CVE-2016-2115 - SMB Signing
Purpose
This solution contains the template for the CVE detection, remediation, and auditing of the agents.
Associated Content
| Content | Type | Function |
|---|---|---|
| CWA Script - CVE-2016-2115 - SMB Signing | Script | This script is created to run the detection/remediation for CVE-2016-2115 - SMB Signing check and enable it if the remediation option is selected via EDF. |
| CWA Script - CVE-2016-2115 SMB Signing Ticketing - Per Client | Client Script | This client script creates a ticket for each client with the computer count where remediation is required. |
| Remote Monitor - SMB Signing Detection | Remote Monitor | This remote monitor is designed to check whether the SMB signing is enabled or not. If SMB Signing is disabled on the agent, it detects this and applies the autofix. |
| Dataview - CVE-2016-2115 SMB Signing Audit | Dataview | This dataview gathers the data from the script CWA Script - CVE-2016-2115 - SMB Signing and depicts the status of SMB Signing on the agent where it is deployed. |
| △ Custom - Execute Script - CVE-2016-2115 - SMB Signing | Alert Template | This alert template is designed to apply to the Remote Monitor - SMB Signing Detection to schedule the autofix script Script - CVE-2016-2115 - SMB Signing to perform the detection or remediation based on the EDF selection and store the data in the EDFs for auditing. |
Implementation
-
Import the following content using the ProSync Plugin:
- Script - CVE-2016-2115 - SMB Signing
- CWA Script - CVE-2016-2115 SMB Signing Ticketing - Per Client
- Dataview - CVE-2016-2115 SMB Signing Audit
- △ Custom - Execute Script - CVE-2016-2115 - SMB Signing
Import the remote monitor by following the documentation below: - Import - Remote Monitor - SMB Signing Detection
-
Reload the system cache:
-
Configure the solution as outlined below:
- Navigate to Browse -> Groups -> _System Automation.Vulnerability Management.CVE-2016-2115 SMB Signing Detection & Rem -> Computers -> Monitors within the CWA Control Center and set the following:
- Remote Monitor - SMB Signing Detection
- Setup with △ Custom - Execute Script - CVE-2016-2115 - SMB Signing and click update.
- Remote Monitor - SMB Signing Detection
- Navigate to Browse -> Groups -> _System Automation.Vulnerability Management.CVE-2016-2115 SMB Signing Detection & Rem -> Computers -> Monitors within the CWA Control Center and set the following: