Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

4 detections

The following analytic identifies DNS queries to domains associated with the 3CX supply chain attack. It leverages the Network_Resolution datamodel to detect these suspicious domain indicators. This activity is significant because it can indicate a potential compromise stemming from the 3CX supply chain attack, which is known for distributing malicious software through trusted updates. If confirmed malicious, this activity could allow attackers to establish a foothold in the network, exfiltrate sensitive data, or further propagate malware, leading to extensive damage and data breaches.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
3 days ago
000
The analytic identifies DNS queries to domains associated with the 3CX supply chain attack. This activity is significant because it can indicate a potential compromise stemming from the 3CX supply chain attack, which is known for distributing malicious software through trusted updates. If confirmed malicious, this activity could allow attackers to establish a foothold in the network, exfiltrate sensitive data, or further propagate malware, leading to extensive damage and data breaches.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
1 year ago
1034
The analytic detects the presence of any version of the 3CXDesktopApp, also known as the 3CX Desktop App, on Mac or Windows systems. It leverages endpoint data to identify instances of the application running. This activity is significant because 3CX has identified vulnerabilities in versions 18.12.407 and 18.12.416, which could be exploited by attackers. If confirmed malicious, this could lead to unauthorized access, data exfiltration, or further compromise of the affected systems.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
1 year ago
0035
The analytic detects instances of the 3CXDesktopApp.exe with a FileVersion of 18.12.x, specifically focusing on vulnerable versions 18.12.407 and 18.12.416. This is crucial for identifying potential exploitation of known vulnerabilities in these specific versions, which could lead to unauthorized access, code execution, or further system compromise.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
1 year ago
0030