Skip to content
KitploitKITPLOIT
ИнструментыЭксплойтыБлог
Log in
Отправить
ИнструментыЭксплойтыБлог
Отправить

Инструменты для хакинга, пентеста и кибербезопасности — ваш арсенал защиты!

Kitploit — это каталог инструментов для хакинга, кибербезопасности и пентестинга. Находите последние обновления проектов для поиска уязвимостей, анализа систем, автоматизации тестирования и усиления вашей безопасности.

ЛентыКонтактыКонфиденциальность© 2026 Kitploit

Каталог инструментов

Категории

Все категории
Loading categories
cve-2023-23397-detection-lab — Detection and mitigation research lab for CVE-2023-23397 using network and endpoint security telemetry. | Kitploit
Инструменты/GitHubGitHub/zhoucc-cpu/cve-2023-23397-detection-lab
Vulnerability AnalysisNetwork SecurityThreat IntelligenceLearning & EducationIncident Response
GitHubzhoucc-cpu/cve-2023-23397-detection-lab

cve-2023-23397-detection-lab

Detection and mitigation research lab for CVE-2023-23397 using network and endpoint security telemetry.

Репозиторий
4026 дней назадЕщё не проверено

Популярное

Смотреть все →

Откройте для себя самые используемые инструменты нашего сообщества.

Изучить все инструменты

Просмотрите нашу коллекцию инструментов

Смотреть все инструменты →
Поделиться
Контент недоступен на запрошенном языке. Показываем английскую версию.

CVE-2023-23397 Detection & Mitigation Research Lab

Overview

This project is a defensive cybersecurity research lab focused on the network behavior associated with CVE-2023-23397.

The project studies suspicious outbound SMB and NTLM authentication from a Windows endpoint and demonstrates a complete defensive workflow:

Baseline
-> Network Observation
-> NTLM Detection
-> Alert Generation
-> Gateway Mitigation
-> Host Mitigation
-> Validation

The laboratory is fully isolated and uses only systems owned and controlled for authorized security testing.


Research Framing

This repository is organized as a reproducible defensive security study rather than an exploit demonstration. Its central research question is:

Can SMB/NTLM protocol semantics and network trust boundaries detect anomalous outbound authentication behavior associated with CVE-2023-23397, and how do host-side and gateway-side mitigations differ in blocking behavior and sensor visibility?

The study evaluates four questions:

  • whether a parsed NTLM Authenticate event distinguishes authentication from a TCP/445-only connection;
  • whether victim and untrusted subnet constraints exclude out-of-scope authentication;
  • how Windows host filtering and Ubuntu gateway filtering change network visibility;
  • whether packet, protocol, notice, firewall and rollback evidence can be reliably correlated.

The project validates forced outbound SMB/NTLM behavior associated with CVE-2023-23397 and the corresponding detection and mitigation controls. It does not prove that Outlook processed a malicious MAPI message or that CVE-2023-23397 was exploited.

Research Documents

DocumentPurpose
report/project-report.mdMain research report with questions, design, results, discussion, and limitations
docs/literature-review.mdReview of authoritative work on the vulnerability, Forced Authentication, NTLM, Zeek and firewall controls
docs/research-methodology.mdTopology, variables, controls, procedures, evidence sources and validity boundaries
docs/live-validation-2026-09-11.mdExact live validation observations and final lab state
evidence/validation-20260911/PCAPs, logs, integrity manifest and machine-readable verification summary
scripts/verify_validation_evidence.pyRead-only automated evidence consistency checks

Project Goals

The primary goals of this project are to:

  • Build an isolated multi-network cybersecurity laboratory.
  • Observe normal SMB and NTLM authentication behavior.
  • Capture and preserve network evidence.
  • Develop a custom Zeek detection for suspicious outbound NTLM authentication.
  • Validate the detection using controlled traffic.
  • Test gateway-based SMB mitigation.
  • Test Windows host-based SMB mitigation.
  • Compare pre-mitigation and post-mitigation behavior.
  • Map the observed security behavior to MITRE ATT&CK.
  • Produce reproducible evidence suitable for defensive security research.

Lab Architecture

The laboratory contains three virtual machines.

SystemRoleAddress
Windows-VictimProtected Windows endpoint10.10.20.10/24
Ubuntu-SensorRouter and Zeek security sensor10.10.20.1/24, 10.10.30.1/24
Kali-AdversaryControlled SMB destination10.10.30.10/24

Logical traffic path:

Windows-Victim
10.10.20.10
      |
      | VICTIM_NET
      |
Ubuntu-Sensor
10.10.20.1 / 10.10.30.1
      |
      | ATTACK_NET
      |
Kali-Adversary
10.10.30.10

The victim and adversary networks are isolated from each other.

Traffic between them must traverse Ubuntu-Sensor, allowing the sensor to observe and control the communication.

A separate VMware management network is used for administrative SSH access to Ubuntu-Sensor.

More information:

lab/network-plan.md


Threat Scenario

CVE-2023-23397 is associated with forced outbound authentication behavior involving Microsoft Outlook.

The security-relevant behavior is a Windows system attempting to authenticate to an attacker-controlled network resource.

This laboratory focuses on the observable network behavior:

Windows endpoint
-> outbound TCP/445
-> SMB negotiation
-> NTLM authentication
-> network detection

The laboratory does not claim that every generated SMB event represents exploitation of the Outlook vulnerability.

Instead, controlled SMB and NTLM traffic is used to safely develop and validate defensive detection logic.

Detailed analysis:

docs/attack-flow.md


MITRE ATT&CK Mapping

Primary technique:

T1187 - Forced Authentication

Primary tactic:

Credential Access

The project focuses on detecting and preventing suspicious outbound authentication from a protected workstation toward an untrusted destination.


Baseline Traffic Analysis

The first phase established normal routed communication between the Windows victim and the controlled adversary.

Baseline packet captures and Zeek connection logs were collected before detection logic was introduced.

This provided a reference point for later comparison.

Analysis:

docs/baseline-traffic-analysis.md


SMB and NTLM Baseline

A controlled SMB server was hosted on Kali-Adversary.

Windows-Victim successfully accessed:

\\10.10.30.10\SHARE

Zeek successfully parsed:

  • TCP/445 communication
  • SMB
  • NTLM
  • SMB share mappings
  • SMB file activity
  • successful NTLM authentication

The baseline demonstrated that the sensor could observe the complete authentication path before custom detection logic was introduced.

Analysis:

docs/smb-baseline-analysis.md


Custom Zeek Detection

A custom Zeek detector was developed:

detections/zeek/cve_2023_23397_ntlm.zeek

The detector generates:

CVE23397::Suspicious_Outbound_NTLM

The rule evaluates four main conditions:

  1. The source belongs to the protected victim network.
  2. The destination belongs to the controlled untrusted network.
  3. The destination port is TCP/445.
  4. Zeek observes an NTLM Authenticate event.

This provides more context than alerting on TCP/445 alone.

Detection logic:

Victim network
+
Untrusted destination
+
TCP/445
+
NTLM Authenticate
=
Suspicious outbound NTLM notice

A five-minute suppression interval is used to reduce duplicate notices for repeated authentication toward the same destination.


Detection Validation

The custom detector was successfully validated using controlled SMB and NTLM traffic.

The validated event demonstrated correlation between:

  • TCP connection telemetry
  • SMB communication
  • NTLM authentication
  • Zeek connection UID
  • custom Notice Framework alert

A validated alert included:

CVE23397::Suspicious_Outbound_NTLM

The detection analysis and integrity-verified evidence are documented in:

docs/ntlm-detection-analysis.md


Gateway Mitigation

The first mitigation was applied on Ubuntu-Sensor.

The gateway blocked forwarded TCP/445 traffic from:

10.10.20.10

to:

10.10.30.10:445

After the rule was enabled:

Windows SYN
-> Ubuntu Sensor
-> DROP

Observed result:

  • Windows TCP/445 connectivity failed.
  • The sensor observed SYN attempts and retransmissions.
  • The firewall DROP counter increased.
  • No complete TCP handshake occurred.
  • No SMB session was established.
  • No new NTLM authentication occurred.
  • No new custom NTLM alert was generated.

Validation:

docs/mitigation-validation.md


Windows Host Mitigation

A second mitigation was tested using Windows Defender Firewall.

The endpoint blocked outbound:

TCP/445 -> 10.10.30.10

Observed result:

  • TCP/445 connectivity failed.
  • SMB access failed.
  • Ubuntu-Sensor captured zero matching TCP/445 frames.
  • No new NTLM authentication reached the sensor.
  • No new custom Zeek notice was generated.

This demonstrated an important difference between the two defensive control points.

Скачать инструмент