Skip to content

Cisco NVM Analytics & Updates - First Batch#3585

Merged
patel-bhavin merged 28 commits into
developfrom
nvm-batch1
Jul 7, 2025
Merged

Cisco NVM Analytics & Updates - First Batch#3585
patel-bhavin merged 28 commits into
developfrom
nvm-batch1

Conversation

@nasbench

@nasbench nasbench commented Jun 30, 2025

Copy link
Copy Markdown
Contributor

New Analytics

  • Cisco NVM - Curl Execution With Insecure Flags
  • Cisco NVM - MSHTML or MSHTA Network Execution Without URL in CLI
  • Cisco NVM - Non-Network Binary Making Network Connection
  • Cisco NVM - Outbound Connection to Suspicious Port
  • Cisco NVM - Rclone Execution With Network Activity
  • Cisco NVM - Rundll32 Abuse of MSHTML.DLL for Payload Download
  • Cisco NVM - Susp Script From Archive Triggering Network Activity
  • Cisco NVM - Suspicious Download From File Sharing Website
  • Cisco NVM - Suspicious Network Connection From Process With No Args
  • Cisco NVM - Webserver Download From File Sharing Website
  • Cisco NVM - Installation of Typosquatted Python Package
  • Cisco NVM - Suspicious Download From File Sharing Website
  • Cisco NVM - Suspicious File Download via Headless Browser
  • Cisco NVM - Suspicious Network Connection From Process With No Args
  • Cisco NVM - Suspicious Network Connection Initiated via MsXsl
  • Cisco NVM - Suspicious Network Connection to IP Lookup Service API
  • Windows File Download Via PowerShell

NVM Mapped Analytics

  • Attacker Tools On Endpoint
  • Detect HTML Help URL in Command Line
  • Detect MSHTA Url in Command Line
  • Detect RClone Command-Line Usage
  • Windows Curl Download to Suspicious Path
  • Windows Curl Upload to Remote Destination
  • Windows File Download Via CertUtil
  • Windows HTTP Network Communication From MSIExec
  • Windows InstallUtil Remote Network Connection
  • Windows InstallUtil URL in Command Line
  • Windows MSIExec Remote Download
  • Windows PowerShell FakeCAPTCHA Clipboard Execution
  • WMIC XSL Execution via URL
  • Windows File Download Via PowerShell

Updated Analytics - Logic

  • Windows Curl Download to Suspicious Path - Increased coverage by adding new paths

New Data Sources

  • Cisco Network Visibility Module Flow Data
  • Cisco Network Visibility Module OSquery

New Analytic Stories

  • Cisco Network Visibility Module Analytics

New Macros

  • cisco_network_visibility_module_flowdata

New Lookups

  • suspicious_ports_list.csv
  • typo_squatted_python_packages.csv

Updated Lookups

  • attacker_tools - Removed duplicate entries

Deprecated Analytics

  • Any Powershell DownloadFile
  • Any Powershell DownloadString
  • Windows InstallUtil Uninstall Option with Network

@nasbench nasbench added this to the v5.9.0 milestone Jun 30, 2025
@nasbench
nasbench marked this pull request as ready for review July 6, 2025 23:23
Comment thread removed/deprecation_mapping.YML Outdated
Comment thread detections/endpoint/attacker_tools_on_endpoint.yml Outdated
Comment thread data_sources/cisco_network_visibility_module_flow_data.yml
Comment thread detections/endpoint/cisco_nvm___curl_execution_with_insecure_flags.yml Outdated
Comment thread detections/endpoint/cisco_nvm___curl_execution_with_insecure_flags.yml Outdated
@patel-bhavin

Copy link
Copy Markdown
Contributor

The latest updates look good! Manually tested the searches on Hoth and discussed with the author regarding some changes.

@patel-bhavin
patel-bhavin merged commit a9b986c into develop Jul 7, 2025
4 checks passed
@patel-bhavin
patel-bhavin deleted the nvm-batch1 branch July 7, 2025 20:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants