<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to search Regex to Detect CVE-2020-0688 Vulnerability? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-search-Regex-to-Detect-CVE-2020-0688-Vulnerability/m-p/510456#M142864</link>
    <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;As you know one of the latest vulnerability was CVE-2020-0688 on microsoft exchange server. so I'm trying free splunk on my lab environment and also install sysmon on microsoft exchange server and copy my sysmon evtx file to splunk for inspection log to detect above vulnerability. but i am new in splunk and want the syntax of search regex to do this.&lt;/P&gt;
&lt;P&gt;please let me know how can i do?&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Mahdi&lt;/P&gt;</description>
    <pubDate>Thu, 23 Jul 2020 03:53:01 GMT</pubDate>
    <dc:creator>MBashiri</dc:creator>
    <dc:date>2020-07-23T03:53:01Z</dc:date>
    <item>
      <title>How to search Regex to Detect CVE-2020-0688 Vulnerability?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-search-Regex-to-Detect-CVE-2020-0688-Vulnerability/m-p/510456#M142864</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;As you know one of the latest vulnerability was CVE-2020-0688 on microsoft exchange server. so I'm trying free splunk on my lab environment and also install sysmon on microsoft exchange server and copy my sysmon evtx file to splunk for inspection log to detect above vulnerability. but i am new in splunk and want the syntax of search regex to do this.&lt;/P&gt;
&lt;P&gt;please let me know how can i do?&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Mahdi&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jul 2020 03:53:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-search-Regex-to-Detect-CVE-2020-0688-Vulnerability/m-p/510456#M142864</guid>
      <dc:creator>MBashiri</dc:creator>
      <dc:date>2020-07-23T03:53:01Z</dc:date>
    </item>
    <item>
      <title>Re: Search Regex to Detect CVE-2020-0688 Vulnerability</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-search-Regex-to-Detect-CVE-2020-0688-Vulnerability/m-p/510470#M142867</link>
      <description>We need more information. Please share some sample data and highlight what you would like the regex to find.</description>
      <pubDate>Wed, 22 Jul 2020 14:34:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-search-Regex-to-Detect-CVE-2020-0688-Vulnerability/m-p/510470#M142867</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-07-22T14:34:43Z</dc:date>
    </item>
    <item>
      <title>Re: Search Regex to Detect CVE-2020-0688 Vulnerability</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-search-Regex-to-Detect-CVE-2020-0688-Vulnerability/m-p/510551#M142892</link>
      <description>&lt;P&gt;&lt;A href="https://github.com/Neo23x0/signature-base/blob/master/yara/vul_cve_2020_0688.yar" target="_blank"&gt;https://github.com/Neo23x0/signature-base/blob/master/yara/vul_cve_2020_0688.yar&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;index=yours&amp;nbsp; "&lt;SPAN&gt;CB2721ABDAF8E9DC516D621D8B8BF13A2C9E8689A25303BF"&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;In the reference, static key is the signature.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jul 2020 22:56:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-search-Regex-to-Detect-CVE-2020-0688-Vulnerability/m-p/510551#M142892</guid>
      <dc:creator>to4kawa</dc:creator>
      <dc:date>2020-07-22T22:56:45Z</dc:date>
    </item>
  </channel>
</rss>

