id: Codecov Breach - Bash Uploader version: -1 name: Codecov Breach - Bash Uploader description: |- This playbook includes the following tasks: - Search for the Security Notice email sent from Codecov. - Collect indicators to be used in your threat hunting process. - Query network logs to detect related activity. - Search for the use of Codecov bash uploader in GitHub repositories - Query Panorama to search for logs with related anti-spyware signatures - Data Exfiltration Traffic Detection - Malicious Modified Shell Script Detection Note: This is a beta playbook, which lets you implement and test pre-release software. Since the playbook is beta, it might contain bugs. Updates to the pack during the beta phase might include non-backward compatible features. We appreciate your feedback on the quality and usability of the pack to help us identify issues, fix them, and continually improve. More information: [Codecov Security Notice](https://about.codecov.io/security-update/) starttaskid: "0" tasks: "0": id: "0" taskid: 1d029b7d-0fcf-4717-8cc6-0e174deed3af type: start task: id: 1d029b7d-0fcf-4717-8cc6-0e174deed3af version: -1 name: "" iscommand: false brand: "" description: '' nexttasks: '#none#': - "7" separatecontext: false view: |- { "position": { "x": 220, "y": -870 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 "1": id: "1" taskid: 448e1a26-0530-4faf-8166-e154230e59cb type: title task: id: 448e1a26-0530-4faf-8166-e154230e59cb version: -1 name: Extract IOCs type: title iscommand: false brand: "" description: '' nexttasks: '#none#': - "21" separatecontext: false view: |- { "position": { "x": -710, "y": 325 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 "5": id: "5" taskid: efe56337-4796-472c-8539-49f568f07e6b type: title task: id: efe56337-4796-472c-8539-49f568f07e6b version: -1 name: Hunt IOCs type: title iscommand: false brand: "" description: '' nexttasks: '#none#': - "19" - "20" separatecontext: false view: |- { "position": { "x": -710, "y": 680 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 "6": id: "6" taskid: 05d283a2-28d2-4112-8cb6-d8ba3e67e80c type: condition task: id: 05d283a2-28d2-4112-8cb6-d8ba3e67e80c version: -1 name: Is EWS enabled? description: Checks if EWS integration enabled type: condition iscommand: false brand: "" nexttasks: '#default#': - "13" "yes": - "11" separatecontext: false conditions: - label: "yes" condition: - - operator: isEqualString left: value: complex: root: modules filters: - - operator: isEqualString left: value: simple: modules.brand iscontext: true right: value: simple: EWS v2 accessor: state iscontext: true right: value: simple: active view: |- { "position": { "x": 220, "y": -420 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 "7": id: "7" taskid: bc99d94d-90fb-4d69-8062-f1e4e54dd719 type: title task: id: bc99d94d-90fb-4d69-8062-f1e4e54dd719 version: -1 name: Check if compromised type: title iscommand: false brand: "" description: '' nexttasks: '#none#': - "8" separatecontext: false view: |- { "position": { "x": 220, "y": -700 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 "8": id: "8" taskid: 9aebf153-14d8-4efa-8cbf-3241f0080615 type: title task: id: 9aebf153-14d8-4efa-8cbf-3241f0080615 version: -1 name: Codecov security notice email check type: title iscommand: false brand: "" description: '' nexttasks: '#none#': - "6" separatecontext: false view: |- { "position": { "x": 220, "y": -560 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 "11": id: "11" taskid: 3b9af3e0-4fe9-4452-8f84-3e67ff7defd8 type: regular task: id: 3b9af3e0-4fe9-4452-8f84-3e67ff7defd8 version: -1 name: 'Search for Codecov security notice email ' description: Searches for items in the specified mailbox. Specific permissions are needed for this operation to search in a target mailbox other than the default. script: '|||ews-search-mailbox' type: regular iscommand: true brand: "" nexttasks: '#none#': - "12" scriptarguments: folder-path: {} is-public: {} limit: complex: root: inputs.EWSSearchQuery_Limit message-id: {} query: complex: root: inputs.EWSSearchQuery selected-fields: {} target-mailbox: {} separatecontext: false view: |- { "position": { "x": -710, "y": -245 } } note: false timertriggers: [] ignoreworker: false skipunavailable: true quietmode: 0 "12": id: "12" taskid: f03d42f1-189a-47d9-8c7b-7a67827fd24f type: condition task: id: f03d42f1-189a-47d9-8c7b-7a67827fd24f version: -1 name: Found Codecov security notice emails? description: Searches for the Codecov Security Notice email type: condition iscommand: false brand: "" nexttasks: '#default#': - "13" "yes": - "1" separatecontext: false conditions: - label: "yes" condition: - - operator: isNotEmpty left: value: complex: root: EWS accessor: Items iscontext: true view: |- { "position": { "x": -710, "y": -55 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 "13": id: "13" taskid: 1ea37a97-35d8-49fa-8233-a594dfdf2d57 type: condition task: id: 1ea37a97-35d8-49fa-8233-a594dfdf2d57 version: -1 name: Check for affected Bash Uploader possible impact description: | If you used the following between January 31, 2021 and April 1, 2021, and did not conduct a checksum validation: Codecov-bash (bash uploader) Codecov-action (Github) Codecov-circleci-orb Codecov-bitrise-step type: condition iscommand: false brand: "" nexttasks: '#default#': - "27" "Yes": - "1" separatecontext: false view: |- { "position": { "x": 220, "y": 140 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 "14": id: "14" taskid: bc58af28-06c5-45a7-8b85-234f5c4ceea4 type: playbook task: id: bc58af28-06c5-45a7-8b85-234f5c4ceea4 version: -1 name: Palo Alto Networks - Hunting And Threat Detection description: "This is a multipurpose playbook used for hunting and threat detection.\ \ The playbook receives inputs based on hashes, IP addresses, or domain names\ \ provided manually or from outputs by other playbooks. \nWith the received\ \ indicators, the playbook leverages data received by PANW products including,\ \ Cortex Data Lake, Autofocus and Pan-OS to search for IP addresses, host\ \ names and users related to the provided indicators.\nThe output provided\ \ by the playbook facilitates pivoting searches for possibly affected IP addresses\ \ or users." playbookName: Palo Alto Networks - Hunting And Threat Detection type: playbook iscommand: false brand: "" nexttasks: '#none#': - "29" scriptarguments: IPAddresses: complex: root: IP accessor: Address transformers: - operator: uniq InternalDomainName: {} InternalHostRegex: {} InternalRange: simple: ${inputs.InternalRange} MD5: complex: root: File accessor: MD5 transformers: - operator: uniq SHA1: {} SHA256: complex: root: File accessor: SHA256 transformers: - operator: uniq URLDomain: {} separatecontext: true loop: iscommand: false exitCondition: "" wait: 1 max: 100 view: |- { "position": { "x": -960, "y": 960 } } note: false timertriggers: [] ignoreworker: false skipunavailable: true quietmode: 0 "16": id: "16" taskid: 974252c0-5c9b-4be0-8467-dfd39c59e3d1 type: playbook task: id: 974252c0-5c9b-4be0-8467-dfd39c59e3d1 version: -1 name: QRadar Indicator Hunting V2 description: 'The Playbook queries QRadar SIEM for indicators such as file hashes, IP addresses, domains, or urls. ' playbookName: QRadar Indicator Hunting V2 type: playbook iscommand: false brand: "" nexttasks: '#none#': - "29" scriptarguments: IPAddress: complex: root: IP accessor: Address transformers: - operator: uniq InternalRange: simple: ${inputs.InternalRange} InvestigationIPFields: simple: sourceip,destinationip InvestigationUserFields: simple: username MD5: complex: root: File accessor: MD5 transformers: - operator: uniq QradarIPfield: simple: sourceip,destinationip QradarMD5Field: {} QradarSHA1Field: {} QradarSHA256Field: {} QradarURLDomainField: {} SHA1: {} SHA256: complex: root: File accessor: SHA256 transformers: - operator: uniq TimeFrame: simple: LAST 7 DAYS URLDomain: {} separatecontext: true loop: iscommand: false exitCondition: "" wait: 1 max: 100 view: |- { "position": { "x": -470, "y": 960 } } note: false timertriggers: [] ignoreworker: false skipunavailable: true quietmode: 0 "18": id: "18" taskid: e2c50a93-9dcd-4b92-8fe6-0e19a0ebeeba type: playbook task: id: e2c50a93-9dcd-4b92-8fe6-0e19a0ebeeba version: -1 name: Splunk Indicator Hunting description: This playbook queries Splunk for indicators such as file hashes, IP addresses, domains, or urls. It outputs detected users, ip addresses, and hostnames related to the indicators. playbookName: Splunk Indicator Hunting type: playbook iscommand: false brand: "" nexttasks: '#none#': - "29" scriptarguments: HostFieldsToReturn: {} IPAddress: complex: root: IP accessor: Address transformers: - operator: uniq IPFieldsToReturn: {} IndexName: simple: '*' InternalDomainName: {} InternalHostRegex: {} InternalIPRange: {} MD5: complex: root: File accessor: MD5 transformers: - operator: uniq SHA1: {} SHA256: complex: root: File accessor: SHA256 transformers: - operator: uniq SelectFields: simple: source,timestamp SplunkIPField: {} SplunkMD5Field: {} SplunkSHA1Field: {} SplunkSHA256Field: {} SplunkURLDomainField: {} URLDomain: {} UserFieldsToReturn: {} earliest_time: simple: -1d event_limit: simple: "100" latest_time: {} separatecontext: true loop: iscommand: false exitCondition: "" wait: 1 max: 100 view: |- { "position": { "x": -20, "y": 960 } } note: false timertriggers: [] ignoreworker: false skipunavailable: true quietmode: 0 "19": id: "19" taskid: a8c96f19-07cb-456b-8f46-71328d1b7e86 type: title task: id: a8c96f19-07cb-456b-8f46-71328d1b7e86 version: -1 name: SIEM Hunting type: title iscommand: false brand: "" description: '' nexttasks: '#none#': - "16" - "18" separatecontext: false view: |- { "position": { "x": -240, "y": 820 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 "20": id: "20" taskid: 3b9ef253-5901-48dc-89c8-39decba4f79c type: title task: id: 3b9ef253-5901-48dc-89c8-39decba4f79c version: -1 name: Hunt Network Logs type: title iscommand: false brand: "" description: '' nexttasks: '#none#': - "14" - "28" separatecontext: false view: |- { "position": { "x": -1190, "y": 820 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 "21": id: "21" taskid: cba1718f-0b78-4ccb-8c15-6a2b7fa4ec74 type: regular task: id: cba1718f-0b78-4ccb-8c15-6a2b7fa4ec74 version: -1 name: Extract indicators from known and custom inputs description: commands.local.cmd.extract.indicators script: Builtin|||extractIndicators type: regular iscommand: true brand: Builtin nexttasks: '#none#': - "5" scriptarguments: entryID: {} filePath: {} investigationID: {} text: complex: root: inputs.KnownRelatedIOCs transformers: - operator: append args: item: value: simple: inputs.CustomIOCs iscontext: true reputationcalc: 2 separatecontext: false view: |- { "position": { "x": -710, "y": 500 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 "22": id: "22" taskid: 8d37d324-0f2c-4564-8493-b1af87f46e79 type: title task: id: 8d37d324-0f2c-4564-8493-b1af87f46e79 version: -1 name: Remediation Steps type: title iscommand: false brand: "" description: '' nexttasks: '#none#': - "23" separatecontext: false view: |- { "position": { "x": -710, "y": 1650 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 "23": id: "23" taskid: 87535b78-126e-4499-89fe-d271f0684c75 type: regular task: id: 87535b78-126e-4499-89fe-d271f0684c75 version: -1 name: 'Re-roll affected users ' description: Re-roll all of credentials for affected users, tokens, or keys located in the environment variables in their CI processes that used one of Codecov’s Bash Uploaders. type: regular iscommand: false brand: "" nexttasks: '#none#': - "24" separatecontext: false view: |- { "position": { "x": -710, "y": 1800 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 "24": id: "24" taskid: 200cb34a-de6d-4276-8ab3-d2e86f790163 type: regular task: id: 200cb34a-de6d-4276-8ab3-d2e86f790163 version: -1 name: Check env command in your CI pipeline description: 'You can determine the keys and tokens that are surfaced to your CI environment by running the env command in your CI pipeline. If anything returned from that command is considered private or sensitive, invalidating the credential and generating a new one. ' type: regular iscommand: false brand: "" nexttasks: '#none#': - "25" separatecontext: false view: |- { "position": { "x": -710, "y": 1970 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 "25": id: "25" taskid: 421e612b-e133-4596-8f81-a4e8f2444cc3 type: condition task: id: 421e612b-e133-4596-8f81-a4e8f2444cc3 version: -1 name: Used local stored version of a Bash Uploader? description: Check if the Bash Uploader is locally stored. type: condition iscommand: false brand: "" nexttasks: '#default#': - "27" "Yes": - "26" separatecontext: false view: |- { "position": { "x": -710, "y": 2140 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 "26": id: "26" taskid: c56d1f45-59a9-4a89-839c-5825e79875a3 type: regular task: id: c56d1f45-59a9-4a89-839c-5825e79875a3 version: -1 name: Check using version description: |- if you use a locally stored version of a Bash Uploader, you should check that version for the following: **curl -sm 0.5 -d “$(git remote -v)** If this appears anywhere in your locally stored Bash Uploader, you should immediately replace the bash files with the most recent version from https://codecov.io/bash. type: regular iscommand: false brand: "" nexttasks: '#none#': - "27" separatecontext: false view: |- { "position": { "x": -50, "y": 2320 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 "27": id: "27" taskid: 7647c176-90dc-4054-8eeb-f3ea3abdb691 type: title task: id: 7647c176-90dc-4054-8eeb-f3ea3abdb691 version: -1 name: Done type: title iscommand: false brand: "" description: '' separatecontext: false view: |- { "position": { "x": 220, "y": 2540 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 "28": id: "28" taskid: a037cfcc-aa5a-417c-81c7-dd569be7b783 type: playbook task: id: a037cfcc-aa5a-417c-81c7-dd569be7b783 version: -1 name: Panorama search thread-ids in threat logs description: 'Query Panorama Logs of types: traffic, threat, url, data-filtering and wildfire.' playbookName: Panorama Query Logs type: playbook iscommand: false brand: "" nexttasks: '#none#': - "29" scriptarguments: action: {} addr-dst: {} addr-src: {} filedigest: {} ip: {} log_type: simple: threat port-dst: {} query: simple: (threatid eq 86353) or (threatid eq 86355) rule: {} time-generated: {} url: {} zone-dst: {} zone-src: {} separatecontext: true loop: iscommand: false exitCondition: "" wait: 1 max: 100 view: |- { "position": { "x": -1430, "y": 960 } } note: false timertriggers: [] ignoreworker: false skipunavailable: true quietmode: 0 "29": id: "29" taskid: b1872629-a361-4e70-8926-f496e1128990 type: title task: id: b1872629-a361-4e70-8926-f496e1128990 version: -1 name: Scope affected repositories type: title iscommand: false brand: "" description: '' nexttasks: '#none#': - "31" separatecontext: false view: |- { "position": { "x": -710, "y": 1160 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 "30": id: "30" taskid: 40bd0498-02d5-450c-8d93-2e436e69dec5 type: regular task: id: 40bd0498-02d5-450c-8d93-2e436e69dec5 version: -1 name: Search Codecov in Git repository description: Searches for code in repositories that match a given query. script: '|||GitHub-search-code' type: regular iscommand: true brand: "" nexttasks: '#none#': - "22" scriptarguments: limit: {} page_number: {} page_size: {} query: complex: root: inputs.Github_Code_Search_query separatecontext: false view: |- { "position": { "x": -430, "y": 1480 } } note: false timertriggers: [] ignoreworker: false skipunavailable: true quietmode: 0 "31": id: "31" taskid: 3e428184-fcd8-4c78-830d-01779ad8f0b5 type: condition task: id: 3e428184-fcd8-4c78-830d-01779ad8f0b5 version: -1 name: Is GitHub integration enabled? description: Checks if GitHub integration enabled. type: condition iscommand: false brand: "" nexttasks: '#default#': - "22" "yes": - "30" separatecontext: false conditions: - label: "yes" condition: - - operator: isEqualString left: value: complex: root: modules filters: - - operator: isEqualString left: value: simple: modules.brand iscontext: true right: value: simple: GitHub accessor: state iscontext: true right: value: simple: active view: |- { "position": { "x": -710, "y": 1310 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 view: |- { "linkLabelsPosition": { "12_13_#default#": 0.2, "12_1_yes": 0.46, "13_1_Yes": 0.24, "13_27_#default#": 0.1, "25_26_Yes": 0.43, "25_27_#default#": 0.2, "31_22_#default#": 0.56, "31_30_yes": 0.54, "6_11_yes": 0.17, "6_13_#default#": 0.28 }, "paper": { "dimensions": { "height": 3475, "width": 2030, "x": -1430, "y": -870 } } } inputs: - key: KnownRelatedIOCs value: simple: 104.248.94.23 required: false description: Known related IOCs to the Codecov Bash Uploader breach to hunt. playbookInputQuery: - key: CustomIOCs value: {} required: false description: Add your own custom Codecov Bash Uploader breach IOCs to hunt. playbookInputQuery: - key: EWSSearchQuery value: simple: From:security@codecov.io AND Subject:Bash Uploader Security Notice AND Received:three months required: false description: The EWS query to find the Codecov security notice email playbookInputQuery: - key: EWSSearchQuery_Limit value: simple: "50" required: false description: The limit of results to return from the search playbookInputQuery: - key: Github_Code_Search_query value: simple: https://codecov.io/bash+in:file required: false description: Github query to search for Codecov bash uploader use. playbookInputQuery: - key: InternalRange value: complex: root: lists accessor: PrivateIPs transformers: - operator: RegexExtractAll args: error_if_no_match: {} ignore_case: {} multi_line: {} period_matches_newline: {} regex: value: simple: (\b(?:\d{1,3}\.){3}\d{1,3}\b/\d{1,2}) unpack_matches: {} - operator: join args: separator: value: simple: ',' required: false description: 'A list of internal IP ranges to check IP addresses against. The comma-separated list should be provided in CIDR notation. For example, a list of ranges would be: "172.16.0.0/12,10.0.0.0/8,192.168.0.0/16" (without quotes).' playbookInputQuery: outputs: [] tests: - No tests (auto formatted) fromversion: 5.5.0