This message was deleted.
# citrix-netscaler
s
This message was deleted.
g
Maybe you should also check for IOCs. Because if you just now patched it is possible that your ADC is already compromised. But I don't know if there are scripts for checking for IOCs based on this cve.
a
thats what i was wondering if there was a way to check with this one but havent found anything yet
m
There is a link in the blog that was posted by Citrix that contains some information on how to detect if you’re hit already. https://media.defense.gov/2022/Dec/13/2003131586/-1/-1/0/CSA-APT5-CITRIXADC-V1.PDF
a
awesome thank you! so turns our we aren't using SAML on our netscaler anymore (we actually have an old SAML policy but its not bound to anything so i'm thinking that would be ok). and also the cyber insurance company just told us they were going off of a scan from beginning of december so didnt even think to ask if we patched mid december when it came out so we're good i guess! thanks for everyones help!