Contact from a source probing a specific CVE

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Content Index


Surfaces hosts that were contacted by an IP HoneyLabs observed probing a specific CVE exploit path, and lists the CVEs that source went after. Available on paid HoneyLabs plans, where the attacker collection also carries CVE probers. This is the query to run when you want to know whether the vulnerabilities being probed in the wild right now line up with what you actually expose: cross-reference the CVE column against your own asset inventory and patch state.

Attribute Value
Type Hunting Query
Solution HoneyLabs
ID 6a2f9b58-c31d-4e07-9d84-3f5b1c7e2a90
Tactics Reconnaissance, InitialAccess
Techniques T1595, T1190
Required Connectors ThreatIntelligenceTaxii
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Transformations Ingestion API Lake-Only
CommonSecurityLog ✓ ✓ ✓
ThreatIntelIndicators ✓ ✓ ✗

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Hunting Queries · Back to HoneyLabs