From 0209f490484ac3619bd1b3fadb6c1bd342d6f55d Mon Sep 17 00:00:00 2001 From: nasbench <8741929+nasbench@users.noreply.github.com> Date: Tue, 22 Sep 2026 11:34:44 +0200 Subject: [PATCH 1/2] update how_to_implement for nvm content --- ...r_spawned_unix_shell_with_external_connection.yml | 11 +++++------ ...isco_nvm___curl_execution_with_insecure_flags.yml | 11 +++++------ ...__installation_of_typosquatted_python_package.yml | 12 +++++------- ...or_mshta_network_execution_without_url_in_cli.yml | 11 +++++------ ..._non_network_binary_making_network_connection.yml | 11 +++++------ ...script_network_connection_for_a_long_duration.yml | 9 ++++----- ..._nvm___outbound_connection_to_suspicious_port.yml | 11 +++++------ ..._nvm___rclone_execution_with_network_activity.yml | 11 +++++------ ...ll32_abuse_of_mshtml_dll_for_payload_download.yml | 11 +++++------ ...ript_from_archive_triggering_network_activity.yml | 11 +++++------ ...suspicious_download_from_file_sharing_website.yml | 11 +++++------ ...suspicious_file_download_via_headless_browser.yml | 11 +++++------ ..._network_connection_from_process_with_no_args.yml | 11 +++++------ ...icious_network_connection_initiated_via_msxsl.yml | 11 +++++------ ...s_network_connection_to_ip_lookup_service_api.yml | 11 +++++------ ..._webserver_download_from_file_sharing_website.yml | 11 +++++------ 16 files changed, 79 insertions(+), 96 deletions(-) diff --git a/detections/endpoint/cisco_nvm___browser_spawned_unix_shell_with_external_connection.yml b/detections/endpoint/cisco_nvm___browser_spawned_unix_shell_with_external_connection.yml index 768ff926ec..15f820549c 100644 --- a/detections/endpoint/cisco_nvm___browser_spawned_unix_shell_with_external_connection.yml +++ b/detections/endpoint/cisco_nvm___browser_spawned_unix_shell_with_external_connection.yml @@ -1,8 +1,8 @@ name: Cisco NVM - Browser Spawned Unix Shell with External Connection id: 6f2de8d1-9a2d-4c7a-9b8c-3b8a2f7d0e41 -version: 1 +version: 2 creation_date: '2026-09-02' -modification_date: '2026-09-02' +modification_date: '2026-09-22' author: Maria Jose Erquiaga, Splunk status: production type: Anomaly @@ -60,14 +60,13 @@ search: | | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `cisco_nvm___browser_spawned_unix_shell_with_external_connection_filter` -how_to_implement: | +how_to_implement: |- This search requires Network Visibility Module logs, which includes the flow data sourcetype. This search uses an input macro named `cisco_network_visibility_module_flowdata`. - We strongly recommend that you specify your environment-specific configurations - (index, source, sourcetype, etc.) for Cisco Network Visibility Module logs. + We strongly recommend that you specify your environment-specific configurations (index, source, sourcetype, etc.) for Cisco Network Visibility Module logs. Replace the macro definition with configurations for your Splunk environment. The search also uses a post-filter macro designed to filter out known false positives. - The logs are to be ingested using the Splunk Add-on for Cisco Endpoint Security Analytics (CESA) (https://splunkbase.splunk.com/app/4221). + The logs are to be ingested using the Cisco Security Cloud App for Splunk (https://splunkbase.splunk.com/app/7404). known_false_positives: | Legitimate workflows may launch Unix command interpreters from browser contexts, including developer tooling, software installers, SSO helpers, browser extensions, and automation wrappers. Tuning may be required for approved applications, users, and destinations. references: diff --git a/detections/endpoint/cisco_nvm___curl_execution_with_insecure_flags.yml b/detections/endpoint/cisco_nvm___curl_execution_with_insecure_flags.yml index 4f2287fd2b..4291c2f1be 100644 --- a/detections/endpoint/cisco_nvm___curl_execution_with_insecure_flags.yml +++ b/detections/endpoint/cisco_nvm___curl_execution_with_insecure_flags.yml @@ -1,8 +1,8 @@ name: Cisco NVM - Curl Execution With Insecure Flags id: cc695238-3117-4e60-aa83-4beac2a42c69 -version: 8 +version: 9 creation_date: '2025-07-01' -modification_date: '2026-07-14' +modification_date: '2026-09-22' author: Nasreddine Bencherchali, Splunk status: production type: Anomaly @@ -45,14 +45,13 @@ search: | additional_logged_in_users_list module_name_list module_hash_list src dest_hostname dest dest_port transport firstTime lastTime | `cisco_nvm___curl_execution_with_insecure_flags_filter` -how_to_implement: | +how_to_implement: |- This search requires Network Visibility Module logs, which includes the flow data sourcetype. This search uses an input macro named `cisco_network_visibility_module_flowdata`. - We strongly recommend that you specify your environment-specific configurations - (index, source, sourcetype, etc.) for Cisco Network Visibility Module logs. + We strongly recommend that you specify your environment-specific configurations (index, source, sourcetype, etc.) for Cisco Network Visibility Module logs. Replace the macro definition with configurations for your Splunk environment. The search also uses a post-filter macro designed to filter out known false positives. - The logs are to be ingested using the Splunk Add-on for Cisco Endpoint Security Analytics (CESA) (https://splunkbase.splunk.com/app/4221). + The logs are to be ingested using the Cisco Security Cloud App for Splunk (https://splunkbase.splunk.com/app/7404). known_false_positives: | Usage of these flags to reach public IPs or uncommon destinations should be reviewed. Tuning may be required for domains with known certificate issues. diff --git a/detections/endpoint/cisco_nvm___installation_of_typosquatted_python_package.yml b/detections/endpoint/cisco_nvm___installation_of_typosquatted_python_package.yml index 1230dc1fe3..c79fc601f8 100644 --- a/detections/endpoint/cisco_nvm___installation_of_typosquatted_python_package.yml +++ b/detections/endpoint/cisco_nvm___installation_of_typosquatted_python_package.yml @@ -1,8 +1,8 @@ name: Cisco NVM - Installation of Typosquatted Python Package id: 5e3f6b44-42cb-4f8a-99f0-59e78a52ea1d -version: 5 +version: 6 creation_date: '2025-07-01' -modification_date: '2026-07-14' +modification_date: '2026-09-22' author: Nasreddine Bencherchali, Splunk status: production type: TTP @@ -43,15 +43,13 @@ search: | process_integrity_level process_path process_name process_arguments process_hash process_id additional_logged_in_users_list module_name_list module_hash_list | `cisco_nvm___installation_of_typosquatted_python_package_filter` -how_to_implement: | +how_to_implement: |- This search requires Network Visibility Module logs, which includes the flow data sourcetype. This search uses an input macro named `cisco_network_visibility_module_flowdata`. - We strongly recommend that you specify your environment-specific configurations - (index, source, sourcetype, etc.) for Cisco Network Visibility Module logs. + We strongly recommend that you specify your environment-specific configurations (index, source, sourcetype, etc.) for Cisco Network Visibility Module logs. Replace the macro definition with configurations for your Splunk environment. The search also uses a post-filter macro designed to filter out known false positives. - The logs are to be ingested using the Splunk Add-on for Cisco Endpoint Security Analytics (CESA) (https://splunkbase.splunk.com/app/4221). - In addition to this, the search make use of the lookup "typo_squatted_python_packages". Which needs to be configured and tuned. + The logs are to be ingested using the Cisco Security Cloud App for Splunk (https://splunkbase.splunk.com/app/7404). known_false_positives: | False positives should be very minimal to non existent, as the names of the packages in the lookup are all extracted from previously malicious packages. references: diff --git a/detections/endpoint/cisco_nvm___mshtml_or_mshta_network_execution_without_url_in_cli.yml b/detections/endpoint/cisco_nvm___mshtml_or_mshta_network_execution_without_url_in_cli.yml index 39f753ba7e..e2b0c93aa3 100644 --- a/detections/endpoint/cisco_nvm___mshtml_or_mshta_network_execution_without_url_in_cli.yml +++ b/detections/endpoint/cisco_nvm___mshtml_or_mshta_network_execution_without_url_in_cli.yml @@ -1,8 +1,8 @@ name: Cisco NVM - MSHTML or MSHTA Network Execution Without URL in CLI id: f2a9df84-9b01-4a21-9e3a-7aa1a217f69e -version: 6 +version: 7 creation_date: '2025-07-01' -modification_date: '2026-07-14' +modification_date: '2026-09-22' author: Nasreddine Bencherchali, Splunk status: production type: Anomaly @@ -48,14 +48,13 @@ search: | additional_logged_in_users_list module_name_list module_hash_list src dest_hostname dest dest_port transport firstTime lastTime | `cisco_nvm___mshtml_or_mshta_network_execution_without_url_in_cli_filter` -how_to_implement: | +how_to_implement: |- This search requires Network Visibility Module logs, which includes the flow data sourcetype. This search uses an input macro named `cisco_network_visibility_module_flowdata`. - We strongly recommend that you specify your environment-specific configurations - (index, source, sourcetype, etc.) for Cisco Network Visibility Module logs. + We strongly recommend that you specify your environment-specific configurations (index, source, sourcetype, etc.) for Cisco Network Visibility Module logs. Replace the macro definition with configurations for your Splunk environment. The search also uses a post-filter macro designed to filter out known false positives. - The logs are to be ingested using the Splunk Add-on for Cisco Endpoint Security Analytics (CESA) (https://splunkbase.splunk.com/app/4221). + The logs are to be ingested using the Cisco Security Cloud App for Splunk (https://splunkbase.splunk.com/app/7404). known_false_positives: | False positives should be minimal as the presence of a network connection during such executions increases the likelihood of malicious behavior. references: diff --git a/detections/endpoint/cisco_nvm___non_network_binary_making_network_connection.yml b/detections/endpoint/cisco_nvm___non_network_binary_making_network_connection.yml index 30d1478029..dc296fbfa2 100644 --- a/detections/endpoint/cisco_nvm___non_network_binary_making_network_connection.yml +++ b/detections/endpoint/cisco_nvm___non_network_binary_making_network_connection.yml @@ -1,8 +1,8 @@ name: Cisco NVM - Non-Network Binary Making Network Connection id: c6db35af-8a0e-4b61-88ed-738e66f15715 -version: 6 +version: 7 creation_date: '2025-07-01' -modification_date: '2026-07-14' +modification_date: '2026-09-22' author: Nasreddine Bencherchali, Splunk status: production type: Anomaly @@ -46,14 +46,13 @@ search: | additional_logged_in_users_list module_name_list module_hash_list src dest_hostname dest dest_port transport firstTime lastTime | `cisco_nvm___non_network_binary_making_network_connection_filter` -how_to_implement: | +how_to_implement: |- This search requires Network Visibility Module logs, which includes the flow data sourcetype. This search uses an input macro named `cisco_network_visibility_module_flowdata`. - We strongly recommend that you specify your environment-specific configurations - (index, source, sourcetype, etc.) for Cisco Network Visibility Module logs. + We strongly recommend that you specify your environment-specific configurations (index, source, sourcetype, etc.) for Cisco Network Visibility Module logs. Replace the macro definition with configurations for your Splunk environment. The search also uses a post-filter macro designed to filter out known false positives. - The logs are to be ingested using the Splunk Add-on for Cisco Endpoint Security Analytics (CESA) (https://splunkbase.splunk.com/app/4221). + The logs are to be ingested using the Cisco Security Cloud App for Splunk (https://splunkbase.splunk.com/app/7404). known_false_positives: | Rare cases may exist where these binaries are used by plugins or third-party extensions to initiate outbound communication. However, such behavior is extremely uncommon and should be investigated for potential injection or abuse. diff --git a/detections/endpoint/cisco_nvm___osascript_network_connection_for_a_long_duration.yml b/detections/endpoint/cisco_nvm___osascript_network_connection_for_a_long_duration.yml index 2b52bc3386..f9652d8760 100644 --- a/detections/endpoint/cisco_nvm___osascript_network_connection_for_a_long_duration.yml +++ b/detections/endpoint/cisco_nvm___osascript_network_connection_for_a_long_duration.yml @@ -1,8 +1,8 @@ name: Cisco NVM - Osascript Network Connection for a Long Duration id: 6bc88a9d-f7de-4257-b526-acf15bc5a517 -version: 1 +version: 2 creation_date: '2026-09-18' -modification_date: '2026-09-18' +modification_date: '2026-09-22' author: Radka Viskova, Splunk status: production type: Anomaly @@ -46,11 +46,10 @@ search: |- how_to_implement: |- This search requires Network Visibility Module logs, which includes the flow data sourcetype. This search uses an input macro named `cisco_network_visibility_module_flowdata`. - We strongly recommend that you specify your environment-specific configurations - (index, source, sourcetype, etc.) for Cisco Network Visibility Module logs. + We strongly recommend that you specify your environment-specific configurations (index, source, sourcetype, etc.) for Cisco Network Visibility Module logs. Replace the macro definition with configurations for your Splunk environment. The search also uses a post-filter macro designed to filter out known false positives. - The logs are to be ingested using the Splunk Add-on for Cisco Endpoint Security Analytics (CESA) (https://splunkbase.splunk.com/app/4221). + The logs are to be ingested using the Cisco Security Cloud App for Splunk (https://splunkbase.splunk.com/app/7404). known_false_positives: |- Legitimate administrative scripting, automation, software deployment, or support workflows that use osascript for long-running network operations. references: diff --git a/detections/endpoint/cisco_nvm___outbound_connection_to_suspicious_port.yml b/detections/endpoint/cisco_nvm___outbound_connection_to_suspicious_port.yml index 012a98db4f..4fbd80b96e 100644 --- a/detections/endpoint/cisco_nvm___outbound_connection_to_suspicious_port.yml +++ b/detections/endpoint/cisco_nvm___outbound_connection_to_suspicious_port.yml @@ -1,8 +1,8 @@ name: Cisco NVM - Outbound Connection to Suspicious Port id: fc32a8d5-bc79-4437-b48f-4646ab7bed9d -version: 6 +version: 7 creation_date: '2025-07-01' -modification_date: '2026-07-14' +modification_date: '2026-09-22' author: Nasreddine Bencherchali, Splunk status: production type: Anomaly @@ -43,14 +43,13 @@ search: | additional_logged_in_users_list module_name_list module_hash_list src dest_hostname dest dest_port transport firstTime lastTime | `cisco_nvm___outbound_connection_to_suspicious_port_filter` -how_to_implement: | +how_to_implement: |- This search requires Network Visibility Module logs, which includes the flow data sourcetype. This search uses an input macro named `cisco_network_visibility_module_flowdata`. - We strongly recommend that you specify your environment-specific configurations - (index, source, sourcetype, etc.) for Cisco Network Visibility Module logs. + We strongly recommend that you specify your environment-specific configurations (index, source, sourcetype, etc.) for Cisco Network Visibility Module logs. Replace the macro definition with configurations for your Splunk environment. The search also uses a post-filter macro designed to filter out known false positives. - The logs are to be ingested using the Splunk Add-on for Cisco Endpoint Security Analytics (CESA) (https://splunkbase.splunk.com/app/4221). + The logs are to be ingested using the Cisco Security Cloud App for Splunk (https://splunkbase.splunk.com/app/7404). known_false_positives: | Some legitimate applications may use high or non-standard ports, such as alternate SSH daemons or development tools. However, many of these ports are commonly used by threat actors for reverse shells or C2 communications. diff --git a/detections/endpoint/cisco_nvm___rclone_execution_with_network_activity.yml b/detections/endpoint/cisco_nvm___rclone_execution_with_network_activity.yml index d707ed4745..002d7f3c79 100644 --- a/detections/endpoint/cisco_nvm___rclone_execution_with_network_activity.yml +++ b/detections/endpoint/cisco_nvm___rclone_execution_with_network_activity.yml @@ -1,8 +1,8 @@ name: Cisco NVM - Rclone Execution With Network Activity id: 719f8c78-b20d-4bb9-8c33-6d1a762e7a9a -version: 7 +version: 8 creation_date: '2025-07-01' -modification_date: '2026-07-14' +modification_date: '2026-09-22' author: Nasreddine Bencherchali, Splunk status: production type: Anomaly @@ -52,14 +52,13 @@ search: | additional_logged_in_users_list module_name_list module_hash_list src dest_hostname dest dest_port transport firstTime lastTime | `cisco_nvm___rclone_execution_with_network_activity_filter` -how_to_implement: | +how_to_implement: |- This search requires Network Visibility Module logs, which includes the flow data sourcetype. This search uses an input macro named `cisco_network_visibility_module_flowdata`. - We strongly recommend that you specify your environment-specific configurations - (index, source, sourcetype, etc.) for Cisco Network Visibility Module logs. + We strongly recommend that you specify your environment-specific configurations (index, source, sourcetype, etc.) for Cisco Network Visibility Module logs. Replace the macro definition with configurations for your Splunk environment. The search also uses a post-filter macro designed to filter out known false positives. - The logs are to be ingested using the Splunk Add-on for Cisco Endpoint Security Analytics (CESA) (https://splunkbase.splunk.com/app/4221). + The logs are to be ingested using the Cisco Security Cloud App for Splunk (https://splunkbase.splunk.com/app/7404). known_false_positives: | Rclone is used legitimately in some backup or other workflows. Tune this rule based on known-good operational usage or restrict by known user/service accounts an specific folders or remote names. references: diff --git a/detections/endpoint/cisco_nvm___rundll32_abuse_of_mshtml_dll_for_payload_download.yml b/detections/endpoint/cisco_nvm___rundll32_abuse_of_mshtml_dll_for_payload_download.yml index 3b0f0d51b9..c8caad0967 100644 --- a/detections/endpoint/cisco_nvm___rundll32_abuse_of_mshtml_dll_for_payload_download.yml +++ b/detections/endpoint/cisco_nvm___rundll32_abuse_of_mshtml_dll_for_payload_download.yml @@ -1,8 +1,8 @@ name: Cisco NVM - Rundll32 Abuse of MSHTML.DLL for Payload Download id: 18f0d27d-569e-4bc4-96e1-09b214fa73c0 -version: 6 +version: 7 creation_date: '2025-07-01' -modification_date: '2026-07-14' +modification_date: '2026-09-22' author: Nasreddine Bencherchali, Splunk status: production type: Anomaly @@ -39,14 +39,13 @@ search: | additional_logged_in_users_list module_name_list module_hash_list src dest_hostname dest dest_port transport firstTime lastTime | `cisco_nvm___rundll32_abuse_of_mshtml_dll_for_payload_download_filter` -how_to_implement: | +how_to_implement: |- This search requires Network Visibility Module logs, which includes the flow data sourcetype. This search uses an input macro named `cisco_network_visibility_module_flowdata`. - We strongly recommend that you specify your environment-specific configurations - (index, source, sourcetype, etc.) for Cisco Network Visibility Module logs. + We strongly recommend that you specify your environment-specific configurations (index, source, sourcetype, etc.) for Cisco Network Visibility Module logs. Replace the macro definition with configurations for your Splunk environment. The search also uses a post-filter macro designed to filter out known false positives. - The logs are to be ingested using the Splunk Add-on for Cisco Endpoint Security Analytics (CESA) (https://splunkbase.splunk.com/app/4221). + The logs are to be ingested using the Cisco Security Cloud App for Splunk (https://splunkbase.splunk.com/app/7404). known_false_positives: | `rundll32.exe` using `mshtml.dll` is rare in legitimate environments. However, edge cases might exist. Tuning may be needed in environments with custom automation scripts. references: diff --git a/detections/endpoint/cisco_nvm___susp_script_from_archive_triggering_network_activity.yml b/detections/endpoint/cisco_nvm___susp_script_from_archive_triggering_network_activity.yml index 0072fc506e..d98e0f72d8 100644 --- a/detections/endpoint/cisco_nvm___susp_script_from_archive_triggering_network_activity.yml +++ b/detections/endpoint/cisco_nvm___susp_script_from_archive_triggering_network_activity.yml @@ -1,8 +1,8 @@ name: Cisco NVM - Susp Script From Archive Triggering Network Activity id: 8b07c2c9-0cde-4c44-9fa6-59dcf2b25777 -version: 6 +version: 7 creation_date: '2025-07-01' -modification_date: '2026-07-14' +modification_date: '2026-09-22' author: Nasreddine Bencherchali, Splunk status: production type: Anomaly @@ -39,14 +39,13 @@ search: | additional_logged_in_users_list module_name_list module_hash_list src dest_hostname dest dest_port transport firstTime lastTime | `cisco_nvm___susp_script_from_archive_triggering_network_activity_filter` -how_to_implement: | +how_to_implement: |- This search requires Network Visibility Module logs, which includes the flow data sourcetype. This search uses an input macro named `cisco_network_visibility_module_flowdata`. - We strongly recommend that you specify your environment-specific configurations - (index, source, sourcetype, etc.) for Cisco Network Visibility Module logs. + We strongly recommend that you specify your environment-specific configurations (index, source, sourcetype, etc.) for Cisco Network Visibility Module logs. Replace the macro definition with configurations for your Splunk environment. The search also uses a post-filter macro designed to filter out known false positives. - The logs are to be ingested using the Splunk Add-on for Cisco Endpoint Security Analytics (CESA) (https://splunkbase.splunk.com/app/4221). + The logs are to be ingested using the Cisco Security Cloud App for Splunk (https://splunkbase.splunk.com/app/7404). known_false_positives: | Some software installers or automation scripts may extract and run scripts from archive files in temporary directories. However, it is uncommon for such scripts to initiate outbound network connections immediately upon extraction. diff --git a/detections/endpoint/cisco_nvm___suspicious_download_from_file_sharing_website.yml b/detections/endpoint/cisco_nvm___suspicious_download_from_file_sharing_website.yml index 88bfa5cba7..2d0f030e05 100644 --- a/detections/endpoint/cisco_nvm___suspicious_download_from_file_sharing_website.yml +++ b/detections/endpoint/cisco_nvm___suspicious_download_from_file_sharing_website.yml @@ -1,8 +1,8 @@ name: Cisco NVM - Suspicious Download From File Sharing Website id: 94ebc001-35e7-4ae8-9b0e-52766b2f99c7 -version: 7 +version: 8 creation_date: '2025-07-01' -modification_date: '2026-07-14' +modification_date: '2026-09-22' author: Nasreddine Bencherchali, Splunk status: production type: Anomaly @@ -54,14 +54,13 @@ search: | additional_logged_in_users_list module_name_list module_hash_list src dest_hostname dest dest_port transport firstTime lastTime | `cisco_nvm___suspicious_download_from_file_sharing_website_filter` -how_to_implement: | +how_to_implement: |- This search requires Network Visibility Module logs, which includes the flow data sourcetype. This search uses an input macro named `cisco_network_visibility_module_flowdata`. - We strongly recommend that you specify your environment-specific configurations - (index, source, sourcetype, etc.) for Cisco Network Visibility Module logs. + We strongly recommend that you specify your environment-specific configurations (index, source, sourcetype, etc.) for Cisco Network Visibility Module logs. Replace the macro definition with configurations for your Splunk environment. The search also uses a post-filter macro designed to filter out known false positives. - The logs are to be ingested using the Splunk Add-on for Cisco Endpoint Security Analytics (CESA) (https://splunkbase.splunk.com/app/4221). + The logs are to be ingested using the Cisco Security Cloud App for Splunk (https://splunkbase.splunk.com/app/7404). known_false_positives: | Some system administrators or development teams may use tools like curl or PowerShell to download files from public services for legitimate automation or scripting purposes. However, use of these binaries to contact domains commonly associated with file sharing or temporary hosting diff --git a/detections/endpoint/cisco_nvm___suspicious_file_download_via_headless_browser.yml b/detections/endpoint/cisco_nvm___suspicious_file_download_via_headless_browser.yml index 7ea531ccb1..9e5dd3c33f 100644 --- a/detections/endpoint/cisco_nvm___suspicious_file_download_via_headless_browser.yml +++ b/detections/endpoint/cisco_nvm___suspicious_file_download_via_headless_browser.yml @@ -1,8 +1,8 @@ name: Cisco NVM - Suspicious File Download via Headless Browser id: cd0e816f-f67d-4dbe-a153-480b546e867e -version: 6 +version: 7 creation_date: '2025-07-01' -modification_date: '2026-07-14' +modification_date: '2026-09-22' author: Nasreddine Bencherchali, Splunk status: production type: TTP @@ -74,14 +74,13 @@ search: | additional_logged_in_users_list module_name_list module_hash_list src dest_hostname dest dest_port transport firstTime lastTime | `cisco_nvm___suspicious_file_download_via_headless_browser_filter` -how_to_implement: | +how_to_implement: |- This search requires Network Visibility Module logs, which includes the flow data sourcetype. This search uses an input macro named `cisco_network_visibility_module_flowdata`. - We strongly recommend that you specify your environment-specific configurations - (index, source, sourcetype, etc.) for Cisco Network Visibility Module logs. + We strongly recommend that you specify your environment-specific configurations (index, source, sourcetype, etc.) for Cisco Network Visibility Module logs. Replace the macro definition with configurations for your Splunk environment. The search also uses a post-filter macro designed to filter out known false positives. - The logs are to be ingested using the Splunk Add-on for Cisco Endpoint Security Analytics (CESA) (https://splunkbase.splunk.com/app/4221). + The logs are to be ingested using the Cisco Security Cloud App for Splunk (https://splunkbase.splunk.com/app/7404). known_false_positives: | Some internal automation frameworks may invoke Chromium browsers in headless mode to programmatically access internal services or webpages. These tools may occasionally download legitimate resources as part of their normal behavior. diff --git a/detections/endpoint/cisco_nvm___suspicious_network_connection_from_process_with_no_args.yml b/detections/endpoint/cisco_nvm___suspicious_network_connection_from_process_with_no_args.yml index 30cb586fc2..f2e4760a56 100644 --- a/detections/endpoint/cisco_nvm___suspicious_network_connection_from_process_with_no_args.yml +++ b/detections/endpoint/cisco_nvm___suspicious_network_connection_from_process_with_no_args.yml @@ -1,8 +1,8 @@ name: Cisco NVM - Suspicious Network Connection From Process With No Args id: 54fa06c5-96a2-4406-a4a7-44d93ddbd173 -version: 6 +version: 7 creation_date: '2025-07-01' -modification_date: '2026-07-14' +modification_date: '2026-09-22' author: Nasreddine Bencherchali, Splunk status: production type: Anomaly @@ -49,14 +49,13 @@ search: | additional_logged_in_users_list module_name_list module_hash_list src dest_hostname dest dest_port transport firstTime lastTime | `cisco_nvm___suspicious_network_connection_from_process_with_no_args_filter` -how_to_implement: | +how_to_implement: |- This search requires Network Visibility Module logs, which includes the flow data sourcetype. This search uses an input macro named `cisco_network_visibility_module_flowdata`. - We strongly recommend that you specify your environment-specific configurations - (index, source, sourcetype, etc.) for Cisco Network Visibility Module logs. + We strongly recommend that you specify your environment-specific configurations (index, source, sourcetype, etc.) for Cisco Network Visibility Module logs. Replace the macro definition with configurations for your Splunk environment. The search also uses a post-filter macro designed to filter out known false positives. - The logs are to be ingested using the Splunk Add-on for Cisco Endpoint Security Analytics (CESA) (https://splunkbase.splunk.com/app/4221). + The logs are to be ingested using the Cisco Security Cloud App for Splunk (https://splunkbase.splunk.com/app/7404). known_false_positives: | Some system binaries may execute without arguments in rare legitimate scenarios (e.g., certain service launches), and initiate a network connection to microsoft servers for telemetry or update purposes. Apply additional filters as needed. diff --git a/detections/endpoint/cisco_nvm___suspicious_network_connection_initiated_via_msxsl.yml b/detections/endpoint/cisco_nvm___suspicious_network_connection_initiated_via_msxsl.yml index 8fe5860f2b..e4cc59a7ea 100644 --- a/detections/endpoint/cisco_nvm___suspicious_network_connection_initiated_via_msxsl.yml +++ b/detections/endpoint/cisco_nvm___suspicious_network_connection_initiated_via_msxsl.yml @@ -1,8 +1,8 @@ name: Cisco NVM - Suspicious Network Connection Initiated via MsXsl id: 1cbcf75f-0e45-4f29-8c1b-7fcd7e55cc55 -version: 6 +version: 7 creation_date: '2025-07-01' -modification_date: '2026-07-14' +modification_date: '2026-09-22' author: Nasreddine Bencherchali, Splunk status: production type: Anomaly @@ -43,14 +43,13 @@ search: | additional_logged_in_users_list module_name_list module_hash_list src dest_hostname dest dest_port transport firstTime lastTime | `cisco_nvm___suspicious_network_connection_initiated_via_msxsl_filter` -how_to_implement: | +how_to_implement: |- This search requires Network Visibility Module logs, which includes the flow data sourcetype. This search uses an input macro named `cisco_network_visibility_module_flowdata`. - We strongly recommend that you specify your environment-specific configurations - (index, source, sourcetype, etc.) for Cisco Network Visibility Module logs. + We strongly recommend that you specify your environment-specific configurations (index, source, sourcetype, etc.) for Cisco Network Visibility Module logs. Replace the macro definition with configurations for your Splunk environment. The search also uses a post-filter macro designed to filter out known false positives. - The logs are to be ingested using the Splunk Add-on for Cisco Endpoint Security Analytics (CESA) (https://splunkbase.splunk.com/app/4221). + The logs are to be ingested using the Cisco Security Cloud App for Splunk (https://splunkbase.splunk.com/app/7404). known_false_positives: | False positives may occur in development or administrative environments where msxsl.exe is used for legitimate XML transformations. However, its use is uncommon in standard user activity diff --git a/detections/endpoint/cisco_nvm___suspicious_network_connection_to_ip_lookup_service_api.yml b/detections/endpoint/cisco_nvm___suspicious_network_connection_to_ip_lookup_service_api.yml index 681ce03876..c7c2ad43c3 100644 --- a/detections/endpoint/cisco_nvm___suspicious_network_connection_to_ip_lookup_service_api.yml +++ b/detections/endpoint/cisco_nvm___suspicious_network_connection_to_ip_lookup_service_api.yml @@ -1,8 +1,8 @@ name: Cisco NVM - Suspicious Network Connection to IP Lookup Service API id: 568cb83e-d79e-4a23-85ec-6e1f6c30cb2f -version: 8 +version: 9 creation_date: '2025-07-01' -modification_date: '2026-07-14' +modification_date: '2026-09-22' author: Nasreddine Bencherchali, Splunk, Janantha Marasinghe status: production type: Anomaly @@ -53,14 +53,13 @@ search: | additional_logged_in_users_list module_name_list module_hash_list src dest_hostname dest dest_port transport firstTime lastTime | `cisco_nvm___suspicious_network_connection_to_ip_lookup_service_api_filter` -how_to_implement: | +how_to_implement: |- This search requires Network Visibility Module logs, which includes the flow data sourcetype. This search uses an input macro named `cisco_network_visibility_module_flowdata`. - We strongly recommend that you specify your environment-specific configurations - (index, source, sourcetype, etc.) for Cisco Network Visibility Module logs. + We strongly recommend that you specify your environment-specific configurations (index, source, sourcetype, etc.) for Cisco Network Visibility Module logs. Replace the macro definition with configurations for your Splunk environment. The search also uses a post-filter macro designed to filter out known false positives. - The logs are to be ingested using the Splunk Add-on for Cisco Endpoint Security Analytics (CESA) (https://splunkbase.splunk.com/app/4221). + The logs are to be ingested using the Cisco Security Cloud App for Splunk (https://splunkbase.splunk.com/app/7404). known_false_positives: | Internal scripts or agents performing network checks may query IP geolocation services. Tune by excluding known tools or adding internal allowlists for destination domains or process names and commandlines. diff --git a/detections/endpoint/cisco_nvm___webserver_download_from_file_sharing_website.yml b/detections/endpoint/cisco_nvm___webserver_download_from_file_sharing_website.yml index bdcf425a92..f1360e9e90 100644 --- a/detections/endpoint/cisco_nvm___webserver_download_from_file_sharing_website.yml +++ b/detections/endpoint/cisco_nvm___webserver_download_from_file_sharing_website.yml @@ -1,8 +1,8 @@ name: Cisco NVM - Webserver Download From File Sharing Website id: 1984f997-3b49-4d4b-a7e9-dc5dbf88370e -version: 7 +version: 8 creation_date: '2025-07-01' -modification_date: '2026-07-14' +modification_date: '2026-09-22' author: Nasreddine Bencherchali, Splunk status: production type: TTP @@ -46,14 +46,13 @@ search: | additional_logged_in_users_list module_name_list module_hash_list src dest_hostname dest dest_port transport firstTime lastTime | `cisco_nvm___webserver_download_from_file_sharing_website_filter` -how_to_implement: | +how_to_implement: |- This search requires Network Visibility Module logs, which includes the flow data sourcetype. This search uses an input macro named `cisco_network_visibility_module_flowdata`. - We strongly recommend that you specify your environment-specific configurations - (index, source, sourcetype, etc.) for Cisco Network Visibility Module logs. + We strongly recommend that you specify your environment-specific configurations (index, source, sourcetype, etc.) for Cisco Network Visibility Module logs. Replace the macro definition with configurations for your Splunk environment. The search also uses a post-filter macro designed to filter out known false positives. - The logs are to be ingested using the Splunk Add-on for Cisco Endpoint Security Analytics (CESA) (https://splunkbase.splunk.com/app/4221). + The logs are to be ingested using the Cisco Security Cloud App for Splunk (https://splunkbase.splunk.com/app/7404). known_false_positives: | In rare cases, a web server may make outbound connections to pull content for legitimate purposes (e.g., downloading templates or updates from a trusted source). However, communication to anonymous file-sharing or temporary content domains is strongly suspicious. From 074a2cf32fdce652768ca7269eeb37eec48a7dd1 Mon Sep 17 00:00:00 2001 From: nasbench <8741929+nasbench@users.noreply.github.com> Date: Tue, 29 Sep 2026 15:27:54 +0200 Subject: [PATCH 2/2] Update cisco_nvm___installation_of_typosquatted_python_package.yml --- .../cisco_nvm___installation_of_typosquatted_python_package.yml | 1 + 1 file changed, 1 insertion(+) diff --git a/detections/endpoint/cisco_nvm___installation_of_typosquatted_python_package.yml b/detections/endpoint/cisco_nvm___installation_of_typosquatted_python_package.yml index c79fc601f8..e9d3748c20 100644 --- a/detections/endpoint/cisco_nvm___installation_of_typosquatted_python_package.yml +++ b/detections/endpoint/cisco_nvm___installation_of_typosquatted_python_package.yml @@ -50,6 +50,7 @@ how_to_implement: |- Replace the macro definition with configurations for your Splunk environment. The search also uses a post-filter macro designed to filter out known false positives. The logs are to be ingested using the Cisco Security Cloud App for Splunk (https://splunkbase.splunk.com/app/7404). + In addition to this, the search make use of the lookup "typo_squatted_python_packages". Which needs to be configured and tuned. known_false_positives: | False positives should be very minimal to non existent, as the names of the packages in the lookup are all extracted from previously malicious packages. references: