Threat Command / May 30, 2023

May 30, 2023

Threat Command

  1. Fewer Positive Alerts for Parked Domains: Alerts will be triggered only once for parked domains that are non-active or for sale. This will reduce false positive alerts for parked domains.

  2. Improved Coverage of Phishing Websites: Rapid7 intelligence analysts are building templates to continuously generate asset-based profiling rules for better coverage of suspicious phishing websites. These new custom queries will be released gradually and will improve the detection coverage for phishing websites.

  3. Improved Phishing Domain Detection: The use of new domain search patterns will yield stronger coverage of suspicious phishing domains.

  4. Remediation Validation Based on Geolocation: Before updating the remediation status, the 'threat existence' tests now consider these geolocation factors:

    • 'Countries of activity' asset
    • Related trademark
    • Company location based on profile

    The remediation status in the dashboard will more accurately reflect the customer's request.

Integrations

  1. Active Directory Continuous Integration: Leaked credentials validation in Active Directory is more stable and robust.
    Customers will gain consistent visibility into potential system infiltration risks, allowing smarter decisions and faster actions, including changing passwords, blocking users, and removing permissions.

Fixes

Threat Command

IDCaseAreaDescription
1PLT-56104231376Public APIAn error occurs when running the /alerts/report-iocs API call.
2CS-235204550654 04528129Leaked CredentialsDuplicate leaked credentials are created.
3CS-235704499378Leaked CredentialsCSV reports and emails are not available for some leaked credentials alerts.
4PHIS-253704307613PhishingIn the Phishing Watch manager, a subdomain is not properly excluded.
5PHIS-256104497258PhishingThe "Exclude domain from monitoring" request is not saved for a website.
6PHIS-2585 PHIS-25930449899704499599PhishingDomain analysis process failure

Integrations

IDCaseAreaDescription
1CS-229904568214 04551426 04551137 04551053 04530644 04530544 04518422 04518399 04500498Active Directory IntegrationEven though records were exposed, the Active Directory notification shows 0 exposed records.
2IST-73604231535Active Directory IntegrationAn incorrect policy was triggered.
30449879004498790Azure Active DirectoryThe Azure Active Directory validation was stuck in the "in progress" state.

TIP

IDCaseAreaDescription
1TIP-573204483209Investigation mapWhen exporting an Investigation Map as a PDF, the PDF is zoomed-in. The exported file does not match what you see on the screen and parts can be cut off.