Detection rules › Kusto

Execution of software vulnerable to webp buffer overflow of CVE-2023-4863

Status
available
Severity
informational
Time window
1h
Source
github.com/Azure/Azure-Sentinel

This query looks at device, process, and network events from Defender for Endpoint that may be vulnerable to buffer overflow defined in CVE-2023-4863. Results are not an indicator of malicious activity.

MITRE ATT&CK coverage

Telemetry coverage

Rule body

id: 26e81021-2de6-4442-a74a-a77885e96911
name: Execution of software vulnerable to webp buffer overflow of CVE-2023-4863
description: |
    'This query looks at device, process, and network events from Defender for Endpoint that may be vulnerable to buffer overflow defined in CVE-2023-4863. Results are not an indicator of malicious activity.'
severity: Informational
status: Available
kind: Scheduled
queryFrequency: 1h
queryPeriod: 1h
triggerOperator: gt
triggerThreshold: 0
tactics:
  - Execution
relevantTechniques:
  - T1203
tags:
  - CVE-2023-4863
requiredDataConnectors:
  - connectorId: MicrosoftThreatProtection
    dataTypes:
      - DeviceProcessEvents
      - DeviceNetworkEvents
      - DeviceEvents
      - DeviceTvmSoftwareVulnerabilities
query: |-
  //CVE-2023-4863 Process activity with .webp files on devices where CVE-2023-4863 is unpatched
  //This query shows all process activity with .webp files on vulnerable machines and is not an indicator of malicious activity
  let VulnDevices = DeviceTvmSoftwareVulnerabilities
      | where CveId == "CVE-2023-4863"
      | distinct DeviceId;
  union DeviceProcessEvents, DeviceNetworkEvents, DeviceEvents
  | where DeviceId in (VulnDevices) and (InitiatingProcessCommandLine has(".webp") or ProcessCommandLine has(".webp"))
  | extend Name = tostring(split(AccountUpn, "@")[0]), UPNSuffix = tostring(split(AccountUpn, "@")[1])
  | extend HostName = tostring(split(DeviceName, ".")[0]), DomainIndex = toint(indexof(DeviceName, '.'))
  | extend HostNameDomain = iff(DomainIndex != -1, substring(DeviceName, DomainIndex + 1), DeviceName)
entityMappings:
- entityType: Host
  fieldMappings:
    - identifier: FullName
      columnName: DeviceName
    - identifier: HostName
      columnName: HostName
    - identifier: DnsDomain
      columnName: HostNameDomain
- entityType: Account
  fieldMappings:
    - identifier: FullName
      columnName: AccountUpn
    - identifier: Name
      columnName: Name
    - identifier: UPNSuffix
      columnName: UPNSuffix
- entityType: IP
  fieldMappings:
    - identifier: Address
      columnName: LocalIP
- entityType: Process
  fieldMappings:
    - identifier: ProcessId
      columnName: ProcessId
- entityType: Process
  fieldMappings:
    - identifier: ProcessId
      columnName: InitiatingProcessId
- entityType: Process
  fieldMappings:
    - identifier: CommandLine
      columnName: ProcessCommandLine
suppressionEnabled: false
incidentConfiguration:
  createIncident: false
  groupingConfiguration:
    enabled: false
    reopenClosedIncident: false
    lookbackDuration: PT5H
    matchingMethod: Selected
    groupByEntities:
    - Account
suppressionDuration: PT5H
alertDetailsOverride:
  alertDisplayNameFormat: Possible exploitation of CVE-2023-4863
  alertDynamicProperties: []
eventGroupingSettings:
  aggregationKind: SingleAlert
version: 1.1.3

Stages and Predicates

Stage 0: let

let VulnDevices = DeviceTvmSoftwareVulnerabilities
    | where CveId == "CVE-2023-4863"
    | distinct DeviceId;

Stage 1: source

let VulnDevices

Stage 2: union

union of 3 branches

Stage 3: source

DeviceProcessEvents

Stage 4: source

DeviceNetworkEvents

Stage 5: source

DeviceEvents

Stage 6: where

where (InitiatingProcessCommandLine contains ".webp" or ProcessCommandLine contains ".webp") and DeviceId =~ "VulnDevices"

Stage 7: extend (3 consecutive steps)

extend DomainIndex, HostName, HostNameDomain, Name, UPNSuffix

Indicators

These rows show field, operator, and value matches.

Output fields

These fields are emitted when the rule matches.

FieldSource
Nameextend
UPNSuffixextend
DomainIndexextend
HostNameextend
HostNameDomainextend