Codecov Breach - Bash Uploader

This playbook includes the following tasks: - Search for the Security Notice email sent from Codecov. - Collect indicators to be used in your threat hunting process. - Query network logs to detect related activity. - Search for the use of Codecov bash uploader in GitHub repositories - Query Panorama to search for logs with related anti-spyware signatures - Data Exfiltration Traffic Detection - Malicious Modified Shell Script Detection Note: This is a beta playbook, which lets you implement and test pre-release software. Since the playbook is beta, it might contain bugs. Updates to the pack during the beta phase might include non-backward compatible features. We appreciate your feedback on the quality and usability of the pack to help us identify issues, fix them, and continually improve. More information: [Codecov Security Notice](https://about.codecov.io/security-update/)

Rapid Breach Response · 25 tasks · 6 inputs · 0 outputs

Details

IDCodecov Breach - Bash Uploader
From Version5.5.0
Tasks25

README

This playbook includes the following tasks:

  • Search for the Security Notice email sent from Codecov.
  • Collect indicators to be used in your threat hunting process.
  • Query network logs to detect related activity.
  • Search for the use of Codecov bash uploader in GitHub repositories
  • Query Panorama to search for logs with related anti-spyware signatures
    • Data Exfiltration Traffic Detection
    • Malicious Modified Shell Script Detection
      Note: This is a beta playbook, which lets you implement and test pre-release software. Since the playbook is beta, it might contain bugs. Updates to the pack during the beta phase might include non-backward compatible features. We appreciate your feedback on the quality and usability of the pack to help us identify issues, fix them, and continually improve.

More information:
Codecov Security Notice

Dependencies

This playbook uses the following sub-playbooks, integrations, and scripts.

Sub-playbooks

  • Splunk Indicator Hunting
  • Panorama search thread-ids in threat logs
  • QRadar Indicator Hunting V2
  • Palo Alto Networks - Hunting And Threat Detection

Integrations

This playbook does not use any integrations.

Scripts

This playbook does not use any scripts.

Commands

  • extractIndicators
  • GitHub-search-code
  • ews-search-mailbox

Playbook Inputs


Name Description Default Value Required
KnownRelatedIOCs Known related IOCs to the Codecov Bash Uploader breach to hunt. 104.248.94.23 Optional
CustomIOCs Add your own custom Codecov Bash Uploader breach IOCs to hunt.   Optional
EWSSearchQuery The EWS query to find the Codecov security notice email From:security@codecov.io AND Subject:Bash Uploader Security Notice AND Received:three months Optional
EWSSearchQuery_Limit The limit of results to return from the search 50 Optional
Github_Code_Search_query Github query to search for Codecov bash uploader use. https://codecov.io/bash+in:file Optional
InternalRange A list of internal IP ranges to check IP addresses against. The comma-separated list should be provided in CIDR notation. For example, a list of ranges would be: “172.16.0.0/12,10.0.0.0/8,192.168.0.0/16” (without quotes). lists.PrivateIPs Optional

Playbook Outputs


There are no outputs for this playbook.

Playbook Image


Codecov Breach - Bash Uploader

Inputs

  • KnownRelatedIOCs — Known related IOCs to the Codecov Bash Uploader breach to hunt.
  • CustomIOCs — Add your own custom Codecov Bash Uploader breach IOCs to hunt.
  • EWSSearchQuery — The EWS query to find the Codecov security notice email
  • EWSSearchQuery_Limit — The limit of results to return from the search
  • Github_Code_Search_query — Github query to search for Codecov bash uploader use.
  • InternalRange — A list of internal IP ranges to check IP addresses against. The comma-separated list should be provided in CIDR notation. For example, a list of ranges would be: "172.16.0.0/12,10.0.0.0/8,192.168.0.0/16" (without quotes).

Commands used

GitHub-search-code ews-search-mailbox extractIndicators

Flowchart

yes yes Yes Yes yes Start Start Extract IOCs Extract IOCs Hunt IOCs Hunt IOCs Is EWS enabled? Is EWS enabled? Check if compromised Check if compromised Codecov security notice email check Codecov security notice e... Search for Codecov security notice email - ews-search-mailbox Search for Codecov securi... ews-search-mailbox Found Codecov security notice emails? Found Codecov security no... Check for affected Bash Uploader possible impact Check for affected Bash U... Palo Alto Networks - Hunting And Threat Detection - Palo Alto Networks - Hunting And Threat Detection Palo Alto Networks - Hunt... Palo Alto Networks - Hunting ... QRadar Indicator Hunting V2 - QRadar Indicator Hunting V2 QRadar Indicator Hunting V2 QRadar Indicator Hunting V2 Splunk Indicator Hunting - Splunk Indicator Hunting Splunk Indicator Hunting Splunk Indicator Hunting SIEM Hunting SIEM Hunting Hunt Network Logs Hunt Network Logs Extract indicators from known and custom inputs - extractIndicators Extract indicators from k... extractIndicators Remediation Steps Remediation Steps Re-roll affected users Re-roll affected users Check env command in your CI pipeline Check env command in your... Used local stored version of a Bash Uploader? Used local stored version... Check using version Check using version Done Done Panorama search thread-ids in threat logs - Panorama Query Logs Panorama search thread-id... Panorama Query Logs Scope affected repositories Scope affected repositories Search Codecov in Git repository - GitHub-search-code Search Codecov in Git rep... GitHub-search-code Is GitHub integration enabled? Is GitHub integration ena...
id: Codecov Breach - Bash Uploader
version: -1
name: Codecov Breach - Bash Uploader
description: |-
  This playbook includes the following tasks:
  - Search for the Security Notice email sent from Codecov.
  - Collect indicators to be used in your threat hunting process.
  - Query network logs to detect related activity.
  - Search for the use of Codecov bash uploader in GitHub repositories
  - Query Panorama to search for logs with related anti-spyware signatures
      - Data Exfiltration Traffic Detection
      - Malicious Modified Shell Script Detection
  Note: This is a beta playbook, which lets you implement and test pre-release software. Since the playbook is beta, it might contain bugs. Updates to the pack during the beta phase might include non-backward compatible features. We appreciate your feedback on the quality and usability of the pack to help us identify issues, fix them, and continually improve.

  More information:
  [Codecov Security Notice](https://about.codecov.io/security-update/)
starttaskid: "0"
tasks:
  "0":
    id: "0"
    taskid: 1d029b7d-0fcf-4717-8cc6-0e174deed3af
    type: start
    task:
      id: 1d029b7d-0fcf-4717-8cc6-0e174deed3af
      version: -1
      name: ""
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "7"
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 220,
          "y": -870
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
  "1":
    id: "1"
    taskid: 448e1a26-0530-4faf-8166-e154230e59cb
    type: title
    task:
      id: 448e1a26-0530-4faf-8166-e154230e59cb
      version: -1
      name: Extract IOCs
      type: title
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "21"
    separatecontext: false
    view: |-
      {
        "position": {
          "x": -710,
          "y": 325
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
  "5":
    id: "5"
    taskid: efe56337-4796-472c-8539-49f568f07e6b
    type: title
    task:
      id: efe56337-4796-472c-8539-49f568f07e6b
      version: -1
      name: Hunt IOCs
      type: title
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "19"
      - "20"
    separatecontext: false
    view: |-
      {
        "position": {
          "x": -710,
          "y": 680
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
  "6":
    id: "6"
    taskid: 05d283a2-28d2-4112-8cb6-d8ba3e67e80c
    type: condition
    task:
      id: 05d283a2-28d2-4112-8cb6-d8ba3e67e80c
      version: -1
      name: Is EWS enabled?
      description: Checks if EWS integration enabled
      type: condition
      iscommand: false
      brand: ""
    nexttasks:
      '#default#':
      - "13"
      "yes":
      - "11"
    separatecontext: false
    conditions:
    - label: "yes"
      condition:
      - - operator: isEqualString
          left:
            value:
              complex:
                root: modules
                filters:
                - - operator: isEqualString
                    left:
                      value:
                        simple: modules.brand
                      iscontext: true
                    right:
                      value:
                        simple: EWS v2
                accessor: state
            iscontext: true
          right:
            value:
              simple: active
    view: |-
      {
        "position": {
          "x": 220,
          "y": -420
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
  "7":
    id: "7"
    taskid: bc99d94d-90fb-4d69-8062-f1e4e54dd719
    type: title
    task:
      id: bc99d94d-90fb-4d69-8062-f1e4e54dd719
      version: -1
      name: Check if compromised
      type: title
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "8"
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 220,
          "y": -700
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
  "8":
    id: "8"
    taskid: 9aebf153-14d8-4efa-8cbf-3241f0080615
    type: title
    task:
      id: 9aebf153-14d8-4efa-8cbf-3241f0080615
      version: -1
      name: Codecov security notice email check
      type: title
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "6"
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 220,
          "y": -560
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
  "11":
    id: "11"
    taskid: 3b9af3e0-4fe9-4452-8f84-3e67ff7defd8
    type: regular
    task:
      id: 3b9af3e0-4fe9-4452-8f84-3e67ff7defd8
      version: -1
      name: 'Search for Codecov security notice email '
      description: Searches for items in the specified mailbox. Specific permissions
        are needed for this operation to search in a target mailbox other than the
        default.
      script: '|||ews-search-mailbox'
      type: regular
      iscommand: true
      brand: ""
    nexttasks:
      '#none#':
      - "12"
    scriptarguments:
      folder-path: {}
      is-public: {}
      limit:
        complex:
          root: inputs.EWSSearchQuery_Limit
      message-id: {}
      query:
        complex:
          root: inputs.EWSSearchQuery
      selected-fields: {}
      target-mailbox: {}
    separatecontext: false
    view: |-
      {
        "position": {
          "x": -710,
          "y": -245
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: true
    quietmode: 0
  "12":
    id: "12"
    taskid: f03d42f1-189a-47d9-8c7b-7a67827fd24f
    type: condition
    task:
      id: f03d42f1-189a-47d9-8c7b-7a67827fd24f
      version: -1
      name: Found Codecov security notice emails?
      description: Searches for the Codecov Security Notice email
      type: condition
      iscommand: false
      brand: ""
    nexttasks:
      '#default#':
      - "13"
      "yes":
      - "1"
    separatecontext: false
    conditions:
    - label: "yes"
      condition:
      - - operator: isNotEmpty
          left:
            value:
              complex:
                root: EWS
                accessor: Items
            iscontext: true
    view: |-
      {
        "position": {
          "x": -710,
          "y": -55
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
  "13":
    id: "13"
    taskid: 1ea37a97-35d8-49fa-8233-a594dfdf2d57
    type: condition
    task:
      id: 1ea37a97-35d8-49fa-8233-a594dfdf2d57
      version: -1
      name: Check for affected Bash Uploader possible impact
      description: |
        If you used the following between January 31, 2021 and April 1, 2021, and did not conduct a checksum validation:
        Codecov-bash (bash uploader)
        Codecov-action (Github)
        Codecov-circleci-orb
        Codecov-bitrise-step
      type: condition
      iscommand: false
      brand: ""
    nexttasks:
      '#default#':
      - "27"
      "Yes":
      - "1"
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 220,
          "y": 140
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
  "14":
    id: "14"
    taskid: bc58af28-06c5-45a7-8b85-234f5c4ceea4
    type: playbook
    task:
      id: bc58af28-06c5-45a7-8b85-234f5c4ceea4
      version: -1
      name: Palo Alto Networks - Hunting And Threat Detection
      description: "This is a multipurpose playbook used for hunting and threat detection.\
        \ The playbook receives inputs based on hashes, IP addresses, or domain names\
        \ provided manually or from outputs by other playbooks. \nWith the received\
        \ indicators, the playbook leverages data received by PANW products including,\
        \ Cortex Data Lake, Autofocus and Pan-OS to search for IP addresses, host\
        \ names and users related to the provided indicators.\nThe output provided\
        \ by the playbook facilitates pivoting searches for possibly affected IP addresses\
        \ or users."
      playbookName: Palo Alto Networks - Hunting And Threat Detection
      type: playbook
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "29"
    scriptarguments:
      IPAddresses:
        complex:
          root: IP
          accessor: Address
          transformers:
          - operator: uniq
      InternalDomainName: {}
      InternalHostRegex: {}
      InternalRange:
        simple: ${inputs.InternalRange}
      MD5:
        complex:
          root: File
          accessor: MD5
          transformers:
          - operator: uniq
      SHA1: {}
      SHA256:
        complex:
          root: File
          accessor: SHA256
          transformers:
          - operator: uniq
      URLDomain: {}
    separatecontext: true
    loop:
      iscommand: false
      exitCondition: ""
      wait: 1
      max: 100
    view: |-
      {
        "position": {
          "x": -960,
          "y": 960
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: true
    quietmode: 0
  "16":
    id: "16"
    taskid: 974252c0-5c9b-4be0-8467-dfd39c59e3d1
    type: playbook
    task:
      id: 974252c0-5c9b-4be0-8467-dfd39c59e3d1
      version: -1
      name: QRadar Indicator Hunting V2
      description: 'The Playbook queries QRadar SIEM for indicators such as file hashes,
        IP addresses, domains, or urls. '
      playbookName: QRadar Indicator Hunting V2
      type: playbook
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "29"
    scriptarguments:
      IPAddress:
        complex:
          root: IP
          accessor: Address
          transformers:
          - operator: uniq
      InternalRange:
        simple: ${inputs.InternalRange}
      InvestigationIPFields:
        simple: sourceip,destinationip
      InvestigationUserFields:
        simple: username
      MD5:
        complex:
          root: File
          accessor: MD5
          transformers:
          - operator: uniq
      QradarIPfield:
        simple: sourceip,destinationip
      QradarMD5Field: {}
      QradarSHA1Field: {}
      QradarSHA256Field: {}
      QradarURLDomainField: {}
      SHA1: {}
      SHA256:
        complex:
          root: File
          accessor: SHA256
          transformers:
          - operator: uniq
      TimeFrame:
        simple: LAST 7 DAYS
      URLDomain: {}
    separatecontext: true
    loop:
      iscommand: false
      exitCondition: ""
      wait: 1
      max: 100
    view: |-
      {
        "position": {
          "x": -470,
          "y": 960
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: true
    quietmode: 0
  "18":
    id: "18"
    taskid: e2c50a93-9dcd-4b92-8fe6-0e19a0ebeeba
    type: playbook
    task:
      id: e2c50a93-9dcd-4b92-8fe6-0e19a0ebeeba
      version: -1
      name: Splunk Indicator Hunting
      description: This playbook queries Splunk for indicators such as file hashes,
        IP addresses, domains, or urls. It outputs detected users, ip addresses, and
        hostnames related to the indicators.
      playbookName: Splunk Indicator Hunting
      type: playbook
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "29"
    scriptarguments:
      HostFieldsToReturn: {}
      IPAddress:
        complex:
          root: IP
          accessor: Address
          transformers:
          - operator: uniq
      IPFieldsToReturn: {}
      IndexName:
        simple: '*'
      InternalDomainName: {}
      InternalHostRegex: {}
      InternalIPRange: {}
      MD5:
        complex:
          root: File
          accessor: MD5
          transformers:
          - operator: uniq
      SHA1: {}
      SHA256:
        complex:
          root: File
          accessor: SHA256
          transformers:
          - operator: uniq
      SelectFields:
        simple: source,timestamp
      SplunkIPField: {}
      SplunkMD5Field: {}
      SplunkSHA1Field: {}
      SplunkSHA256Field: {}
      SplunkURLDomainField: {}
      URLDomain: {}
      UserFieldsToReturn: {}
      earliest_time:
        simple: -1d
      event_limit:
        simple: "100"
      latest_time: {}
    separatecontext: true
    loop:
      iscommand: false
      exitCondition: ""
      wait: 1
      max: 100
    view: |-
      {
        "position": {
          "x": -20,
          "y": 960
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: true
    quietmode: 0
  "19":
    id: "19"
    taskid: a8c96f19-07cb-456b-8f46-71328d1b7e86
    type: title
    task:
      id: a8c96f19-07cb-456b-8f46-71328d1b7e86
      version: -1
      name: SIEM Hunting
      type: title
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "16"
      - "18"
    separatecontext: false
    view: |-
      {
        "position": {
          "x": -240,
          "y": 820
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
  "20":
    id: "20"
    taskid: 3b9ef253-5901-48dc-89c8-39decba4f79c
    type: title
    task:
      id: 3b9ef253-5901-48dc-89c8-39decba4f79c
      version: -1
      name: Hunt Network Logs
      type: title
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "14"
      - "28"
    separatecontext: false
    view: |-
      {
        "position": {
          "x": -1190,
          "y": 820
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
  "21":
    id: "21"
    taskid: cba1718f-0b78-4ccb-8c15-6a2b7fa4ec74
    type: regular
    task:
      id: cba1718f-0b78-4ccb-8c15-6a2b7fa4ec74
      version: -1
      name: Extract indicators from known and custom inputs
      description: commands.local.cmd.extract.indicators
      script: Builtin|||extractIndicators
      type: regular
      iscommand: true
      brand: Builtin
    nexttasks:
      '#none#':
      - "5"
    scriptarguments:
      entryID: {}
      filePath: {}
      investigationID: {}
      text:
        complex:
          root: inputs.KnownRelatedIOCs
          transformers:
          - operator: append
            args:
              item:
                value:
                  simple: inputs.CustomIOCs
                iscontext: true
    reputationcalc: 2
    separatecontext: false
    view: |-
      {
        "position": {
          "x": -710,
          "y": 500
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
  "22":
    id: "22"
    taskid: 8d37d324-0f2c-4564-8493-b1af87f46e79
    type: title
    task:
      id: 8d37d324-0f2c-4564-8493-b1af87f46e79
      version: -1
      name: Remediation Steps
      type: title
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "23"
    separatecontext: false
    view: |-
      {
        "position": {
          "x": -710,
          "y": 1650
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
  "23":
    id: "23"
    taskid: 87535b78-126e-4499-89fe-d271f0684c75
    type: regular
    task:
      id: 87535b78-126e-4499-89fe-d271f0684c75
      version: -1
      name: 'Re-roll affected users '
      description: Re-roll all of credentials for affected users, tokens, or keys
        located in the environment variables in their CI processes that used one of
        Codecov’s Bash Uploaders.
      type: regular
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "24"
    separatecontext: false
    view: |-
      {
        "position": {
          "x": -710,
          "y": 1800
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
  "24":
    id: "24"
    taskid: 200cb34a-de6d-4276-8ab3-d2e86f790163
    type: regular
    task:
      id: 200cb34a-de6d-4276-8ab3-d2e86f790163
      version: -1
      name: Check env command in your CI pipeline
      description: 'You can determine the keys and tokens that are surfaced to your
        CI environment by running the env command in your CI pipeline. If anything
        returned from that command is considered private or sensitive, invalidating
        the credential and generating a new one. '
      type: regular
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "25"
    separatecontext: false
    view: |-
      {
        "position": {
          "x": -710,
          "y": 1970
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
  "25":
    id: "25"
    taskid: 421e612b-e133-4596-8f81-a4e8f2444cc3
    type: condition
    task:
      id: 421e612b-e133-4596-8f81-a4e8f2444cc3
      version: -1
      name: Used local stored version of a Bash Uploader?
      description: Check if the Bash Uploader is locally stored.
      type: condition
      iscommand: false
      brand: ""
    nexttasks:
      '#default#':
      - "27"
      "Yes":
      - "26"
    separatecontext: false
    view: |-
      {
        "position": {
          "x": -710,
          "y": 2140
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
  "26":
    id: "26"
    taskid: c56d1f45-59a9-4a89-839c-5825e79875a3
    type: regular
    task:
      id: c56d1f45-59a9-4a89-839c-5825e79875a3
      version: -1
      name: Check using version
      description: |-
        if you use a locally stored version of a Bash Uploader, you should check that version for the following:
        **curl -sm 0.5 -d “$(git remote -v)**

        If this appears anywhere in your locally stored Bash Uploader, you should immediately replace the bash files with the most recent version from https://codecov.io/bash.
      type: regular
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "27"
    separatecontext: false
    view: |-
      {
        "position": {
          "x": -50,
          "y": 2320
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
  "27":
    id: "27"
    taskid: 7647c176-90dc-4054-8eeb-f3ea3abdb691
    type: title
    task:
      id: 7647c176-90dc-4054-8eeb-f3ea3abdb691
      version: -1
      name: Done
      type: title
      iscommand: false
      brand: ""
      description: ''
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 220,
          "y": 2540
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
  "28":
    id: "28"
    taskid: a037cfcc-aa5a-417c-81c7-dd569be7b783
    type: playbook
    task:
      id: a037cfcc-aa5a-417c-81c7-dd569be7b783
      version: -1
      name: Panorama search thread-ids in threat logs
      description: 'Query Panorama Logs of types: traffic, threat, url, data-filtering
        and wildfire.'
      playbookName: Panorama Query Logs
      type: playbook
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "29"
    scriptarguments:
      action: {}
      addr-dst: {}
      addr-src: {}
      filedigest: {}
      ip: {}
      log_type:
        simple: threat
      port-dst: {}
      query:
        simple: (threatid eq 86353) or (threatid eq 86355)
      rule: {}
      time-generated: {}
      url: {}
      zone-dst: {}
      zone-src: {}
    separatecontext: true
    loop:
      iscommand: false
      exitCondition: ""
      wait: 1
      max: 100
    view: |-
      {
        "position": {
          "x": -1430,
          "y": 960
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: true
    quietmode: 0
  "29":
    id: "29"
    taskid: b1872629-a361-4e70-8926-f496e1128990
    type: title
    task:
      id: b1872629-a361-4e70-8926-f496e1128990
      version: -1
      name: Scope affected repositories
      type: title
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "31"
    separatecontext: false
    view: |-
      {
        "position": {
          "x": -710,
          "y": 1160
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
  "30":
    id: "30"
    taskid: 40bd0498-02d5-450c-8d93-2e436e69dec5
    type: regular
    task:
      id: 40bd0498-02d5-450c-8d93-2e436e69dec5
      version: -1
      name: Search Codecov in Git repository
      description: Searches for code in repositories that match a given query.
      script: '|||GitHub-search-code'
      type: regular
      iscommand: true
      brand: ""
    nexttasks:
      '#none#':
      - "22"
    scriptarguments:
      limit: {}
      page_number: {}
      page_size: {}
      query:
        complex:
          root: inputs.Github_Code_Search_query
    separatecontext: false
    view: |-
      {
        "position": {
          "x": -430,
          "y": 1480
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: true
    quietmode: 0
  "31":
    id: "31"
    taskid: 3e428184-fcd8-4c78-830d-01779ad8f0b5
    type: condition
    task:
      id: 3e428184-fcd8-4c78-830d-01779ad8f0b5
      version: -1
      name: Is GitHub integration enabled?
      description: Checks if GitHub integration enabled.
      type: condition
      iscommand: false
      brand: ""
    nexttasks:
      '#default#':
      - "22"
      "yes":
      - "30"
    separatecontext: false
    conditions:
    - label: "yes"
      condition:
      - - operator: isEqualString
          left:
            value:
              complex:
                root: modules
                filters:
                - - operator: isEqualString
                    left:
                      value:
                        simple: modules.brand
                      iscontext: true
                    right:
                      value:
                        simple: GitHub
                accessor: state
            iscontext: true
          right:
            value:
              simple: active
    view: |-
      {
        "position": {
          "x": -710,
          "y": 1310
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
view: |-
  {
    "linkLabelsPosition": {
      "12_13_#default#": 0.2,
      "12_1_yes": 0.46,
      "13_1_Yes": 0.24,
      "13_27_#default#": 0.1,
      "25_26_Yes": 0.43,
      "25_27_#default#": 0.2,
      "31_22_#default#": 0.56,
      "31_30_yes": 0.54,
      "6_11_yes": 0.17,
      "6_13_#default#": 0.28
    },
    "paper": {
      "dimensions": {
        "height": 3475,
        "width": 2030,
        "x": -1430,
        "y": -870
      }
    }
  }
inputs:
- key: KnownRelatedIOCs
  value:
    simple: 104.248.94.23
  required: false
  description: Known related IOCs to the Codecov Bash Uploader breach to hunt.
  playbookInputQuery:
- key: CustomIOCs
  value: {}
  required: false
  description: Add your own custom Codecov Bash Uploader breach IOCs to hunt.
  playbookInputQuery:
- key: EWSSearchQuery
  value:
    simple: From:security@codecov.io AND Subject:Bash Uploader Security Notice AND
      Received:three months
  required: false
  description: The EWS query to find the Codecov security notice email
  playbookInputQuery:
- key: EWSSearchQuery_Limit
  value:
    simple: "50"
  required: false
  description: The limit of results to return from the search
  playbookInputQuery:
- key: Github_Code_Search_query
  value:
    simple: https://codecov.io/bash+in:file
  required: false
  description: Github query to search for Codecov bash uploader use.
  playbookInputQuery:
- key: InternalRange
  value:
    complex:
      root: lists
      accessor: PrivateIPs
      transformers:
      - operator: RegexExtractAll
        args:
          error_if_no_match: {}
          ignore_case: {}
          multi_line: {}
          period_matches_newline: {}
          regex:
            value:
              simple: (\b(?:\d{1,3}\.){3}\d{1,3}\b/\d{1,2})
          unpack_matches: {}
      - operator: join
        args:
          separator:
            value:
              simple: ','
  required: false
  description: 'A list of internal IP ranges to check IP addresses against. The comma-separated list should be provided in CIDR notation. For example, a list of ranges would be: "172.16.0.0/12,10.0.0.0/8,192.168.0.0/16" (without quotes).'
  playbookInputQuery:
outputs: []
tests:
- No tests (auto formatted)
fromversion: 5.5.0