Hello all
The Australian Federal Government recently issued a warning to all Australian's that we're under an increasing number of cyber attacks. Although this served as a general wanring to everyone, the Australia Cyber Security Center (ACSC) published a TLP:WHITE notification for what's now known as the Copy-Paste Compromise. Within it is an extensive listing of all the TTPs being used by adversaries in an attempt to gain unauthorised access into Australia businesses and networks.
ACSC released a set of IoCs to be partricularly mindful of and to conduct a threat hunt to esnure these have not been witnessed acorss your systems.
As a result of this notification and the impact it potentially has, here's a specific Live Query to enumerate these IoCs.
NOTE: The timing for the query has been constrained to only hours, as such please expand the time frame as required, up to 90 days for each.
The query although pasted below, will be updated at the following location: https://github.com/autoexec-bat/Live_Discover_Queries/blob/master/ACSC_2020008
/* Housekeeping Prior to start - prevents sequential execution from failing */ -- Create temp table with necessary columns /* -- Search Sophos DNS journal over the last 90 days for domain IOCs */ /* -- Search Sophos URL journal over the last 2 days for URL IOCs */ /* -- Compile results and make display more friendly */ |
Cheers
Azz