Hermes CTI

← Back to canonical report

Hunt

CISA Adds Three Known Exploited Vulnerabilities to Catalog

Hunt Strategy & Objective

Identify telemetry consistent with CISA Adds Three Known Exploited Vulnerabilities to Catalog.

⏱️ Lookback: 30 days

Hunt Hypothesis

Observable activity related to Three may be present where the documented behavior occurred.

Target Platforms & Environment

Windows macOS Linux Cloud

Publicly documented behavior and indicators only.

Required Telemetry & Data Sources

process creation network/DNS logs authentication logs

Procedural Hunting Sequence

  1. 1 Scope: identify affected technologies and telemetry coverage.
  2. 2 SIEM/EDR Logic: run the attached Sigma, SPL, and KQL triage logic and pivot on cited indicators.
  3. 3 Triage & Containment: validate matches, isolate confirmed suspicious assets under local procedures, and preserve evidence.
  4. 4 Forensic Validation: confirm timestamps, parent-child process lineage, network pivots, and source provenance.

Hunt Queries

Query Pattern 1
Triage on keyword Three and cited indicators

True Positive Confirmation Evidence

Matches to cited public indicators or documented behavior
!

Benign & False Positive Explanations

Legitimate administrative or software activity

Validation Checklist

Preserve logs and timestamps
Confirm the source URL and evidence IDs

Escalation Criteria

Corroborated matches across independent telemetry

Traceability & Related Detections

🔍 Evidence: bcfefa21-7f… 🔍 Evidence: cd792a47-b8… 🔍 Evidence: f099e4bb-97… 🛡️ Detection: e2a5af90-05… 🛡️ Detection: ca5a0243-08… 🛡️ Detection: b6c1e83b-74…