概要

* は既存ルールの新バージョンを示します。

DPI(Deep Packet Inspection) ルール:

HP Intelligent Management Center (IMC)
1009947* - HPE Intelligent Management Center Various Expression Language Injection Vulnerabilities


Redisサーバ
1009967 - Redis Unauthenticated Code Execution Vulnerability


SSLクライアント
1010014 - Hola VPN Certificate Exchange Detected


SolarWinds Dameware Mini Remote Control
1009999 - SolarWinds DameWare Mini Remote Control CltDHPubKeyLen Out Of Bounds Read Vulnerability (CVE-2019-3956)
1010005 - SolarWinds DameWare Mini Remote Control RsaSignatureLen Out Of Bounds Read Vulnerability (CVE-2019-3957)


Webアプリケーション 共通
1009531* - Jenkins CI Server Groovy Plugin Sandbox Bypass Multiple Vulnerabilities


Webクライアント 共通
1010007 - LibreOffice Macro Python Code Execution Vulnerability (CVE-2019-9851)
1009987* - Microsoft Jet Database Engine Remote Code Execution Vulnerability (CVE-2019-1249)
1010024 - Microsoft Windows Jet Database Engine Remote Code Execution Vulnerability (CVE-2019-1250)


Webサーバ NAI ePolicy Orchestrator
1002360* - McAfee ePolicy Orchestrator Framework Services HTTP Buffer Overflow


変更監視(Integrity Monitoring)ルール:

1002781* - Microsoft Windows - Attributes of a service modified (ATT&CK T1050, T1036, T1031)


セキュリティログ監視(Log Inspection)ルール:

1008670* - Microsoft Windows Security Events - 3
1009771 - Microsoft Windows Sysmon Events - 1
1009777 - Microsoft Windows Sysmon Events - 2