CVE-2024-3400 IOC's

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

CVE-2024-3400 IOC's

Cyber Elite
Cyber Elite

Hello All,

Its a twitter link but will try and summarize the process. 

https://twitter.com/cyb3rops/status/1781294529586331650

Credit to:
Florian Roth
@cyb3rops

 

We decided to share our #YARA rules to scan for indicators of the exploitation of CVE-2024-3400 in #PaloAlto's PAN-OS with the community and included some of the generic rules (detect similar attacks) Three Steps
2. Download and extract THOR Lite nextron-systems.com/thor-lite/
3. Scan the extracted folder (tech support files) thor64-lite.exe -a FileScan -p ..\2024XXXX_XXXX_techsupport.tgz_unpacked --intense --cross-platform --max-file-size 500MB YARA Rules (already included in THOR Lite's signature package) github.com/Neo23x0/signat
 
 
 

Screen shots in the original post on Twitter.

 

Also PAN has updated their guidance and a search for compromise.

 

https://security.paloaltonetworks.com/CVE-2024-3400#:~:text=Q.Are%20there%20any%20checks%20I%20can%2...

 

Good luck to all!

 

1 REPLY 1

Community Team Member

Thanks for sharing @OtakarKlier !

LIVEcommunity team member
Stay Secure,
Jay
Don't forget to Like items if a post is helpful to you!

Please help out other users and “Accept as Solution” if a post helps solve your problem !

Read more about how and why to accept solutions.
  • 1527 Views
  • 1 replies
  • 5 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!