Cisco NVM Analytics & Updates - First Batch#3585
Merged
Merged
Conversation
nasbench
marked this pull request as ready for review
July 6, 2025 23:23
nasbench
commented
Jul 7, 2025
nasbench
commented
Jul 7, 2025
patel-bhavin
reviewed
Jul 7, 2025
patel-bhavin
reviewed
Jul 7, 2025
patel-bhavin
reviewed
Jul 7, 2025
patel-bhavin
approved these changes
Jul 7, 2025
Contributor
|
The latest updates look good! Manually tested the searches on Hoth and discussed with the author regarding some changes. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
New Analytics
Cisco NVM - Curl Execution With Insecure FlagsCisco NVM - MSHTML or MSHTA Network Execution Without URL in CLICisco NVM - Non-Network Binary Making Network ConnectionCisco NVM - Outbound Connection to Suspicious PortCisco NVM - Rclone Execution With Network ActivityCisco NVM - Rundll32 Abuse of MSHTML.DLL for Payload DownloadCisco NVM - Susp Script From Archive Triggering Network ActivityCisco NVM - Suspicious Download From File Sharing WebsiteCisco NVM - Suspicious Network Connection From Process With No ArgsCisco NVM - Webserver Download From File Sharing WebsiteCisco NVM - Installation of Typosquatted Python PackageCisco NVM - Suspicious Download From File Sharing WebsiteCisco NVM - Suspicious File Download via Headless BrowserCisco NVM - Suspicious Network Connection From Process With No ArgsCisco NVM - Suspicious Network Connection Initiated via MsXslCisco NVM - Suspicious Network Connection to IP Lookup Service APIWindows File Download Via PowerShellNVM Mapped Analytics
Attacker Tools On EndpointDetect HTML Help URL in Command LineDetect MSHTA Url in Command LineDetect RClone Command-Line UsageWindows Curl Download to Suspicious PathWindows Curl Upload to Remote DestinationWindows File Download Via CertUtilWindows HTTP Network Communication From MSIExecWindows InstallUtil Remote Network ConnectionWindows InstallUtil URL in Command LineWindows MSIExec Remote DownloadWindows PowerShell FakeCAPTCHA Clipboard ExecutionWMIC XSL Execution via URLWindows File Download Via PowerShellUpdated Analytics - Logic
Windows Curl Download to Suspicious Path- Increased coverage by adding new pathsNew Data Sources
Cisco Network Visibility Module Flow DataCisco Network Visibility Module OSqueryNew Analytic Stories
Cisco Network Visibility Module AnalyticsNew Macros
cisco_network_visibility_module_flowdataNew Lookups
suspicious_ports_list.csvtypo_squatted_python_packages.csvUpdated Lookups
attacker_tools- Removed duplicate entriesDeprecated Analytics
Any Powershell DownloadFileAny Powershell DownloadStringWindows InstallUtil Uninstall Option with Network