From 5dc6036a9a33aebf40c978225b39f9e9735d3f90 Mon Sep 17 00:00:00 2001 From: Ritik Chaddha <44563978+ritikchaddha@users.noreply.github.com> Date: Thu, 20 Apr 2023 02:28:15 +0530 Subject: [PATCH] Update msmq-detect.yaml --- network/detection/msmq-detect.yaml | 10 ++++++---- 1 file changed, 6 insertions(+), 4 deletions(-) diff --git a/network/detection/msmq-detect.yaml b/network/detection/msmq-detect.yaml index dde2afb1a6..fe4b3277c2 100644 --- a/network/detection/msmq-detect.yaml +++ b/network/detection/msmq-detect.yaml @@ -1,18 +1,20 @@ id: msmq-detect info: - name: MSMQ (Microsoft Message Queuing Service) Remote Detection + name: MSMQ (Microsoft Message Queuing Service) Remote - Detect author: bhutch severity: info description: Detects remote MSMQ services. Public exposure of this service may be a misconfiguration. - metadata: - censys-query: services.service_name:MSMQ reference: - https://www.shadowserver.org/what-we-do/network-reporting/accessible-msmq-service-report/ - https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-mqqb/f9bbe350-d70b-4e90-b9c7-d39328653166 - https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-mqqb/50da7ea1-eed7-41f9-ba6a-2aa37f5f1e92 - https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-21554 - tags: network,msmq + metadata: + verified: "true" + shodan-query: MSMQ + censys-query: services.service_name:MSMQ + tags: network,msmq,detect network: - inputs: