Skip to content

Commit 9d7b85e

Browse files
authored
Update win_smbclient_connectivity_exploit_cve_2023_23397_outlook_remote_file.yml
1 parent 7efdff3 commit 9d7b85e

File tree

1 file changed

+1
-0
lines changed

1 file changed

+1
-0
lines changed

rules-emerging-threats/2023/Exploits/CVE-2023-23397/win_smbclient_connectivity_exploit_cve_2023_23397_outlook_remote_file.yml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -4,6 +4,7 @@ status: test
44
description: Detects (failed) outbound connection attempts to internet facing SMB servers. This could be a sign of potential exploitation attempts of CVE-2023-23397.
55
references:
66
- https://www.microsoft.com/en-us/security/blog/2023/03/24/guidance-for-investigating-attacks-using-cve-2023-23397/
7+
- https://github.com/nasbench/Misc-Research/blob/main/ETW/Microsoft-Windows-SMBClient.md
78
author: Nasreddine Bencherchali (Nextron Systems)
89
date: 2023-04-05
910
modified: 2025-04-07

0 commit comments

Comments
 (0)