Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
Surfaces hosts that were contacted by an IP HoneyLabs observed probing a specific CVE exploit path, and lists the CVEs that source went after. Available on paid HoneyLabs plans, where the attacker collection also carries CVE probers. This is the query to run when you want to know whether the vulnerabilities being probed in the wild right now line up with what you actually expose: cross-reference the CVE column against your own asset inventory and patch state.
| Attribute | Value |
|---|---|
| Type | Hunting Query |
| Solution | HoneyLabs |
| ID | 6a2f9b58-c31d-4e07-9d84-3f5b1c7e2a90 |
| Tactics | Reconnaissance, InitialAccess |
| Techniques | T1595, T1190 |
| Required Connectors | ThreatIntelligenceTaxii |
| Source | View on GitHub |
This content item queries data from the following tables:
| Table | Transformations | Ingestion API | Lake-Only |
|---|---|---|---|
CommonSecurityLog |
✓ | ✓ | ✓ |
ThreatIntelIndicators |
✓ | ✓ | ✗ |
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊