NSA - 5 Security Vulnerabilities Under Active Nation-State Attack Deprecated
Deprecated. No available replacement. Russian Foreign Intelligence Service (SVR) actors (also known as APT29, Cozy Bear, and The Dukes) frequently use publicly known vulnerabilities to conduct widespread scanning and exploitation. This playbook should be trigger manually and includes the following tasks: - Enrich related known CVEs reported in the US agencies alert. - Search for unpatched endpoints vulnerable to the exploits. - Search for vulnerable assets facing the internet using Expanse. Note: This is a beta playbook, which lets you implement and test pre-release software. Since the playbook is beta, it might contain bugs. Updates to the pack during the beta phase might include non-backward compatible features. We appreciate your feedback on the quality and usability of the pack to help us identify issues, fix them, and continually improve. More information: [Cyber Security Advisory] (https://media.defense.gov/2021/Apr/15/2002621240/-1/-1/0/CSA_SVR_TARGETS_US_ALLIES_UOO13234021.PDF/CSA_SVR_TARGETS_US_ALLIES_UOO13234021.PDF)
Cortex Xpanse by Palo Alto Networks (Deprecated) · 22 tasks · 1 input · 0 outputs
Details
| ID | NSA - 5 Security Vulnerabilities Under Active Nation-State Attack |
|---|---|
| From Version | 6.0.0 |
| Tasks | 22 |
README
Russian Foreign Intelligence Service (SVR) actors (also known as APT29, Cozy Bear, and The Dukes) frequently use publicly known vulnerabilities to conduct widespread scanning and exploitation.
This playbook should be trigger manually and includes the following tasks:
- Enrich related known CVEs reported in the US agencies alert
- Search for unpatched endpoints vulnerable to the exploits.
- Search for vulnerable assets facing the internet using Expanse.
Note: This is a beta playbook, which lets you implement and test pre-release software. Since the playbook is beta, it might contain bugs. Updates to the pack during the beta phase might include non-backward compatible features. We appreciate your feedback on the quality and usability of the pack to help us identify issues, fix them, and continually improve.
More information:
[Cyber Security Advisory] (https://media.defense.gov/2021/Apr/15/2002621240/-1/-1/0/CSA_SVR_TARGETS_US_ALLIES_UOO13234021.PDF/CSA_SVR_TARGETS_US_ALLIES_UOO13234021.PDF)
Dependencies
This playbook uses the following sub-playbooks, integrations, and scripts.
Sub-playbooks
- CVE Enrichment - Generic v2
- Search Endpoint by CVE - Generic
Integrations
- ExpanseV2
Scripts
- SearchIncidentsV2
Commands
- linkIncidents
- extractIndicators
- expanse-get-issues
Playbook Inputs
| Name | Description | Default Value | Required |
|---|---|---|---|
| Related_CVEs | Known related CVEs to hunt | CVE-2018-13379, CVE-2019-9670, CVE-2019-11510, CVE-2019-19781, CVE-2020-4006 | Optional |
Playbook Outputs
There are no outputs for this playbook.
Playbook Image

Inputs
Related_CVEs— Known related CVEs to hunt
Commands used
expanse-get-issues
extractIndicators
linkIncidents
Flowchart
id: NSA - 5 Security Vulnerabilities Under Active Nation-State Attack version: -1 name: NSA - 5 Security Vulnerabilities Under Active Nation-State Attack deprecated: true description: "Deprecated. No available replacement. \ \ Russian Foreign Intelligence Service (SVR) actors (also known as APT29,\ \ Cozy Bear, and The Dukes) frequently use publicly known vulnerabilities to conduct\ \ widespread scanning and exploitation.\nThis playbook should be trigger manually\ \ and includes the following tasks:\n- Enrich related known CVEs reported in the US agencies alert.\n\ - Search for unpatched endpoints vulnerable to the exploits.\n- Search for vulnerable assets facing\ \ the internet using Expanse.\n\nNote: This is a beta playbook,\ \ which lets you implement and test pre-release software. Since the playbook is\ \ beta, it might contain bugs. Updates to the pack during the beta phase might include\ \ non-backward compatible features. We appreciate your feedback on the quality and\ \ usability of the pack to help us identify issues, fix them, and continually improve.\ \ \n\nMore information:\n[Cyber Security Advisory] (https://media.defense.gov/2021/Apr/15/2002621240/-1/-1/0/CSA_SVR_TARGETS_US_ALLIES_UOO13234021.PDF/CSA_SVR_TARGETS_US_ALLIES_UOO13234021.PDF)" starttaskid: "0" tasks: "0": id: "0" taskid: ed616dd6-95ab-487c-84df-45786d0a2a8d type: start task: id: ed616dd6-95ab-487c-84df-45786d0a2a8d version: -1 name: "" iscommand: false brand: "" description: '' nexttasks: '#none#': - "1" separatecontext: false view: |- { "position": { "x": -390, "y": -30 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 "1": id: "1" taskid: 0930c3cd-7e6b-425d-8a16-b7934c5cb2a4 type: title task: id: 0930c3cd-7e6b-425d-8a16-b7934c5cb2a4 version: -1 name: Enrich CVE's type: title iscommand: false brand: "" description: '' nexttasks: '#none#': - "24" separatecontext: false view: |- { "position": { "x": -390, "y": 125 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 "2": id: "2" taskid: 8f91e61a-f313-44be-8d70-d388fdf5ed1c type: regular task: id: 8f91e61a-f313-44be-8d70-d388fdf5ed1c version: -1 name: Extract CVEs from playbook inputs description: commands.local.cmd.extract.indicators script: Builtin|||extractIndicators type: regular iscommand: true brand: Builtin nexttasks: '#none#': - "5" scriptarguments: entryID: {} filePath: {} investigationID: {} text: complex: root: inputs.Related_CVEs separatecontext: false view: |- { "position": { "x": -390, "y": 450 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 "5": id: "5" taskid: 010befdd-98d2-4ed9-8ae3-e208b8b0a98d type: title task: id: 010befdd-98d2-4ed9-8ae3-e208b8b0a98d version: -1 name: Hunt Indicators type: title iscommand: false brand: "" description: '' nexttasks: '#none#': - "12" - "18" separatecontext: false view: |- { "position": { "x": -390, "y": 610 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 "6": id: "6" taskid: e334c9fd-75d2-492c-88cb-00685cf4f17e type: condition task: id: e334c9fd-75d2-492c-88cb-00685cf4f17e version: -1 name: Is Expanse enabled? description: Checks if Expanse integration enabled type: condition iscommand: false brand: "" nexttasks: '#default#': - "21" "yes": - "7" - "8" - "9" - "10" - "11" separatecontext: false conditions: - label: "yes" condition: - - operator: isEqualString left: value: complex: root: modules filters: - - operator: isEqualString left: value: simple: modules.brand iscontext: true right: value: simple: ExpanseV2 accessor: state iscontext: true right: value: simple: active view: |- { "position": { "x": 470, "y": 880 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 "7": id: "7" taskid: 3589d046-f25d-40dd-81b6-e2fd9d5d0b0e type: regular task: id: 3589d046-f25d-40dd-81b6-e2fd9d5d0b0e version: -1 name: Expanse search for Pulse Secure PCS description: | Search for vulnerable Pulse Secure server with Expanse. script: '|||expanse-get-issues' type: regular iscommand: true brand: "" nexttasks: '#none#': - "14" scriptarguments: activity_status: {} assignee: {} business_unit: {} content_search: {} created_after: {} created_before: {} domain_search: {} inet_search: {} issue_type: simple: VPN Device limit: {} modified_after: {} modified_before: {} port_number: {} priority: {} progress_status: {} provider: {} sort: {} tag: {} separatecontext: false view: |- { "position": { "x": 730, "y": 1240 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 "8": id: "8" taskid: 647f4923-bbc9-4df2-8c8a-201fa1429d4e type: regular task: id: 647f4923-bbc9-4df2-8c8a-201fa1429d4e version: -1 name: Expanse search for FortiOS SSL VPN description: | Search for vulnerable FortiOS SSL VPN server with Expanse. script: '|||expanse-get-issues' type: regular iscommand: true brand: "" nexttasks: '#none#': - "14" scriptarguments: activity_status: {} assignee: {} business_unit: {} content_search: {} created_after: {} created_before: {} domain_search: {} inet_search: {} issue_type: simple: Fortinet Device limit: {} modified_after: {} modified_before: {} port_number: {} priority: {} progress_status: {} provider: {} sort: {} tag: {} separatecontext: false view: |- { "position": { "x": 470, "y": 1120 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 "9": id: "9" taskid: 2f032a8a-892f-4fcb-898a-cf1d6e0f62d9 type: regular task: id: 2f032a8a-892f-4fcb-898a-cf1d6e0f62d9 version: -1 name: Expanse search for Synacor Zimbra Collaboration Suite description: | Search for vulnerable Synacor Zimbra server with Expanse. script: '|||expanse-get-issues' type: regular iscommand: true brand: "" nexttasks: '#none#': - "14" scriptarguments: activity_status: {} assignee: {} business_unit: {} content_search: {} created_after: {} created_before: {} domain_search: {} inet_search: {} issue_type: simple: Synacor Zimbra Collaboration Suite limit: {} modified_after: {} modified_before: {} port_number: {} priority: {} progress_status: {} provider: {} sort: {} tag: {} separatecontext: false view: |- { "position": { "x": 210, "y": 1240 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 "10": id: "10" taskid: 531b8b65-6387-435d-8f69-909643a8d629 type: regular task: id: 531b8b65-6387-435d-8f69-909643a8d629 version: -1 name: Expanse search for VMware Workspace One Access Server description: | Search for vulnerable Vmware Workspace One server with Expanse. script: '|||expanse-get-issues' type: regular iscommand: true brand: "" nexttasks: '#none#': - "14" scriptarguments: activity_status: {} assignee: {} business_unit: {} content_search: {} created_after: {} created_before: {} domain_search: {} inet_search: {} issue_type: simple: VMware Workspace ONE Access Server limit: {} modified_after: {} modified_before: {} port_number: {} priority: {} progress_status: {} provider: {} sort: {} tag: {} separatecontext: false view: |- { "position": { "x": 980, "y": 1360 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 "11": id: "11" taskid: b967d8e1-75c8-4294-8fe9-342870975309 type: regular task: id: b967d8e1-75c8-4294-8fe9-342870975309 version: -1 name: Expanse search for Citrix Application Delivery Controller description: Search for vulnerable Citrix server with Expanse. script: '|||expanse-get-issues' type: regular iscommand: true brand: "" nexttasks: '#none#': - "14" scriptarguments: activity_status: {} assignee: {} business_unit: {} content_search: {} created_after: {} created_before: {} domain_search: {} inet_search: {} issue_type: simple: Citrix Application Delivery Controller limit: {} modified_after: {} modified_before: {} port_number: {} priority: {} progress_status: {} provider: {} sort: {} tag: {} separatecontext: false view: |- { "position": { "x": -30, "y": 1360 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 "12": id: "12" taskid: 2cc967e6-e975-41cc-8fb1-2a782f2380e4 type: playbook task: id: 2cc967e6-e975-41cc-8fb1-2a782f2380e4 version: -1 name: Search Endpoint by CVE - Generic description: Hunt for assets with a given CVE using available tools playbookName: Search Endpoint by CVE - Generic type: playbook iscommand: false brand: "" nexttasks: '#none#': - "21" scriptarguments: CVE_ID: complex: root: inputs.Related_CVEs separatecontext: true loop: iscommand: false exitCondition: "" wait: 1 max: 100 view: |- { "position": { "x": -390, "y": 860 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 "14": id: "14" taskid: f9326536-ddcc-4a8b-87c6-ce1eae292c9e type: title task: id: f9326536-ddcc-4a8b-87c6-ce1eae292c9e version: -1 name: Link XSOAR Incidents type: title iscommand: false brand: "" description: '' nexttasks: '#none#': - "19" separatecontext: false view: |- { "position": { "x": 470, "y": 1540 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 "15": id: "15" taskid: 4e7aae57-ce5f-48e0-8e31-d738f674dd02 type: condition task: id: 4e7aae57-ce5f-48e0-8e31-d738f674dd02 version: -1 name: Are there any affected assets? description: Checks if there are any affected assets from the Expanse issues and the CVEs hunt type: condition iscommand: false brand: "" nexttasks: '#default#': - "17" "yes": - "16" separatecontext: false conditions: - label: "yes" condition: - - operator: isExists left: value: complex: root: Endpoint iscontext: true - operator: isExists left: value: complex: root: Expanse iscontext: true view: |- { "position": { "x": -390, "y": 2500 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 "16": id: "16" taskid: ff20b4c0-752b-482b-81da-c57cc3dfc727 type: regular task: id: ff20b4c0-752b-482b-81da-c57cc3dfc727 version: -1 name: Install related patch on affected assets description: |- Verify and update if necessary the affected assets. Link to related patches: [1. Fortinet](https://www.fortinet.com/blog/psirt-blogs/update-regarding-cve-2018-13379) [2. VMware](https://www.vmware.com/security/advisories/VMSA-2020-0027.html) [3. Citrix](https://support.citrix.com/article/CTX267027) [4. Pulse](https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44101) [5. Zimbra](https://wiki.zimbra.com/wiki/Zimbra_Releases/8.7.11/P10) type: regular iscommand: false brand: "" nexttasks: '#none#': - "17" separatecontext: false view: |- { "position": { "x": -130, "y": 2670 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 "17": id: "17" taskid: 82aa290c-95b0-4b82-8a5d-ded6b9d66b19 type: title task: id: 82aa290c-95b0-4b82-8a5d-ded6b9d66b19 version: -1 name: Done type: title iscommand: false brand: "" description: '' separatecontext: false view: |- { "position": { "x": -390, "y": 2840 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 "18": id: "18" taskid: 9a0993a2-34f7-4d66-8adb-81230807ea5d type: title task: id: 9a0993a2-34f7-4d66-8adb-81230807ea5d version: -1 name: Expanse Search Related Issues type: title iscommand: false brand: "" description: '' nexttasks: '#none#': - "6" separatecontext: false view: |- { "position": { "x": 470, "y": 765 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 "19": id: "19" taskid: 55f2a67c-9673-40da-871f-f3f0a67b74ff type: regular task: id: 55f2a67c-9673-40da-871f-f3f0a67b74ff version: -1 name: Search related Expanse incident description: Searches Demisto incidents scriptName: SearchIncidentsV2 type: regular iscommand: false brand: "" nexttasks: '#none#': - "22" scriptarguments: details: {} fromclosedate: {} fromdate: {} fromduedate: {} id: {} level: {} name: {} notstatus: {} owner: {} page: {} query: simple: type:"Expanse Issue" and name:VMware Workspace One Access Server or name:Vpn Device or name:Fortinet Device or name:Synacor Zimbra Collaboration Suite or name:Citrix Application Delivery Controller reason: {} size: {} sort: {} status: {} toclosedate: {} todate: {} toduedate: {} type: {} separatecontext: false view: |- { "position": { "x": 470, "y": 1680 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 "20": id: "20" taskid: b5aff074-50af-447a-8872-b02543e3b70d type: regular task: id: b5aff074-50af-447a-8872-b02543e3b70d version: -1 name: Link related incidents description: commands.local.cmd.linkIncidents script: Builtin|||linkIncidents type: regular iscommand: true brand: Builtin nexttasks: '#none#': - "23" scriptarguments: action: {} incidentId: {} linkedIncidentIDs: complex: root: foundIncidents accessor: id transformers: - operator: uniq separatecontext: false view: |- { "position": { "x": 770, "y": 2030 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 "21": id: "21" taskid: fcd72390-c33e-4241-8700-bcbcd03f7fd1 type: title task: id: fcd72390-c33e-4241-8700-bcbcd03f7fd1 version: -1 name: Mitigation type: title iscommand: false brand: "" description: '' nexttasks: '#none#': - "15" separatecontext: false view: |- { "position": { "x": -390, "y": 2370 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 "22": id: "22" taskid: c785fcca-4b96-455a-82ef-da7d1d5a4236 type: condition task: id: c785fcca-4b96-455a-82ef-da7d1d5a4236 version: -1 name: Found related Expanse issues in XSOAR? description: Checks if found related Expanse issues in XSOAR. type: condition iscommand: false brand: "" nexttasks: '#default#': - "21" "yes": - "20" separatecontext: false conditions: - label: "yes" condition: - - operator: isNotEmpty left: value: complex: root: foundIncidents iscontext: true view: |- { "position": { "x": 470, "y": 1850 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 "23": id: "23" taskid: a5d79545-c6e0-43c2-8d02-9acee9fe985f type: regular task: id: a5d79545-c6e0-43c2-8d02-9acee9fe985f version: -1 name: Review Expanse incident description: |- Review the Expanse incidents and investigate the connections. Check for abnormalities and verify the legitimacy of the network connection. type: regular iscommand: false brand: "" nexttasks: '#none#': - "21" separatecontext: false view: |- { "position": { "x": 770, "y": 2190 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 "24": id: "24" taskid: 912f3e14-ddfe-40ed-8dd3-e9d828bdb7d5 type: playbook task: id: 912f3e14-ddfe-40ed-8dd3-e9d828bdb7d5 version: -1 name: CVE Enrichment - Generic v2 playbookName: CVE Enrichment - Generic v2 type: playbook iscommand: false brand: "" description: '' nexttasks: '#none#': - "2" scriptarguments: cve_id: complex: root: inputs.Related_CVEs separatecontext: false loop: iscommand: false exitCondition: "" wait: 1 max: 100 view: |- { "position": { "x": -390, "y": 280 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 view: |- { "linkLabelsPosition": { "15_16_yes": 0.46, "15_17_#default#": 0.5, "22_20_yes": 0.49, "22_21_#default#": 0.13, "6_10_yes": 0.74, "6_11_yes": 0.74, "6_21_#default#": 0.37, "6_7_yes": 0.8, "6_9_yes": 0.78 }, "paper": { "dimensions": { "height": 2935, "width": 1750, "x": -390, "y": -30 } } } inputs: - key: Related_CVEs value: simple: CVE-2018-13379, CVE-2019-9670, CVE-2019-11510, CVE-2019-19781, CVE-2020-4006 required: false description: Known related CVEs to hunt playbookInputQuery: outputs: [] tests: - No tests (auto formatted) fromversion: 6.0.0