Skip to content

Latest commit

 

History

History
33 lines (26 loc) · 1.01 KB

MATCH-S00574.md

File metadata and controls

33 lines (26 loc) · 1.01 KB

Rules: .NET Framework Remote Code Execution Vulnerability

Description

Observes for possible exploitation of CVE-2017-8759

Additional Details

Detail Value
Type Templated Match
Category Unknown/Other
Apply Risk to Entities device_hostname, user_username
Signal Name .NET Framework Remote Code Execution Vulnerability
Summary Expression Observed possible CVE-2017-8759 exploit on {{device_hostname}}
Score/Severity Static: 3
Enabled by Default True
Prototype False
Tags _mitreAttackTactic:TA0002, _mitreAttackTactic:TA0001, _mitreAttackTechnique:T1203

Vendors and Products

Fields Used

Origin Field
Normalized Schema baseImage
Normalized Schema device_hostname
Normalized Schema parentBaseImage
Normalized Schema user_username