Hi
As you know one of the latest vulnerability was CVE-2020-0688 on microsoft exchange server. so I'm trying free splunk on my lab environment and also install sysmon on microsoft exchange server and copy my sysmon evtx file to splunk for inspection log to detect above vulnerability. but i am new in splunk and want the syntax of search regex to do this.
please let me know how can i do?
Regards,
Mahdi
https://github.com/Neo23x0/signature-base/blob/master/yara/vul_cve_2020_0688.yar
index=yours "CB2721ABDAF8E9DC516D621D8B8BF13A2C9E8689A25303BF"
In the reference, static key is the signature.