01
detectionlint / library / spl

3CX Supply Chain Attack Network Indicators

splApache-2.0from splunk/security_content

The following analytic identifies DNS queries to domains associated with the 3CX supply chain attack. It leverages the Network_Resolution datamodel to detect these suspicious domain indicators. This activity is significant because it can indicate a potential compromise stemming from the 3CX supply chain attack, which is known for distributing malicious software through trusted updates. If confirmed malicious, this activity could allow attackers to establish a foothold in the network, exfiltrate sensitive data, or further propagate malware, leading to extensive damage and data breaches.

02
quality67
fp risk—
forks0
views0
rule sourcelocked

Sign in to view the rule source

Free accounts can view the source for the top-ranked rules. Create one in seconds — no credit card required.

Sign in
3CX Supply Chain Attack Network Indicators · SPL rule | DetectionLint