Hunt Strategy & Objective
Identify telemetry consistent with CISA Adds Three Known Exploited Vulnerabilities to Catalog.
⏱️ Lookback: 30 days
Hunt Hypothesis
Observable activity related to Three may be present where the documented behavior occurred.
Target Platforms & Environment
Windows
macOS
Linux
Cloud
Publicly documented behavior and indicators only.
Required Telemetry & Data Sources
process creation
network/DNS logs
authentication logs
Procedural Hunting Sequence
- 1 Scope: identify affected technologies and telemetry coverage.
- 2 SIEM/EDR Logic: run the attached Sigma, SPL, and KQL triage logic and pivot on cited indicators.
- 3 Triage & Containment: validate matches, isolate confirmed suspicious assets under local procedures, and preserve evidence.
- 4 Forensic Validation: confirm timestamps, parent-child process lineage, network pivots, and source provenance.
Hunt Queries
Query Pattern 1
Triage on keyword Three and cited indicators
✓
True Positive Confirmation Evidence
●
Matches to cited public indicators or documented behavior
!
Benign & False Positive Explanations
●
Legitimate administrative or software activity
Validation Checklist
Preserve logs and timestamps
Confirm the source URL and evidence IDs
Escalation Criteria
Corroborated matches across independent telemetry
Traceability & Related Detections
🔍 Evidence:
bcfefa21-7f…
🔍 Evidence:
cd792a47-b8…
🔍 Evidence:
f099e4bb-97…
🛡️ Detection: e2a5af90-05…
🛡️ Detection: ca5a0243-08…
🛡️ Detection: b6c1e83b-74…