fireeye-red-team-tools-CVEs [Nobelium]

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Content Index


Search for the CVEs that should be prioritized and resolved to reduce the success of the FireEye Red Team tools compromised by the Nobelium activity group. See red_team_tool_countermeasures on the official FireEye repo. References: https://github.com/fireeye/red_team_tool_countermeasures/blob/master/CVEs_red_team_tools.md https://github.com/fireeye

Attribute Value
Type Hunting Query
Solution GitHub Only
ID c4c6a792-2309-4218-bd2c-13f3cbe0600f
Tactics Privilege escalation, Vulnerability
Required Connectors MicrosoftThreatProtection
Source [View on GitHub](https://github.com/Azure/Azure-Sentinel/blob/master/Hunting Queries/Microsoft%20365%20Defender/Campaigns/fireeye-red-team-tools-CVEs%20%5BNobelium%5D.yaml)

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Hunting Queries