<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: MS Crypto API Vuln - CVE-2020-0601 - Any example logs? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/MS-Crypto-API-Vuln-CVE-2020-0601-Any-example-logs/m-p/483460#M82829</link>
    <description>&lt;P&gt;&lt;A href="https://www.splunk.com/en_us/blog/public-sector/leveraging-splunk-for-a-critically-important-patch-tuesday.html"&gt;https://www.splunk.com/en_us/blog/public-sector/leveraging-splunk-for-a-critically-important-patch-tuesday.html&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 16 Jan 2020 16:09:27 GMT</pubDate>
    <dc:creator>Azeemering</dc:creator>
    <dc:date>2020-01-16T16:09:27Z</dc:date>
    <item>
      <title>MS Crypto API Vuln - CVE-2020-0601 - Any example logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/MS-Crypto-API-Vuln-CVE-2020-0601-Any-example-logs/m-p/483456#M82825</link>
      <description>&lt;P&gt;Hello Splunkers!&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;TL;DR&lt;/STRONG&gt; - Has anyone seen an example log generated by the fix for the 2020-January Critical MS Windows CryptoAPI Vuln?  &lt;EM&gt;(CVE-2020-0601)&lt;/EM&gt;&lt;/P&gt;

&lt;P&gt;Does anyone know what the exact event event looks like?  The technet article: &lt;A href="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0601/"&gt;https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0601/&lt;/A&gt; references the following:&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;Event Log: Windows Logs/Application&lt;/LI&gt;
&lt;LI&gt;Event Source: Audit-CVE &lt;/LI&gt;
&lt;LI&gt;Event ID 1&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;Event ID    1 seems to be a common dumping ground, and I've never seen any logs from that SourceName (Assuming that's the field to key on)  &lt;/P&gt;

&lt;P&gt;I'll (for now) run scheduled searches for the following, but have a feeling the data presents differently.  &lt;/P&gt;

&lt;P&gt;&lt;EM&gt;sourcetype=wineventlog:application SourceName=Audit-CVE&lt;/EM&gt;&lt;/P&gt;

&lt;P&gt;Any ideas/thoughts/suggestions?&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jan 2020 15:35:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/MS-Crypto-API-Vuln-CVE-2020-0601-Any-example-logs/m-p/483456#M82825</guid>
      <dc:creator>dsctm3</dc:creator>
      <dc:date>2020-01-15T15:35:52Z</dc:date>
    </item>
    <item>
      <title>Re: MS Crypto API Vuln - CVE-2020-0601 - Any example logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/MS-Crypto-API-Vuln-CVE-2020-0601-Any-example-logs/m-p/483457#M82826</link>
      <description>&lt;P&gt;One of the handlers at the Internet Storm Center (SANS entity) put together a VBA solution that populates the event log with a replica of these events.&lt;/P&gt;

&lt;P&gt;Take a look at &lt;A href="https://blog.didierstevens.com/2020/01/15/using-cveeventwrite-from-vba-cve-2020-0601/"&gt;https://blog.didierstevens.com/2020/01/15/using-cveeventwrite-from-vba-cve-2020-0601/&lt;/A&gt; for more info.&lt;/P&gt;

&lt;P&gt;Hope that helps!&lt;BR /&gt;
rmmiller&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jan 2020 22:12:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/MS-Crypto-API-Vuln-CVE-2020-0601-Any-example-logs/m-p/483457#M82826</guid>
      <dc:creator>rmmiller</dc:creator>
      <dc:date>2020-01-15T22:12:08Z</dc:date>
    </item>
    <item>
      <title>Re: MS Crypto API Vuln - CVE-2020-0601 - Any example logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/MS-Crypto-API-Vuln-CVE-2020-0601-Any-example-logs/m-p/483458#M82827</link>
      <description>&lt;P&gt;This is exactly what I was looking for.  Many thanks @rmmiller !&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jan 2020 22:55:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/MS-Crypto-API-Vuln-CVE-2020-0601-Any-example-logs/m-p/483458#M82827</guid>
      <dc:creator>dsctm3</dc:creator>
      <dc:date>2020-01-15T22:55:04Z</dc:date>
    </item>
    <item>
      <title>Re: MS Crypto API Vuln - CVE-2020-0601 - Any example logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/MS-Crypto-API-Vuln-CVE-2020-0601-Any-example-logs/m-p/483459#M82828</link>
      <description>&lt;P&gt;Glad I could help!  We're all in this mess together!  &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jan 2020 23:42:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/MS-Crypto-API-Vuln-CVE-2020-0601-Any-example-logs/m-p/483459#M82828</guid>
      <dc:creator>rmmiller</dc:creator>
      <dc:date>2020-01-15T23:42:42Z</dc:date>
    </item>
    <item>
      <title>Re: MS Crypto API Vuln - CVE-2020-0601 - Any example logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/MS-Crypto-API-Vuln-CVE-2020-0601-Any-example-logs/m-p/483460#M82829</link>
      <description>&lt;P&gt;&lt;A href="https://www.splunk.com/en_us/blog/public-sector/leveraging-splunk-for-a-critically-important-patch-tuesday.html"&gt;https://www.splunk.com/en_us/blog/public-sector/leveraging-splunk-for-a-critically-important-patch-tuesday.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Jan 2020 16:09:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/MS-Crypto-API-Vuln-CVE-2020-0601-Any-example-logs/m-p/483460#M82829</guid>
      <dc:creator>Azeemering</dc:creator>
      <dc:date>2020-01-16T16:09:27Z</dc:date>
    </item>
  </channel>
</rss>

