Splunk Search

Detecting CVE-2023-23397 in office content?

DaveBunn
Path Finder

CVE-2023-23397 is all the rage right now.
Has anyone figured out a way to detect this in office content?
I've checked all Microsoft docs I can find, but nothing informs me as to what I'm actually looking for inside an email or contact etc.

0 Karma

paulcurry
Path Finder

MS has some pwershell things to look for in your environment.  Eith on-prem Exchange or Cloud-based.  

https://github.com/microsoft/CSS-Exchange/blob/a4c096e8b6e6eddeba2f42910f165681ed64adf7/docs/Securit...

0 Karma

pneray
New Member
0 Karma

Stjubit147
Loves-to-Learn Lots
0 Karma

DaveBunn
Path Finder

Hi

 

I'm not a member of "splunk-usergroups on Slack" so can't see the detail you are referencing

Tags (1)
0 Karma

Stjubit147
Loves-to-Learn Lots
0 Karma
Get Updates on the Splunk Community!

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...

[Live Demo] Watch SOC transformation in action with the reimagined Splunk Enterprise ...

Overwhelmed SOC? Splunk ES Has Your Back Tool sprawl, alert fatigue, and endless context switching are making ...

What’s New & Next in Splunk SOAR

Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us on ...