← Back to advisories & guidance
March 28, 2025
CISA
Analysis Report
Summary
############ README ############### ## ‐ This is not a conventional Sigma rule. Please do not edit "logsource‐product: blank" unless you are editing this rule to meet specific logsources/fields and know ## ‐ Query may a take long time to process. ## ‐ Ensure your EDR/SIEM instance has enough memory to run these AND/OR condition ## ‐ Analyst may need to make adjustments to the query as required. However, these rules provide full list of IOCs. ################################### title: Detects RESURGE Malware Activity Ivanti CVE 2025_0282 id: d26745fc‐7a56‐4ca9‐9011‐7ab416d14875 description: Detects RESURGE Malware Activity Ivanti CVE 2025_0282 as described in MAR‐25993211.r1.v1. Analyst must adjust as needed. ‐ 52bbc44eb451cb5e16bf98bc5b1823d2f47a18d71f14543b460395a1c1b1aeda author: CISA Code & Media Analysis ‐ '/tmp/installer/do‐install‐coreboot' ‐ '/tmp/data/root/home/etc/manifest/manifest' ‐ '/lib/%s /tmp/data/root/lib' ‐ '/bin/dsmain /tmp/coreboot_fs/bin/dsmain' ‐ '/tmp/data/root/home/perl/DSUpgrade.
News Coverage
No coverage found in monitored research blogs or news feeds.
CVEs Referenced in This Publication
No CVEs are referenced in this publication.
Vendors Named in This Publication
Each vendor links to its Known Exploited Vulnerabilities catalog page.
Only vendors that appear in the KEV catalog are listed, either because
the publication cites one of their KEV entries or because it names them
directly.