elastic / elastic/detection-rules

[Meta] Tool Detections - EvilNoVNC (Phishing)

Open
#3,787 1 comment 1 reaction 1 assignee Claimed by @terrancedejesus View on GitHub
backlog Domain: Cloud Workloads Meta Team: TRADE
Dominant language
Python
Stars
2.7k
Forks
696
Avg merge
4d 17h
Merged PRs (30d)
87

Description

## Parent Epic (If Applicable)
* https://github.com/elastic/ia-trade-team/issues/271

## Meta Summary

This meta was created to assess threat detection coverage for EvilNoVNC phishing platform/toolkit. Since this toolkit can target various SaaS platforms and tenants, the scope of this should focus on our core SaaS integrations, O365, Okta, Google Workspace, GitHub, and SalesForce.

We may follow-up with assessments against CSPs (Azure, AWS, GCP) as well.

## Estimated Time to Complete
2 weeks

## Potential Blockers

## Tasklist

Potential Detection Rules:
- Stolen Cookies from Browser
- Anomalies in user sessions via active or during instantiation
- Geolocation anomalies
- Access to stored objects in common browsers
- Anomalous endpoint URL requests and content
- Anomalous user-agents
- SAMLjacking
- OAuth anomalies
- Keylogger capabilities

```[tasklist]
### Meta Tasks
- [ ] Provide Week 1 Update Comment
- [ ] Provide Week 2 Update or Closeout Comment
```

## Resources / References
* https://github.com/JoelGMSec/EvilnoVNC

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.