Cisco Talos Update for FireSIGHT Management Center

Date: 2019-06-27

This SRU number: 2019-06-26-001
Previous SRU number: 2019-06-24-001

Applies to:

This SEU number: 2038
Previous SEU: 2037

Applies to:

This is the complete list of rules added in SRU 2019-06-26-001 and SEU 2038.

The format of the file is:

GID - SID - Rule Group - Rule Message - Policy State

The Policy State refers to each default Cisco Talos policy, Connectivity, Balanced, Security, and Maximum Detection.

The default passive policy state is the same as the Balanced policy state with the exception of alert being used instead of drop.

Note: Unless stated explicitly, the rules are for the series of products listed above.

New Rules:

High Priority
GIDSIDRule GroupRule MessagePolicy State
Con.Bal.Sec.Max.
150505MALWARE-TOOLSMalicious HTML application download attemptoffdropdropdrop
150506MALWARE-TOOLSMalicious HTML application download attemptoffdropdropdrop
150507MALWARE-BACKDOORWebShellOrb PHP shell outbound connection attemptoffdropdropdrop
150508MALWARE-BACKDOORWebShellOrb PHP shell upload attemptoffdropdropdrop
150509EXPLOIT-KITSpelevo Exploit Kit landing page detected offdropdropdrop
150510EXPLOIT-KITSpelevo Exploit Kit landing page detected offdropdropdrop
150511EXPLOIT-KITSpelevo Exploit Kit browser exploit page detected offdropdropdrop
350512SERVER-WEBAPPCisco Data Center Network Manager authentication bypass attemptoffdropdropdrop
350513SERVER-WEBAPPCisco Data Center Network Manager arbitrary WAR file upload attemptoffdropdropdrop
150518BROWSER-FIREFOXMozilla Firefox Array.prototype.pop type confusion attemptoffdropdropdrop
150519BROWSER-FIREFOXMozilla Firefox Array.prototype.pop type confusion attemptoffdropdropdrop
Medium Priority
GIDSIDRule GroupRule MessagePolicy State
Con.Bal.Sec.Max.
350514SERVER-WEBAPPCisco Data Center Network Manager arbitrary file download attemptoffdropdropdrop
350515SERVER-WEBAPPCisco Data Center Network Manager information disclosure attemptoffdropdropdrop
350516PROTOCOL-OTHERTRUFFLEHUNTER TALOS-2019-0849 attack attemptoffoffoffdrop
150517INDICATOR-COMPROMISEundocumented SMB dialect request attemptoffdropdropdrop