Skip to content

Commit a9b986c

Browse files
authored
Merge pull request #3585 from splunk/nvm-batch1
Cisco NVM Analytics & Updates - First Batch
2 parents 39cdbb6 + 9ba254c commit a9b986c

49 files changed

Lines changed: 2900 additions & 243 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

contentctl.yml

Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -225,4 +225,12 @@ apps:
225225
description: The Splunk Add-on for AppDynamics enables you to easily configure data
226226
inputs to pull data from AppDynamics' REST APIs
227227
hardcoded_path: https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/cisco-splunk-add-on-for-appdynamics_314.tgz
228+
- uid: 4221
229+
title: Cisco Endpoint Security Analytics (CESA) Add-On for Splunk
230+
appid: TA-Cisco-NVM
231+
version: 4.0.7
232+
description: The Cisco Endpoint Security Analytics (CESA) Add-On for Splunk allows IT administrators to analyze and correlate user and endpoint behavior in Splunk Enterprise.
233+
This Add-on provides configuration and collection of data from the Cisco AnyConnect Network Visibility Module IPFIX (nvzFlow) Collector.
234+
This module collects additional context such as user, device, application, location and destination for flows both on and off premise.
235+
hardcoded_path: https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/cisco-endpoint-security-analytics-cesa-add-on-for-splunk_407.tgz
228236
githash: d6fac80e6d50ae06b40f91519a98489d4ce3a3fd
Lines changed: 149 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,149 @@
1+
name: Cisco Network Visibility Module Flow Data
2+
id: d49bcd3c-da06-41c6-b33e-8b8d23078f68
3+
version: 1
4+
date: '2025-06-30'
5+
author: Nasreddine Bencherchali, Splunk
6+
description: Data source object for Netflow events from Cisco Network Visibility Module
7+
source: not_applicable
8+
sourcetype: cisco:nvm:flowdata
9+
supported_TA:
10+
- name: Cisco Endpoint Security Analytics (CESA) Add-On for Splunk
11+
url: https://splunkbase.splunk.com/app/4221
12+
version: 4.0.7
13+
fields:
14+
- action
15+
- aditional_logged_in_user_list
16+
- aliul
17+
- bytes
18+
- bytes_in
19+
- bytes_out
20+
- da
21+
- date_hour
22+
- date_mday
23+
- date_minute
24+
- date_month
25+
- date_second
26+
- date_wday
27+
- date_year
28+
- date_zone
29+
- deserialize
30+
- dest
31+
- dest_hostname
32+
- dest_ip
33+
- dest_ipv6
34+
- dest_port
35+
- dh
36+
- direction
37+
- dp
38+
- dps
39+
- ds
40+
- eventtype
41+
- fd
42+
- fems
43+
- fes
44+
- fet
45+
- field
46+
- flow_dns_suffix
47+
- flow_end_msec
48+
- flow_end_sec
49+
- flow_end_time
50+
- flow_report_stage
51+
- flow_start_msec
52+
- flow_start_sec
53+
- flow_start_time
54+
- flow_version
55+
- fsg
56+
- fsms
57+
- fss
58+
- fst
59+
- fv
60+
- hh
61+
- hm
62+
- host
63+
- ht
64+
- http_host
65+
- http_method
66+
- ibc
67+
- iid
68+
- index
69+
- linecount
70+
- liuat
71+
- liuid
72+
- liuida
73+
- liuidp
74+
- logged_in_user
75+
- logged_in_user_account_type
76+
- logged_in_user_authority
77+
- logged_in_user_principal
78+
- mhl
79+
- mnl
80+
- module_hash_list
81+
- module_name_list
82+
- obc
83+
- pa
84+
- paa
85+
- pap
86+
- parent_process
87+
- parent_process_account
88+
- parent_process_arguments
89+
- parent_process_hash
90+
- parent_process_id
91+
- parent_process_integrity_level
92+
- parent_process_name
93+
- parent_process_path
94+
- parent_process_user_account_type
95+
- parg
96+
- ph
97+
- pid
98+
- pil
99+
- pn
100+
- ppa
101+
- pparg
102+
- ppath
103+
- pph
104+
- ppid
105+
- ppil
106+
- ppn
107+
- pppath
108+
- ppuat
109+
- pr
110+
- process
111+
- process_account_authority
112+
- process_account_principal
113+
- process_arguments
114+
- process_guid
115+
- process_hash
116+
- process_id
117+
- process_integrity_level
118+
- process_name
119+
- process_path
120+
- process_user_account_type
121+
- protocol_identifier
122+
- puat
123+
- puid
124+
- punct
125+
- sa
126+
- source
127+
- sourcetype
128+
- sp
129+
- splunk_server
130+
- splunk_server_group
131+
- sps
132+
- src
133+
- src_interface
134+
- src_ip
135+
- src_ipv6
136+
- src_port
137+
- tag
138+
- tag::action
139+
- tag::eventtype
140+
- timeendpos
141+
- timestamp
142+
- timestartpos
143+
- transport
144+
- udid
145+
- uri_path
146+
- user
147+
output_fields:
148+
- dest
149+
example_log: 'Jun 26 16:09:18 127.0.0.1 Jun 26 16:09:18 ip-172-31-30-201 fv="nvzFlow_v9" pr="6" sa="172.16.3.110" sp="5203" da="140.82.112.3" dp="443" fd="1" fss="1750954134" fst="Thu Jun 26 16:08:54 2025" fes="1750954134" fet="Thu Jun 26 16:08:54 2025" hh="''" hm="''" ht="''" udid="10E8A7F940225180BFDB748D2AE336EA7285CB8C" liuid="EC2AMAZ-E56LIG5\Administrator" liuida="EC2AMAZ-E56LIG5" liuidp="Administrator" liuat="2" pa="EC2AMAZ-E56LIG5\Administrator" paa="EC2AMAZ-E56LIG5" pap="Administrator" puat="8194" pn="msiexec.exe" ph="23EC37A4DF21893A1B3B6F5F72B2D78918E86C3A90F9664F8248A2C8219F889A" ppa="EC2AMAZ-E56LIG5\Administrator" ppuat="8194" ppn="cmd.exe" pph="41871DADE953D9F40F4AA445FC19982AB59D263C8AA93D7F67A1451663A09A57" ibc="0" obc="0" ds="us-east-2.compute.internal" dh="github.com" iid="4" mnl="''" mhl="''" fsms="1750954134331" fems="1750954134340" pid="8496" ppath="C:\Windows\system32\msiexec.exe" parg=" /i \"https://github.com/redcanaryco/atomic-red-team/raw/master/atomics/T1218.007/src/T1218.007_JScript.msi\"" ppid="9232" pppath="C:\Windows\system32\cmd.exe" aliul="''" pil="12288" ppil="12288" fsg="1" puid="071161F29663831BB4A1C0FADA9805E0"'
Lines changed: 51 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,51 @@
1+
name: Cisco Network Visibility Module OSquery
2+
id: d59bcd3c-da06-41c6-b33e-8b8d23078f68
3+
version: 1
4+
date: '2025-06-30'
5+
author: Nasreddine Bencherchali, Splunk
6+
description: Data source object for OSquery events from Cisco Network Visibility Module
7+
source: not_applicable
8+
sourcetype: cisco:nvm:osquery
9+
supported_TA:
10+
- name: Cisco Endpoint Security Analytics (CESA) Add-On for Splunk
11+
url: https://splunkbase.splunk.com/app/4221
12+
version: 4.0.7
13+
fields:
14+
- current_page
15+
- date_hour
16+
- date_mday
17+
- date_minute
18+
- date_month
19+
- date_second
20+
- date_wday
21+
- date_year
22+
- date_zone
23+
- eventtype
24+
- fv
25+
- host
26+
- index
27+
- linecount
28+
- osquery_version
29+
- punct
30+
- qid
31+
- qjr
32+
- qpi
33+
- qpn
34+
- qt
35+
- query_id
36+
- query_json_response
37+
- query_timestamp
38+
- qv
39+
- source
40+
- sourcetype
41+
- splunk_server
42+
- splunk_server_group
43+
- tag
44+
- tag::eventtype
45+
- timeendpos
46+
- timestartpos
47+
- total_pages
48+
- udid
49+
output_fields:
50+
- query_json_response
51+
example_log: 'Jun 30 09:20:43 127.0.0.1 Jun 30 09:20:43 ip-172-31-30-201 fv="nvzFlow_v8" udid="10E8A7F940225180BFDB748D2AE336EA7285CB8C" qv="5.5.1-dirty" qid="38654705666" qt="1751275242" qpi="1" qpn="1" qjr="[{\"active\":\"1\",\"autoupdate\":\"1\",\"creator\":\"null\",\"description\":\"\",\"disabled\":\"0\",\"identifier\":\"addons-search-detection@mozilla.com\",\"location\":\"app-builtin\",\"name\":\"Add-ons Search Detection\",\"native\":\"\",\"path\":\"null\",\"source_url\":\"null\",\"type\":\"extension\",\"uid\":\"500\",\"version\":\"2.0.0\",\"visible\":\"1\"},{\"active\":\"0\",\"autoupdate\":\"1\",\"creator\":\"Mozilla <screenshots-feedback@mozilla.com>\",\"description\":\"Take clips and screenshots from the Web and save them temporarily or permanently.\",\"disabled\":\"1\",\"identifier\":\"screenshots@mozilla.org\",\"location\":\"app-system-defaults\",\"name\":\"Firefox Screenshots\",\"native\":\"\",\"path\":\"C:\\Program Files\\Mozilla Firefox\\browser\\features\\screenshots@mozilla.org.xpi\",\"source_url\":\"null\",\"type\":\"extension\",\"uid\":\"500\",\"version\":\"39.0.1\",\"visible\":\"1\"},{\"active\":\"1\",\"autoupdate\":\"1\",\"creator\":\"null\",\"description\":\"\",\"disabled\":\"0\",\"identifier\":\"formautofill@mozilla.org\",\"location\":\"app-system-defaults\",\"name\":\"Form Autofill\",\"native\":\"\",\"path\":\"C:\\Program Files\\Mozilla Firefox\\browser\\features\\formautofill@mozilla.org.xpi\",\"source_url\":\"null\",\"type\":\"extension\",\"uid\":\"500\",\"version\":\"1.0.1\",\"visible\":\"1\"},{\"active\":\"1\",\"autoupdate\":\"1\",\"creator\":\"null\",\"description\":\"Fixes for web compatibility with Picture-in-Picture\",\"disabled\":\"0\",\"identifier\":\"pictureinpicture@mozilla.org\",\"location\":\"app-system-defaults\",\"name\":\"Picture-In-Picture\",\"native\":\"\",\"path\":\"C:\\Program Files\\Mozilla Firefox\\browser\\features\\pictureinpicture@mozilla.org.xpi\",\"source_url\":\"null\",\"type\":\"extension\",\"uid\":\"500\",\"version\":\"1.0.0\",\"visible\":\"1\"},{\"active\":\"1\",\"autoupdate\":\"1\",\"creator\":\"null\",\"description\":\"Urgent post-release fixes for web compatibility.\",\"disabled\":\"0\",\"identifier\":\"webcompat@mozilla.org\",\"location\":\"app-system-defaults\",\"name\":\"Web Compatibility Interventions\",\"native\":\"\",\"path\":\"C:\\Program Files\\Mozilla Firefox\\browser\\features\\webcompat@mozilla.org.xpi\",\"source_url\":\"null\",\"type\":\"extension\",\"uid\":\"500\",\"version\":\"137.7.0\",\"visible\":\"1\"},{\"active\":\"0\",\"autoupdate\":\"1\",\"creator\":\"Thomas Wisniewski <twisniewski@mozilla.com>\",\"description\":\"Report site compatibility issues on webcompat.com\",\"disabled\":\"1\",\"identifier\":\"webcompat-reporter@mozilla.org\",\"location\":\"app-system-defaults\",\"name\":\"WebCompat Reporter\",\"native\":\"\",\"path\":\"C:\\Program Files\\Mozilla Firefox\\browser\\features\\webcompat-reporter@mozilla.org.xpi\",\"source_url\":\"null\",\"type\":\"extension\",\"uid\":\"500\",\"version\":\"2.1.0\",\"visible\":\"1\"}]"'

detections/endpoint/any_powershell_downloadfile.yml renamed to detections/deprecated/any_powershell_downloadfile.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,9 +1,9 @@
11
name: Any Powershell DownloadFile
22
id: 1a93b7ea-7af7-11eb-adb5-acde48001122
3-
version: '15'
4-
date: '2025-05-06'
3+
version: '16'
4+
date: '2025-06-23'
55
author: Michael Haag, Splunk
6-
status: production
6+
status: deprecated
77
type: TTP
88
description: The following analytic detects the use of PowerShell's `DownloadFile`
99
method to download files. It leverages data from Endpoint Detection and Response

detections/endpoint/any_powershell_downloadstring.yml renamed to detections/deprecated/any_powershell_downloadstring.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,9 +1,9 @@
11
name: Any Powershell DownloadString
22
id: 4d015ef2-7adf-11eb-95da-acde48001122
3-
version: '12'
4-
date: '2025-05-06'
3+
version: '13'
4+
date: '2025-06-23'
55
author: Michael Haag, Splunk
6-
status: production
6+
status: deprecated
77
type: TTP
88
description: The following analytic detects the use of PowerShell's `DownloadString`
99
method to download files. It leverages data from Endpoint Detection and Response

detections/endpoint/windows_installutil_uninstall_option_with_network.yml renamed to detections/deprecated/windows_installutil_uninstall_option_with_network.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,9 +1,9 @@
11
name: Windows InstallUtil Uninstall Option with Network
22
id: 1a52c836-43ef-11ec-a36c-acde48001122
3-
version: 12
4-
date: '2025-05-02'
3+
version: 13
4+
date: '2025-06-26'
55
author: Michael Haag, Splunk
6-
status: production
6+
status: deprecated
77
type: TTP
88
description: The following analytic identifies the use of Windows InstallUtil.exe
99
making a remote network connection using the `/u` (uninstall) switch. This detection

detections/endpoint/attacker_tools_on_endpoint.yml

Lines changed: 9 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
name: Attacker Tools On Endpoint
22
id: a51bfe1a-94f0-48cc-b4e4-16a110145893
33
version: 12
4-
date: '2025-07-03'
4+
date: '2025-07-07'
55
author: Bhavin Patel, Splunk, sventec, Github Community
66
status: production
77
type: TTP
@@ -17,6 +17,7 @@ data_source:
1717
- Sysmon EventID 1
1818
- Windows Event Log Security 4688
1919
- CrowdStrike ProcessRollup2
20+
- Cisco Network Visibility Module Flow Data
2021
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
2122
as lastTime values(Processes.process) as process values(Processes.parent_process)
2223
as parent_process from datamodel=Endpoint.Processes where
@@ -77,6 +78,7 @@ tags:
7778
- CISA AA22-264A
7879
- Compromised Windows Host
7980
- PHP-CGI RCE Attack on Japanese Organizations
81+
- Cisco Network Visibility Module Analytics
8082
asset_type: Endpoint
8183
mitre_attack_id:
8284
- T1003
@@ -88,8 +90,13 @@ tags:
8890
- Splunk Cloud
8991
security_domain: endpoint
9092
tests:
91-
- name: True Positive Test
93+
- name: True Positive Test - Sysmon
9294
attack_data:
9395
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1595/attacker_scan_tools/windows-sysmon.log
9496
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
9597
sourcetype: XmlWinEventLog
98+
- name: True Positive Test - Cisco NVM
99+
attack_data:
100+
- data: https://media.githubusercontent.com/media/splunk/attack_data/refs/heads/master/datasets/cisco_network_visibility_module/cisco_nvm_flowdata/nvm_flowdata.log
101+
source: not_applicable
102+
sourcetype: cisco:nvm:flowdata

detections/endpoint/bitsadmin_download_file.yml

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
name: BITSAdmin Download File
22
id: 80630ff4-8e4c-11eb-aab5-acde48001122
3-
version: 10
4-
date: '2025-05-02'
3+
version: 11
4+
date: '2025-06-24'
55
author: Michael Haag, Sittikorn S
66
status: production
77
type: TTP
@@ -90,12 +90,12 @@ tags:
9090
- Splunk Cloud
9191
security_domain: endpoint
9292
tests:
93-
- name: True Positive Test
93+
- name: True Positive Test - Sysmon
9494
attack_data:
9595
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1197/atomic_red_team/windows-sysmon.log
9696
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
9797
sourcetype: XmlWinEventLog
98-
- name: True Positive Test
98+
- name: True Positive Test - CrowdStrike
9999
attack_data:
100100
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1197/atomic_red_team/crowdstrike_falcon.log
101101
source: crowdstrike

0 commit comments

Comments
 (0)