v4.9.0
·
6330 commits
to develop
since this release
New Analytics
- Ivanti EPMM Remote Unauthenticated API Access CVE-2023-35078
- Ivanti EPMM Remote Unauthenticated API Access CVE-2023-35082
- Citrix ShareFile Exploitation CVE-2023-24489
- Windows Powershell RemoteSigned File
- PowerShell Script Block With URL Chain (External Contributor @nterl0k )
- PowerShell WebRequest Using Memory Stream (External Contributor @nterl0k )
- Suspicious Process Executed From Container File (External Contributor @nterl0k )
- Windows Registry Payload Injection (External Contributor (External Contributor @nterl0k )
- Windows Scheduled Task Service Spawned Shell (External Contributor @nterl0k )
Updated Analytics
- Clop Common Exec Parameter (External Contributor @DipsyTipsy)
- O365 Added Service Principal
- O365 New Federated Domain Added
- O365 Excessive SSO logon errors
New Analytic Story
- Ivanti EPMM Remote Unauthenticated Access
- Citrix ShareFile RCE CVE-2023-24489
Other Updates
- Updated detections with test datasets
- Updated several observables in detections