fireeye-red-team-tools-CVEs [Nobelium]

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Content Index


Search for the CVEs that should be prioritized and resolved to reduce the success of the FireEye Red Team tools compromised by the Nobelium activity group. See red_team_tool_countermeasures on the official FireEye repo. References: https://github.com/fireeye/red_team_tool_countermeasures/blob/master/CVEs_red_team_tools.md https://github.com/fireeye

Attribute Value
Type Hunting Query
Solution GitHub Only
ID c4c6a792-2309-4218-bd2c-13f3cbe0600f
Tactics Privilege escalation, Vulnerability
Required Connectors MicrosoftThreatProtection
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Transformations Ingestion API Lake-Only
DeviceTvmSoftwareVulnerabilitiesKB ?

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Hunting Queries