Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
@@ -1,8 +1,8 @@
name: Cisco NVM - Browser Spawned Unix Shell with External Connection
id: 6f2de8d1-9a2d-4c7a-9b8c-3b8a2f7d0e41
version: 1
version: 2
creation_date: '2026-09-02'
modification_date: '2026-09-02'
modification_date: '2026-09-22'
author: Maria Jose Erquiaga, Splunk
status: production
type: Anomaly
Expand Down Expand Up @@ -60,14 +60,13 @@ search: |
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `cisco_nvm___browser_spawned_unix_shell_with_external_connection_filter`
how_to_implement: |
how_to_implement: |-
This search requires Network Visibility Module logs, which includes the flow data sourcetype.
This search uses an input macro named `cisco_network_visibility_module_flowdata`.
We strongly recommend that you specify your environment-specific configurations
(index, source, sourcetype, etc.) for Cisco Network Visibility Module logs.
We strongly recommend that you specify your environment-specific configurations (index, source, sourcetype, etc.) for Cisco Network Visibility Module logs.
Replace the macro definition with configurations for your Splunk environment.
The search also uses a post-filter macro designed to filter out known false positives.
The logs are to be ingested using the Splunk Add-on for Cisco Endpoint Security Analytics (CESA) (https://splunkbase.splunk.com/app/4221).
The logs are to be ingested using the Cisco Security Cloud App for Splunk (https://splunkbase.splunk.com/app/7404).
known_false_positives: |
Legitimate workflows may launch Unix command interpreters from browser contexts, including developer tooling, software installers, SSO helpers, browser extensions, and automation wrappers. Tuning may be required for approved applications, users, and destinations.
references:
Expand Down
Original file line number Diff line number Diff line change
@@ -1,8 +1,8 @@
name: Cisco NVM - Curl Execution With Insecure Flags
id: cc695238-3117-4e60-aa83-4beac2a42c69
version: 8
version: 9
creation_date: '2025-07-01'
modification_date: '2026-07-14'
modification_date: '2026-09-22'
author: Nasreddine Bencherchali, Splunk
status: production
type: Anomaly
Expand Down Expand Up @@ -45,14 +45,13 @@ search: |
additional_logged_in_users_list module_name_list module_hash_list
src dest_hostname dest dest_port transport firstTime lastTime
| `cisco_nvm___curl_execution_with_insecure_flags_filter`
how_to_implement: |
how_to_implement: |-
This search requires Network Visibility Module logs, which includes the flow data sourcetype.
This search uses an input macro named `cisco_network_visibility_module_flowdata`.
We strongly recommend that you specify your environment-specific configurations
(index, source, sourcetype, etc.) for Cisco Network Visibility Module logs.
We strongly recommend that you specify your environment-specific configurations (index, source, sourcetype, etc.) for Cisco Network Visibility Module logs.
Replace the macro definition with configurations for your Splunk environment.
The search also uses a post-filter macro designed to filter out known false positives.
The logs are to be ingested using the Splunk Add-on for Cisco Endpoint Security Analytics (CESA) (https://splunkbase.splunk.com/app/4221).
The logs are to be ingested using the Cisco Security Cloud App for Splunk (https://splunkbase.splunk.com/app/7404).
known_false_positives: |
Usage of these flags to reach public IPs or uncommon destinations should be reviewed.
Tuning may be required for domains with known certificate issues.
Expand Down
Original file line number Diff line number Diff line change
@@ -1,8 +1,8 @@
name: Cisco NVM - Installation of Typosquatted Python Package
id: 5e3f6b44-42cb-4f8a-99f0-59e78a52ea1d
version: 5
version: 6
creation_date: '2025-07-01'
modification_date: '2026-07-14'
modification_date: '2026-09-22'
author: Nasreddine Bencherchali, Splunk
status: production
type: TTP
Expand Down Expand Up @@ -43,14 +43,13 @@ search: |
process_integrity_level process_path process_name process_arguments process_hash process_id
additional_logged_in_users_list module_name_list module_hash_list
| `cisco_nvm___installation_of_typosquatted_python_package_filter`
how_to_implement: |
how_to_implement: |-
This search requires Network Visibility Module logs, which includes the flow data sourcetype.
This search uses an input macro named `cisco_network_visibility_module_flowdata`.
We strongly recommend that you specify your environment-specific configurations
(index, source, sourcetype, etc.) for Cisco Network Visibility Module logs.
We strongly recommend that you specify your environment-specific configurations (index, source, sourcetype, etc.) for Cisco Network Visibility Module logs.
Replace the macro definition with configurations for your Splunk environment.
The search also uses a post-filter macro designed to filter out known false positives.
The logs are to be ingested using the Splunk Add-on for Cisco Endpoint Security Analytics (CESA) (https://splunkbase.splunk.com/app/4221).
The logs are to be ingested using the Cisco Security Cloud App for Splunk (https://splunkbase.splunk.com/app/7404).
Comment thread
nasbench marked this conversation as resolved.
In addition to this, the search make use of the lookup "typo_squatted_python_packages". Which needs to be configured and tuned.
known_false_positives: |
False positives should be very minimal to non existent, as the names of the packages in the lookup are all extracted from previously malicious packages.
Expand Down
Original file line number Diff line number Diff line change
@@ -1,8 +1,8 @@
name: Cisco NVM - MSHTML or MSHTA Network Execution Without URL in CLI
id: f2a9df84-9b01-4a21-9e3a-7aa1a217f69e
version: 6
version: 7
creation_date: '2025-07-01'
modification_date: '2026-07-14'
modification_date: '2026-09-22'
author: Nasreddine Bencherchali, Splunk
status: production
type: Anomaly
Expand Down Expand Up @@ -48,14 +48,13 @@ search: |
additional_logged_in_users_list module_name_list module_hash_list
src dest_hostname dest dest_port transport firstTime lastTime
| `cisco_nvm___mshtml_or_mshta_network_execution_without_url_in_cli_filter`
how_to_implement: |
how_to_implement: |-
This search requires Network Visibility Module logs, which includes the flow data sourcetype.
This search uses an input macro named `cisco_network_visibility_module_flowdata`.
We strongly recommend that you specify your environment-specific configurations
(index, source, sourcetype, etc.) for Cisco Network Visibility Module logs.
We strongly recommend that you specify your environment-specific configurations (index, source, sourcetype, etc.) for Cisco Network Visibility Module logs.
Replace the macro definition with configurations for your Splunk environment.
The search also uses a post-filter macro designed to filter out known false positives.
The logs are to be ingested using the Splunk Add-on for Cisco Endpoint Security Analytics (CESA) (https://splunkbase.splunk.com/app/4221).
The logs are to be ingested using the Cisco Security Cloud App for Splunk (https://splunkbase.splunk.com/app/7404).
known_false_positives: |
False positives should be minimal as the presence of a network connection during such executions increases the likelihood of malicious behavior.
references:
Expand Down
Original file line number Diff line number Diff line change
@@ -1,8 +1,8 @@
name: Cisco NVM - Non-Network Binary Making Network Connection
id: c6db35af-8a0e-4b61-88ed-738e66f15715
version: 6
version: 7
creation_date: '2025-07-01'
modification_date: '2026-07-14'
modification_date: '2026-09-22'
author: Nasreddine Bencherchali, Splunk
status: production
type: Anomaly
Expand Down Expand Up @@ -46,14 +46,13 @@ search: |
additional_logged_in_users_list module_name_list module_hash_list
src dest_hostname dest dest_port transport firstTime lastTime
| `cisco_nvm___non_network_binary_making_network_connection_filter`
how_to_implement: |
how_to_implement: |-
This search requires Network Visibility Module logs, which includes the flow data sourcetype.
This search uses an input macro named `cisco_network_visibility_module_flowdata`.
We strongly recommend that you specify your environment-specific configurations
(index, source, sourcetype, etc.) for Cisco Network Visibility Module logs.
We strongly recommend that you specify your environment-specific configurations (index, source, sourcetype, etc.) for Cisco Network Visibility Module logs.
Replace the macro definition with configurations for your Splunk environment.
The search also uses a post-filter macro designed to filter out known false positives.
The logs are to be ingested using the Splunk Add-on for Cisco Endpoint Security Analytics (CESA) (https://splunkbase.splunk.com/app/4221).
The logs are to be ingested using the Cisco Security Cloud App for Splunk (https://splunkbase.splunk.com/app/7404).
known_false_positives: |
Rare cases may exist where these binaries are used by plugins or third-party extensions to initiate outbound communication.
However, such behavior is extremely uncommon and should be investigated for potential injection or abuse.
Expand Down
Original file line number Diff line number Diff line change
@@ -1,8 +1,8 @@
name: Cisco NVM - Osascript Network Connection for a Long Duration
id: 6bc88a9d-f7de-4257-b526-acf15bc5a517
version: 1
version: 2
creation_date: '2026-09-18'
modification_date: '2026-09-18'
modification_date: '2026-09-22'
author: Radka Viskova, Splunk
status: production
type: Anomaly
Expand Down Expand Up @@ -46,11 +46,10 @@ search: |-
how_to_implement: |-
This search requires Network Visibility Module logs, which includes the flow data sourcetype.
This search uses an input macro named `cisco_network_visibility_module_flowdata`.
We strongly recommend that you specify your environment-specific configurations
(index, source, sourcetype, etc.) for Cisco Network Visibility Module logs.
We strongly recommend that you specify your environment-specific configurations (index, source, sourcetype, etc.) for Cisco Network Visibility Module logs.
Replace the macro definition with configurations for your Splunk environment.
The search also uses a post-filter macro designed to filter out known false positives.
The logs are to be ingested using the Splunk Add-on for Cisco Endpoint Security Analytics (CESA) (https://splunkbase.splunk.com/app/4221).
The logs are to be ingested using the Cisco Security Cloud App for Splunk (https://splunkbase.splunk.com/app/7404).
known_false_positives: |-
Legitimate administrative scripting, automation, software deployment, or support workflows that use osascript for long-running network operations.
references:
Expand Down
Original file line number Diff line number Diff line change
@@ -1,8 +1,8 @@
name: Cisco NVM - Outbound Connection to Suspicious Port
id: fc32a8d5-bc79-4437-b48f-4646ab7bed9d
version: 6
version: 7
creation_date: '2025-07-01'
modification_date: '2026-07-14'
modification_date: '2026-09-22'
author: Nasreddine Bencherchali, Splunk
status: production
type: Anomaly
Expand Down Expand Up @@ -43,14 +43,13 @@ search: |
additional_logged_in_users_list module_name_list module_hash_list
src dest_hostname dest dest_port transport firstTime lastTime
| `cisco_nvm___outbound_connection_to_suspicious_port_filter`
how_to_implement: |
how_to_implement: |-
This search requires Network Visibility Module logs, which includes the flow data sourcetype.
This search uses an input macro named `cisco_network_visibility_module_flowdata`.
We strongly recommend that you specify your environment-specific configurations
(index, source, sourcetype, etc.) for Cisco Network Visibility Module logs.
We strongly recommend that you specify your environment-specific configurations (index, source, sourcetype, etc.) for Cisco Network Visibility Module logs.
Replace the macro definition with configurations for your Splunk environment.
The search also uses a post-filter macro designed to filter out known false positives.
The logs are to be ingested using the Splunk Add-on for Cisco Endpoint Security Analytics (CESA) (https://splunkbase.splunk.com/app/4221).
The logs are to be ingested using the Cisco Security Cloud App for Splunk (https://splunkbase.splunk.com/app/7404).
known_false_positives: |
Some legitimate applications may use high or non-standard ports, such as alternate SSH daemons or development tools.
However, many of these ports are commonly used by threat actors for reverse shells or C2 communications.
Expand Down
Original file line number Diff line number Diff line change
@@ -1,8 +1,8 @@
name: Cisco NVM - Rclone Execution With Network Activity
id: 719f8c78-b20d-4bb9-8c33-6d1a762e7a9a
version: 7
version: 8
creation_date: '2025-07-01'
modification_date: '2026-07-14'
modification_date: '2026-09-22'
author: Nasreddine Bencherchali, Splunk
status: production
type: Anomaly
Expand Down Expand Up @@ -52,14 +52,13 @@ search: |
additional_logged_in_users_list module_name_list module_hash_list
src dest_hostname dest dest_port transport firstTime lastTime
| `cisco_nvm___rclone_execution_with_network_activity_filter`
how_to_implement: |
how_to_implement: |-
This search requires Network Visibility Module logs, which includes the flow data sourcetype.
This search uses an input macro named `cisco_network_visibility_module_flowdata`.
We strongly recommend that you specify your environment-specific configurations
(index, source, sourcetype, etc.) for Cisco Network Visibility Module logs.
We strongly recommend that you specify your environment-specific configurations (index, source, sourcetype, etc.) for Cisco Network Visibility Module logs.
Replace the macro definition with configurations for your Splunk environment.
The search also uses a post-filter macro designed to filter out known false positives.
The logs are to be ingested using the Splunk Add-on for Cisco Endpoint Security Analytics (CESA) (https://splunkbase.splunk.com/app/4221).
The logs are to be ingested using the Cisco Security Cloud App for Splunk (https://splunkbase.splunk.com/app/7404).
known_false_positives: |
Rclone is used legitimately in some backup or other workflows. Tune this rule based on known-good operational usage or restrict by known user/service accounts an specific folders or remote names.
references:
Expand Down
Original file line number Diff line number Diff line change
@@ -1,8 +1,8 @@
name: Cisco NVM - Rundll32 Abuse of MSHTML.DLL for Payload Download
id: 18f0d27d-569e-4bc4-96e1-09b214fa73c0
version: 6
version: 7
creation_date: '2025-07-01'
modification_date: '2026-07-14'
modification_date: '2026-09-22'
author: Nasreddine Bencherchali, Splunk
status: production
type: Anomaly
Expand Down Expand Up @@ -39,14 +39,13 @@ search: |
additional_logged_in_users_list module_name_list module_hash_list
src dest_hostname dest dest_port transport firstTime lastTime
| `cisco_nvm___rundll32_abuse_of_mshtml_dll_for_payload_download_filter`
how_to_implement: |
how_to_implement: |-
This search requires Network Visibility Module logs, which includes the flow data sourcetype.
This search uses an input macro named `cisco_network_visibility_module_flowdata`.
We strongly recommend that you specify your environment-specific configurations
(index, source, sourcetype, etc.) for Cisco Network Visibility Module logs.
We strongly recommend that you specify your environment-specific configurations (index, source, sourcetype, etc.) for Cisco Network Visibility Module logs.
Replace the macro definition with configurations for your Splunk environment.
The search also uses a post-filter macro designed to filter out known false positives.
The logs are to be ingested using the Splunk Add-on for Cisco Endpoint Security Analytics (CESA) (https://splunkbase.splunk.com/app/4221).
The logs are to be ingested using the Cisco Security Cloud App for Splunk (https://splunkbase.splunk.com/app/7404).
known_false_positives: |
`rundll32.exe` using `mshtml.dll` is rare in legitimate environments. However, edge cases might exist. Tuning may be needed in environments with custom automation scripts.
references:
Expand Down
Original file line number Diff line number Diff line change
@@ -1,8 +1,8 @@
name: Cisco NVM - Susp Script From Archive Triggering Network Activity
id: 8b07c2c9-0cde-4c44-9fa6-59dcf2b25777
version: 6
version: 7
creation_date: '2025-07-01'
modification_date: '2026-07-14'
modification_date: '2026-09-22'
author: Nasreddine Bencherchali, Splunk
status: production
type: Anomaly
Expand Down Expand Up @@ -39,14 +39,13 @@ search: |
additional_logged_in_users_list module_name_list module_hash_list
src dest_hostname dest dest_port transport firstTime lastTime
| `cisco_nvm___susp_script_from_archive_triggering_network_activity_filter`
how_to_implement: |
how_to_implement: |-
This search requires Network Visibility Module logs, which includes the flow data sourcetype.
This search uses an input macro named `cisco_network_visibility_module_flowdata`.
We strongly recommend that you specify your environment-specific configurations
(index, source, sourcetype, etc.) for Cisco Network Visibility Module logs.
We strongly recommend that you specify your environment-specific configurations (index, source, sourcetype, etc.) for Cisco Network Visibility Module logs.
Replace the macro definition with configurations for your Splunk environment.
The search also uses a post-filter macro designed to filter out known false positives.
The logs are to be ingested using the Splunk Add-on for Cisco Endpoint Security Analytics (CESA) (https://splunkbase.splunk.com/app/4221).
The logs are to be ingested using the Cisco Security Cloud App for Splunk (https://splunkbase.splunk.com/app/7404).
known_false_positives: |
Some software installers or automation scripts may extract and run scripts from archive files in temporary directories.
However, it is uncommon for such scripts to initiate outbound network connections immediately upon extraction.
Expand Down
Original file line number Diff line number Diff line change
@@ -1,8 +1,8 @@
name: Cisco NVM - Suspicious Download From File Sharing Website
id: 94ebc001-35e7-4ae8-9b0e-52766b2f99c7
version: 7
version: 8
creation_date: '2025-07-01'
modification_date: '2026-07-14'
modification_date: '2026-09-22'
author: Nasreddine Bencherchali, Splunk
status: production
type: Anomaly
Expand Down Expand Up @@ -54,14 +54,13 @@ search: |
additional_logged_in_users_list module_name_list module_hash_list
src dest_hostname dest dest_port transport firstTime lastTime
| `cisco_nvm___suspicious_download_from_file_sharing_website_filter`
how_to_implement: |
how_to_implement: |-
This search requires Network Visibility Module logs, which includes the flow data sourcetype.
This search uses an input macro named `cisco_network_visibility_module_flowdata`.
We strongly recommend that you specify your environment-specific configurations
(index, source, sourcetype, etc.) for Cisco Network Visibility Module logs.
We strongly recommend that you specify your environment-specific configurations (index, source, sourcetype, etc.) for Cisco Network Visibility Module logs.
Replace the macro definition with configurations for your Splunk environment.
The search also uses a post-filter macro designed to filter out known false positives.
The logs are to be ingested using the Splunk Add-on for Cisco Endpoint Security Analytics (CESA) (https://splunkbase.splunk.com/app/4221).
The logs are to be ingested using the Cisco Security Cloud App for Splunk (https://splunkbase.splunk.com/app/7404).
known_false_positives: |
Some system administrators or development teams may use tools like curl or PowerShell to download files from public services
for legitimate automation or scripting purposes. However, use of these binaries to contact domains commonly associated with file sharing or temporary hosting
Expand Down
Loading
Loading