Audit CVE Event

 Original Source: [Sigma source]
Title: Audit CVE Event
Status: test
Description:Detects events generated by user-mode applications when they call the CveEventWrite API when a known vulnerability is trying to be exploited. MS started using this log in Jan. 2020 with CVE-2020-0601 (a Windows CryptoAPI vulnerability. Unfortunately, that is about the only instance of CVEs being written to this log.
References:
  -https://twitter.com/VM_vivisector/status/1217190929330655232
  -https://twitter.com/DidierStevens/status/1217533958096924676
  -https://twitter.com/FlemmingRiis/status/1217147415482060800
  -https://www.youtube.com/watch?v=ebmW42YYveI
  -https://nullsec.us/windows-event-log-audit-cve/
Author: Florian Roth (Nextron Systems), Zach Mathis
Date: 2020-01-15
modified:2022-10-22
Tags:
  • -'attack.execution'
  • -'attack.stealth'
  • -'attack.t1203'
  • -'attack.privilege-escalation'
  • -'attack.t1068'
  • -'attack.t1211'
  • -'attack.credential-access'
  • -'attack.t1212'
  • -'attack.lateral-movement'
  • -'attack.t1210'
  • -'attack.impact'
  • -'attack.t1499.004'
Logsource:
  • product: windows
  • service: application
Detection:
  selection:
    Provider_Name:
      -'Microsoft-Windows-Audit-CVE'
      -'Audit-CVE'

    EventID: '1'
  condition:selection
Falsepositives:
  -Unknown
Level: critical