-
Notifications
You must be signed in to change notification settings - Fork 522
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[New Rules] Veeam Credential Access DRs #3516
Conversation
rules/windows/credential_access_veeam_backup_dll_imageload.toml
Outdated
Show resolved
Hide resolved
rules/windows/credential_access_veeam_backup_dll_imageload.toml
Outdated
Show resolved
Hide resolved
Co-authored-by: Samirbous <64742097+Samirbous@users.noreply.github.com>
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
looking good thanks!
rules/windows/credential_access_veeam_backup_dll_imageload.toml
Outdated
Show resolved
Hide resolved
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I left a couple suggestions that are easily reconcilable. Approving! Great work 🚀
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
After implementation of feedback LGTM!
Co-authored-by: Terrance DeJesus <99630311+terrancedejesus@users.noreply.github.com>
* [New Rules] Veeam Credential Access DRs * bump * Update credential_access_veeam_commands.toml * Update credential_access_veeam_backup_dll_imageload.toml * Update rules/windows/credential_access_veeam_backup_dll_imageload.toml Co-authored-by: Samirbous <64742097+Samirbous@users.noreply.github.com> * Update credential_access_veeam_commands.toml * Update rules/windows/credential_access_veeam_backup_dll_imageload.toml Co-authored-by: Terrance DeJesus <99630311+terrancedejesus@users.noreply.github.com> --------- Co-authored-by: Ruben Groenewoud <78494512+Aegrah@users.noreply.github.com> Co-authored-by: Samirbous <64742097+Samirbous@users.noreply.github.com> Co-authored-by: Terrance DeJesus <99630311+terrancedejesus@users.noreply.github.com> (cherry picked from commit 779fa77)
* [New Rules] Veeam Credential Access DRs * bump * Update credential_access_veeam_commands.toml * Update credential_access_veeam_backup_dll_imageload.toml * Update rules/windows/credential_access_veeam_backup_dll_imageload.toml Co-authored-by: Samirbous <64742097+Samirbous@users.noreply.github.com> * Update credential_access_veeam_commands.toml * Update rules/windows/credential_access_veeam_backup_dll_imageload.toml Co-authored-by: Terrance DeJesus <99630311+terrancedejesus@users.noreply.github.com> --------- Co-authored-by: Ruben Groenewoud <78494512+Aegrah@users.noreply.github.com> Co-authored-by: Samirbous <64742097+Samirbous@users.noreply.github.com> Co-authored-by: Terrance DeJesus <99630311+terrancedejesus@users.noreply.github.com> (cherry picked from commit 779fa77)
* [New Rules] Veeam Credential Access DRs * bump * Update credential_access_veeam_commands.toml * Update credential_access_veeam_backup_dll_imageload.toml * Update rules/windows/credential_access_veeam_backup_dll_imageload.toml Co-authored-by: Samirbous <64742097+Samirbous@users.noreply.github.com> * Update credential_access_veeam_commands.toml * Update rules/windows/credential_access_veeam_backup_dll_imageload.toml Co-authored-by: Terrance DeJesus <99630311+terrancedejesus@users.noreply.github.com> --------- Co-authored-by: Ruben Groenewoud <78494512+Aegrah@users.noreply.github.com> Co-authored-by: Samirbous <64742097+Samirbous@users.noreply.github.com> Co-authored-by: Terrance DeJesus <99630311+terrancedejesus@users.noreply.github.com> (cherry picked from commit 779fa77)
* [New Rules] Veeam Credential Access DRs * bump * Update credential_access_veeam_commands.toml * Update credential_access_veeam_backup_dll_imageload.toml * Update rules/windows/credential_access_veeam_backup_dll_imageload.toml Co-authored-by: Samirbous <64742097+Samirbous@users.noreply.github.com> * Update credential_access_veeam_commands.toml * Update rules/windows/credential_access_veeam_backup_dll_imageload.toml Co-authored-by: Terrance DeJesus <99630311+terrancedejesus@users.noreply.github.com> --------- Co-authored-by: Ruben Groenewoud <78494512+Aegrah@users.noreply.github.com> Co-authored-by: Samirbous <64742097+Samirbous@users.noreply.github.com> Co-authored-by: Terrance DeJesus <99630311+terrancedejesus@users.noreply.github.com> (cherry picked from commit 779fa77)
* [New Rules] Veeam Credential Access DRs * bump * Update credential_access_veeam_commands.toml * Update credential_access_veeam_backup_dll_imageload.toml * Update rules/windows/credential_access_veeam_backup_dll_imageload.toml Co-authored-by: Samirbous <64742097+Samirbous@users.noreply.github.com> * Update credential_access_veeam_commands.toml * Update rules/windows/credential_access_veeam_backup_dll_imageload.toml Co-authored-by: Terrance DeJesus <99630311+terrancedejesus@users.noreply.github.com> --------- Co-authored-by: Ruben Groenewoud <78494512+Aegrah@users.noreply.github.com> Co-authored-by: Samirbous <64742097+Samirbous@users.noreply.github.com> Co-authored-by: Terrance DeJesus <99630311+terrancedejesus@users.noreply.github.com> (cherry picked from commit 779fa77)
* [New Rules] Veeam Credential Access DRs * bump * Update credential_access_veeam_commands.toml * Update credential_access_veeam_backup_dll_imageload.toml * Update rules/windows/credential_access_veeam_backup_dll_imageload.toml Co-authored-by: Samirbous <64742097+Samirbous@users.noreply.github.com> * Update credential_access_veeam_commands.toml * Update rules/windows/credential_access_veeam_backup_dll_imageload.toml Co-authored-by: Terrance DeJesus <99630311+terrancedejesus@users.noreply.github.com> --------- Co-authored-by: Ruben Groenewoud <78494512+Aegrah@users.noreply.github.com> Co-authored-by: Samirbous <64742097+Samirbous@users.noreply.github.com> Co-authored-by: Terrance DeJesus <99630311+terrancedejesus@users.noreply.github.com> (cherry picked from commit 779fa77)
* [New Rules] Veeam Credential Access DRs * bump * Update credential_access_veeam_commands.toml * Update credential_access_veeam_backup_dll_imageload.toml * Update rules/windows/credential_access_veeam_backup_dll_imageload.toml Co-authored-by: Samirbous <64742097+Samirbous@users.noreply.github.com> * Update credential_access_veeam_commands.toml * Update rules/windows/credential_access_veeam_backup_dll_imageload.toml Co-authored-by: Terrance DeJesus <99630311+terrancedejesus@users.noreply.github.com> --------- Co-authored-by: Ruben Groenewoud <78494512+Aegrah@users.noreply.github.com> Co-authored-by: Samirbous <64742097+Samirbous@users.noreply.github.com> Co-authored-by: Terrance DeJesus <99630311+terrancedejesus@users.noreply.github.com> (cherry picked from commit 779fa77)
* [New Rules] Veeam Credential Access DRs * bump * Update credential_access_veeam_commands.toml * Update credential_access_veeam_backup_dll_imageload.toml * Update rules/windows/credential_access_veeam_backup_dll_imageload.toml Co-authored-by: Samirbous <64742097+Samirbous@users.noreply.github.com> * Update credential_access_veeam_commands.toml * Update rules/windows/credential_access_veeam_backup_dll_imageload.toml Co-authored-by: Terrance DeJesus <99630311+terrancedejesus@users.noreply.github.com> --------- Co-authored-by: Ruben Groenewoud <78494512+Aegrah@users.noreply.github.com> Co-authored-by: Samirbous <64742097+Samirbous@users.noreply.github.com> Co-authored-by: Terrance DeJesus <99630311+terrancedejesus@users.noreply.github.com> (cherry picked from commit 779fa77)
* [New Rules] Veeam Credential Access DRs * bump * Update credential_access_veeam_commands.toml * Update credential_access_veeam_backup_dll_imageload.toml * Update rules/windows/credential_access_veeam_backup_dll_imageload.toml Co-authored-by: Samirbous <64742097+Samirbous@users.noreply.github.com> * Update credential_access_veeam_commands.toml * Update rules/windows/credential_access_veeam_backup_dll_imageload.toml Co-authored-by: Terrance DeJesus <99630311+terrancedejesus@users.noreply.github.com> --------- Co-authored-by: Ruben Groenewoud <78494512+Aegrah@users.noreply.github.com> Co-authored-by: Samirbous <64742097+Samirbous@users.noreply.github.com> Co-authored-by: Terrance DeJesus <99630311+terrancedejesus@users.noreply.github.com> (cherry picked from commit 779fa77)
* [New Rules] Veeam Credential Access DRs * bump * Update credential_access_veeam_commands.toml * Update credential_access_veeam_backup_dll_imageload.toml * Update rules/windows/credential_access_veeam_backup_dll_imageload.toml Co-authored-by: Samirbous <64742097+Samirbous@users.noreply.github.com> * Update credential_access_veeam_commands.toml * Update rules/windows/credential_access_veeam_backup_dll_imageload.toml Co-authored-by: Terrance DeJesus <99630311+terrancedejesus@users.noreply.github.com> --------- Co-authored-by: Ruben Groenewoud <78494512+Aegrah@users.noreply.github.com> Co-authored-by: Samirbous <64742097+Samirbous@users.noreply.github.com> Co-authored-by: Terrance DeJesus <99630311+terrancedejesus@users.noreply.github.com> (cherry picked from commit 779fa77)
* [New Rules] Veeam Credential Access DRs * bump * Update credential_access_veeam_commands.toml * Update credential_access_veeam_backup_dll_imageload.toml * Update rules/windows/credential_access_veeam_backup_dll_imageload.toml Co-authored-by: Samirbous <64742097+Samirbous@users.noreply.github.com> * Update credential_access_veeam_commands.toml * Update rules/windows/credential_access_veeam_backup_dll_imageload.toml Co-authored-by: Terrance DeJesus <99630311+terrancedejesus@users.noreply.github.com> --------- Co-authored-by: Ruben Groenewoud <78494512+Aegrah@users.noreply.github.com> Co-authored-by: Samirbous <64742097+Samirbous@users.noreply.github.com> Co-authored-by: Terrance DeJesus <99630311+terrancedejesus@users.noreply.github.com> (cherry picked from commit 779fa77)
Summary
Adds 3 new rules to cover some TTPs described by CrowdStrike and TheDFIRReport as being abused by attackers to get access to Veeam credentials via MSSQL.