elastic / elastic/detection-rules
[Meta] Tool Detections - EvilNoVNC (Phishing)
- 主要言語
- Python
- スター
- 2.7k
- フォーク
- 696
- 平均マージ
- 5日 1時間
- マージ済み PR(30日)
- 72
説明
## Parent Epic (If Applicable)
* https://github.com/elastic/ia-trade-team/issues/271
## Meta Summary
This meta was created to assess threat detection coverage for EvilNoVNC phishing platform/toolkit. Since this toolkit can target various SaaS platforms and tenants, the scope of this should focus on our core SaaS integrations, O365, Okta, Google Workspace, GitHub, and SalesForce.
We may follow-up with assessments against CSPs (Azure, AWS, GCP) as well.
## Estimated Time to Complete
2 weeks
## Potential Blockers
## Tasklist
Potential Detection Rules:
- Stolen Cookies from Browser
- Anomalies in user sessions via active or during instantiation
- Geolocation anomalies
- Access to stored objects in common browsers
- Anomalous endpoint URL requests and content
- Anomalous user-agents
- SAMLjacking
- OAuth anomalies
- Keylogger capabilities
```[tasklist]
### Meta Tasks
- [ ] Provide Week 1 Update Comment
- [ ] Provide Week 2 Update or Closeout Comment
```
## Resources / References
* https://github.com/JoelGMSec/EvilnoVNC
コントリビューションガイド
評価
この issue はまだ評価されていません。