Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Meta] EvilNoVNC Threat Detection Coverage Assessment #3787

Open
2 tasks
terrancedejesus opened this issue Jun 13, 2024 · 0 comments
Open
2 tasks

[Meta] EvilNoVNC Threat Detection Coverage Assessment #3787

terrancedejesus opened this issue Jun 13, 2024 · 0 comments

Comments

@terrancedejesus
Copy link
Contributor

Parent Epic (If Applicable)

Meta Summary

This meta was created to assess threat detection coverage for EvilNoVNC phishing platform/toolkit. Since this toolkit can target various SaaS platforms and tenants, the scope of this should focus on our core SaaS integrations, O365, Okta, Google Workspace, GitHub, and SalesForce.

We may follow-up with assessments against CSPs (Azure, AWS, GCP) as well.

Estimated Time to Complete

2 weeks

Potential Blockers

Tasklist

Potential Detection Rules:

  • Stolen Cookies from Browser
  • Anomalies in user sessions via active or during instantiation
  • Geolocation anomalies
  • Access to stored objects in common browsers
  • Anomalous endpoint URL requests and content
  • Anomalous user-agents
  • SAMLjacking
  • OAuth anomalies
  • Keylogger capabilities

Meta Tasks

Resources / References

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants