File tree Expand file tree Collapse file tree 3 files changed +21
-9
lines changed Expand file tree Collapse file tree 3 files changed +21
-9
lines changed Original file line number Diff line number Diff line change @@ -38,8 +38,12 @@ known_false_positives: |
38
38
references :
39
39
- https://blog.talosintelligence.com/arcanedoor-new-espionage-focused-campaign-found-targeting-perimeter-network-devices/
40
40
- https://sec.cloudapps.cisco.com/security/center/resources/asa_ftd_continued_attacks
41
- - https://ciscovulnmgmtprod.service-now.com/psirt?id=advisory_preview&sysparm_sys_id=bd8313cb47a7ea10f61dfa74116d43d8
42
- - https://ciscovulnmgmtprod.service-now.com/psirt?id=advisory_preview&sysparm_sys_id=cf28925747636e10f61dfa74116d43d9
41
+ - https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-webvpn-z5xP8EUB
42
+ - https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-http-code-exec-WmfP3h3O
43
+ - https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-webvpn-YROOTUW
44
+ - https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-http-code-exec-WmfP3h3O
45
+ - https://www.cisa.gov/news-events/directives/ed-25-03-identify-and-mitigate-potential-compromise-cisco-devices
46
+ - https://www.ncsc.gov.uk/news/persistent-malicious-targeting-cisco-devices
43
47
tags :
44
48
analytic_story :
45
49
- ArcaneDoor
Original file line number Diff line number Diff line change 1
1
name : Cisco ASA - Logging Disabled via CLI
2
2
id : 7b4c9f3e-5a88-4b7b-9c4b-94d8e5d67201
3
- version : 1
4
- date : ' 2025-09-23 '
3
+ version : 2
4
+ date : ' 2025-09-25 '
5
5
author : Bhavin Patel, Micheal Haag, Splunk
6
6
status : production
7
7
type : TTP
@@ -38,8 +38,12 @@ known_false_positives: |
38
38
references :
39
39
- https://blog.talosintelligence.com/arcanedoor-new-espionage-focused-campaign-found-targeting-perimeter-network-devices/
40
40
- https://sec.cloudapps.cisco.com/security/center/resources/asa_ftd_continued_attacks
41
- - https://ciscovulnmgmtprod.service-now.com/psirt?id=advisory_preview&sysparm_sys_id=bd8313cb47a7ea10f61dfa74116d43d8
42
- - https://ciscovulnmgmtprod.service-now.com/psirt?id=advisory_preview&sysparm_sys_id=cf28925747636e10f61dfa74116d43d9
41
+ - https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-webvpn-z5xP8EUB
42
+ - https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-http-code-exec-WmfP3h3O
43
+ - https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-webvpn-YROOTUW
44
+ - https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-http-code-exec-WmfP3h3O
45
+ - https://www.cisa.gov/news-events/directives/ed-25-03-identify-and-mitigate-potential-compromise-cisco-devices
46
+ - https://www.ncsc.gov.uk/news/persistent-malicious-targeting-cisco-devices
43
47
drilldown_searches :
44
48
- name : View the detection results for $host$
45
49
search : ' %original_detection_search% | search host = $host$'
Original file line number Diff line number Diff line change 1
1
name : ArcaneDoor
2
2
id : 7f2b9eac-0df5-4d0c-9e35-2b8fd552c9f1
3
- version : 1
3
+ version : 2
4
4
date : ' 2025-09-23'
5
5
author : Bhavin Patel, Micheal Haag, Splunk
6
6
status : production
@@ -14,8 +14,12 @@ narrative: |
14
14
references :
15
15
- https://blog.talosintelligence.com/arcanedoor-new-espionage-focused-campaign-found-targeting-perimeter-network-devices/
16
16
- https://sec.cloudapps.cisco.com/security/center/resources/asa_ftd_continued_attacks
17
- - https://ciscovulnmgmtprod.service-now.com/psirt?id=advisory_preview&sysparm_sys_id=bd8313cb47a7ea10f61dfa74116d43d8
18
- - https://ciscovulnmgmtprod.service-now.com/psirt?id=advisory_preview&sysparm_sys_id=cf28925747636e10f61dfa74116d43d9
17
+ - https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-webvpn-z5xP8EUB
18
+ - https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-http-code-exec-WmfP3h3O
19
+ - https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-webvpn-YROOTUW
20
+ - https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-http-code-exec-WmfP3h3O
21
+ - https://www.cisa.gov/news-events/directives/ed-25-03-identify-and-mitigate-potential-compromise-cisco-devices
22
+ - https://www.ncsc.gov.uk/news/persistent-malicious-targeting-cisco-devices
19
23
tags :
20
24
category :
21
25
- Adversary Tactics
You can’t perform that action at this time.
0 commit comments