elastic / elastic/detection-rules

[Meta] Tool Detections - EvilNoVNC (Phishing)

オープン
#3,787 コメント 1 件 リアクション 1 件 担当者 1 名 @terrancedejesus が担当を希望しています GitHub で見る
backlog Domain: Cloud Workloads Meta Team: TRADE
主要言語
Python
スター
2.7k
フォーク
696
平均マージ
5日 1時間
マージ済み PR(30日)
72

説明

## Parent Epic (If Applicable)
* https://github.com/elastic/ia-trade-team/issues/271

## Meta Summary

This meta was created to assess threat detection coverage for EvilNoVNC phishing platform/toolkit. Since this toolkit can target various SaaS platforms and tenants, the scope of this should focus on our core SaaS integrations, O365, Okta, Google Workspace, GitHub, and SalesForce.

We may follow-up with assessments against CSPs (Azure, AWS, GCP) as well.

## Estimated Time to Complete
2 weeks

## Potential Blockers

## Tasklist

Potential Detection Rules:
- Stolen Cookies from Browser
- Anomalies in user sessions via active or during instantiation
- Geolocation anomalies
- Access to stored objects in common browsers
- Anomalous endpoint URL requests and content
- Anomalous user-agents
- SAMLjacking
- OAuth anomalies
- Keylogger capabilities

```[tasklist]
### Meta Tasks
- [ ] Provide Week 1 Update Comment
- [ ] Provide Week 2 Update or Closeout Comment
```

## Resources / References
* https://github.com/JoelGMSec/EvilnoVNC

コントリビューションガイド

コントリビューションガイドを開く

評価

この issue はまだ評価されていません。

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。