Cisco Talos Update for FireSIGHT Management Center

Date: 2020-01-14

This SRU number: 2020-01-13-001
Previous SRU number: 2020-01-08-001

Applies to:

This SEU number: 2110
Previous SEU: 2109

Applies to:

This is the complete list of rules added in SRU 2020-01-13-001 and SEU 2110.

The format of the file is:

GID - SID - Rule Group - Rule Message - Policy State

The Policy State refers to each default Cisco Talos policy, Connectivity, Balanced, Security, and Maximum Detection.

The default passive policy state is the same as the Balanced policy state with the exception of alert being used instead of drop.

Note: Unless stated explicitly, the rules are for the series of products listed above.

New Rules:

High Priority
GIDSIDRule GroupRule MessagePolicy State
Con.Bal.Sec.Max.
152584EXPLOIT-KITBottleEK landing page detectedoffdropdropdrop
152585EXPLOIT-KITBottleEK variant outbound connectionoffdropdropdrop
152586EXPLOIT-KITBottleEK variant outbound connectionoffoffdropdrop
152587EXPLOIT-KITBottleEK landing page detectedoffdropdropdrop
152588MALWARE-CNCUnix.Trojan.Mirai Enigma NMS command injection attemptoffdropdropdrop
152589SERVER-WEBAPPEnigma NMS command injection attemptoffoffdropdrop
152590SERVER-WEBAPPEnigma NMS command injection attemptoffoffdropdrop
152591SERVER-WEBAPPEnigma NMS command injection attemptoffoffdropdrop
152592SERVER-WEBAPPEnigma NMS command injection attemptoffoffdropdrop
152597BROWSER-WEBKITApple Safari Webkit css title memory corruption attemptoffoffoffdrop
152598BROWSER-WEBKITApple Safari Webkit css title memory corruption attemptoffoffoffdrop
152599BROWSER-IEMicrosoft Edge scripting engine memory corruption attemptoffoffoffdrop
152600BROWSER-IEMicrosoft Edge scripting engine memory corruption attemptoffoffoffdrop
152601BROWSER-CHROMEGoogle V8 engine type confusion attemptoffdropdropdrop
152602BROWSER-CHROMEGoogle V8 engine type confusion attemptoffdropdropdrop
152603SERVER-WEBAPPCitrix ADC and Gateway arbitrary code execution attemptoffdropdropdrop
152604OS-WINDOWSMicrosoft Windows clfs.sys local privilege escalation attemptoffdropdropdrop
152605OS-WINDOWSMicrosoft Windows clfs.sys local privilege escalation attemptoffdropdropdrop
Medium Priority
GIDSIDRule GroupRule MessagePolicy State
Con.Bal.Sec.Max.
152593OS-WINDOWSMicrosoft Windows CryptoAPI signed binary with spoofed certificate attemptoffoffdropdrop
152594OS-WINDOWSMicrosoft Windows CryptoAPI signed binary with spoofed certificate attemptoffoffdropdrop
152595OS-WINDOWSMicrosoft Windows CryptoAPI signed binary with spoofed certificate attemptoffoffdropdrop
152596OS-WINDOWSMicrosoft Windows CryptoAPI signed binary with spoofed certificate attemptoffoffdropdrop

Updated Rules:

Updated rules can be found at this link.