Cortex XDR - CVE-2025-31324 - SAP NetWeaver Visual Composer

This playbook should be triggered manually or can be configured as a job. Please create a new incident and choose the Cortex XDR - CVE-2025-31324 - SAP NetWeaver Visual Composer playbook and Rapid Breach Response incident type. CVE-2025-31324 is a critical zero-day vulnerability affecting the Metadata Uploader component of SAP NetWeaver Visual Composer. The vulnerability arises from missing authorization checks, allowing unauthenticated attackers to upload malicious executable binaries. Exploitation of this flaw can lead to full remote code execution (RCE) on affected systems, posing a significant risk to confidentiality, integrity, and availability. ## CVE-2025-31324 - SAP NetWeaver RCE Vulnerability ## Vulnerability Overview - **Component Affected**: SAP NetWeaver Visual Composer Metadata Uploader - **Endpoint**: `/developmentserver/metadatauploader` - **CVE ID**: CVE-2025-31324 - **CVSS Score**: 10.0 (Critical) - **Exploitability**: Unauthenticated remote attackers can exploit this without user interaction This flaw allows unauthenticated attackers to upload arbitrary files (e.g., JSP web shells), enabling remote code execution with the same privileges as the SAP application server process. [Source: Unit42 - Palo Alto Networks](https://unit42.paloaltonetworks.com/threat-brief-sap-netweaver-cve-2025-31324/) ## Mitigation and Recommendations - **Apply Patch**: SAP Note #3594142 (released April 24, 2025) - **Disable Visual Composer** if not in use - **Restrict Access** to the vulnerable endpoint - **Monitor for IoCs** in `/irj/servlet_jsp/irj/root/` and suspicious traffic ## Conclusion CVE-2025-31324 is actively exploited and is critically severe. Organizations should patch immediately, monitor for compromise, and disable or restrict vulnerable components. [View official CVE details on NIST](https://nvd.nist.gov/vuln/detail/CVE-2025-31324) ## Playbook Triggers - Manually - "CVE Exploitation - 986328356" Agent rule ## Playbook Flow - Collects IoCs from Unit42 blog. - Downloads Sigma rules. - Search for CVE Exploitation alerts. - Directory enumeration to identify if there are already any suspicious files that might indicate a webshell. - Using XQL, identify potential SAP NetWeaver instances in your environment. - Using XQL, check if there are events that point to any potential webshells downloaded in the directories. - Hunt the IoCs using Panorama and 3rd party SIEM. - Remediate using "Block Indicators - Generic v3" playbook. - Provides Mitigation recommendations. Note: This is a beta playbook, which lets you implement and test pre-release software. Since the playbook is beta, it might contain bugs. Updates to the pack during the beta phase might include non-backward compatible features. We appreciate your feedback on the quality and usability of the pack to help us identify issues, fix them, and continually improve.

CVE-2025-31324 - SAP NetWeaver Visual Composer · 63 tasks · 4 inputs · 0 outputs

Details

IDCortex XDR - CVE-2025-31324 - SAP NetWeaver Visual Composer
From Version6.10.0
Tasks63
TagsRapid Breach Response CVE-2025-31324

README

This playbook should be triggered manually or can be configured as a job.
Please create a new incident and choose the Cortex XDR - CVE-2025-31324 - SAP NetWeaver Visual Composer playbook and Rapid Breach Response incident type.

CVE-2025-31324 is a critical zero-day vulnerability affecting the Metadata Uploader component of SAP NetWeaver Visual Composer. The vulnerability arises from missing authorization checks, allowing unauthenticated attackers to upload malicious executable binaries. Exploitation of this flaw can lead to full remote code execution (RCE) on affected systems, posing a significant risk to confidentiality, integrity, and availability.

CVE-2025-31324 - SAP NetWeaver RCE Vulnerability

Vulnerability Overview

  • Component Affected: SAP NetWeaver Visual Composer Metadata Uploader
  • Endpoint: /developmentserver/metadatauploader
  • CVE ID: CVE-2025-31324
  • CVSS Score: 10.0 (Critical)
  • Exploitability: Unauthenticated remote attackers can exploit this without user interaction

This flaw allows unauthenticated attackers to upload arbitrary files (e.g., JSP web shells), enabling remote code execution with the same privileges as the SAP application server process.
Source: Unit42 - Palo Alto Networks

Mitigation and Recommendations

  • Apply Patch: SAP Note #3594142 (released April 24, 2025)
  • Disable Visual Composer if not in use
  • Restrict Access to the vulnerable endpoint
  • Monitor for IoCs in /irj/servlet_jsp/irj/root/ and suspicious traffic

Conclusion

CVE-2025-31324 is actively exploited and is critically severe. Organizations should patch immediately, monitor for compromise, and disable or restrict vulnerable components.

View official CVE details on NIST

Playbook Triggers

  • Manually
  • “CVE Exploitation - 986328356” Agent rule

Playbook Flow

  • Collects IoCs from Unit42 blog.
  • Downloads Sigma rules.
  • Search for CVE Exploitation alerts.
  • Directory enumeration to identify if there are already any suspicious files that might indicate a webshell.
  • Using XQL, identify potential SAP NetWeaver instances in your environment.
  • Using XQL, check if there are events that point to any potential webshells downloaded in the directories.
  • Hunt the IoCs using Panorama and 3rd party SIEM.
  • Remediate using “Block Indicators - Generic v3” playbook.
  • Provides Mitigation recommendations.

Note: This is a beta playbook, which lets you implement and test pre-release software. Since the playbook is beta, it might contain bugs. Updates to the pack during the beta phase might include non-backward compatible features. We appreciate your feedback on the quality and usability of the pack to help us identify issues, fix them, and continually improve.

Dependencies

This playbook uses the following sub-playbooks, integrations, and scripts.

Sub-playbooks

  • Block Indicators - Generic v3
  • Rapid Breach Response - Set Incident Info
  • Search logs for related sessions
  • Threat Hunting - Generic

Integrations

This playbook does not use any integrations.

Scripts

  • IsIntegrationAvailable
  • ParseHTMLIndicators
  • SearchIncidentsV2
  • SetAndHandleEmpty
  • http

Commands

  • associateIndicatorsToIncident
  • closeInvestigation
  • createNewIndicator
  • extractIndicators
  • setIncident
  • xdr-get-cloud-original-alerts
  • xdr-get-script-execution-results
  • xdr-script-commands-execute
  • xdr-xql-generic-query
  • xdr-xql-get-quota

Playbook Inputs


Name Description Default Value Required
SplunkEarliestTime The earliest time for Splunk query. -7d@d Optional
SplunkLatestTime The latest time for the Splunk search query. now Optional
QRadarTimeRange The time range for QRadar query. Last 7 DAYS Optional
PlaybookDescription The playbook description for the Rapid Breach Response layout. This playbook should be triggered manually or can be configured as a job.
Please create a new incident and choose the Cortex XDR - CVE-2025-31324 - SAP NetWeaver Visual Composer playbook and Rapid Breach Response incident type.

CVE-2025-31324 is a critical zero-day vulnerability affecting the Metadata Uploader component of SAP NetWeaver Visual Composer. The vulnerability arises from missing authorization checks, allowing unauthenticated attackers to upload malicious executable binaries. Exploitation of this flaw can lead to full remote code execution (RCE) on affected systems, posing a significant risk to confidentiality, integrity, and availability.

## CVE-2025-31324 - SAP NetWeaver RCE Vulnerability

## Vulnerability Overview

- Component Affected: SAP NetWeaver Visual Composer Metadata Uploader
- Endpoint: /developmentserver/metadatauploader
- CVE ID: CVE-2025-31324
- CVSS Score: 10.0 (Critical)
- Exploitability: Unauthenticated remote attackers can exploit this without user interaction

This flaw allows unauthenticated attackers to upload arbitrary files (e.g., JSP web shells), enabling remote code execution with the same privileges as the SAP application server process.
Source: Unit42 - Palo Alto Networks


## Mitigation and Recommendations

- Apply Patch: SAP Note #3594142 (released April 24, 2025)
- Disable Visual Composer if not in use
- Restrict Access to the vulnerable endpoint
- Monitor for IoCs in /irj/servlet_jsp/irj/root/ and suspicious traffic

## Conclusion

CVE-2025-31324 is actively exploited and is critically severe. Organizations should patch immediately, monitor for compromise, and disable or restrict vulnerable components.

View official CVE details on NIST

## Playbook Triggers
- Manually
- “CVE Exploitation - 986328356” Agent rule

## Playbook Flow
- Collects IoCs from Unit42 blog.
- Downloads Sigma rules.
- Search for CVE Exploitation alerts.
- Directory enumeration to identify if there are already any suspicious files that might indicate a webshell.
- Using XQL, identify potential SAP NetWeaver instances in your environment.
- Using XQL, check if there are events that point to any potential webshells downloaded in the directories.
- Hunt the IoCs using Panorama and 3rd party SIEM.
- Remediate using “Block Indicators - Generic v3” playbook.
- Provides Mitigation recommendations.

Note: This is a beta playbook, which lets you implement and test pre-release software. Since the playbook is beta, it might contain bugs. Updates to the pack during the beta phase might include non-backward compatible features. We appreciate your feedback on the quality and usability of the pack to help us identify issues, fix them, and continually improve.
Optional

Playbook Outputs


There are no outputs for this playbook.

Playbook Image


Cortex XDR - CVE-2025-31324 - SAP NetWeaver Visual Composer

Inputs

  • SplunkEarliestTime — The earliest time for Splunk query.
  • SplunkLatestTime — The latest time for the Splunk search query.
  • QRadarTimeRange — The time range for QRadar query.
  • PlaybookDescription — The playbook description for the Rapid Breach Response layout.

Commands used

associateIndicatorsToIncident closeInvestigation createNewIndicator extractIndicators setIncident xdr-get-cloud-original-alerts xdr-get-script-execution-results xdr-script-commands-execute xdr-xql-generic-query xdr-xql-get-quota

Flowchart

no yes yes yes No Yes yes yes no yes yes yes yes yes yes Start Start Search compromised hosts - xdr-xql-generic-query Search compromised hosts xdr-xql-generic-query Manual – Search possible hosts Manual – Search possible ... Is the integration of 'XQL Query Engine' available? - IsIntegrationAvailable Is the integration of 'XQ... IsIntegrationAvailable Any results from XQL? Any results from XQL? Check XQL quota - xdr-xql-get-quota Check XQL quota xdr-xql-get-quota Is there enough quota? Is there enough quota? XQL: Identify SAP NetWeaver Instances XQL: Identify SAP NetWeav... Remediation Remediation Mitigation Mitigation Analysis Resolution - Should continue with the investigation? Analysis Resolution - Sho... Done Done Investigate Further Investigate Further Close investigation - closeInvestigation Close investigation closeInvestigation Resolution Resolution Are there any compromised hosts? Are there any compromised... WebShell XQL Hunt WebShell XQL Hunt XQL Query - Search possible webshells - xdr-xql-generic-query XQL Query - Search possib... xdr-xql-generic-query Is the integration of 'XQL Query Engine' available? - IsIntegrationAvailable Is the integration of 'XQ... IsIntegrationAvailable Check XQL quota - xdr-xql-get-quota Check XQL quota xdr-xql-get-quota Is there enough quota? Is there enough quota? Manual – Search webshells using XQL query and quarantine the files Manual – Search webshells... Potential Webshells via Script Potential Webshells via S... Mitigation Actions Mitigation Actions Get script results - xdr-get-script-execution-results Get script results xdr-get-script-execution-results Extract the script's potential files - SetAndHandleEmpty Extract the script's pote... SetAndHandleEmpty Set agent IDs to incident context - setIncident Set agent IDs to incident... setIncident Are there any potential webshells found? Are there any potential w... Set potential files paths - SetAndHandleEmpty Set potential files paths SetAndHandleEmpty Manual Action - Quarantine Manual Action - Quarantine Is there a file path? Is there a file path? Threat Hunting - Generic - Threat Hunting - Generic Threat Hunting - Generic Threat Hunting - Generic Any results from threat hunting? Any results from threat h... Review threat hunting results Review threat hunting res... Any results from the manual XQL? Any results from the manu... Set agent IDs to incident context - setIncident Set agent IDs to incident... setIncident Get alert's extra data - xdr-get-cloud-original-alerts Get alert's extra data xdr-get-cloud-original-alerts Check for any other files in that directory - xdr-script-commands-execute Check for any other files... xdr-script-commands-execute Block Indicators - Generic v3 - Block Indicators - Generic v3 Block Indicators - Generi... Block Indicators - Generic v3 Handle Rapid Breach Response Layout Handle Rapid Breach Respo... Rapid Breach Response - Set Incident Info - Rapid Breach Response - Set Incident Info Rapid Breach Response - S... Rapid Breach Response - Set I... Collect Indicators Collect Indicators Collect indicators from Unit42 blog - ParseHTMLIndicators Collect indicators from U... ParseHTMLIndicators Extract indicators from data collected - extractIndicators Extract indicators from d... extractIndicators Tag and Link Indicators Tag and Link Indicators Tag IP indicators - createNewIndicator Tag IP indicators createNewIndicator Tag CVE indicators - createNewIndicator Tag CVE indicators createNewIndicator Extract Indicators Extract Indicators Link indicators to alert - associateIndicatorsToIncident Link indicators to alert associateIndicatorsToIncident Tag File indicators - createNewIndicator Tag File indicators createNewIndicator Tag Domain indicators - createNewIndicator Tag Domain indicators createNewIndicator Threat Hunting Threat Hunting PANW PANW Search logs for related sessions - Panorama Query Logs Search logs for related s... Panorama Query Logs Panorama Panorama SIEM SIEM Download Sigma - Potential Java webshell uploads - http Download Sigma - Potenti... http Collect Detection Rules Collect Detection Rules Download Sigma - Potential command execution via webshell - http Download Sigma - Potentia... http CVE Exploitation CVE Exploitation Search CVE Exploitation alerts - SearchIncidentsV2 Search CVE Exploitation a... SearchIncidentsV2 Found CVE Exploitation alerts? Found CVE Exploitation al... Set agent ID to incident context - setIncident Set agent ID to incident ... setIncident
id: Cortex XDR - CVE-2025-31324 - SAP NetWeaver Visual Composer
version: -1
contentitemexportablefields:
  contentitemfields: {}
name: Cortex XDR - CVE-2025-31324 - SAP NetWeaver Visual Composer
description: "This playbook should be triggered manually or can be configured as a job.\nPlease create a new incident and choose the Cortex XDR - CVE-2025-31324 - SAP NetWeaver Visual Composer playbook and Rapid Breach Response incident type.\n\nCVE-2025-31324 is a critical zero-day vulnerability affecting the Metadata Uploader component of SAP NetWeaver Visual Composer. The vulnerability arises from missing authorization checks, allowing unauthenticated attackers to upload malicious executable binaries. Exploitation of this flaw can lead to full remote code execution (RCE) on affected systems, posing a significant risk to confidentiality, integrity, and availability.\n\n## CVE-2025-31324 - SAP NetWeaver RCE Vulnerability\n\n##   Vulnerability Overview\n\n- **Component Affected**: SAP NetWeaver Visual Composer Metadata Uploader  \n- **Endpoint**: `/developmentserver/metadatauploader`  \n- **CVE ID**: CVE-2025-31324  \n- **CVSS Score**: 10.0 (Critical)  \n- **Exploitability**: Unauthenticated remote attackers can exploit this without user interaction  \n\nThis flaw allows unauthenticated attackers to upload arbitrary files (e.g., JSP web shells), enabling remote code execution with the same privileges as the SAP application server process.  \n[Source: Unit42 - Palo Alto Networks](https://unit42.paloaltonetworks.com/threat-brief-sap-netweaver-cve-2025-31324/)\n\n\n##  Mitigation and Recommendations\n\n- **Apply Patch**: SAP Note #3594142 (released April 24, 2025)  \n- **Disable Visual Composer** if not in use  \n- **Restrict Access** to the vulnerable endpoint  \n- **Monitor for IoCs** in `/irj/servlet_jsp/irj/root/` and suspicious traffic  \n\n##  Conclusion\n\nCVE-2025-31324 is actively exploited and is critically severe. Organizations should patch immediately, monitor for compromise, and disable or restrict vulnerable components.\n\n[View official CVE details on NIST](https://nvd.nist.gov/vuln/detail/CVE-2025-31324)\n\n##  Playbook Triggers\n- Manually\n- \"CVE Exploitation - 986328356\" Agent rule\n\n##  Playbook Flow\n- Collects IoCs from Unit42 blog.\n- Downloads Sigma rules.\n- Search for CVE Exploitation alerts.\n- Directory enumeration to identify if there are already any suspicious files that might indicate a webshell.\n-  Using XQL, identify potential SAP NetWeaver instances in your environment.\n- Using XQL, check if there are events that point to any potential webshells downloaded in the directories.\n- Hunt the IoCs using Panorama and 3rd party SIEM.\n- Remediate using \"Block Indicators - Generic v3\" playbook.\n- Provides Mitigation recommendations.\n\nNote: This is a beta playbook, which lets you implement and test pre-release software. Since the playbook is beta, it might contain bugs. Updates to the pack during the beta phase might include non-backward compatible features. We appreciate your feedback on the quality and usability of the pack to help us identify issues, fix them, and continually improve."
tags:
- Rapid Breach Response
- CVE-2025-31324
starttaskid: "0"
tasks:
  "0":
    id: "0"
    taskid: ffaa77c7-23f5-4480-8e58-8fb27306077b
    type: start
    task:
      id: ffaa77c7-23f5-4480-8e58-8fb27306077b
      version: -1
      name: ""
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "110"
      - "126"
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 4225,
          "y": -1390
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "1":
    id: "1"
    taskid: f205a898-45d4-4651-8cc9-d5b5fc735b04
    type: regular
    task:
      id: f205a898-45d4-4651-8cc9-d5b5fc735b04
      version: -1
      name: Search compromised hosts
      description: |-
        Execute an XQL query and retrieve results of an executed XQL query API. The command will be executed every 10 seconds until results are retrieved or until a timeout error is raised.
        When more than 1000 results are retrieved, the command will return a compressed gzipped JSON format file,
        unless the argument 'parse_result_file_to_context' is set to true and then the results will be extracted to the context.
      script: '|||xdr-xql-generic-query'
      type: regular
      iscommand: true
      brand: ""
    nexttasks:
      '#none#':
      - "4"
    scriptarguments:
      max_fields:
        simple: "100"
      query:
        simple: 'config timeframe=7d | dataset = xdr_data | filter event_type = ENUM.FILE  and lowercase(actor_process_image_name) = "jstart.exe" and lowercase(action_file_path) contains  "visualcomposer" | fields  agent_id,agent_hostname,agent_ip_addresses | dedup agent_id  '
      query_name:
        simple: Check for SAP NetWeaver Visual Composer
      time_frame:
        simple: 1 week ago
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 3221.5,
          "y": 1372
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: true
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "2":
    id: "2"
    taskid: b2f61764-f2bc-4e8c-80d2-1958422732de
    type: regular
    task:
      id: b2f61764-f2bc-4e8c-80d2-1958422732de
      version: -1
      name: Manual – Search possible hosts
      description: |-
        Dear Analyst,

        Ensure that the 'XQL Query Engine' integration is active. If it's not enabled, activate the integration or manually run the following XQL query to determine if any hosts are running a potentially vulnerable product.

        Query:

        config timeframe=7d | dataset = xdr_data | filter event_type = ENUM.FILE and lowercase(actor_process_image_name) = "jstart.exe" and lowercase(action_file_path) contains  "visualcomposer" | fields  agent_id,agent_hostname,agent_ip_addresses | dedup agent_id
      type: regular
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "103"
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 3725.5,
          "y": 1372
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "3":
    id: "3"
    taskid: b938543e-fc9d-4812-a3d6-32f55cfd42e1
    type: condition
    task:
      id: b938543e-fc9d-4812-a3d6-32f55cfd42e1
      version: -1
      name: Is the integration of 'XQL Query Engine' available?
      description: Returns 'yes' if integration brand 'XQL Query Engine' is available. Otherwise returns 'no'.
      scriptName: IsIntegrationAvailable
      type: condition
      iscommand: false
      brand: ""
    nexttasks:
      "no":
      - "2"
      "yes":
      - "5"
    scriptarguments:
      brandname:
        simple: Cortex XDR - XQL Query Engine
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 3725.5,
          "y": 896
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "4":
    id: "4"
    taskid: 74e81ef1-4e24-4e56-8fa8-65244aba4b7e
    type: condition
    task:
      id: 74e81ef1-4e24-4e56-8fa8-65244aba4b7e
      version: -1
      name: Any results from XQL?
      description: Any results from the XQL Query?
      type: condition
      iscommand: false
      brand: ""
    nexttasks:
      '#default#':
      - "72"
      "yes":
      - "92"
    separatecontext: false
    conditions:
    - label: "yes"
      condition:
      - - operator: isNotEmpty
          left:
            value:
              simple: PaloAltoNetworksXQL.GenericQuery.results
            iscontext: true
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 3221.5,
          "y": 1504
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "5":
    id: "5"
    taskid: 5c9225f1-1f25-4195-8988-c99b633ed97b
    type: regular
    task:
      id: 5c9225f1-1f25-4195-8988-c99b633ed97b
      version: -1
      name: Check XQL quota
      description: Retrieve the amount of query quota available and used.
      script: '|||xdr-xql-get-quota'
      type: regular
      iscommand: true
      brand: ""
    nexttasks:
      '#none#':
      - "6"
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 3334.25,
          "y": 1045
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "6":
    id: "6"
    taskid: 4579302d-c9ba-4b6f-84aa-11c7d7696aab
    type: condition
    task:
      id: 4579302d-c9ba-4b6f-84aa-11c7d7696aab
      version: -1
      name: Is there enough quota?
      description: Check if there is enough quota to run the query.
      type: condition
      iscommand: false
      brand: ""
    nexttasks:
      '#default#':
      - "2"
      "yes":
      - "1"
    separatecontext: false
    conditions:
    - label: "yes"
      condition:
      - - operator: greaterThanOrEqual
          left:
            value:
              complex:
                root: PaloAltoNetworksXQL.Quota
                accessor: license_quota
                transformers:
                - operator: subtraction
                  args:
                    by:
                      value:
                        simple: PaloAltoNetworksXQL.Quota.used_quota
                      iscontext: true
            iscontext: true
          right:
            value:
              simple: "1"
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 3334.25,
          "y": 1187
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "7":
    id: "7"
    taskid: 0b46aedb-15be-41d1-8416-9e278da0c353
    type: title
    task:
      id: 0b46aedb-15be-41d1-8416-9e278da0c353
      version: -1
      name: 'XQL: Identify SAP NetWeaver Instances'
      description: This section identifies SAP NetWeaver Visual Composer instances.
      type: title
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "3"
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 3725.5,
          "y": 761
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "28":
    id: "28"
    taskid: 2418b131-27a7-4c80-8b68-37d40d306556
    type: title
    task:
      id: 2418b131-27a7-4c80-8b68-37d40d306556
      version: -1
      name: Remediation
      type: title
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "93"
      - "107"
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 4220,
          "y": 2886
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "31":
    id: "31"
    taskid: 783e49ba-c974-48c5-874d-25cf2b440fa1
    type: title
    task:
      id: 783e49ba-c974-48c5-874d-25cf2b440fa1
      version: -1
      name: Mitigation
      type: title
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "87"
      - "99"
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 4220,
          "y": 3324
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "34":
    id: "34"
    taskid: e63a492b-c6fb-42b8-82e6-7058feeb4e26
    type: condition
    task:
      id: e63a492b-c6fb-42b8-82e6-7058feeb4e26
      version: -1
      name: Analysis Resolution - Should continue with the investigation?
      description: |+
        ## Check with the analyst whether to continue with the investigation.

        - Verify that SAP NetWeaver's Visual Composer Framework is version 7.50 (the vulnerable version).

        - Check the Threat Hunting steps returned results (if any).

        - Validate that there are no other affected systems, and the Potential WebShells are investigated.


      type: condition
      iscommand: false
      brand: ""
    nexttasks:
      "No":
      - "37"
      "Yes":
      - "36"
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 4217,
          "y": 3885
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    message:
      to:
      subject:
      body:
        simple: Do you need to continue with the investigation?
      methods: []
      format: ""
      bcc:
      cc:
      timings:
        retriescount: 2
        retriesinterval: 360
        completeafterreplies: 1
        completeafterv2: true
        completeaftersla: false
      replyOptions:
      - "Yes"
      - "No"
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "35":
    id: "35"
    taskid: c4d67153-6a58-4680-82ed-c97b39ed71d2
    type: title
    task:
      id: c4d67153-6a58-4680-82ed-c97b39ed71d2
      version: -1
      name: Done
      type: title
      iscommand: false
      brand: ""
      description: ''
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 4219.5,
          "y": 4176
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "36":
    id: "36"
    taskid: 2352cdd2-643f-425d-8b47-c872d90425d5
    type: regular
    task:
      id: 2352cdd2-643f-425d-8b47-c872d90425d5
      version: -1
      name: Investigate Further
      description: |
        ## Manual step for further alert investigation.
        For example, use the following opensource tool from Onapsis.

        Onapsis and Mandiant have collaborated to release an open-source tool to help SAP customers identify potential compromises related to CVE-2025-31324, a critical zero-day vulnerability in SAP NetWeaver Java systems.

        For more information, see https://github.com/Onapsis/Onapsis-Mandiant-CVE-2025-31324-Vuln-Compromise-Assessment

        **Note**: Running this script is a manual action. You are responsible for any outcomes or issues that may arise from its execution.
      type: regular
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "35"
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 3996.75,
          "y": 4033
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "37":
    id: "37"
    taskid: 247e1217-8c75-48c1-836c-ec783ba881b0
    type: regular
    task:
      id: 247e1217-8c75-48c1-836c-ec783ba881b0
      version: -1
      name: Close investigation
      description: Close the current alert
      script: Builtin|||closeInvestigation
      type: regular
      iscommand: true
      brand: Builtin
    nexttasks:
      '#none#':
      - "35"
    scriptarguments:
      closeReason:
        simple: No further actions are required.
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 4437.5,
          "y": 4033
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "38":
    id: "38"
    taskid: 3cbbc09a-3ae3-4a75-8be8-b36cf8513027
    type: title
    task:
      id: 3cbbc09a-3ae3-4a75-8be8-b36cf8513027
      version: -1
      name: Resolution
      type: title
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "34"
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 4217,
          "y": 3773
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "72":
    id: "72"
    taskid: 80ba813d-d15e-4d35-ac87-3f0fe1b53912
    type: condition
    task:
      id: 80ba813d-d15e-4d35-ac87-3f0fe1b53912
      version: -1
      name: Are there any compromised hosts?
      description: Are there any compromised hosts?
      type: condition
      iscommand: false
      brand: ""
    nexttasks:
      '#default#':
      - "28"
      "yes":
      - "73"
      - "81"
    separatecontext: false
    conditions:
    - label: "yes"
      condition:
      - - operator: isNotEmpty
          left:
            value:
              simple: incident.agentsid
            iscontext: true
          right:
            value: {}
        - operator: isNotEmpty
          left:
            value:
              simple: incident.agentid
            iscontext: true
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 3725.5,
          "y": 1822
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "73":
    id: "73"
    taskid: 25f18f50-0f20-4609-8dbb-a7e0cbd3142e
    type: title
    task:
      id: 25f18f50-0f20-4609-8dbb-a7e0cbd3142e
      version: -1
      name: WebShell XQL Hunt
      type: title
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "75"
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 2996.25,
          "y": 2000
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "74":
    id: "74"
    taskid: fccf43dc-a341-400e-8a7e-216c98e71561
    type: regular
    task:
      id: fccf43dc-a341-400e-8a7e-216c98e71561
      version: -1
      name: XQL Query - Search possible webshells
      description: |-
        Execute an XQL query and retrieve results of an executed XQL query API. The command will be executed every 10 seconds until results are retrieved or until a timeout error is raised.
        When more than 1000 results are retrieved, the command will return a compressed gzipped JSON format file,
        unless the argument 'parse_result_file_to_context' is set to true and then the results will be extracted to the context.
      script: '|||xdr-xql-generic-query'
      type: regular
      iscommand: true
      brand: ""
    nexttasks:
      '#none#':
      - "94"
    scriptarguments:
      extend-context:
        simple: XQLPossibleMaliciousFiles=
      ignore-outputs:
        simple: "true"
      max_fields:
        simple: "100"
      query:
        simple: |-
          config case_sensitive = false timeframe=7d
          | dataset = xdr_data
          | filter event_type = ENUM.FILE and event_sub_type in (ENUM.FILE_WRITE, ENUM.FILE_CREATE_NEW, ENUM.FILE_RENAME, ENUM.FILE_REMOVE)
          | filter lowercase(action_file_extension) in ("jsp","class","jar","jspx","war","jnlp") and lowercase(action_file_path) contains  "\servlet_jsp\irj\" | fields agent_id,agent_hostname,action_file_path | dedup action_file_path
      query_name:
        simple: Check for possibles malicious payload
      time_frame:
        simple: 7 days ago
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 2580.75,
          "y": 2579
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: true
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "75":
    id: "75"
    taskid: 26cfd16c-4f8a-41f4-bae5-2603559fef15
    type: condition
    task:
      id: 26cfd16c-4f8a-41f4-bae5-2603559fef15
      version: -1
      name: Is the integration of 'XQL Query Engine' available?
      description: Returns 'yes' if integration brand 'XQL Query Engine' is available. Otherwise returns 'no'.
      scriptName: IsIntegrationAvailable
      type: condition
      iscommand: false
      brand: ""
    nexttasks:
      "no":
      - "28"
      "yes":
      - "77"
    scriptarguments:
      brandname:
        simple: Cortex XDR - XQL Query Engine
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 2996.25,
          "y": 2130
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "77":
    id: "77"
    taskid: 439743e7-5050-4a85-b08c-2cccf59723d9
    type: regular
    task:
      id: 439743e7-5050-4a85-b08c-2cccf59723d9
      version: -1
      name: Check XQL quota
      description: Retrieve the amount of query quota available and used.
      script: '|||xdr-xql-get-quota'
      type: regular
      iscommand: true
      brand: ""
    nexttasks:
      '#none#':
      - "78"
    scriptarguments:
      extend-context:
        simple: PaloAltoNetworksXQL.Quota2=
      ignore-outputs:
        simple: "true"
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 2580.75,
          "y": 2273
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "78":
    id: "78"
    taskid: acf0845c-8787-45ee-8587-cf87ba0dfa8d
    type: condition
    task:
      id: acf0845c-8787-45ee-8587-cf87ba0dfa8d
      version: -1
      name: Is there enough quota?
      description: Is there enough quota?
      type: condition
      iscommand: false
      brand: ""
    nexttasks:
      '#default#':
      - "79"
      "yes":
      - "74"
    separatecontext: false
    conditions:
    - label: "yes"
      condition:
      - - operator: greaterThanOrEqual
          left:
            value:
              complex:
                root: PaloAltoNetworksXQL.Quota2
                accessor: license_quota
                transformers:
                - operator: LastArrayElement
                - operator: subtraction
                  args:
                    by:
                      value:
                        simple: PaloAltoNetworksXQL.Quota2.used_quota
                      iscontext: true
            iscontext: true
          right:
            value:
              simple: "1"
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 2580.75,
          "y": 2420
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "79":
    id: "79"
    taskid: 2a938735-256d-4890-8870-93374fc0cd7e
    type: regular
    task:
      id: 2a938735-256d-4890-8870-93374fc0cd7e
      version: -1
      name: Manual – Search webshells using XQL query and quarantine the files
      description: |-
        Dear Analyst,

        Ensure that the 'XQL Query Engine' integration is active. If it's not enabled, activate the integration or manually run the following XQL query to determine if any webshells have been downloaded.

        Query:

        config case_sensitive = false timeframe=7d
        | dataset = xdr_data
        | filter event_type = ENUM.FILE and event_sub_type in (ENUM.FILE_WRITE, ENUM.FILE_CREATE_NEW, ENUM.FILE_RENAME, ENUM.FILE_REMOVE)
        | filter lowercase(action_file_extension) in ("jsp","class","jar","jspx","war","jnlp") and lowercase(action_file_path) contains  "\servlet_jsp\irj\" | fields agent_id,agent_hostname,action_file_path | dedup action_file_path

        If the query output indicates on possible activity with file/s, investigate those files and quarantine/remove them per your need.
      type: regular
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "28"
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 2996.25,
          "y": 2579
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "81":
    id: "81"
    taskid: 980ecbab-5214-4427-894a-31ebbacfabf0
    type: title
    task:
      id: 980ecbab-5214-4427-894a-31ebbacfabf0
      version: -1
      name: Potential Webshells via Script
      type: title
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "96"
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 3725.5,
          "y": 2000
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "87":
    id: "87"
    taskid: 3c11cd5c-8703-4558-90ba-9fb1cd59bbb7
    type: regular
    task:
      id: 3c11cd5c-8703-4558-90ba-9fb1cd59bbb7
      version: -1
      name: Mitigation Actions
      description: "# Suggested Mitigation Steps\n\n## Patch Recommendations For SAP Visual Composer: \n\n[See the Onapsis blog](https://onapsis.com/blog/active-exploitation-of-sap-vulnerability-cve-2025-31324/)\n\n\n#### Go to the following link to download and patch your SAP product according to the vendor's advisory:  \n[SAP Security Note #3594142](https://me.sap.com/notes/3594142)\n\n#### For more information about SAP's FAQ:\n[SAP Note #3596125](https://me.sap.com/notes/3596125/E)\n\n#### For workaround mitigation steps for customers that cannot apply the patch, see:\n[SAP Note #3593336](https://me.sap.com/notes/3593336/E)\n\n\n## Sigma Rules:\n\nUse the 'SigmaRules' tag to download the files from the War Room.\n\n## You can implement the following YARA rule: \n\n[Link to the blog for this Yara rule](https://onapsis.com/blog/active-exploitation-of-sap-vulnerability-cve-2025-31324/)\n\nrule detect_CVE202531324_webshells_by_name\n`{\n    meta:\n        description = “Detects the known webshell file names that are uploaded in the root directory”\n        author = “Emanuela Ionas, Onapsis Research Labs”\n        date = “2025-05-05”\n        tags = “CVE-2025-31324”\n    strings:\n        $webshell_1 = “/irj/cache.jsp” nocase\n        $webshell_2 = “/irj/helper.jsp” nocase\n        $webshell_3 = “/irj/forwardsap.jsp” nocase\n        $webshell_4 = “/irj/coresap.jsp” nocase\n        $webshell_5 = “/irj/webhelp.jsp” nocase\n        $webshell_6 = “/irj/.webhelper.jsp” nocase\n        $webshell_7 = “/irj/usage.jsp” nocase\n        $webshell_8 = “/irj/usage1.jsp” nocase\n        $webshell_9 = “/irj/404_error.jsp” nocase\n        $webshell_10 = “/irj/.h.jsp” nocase\n        $webshell_regex = /\\/irj\\/[._a-zA-Z0-9]{2,10}\\.jsp/\n        $status = /HTTP\\/[12]\\.[012]\\s+200/\n    condition:\n        ($webshell_1 or $webshell_2 or $webshell_3 or $webshell_4 or $webshell_5 or $webshell_6 or $webshell_7 or $webshell_8 or $webshell_9 or $webshell_10 or $webshell_regex) and $status\n}`\n\n## Monitor Creation of Suspicious Files with XQL: \nUse the following XQL to identify any suspicious activity created \n\n``` config case_sensitive = false timeframe=30d\n| dataset = xdr_data\n| filter event_type = ENUM.FILE and event_sub_type in (ENUM.FILE_WRITE, ENUM.FILE_CREATE_NEW, ENUM.FILE_RENAME, ENUM.FILE_REMOVE)\n| filter lowercase(action_file_extension) in (\"jsp\",\"class\",\"jar\",\"jspx\",\"war\",\"jnlp\") and lowercase(action_file_path) contains  \"\\servlet_jsp\\irj\\\" ```"
      type: regular
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "38"
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 3996.75,
          "y": 3462
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "89":
    id: "89"
    taskid: 530d8b08-e090-407b-b1e9-de3b6faef4de
    type: regular
    task:
      id: 530d8b08-e090-407b-b1e9-de3b6faef4de
      version: -1
      name: Get script results
      description: Retrieve the results of a script execution action.
      script: '|||xdr-get-script-execution-results'
      type: regular
      iscommand: true
      brand: ""
    nexttasks:
      '#none#':
      - "90"
    scriptarguments:
      action_id:
        simple: ${PaloAltoNetworksXDR.ScriptRun.action_id}
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 3725.5,
          "y": 2420
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "90":
    id: "90"
    taskid: 6e168775-f890-4809-82e0-d67661f775b8
    type: regular
    task:
      id: 6e168775-f890-4809-82e0-d67661f775b8
      version: -1
      name: Extract the script's potential files
      description: "Set a value in context under the key you entered. If no value is entered, the script doesn't do anything.\n\nThis automation runs using the default Limited User role, unless you explicitly change the permissions.\nFor more information, see the section about permissions here:\n- For Cortex XSOAR 6 see https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/6.x/Cortex-XSOAR-Playbook-Design-Guide/Automations \n- For Cortex XSOAR 8 Cloud see https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/8/Cortex-XSOAR-Cloud-Documentation/Create-a-script\n- For Cortex XSOAR 8.7 On-prem see https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/8.7/Cortex-XSOAR-On-prem-Documentation/Create-a-script"
      scriptName: SetAndHandleEmpty
      type: regular
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "28"
    scriptarguments:
      append:
        simple: "true"
      key:
        simple: Potential_suspicious_files
      value:
        complex:
          root: PaloAltoNetworksXDR.ScriptResult.results
          accessor: standard_output
          transformers:
          - operator: toLowerCase
          - operator: RegexExtractAll
            args:
              error_if_no_match: {}
              ignore_case: {}
              multi_line: {}
              period_matches_newline: {}
              regex:
                value:
                  simple: \b([^\s\\/]+?\.(?:jsp|class|jar|jspx|war|jnlp))\b
              unpack_matches:
                value:
                  simple: "true"
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 3725.5,
          "y": 2579
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "92":
    id: "92"
    taskid: 8cd1abd8-33e0-483a-906e-c1a98aff3f1a
    type: regular
    task:
      id: 8cd1abd8-33e0-483a-906e-c1a98aff3f1a
      version: -1
      name: Set agent IDs to incident context
      description: commands.local.cmd.set.incident
      script: Builtin|||setIncident
      type: regular
      iscommand: true
      brand: Builtin
    nexttasks:
      '#none#':
      - "72"
    scriptarguments:
      agentsid:
        simple: ${PaloAltoNetworksXQL.GenericQuery.results.agent_id}
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 2996.25,
          "y": 1652
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "93":
    id: "93"
    taskid: 1660dca0-d705-4f74-8883-a9c7a53833df
    type: condition
    task:
      id: 1660dca0-d705-4f74-8883-a9c7a53833df
      version: -1
      name: Are there any potential webshells found?
      description: Are there any potential WebShells found?
      type: condition
      iscommand: false
      brand: ""
    nexttasks:
      '#default#':
      - "31"
      "yes":
      - "95"
    separatecontext: false
    conditions:
    - label: "yes"
      condition:
      - - operator: isNotEmpty
          left:
            value:
              simple: Potential_suspicious_files
            iscontext: true
          right:
            value: {}
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 4437.5,
          "y": 3018
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "94":
    id: "94"
    taskid: 402004f4-29c9-4084-8470-f3ac433d3ee5
    type: regular
    task:
      id: 402004f4-29c9-4084-8470-f3ac433d3ee5
      version: -1
      name: Set potential files paths
      description: "Set a value in context under the key you entered. If no value is entered, the script doesn't do anything.\n\nThis automation runs using the default Limited User role, unless you explicitly change the permissions.\nFor more information, see the section about permissions here:\n- For Cortex XSOAR 6 see https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/6.x/Cortex-XSOAR-Playbook-Design-Guide/Automations \n- For Cortex XSOAR 8 Cloud see https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/8/Cortex-XSOAR-Cloud-Documentation/Create-a-script\n- For Cortex XSOAR 8.7 On-prem see https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/8.7/Cortex-XSOAR-On-prem-Documentation/Create-a-script"
      scriptName: SetAndHandleEmpty
      type: regular
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "28"
    scriptarguments:
      append:
        simple: "true"
      key:
        simple: Potential_suspicious_files
      value:
        simple: ${XQLPossibleMaliciousFiles.results.action_file_path}
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 2580.75,
          "y": 2719
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "95":
    id: "95"
    taskid: 75337bfd-90ec-4ba5-8da8-635868b79611
    type: regular
    task:
      id: 75337bfd-90ec-4ba5-8da8-635868b79611
      version: -1
      name: Manual Action - Quarantine
      description: "As a part of the playbook, we have determined potential webshells that might be in the same directory *\"...servlet_jsp\\irj\\....\"*.\nSince we can't determine with strong confidence that those files are webshells, we suggest that you investigate them and quarantine as needed. \n\nList of files:\n${Potential_suspicious_files}\n\nList of agent IDs:\n${alert.agentid}\n${alert.agentsid}"
      type: regular
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "31"
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 4626,
          "y": 3174
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "96":
    id: "96"
    taskid: 71e64d8d-4a69-4bea-a1d2-7be738850970
    type: condition
    task:
      id: 71e64d8d-4a69-4bea-a1d2-7be738850970
      version: -1
      name: Is there a file path?
      description: Is there a file path in context data from XDR alerts?
      type: condition
      iscommand: false
      brand: ""
    nexttasks:
      '#default#':
      - "28"
      "yes":
      - "106"
    separatecontext: false
    conditions:
    - label: "yes"
      condition:
      - - operator: isNotEmpty
          left:
            value:
              simple: PaloAltoNetworksXDR.OriginalAlert.messageData.dynamicAnalysis.internals.attributes.file_path
            iscontext: true
          right:
            value: {}
      - - operator: containsGeneral
          left:
            value:
              simple: foundIncidents.CustomFields.xdralerts.agentostype
            iscontext: true
          right:
            value:
              simple: windows
          ignorecase: true
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 3725.5,
          "y": 2130
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "98":
    id: "98"
    taskid: 7d475f0d-6997-4030-ba76-441aadd846d4
    type: playbook
    task:
      id: 7d475f0d-6997-4030-ba76-441aadd846d4
      version: -1
      name: Threat Hunting - Generic
      description: "This playbook enables threat hunting for IOCs in your enterprise. It currently supports the following integrations: \n- Splunk\n- Qradar\n- Pan-os \n- Cortex Data Lake \n- Autofocus\n- Microsoft 365 Defender"
      playbookName: Threat Hunting - Generic
      type: playbook
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "28"
    scriptarguments:
      IPAddress:
        complex:
          root: ExtractedIndicators
          accessor: IP
          transformers:
          - operator: uniq
      InternalRange:
        complex:
          root: lists
          accessor: PrivateIPs
          transformers:
          - operator: RegexExtractAll
            args:
              error_if_no_match: {}
              ignore_case: {}
              multi_line: {}
              period_matches_newline: {}
              regex:
                value:
                  simple: (\b(?:\d{1,3}\.){3}\d{1,3}\b/\d{1,2})
              unpack_matches: {}
          - operator: join
            args:
              separator:
                value:
                  simple: ','
      QRadarTimeFrame:
        simple: ${inputs.QRadarTimeRange}
      SHA256:
        complex:
          root: ExtractedIndicators.File
          filters:
          - - operator: hasLength
              left:
                value:
                  simple: ExtractedIndicators.File
                iscontext: true
              right:
                value:
                  simple: "64"
          transformers:
          - operator: uniq
      SplunkEarliestTime:
        simple: ${inputs.SplunkEarliestTime}
      SplunkLatestTime:
        simple: ${inputs.SplunkLatestTime}
      URLDomain:
        complex:
          root: ExtractedIndicators
          accessor: URL
          transformers:
          - operator: AppendIfNotEmpty
            args:
              item:
                value:
                  simple: ExtractedIndicators.Domain
                iscontext: true
              raw: {}
          - operator: uniq
    separatecontext: true
    continueonerrortype: ""
    loop:
      iscommand: false
      exitCondition: ""
      wait: 1
      max: 100
    view: |-
      {
        "position": {
          "x": 5380,
          "y": 426
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "99":
    id: "99"
    taskid: 3220aeb7-9f6c-4293-8aa1-8d3c1db504a2
    type: condition
    task:
      id: 3220aeb7-9f6c-4293-8aa1-8d3c1db504a2
      version: -1
      name: Any results from threat hunting?
      description: Any results from Threat Hunting?
      type: condition
      iscommand: false
      brand: ""
    nexttasks:
      '#default#':
      - "38"
      "yes":
      - "102"
    separatecontext: false
    conditions:
    - label: "yes"
      condition:
      - - operator: isNotEmpty
          left:
            value:
              simple: Splunk
            iscontext: true
          right:
            value: {}
        - operator: isNotEmpty
          left:
            value:
              simple: PANWHunting
            iscontext: true
        - operator: isNotEmpty
          left:
            value:
              simple: QRadar
            iscontext: true
        - operator: isNotEmpty
          left:
            value:
              simple: Microsoft365Defender
            iscontext: true
        - operator: isNotEmpty
          left:
            value:
              simple: Panorama.Monitor.Logs
            iscontext: true
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 4437.5,
          "y": 3462
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "102":
    id: "102"
    taskid: 7d34a9b6-b318-482a-8787-30689f0dcdba
    type: regular
    task:
      id: 7d34a9b6-b318-482a-8787-30689f0dcdba
      version: -1
      name: Review threat hunting results
      description: Review the Threat Hunting - Generic playbook outputs and take appropriate action.
      type: regular
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "38"
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 4626,
          "y": 3619
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "103":
    id: "103"
    taskid: a2e8bcdc-c8f1-444a-8f9c-74b68850fb01
    type: collection
    task:
      id: a2e8bcdc-c8f1-444a-8f9c-74b68850fb01
      version: -1
      name: Any results from the manual XQL?
      description: Any results from the manual XQL?
      type: collection
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "104"
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 3725.5,
          "y": 1504
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    message:
      to:
      subject:
      body:
        simple: Are there any SAP NetWeaver Visual Composer instances in your env?
      methods: []
      format: ""
      bcc:
      cc:
      timings:
        retriescount: 2
        retriesinterval: 360
        completeafterreplies: 1
        completeafterv2: true
        completeaftersla: false
      replyOptions:
      - "Yes"
      - "No"
    form:
      questions:
      - id: "0"
        label: ""
        labelarg:
          simple: Please provide the agent IDs for those machines. If you have multiple endpoints, enter them as comma-separated values.
        required: false
        gridcolumns: []
        defaultrows: []
        type: shortText
        options: []
        optionsarg:
        - simple: "Yes"
        - simple: "No"
        fieldassociated: ""
        placeholder: ""
        tooltip: ""
        readonly: false
      title: Have you find any instances of SAP NetWaver?
      description: ""
      sender: ""
      expired: false
      totalanswers: 0
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "104":
    id: "104"
    taskid: bf3f1e91-0040-4fab-9ecc-1b42688193cc
    type: regular
    task:
      id: bf3f1e91-0040-4fab-9ecc-1b42688193cc
      version: -1
      name: Set agent IDs to incident context
      description: commands.local.cmd.set.incident
      script: Builtin|||setIncident
      type: regular
      iscommand: true
      brand: Builtin
    nexttasks:
      '#none#':
      - "72"
    scriptarguments:
      agentsid:
        complex:
          root: Have you find any instances of SAP NetWaver?.Answers
          accessor: "0"
          transformers:
          - operator: split
            args:
              delimiter:
                value:
                  simple: ','
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 3725.5,
          "y": 1652
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "105":
    id: "105"
    taskid: a29a0f59-e1a5-4351-9684-be511bbd710e
    type: regular
    task:
      id: a29a0f59-e1a5-4351-9684-be511bbd710e
      version: -1
      name: Get alert's extra data
      description: Returns information about each alert ID.
      script: '|||xdr-get-cloud-original-alerts'
      type: regular
      iscommand: true
      brand: ""
    nexttasks:
      '#none#':
      - "72"
    scriptarguments:
      alert_ids:
        complex:
          root: foundIncidents.CustomFields.xdralerts
          filters:
          - - operator: containsString
              left:
                value:
                  simple: foundIncidents.CustomFields.xdralerts.name
                iscontext: true
              right:
                value:
                  simple: CVE Exploitation
              ignorecase: true
          accessor: alert_id
      filter_alert_fields:
        simple: "false"
    separatecontext: false
    continueonerror: true
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 4220,
          "y": 896
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "106":
    id: "106"
    taskid: 356e5d53-e49f-435b-bfd2-2a498fa39ad1
    type: regular
    task:
      id: 356e5d53-e49f-435b-bfd2-2a498fa39ad1
      version: -1
      name: Check for any other files in that directory
      description: Initiates a new endpoint script execution of shell commands.
      script: '|||xdr-script-commands-execute'
      type: regular
      iscommand: true
      brand: ""
    nexttasks:
      '#none#':
      - "89"
    scriptarguments:
      commands:
        complex:
          root: PaloAltoNetworksXDR.OriginalAlert.messageData.dynamicAnalysis.internals
          filters:
          - - operator: containsGeneral
              left:
                value:
                  simple: PaloAltoNetworksXDR.OriginalAlert.messageData.dynamicAnalysis.internals.attributes.file_path
                iscontext: true
              right:
                value:
                  simple: \servlet_jsp\irj\
          accessor: attributes.file_path
          transformers:
          - operator: RegexExtractAll
            args:
              error_if_no_match: {}
              ignore_case: {}
              multi_line: {}
              period_matches_newline: {}
              regex:
                value:
                  simple: ^(.*\\)[^\\]+$
              unpack_matches: {}
          - operator: concat
            args:
              prefix:
                value:
                  simple: 'dir '
              suffix: {}
      endpoint_ids:
        complex:
          root: incident.xdralerts
          filters:
          - - operator: containsString
              left:
                value:
                  simple: incident.xdralerts.name
                iscontext: true
              right:
                value:
                  simple: CVE Exploitation
              ignorecase: true
          accessor: endpointid
          transformers:
          - operator: AppendIfNotEmpty
            args:
              item:
                value:
                  simple: incident.agentsid
                iscontext: true
              raw: {}
          - operator: uniq
      incident_id:
        simple: ${incident.id}
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 3725.5,
          "y": 2273
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "107":
    id: "107"
    taskid: 70385297-b5a9-4d95-9036-46146dfa3ccd
    type: playbook
    task:
      id: 70385297-b5a9-4d95-9036-46146dfa3ccd
      version: -1
      name: Block Indicators - Generic v3
      description: |-
        This playbook blocks malicious indicators using all integrations that are enabled, using the following sub-playbooks:

        - Block URL - Generic v2
        - Block Account - Generic v2
        - Block IP - Generic v3
        - Block File - Generic v2
        - Block Email - Generic v2
        - Block Domain - Generic v2.
      playbookName: Block Indicators - Generic v3
      type: playbook
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "31"
    scriptarguments:
      AutoBlockIndicators:
        simple: "True"
      AutoCommit:
        simple: "No"
      CustomBlockRule:
        simple: "True"
      CustomURLCategory:
        simple: XSOAR Remediation - Malicious URLs
      DomainToBlock:
        complex:
          root: ExtractedIndicators
          accessor: Domain
          transformers:
          - operator: uniq
      FilesToBlock:
        complex:
          root: ExtractedIndicators
          accessor: File
          transformers:
          - operator: uniq
      IP:
        complex:
          root: ExtractedIndicators
          accessor: IP
          transformers:
          - operator: uniq
      InputEnrichment:
        simple: "False"
      InternalRange:
        complex:
          root: lists
          accessor: PrivateIPs
          transformers:
          - operator: RegexExtractAll
            args:
              error_if_no_match: {}
              ignore_case: {}
              multi_line: {}
              period_matches_newline: {}
              regex:
                value:
                  simple: (\b(?:\d{1,3}\.){3}\d{1,3}\b/\d{1,2})
              unpack_matches: {}
          - operator: join
            args:
              separator:
                value:
                  simple: ','
      MD5:
        complex:
          root: ExtractedIndicators.File
          filters:
          - - operator: stringHasLength
              left:
                value:
                  simple: ExtractedIndicators.File
                iscontext: true
              right:
                value:
                  simple: "32"
          transformers:
          - operator: uniq
      RuleDirection:
        simple: outbound
      RuleName:
        simple: XSOAR - Block Indicators playbook - ${incident.id}
      SHA256:
        complex:
          root: ExtractedIndicators.File
          filters:
          - - operator: stringHasLength
              left:
                value:
                  simple: ExtractedIndicators.File
                iscontext: true
              right:
                value:
                  simple: "64"
          transformers:
          - operator: uniq
      Tag:
        simple: Blocked Indicator In Systems
      URL:
        complex:
          root: ExtractedIndicators
          accessor: URL
          transformers:
          - operator: uniq
      UserVerification:
        simple: "True"
      Username:
        complex:
          root: DBotScore
          filters:
          - - operator: isEqualString
              left:
                value:
                  simple: DBotScore.Type
                iscontext: true
              right:
                value:
                  simple: username
              ignorecase: true
          - - operator: greaterThanOrEqual
              left:
                value:
                  simple: DBotScore.Score
                iscontext: true
              right:
                value:
                  simple: "3"
          accessor: Indicator
          transformers:
          - operator: uniq
    separatecontext: true
    continueonerrortype: ""
    loop:
      iscommand: false
      exitCondition: ""
      wait: 1
      max: 100
    view: |-
      {
        "position": {
          "x": 3996.75,
          "y": 3018
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "108":
    id: "108"
    taskid: cf0846ef-719a-4fb2-80c6-5e6af25f481f
    type: title
    task:
      id: cf0846ef-719a-4fb2-80c6-5e6af25f481f
      version: -1
      name: Handle Rapid Breach Response Layout
      type: title
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "109"
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 4220,
          "y": -281.25
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "109":
    id: "109"
    taskid: bfd02b81-4860-42cf-8526-34ba3277fb20
    type: playbook
    task:
      id: bfd02b81-4860-42cf-8526-34ba3277fb20
      version: -1
      name: Rapid Breach Response - Set Incident Info
      description: This playbook is responsible for setting up the Rapid Breach Response Incident Info tab in the layout.
      playbookName: Rapid Breach Response - Set Incident Info
      type: playbook
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "120"
    scriptarguments:
      SourceOfIndicators:
        simple: ${http.parsedBlog.sourceLink}
      countTotalIndicators:
        complex:
          root: ExtractedIndicators
          accessor: CVE
          transformers:
          - operator: append
            args:
              item:
                value:
                  simple: ExtractedIndicators.Domain
                iscontext: true
          - operator: append
            args:
              item:
                value:
                  simple: ExtractedIndicators.IP
                iscontext: true
          - operator: append
            args:
              item:
                value:
                  simple: ExtractedIndicators.URL
                iscontext: true
          - operator: append
            args:
              item:
                value:
                  simple: ExtractedIndicators.File
                iscontext: true
          - operator: uniq
          - operator: count
      playbookDescription:
        simple: ${inputs.PlaybookDescription}
    separatecontext: true
    continueonerrortype: ""
    loop:
      iscommand: false
      exitCondition: ""
      wait: 1
      max: 100
    view: |-
      {
        "position": {
          "x": 4220,
          "y": -151.25
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "110":
    id: "110"
    taskid: a81acf66-133b-44e3-830a-2d2ea7fc42d1
    type: title
    task:
      id: a81acf66-133b-44e3-830a-2d2ea7fc42d1
      version: -1
      name: Collect Indicators
      type: title
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "111"
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 4505,
          "y": -1242.5
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "111":
    id: "111"
    taskid: 5e88167a-2330-4771-8f5b-7b84badfdcc5
    type: regular
    task:
      id: 5e88167a-2330-4771-8f5b-7b84badfdcc5
      version: -1
      name: Collect indicators from Unit42 blog
      description: This script extracts indicators from HTML and handles bad TLDs to avoid file extension false positives.
      scriptName: ParseHTMLIndicators
      type: regular
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "116"
    scriptarguments:
      unescape_domain:
        simple: "False"
      url:
        simple: https://unit42.paloaltonetworks.com/threat-brief-sap-netweaver-cve-2025-31324/
    separatecontext: false
    continueonerror: true
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 4505,
          "y": -1118.75
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "112":
    id: "112"
    taskid: ad5fa62e-47bd-422b-8a96-be1dc1a559f1
    type: regular
    task:
      id: ad5fa62e-47bd-422b-8a96-be1dc1a559f1
      version: -1
      name: Extract indicators from data collected
      description: commands.local.cmd.extract.indicators
      script: Builtin|||extractIndicators
      type: regular
      iscommand: true
      brand: Builtin
    nexttasks:
      '#none#':
      - "113"
    scriptarguments:
      text:
        complex:
          root: http.parsedBlog
          accessor: indicators
          transformers:
          - operator: RemoveEmpty
            args:
              empty_values: {}
              remove_keys:
                value:
                  simple: "true"
    separatecontext: false
    continueonerror: true
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 4225,
          "y": -839.5
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "113":
    id: "113"
    taskid: 122907ce-f61f-4d59-8740-68fe7069fcfa
    type: title
    task:
      id: 122907ce-f61f-4d59-8740-68fe7069fcfa
      version: -1
      name: Tag and Link Indicators
      type: title
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "114"
      - "115"
      - "119"
      - "118"
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 4225,
          "y": -692.5
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "114":
    id: "114"
    taskid: 20b99720-e62d-4db5-8d67-859a7ec83be5
    type: regular
    task:
      id: 20b99720-e62d-4db5-8d67-859a7ec83be5
      version: -1
      name: Tag IP indicators
      description: commands.local.cmd.new.indicator
      script: Builtin|||createNewIndicator
      type: regular
      iscommand: true
      brand: Builtin
    nexttasks:
      '#none#':
      - "117"
    scriptarguments:
      retry-count:
        simple: "3"
      retry-interval:
        simple: "2"
      tags:
        simple: CVE-2025-31324
      type:
        simple: IP
      value:
        complex:
          root: ExtractedIndicators.IP
          filters:
          - - operator: isNotEmpty
              left:
                value:
                  simple: ExtractedIndicators.IP
                iscontext: true
          transformers:
          - operator: uniq
      verdict:
        simple: Malicious
    separatecontext: false
    continueonerror: true
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 3637.25,
          "y": -553.5
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "115":
    id: "115"
    taskid: ad862821-fd41-4946-bb0e-cf822319f560
    type: regular
    task:
      id: ad862821-fd41-4946-bb0e-cf822319f560
      version: -1
      name: Tag CVE indicators
      description: commands.local.cmd.new.indicator
      script: Builtin|||createNewIndicator
      type: regular
      iscommand: true
      brand: Builtin
    nexttasks:
      '#none#':
      - "117"
    scriptarguments:
      retry-count:
        simple: "3"
      retry-interval:
        simple: "2"
      tags:
        simple: SAP NetWeaver's Visual Composer Framework
      type:
        simple: CVE
      value:
        complex:
          root: ExtractedIndicators
          accessor: CVE
          transformers:
          - operator: uniq
      verdict:
        simple: Suspicious
    separatecontext: false
    continueonerror: true
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 4031.25,
          "y": -553.5
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "116":
    id: "116"
    taskid: ab7b0e86-8449-40d0-8575-ccba7356c050
    type: title
    task:
      id: ab7b0e86-8449-40d0-8575-ccba7356c050
      version: -1
      name: Extract Indicators
      type: title
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "112"
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 4225,
          "y": -962.5
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "117":
    id: "117"
    taskid: 64c828f0-be73-480e-9005-614d1fb50da3
    type: regular
    task:
      id: 64c828f0-be73-480e-9005-614d1fb50da3
      version: -1
      name: Link indicators to alert
      description: commands.local.cmd.associate.indicators
      script: Builtin|||associateIndicatorsToIncident
      type: regular
      iscommand: true
      brand: Builtin
    nexttasks:
      '#none#':
      - "108"
    scriptarguments:
      incidentId:
        simple: ${incident.id}
      indicatorsValues:
        complex:
          root: ExtractedIndicators.IP
          filters:
          - - operator: isNotEmpty
              left:
                value:
                  simple: ExtractedIndicators.IP
                iscontext: true
          transformers:
          - operator: AppendIfNotEmpty
            args:
              item:
                value:
                  simple: ExtractedIndicators.Domain
                iscontext: true
              raw: {}
          - operator: AppendIfNotEmpty
            args:
              item:
                value:
                  simple: ExtractedIndicators.URL
                iscontext: true
              raw: {}
          - operator: AppendIfNotEmpty
            args:
              item:
                value:
                  simple: ExtractedIndicators.IP
                iscontext: true
              raw: {}
          - operator: AppendIfNotEmpty
            args:
              item:
                value:
                  simple: ExtractedIndicators.File
              raw: {}
          - operator: uniq
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 4220,
          "y": -410
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "118":
    id: "118"
    taskid: 5f931c26-e968-443e-89d0-1d7386a5588e
    type: regular
    task:
      id: 5f931c26-e968-443e-89d0-1d7386a5588e
      version: -1
      name: Tag File indicators
      description: commands.local.cmd.new.indicator
      script: Builtin|||createNewIndicator
      type: regular
      iscommand: true
      brand: Builtin
    nexttasks:
      '#none#':
      - "117"
    scriptarguments:
      retry-count:
        simple: "3"
      retry-interval:
        simple: "2"
      tags:
        simple: CVE-2025-31324
      type:
        simple: File
      value:
        complex:
          root: ExtractedIndicators.File
          filters:
          - - operator: isNotEmpty
              left:
                value:
                  simple: ExtractedIndicators.File
                iscontext: true
          transformers:
          - operator: uniq
      verdict:
        simple: Malicious
    separatecontext: false
    continueonerror: true
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 4817.5,
          "y": -553.5
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "119":
    id: "119"
    taskid: 99b595f9-6460-46ff-bdeb-ec4add2aa5fd
    type: regular
    task:
      id: 99b595f9-6460-46ff-bdeb-ec4add2aa5fd
      version: -1
      name: Tag Domain indicators
      description: commands.local.cmd.new.indicator
      script: Builtin|||createNewIndicator
      type: regular
      iscommand: true
      brand: Builtin
    nexttasks:
      '#none#':
      - "117"
    scriptarguments:
      retry-count:
        simple: "3"
      retry-interval:
        simple: "2"
      tags:
        simple: CVE-2025-31324
      type:
        simple: Domain
      value:
        complex:
          root: ExtractedIndicators.Domain
          filters:
          - - operator: isNotEmpty
              left:
                value:
                  simple: ExtractedIndicators.Domain
                iscontext: true
          transformers:
          - operator: uniq
      verdict:
        simple: Malicious
    separatecontext: false
    continueonerror: true
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 4411.25,
          "y": -553.5
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "120":
    id: "120"
    taskid: ce29881f-4c43-4588-84cd-4d8c36f082c1
    type: title
    task:
      id: ce29881f-4c43-4588-84cd-4d8c36f082c1
      version: -1
      name: Threat Hunting
      type: title
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "121"
      - "124"
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 4220,
          "y": -0.0000152587890625
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "121":
    id: "121"
    taskid: 4d8771eb-da11-4a2c-9d4e-aa96b4290a3d
    type: title
    task:
      id: 4d8771eb-da11-4a2c-9d4e-aa96b4290a3d
      version: -1
      name: PANW
      type: title
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "123"
      - "128"
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 4220,
          "y": 140
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "122":
    id: "122"
    taskid: 86a513e3-d195-4f95-8206-dfcf228b464a
    type: playbook
    task:
      id: 86a513e3-d195-4f95-8206-dfcf228b464a
      version: -1
      name: Search logs for related sessions
      description: 'Query Panorama Logs of types: traffic, threat, url, data-filtering and wildfire.'
      playbookName: Panorama Query Logs
      type: playbook
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "28"
    scriptarguments:
      log_type:
        simple: threat
      query:
        simple: '(threatid eq 96181) '
    separatecontext: true
    continueonerrortype: ""
    loop:
      iscommand: false
      exitCondition: ""
      wait: 1
      max: 100
    view: |-
      {
        "position": {
          "x": 4910,
          "y": 426
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: true
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "123":
    id: "123"
    taskid: 5d3ea82d-7f70-4d6f-8b58-221ec767d740
    type: title
    task:
      id: 5d3ea82d-7f70-4d6f-8b58-221ec767d740
      version: -1
      name: Panorama
      type: title
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "122"
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 4910,
          "y": 291
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "124":
    id: "124"
    taskid: 5f517afa-a4b7-4a2b-bfd7-bc5b070bfafc
    type: title
    task:
      id: 5f517afa-a4b7-4a2b-bfd7-bc5b070bfafc
      version: -1
      name: SIEM
      type: title
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "98"
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 5380,
          "y": 291
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "125":
    id: "125"
    taskid: 2266dbb8-7a88-4dc2-8d67-87d4d039ace3
    type: regular
    task:
      id: 2266dbb8-7a88-4dc2-8d67-87d4d039ace3
      version: -1
      name: Download Sigma -  Potential Java webshell uploads
      description: Download Sigma Rules
      tags:
      - SigmsRules
      scriptName: http
      type: regular
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "116"
    scriptarguments:
      filename:
        simple: web_lnx_exploit_cve_2025_31324_sap_netviewer_webshell_uploaded.yml
      method:
        simple: GET
      saveAsFile:
        simple: "yes"
      url:
        simple: https://raw.githubusercontent.com/SigmaHQ/sigma/refs/heads/master/rules-emerging-threats/2025/Exploits/CVE-2025-31324/web_lnx_exploit_cve_2025_31324_sap_netviewer_webshell_uploaded.yml
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 3978.75,
          "y": -1118.75
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: true
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "126":
    id: "126"
    taskid: 3d4a34b8-1d72-49e4-84d6-635637ab61ba
    type: title
    task:
      id: 3d4a34b8-1d72-49e4-84d6-635637ab61ba
      version: -1
      name: Collect Detection Rules
      type: title
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "125"
      - "127"
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 3760,
          "y": -1252.5
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "127":
    id: "127"
    taskid: c11c4038-9089-49a8-9112-f13d903879d9
    type: regular
    task:
      id: c11c4038-9089-49a8-9112-f13d903879d9
      version: -1
      name: Download Sigma - Potential command execution via webshell
      description: Download Sigma Rules
      tags:
      - SigmsRules
      scriptName: http
      type: regular
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "116"
    scriptarguments:
      filename:
        simple: web_lnx_exploit_cve_2025_31324_sap_netviewer_webshell.yml
      method:
        simple: GET
      saveAsFile:
        simple: "yes"
      url:
        simple: https://raw.githubusercontent.com/SigmaHQ/sigma/refs/heads/master/rules-emerging-threats/2025/Exploits/CVE-2025-31324/web_lnx_exploit_cve_2025_31324_sap_netviewer_webshell.yml
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 3538.75,
          "y": -1118.75
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: true
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "128":
    id: "128"
    taskid: b34c879f-921d-41b7-82d6-0a95a9089409
    type: title
    task:
      id: b34c879f-921d-41b7-82d6-0a95a9089409
      version: -1
      name: CVE Exploitation
      type: title
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "129"
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 4220,
          "y": 291
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "129":
    id: "129"
    taskid: 8866a349-7d57-416a-9a7d-2526746dfceb
    type: regular
    task:
      id: 8866a349-7d57-416a-9a7d-2526746dfceb
      version: -1
      name: Search CVE Exploitation alerts
      description: "Searches Demisto incidents. A summarized version of this scrips is available with the summarizedversion argument.\n\nThis automation runs using the default Limited User role, unless you explicitly change the permissions.\nFor more information, see the section about permissions here:\n- For Cortex XSOAR 6 see https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/6.x/Cortex-XSOAR-Playbook-Design-Guide/Automations \n- For Cortex XSOAR 8 Cloud see https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/8/Cortex-XSOAR-Cloud-Documentation/Create-a-script\n- For Cortex XSOAR 8.7 On-prem see https://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/8.7/Cortex-XSOAR-On-prem-Documentation/Create-a-script\nhttps://docs-cortex.paloaltonetworks.com/r/Cortex-XSOAR/6.10/Cortex-XSOAR-Administrator-Guide/Automations"
      scriptName: SearchIncidentsV2
      type: regular
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "130"
    scriptarguments:
      query:
        simple: xdralertname:"CVE Exploitation - 986328356"
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 4220,
          "y": 426
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "130":
    id: "130"
    taskid: 6c4760fe-b83a-4121-9717-be71e4065800
    type: condition
    task:
      id: 6c4760fe-b83a-4121-9717-be71e4065800
      version: -1
      name: Found CVE Exploitation alerts?
      description: 'Checks if a CVE Exploitation alert was found '
      type: condition
      iscommand: false
      brand: ""
    nexttasks:
      '#default#':
      - "7"
      "yes":
      - "131"
    separatecontext: false
    conditions:
    - label: "yes"
      condition:
      - - operator: containsString
          left:
            value:
              simple: foundIncidents.CustomFields.xdralertname
            iscontext: true
          right:
            value:
              simple: CVE Exploitation - 986328356
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 4220,
          "y": 565
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "131":
    id: "131"
    taskid: 2f230253-49ba-4bcb-a5ed-2cdea37ecea6
    type: regular
    task:
      id: 2f230253-49ba-4bcb-a5ed-2cdea37ecea6
      version: -1
      name: Set agent ID to incident context
      description: commands.local.cmd.set.incident
      script: Builtin|||setIncident
      type: regular
      iscommand: true
      brand: Builtin
    nexttasks:
      '#none#':
      - "105"
    scriptarguments:
      agentsid:
        complex:
          root: foundIncidents.CustomFields.xdralerts
          accessor: endpointid
          transformers:
          - operator: uniq
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 4220,
          "y": 756
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
view: |-
  {
    "linkLabelsPosition": {
      "130_131_yes": 0.44,
      "130_7_#default#": 0.47,
      "4_72_#default#": 0.22,
      "72_28_#default#": 0.28,
      "72_81_yes": 0.51,
      "75_28_no": 0.1,
      "78_74_yes": 0.47,
      "96_106_yes": 0.42,
      "96_28_#default#": 0.43,
      "99_38_#default#": 0.46
    },
    "paper": {
      "dimensions": {
        "height": 5626,
        "width": 3179.25,
        "x": 2580.75,
        "y": -1390
      }
    }
  }
inputs:
- key: SplunkEarliestTime
  value:
    simple: -7d@d
  required: false
  description: The earliest time for Splunk query.
  playbookInputQuery:
- key: SplunkLatestTime
  value:
    simple: now
  required: false
  description: The latest time for the Splunk search query.
  playbookInputQuery:
- key: QRadarTimeRange
  value:
    simple: Last 7 DAYS
  required: false
  description: The time range for QRadar query.
  playbookInputQuery:
- key: PlaybookDescription
  value:
    simple: "This playbook should be triggered manually or can be configured as a job.\nPlease create a new incident and choose the Cortex XDR - CVE-2025-31324 - SAP NetWeaver Visual Composer playbook and Rapid Breach Response incident type.\n\nCVE-2025-31324 is a critical zero-day vulnerability affecting the Metadata Uploader component of SAP NetWeaver Visual Composer. The vulnerability arises from missing authorization checks, allowing unauthenticated attackers to upload malicious executable binaries. Exploitation of this flaw can lead to full remote code execution (RCE) on affected systems, posing a significant risk to confidentiality, integrity, and availability.\n\n## CVE-2025-31324 - SAP NetWeaver RCE Vulnerability\n\n##   Vulnerability Overview\n\n- **Component Affected**: SAP NetWeaver Visual Composer Metadata Uploader  \n- **Endpoint**: `/developmentserver/metadatauploader`  \n- **CVE ID**: CVE-2025-31324  \n- **CVSS Score**: 10.0 (Critical)  \n- **Exploitability**: Unauthenticated remote attackers can exploit this without user interaction  \n\nThis flaw allows unauthenticated attackers to upload arbitrary files (e.g., JSP web shells), enabling remote code execution with the same privileges as the SAP application server process.  \n[Source: Unit42 - Palo Alto Networks](https://unit42.paloaltonetworks.com/threat-brief-sap-netweaver-cve-2025-31324/)\n\n\n##  Mitigation and Recommendations\n\n- **Apply Patch**: SAP Note #3594142 (released April 24, 2025)  \n- **Disable Visual Composer** if not in use  \n- **Restrict Access** to the vulnerable endpoint  \n- **Monitor for IoCs** in `/irj/servlet_jsp/irj/root/` and suspicious traffic  \n\n##  Conclusion\n\nCVE-2025-31324 is actively exploited and is critically severe. Organizations should patch immediately, monitor for compromise, and disable or restrict vulnerable components.\n\n[View official CVE details on NIST](https://nvd.nist.gov/vuln/detail/CVE-2025-31324)\n\n##  Playbook Triggers\n- Manually\n- \"CVE Exploitation - 986328356\" Agent rule\n\n##  Playbook Flow\n- Collects IoCs from Unit42 blog.\n- Downloads Sigma rules.\n- Search for CVE Exploitation alerts.\n- Directory enumeration to identify if there are already any suspicious files that might indicate a webshell.\n-  Using XQL, identify potential SAP NetWeaver instances in your environment.\n- Using XQL, check if there are events that point to any potential webshells downloaded in the directories.\n- Hunt the IoCs using Panorama and 3rd party SIEM.\n- Remediate using \"Block Indicators - Generic v3\" playbook.\n- Provides Mitigation recommendations.\n\nNote: This is a beta playbook, which lets you implement and test pre-release software. Since the playbook is beta, it might contain bugs. Updates to the pack during the beta phase might include non-backward compatible features. We appreciate your feedback on the quality and usability of the pack to help us identify issues, fix them, and continually improve."
  required: false
  description: The playbook description for the Rapid Breach Response layout.
  playbookInputQuery:
inputSections:
- inputs:
  - SplunkEarliestTime
  - SplunkLatestTime
  - QRadarTimeRange
  - PlaybookDescription
  name: General (Inputs group)
  description: Generic group for inputs
outputSections:
- outputs: []
  name: General (Outputs group)
  description: Generic group for outputs
outputs: []
tests:
- No tests (auto formatted)
fromversion: 6.10.0
supportedModules:
- agentix