Hunt Strategy & Objective
Identify telemetry consistent with CISA Adds Six Known Exploited Vulnerabilities to Catalog.
⏱️ Lookback: 30 days
Hunt Hypothesis
Observable activity related to Known may be present where the documented behavior occurred.
Target Platforms & Environment
Windows
macOS
Linux
Cloud
Publicly documented behavior and indicators only.
Required Telemetry & Data Sources
process creation
network/DNS logs
authentication logs
Procedural Hunting Sequence
- 1 Scope: identify affected technologies and telemetry coverage.
- 2 SIEM/EDR Logic: run the attached Sigma, SPL, and KQL triage logic and pivot on cited indicators.
- 3 Triage & Containment: validate matches, isolate confirmed suspicious assets under local procedures, and preserve evidence.
- 4 Forensic Validation: confirm timestamps, parent-child process lineage, network pivots, and source provenance.
Hunt Queries
Query Pattern 1
Triage on keyword Known and cited indicators
✓
True Positive Confirmation Evidence
●
Matches to cited public indicators or documented behavior
!
Benign & False Positive Explanations
●
Legitimate administrative or software activity
Validation Checklist
Preserve logs and timestamps
Confirm the source URL and evidence IDs
Escalation Criteria
Corroborated matches across independent telemetry
Traceability & Related Detections
🔍 Evidence:
5194f4be-f5…
🔍 Evidence:
6db7bee0-74…
🔍 Evidence:
76e53c77-90…
🔍 Evidence:
ac932e50-18…
🔍 Evidence:
bd3bce74-60…
🔍 Evidence:
e60b1c33-54…
🛡️ Detection: 833d1955-02…
🛡️ Detection: 99e8797c-e3…
🛡️ Detection: 74b9d962-a9…