbook queries QRadar SIEM for indicators such as file hashes, IP addresses, domains, or urls. '
      playbookName: QRadar Indicator Hunting V2
      type: playbook
      iscommand: false
      brand: ''
    nexttasks:
      '#none#':
      - '29'
    scriptarguments:
      IPAddress:
        complex:
          root: ExtractedIndicators
          accessor: IP
          transformers:
          - operator: uniq
      InvestigationIPFields:
        simple: sourceip,destinationip
      InvestigationUserFields:
        simple: username
      QradarIPfield:
        simple: sourceip,destinationip
      TimeFrame:
        complex:
          root: inputs.QRadarTimeRange
      URLDomain:
        complex:
          root: ExtractedIndicators
          accessor: Domain
          transformers:
          - operator: uniq
    separatecontext: true
    loop:
      iscommand: false
      scriptArguments:
        IPAddress:
          complex:
            root: ExtractedIndicators
            accessor: IP
            transformers:
            - operator: uniq
        InvestigationIPFields:
          simple: sourceip,destinationip
        InvestigationUserFields:
          simple: username
        MD5:
          complex:
            root: ExtractedIndicators.File
            filters:
            - - operator: stringHasLength
                left:
                  value:
                    simple: ExtractedIndicators.File
                  iscontext: true
                right:
                  value:
                    simple: '32'
            transformers:
            - operator: uniq
        QradarIPfield:
          simple: sourceip,destinationip
        SHA1:
          complex:
            root: ExtractedIndicators.File
            filters:
            - - operator: stringHasLength
                left:
                  value:
                    simple: ExtractedIndicators.File
                  iscontext: true
                right:
                  value:
                    simple: '40'
            transformers:
            - operator: uniq
        SHA256:
          complex:
            root: ExtractedIndicators.File
            filters:
            - - operator: stringHasLength
                left:
                  value:
                    simple: ExtractedIndicators.File
                  iscontext: true
                right:
                  value:
                    simple: '64'
            transformers:
            - operator: uniq
        TimeFrame:
          complex:
            root: inputs.QRadarTimeRange
        URLDomain:
          complex:
            root: ExtractedIndicators
            accessor: Domain
            transformers:
            - operator: uniq
      exitCondition: ''
      wait: 1
      max: 100
    view: |-
      {
        "position": {
          "x": -1590,
          "y": 1470
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: true
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  '29':
    id: '29'
    taskid: 7da3fe61-f81c-4be3-86d8-1097cef66ba3
    type: title
    task:
      id: 7da3fe61-f81c-4be3-86d8-1097cef66ba3
      version: -1
      name: Mitigation
      type: title
      iscommand: false
      brand: ''
      description: ''
    nexttasks:
      '#none#':
      - '30'
      - '32'
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 0,
          "y": 1640
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  '30':
    id: '30'
    taskid: 652c77ce-7949-44c8-8aa1-3ad05901293a
    type: title
    task:
      id: 652c77ce-7949-44c8-8aa1-3ad05901293a
      version: -1
      name: Recommended Workarounds
      type: title
      iscommand: false
      brand: ''
      description: ''
    nexttasks:
      '#none#':
      - '34'
      - '35'
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 220,
          "y": 1790
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  '32':
    id: '32'
    taskid: ea976d7e-f7bc-47a5-885f-0fdc04f8e88c
    type: title
    task:
      id: ea976d7e-f7bc-47a5-885f-0fdc04f8e88c
      version: -1
      name: Deploy Detection Rules
      type: title
      iscommand: false
      brand: ''
      description: ''
    nexttasks:
      '#none#':
      - '36'
    separatecontext: false
    view: |-
      {
        "position": {
          "x": -440,
          "y": 1790
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  '33':
    id: '33'
    taskid: f090b81e-e568-442d-8a82-913a5769596d
    type: regular
    task:
      id: f090b81e-e568-442d-8a82-913a5769596d
      version: -1
      name: 'Office spawns a child process with a protocol handler path traversal '
      description: |-
        Execute an XQL query and retrieve results of an executed XQL query API. The command will be executed every 10 seconds until results are retrieved or until a timeout error is raised.
        When more than 1000 results are retrieved, the command will return a compressed gzipped JSON format file,
        unless the argument 'parse_result_file_to_context' is set to true and then the results will be extracted to the context.
      script: '|||xdr-xql-generic-query'
      type: regular
      iscommand: true
      brand: ''
    nexttasks:
      '#none#':
      - '29'
    scriptarguments:
      query:
        simple: |-
          config case_sensitive = false timeframe=30d
          |dataset = xdr_data
          |filter actor_process_image_name in ("winword.exe","powerpnt.exe","excel.exe") and  action_process_image_command_line ~= "\.[a-z0-9]+:\.\.(\\|\/)"
          |fields _time, agent_hostname, agent_version,actor_effective_username, actor_process_image_name, actor_process_command_line, action_process_image_name, action_process_image_command_line
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 1340,
          "y": 1470
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: true
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  '34':
    id: '34'
    taskid: 8da42030-a9ec-4feb-8887-158467b0477a
    type: regular
    task:
      id: 8da42030-a9ec-4feb-8887-158467b0477a
      version: -1
      name: Disable the MSDT URL Protocol
      description: |-
        1. Run Command Prompt as Administrator.
        2. Backup your registry key before deletion using the following command:
        “reg export HKEY_CLASSES_ROOT\ms-msdt filename“
        3. Remove the registry key using the following command:
         “reg delete HKEY_CLASSES_ROOT\ms-msdt /f”.
      type: regular
      iscommand: false
      brand: ''
    nexttasks:
      '#none#':
      - '41'
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 0,
          "y": 1930
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  '35':
    id: '35'
    taskid: 7e1c7292-87ee-4de5-8682-7662905e952f
    type: regular
    task:
      id: 7e1c7292-87ee-4de5-8682-7662905e952f
      version: -1
      name: Create an ASL rule to prevent Office child-processes creation
      description: |-
        To prevent office from spawning child processes execute the following command:
        " Set-MpPreference -AttackSurfaceReductionRules_Ids d4f940ab-401b-4efc-aadc-ad5f3c50688a -AttackSurfaceReductionRules_Actions Enabled"
      type: regular
      iscommand: false
      brand: ''
    nexttasks:
      '#none#':
      - '41'
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 440,
          "y": 1930
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  '36':
    id: '36'
    taskid: 714c5220-8abb-4f17-8c6e-4d313190170f
    type: regular
    task:
      id: 714c5220-8abb-4f17-8c6e-4d313190170f
      version: -1
      name: Sigma Rules
      description: Sigma rules file has been downloaded as SigmaRules.yml and is available for download directly from XSOAR.
      type: regular
      iscommand: false
      brand: ''
    nexttasks:
      '#none#':
      - '41'
    separatecontext: false
    view: |-
      {
        "position": {
          "x": -440,
          "y": 1930
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  '37':
    id: '37'
    taskid: 57c2a1ab-f177-4905-8baa-8153f39b5234
    type: condition
    task:
      id: 57c2a1ab-f177-4905-8baa-8153f39b5234
      version: -1
      name: Analysis resolution - Should continue with the investigation?
      description: Check with the analyst whether to continue with the investigation.
      type: condition
      iscommand: false
      brand: ''
    nexttasks:
      No:
      - '40'
      Yes:
      - '39'
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 0,
          "y": 2240
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    message:
      to:
      subject:
      body:
        simple: Do you need to continue with the investigation?
      methods: []
      format: ''
      bcc:
      cc:
      timings:
        retriescount: 2
        retriesinterval: 360
        completeafterreplies: 1
        completeafterv2: false
        completeaftersla: false
      replyOptions:
      - Yes
      - No
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  '38':
    id: '38'
    taskid: 6cfaa7b1-4e31-4416-895d-63207cf92943
    type: title
    task:
      id: 6cfaa7b1-4e31-4416-895d-63207cf92943
      version: -1
      name: Done
      type: title
      iscommand: false
      brand: ''
      description: ''
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 0,
          "y": 2610
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  '39':
    id: '39'
    taskid: 777f4470-dce6-4a3e-84f6-dab4eebdd0e9
    type: regular
    task:
      id: 777f4470-dce6-4a3e-84f6-dab4eebdd0e9
      version: -1
      name: Investigate Further
      description: Manual step for further incident investigation. CISA released an open-source detection and scanning tool for discovering and fuzzing for Log4J RCE CVE-2021-44228 vulnerability. For more information , [CISA GitHub](https://github.com/cisagov/log4j-scanner/tree/master/log4-scanner)
      type: regular
      iscommand: false
      brand: ''
    nexttasks:
      '#none#':
      - '38'
    separatecontext: false
    view: |-
      {
        "position": {
          "x": -450,
          "y": 2440
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  '40':
    id: '40'
    taskid: 151be857-a390-4633-8da5-16f0bd06639a
    type: regular
    task:
      id: 151be857-a390-4633-8da5-16f0bd06639a
      version: -1
      name: Close Investigation
      description: Close the current incident
      script: Builtin|||closeInvestigation
      type: regular
      iscommand: true
      brand: Builtin
    nexttasks:
      '#none#':
      - '38'
    scriptarguments:
      closeReason:
        simple: No further actions are required.
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 0,
          "y": 2440
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  '41':
    id: '41'
    taskid: 706858e1-9d91-4a9a-88f7-8479f62aa1a9
    type: title
    task:
      id: 706858e1-9d91-4a9a-88f7-8479f62aa1a9
      version: -1
      name: Resolution
      type: title
      iscommand: false
      brand: ''
      description: ''
    nexttasks:
      '#none#':
      - '37'
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 0,
          "y": 2110
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  '42':
    id: '42'
    taskid: e081bb18-a7c7-4036-88a6-ede73e58503e
    type: regular
    task:
      id: e081bb18-a7c7-4036-88a6-ede73e58503e
      version: -1
      name: 'Splunk search for msdt.exe launching via the command line. '
      description: Searches Splunk for suspicious file creation where the file path is under INETCACHE.
      script: '|||splunk-search'
      type: regular
      iscommand: true
      brand: ''
    nexttasks:
      '#none#':
      - '27'
    scriptarguments:
      earliest_time:
        complex:
          root: inputs.SplunkEarliestTime
      latest_time:
        complex:
          root: inputs.SplunkLatestTime
      query:
        simple: |-
          index=${inputs.SplunkIndex} source="xmlwineventlog:microsoft-windows-sysmon/operational" process_name=msdt.exe
          | where (like(CommandLine, "%PCWDiagnostic%") AND like(CommandLine, "%ms-msdt:/id%") OR like(CommandLine, "%ms-msdt:-id%")) OR (like(CommandLine, "%invoke%"))
          | table host CommandLine parent_process_name parent_process_id process_name process_id
    separatecontext: false
    view: |-
      {
        "position": {
          "x": -1040,
          "y": 1300
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: true
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  '43':
    id: '43'
    taskid: ede94e96-e35e-4c2d-874c-21409504d7c3
    type: regular
    task:
      id: ede94e96-e35e-4c2d-874c-21409504d7c3
      version: -1
      name: msdt.exe execution with a suspicious argument
      description: |-
        Execute an XQL query and retrieve results of an executed XQL query API. The command will be executed every 10 seconds until results are retrieved or until a timeout error is raised.
        When more than 1000 results are retrieved, the command will return a compressed gzipped JSON format file,
        unless the argument 'parse_result_file_to_context' is set to true and then the results will be extracted to the context.
      script: '|||xdr-xql-generic-query'
      type: regular
      iscommand: true
      brand: ''
    nexttasks:
      '#none#':
      - '29'
    scriptarguments:
      query:
        simple: |-
          config case_sensitive = false timeframe = 30d
          | dataset = xdr_data
          | filter event_type = ENUM.PROCESS and action_process_image_command_line contains "msdt.exe" and
          action_process_image_command_line contains "it_browseforfile"
          | fields agent_hostname , action_process_image_command_line , action_process_image_path , actor_process_command_line , actor_process_image_path , causality_actor_process_image_path
      query_name:
        simple: msdt.exe execution with a suspicious argument
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 1750,
          "y": 1470
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: true
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  '46':
    id: '46'
    taskid: c7843151-1642-4eee-879e-f351fdb0215b
    type: title
    task:
      id: c7843151-1642-4eee-879e-f351fdb0215b
      version: -1
      name: Collect Indicators
      type: title
      iscommand: false
      brand: ''
      description: ''
    nexttasks:
      '#none#':
      - '47'
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 230,
          "y": -620
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  '47':
    id: '47'
    taskid: d364fb30-5de8-4dc7-86ee-a685f4de770e
    type: regular
    task:
      id: d364fb30-5de8-4dc7-86ee-a685f4de770e
      version: -1
      name: Collect indicators from TALOS
      description: This script will extract indicators from HTML and will handle bad TLDs to avoid file extensions false positives.
      scriptName: ParseHTMLIndicators
      type: regular
      iscommand: false
      brand: ''
    nexttasks:
      '#none#':
      - '49'
    scriptarguments:
      unescape_domain:
        simple: 'False'
      url:
        simple: https://blog.talosintelligence.com/2022/06/msdt-follina-coverage.html#more
    separatecontext: false
    continueonerror: true
    view: |-
      {
        "position": {
          "x": 230,
          "y": -480
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  '49':
    id: '49'
    taskid: 0974739c-7588-4297-8b16-5dc3c348d232
    type: title
    task:
      id: 0974739c-7588-4297-8b16-5dc3c348d232
      version: -1
      name: Extract Indicators
      type: title
      iscommand: false
      brand: ''
      description: ''
    nexttasks:
      '#none#':
      - '50'
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 0,
          "y": -290
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  '50':
    id: '50'
    taskid: 697d4322-9394-4d7a-85e2-a583b40d2375
    type: regular
    task:
      id: 697d4322-9394-4d7a-85e2-a583b40d2375
      version: -1
      name: Extract Indicators From Data Collected
      description: commands.local.cmd.extract.indicators
      script: Builtin|||extractIndicators
      type: regular
      iscommand: true
      brand: Builtin
    nexttasks:
      '#none#':
      - '51'
    scriptarguments:
      text:
        complex:
          root: http.parsedBlog
          accessor: indicators
    separatecontext: false
    continueonerror: true
    view: |-
      {
        "position": {
          "x": 0,
          "y": -160
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  '51':
    id: '51'
    taskid: f48258c7-6d91-4831-8bc4-5f2ef807b525
    type: title
    task:
      id: f48258c7-6d91-4831-8bc4-5f2ef807b525
      version: -1
      name: Tag and Link Indicators
      type: title
      iscommand: false
      brand: ''
      description: ''
    nexttasks:
      '#none#':
      - '53'
      - '54'
      - '55'
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 0,
          "y": -10
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  '52':
    id: '52'
    taskid: e4487ba3-a245-41b4-8210-d7f15910d3a7
    type: regular
    task:
      id: e4487ba3-a245-41b4-8210-d7f15910d3a7
      version: -1
      name: Link Indicators To Incident
      description: commands.local.cmd.associate.indicators
      script: Builtin|||associateIndicatorsToIncident
      type: regular
      iscommand: true
      brand: Builtin
    nexttasks:
      '#none#':
      - "57"
    scriptarguments:
      incidentId:
        complex:
          root: incident
          accessor: id
      indicatorsValues:
        complex:
          root: ExtractedIndicators.IP
          filters:
          - - operator: isNotEmpty
              left:
                value:
                  simple: ExtractedIndicators.IP
                iscontext: true
          transformers:
          - operator: append
            args:
              item:
                value:
                  simple: ExtractedIndicators.Domain
                iscontext: true
          - operator: append
            args:
              item:
                value:
                  simple: ExtractedIndicators.URL
                iscontext: true
          - operator: append
            args:
              item:
                value:
                  simple: ExtractedIndicators.CVE
                iscontext: true
          - operator: append
            args:
              item:
                value:
                  simple: ExtractedIndicators.File
                iscontext: true
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 0,
          "y": 330
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  '53':
    id: '53'
    taskid: bb84dbc9-c8c3-4f8d-8801-7d200ab431c8
    type: regular
    task:
      id: bb84dbc9-c8c3-4f8d-8801-7d200ab431c8
      version: -1
      name: Tag File indicators
      description: commands.local.cmd.new.indicator
      script: Builtin|||createNewIndicator
      type: regular
      iscommand: true
      brand: Builtin
    nexttasks:
      '#none#':
      - '52'
    scriptarguments:
      retry-count:
        simple: '3'
      retry-interval:
        simple: '2'
      tags:
        simple: CVE-2022-30190
      type:
        simple: File
      value:
        complex:
          root: ExtractedIndicators.File
          filters:
          - - operator: isNotEmpty
              left:
                value:
                  simple: ExtractedIndicators.File
                iscontext: true
          transformers:
          - operator: uniq
    separatecontext: false
    continueonerror: true
    view: |-
      {
        "position": {
          "x": 0,
          "y": 140
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  '54':
    id: '54'
    taskid: e2dbc165-dc88-431d-81be-daa4b67b65d2
    type: regular
    task:
      id: e2dbc165-dc88-431d-81be-daa4b67b65d2
      version: -1
      name: Tag CVE indicators
      description: commands.local.cmd.new.indicator
      script: Builtin|||createNewIndicator
      type: regular
      iscommand: true
      brand: Builtin
    nexttasks:
      '#none#':
      - '52'
    scriptarguments:
      retry-count:
        simple: '3'
      retry-interval:
        simple: '2'
      tags:
        simple: Follina, MSDT
      type:
        simple: CVE
      value:
        complex:
          root: inputs.RelatedCVEs
          transformers:
          - operator: split
            args:
              delimiter:
                value:
                  simple: ', '
    separatecontext: false
    continueonerror: true
    view: |-
      {
        "position": {
          "x": 440,
          "y": 140
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  '55':
    id: '55'
    taskid: d7532ae2-4403-4b51-840b-395a955870ca
    type: regular
    task:
      id: d7532ae2-4403-4b51-840b-395a955870ca
      version: -1
      name: Tag Domain indicators
      description: commands.local.cmd.new.indicator
      script: Builtin|||createNewIndicator
      type: regular
      iscommand: true
      brand: Builtin
    nexttasks:
      '#none#':
      - '52'
    scriptarguments:
      retry-count:
        simple: '3'
      retry-interval:
        simple: '2'
      tags:
        simple: CVE-2022-30190
      type:
        simple: URL
      value:
        complex:
          root: ExtractedIndicators.Domain
          filters:
          - - operator: isNotEmpty
              left:
                value:
                  simple: ExtractedIndicators.Domain
                iscontext: true
          transformers:
          - operator: uniq
    separatecontext: false
    continueonerror: true
    view: |-
      {
        "position": {
          "x": -450,
          "y": 140
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  '56':
    id: '56'
    taskid: 7f27889c-5916-47a1-8731-154b05fd82b1
    type: playbook
    task:
      id: 7f27889c-5916-47a1-8731-154b05fd82b1
      version: -1
      name: QRadar search for msdt.exe launching via the command line
      description: This playbook runs a QRadar query and return its results to the context.
      playbookName: QRadarFullSearch
      type: playbook
      iscommand: false
      brand: ''
    nexttasks:
      '#none#':
      - '29'
    scriptarguments:
      interval:
        simple: '1'
      query_expression:
        simple: SELECT UTF8(payload) from events where LOGSOURCETYPENAME(devicetype)='Microsoft Windows Security Event Log' and ("Process CommandLine" ilike '%PCWDiagnostic%' and ("Process CommandLine" ilike '%ms-msdt:/id%' OR "Process CommandLine" ilike '%ms-msdt:-id%') OR "Process CommandLine" ilike '%invoke%')
      timeout:
        simple: '600'
    separatecontext: true
    loop:
      iscommand: false
      exitCondition: ''
      wait: 1
      max: 0
    view: |-
      {
        "position": {
          "x": -1990,
          "y": 1300
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: true
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "57":
    id: "57"
    taskid: d46c5404-0fe3-49c6-84bc-3b789a215bb3
    type: title
    task:
      id: d46c5404-0fe3-49c6-84bc-3b789a215bb3
      version: -1
      name: Handle Rapid Breach Response Layout
      type: title
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "58"
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 0,
          "y": 510
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "58":
    id: "58"
    taskid: fae48ca5-0cde-4a0f-8568-8822f2613327
    type: playbook
    task:
      id: fae48ca5-0cde-4a0f-8568-8822f2613327
      version: -1
      name: Rapid Breach Response - Set Incident Info
      playbookName: Rapid Breach Response - Set Incident Info
      type: playbook
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "9"
    scriptarguments:
      SourceOfIndicators:
        complex:
          root: http.parsedBlog
          accessor: sourceLink
      countTotalIndicators:
        complex:
          root: ExtractedIndicators
          accessor: Domain
          transformers:
          - operator: append
            args:
              item:
                value:
                  simple: ExtractedIndicators.IP
          - operator: append
            args:
              item:
                value:
                  simple: ExtractedIndicators.URL
          - operator: append
            args:
              item:
                value:
                  simple: ExtractedIndicators.File
          - operator: append
            args:
              item:
                value:
                  simple: ExtractedIndicators.CVE
          - operator: uniq
          - operator: count
      playbookDescription:
        complex:
          root: inputs.PlaybookDescription
    separatecontext: true
    continueonerrortype: ""
    loop:
      iscommand: false
      exitCondition: ""
      wait: 1
      max: 100
    view: |-
      {
        "position": {
          "x": 0,
          "y": 640
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
system: true
view: |-
  {
    "linkLabelsPosition": {
      "11_14_Yes": 0.37,
      "11_29_no": 0.25,
      "12_15_Yes": 0.38,
      "12_29_#default#": 0.11,
      "12_56_Yes": 0.69,
      "19_20_yes": 0.4,
      "19_29_#default#": 0.32,
      "20_29_no": 0.12,
      "21_17_Yes": 0.47,
      "21_29_no": 0.3,
      "23_24_yes": 0.37,
      "23_29_no": 0.29,
      "37_40_No": 0.63
    },
    "paper": {
      "dimensions": {
        "height": 3455,
        "width": 4120,
        "x": -1990,
        "y": -780
      }
    }
  }
inputs:
- key: SplunkIndex
  value:
    simple: '*'
  required: false
  description: Splunk's index name in which to search. Default is "*" - All.
  playbookInputQuery:
- key: SplunkEarliestTime
  value:
    simple: now
  required: false
  description: Splunk's earliest time to search.
  playbookInputQuery:
- key: SplunkLatestTime
  value:
    simple: -1d@d
  required: false
  description: Splunk's latest time to search.
  playbookInputQuery:
- key: ElasticIndex
  value: {}
  required: false
  description: Elastic's index name in which to search.
  playbookInputQuery:
- key: QRadarTimeRange
  value:
    simple: Last 1 DAYS
  required: false
  description: QRadar's query time range.
  playbookInputQuery:
- key: PlaybookDescription
  value:
    simple: "On **May 27th**, a new Microsoft Office Zero-Day was discovered by [Nao_sec](https://twitter.com/nao_sec). \n\nThe new Zero-Day is a remote code execution vulnerability that exists when MSDT is called using the URL protocol from a calling application such as Word. \n\nOn **May 30th**, Microsoft assigned **CVE-2022-30190** to the MSDT vulnerability, aka **Follina vulnerability**.\n\nThis playbook includes the following tasks:\n\n* Collect detection rules.\n* Exploitation patterns hunting using Cortex XDR - XQL Engine and 3rd party SIEM products.\n* Cortex XDR BIOCs coverage.\n* Provides Microsoft workarounds and detection capabilities.\n\n**More information:**\n\n[Guidance for CVE-2022-30190 Microsoft Support Diagnostic Tool Vulnerability\n](https://msrc-blog.microsoft.com/2022/05/30/guidance-for-cve-2022-30190-microsoft-support-diagnostic-tool-vulnerability/)\n\n**Note:** This is a beta playbook, which lets you implement and test pre-release software. Since the playbook is beta, it might contain bugs. Updates to the pack during the beta phase might include non-backward compatible features. We appreciate your feedback on the quality and usability of the pack to help us identify issues, fix them, and continually improve."
  required: false
  description: The playbook's description.
  playbookInputQuery:
- key: RunXQLHuntingQueries
  value:
    simple: 'False'
  required: false
  description: Whether to execute the XQL queries.
  playbookInputQuery:
- key: RelatedCVEs
  value:
    simple: CVE-2022-30190
  required: false
  description: Follina vulnerability CVE reference.
  playbookInputQuery:
outputs: []
tests:
- No tests (auto formatted)
fromversion: 6.2.0