Merge branch 'develop' into nterl0k-rmm_must_die_update_1

This commit is contained in:
Lou Stella
2024-07-26 10:32:02 -05:00
committed by GitHub
1097 changed files with 19282 additions and 15058 deletions
+1 -1
View File
@@ -23,7 +23,7 @@ jobs:
- name: Install Python Dependencies and ContentCTL and Atomic Red Team
run: |
pip install contentctl==4.1.5
pip install contentctl==4.2.0
git clone --depth=1 --single-branch --branch=master https://github.com/redcanaryco/atomic-red-team.git
- name: Running build with enrichments
+1 -1
View File
@@ -24,7 +24,7 @@ jobs:
- name: Install Python Dependencies and ContentCTL
run: |
python -m pip install --upgrade pip
pip install contentctl==4.1.5
pip install contentctl==4.2.0
# Running contentctl test with a few arguments, before running the command make sure you checkout into the current branch of the pull request. This step only performs unit testing on all the changes against the target-branch. In most cases this target branch will be develop
# Make sure we check out the PR, even if it actually lives in a fork
-38
View File
@@ -1,38 +0,0 @@
name: PingID
id: 17890675-61c1-40bd-a88e-6a8e9e246b43
author: Patrick Bareiss, Splunk
source: XmlWinEventLog:Security
sourcetype: XmlWinEventLog
supported_TA: {}
event_names: []
fields:
- _time
- actors{}.name
- actors{}.type
- date_hour
- date_mday
- date_minute
- date_month
- date_second
- date_wday
- date_year
- date_zone
- extracted_source
- host
- id
- index
- linecount
- punct
- recorded
- resources{}.ipaddress
- resources{}.websession
- result.message
- result.status
- source
- sourcetype
- splunk_server
- timeendpos
- timestartpos
example_log:
'{"source":"PINGID","id":"b2eb1fef-651b-11ee-b38b-0ac7a554ed19","recorded":"2023-10-05T14:10:53.538Z","actors":[{"type":"user","name":"victim_user"}],"resources":[{"ipaddress":"174.235.80.142","websession":"webs_ijkF-T_bAC_G3w2TfvdpAEQeC545KFlqVFOsolCXdjo"}],"result":{"status":"SUCCESS","message":"Device
Paired SMS \"Mobile 1\""}}'
-34
View File
@@ -1,34 +0,0 @@
name: Splunk
id: d8a2c791-460b-4756-a8e5-ecade77b21e3
author: Patrick Bareiss, Splunk
source: splunkd_ui_access.log
sourcetype: splunkd_ui_access
supported_TA: {}
event_names: []
fields:
- _time
- action
- date_hour
- date_mday
- date_minute
- date_month
- date_second
- date_wday
- date_year
- date_zone
- dest
- host
- index
- info
- linecount
- punct
- source
- sourcetype
- splunk_server
- timeendpos
- timestamp
- timestartpos
- user
example_log:
"Audit:[timestamp=01-25-2023 22:08:54.818, user=admin, action=search,
info=granted REST: /search/jobs/rt_1674684525.24/events]"
+98
View File
@@ -0,0 +1,98 @@
name: AWS Cloudfront
id: 780086dc-2384-45b6-ade7-56cb00105464
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
description: Data source object for AWS Cloudfront
source: aws
sourcetype: aws:cloudfront:accesslogs
supported_TA:
- name: Splunk Add-on for Amazon Web Services (AWS)
url: https://splunkbase.splunk.com/app/1876
version: 7.4.1
fields:
- _time
- action
- app
- bytes
- bytes_in
- bytes_out
- c_ip
- c_port
- cached
- category
- client_ip
- cs_bytes
- cs_cookie
- cs_host
- cs_method
- cs_protocol
- cs_protocol_version
- cs_referer
- cs_uri_query
- cs_uri_stem
- cs_user_agent
- date
- date_hour
- date_mday
- date_minute
- date_month
- date_second
- date_wday
- date_year
- date_zone
- dest
- duration
- edge_location_name
- eventtype
- fle_encrypted_fields
- fle_status
- host
- http_content_type
- http_method
- http_user_agent
- http_user_agent_length
- index
- linecount
- punct
- response_time
- sc_bytes
- sc_content_len
- sc_content_type
- sc_range_end
- sc_range_start
- sc_status
- source
- sourcetype
- splunk_server
- src
- src_ip
- src_port
- ssl_cipher
- ssl_protocol
- status
- tag
- tag::eventtype
- time
- time_taken
- time_to_first_byte
- timeendpos
- timestartpos
- uri_path
- url
- url_domain
- url_length
- vendor_product
- x_edge_detail_result_type
- x_edge_location
- x_edge_request_id
- x_edge_response_result_type
- x_edge_result_type
- x_forwarded_for
- x_host_header
example_log: "2023-11-07\t16:58:21\tIAD55-P5\t921\t44.192.78.55\tGET\td3u5aue66f5ui4.cloudfront.net\t\
/plugins/servlet/com.jsos.shell/ShellServlet\t200\t-\tSlackbot-LinkExpanding%201.0%20(+https://api.slack.com/robots)\t\
-\t-\tLambdaGeneratedResponse\tsGwvFCkFU4qlMxatCoJRgW87P7Ee8bKQor3U6lRt6I6jaFvLC7vcPA==\t\
confluence.catjamfest.com\thttps\t232\t0.276\t-\tTLSv1.3\tTLS_AES_128_GCM_SHA256\t\
LambdaGeneratedResponse\tHTTP/1.1\t-\t-\t57232\t0.276\tLambdaGeneratedResponse\t\
text/html\t527\t-\t-"
+14
View File
@@ -0,0 +1,14 @@
name: AWS CloudTrail
id: e8ace6db-1dbd-4c72-a1fb-334684619a38
version: 1
date: '2024-07-24'
author: Patrick Bareiss, Splunk
description: Data source object for AWS CloudTrail
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
supported_TA:
- name: Splunk Add-on for Amazon Web Services (AWS)
url: https://splunkbase.splunk.com/app/1876
version: 7.4.1
@@ -0,0 +1,126 @@
name: AWS CloudTrail AssumeRoleWithSAML
id: 1e28f2a6-2db9-405f-b298-18734a293f77
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
description: Data source object for AWS CloudTrail AssumeRoleWithSAML
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
supported_TA:
- name: Splunk Add-on for Amazon Web Services (AWS)
url: https://splunkbase.splunk.com/app/1876
version: 7.4.1
fields:
- _time
- action
- app
- awsRegion
- change_type
- command
- date_hour
- date_mday
- date_minute
- date_month
- date_second
- date_wday
- date_year
- date_zone
- dest
- dvc
- errorCode
- eventCategory
- eventID
- eventName
- eventSource
- eventTime
- eventType
- eventVersion
- eventtype
- host
- index
- linecount
- managementEvent
- msg
- object_category
- product
- punct
- readOnly
- recipientAccountId
- region
- requestID
- requestParameters.durationSeconds
- requestParameters.principalArn
- requestParameters.roleArn
- requestParameters.roleSessionName
- requestParameters.sAMLAssertionID
- resources{}.ARN
- resources{}.accountId
- resources{}.type
- responseElements.assumedRoleUser.arn
- responseElements.assumedRoleUser.assumedRoleId
- responseElements.audience
- responseElements.credentials.accessKeyId
- responseElements.credentials.expiration
- responseElements.credentials.sessionToken
- responseElements.issuer
- responseElements.nameQualifier
- responseElements.subject
- responseElements.subjectType
- signature
- source
- sourceIPAddress
- sourcetype
- splunk_server
- src
- src_ip
- src_user
- src_user_id
- src_user_type
- start_time
- status
- tag
- tag::action
- tag::eventtype
- temp_access_key
- timeendpos
- timestartpos
- user
- userAgent
- userIdentity.identityProvider
- userIdentity.principalId
- userIdentity.type
- userIdentity.userName
- user_agent
- user_arn
- user_id
- user_name
- user_role
- user_type
- vendor
- vendor_account
- vendor_product
- vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "SAMLUser", "principalId":
"ZRu9MRAjiG9tvi1QBNfdI664G5A=:rodsoto@rodsoto.onmicrosoft.com", "userName": "rodsoto@rodsoto.onmicrosoft.com",
"identityProvider": "ZRu9MRAjiG9tvi1QBNfdI664G5A="}, "eventTime": "2021-01-22T03:44:16Z",
"eventSource": "sts.amazonaws.com", "eventName": "AssumeRoleWithSAML", "awsRegion":
"us-east-1", "sourceIPAddress": "72.21.217.152", "userAgent": "AWS Signin, aws-internal/3
aws-sdk-java/1.11.898 Linux/4.9.230-0.1.ac.223.84.332.metal1.x86_64 OpenJDK_64-Bit_Server_VM/25.275-b01
java/1.8.0_275 kotlin/1.3.72 vendor/Oracle_Corporation", "requestParameters": {"sAMLAssertionID":
"_d33ba0ad-0c88-4b83-80a6-27c08027d000", "roleSessionName": "rodsoto@rodsoto.onmicrosoft.com",
"durationSeconds": 3600, "roleArn": "arn:aws:iam::111111111111:role/rodonmicrotestrole",
"principalArn": "arn:aws:iam::111111111111:saml-provider/rodsotoonmicrosoft"}, "responseElements":
{"subjectType": "urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress", "issuer":
"https://sts.windows.net/0e8108b1-18e9-41a4-961b-dfcddf92ef08/", "credentials":
{"accessKeyId": "ASIAYTOGP2RLKJXOV7VR", "expiration": "Jan 22, 2021 3:59:16 AM",
"sessionToken": "IQoJb3JpZ2luX2VjENz//////////wEaCXVzLWVhc3QtMSJGMEQCIHl/WQdLq53ULYl10fPtpeV3H7da9mOXGuIStvhdDA6kAiAdO/7rocOXAtyDV+0MJhSj/piqlqEI/BcAKm8zqBhOgiqgAwi1//////////8BEAIaDDU5MTUxMTE0NzYwNiIMAFP8GfyI/x1fKCHYKvQCznxxgKnEdcuvrr/fBLmHxEDjQ9vQxjasA8gZF8GawZ5SFH9ViKqoZh93bYkOwKqZD8cdqJIo9SYL17RGhVqxzvsjU4+QsRXTN5eGgh+LyF9EZqeCl6oCkaTJqNrXHuenzTi0yiL510LKsSckrAm8+SuwI/jQu3oE1BEcJQieAc4RjYx3II+1cUvyfRlFvR2NDfZhdWcQvAivV06KJg9c2zfCF0Agzn/YZSNvsRL5UhnKhJ2wktSvT8lR0mS3n9xR1j3iYNxVDHab180cnfkP3G6tAmxj5U29diNQrusJxKWWhr/Q9wHRdDj5dO2QUZzSymKKU/UiRJ8nyYPINaJ8XWVAPiT4QgzpMxotkvSkDLEG/brB9yEr2p7W8Y3xMGZ37qSGkuU4z9x40RU9G1XPhv27NO9aaGs/VXYTMCzWRNxnsLfNkk/DihrcaR0SclRcvs+zmfe1ZUoGnfjNYm+AIyJi4D7OrXF5/Mt46Z2y76DnULlAMJCUqYAGOpsBw4fyafV8OizX7Lebh2JRXFZsWBY1GTpyGvO5otrw++4axud44vYVi5iU5rbJxtTBm4vtJartxgXoPJFnQuat9gLrIlXhjmg+m50a5xs1Ut2UWEsWY2Duu4jA9ap7P7dYv9kIK9P2uyhsjKQhCjTpfe4I/llcupbDotYBJuvlB5n85a5kgiSriFk5zetoXQIweuYEWQZsD/AN+LE="},
"nameQualifier": "ZRu9MRAjiG9tvi1QBNfdI664G5A=", "assumedRoleUser": {"assumedRoleId":
"AROAYTOGP2RLKFUVAQAIJ:rodsoto@rodsoto.onmicrosoft.com", "arn": "arn:aws:sts::111111111111:assumed-role/rodonmicrotestrole/rodsoto@rodsoto.onmicrosoft.com"},
"subject": "rodsoto@rodsoto.onmicrosoft.com", "audience": "https://signin.aws.amazon.com/saml"},
"requestID": "e19c7a7f-cd96-4642-9ee6-2360a7b01b12", "eventID": "b25b825d-9c9b-49d3-9ecd-290dbe8f2c29",
"readOnly": true, "resources": [{"accountId": "111111111111", "type": "AWS::IAM::Role",
"ARN": "arn:aws:iam::111111111111:role/rodonmicrotestrole"}, {"accountId": "111111111111",
"type": "AWS::IAM::SAMLProvider", "ARN": "arn:aws:iam::111111111111:saml-provider/rodsotoonmicrosoft"}],
"eventType": "AwsApiCall", "managementEvent": true, "eventCategory": "Management",
"recipientAccountId": "111111111111"}'
@@ -0,0 +1,102 @@
name: AWS CloudTrail ConsoleLogin
id: b68b3f26-bd21-4fa8-b593-616fe75ac0ae
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
description: Data source object for AWS CloudTrail ConsoleLogin
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
supported_TA:
- name: Splunk Add-on for Amazon Web Services (AWS)
url: https://splunkbase.splunk.com/app/1876
version: 7.4.1
fields:
- _time
- action
- additionalEventData.LoginTo
- additionalEventData.MFAUsed
- additionalEventData.MobileVersion
- app
- authentication_method
- awsRegion
- aws_account_id
- command
- date_hour
- date_mday
- date_minute
- date_month
- date_second
- date_wday
- date_year
- date_zone
- desc
- dest
- dvc
- errorCode
- errorMessage
- eventCategory
- eventID
- eventName
- eventSource
- eventTime
- eventType
- eventVersion
- eventtype
- host
- index
- linecount
- managementEvent
- msg
- object_category
- product
- punct
- readOnly
- reason
- recipientAccountId
- region
- requestParameters
- responseElements.ConsoleLogin
- result
- signature
- source
- sourceIPAddress
- sourcetype
- splunk_server
- src
- src_ip
- start_time
- status
- tag
- tag::action
- tag::eventtype
- timeendpos
- timestartpos
- tlsDetails.cipherSuite
- tlsDetails.clientProvidedHostHeader
- tlsDetails.tlsVersion
- userAgent
- userIdentity.accessKeyId
- userIdentity.accountId
- userIdentity.type
- userIdentity.userName
- user_access_key
- user_agent
- user_group_id
- user_name
- user_type
- vendor
- vendor_account
- vendor_product
- vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "accountId":
"140429656527", "accessKeyId": "", "userName": "HIDDEN_DUE_TO_SECURITY_REASONS"},
"eventTime": "2022-10-19T20:33:38Z", "eventSource": "signin.amazonaws.com", "eventName":
"ConsoleLogin", "awsRegion": "us-east-1", "sourceIPAddress": "142.254.89.27", "userAgent":
"Go-http-client/1.1", "errorMessage": "No username found in supplied account", "requestParameters":
null, "responseElements": {"ConsoleLogin": "Failure"}, "additionalEventData": {"LoginTo":
"https://console.aws.amazon.com", "MobileVersion": "No", "MFAUsed": "No"}, "eventID":
"9fcfb8c3-3fca-48db-85d2-7b107f9d95d0", "readOnly": false, "eventType": "AwsConsoleSignIn",
"managementEvent": true, "recipientAccountId": "140429656527", "eventCategory":
"Management", "tlsDetails": {"tlsVersion": "TLSv1.2", "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "signin.aws.amazon.com"}}'
+119
View File
@@ -0,0 +1,119 @@
name: AWS CloudTrail CopyObject
id: 965083f4-64a8-403f-99cc-252e1a6bd3b6
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
description: Data source object for AWS CloudTrail CopyObject
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
supported_TA:
- name: Splunk Add-on for Amazon Web Services (AWS)
url: https://splunkbase.splunk.com/app/1876
version: 7.4.1
fields:
- _time
- additionalEventData.AuthenticationMethod
- additionalEventData.CipherSuite
- additionalEventData.SSEApplied
- additionalEventData.SignatureVersion
- additionalEventData.bytesTransferredIn
- additionalEventData.bytesTransferredOut
- additionalEventData.x-amz-id-2
- app
- awsRegion
- aws_account_id
- command
- date_hour
- date_mday
- date_minute
- date_month
- date_second
- date_wday
- date_year
- date_zone
- dest
- dvc
- errorCode
- eventCategory
- eventID
- eventName
- eventSource
- eventTime
- eventType
- eventVersion
- host
- index
- linecount
- managementEvent
- msg
- object_category
- product
- punct
- readOnly
- recipientAccountId
- region
- requestID
- requestParameters.Host
- requestParameters.bucketName
- requestParameters.key
- requestParameters.x-amz-copy-source
- requestParameters.x-amz-server-side-encryption
- requestParameters.x-amz-server-side-encryption-aws-kms-key-id
- resources{}.ARN
- resources{}.accountId
- resources{}.type
- responseElements.x-amz-server-side-encryption
- responseElements.x-amz-server-side-encryption-aws-kms-key-id
- signature
- source
- sourceIPAddress
- sourcetype
- splunk_server
- src
- src_ip
- start_time
- timeendpos
- timestartpos
- user
- userAgent
- userIdentity.accessKeyId
- userIdentity.accountId
- userIdentity.arn
- userIdentity.principalId
- userIdentity.type
- userIdentity.userName
- userName
- user_access_key
- user_agent
- user_arn
- user_group_id
- user_id
- user_name
- user_type
- vendor
- vendor_account
- vendor_product
- vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId":
"AIDAYTOGP2RLNALZHZ6KX", "arn": "arn:aws:iam::111111111111:user/patrick_cli", "accountId":
"111111111111", "accessKeyId": "AKIAYTOGP2RLJ2OYSF6E", "userName": "patrick_cli"},
"eventTime": "2021-01-11T12:40:47Z", "eventSource": "s3.amazonaws.com", "eventName":
"CopyObject", "awsRegion": "us-west-2", "sourceIPAddress": "95.90.199.65", "userAgent":
"[aws-cli/2.0.45 Python/3.7.4 Darwin/20.2.0 exe/x86_64 command/s3.cp]", "requestParameters":
{"bucketName": "patricktestbucketencrypt", "x-amz-server-side-encryption-aws-kms-key-id":
"arn:aws:kms:us-west-2:111111111111:key/f2a82583-a7d3-4c92-8787-fe2baab1cee1", "Host":
"patricktestbucketencrypt.s3.us-west-2.amazonaws.com", "x-amz-server-side-encryption":
"aws:kms", "x-amz-copy-source": "patricktestbucketencrypt/kms_aws_events.json",
"key": "kms_aws_events_encrypted.json"}, "responseElements": {"x-amz-server-side-encryption":
"aws:kms", "x-amz-server-side-encryption-aws-kms-key-id": "arn:aws:kms:us-west-2:111111111111:key/f2a82583-a7d3-4c92-8787-fe2baab1cee1"},
"additionalEventData": {"SignatureVersion": "SigV4", "CipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"bytesTransferredIn": 0.0, "SSEApplied": "SSE_KMS", "AuthenticationMethod": "AuthHeader",
"x-amz-id-2": "fqzX1iZV6ImDtkFxbGvziOE6fUwryRa+PhnLckfVAkLNHdbCAHNq4l/yckUd1a2HNJPL6NAS01U=",
"bytesTransferredOut": 234.0}, "requestID": "6A7359F7A9414B02", "eventID": "b20d43de-175d-4443-acd7-f5f3e587ae00",
"readOnly": false, "resources": [{"type": "AWS::S3::Object", "ARN": "arn:aws:s3:::patricktestbucketencrypt/kms_aws_events_encrypted.json"},
{"accountId": "111111111111", "type": "AWS::S3::Bucket", "ARN": "arn:aws:s3:::patricktestbucketencrypt"},
{"accountId": "111111111111", "type": "AWS::S3::Bucket", "ARN": "arn:aws:s3:::patricktestbucketencrypt"},
{"type": "AWS::S3::Object", "ARN": "arn:aws:s3:::patricktestbucketencrypt/kms_aws_events.json"}],
"eventType": "AwsApiCall", "managementEvent": false, "recipientAccountId": "111111111111",
"eventCategory": "Data"}'
@@ -0,0 +1,103 @@
name: AWS CloudTrail CreateAccessKey
id: 0460f7da-3254-4d90-b8c0-2ca657d0cea0
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
description: Data source object for AWS CloudTrail CreateAccessKey
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
supported_TA:
- name: Splunk Add-on for Amazon Web Services (AWS)
url: https://splunkbase.splunk.com/app/1876
version: 7.4.1
fields:
- _time
- action
- app
- awsRegion
- aws_account_id
- change_type
- command
- date_hour
- date_mday
- date_minute
- date_month
- date_second
- date_wday
- date_year
- date_zone
- dest
- dvc
- errorCode
- eventCategory
- eventID
- eventName
- eventSource
- eventTime
- eventType
- eventVersion
- eventtype
- host
- index
- linecount
- managementEvent
- msg
- object_category
- product
- punct
- readOnly
- recipientAccountId
- region
- requestID
- requestParameters.userName
- responseElements.accessKey.accessKeyId
- responseElements.accessKey.createDate
- responseElements.accessKey.status
- responseElements.accessKey.userName
- signature
- source
- sourceIPAddress
- sourcetype
- splunk_server
- src
- src_ip
- src_user_name
- start_time
- status
- tag
- tag::eventtype
- timeendpos
- timestartpos
- user
- userAgent
- userIdentity.accessKeyId
- userIdentity.accountId
- userIdentity.arn
- userIdentity.principalId
- userIdentity.type
- userIdentity.userName
- userName
- user_access_key
- user_agent
- user_arn
- user_group_id
- user_id
- user_name
- user_type
- vendor
- vendor_account
- vendor_product
- vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId":
"AIDAYTOGP2RLEHRX5YWNV", "arn": "arn:aws:iam::121521347698:user/bhavin_cli", "accountId":
"121521347698", "accessKeyId": "AKIAYTOGP2RLLAA6NJUM", "userName": "bhavin_cli"},
"eventTime": "2021-03-02T21:18:24Z", "eventSource": "iam.amazonaws.com", "eventName":
"CreateAccessKey", "awsRegion": "us-east-1", "sourceIPAddress": "12.25.72.12", "userAgent":
"aws-cli/2.0.62 Python/3.9.0 Darwin/19.6.0 source/x86_64 command/iam.create-access-key",
"requestParameters": {"userName": "AtomicRedTeam"}, "responseElements": {"accessKey":
{"userName": "AtomicRedTeam", "accessKeyId": "AKIAYTOGP2RLOQ4ULYGT", "status": "Active",
"createDate": "Mar 2, 2021 9:18:24 PM"}}, "requestID": "12c8773d-6c78-46bf-a8e4-f841adc8f70d",
"eventID": "5772e8d5-cccc-470d-81ef-acacfe85a804", "readOnly": false, "eventType":
"AwsApiCall", "managementEvent": true, "eventCategory": "Management", "recipientAccountId":
"121521347698"}'
+150
View File
@@ -0,0 +1,150 @@
name: AWS CloudTrail CreateKey
id: fcfc1593-b6b5-4a0f-91c5-3c395116a8b9
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
description: Data source object for AWS CloudTrail CreateKey
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
supported_TA:
- name: Splunk Add-on for Amazon Web Services (AWS)
url: https://splunkbase.splunk.com/app/1876
version: 7.4.1
fields:
- _time
- app
- awsRegion
- aws_account_id
- command
- date_hour
- date_mday
- date_minute
- date_month
- date_second
- date_wday
- date_year
- date_zone
- dest
- dvc
- errorCode
- eventCategory
- eventID
- eventName
- eventSource
- eventTime
- eventType
- eventVersion
- eventtype
- host
- index
- linecount
- managementEvent
- msg
- object_category
- product
- punct
- readOnly
- recipientAccountId
- region
- requestID
- requestParameters.bypassPolicyLockoutSafetyCheck
- requestParameters.customerMasterKeySpec
- requestParameters.description
- requestParameters.keyUsage
- requestParameters.origin
- requestParameters.policy
- resources{}.ARN
- resources{}.accountId
- resources{}.type
- responseElements.keyMetadata.aWSAccountId
- responseElements.keyMetadata.arn
- responseElements.keyMetadata.creationDate
- responseElements.keyMetadata.customerMasterKeySpec
- responseElements.keyMetadata.description
- responseElements.keyMetadata.enabled
- responseElements.keyMetadata.encryptionAlgorithms{}
- responseElements.keyMetadata.keyId
- responseElements.keyMetadata.keyManager
- responseElements.keyMetadata.keyState
- responseElements.keyMetadata.keyUsage
- responseElements.keyMetadata.origin
- signature
- source
- sourceIPAddress
- sourcetype
- splunk_server
- src
- src_ip
- start_time
- tag
- tag::eventtype
- timeendpos
- timestartpos
- user
- userAgent
- userIdentity.accessKeyId
- userIdentity.accountId
- userIdentity.arn
- userIdentity.principalId
- userIdentity.sessionContext.attributes.creationDate
- userIdentity.sessionContext.attributes.mfaAuthenticated
- userIdentity.sessionContext.sessionIssuer.accountId
- userIdentity.sessionContext.sessionIssuer.arn
- userIdentity.sessionContext.sessionIssuer.principalId
- userIdentity.sessionContext.sessionIssuer.type
- userIdentity.sessionContext.sessionIssuer.userName
- userIdentity.type
- userName
- user_access_key
- user_agent
- user_arn
- user_group_id
- user_id
- user_name
- user_type
- vendor
- vendor_account
- vendor_product
- vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "principalId":
"AROAIJIESMXKGCJRCTPR6:pbareiss@splunk.local", "arn": "arn:aws:sts::111111111111:assumed-role/okta_adm_role/pbareiss@splunk.local",
"accountId": "111111111111", "accessKeyId": "ASIAYTOGP2RLK74OPBDR", "sessionContext":
{"sessionIssuer": {"type": "Role", "principalId": "AROAIJIESMXKGCJRCTPR6", "arn":
"arn:aws:iam::111111111111:role/okta_adm_role", "accountId": "111111111111", "userName":
"okta_adm_role"}, "webIdFederationData": {}, "attributes": {"mfaAuthenticated":
"false", "creationDate": "2021-01-11T09:03:18Z"}}}, "eventTime": "2021-01-11T09:56:31Z",
"eventSource": "kms.amazonaws.com", "eventName": "CreateKey", "awsRegion": "us-west-2",
"sourceIPAddress": "95.90.199.65", "userAgent": "aws-internal/3 aws-sdk-java/1.11.893
Linux/4.9.230-0.1.ac.223.84.332.metal1.x86_64 OpenJDK_64-Bit_Server_VM/25.272-b10
java/1.8.0_272 vendor/Oracle_Corporation", "requestParameters": {"origin": "AWS_KMS",
"policy": "{\n \"Id\": \"key-consolepolicy-3\",\n \"Version\": \"2012-10-17\",\n \"Statement\":
[\n {\n \"Sid\": \"Enable IAM User Permissions\",\n \"Effect\":
\"Allow\",\n \"Principal\": {\n \"AWS\": \"arn:aws:iam::111111111111:root\"\n },\n \"Action\":
\"kms:*\",\n \"Resource\": \"*\"\n },\n {\n \"Sid\":
\"Allow access for Key Administrators\",\n \"Effect\": \"Allow\",\n \"Principal\":
{\n \"AWS\": \"arn:aws:iam::111111111111:user/patrick_cli\"\n },\n \"Action\":
[\n \"kms:Create*\",\n \"kms:Describe*\",\n \"kms:Enable*\",\n \"kms:List*\",\n \"kms:Put*\",\n \"kms:Update*\",\n \"kms:Revoke*\",\n \"kms:Disable*\",\n \"kms:Get*\",\n \"kms:Delete*\",\n \"kms:TagResource\",\n \"kms:UntagResource\",\n \"kms:ScheduleKeyDeletion\",\n \"kms:CancelKeyDeletion\"\n ],\n \"Resource\":
\"*\"\n },\n {\n \"Sid\": \"Allow use of the key\",\n \"Effect\":
\"Allow\",\n \"Principal\": {\n \"AWS\": \"arn:aws:iam::111111111111:user/patrick_cli\"\n },\n \"Action\":
[\n \"kms:Encrypt\",\n \"kms:Decrypt\",\n \"kms:ReEncrypt*\",\n \"kms:GenerateDataKey*\",\n \"kms:DescribeKey\"\n ],\n \"Resource\":
\"*\"\n },\n {\n \"Sid\": \"Allow attachment of persistent
resources\",\n \"Effect\": \"Allow\",\n \"Principal\": {\n \"AWS\":
\"arn:aws:iam::111111111111:user/patrick_cli\"\n },\n \"Action\":
[\n \"kms:CreateGrant\",\n \"kms:ListGrants\",\n \"kms:RevokeGrant\"\n ],\n \"Resource\":
\"*\",\n \"Condition\": {\n \"Bool\": {\n \"kms:GrantIsForAWSResource\":
\"true\"\n }\n }\n },\n {\n \"Sid\":
\"Allow use of the key\",\n \"Effect\": \"Allow\",\n \"Principal\":
{\n \"AWS\": \"*\"\n },\n \"Action\": [\n \"kms:Encrypt\"\n ],\n \"Resource\":
\"*\"\n }\n ]\n}", "description": "", "customerMasterKeySpec": "SYMMETRIC_DEFAULT",
"bypassPolicyLockoutSafetyCheck": false, "tags": [], "keyUsage": "ENCRYPT_DECRYPT"},
"responseElements": {"keyMetadata": {"aWSAccountId": "111111111111", "keyId": "f2a82583-a7d3-4c92-8787-fe2baab1cee1",
"arn": "arn:aws:kms:us-west-2:111111111111:key/f2a82583-a7d3-4c92-8787-fe2baab1cee1",
"creationDate": "Jan 11, 2021, 9:56:30 AM", "enabled": true, "description": "",
"keyUsage": "ENCRYPT_DECRYPT", "keyState": "Enabled", "origin": "AWS_KMS", "keyManager":
"CUSTOMER", "customerMasterKeySpec": "SYMMETRIC_DEFAULT", "encryptionAlgorithms":
["SYMMETRIC_DEFAULT"]}}, "requestID": "3356af25-a237-471f-ba5e-abb37d4a256f", "eventID":
"f09518ac-5ae5-4214-80ee-4f23ccdedd4c", "readOnly": false, "resources": [{"accountId":
"111111111111", "type": "AWS::KMS::Key", "ARN": "arn:aws:kms:us-west-2:111111111111:key/f2a82583-a7d3-4c92-8787-fe2baab1cee1"}],
"eventType": "AwsApiCall", "managementEvent": true, "eventCategory": "Management",
"recipientAccountId": "111111111111"}'
@@ -0,0 +1,102 @@
name: AWS CloudTrail CreateLoginProfile
id: 0024fdb1-0d62-4449-970a-746952cf80b6
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
description: Data source object for AWS CloudTrail CreateLoginProfile
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
supported_TA:
- name: Splunk Add-on for Amazon Web Services (AWS)
url: https://splunkbase.splunk.com/app/1876
version: 7.4.1
fields:
- _time
- action
- app
- awsRegion
- aws_account_id
- change_type
- command
- date_hour
- date_mday
- date_minute
- date_month
- date_second
- date_wday
- date_year
- date_zone
- dest
- dvc
- errorCode
- eventCategory
- eventID
- eventName
- eventSource
- eventTime
- eventType
- eventVersion
- eventtype
- host
- index
- linecount
- managementEvent
- msg
- object_category
- product
- punct
- readOnly
- recipientAccountId
- region
- requestID
- requestParameters.passwordResetRequired
- requestParameters.userName
- responseElements.loginProfile.createDate
- responseElements.loginProfile.passwordResetRequired
- responseElements.loginProfile.userName
- signature
- source
- sourceIPAddress
- sourcetype
- splunk_server
- src
- src_ip
- start_time
- status
- tag
- tag::eventtype
- timeendpos
- timestartpos
- user
- userAgent
- userIdentity.accessKeyId
- userIdentity.accountId
- userIdentity.arn
- userIdentity.principalId
- userIdentity.type
- userIdentity.userName
- userName
- user_access_key
- user_agent
- user_arn
- user_group_id
- user_id
- user_name
- user_type
- vendor
- vendor_account
- vendor_product
- vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId":
"AIDAYTOGP2RLEHRX5YWNV", "arn": "arn:aws:iam::111111111111:user/bhavin_cli", "accountId":
"111111111111", "accessKeyId": "AKIAYTOGP2RLLAA6NJUM", "userName": "bhavin_cli"},
"eventTime": "2021-03-05T01:02:38Z", "eventSource": "iam.amazonaws.com", "eventName":
"CreateLoginProfile", "awsRegion": "us-east-1", "sourceIPAddress": "73.15.72.101",
"userAgent": "aws-cli/2.0.62 Python/3.9.2 Darwin/19.6.0 source/x86_64 command/iam.create-login-profile",
"requestParameters": {"userName": "AtomicRedTeam", "passwordResetRequired": false},
"responseElements": {"loginProfile": {"userName": "AtomicRedTeam", "createDate":
"Mar 5, 2021 1:02:38 AM", "passwordResetRequired": false}}, "requestID": "f1b90364-8aed-4559-96cf-f5f2009bb7cb",
"eventID": "ffb76906-6dd1-4219-adfe-e26b92036a1e", "readOnly": false, "eventType":
"AwsApiCall", "managementEvent": true, "eventCategory": "Management", "recipientAccountId":
"111111111111"}'
@@ -0,0 +1,121 @@
name: AWS CloudTrail CreateNetworkAclEntry
id: 45934028-10ec-4ab5-a7b1-a6349b833e67
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
description: Data source object for AWS CloudTrail CreateNetworkAclEntry
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
supported_TA:
- name: Splunk Add-on for Amazon Web Services (AWS)
url: https://splunkbase.splunk.com/app/1876
version: 7.4.1
fields:
- _time
- action
- app
- awsRegion
- aws_account_id
- change_type
- command
- date_hour
- date_mday
- date_minute
- date_month
- date_second
- date_wday
- date_year
- date_zone
- dest
- direction
- dvc
- errorCode
- eventCategory
- eventID
- eventName
- eventSource
- eventTime
- eventType
- eventVersion
- eventtype
- host
- index
- linecount
- managementEvent
- msg
- object
- object_category
- object_id
- product
- protocol
- protocol_code
- punct
- readOnly
- recipientAccountId
- region
- requestID
- requestParameters.aclProtocol
- requestParameters.cidrBlock
- requestParameters.egress
- requestParameters.networkAclId
- requestParameters.ruleAction
- requestParameters.ruleNumber
- responseElements._return
- responseElements.requestId
- rule_action
- signature
- source
- sourceIPAddress
- sourcetype
- splunk_server
- src
- src_ip
- src_ip_range
- start_time
- status
- tag
- tag::eventtype
- timeendpos
- timestartpos
- user
- userAgent
- userIdentity.accessKeyId
- userIdentity.accountId
- userIdentity.arn
- userIdentity.principalId
- userIdentity.sessionContext.attributes.creationDate
- userIdentity.sessionContext.attributes.mfaAuthenticated
- userIdentity.sessionContext.sessionIssuer.accountId
- userIdentity.sessionContext.sessionIssuer.arn
- userIdentity.sessionContext.sessionIssuer.principalId
- userIdentity.sessionContext.sessionIssuer.type
- userIdentity.sessionContext.sessionIssuer.userName
- userIdentity.type
- userName
- user_access_key
- user_agent
- user_arn
- user_group_id
- user_id
- user_name
- user_type
- vendor
- vendor_account
- vendor_product
- vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "principalId":
"AROAIJIESMXKGCJRCTPR6:pbareiss@splunk.local", "arn": "arn:aws:sts::111111111111:assumed-role/okta_adm_role/pbareiss@splunk.local",
"accountId": "111111111111", "accessKeyId": "ASIAYTOGP2RLF3F7BXZK", "sessionContext":
{"sessionIssuer": {"type": "Role", "principalId": "AROAIJIESMXKGCJRCTPR6", "arn":
"arn:aws:iam::111111111111:role/okta_adm_role", "accountId": "111111111111", "userName":
"okta_adm_role"}, "webIdFederationData": {}, "attributes": {"mfaAuthenticated":
"false", "creationDate": "2021-01-12T08:36:15Z"}}}, "eventTime": "2021-01-12T08:38:39Z",
"eventSource": "ec2.amazonaws.com", "eventName": "CreateNetworkAclEntry", "awsRegion":
"eu-central-1", "sourceIPAddress": "95.90.199.65", "userAgent": "console.ec2.amazonaws.com",
"requestParameters": {"networkAclId": "acl-078ccebebcbabe175", "ruleNumber": 10,
"egress": false, "ruleAction": "allow", "icmpTypeCode": {}, "portRange": {}, "aclProtocol":
"-1", "cidrBlock": "0.0.0.0/0"}, "responseElements": {"requestId": "d29c9c32-3a72-48d3-b612-6ba795e9ec64",
"_return": true}, "requestID": "d29c9c32-3a72-48d3-b612-6ba795e9ec64", "eventID":
"6d1ce00e-4099-463c-8a4d-2af2fb2178ba", "readOnly": false, "eventType": "AwsApiCall",
"managementEvent": true, "eventCategory": "Management", "recipientAccountId": "111111111111"}'
@@ -0,0 +1,106 @@
name: AWS CloudTrail CreatePolicyVersion
id: f9f0f3da-37ec-4164-9ea0-0ae46645a86b
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
description: Data source object for AWS CloudTrail CreatePolicyVersion
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
supported_TA:
- name: Splunk Add-on for Amazon Web Services (AWS)
url: https://splunkbase.splunk.com/app/1876
version: 7.4.1
fields:
- _time
- action
- app
- awsRegion
- aws_account_id
- change_type
- command
- date_hour
- date_mday
- date_minute
- date_month
- date_second
- date_wday
- date_year
- date_zone
- dest
- dvc
- errorCode
- eventCategory
- eventID
- eventName
- eventSource
- eventTime
- eventType
- eventVersion
- eventtype
- host
- index
- linecount
- managementEvent
- msg
- object_category
- product
- punct
- readOnly
- recipientAccountId
- region
- requestID
- requestParameters.policyArn
- requestParameters.policyDocument
- requestParameters.setAsDefault
- responseElements.policyVersion.createDate
- responseElements.policyVersion.isDefaultVersion
- responseElements.policyVersion.versionId
- signature
- source
- sourceIPAddress
- sourcetype
- splunk_server
- src
- src_ip
- start_time
- status
- tag
- tag::eventtype
- timeendpos
- timestartpos
- user
- userAgent
- userIdentity.accessKeyId
- userIdentity.accountId
- userIdentity.arn
- userIdentity.principalId
- userIdentity.type
- userIdentity.userName
- userName
- user_access_key
- user_agent
- user_arn
- user_group_id
- user_id
- user_name
- user_type
- vendor
- vendor_account
- vendor_product
- vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId":
"AIDAYTOGP2RLNMCDVJZAY", "arn": "arn:aws:iam::111111111111:user/rhino_escalate",
"accountId": "111111111111", "accessKeyId": "AKIAYTOGP2RLHSQZPZFZ", "userName":
"rhino_escalate"}, "eventTime": "2021-02-23T00:02:30Z", "eventSource": "iam.amazonaws.com",
"eventName": "CreatePolicyVersion", "awsRegion": "us-east-1", "sourceIPAddress":
"73.15.72.101", "userAgent": "aws-cli/2.0.62 Python/3.9.0 Darwin/19.6.0 source/x86_64
command/iam.create-policy-version", "requestParameters": {"policyArn": "arn:aws:iam::111111111111:policy/rhino_escalate",
"policyDocument": "{\n \"Version\": \"2012-10-17\",\n \"Statement\": [\n {\n \"Sid\":
\"AllowEverything\",\n \"Effect\": \"Allow\",\n \"Action\":
\"iam:*\",\n \"Resource\": \"*\"\n }\n ]\n }", "setAsDefault":
true}, "responseElements": {"policyVersion": {"versionId": "v2", "isDefaultVersion":
true, "createDate": "Feb 23, 2021 12:02:30 AM"}}, "requestID": "fa42b4b2-f34a-4673-8f9f-b25cf1f5005a",
"eventID": "33149175-90fd-4cff-a43b-408e4f848c1c", "readOnly": false, "eventType":
"AwsApiCall", "managementEvent": true, "eventCategory": "Management", "recipientAccountId":
"111111111111"}'
@@ -0,0 +1,118 @@
name: AWS CloudTrail CreateSnapshot
id: 514135a2-f4b2-4d32-8f31-d87824887f9f
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
description: Data source object for AWS CloudTrail CreateSnapshot
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
supported_TA:
- name: Splunk Add-on for Amazon Web Services (AWS)
url: https://splunkbase.splunk.com/app/1876
version: 7.4.1
fields:
- _time
- app
- awsRegion
- aws_account_id
- change_type
- command
- date_hour
- date_mday
- date_minute
- date_month
- date_second
- date_wday
- date_year
- date_zone
- dest
- dvc
- errorCode
- eventCategory
- eventID
- eventName
- eventSource
- eventTime
- eventType
- eventVersion
- eventtype
- host
- index
- linecount
- managementEvent
- msg
- object_category
- product
- punct
- readOnly
- recipientAccountId
- region
- requestID
- requestParameters.tagSpecificationSet.items{}.resourceType
- requestParameters.tagSpecificationSet.items{}.tags{}.key
- requestParameters.tagSpecificationSet.items{}.tags{}.value
- requestParameters.volumeId
- responseElements.encrypted
- responseElements.ownerId
- responseElements.requestId
- responseElements.snapshotId
- responseElements.startTime
- responseElements.status
- responseElements.tagSet.items{}.key
- responseElements.tagSet.items{}.value
- responseElements.volumeId
- responseElements.volumeSize
- signature
- source
- sourceIPAddress
- sourcetype
- splunk_server
- src
- src_ip
- start_time
- tag
- tag::eventtype
- timeendpos
- timestartpos
- tlsDetails.cipherSuite
- tlsDetails.clientProvidedHostHeader
- tlsDetails.tlsVersion
- user
- userAgent
- userIdentity.accessKeyId
- userIdentity.accountId
- userIdentity.arn
- userIdentity.principalId
- userIdentity.type
- userIdentity.userName
- userName
- user_access_key
- user_agent
- user_arn
- user_group_id
- user_id
- user_name
- user_type
- vendor
- vendor_account
- vendor_product
- vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId":
"AIDAYTOGP2RLCNEAQXWZV", "arn": "arn:aws:iam::111111111111:user/bhavin_console",
"accountId": "111111111111", "accessKeyId": "AKIAYTOGP2RLF5EAXXXX", "userName":
"bhavin_console"}, "eventTime": "2023-03-20T22:31:18Z", "eventSource": "ec2.amazonaws.com",
"eventName": "CreateSnapshot", "awsRegion": "us-west-2", "sourceIPAddress": "72.135.1.1",
"userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io)
terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws)
aws-sdk-go/1.44.157 (go1.19.3; darwin; amd64) stratus-red-team_46665bb8-dc15-4aba-a5ad-a362772b3f0d
HashiCorp-terraform-exec/0.17.3", "requestParameters": {"volumeId": "vol-0363e53e12f67c9b7",
"tagSpecificationSet": {"items": [{"resourceType": "snapshot", "tags": [{"key":
"StratusRedTeam", "value": "true"}]}]}}, "responseElements": {"requestId": "fefed928-d461-45f0-802f-a99d94c833a8",
"snapshotId": "snap-02effb3bb62786b18", "volumeId": "vol-0363e53e12f67c9b7", "status":
"pending", "startTime": 1679351478226, "ownerId": "111111111111", "volumeSize":
"1", "encrypted": false, "tagSet": {"items": [{"key": "StratusRedTeam", "value":
"true"}]}}, "requestID": "fefed928-d461-45f0-802f-a99d94c833a8", "eventID": "2d52d141-d1e6-4d1f-a380-1461c1bf9f83",
"readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId":
"111111111111", "eventCategory": "Management", "tlsDetails": {"tlsVersion": "TLSv1.2",
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256", "clientProvidedHostHeader": "ec2.us-west-2.amazonaws.com"}}'
+121
View File
@@ -0,0 +1,121 @@
name: AWS CloudTrail CreateTask
id: 6501e4fe-05b2-45f1-bd51-9e06a94fa7d9
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
description: Data source object for AWS CloudTrail CreateTask
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
supported_TA:
- name: Splunk Add-on for Amazon Web Services (AWS)
url: https://splunkbase.splunk.com/app/1876
version: 7.4.1
fields:
- _time
- app
- awsRegion
- aws_account_id
- command
- date_hour
- date_mday
- date_minute
- date_month
- date_second
- date_wday
- date_year
- date_zone
- dest
- dvc
- errorCode
- eventCategory
- eventID
- eventName
- eventSource
- eventTime
- eventType
- eventVersion
- eventtype
- host
- index
- linecount
- managementEvent
- msg
- object_category
- product
- punct
- readOnly
- recipientAccountId
- region
- requestID
- requestParameters.cloudWatchLogGroupArn
- requestParameters.destinationLocationArn
- requestParameters.options.logLevel
- requestParameters.options.verifyMode
- requestParameters.schedule.scheduleExpression
- requestParameters.sourceLocationArn
- responseElements.taskArn
- sessionCredentialFromConsole
- signature
- source
- sourceIPAddress
- sourcetype
- splunk_server
- src
- src_ip
- start_time
- tag
- tag::eventtype
- timeendpos
- timestartpos
- tlsDetails.cipherSuite
- tlsDetails.clientProvidedHostHeader
- tlsDetails.tlsVersion
- user
- userAgent
- userIdentity.accessKeyId
- userIdentity.accountId
- userIdentity.arn
- userIdentity.principalId
- userIdentity.sessionContext.attributes.creationDate
- userIdentity.sessionContext.attributes.mfaAuthenticated
- userIdentity.sessionContext.sessionIssuer.accountId
- userIdentity.sessionContext.sessionIssuer.arn
- userIdentity.sessionContext.sessionIssuer.principalId
- userIdentity.sessionContext.sessionIssuer.type
- userIdentity.sessionContext.sessionIssuer.userName
- userIdentity.type
- userName
- user_access_key
- user_agent
- user_arn
- user_group_id
- user_id
- user_name
- user_type
- vendor
- vendor_account
- vendor_product
- vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "principalId":
"AROAYTOGP2RLDF6WQQQQQ:abc@acme.com", "arn": "arn:aws:sts::111111111111:assumed-role/AWSReservedSSO_SPLKAdministratorAccess_d9ce1347d0a6dd3f/abc@acme.com",
"accountId": "111111111111", "accessKeyId": "ASIAYTOGP2RLOB2GM111", "sessionContext":
{"sessionIssuer": {"type": "Role", "principalId": "AROAYTOGP2RLDF6WQQQQQ", "arn":
"arn:aws:iam::111111111111:role/aws-reserved/sso.amazonaws.com/us-west-2/AWSReservedSSO_SPLKAdministratorAccess_d9ce1347d0a6dd3f",
"accountId": "111111111111", "userName": "AWSReservedSSO_SPLKAdministratorAccess_d9ce1347d0a6dd3f"},
"webIdFederationData": {}, "attributes": {"creationDate": "2023-03-14T21:53:15Z",
"mfaAuthenticated": "false"}}}, "eventTime": "2023-03-14T22:05:36Z", "eventSource":
"datasync.amazonaws.com", "eventName": "CreateTask", "awsRegion": "us-west-2", "sourceIPAddress":
"1.1.1.1", "userAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36
(KHTML, like Gecko) Chrome/111.0.0.0 Safari/537.36", "requestParameters": {"sourceLocationArn":
"arn:aws:datasync:us-west-2:111111111111:location/loc-0921d426f7955d416", "destinationLocationArn":
"arn:aws:datasync:us-west-1:111111111111:location/loc-0b94cf657c358ef06", "cloudWatchLogGroupArn":
"arn:aws:logs:us-west-2:111111111111:log-group:/aws/datasync", "options": {"verifyMode":
"ONLY_FILES_TRANSFERRED", "logLevel": "BASIC"}, "excludes": [], "schedule": {"scheduleExpression":
"cron(6 * * * ? *)"}, "tags": [], "includes": []}, "responseElements": {"taskArn":
"arn:aws:datasync:us-west-2:111111111111:task/task-0c77dc0d4b0792ce6"}, "requestID":
"de5f4282-aa2b-49b8-8d1b-c3bdb11e2fba", "eventID": "def4cd05-f845-4aec-bc96-07d6ce420d16",
"readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId":
"111111111111", "eventCategory": "Management", "tlsDetails": {"tlsVersion": "TLSv1.2",
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256", "clientProvidedHostHeader": "datasync.us-west-2.amazonaws.com"},
"sessionCredentialFromConsole": "true"}'
@@ -0,0 +1,100 @@
name: AWS CloudTrail CreateVirtualMFADevice
id: 13e6e952-0dad-4190-865c-fb5911725f7a
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
description: Data source object for AWS CloudTrail CreateVirtualMFADevice
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
supported_TA:
- name: Splunk Add-on for Amazon Web Services (AWS)
url: https://splunkbase.splunk.com/app/1876
version: 7.4.1
fields:
- _time
- action
- app
- awsRegion
- aws_account_id
- change_type
- command
- date_hour
- date_mday
- date_minute
- date_month
- date_second
- date_wday
- date_year
- date_zone
- dest
- dvc
- errorCode
- eventCategory
- eventID
- eventName
- eventSource
- eventTime
- eventType
- eventVersion
- eventtype
- host
- index
- linecount
- managementEvent
- msg
- object_category
- product
- punct
- readOnly
- recipientAccountId
- region
- requestID
- requestParameters.path
- requestParameters.virtualMFADeviceName
- responseElements.virtualMFADevice.serialNumber
- sessionCredentialFromConsole
- signature
- source
- sourceIPAddress
- sourcetype
- splunk_server
- src
- src_ip
- start_time
- status
- tag
- tag::eventtype
- timeendpos
- timestartpos
- user
- userAgent
- userIdentity.accessKeyId
- userIdentity.accountId
- userIdentity.arn
- userIdentity.principalId
- userIdentity.sessionContext.attributes.creationDate
- userIdentity.sessionContext.attributes.mfaAuthenticated
- userIdentity.type
- userName
- user_access_key
- user_agent
- user_arn
- user_group_id
- user_id
- user_type
- vendor
- vendor_account
- vendor_product
- vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "Root", "principalId":
"140429656527", "arn": "arn:aws:iam::140429656527:root", "accountId": "140429656527",
"accessKeyId": "ASIASBMSCQHH2YXNXJBU", "sessionContext": {"sessionIssuer": {}, "webIdFederationData":
{}, "attributes": {"creationDate": "2023-01-30T22:59:36Z", "mfaAuthenticated": "false"}}},
"eventTime": "2023-01-30T23:02:23Z", "eventSource": "iam.amazonaws.com", "eventName":
"CreateVirtualMFADevice", "awsRegion": "us-east-1", "sourceIPAddress": "23.93.193.6",
"userAgent": "AWS Internal", "requestParameters": {"path": "/", "virtualMFADeviceName":
"strt_mfa_2"}, "responseElements": {"virtualMFADevice": {"serialNumber": "arn:aws:iam::140429656527:mfa/strt_mfa_2"}},
"requestID": "2fbe2074-55f8-4ec6-ad32-0b250803cf46", "eventID": "7e1c493d-c3c3-4f4a-ae4f-8cdd38970027",
"readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId":
"140429656527", "eventCategory": "Management", "sessionCredentialFromConsole": "true"}'
@@ -0,0 +1,100 @@
name: AWS CloudTrail DeactivateMFADevice
id: 7397a10b-1150-4de9-8062-a96454ae53b2
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
description: Data source object for AWS CloudTrail DeactivateMFADevice
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
supported_TA:
- name: Splunk Add-on for Amazon Web Services (AWS)
url: https://splunkbase.splunk.com/app/1876
version: 7.4.1
fields:
- _time
- action
- app
- awsRegion
- aws_account_id
- change_type
- command
- date_hour
- date_mday
- date_minute
- date_month
- date_second
- date_wday
- date_year
- date_zone
- dest
- dvc
- errorCode
- eventCategory
- eventID
- eventName
- eventSource
- eventTime
- eventType
- eventVersion
- eventtype
- host
- index
- linecount
- managementEvent
- msg
- object_category
- product
- punct
- readOnly
- recipientAccountId
- region
- requestID
- requestParameters.serialNumber
- requestParameters.userName
- responseElements
- signature
- source
- sourceIPAddress
- sourcetype
- splunk_server
- src
- src_ip
- start_time
- status
- tag
- tag::eventtype
- timeendpos
- timestartpos
- user
- userAgent
- userIdentity.accessKeyId
- userIdentity.accountId
- userIdentity.arn
- userIdentity.principalId
- userIdentity.sessionContext.attributes.creationDate
- userIdentity.sessionContext.attributes.mfaAuthenticated
- userIdentity.type
- userName
- user_access_key
- user_agent
- user_arn
- user_group_id
- user_id
- user_name
- user_type
- vendor
- vendor_account
- vendor_product
- vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "Root", "principalId":
"111111111111", "arn": "arn:aws:iam::111111111111:root", "accountId": "111111111111",
"accessKeyId": "ASIASBMSCQHHWAIHMHUX", "sessionContext": {"sessionIssuer": {}, "webIdFederationData":
{}, "attributes": {"creationDate": "2022-10-04T16:13:23Z", "mfaAuthenticated": "true"}}},
"eventTime": "2022-10-04T16:13:45Z", "eventSource": "iam.amazonaws.com", "eventName":
"DeactivateMFADevice", "awsRegion": "us-east-1", "sourceIPAddress": "142.254.89.27",
"userAgent": "Coral/Netty4", "requestParameters": {"userName": "AWS ROOT USER",
"serialNumber": "arn:aws:iam::111111111111:mfa/root-account-mfa-device"}, "responseElements":
null, "requestID": "d27cfb15-34b4-4c16-82bc-a55d15b4e47d", "eventID": "bfe9fd91-0b4d-470a-9c03-77839151806d",
"readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId":
"111111111111", "eventCategory": "Management"}'
@@ -0,0 +1,100 @@
name: AWS CloudTrail DeleteAccountPasswordPolicy
id: b0730ac8-0992-4de8-b000-2c7d0fc7a67f
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
description: Data source object for AWS CloudTrail DeleteAccountPasswordPolicy
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
supported_TA:
- name: Splunk Add-on for Amazon Web Services (AWS)
url: https://splunkbase.splunk.com/app/1876
version: 7.4.1
fields:
- _time
- action
- app
- awsRegion
- aws_account_id
- change_type
- command
- date_hour
- date_mday
- date_minute
- date_month
- date_second
- date_wday
- date_year
- date_zone
- desc
- dest
- dvc
- errorCode
- eventCategory
- eventID
- eventName
- eventSource
- eventTime
- eventType
- eventVersion
- eventtype
- host
- index
- linecount
- managementEvent
- msg
- object_category
- product
- punct
- readOnly
- recipientAccountId
- region
- requestID
- requestParameters
- responseElements
- sessionCredentialFromConsole
- signature
- source
- sourceIPAddress
- sourcetype
- splunk_server
- src
- src_ip
- start_time
- status
- tag
- tag::eventtype
- timeendpos
- timestartpos
- user
- userAgent
- userIdentity.accessKeyId
- userIdentity.accountId
- userIdentity.arn
- userIdentity.principalId
- userIdentity.sessionContext.attributes.creationDate
- userIdentity.sessionContext.attributes.mfaAuthenticated
- userIdentity.type
- userName
- user_access_key
- user_agent
- user_arn
- user_group_id
- user_id
- user_name
- user_type
- vendor
- vendor_account
- vendor_product
- vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "Root", "principalId":
"111111111111", "arn": "arn:aws:iam::111111111111:root", "accountId": "111111111111",
"accessKeyId": "ASIASBMSCQHHWMDJXSE6", "sessionContext": {"sessionIssuer": {}, "webIdFederationData":
{}, "attributes": {"creationDate": "2023-01-26T18:44:21Z", "mfaAuthenticated": "false"}}},
"eventTime": "2023-01-26T21:23:22Z", "eventSource": "iam.amazonaws.com", "eventName":
"DeleteAccountPasswordPolicy", "awsRegion": "us-east-1", "sourceIPAddress": "23.93.193.7",
"userAgent": "AWS Internal", "requestParameters": null, "responseElements": null,
"requestID": "e3616938-1aac-4abd-9ea3-3b0367b85082", "eventID": "bbd8cb02-22ba-4d1b-b23d-b82975463376",
"readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId":
"111111111111", "eventCategory": "Management", "sessionCredentialFromConsole": "true"}'
@@ -0,0 +1,98 @@
name: AWS CloudTrail DeleteDetector
id: 5d8bd475-c8bc-4447-b27f-efa508728b90
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
description: Data source object for AWS CloudTrail DeleteDetector
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
supported_TA:
- name: Splunk Add-on for Amazon Web Services (AWS)
url: https://splunkbase.splunk.com/app/1876
version: 7.4.1
fields:
- _time
- app
- awsRegion
- aws_account_id
- command
- date_hour
- date_mday
- date_minute
- date_month
- date_second
- date_wday
- date_year
- date_zone
- dest
- dvc
- errorCode
- eventCategory
- eventID
- eventName
- eventSource
- eventTime
- eventType
- eventVersion
- eventtype
- host
- index
- linecount
- managementEvent
- msg
- object_category
- product
- punct
- readOnly
- recipientAccountId
- region
- requestID
- requestParameters.detectorId
- responseElements.__type
- responseElements.message
- result_id
- signature
- source
- sourceIPAddress
- sourcetype
- splunk_server
- src
- src_ip
- start_time
- tag
- tag::eventtype
- timeendpos
- timestartpos
- user
- userAgent
- userIdentity.accessKeyId
- userIdentity.accountId
- userIdentity.arn
- userIdentity.principalId
- userIdentity.type
- userIdentity.userName
- userName
- user_access_key
- user_agent
- user_arn
- user_group_id
- user_id
- user_name
- user_type
- vendor
- vendor_account
- vendor_product
- vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId":
"AIDAYTOGP2RLI4PXTGCEU", "arn": "arn:aws:iam::111111111111:user/gowthamaraj_cli",
"accountId": "111111111111", "accessKeyId": "AKIAYTOGP2RLFLKADUVG", "userName":
"gowthamaraj_cli"}, "eventTime": "2022-07-21T20:27:54Z", "eventSource": "guardduty.amazonaws.com",
"eventName": "DeleteDetector", "awsRegion": "us-west-2", "sourceIPAddress": "67.171.71.185",
"userAgent": "aws-cli/2.7.3 Python/3.9.13 Darwin/21.5.0 source/x86_64 prompt/off
command/guardduty.delete-detector", "errorCode": "BadRequestException", "requestParameters":
{"detectorId": "123"}, "responseElements": {"message": "The request is rejected
because the parameter detectorId has an invalid value.", "__type": "InvalidInputException"},
"requestID": "1e832076-d7a8-432b-b0df-54ba62f6b62c", "eventID": "c1367a2f-8910-4e64-9256-a854d2e9f37d",
"readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId":
"111111111111", "eventCategory": "Management"}'
+102
View File
@@ -0,0 +1,102 @@
name: AWS CloudTrail DeleteGroup
id: c95308a4-a943-42ca-b112-f90a05c21bd3
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
description: Data source object for AWS CloudTrail DeleteGroup
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
supported_TA:
- name: Splunk Add-on for Amazon Web Services (AWS)
url: https://splunkbase.splunk.com/app/1876
version: 7.4.1
fields:
- _time
- action
- app
- awsRegion
- aws_account_id
- change_type
- command
- date_hour
- date_mday
- date_minute
- date_month
- date_second
- date_wday
- date_year
- date_zone
- dest
- dvc
- errorCode
- errorMessage
- eventCategory
- eventID
- eventName
- eventSource
- eventTime
- eventType
- eventVersion
- eventtype
- host
- index
- linecount
- managementEvent
- msg
- object_category
- product
- punct
- readOnly
- reason
- recipientAccountId
- region
- requestID
- requestParameters.groupName
- responseElements
- result
- result_id
- signature
- source
- sourceIPAddress
- sourcetype
- splunk_server
- src
- src_ip
- start_time
- status
- tag
- tag::eventtype
- timeendpos
- timestartpos
- user
- userAgent
- userIdentity.accessKeyId
- userIdentity.accountId
- userIdentity.arn
- userIdentity.principalId
- userIdentity.type
- userIdentity.userName
- userName
- user_access_key
- user_agent
- user_arn
- user_group_id
- user_id
- user_name
- user_type
- vendor
- vendor_account
- vendor_product
- vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId":
"AIDAYTOGP2RLEHRX5YWNV", "arn": "arn:aws:iam::121522247101:user/bhavin_cli", "accountId":
"121522247101", "accessKeyId": "AKIAYTOGP2RLLAA6NJUM", "userName": "bhavin_cli"},
"eventTime": "2021-04-07T00:17:50Z", "eventSource": "iam.amazonaws.com", "eventName":
"DeleteGroup", "awsRegion": "us-east-1", "sourceIPAddress": "12.12.12.20", "userAgent":
"aws-cli/2.0.62 Python/3.9.2 Darwin/19.6.0 source/x86_64 command/iam.delete-group",
"errorCode": "NoSuchEntityException", "errorMessage": "The group with name AtomicRedTeam_Victim
cannot be found.", "requestParameters": {"groupName": "AtomicRedTeam_Victim"}, "responseElements":
null, "requestID": "15684d3b-a8c5-4334-a996-16619e901c17", "eventID": "ab65dca3-3d28-41f4-9f99-443606cc49fe",
"readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "eventCategory":
"Management", "recipientAccountId": "121522247101"}'
@@ -0,0 +1,99 @@
name: AWS CloudTrail DeleteIPSet
id: ebdeeb63-77a0-4808-a6fe-549956731377
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
description: Data source object for AWS CloudTrail DeleteIPSet
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
supported_TA:
- name: Splunk Add-on for Amazon Web Services (AWS)
url: https://splunkbase.splunk.com/app/1876
version: 7.4.1
fields:
- _time
- app
- awsRegion
- aws_account_id
- command
- date_hour
- date_mday
- date_minute
- date_month
- date_second
- date_wday
- date_year
- date_zone
- dest
- dvc
- errorCode
- eventCategory
- eventID
- eventName
- eventSource
- eventTime
- eventType
- eventVersion
- eventtype
- host
- index
- linecount
- managementEvent
- msg
- object_category
- product
- punct
- readOnly
- recipientAccountId
- region
- requestID
- requestParameters.detectorId
- requestParameters.ipSetId
- responseElements.__type
- responseElements.message
- result_id
- signature
- source
- sourceIPAddress
- sourcetype
- splunk_server
- src
- src_ip
- start_time
- tag
- tag::eventtype
- timeendpos
- timestartpos
- user
- userAgent
- userIdentity.accessKeyId
- userIdentity.accountId
- userIdentity.arn
- userIdentity.principalId
- userIdentity.type
- userIdentity.userName
- userName
- user_access_key
- user_agent
- user_arn
- user_group_id
- user_id
- user_name
- user_type
- vendor
- vendor_account
- vendor_product
- vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId":
"AIDAYTOGP2RLEHRX5YWNV", "arn": "arn:aws:iam::111111111111:user/bhavin_cli", "accountId":
"111111111111", "accessKeyId": "AKIAYTOGP2RLKQ3U2PDY", "userName": "bhavin_cli"},
"eventTime": "2022-07-26T23:14:57Z", "eventSource": "guardduty.amazonaws.com", "eventName":
"DeleteIPSet", "awsRegion": "us-west-2", "sourceIPAddress": "142.254.89.27", "userAgent":
"aws-cli/2.0.62 Python/3.9.2 Darwin/21.5.0 source/x86_64 command/guardduty.delete-ip-set",
"errorCode": "BadRequestException", "requestParameters": {"detectorId": "11111",
"ipSetId": "1111"}, "responseElements": {"message": "The request is rejected because
the parameter detectorId has an invalid value.", "__type": "InvalidInputException"},
"requestID": "70d36916-4ce7-4b6e-9226-9da47d58d554", "eventID": "884dc529-d98f-4529-bfa1-8cdd6c06d02f",
"readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId":
"111111111111", "eventCategory": "Management"}'
@@ -0,0 +1,100 @@
name: AWS CloudTrail DeleteLogGroup
id: 60cf6a69-fa43-4a6c-8808-e9fb46bf387f
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
description: Data source object for AWS CloudTrail DeleteLogGroup
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
supported_TA:
- name: Splunk Add-on for Amazon Web Services (AWS)
url: https://splunkbase.splunk.com/app/1876
version: 7.4.1
fields:
- _time
- apiVersion
- app
- awsRegion
- aws_account_id
- command
- date_hour
- date_mday
- date_minute
- date_month
- date_second
- date_wday
- date_year
- date_zone
- dest
- dvc
- errorCode
- eventCategory
- eventID
- eventName
- eventSource
- eventTime
- eventType
- eventVersion
- eventtype
- host
- index
- linecount
- managementEvent
- msg
- object_category
- product
- punct
- readOnly
- recipientAccountId
- region
- requestID
- requestParameters.logGroupName
- responseElements
- signature
- source
- sourceIPAddress
- sourcetype
- splunk_server
- src
- src_ip
- start_time
- tag
- tag::eventtype
- timeendpos
- timestartpos
- tlsDetails.cipherSuite
- tlsDetails.clientProvidedHostHeader
- tlsDetails.tlsVersion
- user
- userAgent
- userIdentity.accessKeyId
- userIdentity.accountId
- userIdentity.arn
- userIdentity.principalId
- userIdentity.type
- userIdentity.userName
- userName
- user_access_key
- user_agent
- user_arn
- user_group_id
- user_id
- user_name
- user_type
- vendor
- vendor_account
- vendor_product
- vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId":
"AIDAYTOGP2RLI4PXTGCEU", "arn": "arn:aws:iam::111111111111:user/gowthamaraj_cli",
"accountId": "111111111111", "accessKeyId": "AKIAYTOGP2RLFLKADUVG", "userName":
"gowthamaraj_cli"}, "eventTime": "2022-07-19T08:58:48Z", "eventSource": "logs.amazonaws.com",
"eventName": "DeleteLogGroup", "awsRegion": "us-west-2", "sourceIPAddress": "67.171.71.185",
"userAgent": "aws-cli/2.7.3 Python/3.9.13 Darwin/21.5.0 source/x86_64 prompt/off
command/logs.delete-log-group", "requestParameters": {"logGroupName": "test-logs"},
"responseElements": null, "requestID": "76089b03-d749-4f83-bc0e-b857c83bba5f", "eventID":
"5aba96c4-e7f9-4e4f-b5e6-49694162195d", "readOnly": false, "eventType": "AwsApiCall",
"apiVersion": "20140328", "managementEvent": true, "recipientAccountId": "111111111111",
"eventCategory": "Management", "tlsDetails": {"tlsVersion": "TLSv1.2", "cipherSuite":
"ECDHE-RSA-AES128-GCM-SHA256", "clientProvidedHostHeader": "logs.us-west-2.amazonaws.com"}}'
@@ -0,0 +1,101 @@
name: AWS CloudTrail DeleteLogStream
id: 6f8bb808-89f8-465e-a34d-229df2f46402
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
description: Data source object for AWS CloudTrail DeleteLogStream
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
supported_TA:
- name: Splunk Add-on for Amazon Web Services (AWS)
url: https://splunkbase.splunk.com/app/1876
version: 7.4.1
fields:
- _time
- apiVersion
- app
- awsRegion
- aws_account_id
- command
- date_hour
- date_mday
- date_minute
- date_month
- date_second
- date_wday
- date_year
- date_zone
- dest
- dvc
- errorCode
- eventCategory
- eventID
- eventName
- eventSource
- eventTime
- eventType
- eventVersion
- eventtype
- host
- index
- linecount
- managementEvent
- msg
- object_category
- product
- punct
- readOnly
- recipientAccountId
- region
- requestID
- requestParameters.logGroupName
- requestParameters.logStreamName
- responseElements
- signature
- source
- sourceIPAddress
- sourcetype
- splunk_server
- src
- src_ip
- start_time
- tag
- tag::eventtype
- timeendpos
- timestartpos
- tlsDetails.cipherSuite
- tlsDetails.clientProvidedHostHeader
- tlsDetails.tlsVersion
- user
- userAgent
- userIdentity.accessKeyId
- userIdentity.accountId
- userIdentity.arn
- userIdentity.principalId
- userIdentity.type
- userIdentity.userName
- userName
- user_access_key
- user_agent
- user_arn
- user_group_id
- user_id
- user_name
- user_type
- vendor
- vendor_account
- vendor_product
- vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId":
"AIDAYTOGP2RLI4PXTGCEU", "arn": "arn:aws:iam::111111111111:user/gowthamaraj_cli",
"accountId": "111111111111", "accessKeyId": "AKIAYTOGP2RLFLKADUVG", "userName":
"gowthamaraj_cli"}, "eventTime": "2022-07-20T21:09:51Z", "eventSource": "logs.amazonaws.com",
"eventName": "DeleteLogStream", "awsRegion": "us-west-2", "sourceIPAddress": "67.171.71.185",
"userAgent": "aws-cli/2.7.3 Python/3.9.13 Darwin/21.5.0 source/x86_64 prompt/off
command/logs.delete-log-stream", "requestParameters": {"logGroupName": "test-logs",
"logStreamName": "20150601"}, "responseElements": null, "requestID": "2d7e859e-d697-426f-8b56-c4c11c4055f3",
"eventID": "561c3f4e-17ca-4438-b15d-29903baf7b13", "readOnly": false, "eventType":
"AwsApiCall", "apiVersion": "20140328", "managementEvent": true, "recipientAccountId":
"111111111111", "eventCategory": "Management", "tlsDetails": {"tlsVersion": "TLSv1.2",
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256", "clientProvidedHostHeader": "logs.us-west-2.amazonaws.com"}}'
@@ -0,0 +1,110 @@
name: AWS CloudTrail DeleteNetworkAclEntry
id: a0dd0f10-cc03-425d-bd5a-e1e0d954b856
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
description: Data source object for AWS CloudTrail DeleteNetworkAclEntry
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
supported_TA:
- name: Splunk Add-on for Amazon Web Services (AWS)
url: https://splunkbase.splunk.com/app/1876
version: 7.4.1
fields:
- _time
- action
- app
- awsRegion
- aws_account_id
- change_type
- command
- date_hour
- date_mday
- date_minute
- date_month
- date_second
- date_wday
- date_year
- date_zone
- direction
- dvc
- errorCode
- eventCategory
- eventID
- eventName
- eventSource
- eventTime
- eventType
- eventVersion
- eventtype
- host
- index
- linecount
- managementEvent
- msg
- object_category
- product
- punct
- readOnly
- recipientAccountId
- region
- requestID
- requestParameters.egress
- requestParameters.networkAclId
- requestParameters.ruleNumber
- responseElements._return
- responseElements.requestId
- signature
- source
- sourceIPAddress
- sourcetype
- splunk_server
- src
- src_ip
- start_time
- status
- tag
- tag::eventtype
- timeendpos
- timestartpos
- user
- userAgent
- userIdentity.accessKeyId
- userIdentity.accountId
- userIdentity.arn
- userIdentity.principalId
- userIdentity.sessionContext.attributes.creationDate
- userIdentity.sessionContext.attributes.mfaAuthenticated
- userIdentity.sessionContext.sessionIssuer.accountId
- userIdentity.sessionContext.sessionIssuer.arn
- userIdentity.sessionContext.sessionIssuer.principalId
- userIdentity.sessionContext.sessionIssuer.type
- userIdentity.sessionContext.sessionIssuer.userName
- userIdentity.type
- userName
- user_access_key
- user_agent
- user_arn
- user_group_id
- user_id
- user_name
- user_type
- vendor
- vendor_account
- vendor_product
- vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "principalId":
"AROAIJIESMXKGCJRCTPR6:pbareiss@splunk.local", "arn": "arn:aws:sts::111111111111:assumed-role/okta_adm_role/pbareiss@splunk.local",
"accountId": "111111111111", "accessKeyId": "ASIAYTOGP2RLF3F7BXZK", "sessionContext":
{"sessionIssuer": {"type": "Role", "principalId": "AROAIJIESMXKGCJRCTPR6", "arn":
"arn:aws:iam::111111111111:role/okta_adm_role", "accountId": "111111111111", "userName":
"okta_adm_role"}, "webIdFederationData": {}, "attributes": {"mfaAuthenticated":
"false", "creationDate": "2021-01-12T08:36:15Z"}}}, "eventTime": "2021-01-12T09:26:26Z",
"eventSource": "ec2.amazonaws.com", "eventName": "DeleteNetworkAclEntry", "awsRegion":
"eu-central-1", "sourceIPAddress": "95.90.199.65", "userAgent": "console.ec2.amazonaws.com",
"requestParameters": {"networkAclId": "acl-078ccebebcbabe175", "ruleNumber": 40,
"egress": false}, "responseElements": {"requestId": "607474bb-836b-46be-be4a-351ebbef67d6",
"_return": true}, "requestID": "607474bb-836b-46be-be4a-351ebbef67d6", "eventID":
"b9e05770-e9b0-4ba1-91e8-6537097e06e7", "readOnly": false, "eventType": "AwsApiCall",
"managementEvent": true, "eventCategory": "Management", "recipientAccountId": "111111111111"}'
@@ -0,0 +1,102 @@
name: AWS CloudTrail DeletePolicy
id: d190d23a-2c59-4a0e-9c55-a53ebef28ee5
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
description: Data source object for AWS CloudTrail DeletePolicy
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
supported_TA:
- name: Splunk Add-on for Amazon Web Services (AWS)
url: https://splunkbase.splunk.com/app/1876
version: 7.4.1
fields:
- _time
- action
- app
- awsRegion
- aws_account_id
- change_type
- command
- date_hour
- date_mday
- date_minute
- date_month
- date_second
- date_wday
- date_year
- date_zone
- dest
- dvc
- errorCode
- errorMessage
- eventCategory
- eventID
- eventName
- eventSource
- eventTime
- eventType
- eventVersion
- eventtype
- host
- index
- linecount
- managementEvent
- msg
- object_category
- product
- punct
- readOnly
- reason
- recipientAccountId
- region
- requestID
- requestParameters.policyArn
- responseElements
- result
- result_id
- signature
- source
- sourceIPAddress
- sourcetype
- splunk_server
- src
- src_ip
- start_time
- status
- tag
- tag::eventtype
- timeendpos
- timestartpos
- user
- userAgent
- userIdentity.accessKeyId
- userIdentity.accountId
- userIdentity.arn
- userIdentity.principalId
- userIdentity.type
- userIdentity.userName
- userName
- user_access_key
- user_agent
- user_arn
- user_group_id
- user_id
- user_name
- user_type
- vendor
- vendor_account
- vendor_product
- vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId":
"AIDAYTOGP2RLEHRX5YWNV", "arn": "arn:aws:iam::151521547504:user/bhavin_cli", "accountId":
"151521547504", "accessKeyId": "AKIAYTOGP2RLLAA6NJUM", "userName": "bhavin_cli"},
"eventTime": "2021-04-02T18:01:00Z", "eventSource": "iam.amazonaws.com", "eventName":
"DeletePolicy", "awsRegion": "us-east-1", "sourceIPAddress": "61.25.42.212", "userAgent":
"aws-cli/2.0.62 Python/3.9.2 Darwin/19.6.0 source/x86_64 command/iam.delete-policy",
"errorCode": "NoSuchEntityException", "errorMessage": "Policy arn:aws:iam::151521547504:policy/AtomicRedTeam
was not found.", "requestParameters": {"policyArn": "arn:aws:iam::151521547504:policy/AtomicRedTeam"},
"responseElements": null, "requestID": "90cbe52f-e744-4bba-9f5c-1843c9ca1855", "eventID":
"abd071bf-0a38-4fab-af4a-5eee55f0935e", "readOnly": false, "eventType": "AwsApiCall",
"managementEvent": true, "eventCategory": "Management", "recipientAccountId": "151521547504"}'
+102
View File
@@ -0,0 +1,102 @@
name: AWS CloudTrail DeleteRule
id: b5760623-f3ca-492d-a372-d5c2b3567dfc
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
description: Data source object for AWS CloudTrail DeleteRule
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
supported_TA:
- name: Splunk Add-on for Amazon Web Services (AWS)
url: https://splunkbase.splunk.com/app/1876
version: 7.4.1
fields:
- _time
- apiVersion
- app
- awsRegion
- aws_account_id
- command
- date_hour
- date_mday
- date_minute
- date_month
- date_second
- date_wday
- date_year
- date_zone
- dest
- dvc
- errorCode
- eventCategory
- eventID
- eventName
- eventSource
- eventTime
- eventType
- eventVersion
- eventtype
- host
- index
- linecount
- managementEvent
- msg
- object_category
- product
- punct
- readOnly
- recipientAccountId
- region
- requestID
- requestParameters.changeToken
- requestParameters.ruleId
- responseElements.changeToken
- signature
- source
- sourceIPAddress
- sourcetype
- splunk_server
- src
- src_ip
- start_time
- tag
- tag::eventtype
- timeendpos
- timestartpos
- tlsDetails.cipherSuite
- tlsDetails.clientProvidedHostHeader
- tlsDetails.tlsVersion
- user
- userAgent
- userIdentity.accessKeyId
- userIdentity.accountId
- userIdentity.arn
- userIdentity.principalId
- userIdentity.type
- userIdentity.userName
- userName
- user_access_key
- user_agent
- user_arn
- user_group_id
- user_id
- user_name
- user_type
- vendor
- vendor_account
- vendor_product
- vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId":
"AIDAYTOGP2RLI4PXTGCEU", "arn": "arn:aws:iam::111111111111:user/gowthamaraj_cli",
"accountId": "111111111111", "accessKeyId": "AKIAYTOGP2RLFLKADUVG", "userName":
"gowthamaraj_cli"}, "eventTime": "2022-07-20T21:40:42Z", "eventSource": "waf.amazonaws.com",
"eventName": "DeleteRule", "awsRegion": "us-east-1", "sourceIPAddress": "67.171.71.185",
"userAgent": "aws-cli/2.7.3 Python/3.9.13 Darwin/21.5.0 source/x86_64 prompt/off
command/waf.delete-rule", "requestParameters": {"changeToken": "c5daf4cb-68e1-425f-b52d-49a32a7f187f",
"ruleId": "5a9b1c4a-a999-4bb2-9f51-555f086ff34f"}, "responseElements": {"changeToken":
"c5daf4cb-68e1-425f-b52d-49a32a7f187f"}, "requestID": "2089be3e-28ea-4349-b505-db72c81c272a",
"eventID": "0f815483-f6bb-42d9-b870-0dcc64ddc9a4", "readOnly": false, "eventType":
"AwsApiCall", "apiVersion": "2015-08-24", "managementEvent": true, "recipientAccountId":
"111111111111", "eventCategory": "Management", "tlsDetails": {"tlsVersion": "TLSv1.2",
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256", "clientProvidedHostHeader": "waf.amazonaws.com"}}'
@@ -0,0 +1,98 @@
name: AWS CloudTrail DeleteTrail
id: a5af09ff-07b6-4df6-92a0-2146bfe402c8
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
description: Data source object for AWS CloudTrail DeleteTrail
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
supported_TA:
- name: Splunk Add-on for Amazon Web Services (AWS)
url: https://splunkbase.splunk.com/app/1876
version: 7.4.1
fields:
- _time
- app
- awsRegion
- aws_account_id
- command
- date_hour
- date_mday
- date_minute
- date_month
- date_second
- date_wday
- date_year
- date_zone
- dest
- dvc
- errorCode
- eventCategory
- eventID
- eventName
- eventSource
- eventTime
- eventType
- eventVersion
- eventtype
- host
- index
- linecount
- managementEvent
- msg
- object_category
- product
- punct
- readOnly
- recipientAccountId
- region
- requestID
- requestParameters.name
- responseElements
- signature
- source
- sourceIPAddress
- sourcetype
- splunk_server
- src
- src_ip
- start_time
- tag
- tag::eventtype
- timeendpos
- timestartpos
- tlsDetails.cipherSuite
- tlsDetails.clientProvidedHostHeader
- tlsDetails.tlsVersion
- user
- userAgent
- userIdentity.accessKeyId
- userIdentity.accountId
- userIdentity.arn
- userIdentity.principalId
- userIdentity.type
- userIdentity.userName
- userName
- user_access_key
- user_agent
- user_arn
- user_group_id
- user_id
- user_name
- user_type
- vendor
- vendor_account
- vendor_product
- vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId":
"AIDAYTOGP2RLEHRX5YWNV", "arn": "arn:aws:iam::111111111111:user/bhavin_cli", "accountId":
"111111111111", "accessKeyId": "AKIAYTOGP2RLKQ3U2PDY", "userName": "bhavin_cli"},
"eventTime": "2022-07-13T19:03:51Z", "eventSource": "cloudtrail.amazonaws.com",
"eventName": "DeleteTrail", "awsRegion": "us-west-2", "sourceIPAddress": "192.184.242.57",
"userAgent": "aws-cli/2.0.62 Python/3.9.2 Darwin/21.5.0 source/x86_64 command/cloudtrail.delete-trail",
"requestParameters": {"name": "redatomictesttrail"}, "responseElements": null, "requestID":
"2ba0af54-1451-4a2c-846e-18436bcee01e", "eventID": "1c53bcce-650d-486a-b3f6-f64fd853e509",
"readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId":
"111111111111", "eventCategory": "Management", "tlsDetails": {"tlsVersion": "TLSv1.2",
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256", "clientProvidedHostHeader": "cloudtrail.us-west-2.amazonaws.com"}}'
@@ -0,0 +1,100 @@
name: AWS CloudTrail DeleteVirtualMFADevice
id: 84a08d6b-3d59-4260-8cab-84278ada262f
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
description: Data source object for AWS CloudTrail DeleteVirtualMFADevice
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
supported_TA:
- name: Splunk Add-on for Amazon Web Services (AWS)
url: https://splunkbase.splunk.com/app/1876
version: 7.4.1
fields:
- _time
- action
- app
- awsRegion
- aws_account_id
- change_type
- command
- date_hour
- date_mday
- date_minute
- date_month
- date_second
- date_wday
- date_year
- date_zone
- dest
- dvc
- errorCode
- eventCategory
- eventID
- eventName
- eventSource
- eventTime
- eventType
- eventVersion
- eventtype
- host
- index
- linecount
- managementEvent
- msg
- object_category
- product
- punct
- readOnly
- recipientAccountId
- region
- requestID
- requestParameters.serialNumber
- responseElements
- sessionCredentialFromConsole
- signature
- source
- sourceIPAddress
- sourcetype
- splunk_server
- src
- src_ip
- start_time
- status
- tag
- tag::eventtype
- timeendpos
- timestartpos
- user
- userAgent
- userIdentity.accessKeyId
- userIdentity.accountId
- userIdentity.arn
- userIdentity.principalId
- userIdentity.sessionContext.attributes.creationDate
- userIdentity.sessionContext.attributes.mfaAuthenticated
- userIdentity.type
- userName
- user_access_key
- user_agent
- user_arn
- user_group_id
- user_id
- user_name
- user_type
- vendor
- vendor_account
- vendor_product
- vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "Root", "principalId":
"111111111111", "arn": "arn:aws:iam::111111111111:root", "accountId": "111111111111",
"accessKeyId": "ASIASBMSCQHHWAIHMHUX", "sessionContext": {"sessionIssuer": {}, "webIdFederationData":
{}, "attributes": {"creationDate": "2022-10-04T16:13:23Z", "mfaAuthenticated": "true"}}},
"eventTime": "2022-10-04T16:13:46Z", "eventSource": "iam.amazonaws.com", "eventName":
"DeleteVirtualMFADevice", "awsRegion": "us-east-1", "sourceIPAddress": "AWS Internal",
"userAgent": "AWS Internal", "requestParameters": {"serialNumber": "arn:aws:iam::111111111111:mfa/root-account-mfa-device"},
"responseElements": null, "requestID": "5f192b01-d59d-4cee-8880-cc5cc6fd9b43", "eventID":
"01f0258f-b83f-4c0f-8fd3-380473840db8", "readOnly": false, "eventType": "AwsApiCall",
"managementEvent": true, "recipientAccountId": "111111111111", "eventCategory":
"Management", "sessionCredentialFromConsole": "true"}'
@@ -0,0 +1,102 @@
name: AWS CloudTrail DeleteWebACL
id: 90da5f08-7961-4c29-8de8-01364982aadf
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
description: Data source object for AWS CloudTrail DeleteWebACL
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
supported_TA:
- name: Splunk Add-on for Amazon Web Services (AWS)
url: https://splunkbase.splunk.com/app/1876
version: 7.4.1
fields:
- _time
- apiVersion
- app
- awsRegion
- aws_account_id
- command
- date_hour
- date_mday
- date_minute
- date_month
- date_second
- date_wday
- date_year
- date_zone
- dest
- dvc
- errorCode
- eventCategory
- eventID
- eventName
- eventSource
- eventTime
- eventType
- eventVersion
- eventtype
- host
- index
- linecount
- managementEvent
- msg
- object_category
- product
- punct
- readOnly
- recipientAccountId
- region
- requestID
- requestParameters.changeToken
- requestParameters.webACLId
- responseElements.changeToken
- signature
- source
- sourceIPAddress
- sourcetype
- splunk_server
- src
- src_ip
- start_time
- tag
- tag::eventtype
- timeendpos
- timestartpos
- tlsDetails.cipherSuite
- tlsDetails.clientProvidedHostHeader
- tlsDetails.tlsVersion
- user
- userAgent
- userIdentity.accessKeyId
- userIdentity.accountId
- userIdentity.arn
- userIdentity.principalId
- userIdentity.type
- userIdentity.userName
- userName
- user_access_key
- user_agent
- user_arn
- user_group_id
- user_id
- user_name
- user_type
- vendor
- vendor_account
- vendor_product
- vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId":
"AIDAYTOGP2RLI4PXTGCEU", "arn": "arn:aws:iam::111111111111:user/gowthamaraj_cli",
"accountId": "111111111111", "accessKeyId": "AKIAYTOGP2RLFLKADUVG", "userName":
"gowthamaraj_cli"}, "eventTime": "2022-07-20T21:32:54Z", "eventSource": "waf.amazonaws.com",
"eventName": "DeleteWebACL", "awsRegion": "us-east-1", "sourceIPAddress": "67.171.71.185",
"userAgent": "aws-cli/2.7.3 Python/3.9.13 Darwin/21.5.0 source/x86_64 prompt/off
command/waf.delete-web-acl", "requestParameters": {"changeToken": "11eb19d6-d960-4398-8761-6a8fbf8fc425",
"webACLId": "6a9771ff-7d94-4fec-a049-e42da0bc7347"}, "responseElements": {"changeToken":
"11eb19d6-d960-4398-8761-6a8fbf8fc425"}, "requestID": "55fd5189-5f86-4052-8e8e-993faf1753e8",
"eventID": "c8fd51ac-676d-4d5d-aa5a-7e642cf5bb97", "readOnly": false, "eventType":
"AwsApiCall", "apiVersion": "2015-08-24", "managementEvent": true, "recipientAccountId":
"111111111111", "eventCategory": "Management", "tlsDetails": {"tlsVersion": "TLSv1.2",
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256", "clientProvidedHostHeader": "waf.amazonaws.com"}}'
@@ -0,0 +1,97 @@
name: AWS CloudTrail DescribeEventAggregates
id: 7efe4afe-62ae-4f96-81d1-76598ea37fc2
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
description: Data source object for AWS CloudTrail DescribeEventAggregates
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
supported_TA:
- name: Splunk Add-on for Amazon Web Services (AWS)
url: https://splunkbase.splunk.com/app/1876
version: 7.4.1
fields:
- _time
- app
- awsRegion
- aws_account_id
- command
- date_hour
- date_mday
- date_minute
- date_month
- date_second
- date_wday
- date_year
- date_zone
- dest
- dvc
- errorCode
- eventCategory
- eventID
- eventName
- eventSource
- eventTime
- eventType
- eventVersion
- host
- index
- linecount
- managementEvent
- msg
- object_category
- product
- punct
- readOnly
- recipientAccountId
- region
- requestID
- requestParameters.aggregateField
- requestParameters.filter.eventStatusCodes{}
- requestParameters.filter.startTimes{}.from
- responseElements
- sessionCredentialFromConsole
- signature
- source
- sourceIPAddress
- sourcetype
- splunk_server
- src
- src_ip
- start_time
- timeendpos
- timestartpos
- user
- userAgent
- userIdentity.accessKeyId
- userIdentity.accountId
- userIdentity.arn
- userIdentity.principalId
- userIdentity.sessionContext.attributes.creationDate
- userIdentity.sessionContext.attributes.mfaAuthenticated
- userIdentity.type
- userName
- user_access_key
- user_agent
- user_arn
- user_group_id
- user_id
- user_name
- user_type
- vendor
- vendor_account
- vendor_product
- vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "Root", "principalId":
"140429656527", "arn": "arn:aws:iam::140429656527:root", "accountId": "140429656527",
"accessKeyId": "ASIASBMSCQHHQQ6LB24V", "sessionContext": {"sessionIssuer": {}, "webIdFederationData":
{}, "attributes": {"creationDate": "2023-01-31T21:58:17Z", "mfaAuthenticated": "true"}}},
"eventTime": "2023-02-01T02:52:34Z", "eventSource": "health.amazonaws.com", "eventName":
"DescribeEventAggregates", "awsRegion": "us-east-1", "sourceIPAddress": "54.188.0.152",
"userAgent": "AWS Internal", "requestParameters": {"aggregateField": "eventTypeCategory",
"filter": {"eventStatusCodes": ["open", "upcoming"], "startTimes": [{"from": "Jan
25, 2023 2:54:32 AM"}]}}, "responseElements": null, "requestID": "d6adf050-1d7a-4c25-9d48-0319e33f6f9a",
"eventID": "201cee69-61ab-4ffb-80b7-bd31e81e0d82", "readOnly": true, "eventType":
"AwsApiCall", "managementEvent": true, "recipientAccountId": "140429656527", "eventCategory":
"Management", "sessionCredentialFromConsole": "true"}'
@@ -0,0 +1,895 @@
name: AWS CloudTrail DescribeImageScanFindings
id: 688ea789-9ba2-4970-90a2-17e541e273c9
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
description: Data source object for AWS CloudTrail DescribeImageScanFindings
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
supported_TA:
- name: Splunk Add-on for Amazon Web Services (AWS)
url: https://splunkbase.splunk.com/app/1876
version: 7.4.1
fields:
- _time
- app
- awsRegion
- aws_account_id
- command
- date_hour
- date_mday
- date_minute
- date_month
- date_second
- date_wday
- date_year
- date_zone
- dest
- dvc
- errorCode
- eventCategory
- eventID
- eventName
- eventSource
- eventTime
- eventType
- eventVersion
- eventtype
- host
- index
- linecount
- managementEvent
- msg
- object_category
- product
- punct
- readOnly
- recipientAccountId
- region
- requestID
- requestParameters.imageId.imageDigest
- requestParameters.maxResults
- requestParameters.repositoryName
- responseElements.imageId.imageDigest
- responseElements.imageScanFindings.findingSeverityCounts.HIGH
- responseElements.imageScanFindings.findingSeverityCounts.INFORMATIONAL
- responseElements.imageScanFindings.findingSeverityCounts.LOW
- responseElements.imageScanFindings.findingSeverityCounts.MEDIUM
- responseElements.imageScanFindings.findingSeverityCounts.UNDEFINED
- responseElements.imageScanFindings.findings{}.attributes{}.key
- responseElements.imageScanFindings.findings{}.attributes{}.value
- responseElements.imageScanFindings.findings{}.description
- responseElements.imageScanFindings.findings{}.name
- responseElements.imageScanFindings.findings{}.severity
- responseElements.imageScanFindings.findings{}.uri
- responseElements.imageScanFindings.imageScanCompletedAt
- responseElements.imageScanFindings.vulnerabilitySourceUpdatedAt
- responseElements.imageScanStatus.description
- responseElements.imageScanStatus.status
- responseElements.registryId
- responseElements.repositoryName
- signature
- source
- sourceIPAddress
- sourcetype
- splunk_server
- src
- src_ip
- start_time
- tag
- tag::eventtype
- timeendpos
- timestartpos
- user
- userAgent
- userIdentity.accessKeyId
- userIdentity.accountId
- userIdentity.arn
- userIdentity.principalId
- userIdentity.sessionContext.attributes.creationDate
- userIdentity.sessionContext.attributes.mfaAuthenticated
- userIdentity.sessionContext.sessionIssuer.accountId
- userIdentity.sessionContext.sessionIssuer.arn
- userIdentity.sessionContext.sessionIssuer.principalId
- userIdentity.sessionContext.sessionIssuer.type
- userIdentity.sessionContext.sessionIssuer.userName
- userIdentity.type
- userName
- user_access_key
- user_agent
- user_arn
- user_group_id
- user_id
- user_name
- user_type
- vendor
- vendor_account
- vendor_product
- vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "principalId":
"AAAAAAAAAAAAAAAAAAAAA:test@test.com", "arn": "arn:aws:sts::111111111111:assumed-role/role_name/test@test.com",
"accountId": "111111111111", "accessKeyId": "AKIAIOSFODNN7EXAMPLE", "sessionContext":
{"sessionIssuer": {"type": "Role", "principalId": "AKIAIOSFODNN7EXAMPLE", "arn":
"arn:aws:iam::111111111111:role/aws-reserved/test/region/group", "accountId": "111111111111",
"userName": "test"}, "webIdFederationData": {}, "attributes": {"creationDate": "2021-08-11T09:42:53Z",
"mfaAuthenticated": "false"}}}, "eventTime": "2021-08-11T11:52:27Z", "eventSource":
"ecr.amazonaws.com", "eventName": "DescribeImageScanFindings", "awsRegion": "eu-central-1",
"sourceIPAddress": "154.16.165.133", "userAgent": "aws-internal/3 aws-sdk-java/1.11.1030
Linux/4.9.273-0.1.ac.226.84.332.metal1.x86_64 OpenJDK_64-Bit_Server_VM/25.302-b08
java/1.8.0_302 vendor/Oracle_Corporation cfg/retry-mode/legacy", "requestParameters":
{"repositoryName": "devsecops/cat_dog_client", "imageId": {"imageDigest": "sha256:a27d73188718a511a1ec1ec788826674b21e097f29873dde734a4dedfbfab1c6"},
"maxResults": 1000}, "responseElements": {"registryId": "111111111111", "repositoryName":
"devsecops/cat_dog_client", "imageId": {"imageDigest": "sha256:a27d73188718a511a1ec1ec788826674b21e097f29873dde734a4dedfbfab1c6"},
"imageScanStatus": {"status": "COMPLETE", "description": "The scan was completed
successfully."}, "imageScanFindings": {"imageScanCompletedAt": "Aug 11, 2021, 11:30:16
AM", "vulnerabilitySourceUpdatedAt": "Aug 11, 2021, 1:17:52 AM", "findings": [{"name":
"CVE-2019-25013", "description": "The iconv feature in the GNU C Library (aka glibc
or libc6) through 2.32, when processing invalid multi-byte input sequences in the
EUC-KR encoding, may have a buffer over-read.", "uri": "https://security-tracker.debian.org/tracker/CVE-2019-25013",
"severity": "HIGH", "attributes": [{"key": "package_version", "value": "2.28-10"},
{"key": "package_name", "value": "glibc"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:N/I:N/A:C"},
{"key": "CVSS2_SCORE", "value": "7.1"}]}, {"name": "CVE-2021-33574", "description":
"The mq_notify function in the GNU C Library (aka glibc) versions 2.32 and 2.33
has a use-after-free. It may use the notification thread attributes object (passed
through its struct sigevent parameter) after it has been freed by the caller, leading
to a denial of service (application crash) or possibly unspecified other impact.",
"uri": "https://security-tracker.debian.org/tracker/CVE-2021-33574", "severity":
"HIGH", "attributes": [{"key": "package_version", "value": "2.28-10"}, {"key": "package_name",
"value": "glibc"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:L/Au:N/C:P/I:P/A:P"},
{"key": "CVSS2_SCORE", "value": "7.5"}]}, {"name": "CVE-2018-12886", "description":
"stack_protect_prologue in cfgexpand.c and stack_protect_epilogue in function.c
in GNU Compiler Collection (GCC) 4.1 through 8 (under certain circumstances) generate
instruction sequences when targeting ARM targets that spill the address of the stack
protector guard, which allows an attacker to bypass the protection of -fstack-protector,
-fstack-protector-all, -fstack-protector-strong, and -fstack-protector-explicit
against stack overflow by controlling what the stack canary is compared against.",
"uri": "https://security-tracker.debian.org/tracker/CVE-2018-12886", "severity":
"MEDIUM", "attributes": [{"key": "package_version", "value": "8.3.0-6"}, {"key":
"package_name", "value": "gcc-8"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:P/I:P/A:P"},
{"key": "CVSS2_SCORE", "value": "6.8"}]}, {"name": "CVE-2020-1751", "description":
"An out-of-bounds write vulnerability was found in glibc before 2.31 when handling
signal trampolines on PowerPC. Specifically, the backtrace function did not properly
check the array bounds when storing the frame address, resulting in a denial of
service or potential code execution. The highest threat from this vulnerability
is to system availability.", "uri": "https://security-tracker.debian.org/tracker/CVE-2020-1751",
"severity": "MEDIUM", "attributes": [{"key": "package_version", "value": "2.28-10"},
{"key": "package_name", "value": "glibc"}, {"key": "CVSS2_VECTOR", "value": "AV:L/AC:M/Au:N/C:P/I:P/A:C"},
{"key": "CVSS2_SCORE", "value": "5.9"}]}, {"name": "CVE-2021-3326", "description":
"The iconv function in the GNU C Library (aka glibc or libc6) 2.32 and earlier,
when processing invalid input sequences in the ISO-2022-JP-3 encoding, fails an
assertion in the code path and aborts the program, potentially resulting in a denial
of service.", "uri": "https://security-tracker.debian.org/tracker/CVE-2021-3326",
"severity": "MEDIUM", "attributes": [{"key": "package_version", "value": "2.28-10"},
{"key": "package_name", "value": "glibc"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:L/Au:N/C:N/I:N/A:P"},
{"key": "CVSS2_SCORE", "value": "5"}]}, {"name": "CVE-2021-35942", "description":
"The wordexp function in the GNU C Library (aka glibc) through 2.33 may crash or
read arbitrary memory in parse_param (in posix/wordexp.c) when called with an untrusted,
crafted pattern, potentially resulting in a denial of service or disclosure of information.
This occurs because atoi was used but strtoul should have been used to ensure correct
calculations.", "uri": "https://security-tracker.debian.org/tracker/CVE-2021-35942",
"severity": "MEDIUM", "attributes": [{"key": "package_version", "value": "2.28-10"},
{"key": "package_name", "value": "glibc"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:L/Au:N/C:P/I:N/A:P"},
{"key": "CVSS2_SCORE", "value": "6.4"}]}, {"name": "CVE-2019-12904", "description":
"In Libgcrypt 1.8.4, the C implementation of AES is vulnerable to a flush-and-reload
side-channel attack because physical addresses are available to other processes.
(The C implementation is used on platforms where an assembly-language implementation
is unavailable.)", "uri": "https://security-tracker.debian.org/tracker/CVE-2019-12904",
"severity": "MEDIUM", "attributes": [{"key": "package_version", "value": "1.8.4-5+deb10u1"},
{"key": "package_name", "value": "libgcrypt20"}, {"key": "CVSS2_VECTOR", "value":
"AV:N/AC:M/Au:N/C:P/I:N/A:N"}, {"key": "CVSS2_SCORE", "value": "4.3"}]}, {"name":
"CVE-2017-6363", "description": "** DISPUTED ** In the GD Graphics Library (aka
LibGD) through 2.2.5, there is a heap-based buffer over-read in tiffWriter in gd_tiff.c.
NOTE: the vendor says \"In my opinion this issue should not have a CVE, since the
GD and GD2 formats are documented to be ''obsolete, and should only be used for
development and testing purposes.''\"", "uri": "https://security-tracker.debian.org/tracker/CVE-2017-6363",
"severity": "MEDIUM", "attributes": [{"key": "package_version", "value": "2.2.5-5.2"},
{"key": "package_name", "value": "libgd2"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:P/I:N/A:P"},
{"key": "CVSS2_SCORE", "value": "5.8"}]}, {"name": "CVE-2019-12290", "description":
"GNU libidn2 before 2.2.0 fails to perform the roundtrip checks specified in RFC3490
Section 4.2 when converting A-labels to U-labels. This makes it possible in some
circumstances for one domain to impersonate another. By creating a malicious domain
that matches a target domain except for the inclusion of certain punycoded Unicode
characters (that would be discarded when converted first to a Unicode label and
then back to an ASCII label), arbitrary domains can be impersonated.", "uri": "https://security-tracker.debian.org/tracker/CVE-2019-12290",
"severity": "MEDIUM", "attributes": [{"key": "package_version", "value": "2.0.5-1+deb10u1"},
{"key": "package_name", "value": "libidn2"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:L/Au:N/C:N/I:P/A:N"},
{"key": "CVSS2_SCORE", "value": "5"}]}, {"name": "CVE-2019-13115", "description":
"In libssh2 before 1.9.0, kex_method_diffie_hellman_group_exchange_sha256_key_exchange
in kex.c has an integer overflow that could lead to an out-of-bounds read in the
way packets are read from the server. A remote attacker who compromises a SSH server
may be able to disclose sensitive information or cause a denial of service condition
on the client system when a user connects to the server. This is related to an _libssh2_check_length
mistake, and is different from the various issues fixed in 1.8.1, such as CVE-2019-3855.",
"uri": "https://security-tracker.debian.org/tracker/CVE-2019-13115", "severity":
"MEDIUM", "attributes": [{"key": "package_version", "value": "1.8.0-2.1"}, {"key":
"package_name", "value": "libssh2"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:P/I:N/A:P"},
{"key": "CVSS2_SCORE", "value": "5.8"}]}, {"name": "CVE-2016-9318", "description":
"libxml2 2.9.4 and earlier, as used in XMLSec 1.2.23 and earlier and other products,
does not offer a flag directly indicating that the current document may be read
but other files may not be opened, which makes it easier for remote attackers to
conduct XML External Entity (XXE) attacks via a crafted document.", "uri": "https://security-tracker.debian.org/tracker/CVE-2016-9318",
"severity": "MEDIUM", "attributes": [{"key": "package_version", "value": "2.9.4+dfsg1-7+deb10u2"},
{"key": "package_name", "value": "libxml2"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:P/I:N/A:N"},
{"key": "CVSS2_SCORE", "value": "4.3"}]}, {"name": "CVE-2017-16932", "description":
"parser.c in libxml2 before 2.9.5 does not prevent infinite recursion in parameter
entities.", "uri": "https://security-tracker.debian.org/tracker/CVE-2017-16932",
"severity": "MEDIUM", "attributes": [{"key": "package_version", "value": "2.9.4+dfsg1-7+deb10u2"},
{"key": "package_name", "value": "libxml2"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:L/Au:N/C:N/I:N/A:P"},
{"key": "CVSS2_SCORE", "value": "5"}]}, {"name": "CVE-2020-36309", "description":
"ngx_http_lua_module (aka lua-nginx-module) before 0.10.16 in OpenResty allows unsafe
characters in an argument when using the API to mutate a URI, or a request or response
header.", "uri": "https://security-tracker.debian.org/tracker/CVE-2020-36309", "severity":
"MEDIUM", "attributes": [{"key": "package_version", "value": "1.21.1-1~buster"},
{"key": "package_name", "value": "nginx"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:L/Au:N/C:N/I:P/A:N"},
{"key": "CVSS2_SCORE", "value": "5"}]}, {"name": "CVE-2020-14155", "description":
"libpcre in PCRE before 8.44 allows an integer overflow via a large number after
a (?C substring.", "uri": "https://security-tracker.debian.org/tracker/CVE-2020-14155",
"severity": "MEDIUM", "attributes": [{"key": "package_version", "value": "2:8.39-12"},
{"key": "package_name", "value": "pcre3"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:L/Au:N/C:N/I:N/A:P"},
{"key": "CVSS2_SCORE", "value": "5"}]}, {"name": "CVE-2019-3843", "description":
"It was discovered that a systemd service that uses DynamicUser property can create
a SUID/SGID binary that would be allowed to run as the transient service UID/GID
even after the service is terminated. A local attacker may use this flaw to access
resources that will be owned by a potentially different service in the future, when
the UID/GID will be recycled.", "uri": "https://security-tracker.debian.org/tracker/CVE-2019-3843",
"severity": "MEDIUM", "attributes": [{"key": "package_version", "value": "241-7~deb10u8"},
{"key": "package_name", "value": "systemd"}, {"key": "CVSS2_VECTOR", "value": "AV:L/AC:L/Au:N/C:P/I:P/A:P"},
{"key": "CVSS2_SCORE", "value": "4.6"}]}, {"name": "CVE-2019-3844", "description":
"It was discovered that a systemd service that uses DynamicUser property can get
new privileges through the execution of SUID binaries, which would allow to create
binaries owned by the service transient group with the setgid bit set. A local attacker
may use this flaw to access resources that will be owned by a potentially different
service in the future, when the GID will be recycled.", "uri": "https://security-tracker.debian.org/tracker/CVE-2019-3844",
"severity": "MEDIUM", "attributes": [{"key": "package_version", "value": "241-7~deb10u8"},
{"key": "package_name", "value": "systemd"}, {"key": "CVSS2_VECTOR", "value": "AV:L/AC:L/Au:N/C:P/I:P/A:P"},
{"key": "CVSS2_SCORE", "value": "4.6"}]}, {"name": "CVE-2016-2781", "description":
"chroot in GNU coreutils, when used with --userspec, allows local users to escape
to the parent session via a crafted TIOCSTI ioctl call, which pushes characters
to the terminal''s input buffer.", "uri": "https://security-tracker.debian.org/tracker/CVE-2016-2781",
"severity": "LOW", "attributes": [{"key": "package_version", "value": "8.30-3"},
{"key": "package_name", "value": "coreutils"}, {"key": "CVSS2_VECTOR", "value":
"AV:L/AC:L/Au:N/C:N/I:P/A:N"}, {"key": "CVSS2_SCORE", "value": "2.1"}]}, {"name":
"CVE-2021-22898", "description": "curl 7.7 through 7.76.1 suffers from an information
disclosure when the `-t` command line option, known as `CURLOPT_TELNETOPTIONS` in
libcurl, is used to send variable=content pairs to TELNET servers. Due to a flaw
in the option parser for sending NEW_ENV variables, libcurl could be made to pass
on uninitialized data from a stack based buffer to the server, resulting in potentially
revealing sensitive internal information to the server using a clear-text network
protocol.", "uri": "https://security-tracker.debian.org/tracker/CVE-2021-22898",
"severity": "LOW", "attributes": [{"key": "package_version", "value": "7.64.0-4+deb10u2"},
{"key": "package_name", "value": "curl"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:H/Au:N/C:P/I:N/A:N"},
{"key": "CVSS2_SCORE", "value": "2.6"}]}, {"name": "CVE-2019-15847", "description":
"The POWER9 backend in GNU Compiler Collection (GCC) before version 10 could optimize
multiple calls of the __builtin_darn intrinsic into a single call, thus reducing
the entropy of the random number generator. This occurred because a volatile operation
was not specified. For example, within a single execution of a program, the output
of every __builtin_darn() call may be the same.", "uri": "https://security-tracker.debian.org/tracker/CVE-2019-15847",
"severity": "LOW", "attributes": [{"key": "package_version", "value": "8.3.0-6"},
{"key": "package_name", "value": "gcc-8"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:L/Au:N/C:P/I:N/A:N"},
{"key": "CVSS2_SCORE", "value": "5"}]}, {"name": "CVE-2020-1752", "description":
"A use-after-free vulnerability introduced in glibc upstream version 2.14 was found
in the way the tilde expansion was carried out. Directory paths containing an initial
tilde followed by a valid username were affected by this issue. A local attacker
could exploit this flaw by creating a specially crafted path that, when processed
by the glob function, would potentially lead to arbitrary code execution. This was
fixed in version 2.32.", "uri": "https://security-tracker.debian.org/tracker/CVE-2020-1752",
"severity": "LOW", "attributes": [{"key": "package_version", "value": "2.28-10"},
{"key": "package_name", "value": "glibc"}, {"key": "CVSS2_VECTOR", "value": "AV:L/AC:H/Au:N/C:P/I:P/A:P"},
{"key": "CVSS2_SCORE", "value": "3.7"}]}, {"name": "CVE-2020-6096", "description":
"An exploitable signed comparison vulnerability exists in the ARMv7 memcpy() implementation
of GNU glibc 2.30.9000. Calling memcpy() (on ARMv7 targets that utilize the GNU
glibc implementation) with a negative value for the ''num'' parameter results in
a signed comparison vulnerability. If an attacker underflows the ''num'' parameter
to memcpy(), this vulnerability could lead to undefined behavior such as writing
to out-of-bounds memory and potentially remote code execution. Furthermore, this
memcpy() implementation allows for program execution to continue in scenarios where
a segmentation fault or crash should have occurred. The dangers occur in that subsequent
execution and iterations of this code will be executed with this corrupted data.",
"uri": "https://security-tracker.debian.org/tracker/CVE-2020-6096", "severity":
"LOW", "attributes": [{"key": "package_version", "value": "2.28-10"}, {"key": "package_name",
"value": "glibc"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:P/I:P/A:P"},
{"key": "CVSS2_SCORE", "value": "6.8"}]}, {"name": "CVE-2020-10029", "description":
"The GNU C Library (aka glibc or libc6) before 2.32 could overflow an on-stack buffer
during range reduction if an input to an 80-bit long double function contains a
non-canonical bit pattern, a seen when passing a 0x5d414141414141410000 value to
sinl on x86 targets. This is related to sysdeps/ieee754/ldbl-96/e_rem_pio2l.c.",
"uri": "https://security-tracker.debian.org/tracker/CVE-2020-10029", "severity":
"LOW", "attributes": [{"key": "package_version", "value": "2.28-10"}, {"key": "package_name",
"value": "glibc"}, {"key": "CVSS2_VECTOR", "value": "AV:L/AC:L/Au:N/C:N/I:N/A:P"},
{"key": "CVSS2_SCORE", "value": "2.1"}]}, {"name": "CVE-2020-27618", "description":
"The iconv function in the GNU C Library (aka glibc or libc6) 2.32 and earlier,
when processing invalid multi-byte input sequences in IBM1364, IBM1371, IBM1388,
IBM1390, and IBM1399 encodings, fails to advance the input state, which could lead
to an infinite loop in applications, resulting in a denial of service, a different
vulnerability from CVE-2016-10228.", "uri": "https://security-tracker.debian.org/tracker/CVE-2020-27618",
"severity": "LOW", "attributes": [{"key": "package_version", "value": "2.28-10"},
{"key": "package_name", "value": "glibc"}, {"key": "CVSS2_VECTOR", "value": "AV:L/AC:L/Au:N/C:N/I:N/A:P"},
{"key": "CVSS2_SCORE", "value": "2.1"}]}, {"name": "CVE-2016-10228", "description":
"The iconv program in the GNU C Library (aka glibc or libc6) 2.31 and earlier, when
invoked with multiple suffixes in the destination encoding (TRANSLATE or IGNORE)
along with the -c option, enters an infinite loop when processing invalid multi-byte
input sequences, leading to a denial of service.", "uri": "https://security-tracker.debian.org/tracker/CVE-2016-10228",
"severity": "LOW", "attributes": [{"key": "package_version", "value": "2.28-10"},
{"key": "package_name", "value": "glibc"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:N/I:N/A:P"},
{"key": "CVSS2_SCORE", "value": "4.3"}]}, {"name": "CVE-2019-19126", "description":
"On the x86-64 architecture, the GNU C Library (aka glibc) before 2.31 fails to
ignore the LD_PREFER_MAP_32BIT_EXEC environment variable during program execution
after a security transition, allowing local attackers to restrict the possible mapping
addresses for loaded libraries and thus bypass ASLR for a setuid program.", "uri":
"https://security-tracker.debian.org/tracker/CVE-2019-19126", "severity": "LOW",
"attributes": [{"key": "package_version", "value": "2.28-10"}, {"key": "package_name",
"value": "glibc"}, {"key": "CVSS2_VECTOR", "value": "AV:L/AC:L/Au:N/C:P/I:N/A:N"},
{"key": "CVSS2_SCORE", "value": "2.1"}]}, {"name": "CVE-2021-27645", "description":
"The nameserver caching daemon (nscd) in the GNU C Library (aka glibc or libc6)
2.29 through 2.33, when processing a request for netgroup lookup, may crash due
to a double-free, potentially resulting in degraded service or Denial of Service
on the local system. This is related to netgroupcache.c.", "uri": "https://security-tracker.debian.org/tracker/CVE-2021-27645",
"severity": "LOW", "attributes": [{"key": "package_version", "value": "2.28-10"},
{"key": "package_name", "value": "glibc"}, {"key": "CVSS2_VECTOR", "value": "AV:L/AC:M/Au:N/C:N/I:N/A:P"},
{"key": "CVSS2_SCORE", "value": "1.9"}]}, {"name": "CVE-2019-14855", "description":
"A flaw was found in the way certificate signatures could be forged using collisions
found in the SHA-1 algorithm. An attacker could use this weakness to create forged
certificate signatures. This issue affects GnuPG versions before 2.2.18.", "uri":
"https://security-tracker.debian.org/tracker/CVE-2019-14855", "severity": "LOW",
"attributes": [{"key": "package_version", "value": "2.2.12-1+deb10u1"}, {"key":
"package_name", "value": "gnupg2"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:L/Au:N/C:P/I:N/A:N"},
{"key": "CVSS2_SCORE", "value": "5"}]}, {"name": "CVE-2019-13627", "description":
"It was discovered that there was a ECDSA timing attack in the libgcrypt20 cryptographic
library. Version affected: 1.8.4-5, 1.7.6-2+deb9u3, and 1.6.3-2+deb8u4. Versions
fixed: 1.8.5-2 and 1.6.3-2+deb8u7.", "uri": "https://security-tracker.debian.org/tracker/CVE-2019-13627",
"severity": "LOW", "attributes": [{"key": "package_version", "value": "1.8.4-5+deb10u1"},
{"key": "package_name", "value": "libgcrypt20"}, {"key": "CVSS2_VECTOR", "value":
"AV:L/AC:H/Au:N/C:P/I:P/A:N"}, {"key": "CVSS2_SCORE", "value": "2.6"}]}, {"name":
"CVE-2018-14553", "description": "gdImageClone in gd.c in libgd 2.1.0-rc2 through
2.2.5 has a NULL pointer dereference allowing attackers to crash an application
via a specific function call sequence. Only affects PHP when linked with an external
libgd (not bundled).", "uri": "https://security-tracker.debian.org/tracker/CVE-2018-14553",
"severity": "LOW", "attributes": [{"key": "package_version", "value": "2.2.5-5.2"},
{"key": "package_name", "value": "libgd2"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:L/Au:N/C:N/I:N/A:P"},
{"key": "CVSS2_SCORE", "value": "5"}]}, {"name": "CVE-2021-36086", "description":
"The CIL compiler in SELinux 3.2 has a use-after-free in cil_reset_classpermission
(called from cil_reset_classperms_set and cil_reset_classperms_list).", "uri": "https://security-tracker.debian.org/tracker/CVE-2021-36086",
"severity": "LOW", "attributes": [{"key": "package_version", "value": "2.8-1"},
{"key": "package_name", "value": "libsepol"}, {"key": "CVSS2_VECTOR", "value": "AV:L/AC:L/Au:N/C:N/I:N/A:P"},
{"key": "CVSS2_SCORE", "value": "2.1"}]}, {"name": "CVE-2021-36085", "description":
"The CIL compiler in SELinux 3.2 has a use-after-free in __cil_verify_classperms
(called from __verify_map_perm_classperms and hashtab_map).", "uri": "https://security-tracker.debian.org/tracker/CVE-2021-36085",
"severity": "LOW", "attributes": [{"key": "package_version", "value": "2.8-1"},
{"key": "package_name", "value": "libsepol"}, {"key": "CVSS2_VECTOR", "value": "AV:L/AC:L/Au:N/C:N/I:N/A:P"},
{"key": "CVSS2_SCORE", "value": "2.1"}]}, {"name": "CVE-2021-36087", "description":
"The CIL compiler in SELinux 3.2 has a heap-based buffer over-read in ebitmap_match_any
(called indirectly from cil_check_neverallow). This occurs because there is sometimes
a lack of checks for invalid statements in an optional block.", "uri": "https://security-tracker.debian.org/tracker/CVE-2021-36087",
"severity": "LOW", "attributes": [{"key": "package_version", "value": "2.8-1"},
{"key": "package_name", "value": "libsepol"}, {"key": "CVSS2_VECTOR", "value": "AV:L/AC:L/Au:N/C:N/I:N/A:P"},
{"key": "CVSS2_SCORE", "value": "2.1"}]}, {"name": "CVE-2021-36084", "description":
"The CIL compiler in SELinux 3.2 has a use-after-free in __cil_verify_classperms
(called from __cil_verify_classpermission and __cil_pre_verify_helper).", "uri":
"https://security-tracker.debian.org/tracker/CVE-2021-36084", "severity": "LOW",
"attributes": [{"key": "package_version", "value": "2.8-1"}, {"key": "package_name",
"value": "libsepol"}, {"key": "CVSS2_VECTOR", "value": "AV:L/AC:L/Au:N/C:N/I:N/A:P"},
{"key": "CVSS2_SCORE", "value": "2.1"}]}, {"name": "CVE-2019-17498", "description":
"In libssh2 v1.9.0 and earlier versions, the SSH_MSG_DISCONNECT logic in packet.c
has an integer overflow in a bounds check, enabling an attacker to specify an arbitrary
(out-of-bounds) offset for a subsequent memory read. A crafted SSH server may be
able to disclose sensitive information or cause a denial of service condition on
the client system when a user connects to the server.", "uri": "https://security-tracker.debian.org/tracker/CVE-2019-17498",
"severity": "LOW", "attributes": [{"key": "package_version", "value": "1.8.0-2.1"},
{"key": "package_name", "value": "libssh2"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:P/I:N/A:P"},
{"key": "CVSS2_SCORE", "value": "5.8"}]}, {"name": "CVE-2019-17543", "description":
"LZ4 before 1.9.2 has a heap-based buffer overflow in LZ4_write32 (related to LZ4_compress_destSize),
affecting applications that call LZ4_compress_fast with a large input. (This issue
can also lead to data corruption.) NOTE: the vendor states \"only a few specific
/ uncommon usages of the API are at risk.\"", "uri": "https://security-tracker.debian.org/tracker/CVE-2019-17543",
"severity": "LOW", "attributes": [{"key": "package_version", "value": "1.8.3-1+deb10u1"},
{"key": "package_name", "value": "lz4"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:P/I:P/A:P"},
{"key": "CVSS2_SCORE", "value": "6.8"}]}, {"name": "CVE-2013-0337", "description":
"The default configuration of nginx, possibly 1.3.13 and earlier, uses world-readable
permissions for the (1) access.log and (2) error.log files, which allows local users
to obtain sensitive information by reading the files.", "uri": "https://security-tracker.debian.org/tracker/CVE-2013-0337",
"severity": "LOW", "attributes": [{"key": "package_version", "value": "1.21.1-1~buster"},
{"key": "package_name", "value": "nginx"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:L/Au:N/C:P/I:P/A:P"},
{"key": "CVSS2_SCORE", "value": "7.5"}]}, {"name": "CVE-2018-7169", "description":
"An issue was discovered in shadow 4.5. newgidmap (in shadow-utils) is setuid and
allows an unprivileged user to be placed in a user namespace where setgroups(2)
is permitted. This allows an attacker to remove themselves from a supplementary
group, which may allow access to certain filesystem paths if the administrator has
used \"group blacklisting\" (e.g., chmod g-rwx) to restrict access to paths. This
flaw effectively reverts a security feature in the kernel (in particular, the /proc/self/setgroups
knob) to prevent this sort of privilege escalation.", "uri": "https://security-tracker.debian.org/tracker/CVE-2018-7169",
"severity": "LOW", "attributes": [{"key": "package_version", "value": "1:4.5-1.1"},
{"key": "package_name", "value": "shadow"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:L/Au:N/C:P/I:N/A:N"},
{"key": "CVSS2_SCORE", "value": "5"}]}, {"name": "CVE-2021-37600", "description":
"An integer overflow in util-linux through 2.37.1 can potentially cause a buffer
overflow if an attacker were able to use system resources in a way that leads to
a large number in the /proc/sysvipc/sem file.", "uri": "https://security-tracker.debian.org/tracker/CVE-2021-37600",
"severity": "LOW", "attributes": [{"key": "package_version", "value": "2.33.1-0.1"},
{"key": "package_name", "value": "util-linux"}, {"key": "CVSS2_VECTOR", "value":
"AV:N/AC:L/Au:N/C:P/I:P/A:P"}, {"key": "CVSS2_SCORE", "value": "7.5"}]}, {"name":
"CVE-2011-3374", "description": "It was found that apt-key in apt, all versions,
do not correctly validate gpg keys with the master keyring, leading to a potential
man-in-the-middle attack.", "uri": "https://security-tracker.debian.org/tracker/CVE-2011-3374",
"severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
"1.8.2.3"}, {"key": "package_name", "value": "apt"}, {"key": "CVSS2_VECTOR", "value":
"AV:N/AC:M/Au:N/C:N/I:P/A:N"}, {"key": "CVSS2_SCORE", "value": "4.3"}]}, {"name":
"CVE-2019-18276", "description": "An issue was discovered in disable_priv_mode in
shell.c in GNU Bash through 5.0 patch 11. By default, if Bash is run with its effective
UID not equal to its real UID, it will drop privileges by setting its effective
UID to its real UID. However, it does so incorrectly. On Linux and other systems
that support \"saved UID\" functionality, the saved UID is not dropped. An attacker
with command execution in the shell can use \"enable -f\" for runtime loading of
a new builtin, which can be a shared object that calls setuid() and therefore regains
privileges. However, binaries running with an effective UID of 0 are unaffected.",
"uri": "https://security-tracker.debian.org/tracker/CVE-2019-18276", "severity":
"INFORMATIONAL", "attributes": [{"key": "package_version", "value": "5.0-4"}, {"key":
"package_name", "value": "bash"}, {"key": "CVSS2_VECTOR", "value": "AV:L/AC:L/Au:N/C:C/I:C/A:C"},
{"key": "CVSS2_SCORE", "value": "7.2"}]}, {"name": "CVE-2017-18018", "description":
"In GNU Coreutils through 8.29, chown-core.c in chown and chgrp does not prevent
replacement of a plain file with a symlink during use of the POSIX \"-R -L\" options,
which allows local users to modify the ownership of arbitrary files by leveraging
a race condition.", "uri": "https://security-tracker.debian.org/tracker/CVE-2017-18018",
"severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
"8.30-3"}, {"key": "package_name", "value": "coreutils"}, {"key": "CVSS2_VECTOR",
"value": "AV:L/AC:M/Au:N/C:N/I:P/A:N"}, {"key": "CVSS2_SCORE", "value": "1.9"}]},
{"name": "CVE-2021-22923", "description": "When curl is instructed to get content
using the metalink feature, and a user name and password are used to download the
metalink XML file, those same credentials are then subsequently passed on to each
of the servers from which curl will download or try to download the contents from.
Often contrary to the user''s expectations and intentions and without telling the
user it happened.", "uri": "https://security-tracker.debian.org/tracker/CVE-2021-22923",
"severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
"7.64.0-4+deb10u2"}, {"key": "package_name", "value": "curl"}]}, {"name": "CVE-2021-22922",
"description": "When curl is instructed to download content using the metalink feature,
thecontents is verified against a hash provided in the metalink XML file.The metalink
XML file points out to the client how to get the same contentfrom a set of different
URLs, potentially hosted by different servers and theclient can then download the
file from one or several of them. In a serial orparallel manner.If one of the servers
hosting the contents has been breached and the contentsof the specific file on that
server is replaced with a modified payload, curlshould detect this when the hash
of the file mismatches after a completeddownload. It should remove the contents
and instead try getting the contentsfrom another URL. This is not done, and instead
such a hash mismatch is onlymentioned in text and the potentially malicious content
is kept in the file ondisk.", "uri": "https://security-tracker.debian.org/tracker/CVE-2021-22922",
"severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
"7.64.0-4+deb10u2"}, {"key": "package_name", "value": "curl"}]}, {"name": "CVE-2013-0340",
"description": "expat 2.1.0 and earlier does not properly handle entities expansion
unless an application developer uses the XML_SetEntityDeclHandler function, which
allows remote attackers to cause a denial of service (resource consumption), send
HTTP requests to intranet servers, or read arbitrary files via a crafted XML document,
aka an XML External Entity (XXE) issue. NOTE: it could be argued that because expat
already provides the ability to disable external entity expansion, the responsibility
for resolving this issue lies with application developers; according to this argument,
this entry should be REJECTed, and each affected application would need its own
CVE.", "uri": "https://security-tracker.debian.org/tracker/CVE-2013-0340", "severity":
"INFORMATIONAL", "attributes": [{"key": "package_version", "value": "2.2.6-2+deb10u1"},
{"key": "package_name", "value": "expat"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:P/I:P/A:P"},
{"key": "CVSS2_SCORE", "value": "6.8"}]}, {"name": "CVE-2019-1010023", "description":
"** DISPUTED ** GNU Libc current is affected by: Re-mapping current loaded library
with malicious ELF file. The impact is: In worst case attacker may evaluate privileges.
The component is: libld. The attack vector is: Attacker sends 2 ELF files to victim
and asks to run ldd on it. ldd execute code. NOTE: Upstream comments indicate \"this
is being treated as a non-security bug and no real threat.\"", "uri": "https://security-tracker.debian.org/tracker/CVE-2019-1010023",
"severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
"2.28-10"}, {"key": "package_name", "value": "glibc"}, {"key": "CVSS2_VECTOR", "value":
"AV:N/AC:M/Au:N/C:P/I:P/A:P"}, {"key": "CVSS2_SCORE", "value": "6.8"}]}, {"name":
"CVE-2010-4051", "description": "The regcomp implementation in the GNU C Library
(aka glibc or libc6) through 2.11.3, and 2.12.x through 2.12.2, allows context-dependent
attackers to cause a denial of service (application crash) via a regular expression
containing adjacent bounded repetitions that bypass the intended RE_DUP_MAX limitation,
as demonstrated by a {10,}{10,}{10,}{10,}{10,} sequence in the proftpd.gnu.c exploit
for ProFTPD, related to a \"RE_DUP_MAX overflow.\"", "uri": "https://security-tracker.debian.org/tracker/CVE-2010-4051",
"severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
"2.28-10"}, {"key": "package_name", "value": "glibc"}, {"key": "CVSS2_VECTOR", "value":
"AV:N/AC:L/Au:N/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value": "5"}]}, {"name":
"CVE-2019-1010022", "description": "** DISPUTED ** GNU Libc current is affected
by: Mitigation bypass. The impact is: Attacker may bypass stack guard protection.
The component is: nptl. The attack vector is: Exploit stack buffer overflow vulnerability
and use this bypass vulnerability to bypass stack guard. NOTE: Upstream comments
indicate \"this is being treated as a non-security bug and no real threat.\"", "uri":
"https://security-tracker.debian.org/tracker/CVE-2019-1010022", "severity": "INFORMATIONAL",
"attributes": [{"key": "package_version", "value": "2.28-10"}, {"key": "package_name",
"value": "glibc"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:L/Au:N/C:P/I:P/A:P"},
{"key": "CVSS2_SCORE", "value": "7.5"}]}, {"name": "CVE-2010-4052", "description":
"Stack consumption vulnerability in the regcomp implementation in the GNU C Library
(aka glibc or libc6) through 2.11.3, and 2.12.x through 2.12.2, allows context-dependent
attackers to cause a denial of service (resource exhaustion) via a regular expression
containing adjacent repetition operators, as demonstrated by a {10,}{10,}{10,}{10,}
sequence in the proftpd.gnu.c exploit for ProFTPD.", "uri": "https://security-tracker.debian.org/tracker/CVE-2010-4052",
"severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
"2.28-10"}, {"key": "package_name", "value": "glibc"}, {"key": "CVSS2_VECTOR", "value":
"AV:N/AC:L/Au:N/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value": "5"}]}, {"name":
"CVE-2019-1010024", "description": "** DISPUTED ** GNU Libc current is affected
by: Mitigation bypass. The impact is: Attacker may bypass ASLR using cache of thread
stack and heap. The component is: glibc. NOTE: Upstream comments indicate \"this
is being treated as a non-security bug and no real threat.\"", "uri": "https://security-tracker.debian.org/tracker/CVE-2019-1010024",
"severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
"2.28-10"}, {"key": "package_name", "value": "glibc"}, {"key": "CVSS2_VECTOR", "value":
"AV:N/AC:L/Au:N/C:P/I:N/A:N"}, {"key": "CVSS2_SCORE", "value": "5"}]}, {"name":
"CVE-2010-4756", "description": "The glob implementation in the GNU C Library (aka
glibc or libc6) allows remote authenticated users to cause a denial of service (CPU
and memory consumption) via crafted glob expressions that do not match any pathnames,
as demonstrated by glob expressions in STAT commands to an FTP daemon, a different
vulnerability than CVE-2010-2632.", "uri": "https://security-tracker.debian.org/tracker/CVE-2010-4756",
"severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
"2.28-10"}, {"key": "package_name", "value": "glibc"}, {"key": "CVSS2_VECTOR", "value":
"AV:N/AC:L/Au:S/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value": "4"}]}, {"name":
"CVE-2019-1010025", "description": "** DISPUTED ** GNU Libc current is affected
by: Mitigation bypass. The impact is: Attacker may guess the heap addresses of pthread_created
thread. The component is: glibc. NOTE: the vendor''s position is \"ASLR bypass itself
is not a vulnerability.\"", "uri": "https://security-tracker.debian.org/tracker/CVE-2019-1010025",
"severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
"2.28-10"}, {"key": "package_name", "value": "glibc"}, {"key": "CVSS2_VECTOR", "value":
"AV:N/AC:L/Au:N/C:P/I:N/A:N"}, {"key": "CVSS2_SCORE", "value": "5"}]}, {"name":
"CVE-2018-20796", "description": "In the GNU C Library (aka glibc or libc6) through
2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion,
as demonstrated by ''(\\227|)(\\\\1\\\\1|t1|\\\\\\2537)+'' in grep.", "uri": "https://security-tracker.debian.org/tracker/CVE-2018-20796",
"severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
"2.28-10"}, {"key": "package_name", "value": "glibc"}, {"key": "CVSS2_VECTOR", "value":
"AV:N/AC:L/Au:N/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value": "5"}]}, {"name":
"CVE-2019-9192", "description": "** DISPUTED ** In the GNU C Library (aka glibc
or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled
Recursion, as demonstrated by ''(|)(\\\\1\\\\1)*'' in grep, a different issue than
CVE-2018-20796. NOTE: the software maintainer disputes that this is a vulnerability
because the behavior occurs only with a crafted pattern.", "uri": "https://security-tracker.debian.org/tracker/CVE-2019-9192",
"severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
"2.28-10"}, {"key": "package_name", "value": "glibc"}, {"key": "CVSS2_VECTOR", "value":
"AV:N/AC:L/Au:N/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value": "5"}]}, {"name":
"CVE-2011-3389", "description": "The SSL protocol, as used in certain configurations
in Microsoft Windows and Microsoft Internet Explorer, Mozilla Firefox, Google Chrome,
Opera, and other products, encrypts data by using CBC mode with chained initialization
vectors, which allows man-in-the-middle attackers to obtain plaintext HTTP headers
via a blockwise chosen-boundary attack (BCBA) on an HTTPS session, in conjunction
with JavaScript code that uses (1) the HTML5 WebSocket API, (2) the Java URLConnection
API, or (3) the Silverlight WebClient API, aka a \"BEAST\" attack.", "uri": "https://security-tracker.debian.org/tracker/CVE-2011-3389",
"severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
"3.6.7-4+deb10u7"}, {"key": "package_name", "value": "gnutls28"}, {"key": "CVSS2_VECTOR",
"value": "AV:N/AC:M/Au:N/C:P/I:N/A:N"}, {"key": "CVSS2_SCORE", "value": "4.3"}]},
{"name": "CVE-2021-30535", "description": "Double free in ICU in Google Chrome prior
to 91.0.4472.77 allowed a remote attacker to potentially exploit heap corruption
via a crafted HTML page.", "uri": "https://security-tracker.debian.org/tracker/CVE-2021-30535",
"severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
"63.1-6+deb10u1"}, {"key": "package_name", "value": "icu"}, {"key": "CVSS2_VECTOR",
"value": "AV:N/AC:M/Au:N/C:P/I:P/A:P"}, {"key": "CVSS2_SCORE", "value": "6.8"}]},
{"name": "CVE-2017-9937", "description": "In LibTIFF 4.0.8, there is a memory malloc
failure in tif_jbig.c. A crafted TIFF document can lead to an abort resulting in
a remote denial of service attack.", "uri": "https://security-tracker.debian.org/tracker/CVE-2017-9937",
"severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
"2.1-3.1"}, {"key": "package_name", "value": "jbigkit"}, {"key": "CVSS2_VECTOR",
"value": "AV:N/AC:M/Au:N/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value": "4.3"}]},
{"name": "CVE-2018-5709", "description": "An issue was discovered in MIT Kerberos
5 (aka krb5) through 1.16. There is a variable \"dbentry->n_key_data\" in kadmin/dbutil/dump.c
that can store 16-bit data but unknowingly the developer has assigned a \"u4\" variable
to it, which is for 32-bit data. An attacker can use this vulnerability to affect
other artifacts of the database as we know that a Kerberos database dump file contains
trusted data.", "uri": "https://security-tracker.debian.org/tracker/CVE-2018-5709",
"severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
"1.17-3+deb10u1"}, {"key": "package_name", "value": "krb5"}, {"key": "CVSS2_VECTOR",
"value": "AV:N/AC:L/Au:N/C:N/I:P/A:N"}, {"key": "CVSS2_SCORE", "value": "5"}]},
{"name": "CVE-2021-36222", "description": "ec_verify in kdc/kdc_preauth_ec.c in
the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.18.4 and
1.19.x before 1.19.2 allows remote attackers to cause a NULL pointer dereference
and daemon crash. This occurs because a return value is not properly managed in
a certain situation.", "uri": "https://security-tracker.debian.org/tracker/CVE-2021-36222",
"severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
"1.17-3+deb10u1"}, {"key": "package_name", "value": "krb5"}, {"key": "CVSS2_VECTOR",
"value": "AV:N/AC:L/Au:N/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value": "5"}]},
{"name": "CVE-2004-0971", "description": "The krb5-send-pr script in the kerberos5
(krb5) package in Trustix Secure Linux 1.5 through 2.1, and possibly other operating
systems, allows local users to overwrite files via a symlink attack on temporary
files.", "uri": "https://security-tracker.debian.org/tracker/CVE-2004-0971", "severity":
"INFORMATIONAL", "attributes": [{"key": "package_version", "value": "1.17-3+deb10u1"},
{"key": "package_name", "value": "krb5"}, {"key": "CVSS2_VECTOR", "value": "AV:L/AC:L/Au:N/C:N/I:P/A:N"},
{"key": "CVSS2_SCORE", "value": "2.1"}]}, {"name": "CVE-2018-6829", "description":
"cipher/elgamal.c in Libgcrypt through 1.8.2, when used to encrypt messages directly,
improperly encodes plaintexts, which allows attackers to obtain sensitive information
by reading ciphertext data (i.e., it does not have semantic security in face of
a ciphertext-only attack). The Decisional Diffie-Hellman (DDH) assumption does not
hold for Libgcrypt''s ElGamal implementation.", "uri": "https://security-tracker.debian.org/tracker/CVE-2018-6829",
"severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
"1.8.4-5+deb10u1"}, {"key": "package_name", "value": "libgcrypt20"}, {"key": "CVSS2_VECTOR",
"value": "AV:N/AC:L/Au:N/C:P/I:N/A:N"}, {"key": "CVSS2_SCORE", "value": "5"}]},
{"name": "CVE-2018-11813", "description": "libjpeg 9c has a large loop because read_pixel
in rdtarga.c mishandles EOF.", "uri": "https://security-tracker.debian.org/tracker/CVE-2018-11813",
"severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
"1:1.5.2-2+deb10u1"}, {"key": "package_name", "value": "libjpeg-turbo"}, {"key":
"CVSS2_VECTOR", "value": "AV:N/AC:L/Au:N/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value":
"5"}]}, {"name": "CVE-2020-17541", "description": "Libjpeg-turbo all version have
a stack-based buffer overflow in the \"transform\" component. A remote attacker
can send a malformed jpeg file to the service and cause arbitrary code execution
or denial of service of the target service.", "uri": "https://security-tracker.debian.org/tracker/CVE-2020-17541",
"severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
"1:1.5.2-2+deb10u1"}, {"key": "package_name", "value": "libjpeg-turbo"}, {"key":
"CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:P/I:P/A:P"}, {"key": "CVSS2_SCORE", "value":
"6.8"}]}, {"name": "CVE-2017-15232", "description": "libjpeg-turbo 1.5.2 has a NULL
Pointer Dereference in jdpostct.c and jquant1.c via a crafted JPEG file.", "uri":
"https://security-tracker.debian.org/tracker/CVE-2017-15232", "severity": "INFORMATIONAL",
"attributes": [{"key": "package_version", "value": "1:1.5.2-2+deb10u1"}, {"key":
"package_name", "value": "libjpeg-turbo"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:N/I:N/A:P"},
{"key": "CVSS2_SCORE", "value": "4.3"}]}, {"name": "CVE-2018-14048", "description":
"An issue has been found in libpng 1.6.34. It is a SEGV in the function png_free_data
in png.c, related to the recommended error handling for png_read_image.", "uri":
"https://security-tracker.debian.org/tracker/CVE-2018-14048", "severity": "INFORMATIONAL",
"attributes": [{"key": "package_version", "value": "1.6.36-6"}, {"key": "package_name",
"value": "libpng1.6"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:N/I:N/A:P"},
{"key": "CVSS2_SCORE", "value": "4.3"}]}, {"name": "CVE-2019-6129", "description":
"** DISPUTED ** png_create_info_struct in png.c in libpng 1.6.36 has a memory leak,
as demonstrated by pngcp. NOTE: a third party has stated \"I don''t think it is
libpng''s job to free this buffer.\"", "uri": "https://security-tracker.debian.org/tracker/CVE-2019-6129",
"severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
"1.6.36-6"}, {"key": "package_name", "value": "libpng1.6"}, {"key": "CVSS2_VECTOR",
"value": "AV:N/AC:M/Au:N/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value": "4.3"}]},
{"name": "CVE-2018-14550", "description": "An issue has been found in third-party
PNM decoding associated with libpng 1.6.35. It is a stack-based buffer overflow
in the function get_token in pnm2png.c in pnm2png.", "uri": "https://security-tracker.debian.org/tracker/CVE-2018-14550",
"severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
"1.6.36-6"}, {"key": "package_name", "value": "libpng1.6"}, {"key": "CVSS2_VECTOR",
"value": "AV:N/AC:M/Au:N/C:P/I:P/A:P"}, {"key": "CVSS2_SCORE", "value": "6.8"}]},
{"name": "CVE-2019-9893", "description": "libseccomp before 2.4.0 did not correctly
generate 64-bit syscall argument comparisons using the arithmetic operators (LT,
GT, LE, GE), which might able to lead to bypassing seccomp filters and potential
privilege escalations.", "uri": "https://security-tracker.debian.org/tracker/CVE-2019-9893",
"severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
"2.3.3-4"}, {"key": "package_name", "value": "libseccomp"}, {"key": "CVSS2_VECTOR",
"value": "AV:N/AC:L/Au:N/C:P/I:P/A:P"}, {"key": "CVSS2_SCORE", "value": "7.5"}]},
{"name": "CVE-2018-1000654", "description": "GNU Libtasn1-4.13 libtasn1-4.13 version
libtasn1-4.13, libtasn1-4.12 contains a DoS, specifically CPU usage will reach 100%
when running asn1Paser against the POC due to an issue in _asn1_expand_object_id(p_tree),
after a long time, the program will be killed. This attack appears to be exploitable
via parsing a crafted file.", "uri": "https://security-tracker.debian.org/tracker/CVE-2018-1000654",
"severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
"4.13-3"}, {"key": "package_name", "value": "libtasn1-6"}, {"key": "CVSS2_VECTOR",
"value": "AV:N/AC:M/Au:N/C:N/I:N/A:C"}, {"key": "CVSS2_SCORE", "value": "7.1"}]},
{"name": "CVE-2016-9085", "description": "Multiple integer overflows in libwebp
allows attackers to have unspecified impact via unknown vectors.", "uri": "https://security-tracker.debian.org/tracker/CVE-2016-9085",
"severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
"0.6.1-2+deb10u1"}, {"key": "package_name", "value": "libwebp"}, {"key": "CVSS2_VECTOR",
"value": "AV:L/AC:L/Au:N/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value": "2.1"}]},
{"name": "CVE-2015-9019", "description": "In libxslt 1.1.29 and earlier, the EXSLT
math.random function was not initialized with a random seed during startup, which
could cause usage of this function to produce predictable outputs.", "uri": "https://security-tracker.debian.org/tracker/CVE-2015-9019",
"severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
"1.1.32-2.2~deb10u1"}, {"key": "package_name", "value": "libxslt"}, {"key": "CVSS2_VECTOR",
"value": "AV:N/AC:L/Au:N/C:P/I:N/A:N"}, {"key": "CVSS2_SCORE", "value": "5"}]},
{"name": "CVE-2009-4487", "description": "nginx 0.7.64 writes data to a log file
without sanitizing non-printable characters, which might allow remote attackers
to modify a window''s title, or possibly execute arbitrary commands or overwrite
files, via an HTTP request containing an escape sequence for a terminal emulator.",
"uri": "https://security-tracker.debian.org/tracker/CVE-2009-4487", "severity":
"INFORMATIONAL", "attributes": [{"key": "package_version", "value": "1.21.1-1~buster"},
{"key": "package_name", "value": "nginx"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:P/I:P/A:P"},
{"key": "CVSS2_SCORE", "value": "6.8"}]}, {"name": "CVE-2020-15719", "description":
"libldap in certain third-party OpenLDAP packages has a certificate-validation flaw
when the third-party package is asserting RFC6125 support. It considers CN even
when there is a non-matching subjectAltName (SAN). This is fixed in, for example,
openldap-2.4.46-10.el8 in Red Hat Enterprise Linux.", "uri": "https://security-tracker.debian.org/tracker/CVE-2020-15719",
"severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
"2.4.47+dfsg-3+deb10u6"}, {"key": "package_name", "value": "openldap"}, {"key":
"CVSS2_VECTOR", "value": "AV:N/AC:H/Au:N/C:P/I:P/A:N"}, {"key": "CVSS2_SCORE", "value":
"4"}]}, {"name": "CVE-2015-3276", "description": "The nss_parse_ciphers function
in libraries/libldap/tls_m.c in OpenLDAP does not properly parse OpenSSL-style multi-keyword
mode cipher strings, which might cause a weaker than intended cipher to be used
and allow remote attackers to have unspecified impact via unknown vectors.", "uri":
"https://security-tracker.debian.org/tracker/CVE-2015-3276", "severity": "INFORMATIONAL",
"attributes": [{"key": "package_version", "value": "2.4.47+dfsg-3+deb10u6"}, {"key":
"package_name", "value": "openldap"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:L/Au:N/C:N/I:P/A:N"},
{"key": "CVSS2_SCORE", "value": "5"}]}, {"name": "CVE-2017-14159", "description":
"slapd in OpenLDAP 2.4.45 and earlier creates a PID file after dropping privileges
to a non-root account, which might allow local users to kill arbitrary processes
by leveraging access to this non-root account for PID file modification before a
root script executes a \"kill `cat /pathname`\" command, as demonstrated by openldap-initscript.",
"uri": "https://security-tracker.debian.org/tracker/CVE-2017-14159", "severity":
"INFORMATIONAL", "attributes": [{"key": "package_version", "value": "2.4.47+dfsg-3+deb10u6"},
{"key": "package_name", "value": "openldap"}, {"key": "CVSS2_VECTOR", "value": "AV:L/AC:M/Au:N/C:N/I:N/A:P"},
{"key": "CVSS2_SCORE", "value": "1.9"}]}, {"name": "CVE-2017-17740", "description":
"contrib/slapd-modules/nops/nops.c in OpenLDAP through 2.4.45, when both the nops
module and the memberof overlay are enabled, attempts to free a buffer that was
allocated on the stack, which allows remote attackers to cause a denial of service
(slapd crash) via a member MODDN operation.", "uri": "https://security-tracker.debian.org/tracker/CVE-2017-17740",
"severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
"2.4.47+dfsg-3+deb10u6"}, {"key": "package_name", "value": "openldap"}, {"key":
"CVSS2_VECTOR", "value": "AV:N/AC:L/Au:N/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value":
"5"}]}, {"name": "CVE-2010-0928", "description": "OpenSSL 0.9.8i on the Gaisler
Research LEON3 SoC on the Xilinx Virtex-II Pro FPGA uses a Fixed Width Exponentiation
(FWE) algorithm for certain signature calculations, and does not verify the signature
before providing it to a caller, which makes it easier for physically proximate
attackers to determine the private key via a modified supply voltage for the microprocessor,
related to a \"fault-based attack.\"", "uri": "https://security-tracker.debian.org/tracker/CVE-2010-0928",
"severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
"1.1.1d-0+deb10u6"}, {"key": "package_name", "value": "openssl"}, {"key": "CVSS2_VECTOR",
"value": "AV:L/AC:H/Au:N/C:C/I:N/A:N"}, {"key": "CVSS2_SCORE", "value": "4"}]},
{"name": "CVE-2007-6755", "description": "The NIST SP 800-90A default statement
of the Dual Elliptic Curve Deterministic Random Bit Generation (Dual_EC_DRBG) algorithm
contains point Q constants with a possible relationship to certain \"skeleton key\"
values, which might allow context-dependent attackers to defeat cryptographic protection
mechanisms by leveraging knowledge of those values. NOTE: this is a preliminary
CVE for Dual_EC_DRBG; future research may provide additional details about point
Q and associated attacks, and could potentially lead to a RECAST or REJECT of this
CVE.", "uri": "https://security-tracker.debian.org/tracker/CVE-2007-6755", "severity":
"INFORMATIONAL", "attributes": [{"key": "package_version", "value": "1.1.1d-0+deb10u6"},
{"key": "package_name", "value": "openssl"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:P/I:P/A:N"},
{"key": "CVSS2_SCORE", "value": "5.8"}]}, {"name": "CVE-2017-7246", "description":
"Stack-based buffer overflow in the pcre32_copy_substring function in pcre_get.c
in libpcre1 in PCRE 8.40 allows remote attackers to cause a denial of service (WRITE
of size 268) or possibly have unspecified other impact via a crafted file.", "uri":
"https://security-tracker.debian.org/tracker/CVE-2017-7246", "severity": "INFORMATIONAL",
"attributes": [{"key": "package_version", "value": "2:8.39-12"}, {"key": "package_name",
"value": "pcre3"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:P/I:P/A:P"},
{"key": "CVSS2_SCORE", "value": "6.8"}]}, {"name": "CVE-2019-20838", "description":
"libpcre in PCRE before 8.43 allows a subject buffer over-read in JIT when UTF is
disabled, and \\X or \\R has more than one fixed quantifier, a related issue to
CVE-2019-20454.", "uri": "https://security-tracker.debian.org/tracker/CVE-2019-20838",
"severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
"2:8.39-12"}, {"key": "package_name", "value": "pcre3"}, {"key": "CVSS2_VECTOR",
"value": "AV:N/AC:M/Au:N/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value": "4.3"}]},
{"name": "CVE-2017-7245", "description": "Stack-based buffer overflow in the pcre32_copy_substring
function in pcre_get.c in libpcre1 in PCRE 8.40 allows remote attackers to cause
a denial of service (WRITE of size 4) or possibly have unspecified other impact
via a crafted file.", "uri": "https://security-tracker.debian.org/tracker/CVE-2017-7245",
"severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
"2:8.39-12"}, {"key": "package_name", "value": "pcre3"}, {"key": "CVSS2_VECTOR",
"value": "AV:N/AC:M/Au:N/C:P/I:P/A:P"}, {"key": "CVSS2_SCORE", "value": "6.8"}]},
{"name": "CVE-2017-16231", "description": "** DISPUTED ** In PCRE 8.41, after compiling,
a pcretest load test PoC produces a crash overflow in the function match() in pcre_exec.c
because of a self-recursive call. NOTE: third parties dispute the relevance of this
report, noting that there are options that can be used to limit the amount of stack
that is used.", "uri": "https://security-tracker.debian.org/tracker/CVE-2017-16231",
"severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
"2:8.39-12"}, {"key": "package_name", "value": "pcre3"}, {"key": "CVSS2_VECTOR",
"value": "AV:L/AC:L/Au:N/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value": "2.1"}]},
{"name": "CVE-2017-11164", "description": "In PCRE 8.41, the OP_KETRMAX feature
in the match function in pcre_exec.c allows stack exhaustion (uncontrolled recursion)
when processing a crafted regular expression.", "uri": "https://security-tracker.debian.org/tracker/CVE-2017-11164",
"severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
"2:8.39-12"}, {"key": "package_name", "value": "pcre3"}, {"key": "CVSS2_VECTOR",
"value": "AV:N/AC:L/Au:N/C:N/I:N/A:C"}, {"key": "CVSS2_SCORE", "value": "7.8"}]},
{"name": "CVE-2011-4116", "description": "_is_safe in the File::Temp module for
Perl does not properly handle symlinks.", "uri": "https://security-tracker.debian.org/tracker/CVE-2011-4116",
"severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
"5.28.1-6+deb10u1"}, {"key": "package_name", "value": "perl"}, {"key": "CVSS2_VECTOR",
"value": "AV:N/AC:L/Au:N/C:N/I:P/A:N"}, {"key": "CVSS2_SCORE", "value": "5"}]},
{"name": "CVE-2019-19882", "description": "shadow 4.8, in certain circumstances
affecting at least Gentoo, Arch Linux, and Void Linux, allows local users to obtain
root access because setuid programs are misconfigured. Specifically, this affects
shadow 4.8 when compiled using --with-libpam but without explicitly passing --disable-account-tools-setuid,
and without a PAM configuration suitable for use with setuid account management
tools. This combination leads to account management tools (groupadd, groupdel, groupmod,
useradd, userdel, usermod) that can easily be used by unprivileged local users to
escalate privileges to root in multiple ways. This issue became much more relevant
in approximately December 2019 when an unrelated bug was fixed (i.e., the chmod
calls to suidusbins were fixed in the upstream Makefile which is now included in
the release version 4.8).", "uri": "https://security-tracker.debian.org/tracker/CVE-2019-19882",
"severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
"1:4.5-1.1"}, {"key": "package_name", "value": "shadow"}, {"key": "CVSS2_VECTOR",
"value": "AV:L/AC:M/Au:N/C:C/I:C/A:C"}, {"key": "CVSS2_SCORE", "value": "6.9"}]},
{"name": "CVE-2007-5686", "description": "initscripts in rPath Linux 1 sets insecure
permissions for the /var/log/btmp file, which allows local users to obtain sensitive
information regarding authentication attempts. NOTE: because sshd detects the insecure
permissions and does not log certain events, this also prevents sshd from logging
failed authentication attempts by remote attackers.", "uri": "https://security-tracker.debian.org/tracker/CVE-2007-5686",
"severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
"1:4.5-1.1"}, {"key": "package_name", "value": "shadow"}, {"key": "CVSS2_VECTOR",
"value": "AV:L/AC:L/Au:N/C:C/I:N/A:N"}, {"key": "CVSS2_SCORE", "value": "4.9"}]},
{"name": "CVE-2013-4235", "description": "shadow: TOCTOU (time-of-check time-of-use)
race condition when copying and removing directory trees", "uri": "https://security-tracker.debian.org/tracker/CVE-2013-4235",
"severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
"1:4.5-1.1"}, {"key": "package_name", "value": "shadow"}, {"key": "CVSS2_VECTOR",
"value": "AV:L/AC:M/Au:N/C:N/I:P/A:P"}, {"key": "CVSS2_SCORE", "value": "3.3"}]},
{"name": "CVE-2020-13529", "description": "An exploitable denial-of-service vulnerability
exists in Systemd 245. A specially crafted DHCP FORCERENEW packet can cause a server
running the DHCP client to be vulnerable to a DHCP ACK spoofing attack. An attacker
can forge a pair of FORCERENEW and DCHP ACK packets to reconfigure the server.",
"uri": "https://security-tracker.debian.org/tracker/CVE-2020-13529", "severity":
"INFORMATIONAL", "attributes": [{"key": "package_version", "value": "241-7~deb10u8"},
{"key": "package_name", "value": "systemd"}, {"key": "CVSS2_VECTOR", "value": "AV:A/AC:M/Au:N/C:N/I:N/A:P"},
{"key": "CVSS2_SCORE", "value": "2.9"}]}, {"name": "CVE-2013-4392", "description":
"systemd, when updating file permissions, allows local users to change the permissions
and SELinux security contexts for arbitrary files via a symlink attack on unspecified
files.", "uri": "https://security-tracker.debian.org/tracker/CVE-2013-4392", "severity":
"INFORMATIONAL", "attributes": [{"key": "package_version", "value": "241-7~deb10u8"},
{"key": "package_name", "value": "systemd"}, {"key": "CVSS2_VECTOR", "value": "AV:L/AC:M/Au:N/C:P/I:P/A:N"},
{"key": "CVSS2_SCORE", "value": "3.3"}]}, {"name": "CVE-2020-13776", "description":
"systemd through v245 mishandles numerical usernames such as ones composed of decimal
digits or 0x followed by hex digits, as demonstrated by use of root privileges when
privileges of the 0x0 user account were intended. NOTE: this issue exists because
of an incomplete fix for CVE-2017-1000082.", "uri": "https://security-tracker.debian.org/tracker/CVE-2020-13776",
"severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
"241-7~deb10u8"}, {"key": "package_name", "value": "systemd"}, {"key": "CVSS2_VECTOR",
"value": "AV:L/AC:H/Au:N/C:C/I:C/A:C"}, {"key": "CVSS2_SCORE", "value": "6.2"}]},
{"name": "CVE-2019-20386", "description": "An issue was discovered in button_open
in login/logind-button.c in systemd before 243. When executing the udevadm trigger
command, a memory leak may occur.", "uri": "https://security-tracker.debian.org/tracker/CVE-2019-20386",
"severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
"241-7~deb10u8"}, {"key": "package_name", "value": "systemd"}, {"key": "CVSS2_VECTOR",
"value": "AV:L/AC:L/Au:N/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value": "2.1"}]},
{"name": "CVE-2019-9923", "description": "pax_decode_header in sparse.c in GNU Tar
before 1.32 had a NULL pointer dereference when parsing certain archives that have
malformed extended headers.", "uri": "https://security-tracker.debian.org/tracker/CVE-2019-9923",
"severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
"1.30+dfsg-6"}, {"key": "package_name", "value": "tar"}, {"key": "CVSS2_VECTOR",
"value": "AV:N/AC:L/Au:N/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value": "5"}]},
{"name": "CVE-2005-2541", "description": "Tar 1.15.1 does not properly warn the
user when extracting setuid or setgid files, which may allow local users or remote
attackers to gain privileges.", "uri": "https://security-tracker.debian.org/tracker/CVE-2005-2541",
"severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
"1.30+dfsg-6"}, {"key": "package_name", "value": "tar"}, {"key": "CVSS2_VECTOR",
"value": "AV:N/AC:L/Au:N/C:C/I:C/A:C"}, {"key": "CVSS2_SCORE", "value": "10"}]},
{"name": "CVE-2021-20193", "description": "A flaw was found in the src/list.c of
tar 1.33 and earlier. This flaw allows an attacker who can submit a crafted input
file to tar to cause uncontrolled consumption of memory. The highest threat from
this vulnerability is to system availability.", "uri": "https://security-tracker.debian.org/tracker/CVE-2021-20193",
"severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
"1.30+dfsg-6"}, {"key": "package_name", "value": "tar"}, {"key": "CVSS2_VECTOR",
"value": "AV:N/AC:M/Au:N/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value": "4.3"}]},
{"name": "CVE-2017-17973", "description": "** DISPUTED ** In LibTIFF 4.0.8, there
is a heap-based use-after-free in the t2p_writeproc function in tiff2pdf.c. NOTE:
there is a third-party report of inability to reproduce this issue.", "uri": "https://security-tracker.debian.org/tracker/CVE-2017-17973",
"severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
"4.1.0+git191117-2~deb10u2"}, {"key": "package_name", "value": "tiff"}, {"key":
"CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:P/I:P/A:P"}, {"key": "CVSS2_SCORE", "value":
"6.8"}]}, {"name": "CVE-2020-35521", "description": "A flaw was found in libtiff.
Due to a memory allocation failure in tif_read.c, a crafted TIFF file can lead to
an abort, resulting in denial of service.", "uri": "https://security-tracker.debian.org/tracker/CVE-2020-35521",
"severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
"4.1.0+git191117-2~deb10u2"}, {"key": "package_name", "value": "tiff"}, {"key":
"CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value":
"4.3"}]}, {"name": "CVE-2014-8130", "description": "The _TIFFmalloc function in
tif_unix.c in LibTIFF 4.0.3 does not reject a zero size, which allows remote attackers
to cause a denial of service (divide-by-zero error and application crash) via a
crafted TIFF image that is mishandled by the TIFFWriteScanline function in tif_write.c,
as demonstrated by tiffdither.", "uri": "https://security-tracker.debian.org/tracker/CVE-2014-8130",
"severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
"4.1.0+git191117-2~deb10u2"}, {"key": "package_name", "value": "tiff"}, {"key":
"CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value":
"4.3"}]}, {"name": "CVE-2017-5563", "description": "LibTIFF version 4.0.7 is vulnerable
to a heap-based buffer over-read in tif_lzw.c resulting in DoS or code execution
via a crafted bmp image to tools/bmp2tiff.", "uri": "https://security-tracker.debian.org/tracker/CVE-2017-5563",
"severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
"4.1.0+git191117-2~deb10u2"}, {"key": "package_name", "value": "tiff"}, {"key":
"CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:P/I:P/A:P"}, {"key": "CVSS2_SCORE", "value":
"6.8"}]}, {"name": "CVE-2020-35522", "description": "In LibTIFF, there is a memory
malloc failure in tif_pixarlog.c. A crafted TIFF document can lead to an abort,
resulting in a remote denial of service attack.", "uri": "https://security-tracker.debian.org/tracker/CVE-2020-35522",
"severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
"4.1.0+git191117-2~deb10u2"}, {"key": "package_name", "value": "tiff"}, {"key":
"CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value":
"4.3"}]}, {"name": "CVE-2017-9117", "description": "In LibTIFF 4.0.7, the program
processes BMP images without verifying that biWidth and biHeight in the bitmap-information
header match the actual input, leading to a heap-based buffer over-read in bmp2tiff.",
"uri": "https://security-tracker.debian.org/tracker/CVE-2017-9117", "severity":
"INFORMATIONAL", "attributes": [{"key": "package_version", "value": "4.1.0+git191117-2~deb10u2"},
{"key": "package_name", "value": "tiff"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:L/Au:N/C:P/I:P/A:P"},
{"key": "CVSS2_SCORE", "value": "7.5"}]}, {"name": "CVE-2017-16232", "description":
"** DISPUTED ** LibTIFF 4.0.8 has multiple memory leak vulnerabilities, which allow
attackers to cause a denial of service (memory consumption), as demonstrated by
tif_open.c, tif_lzw.c, and tif_aux.c. NOTE: Third parties were unable to reproduce
the issue.", "uri": "https://security-tracker.debian.org/tracker/CVE-2017-16232",
"severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
"4.1.0+git191117-2~deb10u2"}, {"key": "package_name", "value": "tiff"}, {"key":
"CVSS2_VECTOR", "value": "AV:N/AC:L/Au:N/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value":
"5"}]}, {"name": "CVE-2018-10126", "description": "LibTIFF 4.0.9 has a NULL pointer
dereference in the jpeg_fdct_16x16 function in jfdctint.c.", "uri": "https://security-tracker.debian.org/tracker/CVE-2018-10126",
"severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
"4.1.0+git191117-2~deb10u2"}, {"key": "package_name", "value": "tiff"}, {"key":
"CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value":
"4.3"}]}, {"name": "CVE-2021-22924", "description": "libcurl keeps previously used
connections in a connection pool for subsequenttransfers to reuse, if one of them
matches the setup.Due to errors in the logic, the config matching function did not
take ''issuercert'' into account and it compared the involved paths *case insensitively*,which
could lead to libcurl reusing wrong connections.File paths are, or can be, case
sensitive on many systems but not all, and caneven vary depending on used file systems.The
comparison also didn''t include the ''issuer cert'' which a transfer can setto qualify
how to verify the server certificate.", "uri": "https://security-tracker.debian.org/tracker/CVE-2021-22924",
"severity": "UNDEFINED", "attributes": [{"key": "package_version", "value": "7.64.0-4+deb10u2"},
{"key": "package_name", "value": "curl"}]}, {"name": "CVE-2021-38115", "description":
"read_header_tga in gd_tga.c in the GD Graphics Library (aka LibGD) through 2.3.2
allows remote attackers to cause a denial of service (out-of-bounds read) via a
crafted TGA file.", "uri": "https://security-tracker.debian.org/tracker/CVE-2021-38115",
"severity": "UNDEFINED", "attributes": [{"key": "package_version", "value": "2.2.5-5.2"},
{"key": "package_name", "value": "libgd2"}]}, {"name": "CVE-2021-3618", "uri": "https://security-tracker.debian.org/tracker/CVE-2021-3618",
"severity": "UNDEFINED", "attributes": [{"key": "package_version", "value": "1.21.1-1~buster"},
{"key": "package_name", "value": "nginx"}]}], "findingSeverityCounts": {"HIGH":
2, "MEDIUM": 14, "INFORMATIONAL": 63, "LOW": 22, "UNDEFINED": 3}}}, "requestID":
"23c19e2d-c48b-4265-b4eb-853e7b325780", "eventID": "6c94a9b2-36dc-43f8-a6dd-4ec839ded8af",
"readOnly": true, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId":
"111111111111", "eventCategory": "Management"}'
@@ -0,0 +1,99 @@
name: AWS CloudTrail GetAccountPasswordPolicy
id: 439bdc53-6e4b-4cd7-b326-86c7317fd396
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
description: Data source object for AWS CloudTrail GetAccountPasswordPolicy
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
supported_TA:
- name: Splunk Add-on for Amazon Web Services (AWS)
url: https://splunkbase.splunk.com/app/1876
version: 7.4.1
fields:
- _time
- action
- app
- awsRegion
- aws_account_id
- change_type
- command
- date_hour
- date_mday
- date_minute
- date_month
- date_second
- date_wday
- date_year
- date_zone
- desc
- dest
- dvc
- errorCode
- eventCategory
- eventID
- eventName
- eventSource
- eventTime
- eventType
- eventVersion
- host
- index
- linecount
- managementEvent
- msg
- object_category
- product
- punct
- readOnly
- recipientAccountId
- region
- requestID
- requestParameters
- responseElements
- signature
- source
- sourceIPAddress
- sourcetype
- splunk_server
- src
- src_ip
- start_time
- status
- timeendpos
- timestartpos
- tlsDetails.cipherSuite
- tlsDetails.clientProvidedHostHeader
- tlsDetails.tlsVersion
- user
- userAgent
- userIdentity.accessKeyId
- userIdentity.accountId
- userIdentity.arn
- userIdentity.principalId
- userIdentity.type
- userIdentity.userName
- userName
- user_access_key
- user_agent
- user_arn
- user_group_id
- user_id
- user_name
- user_type
- vendor
- vendor_account
- vendor_product
- vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId":
"AIDASBMSCQHHTH5NDF4GD", "arn": "arn:aws:iam::111111111111:user/strt_fonder", "accountId":
"111111111111", "accessKeyId": "AKIASBMSCQHH5A5NJDM5", "userName": "strt_fonder"},
"eventTime": "2023-01-26T22:39:06Z", "eventSource": "iam.amazonaws.com", "eventName":
"GetAccountPasswordPolicy", "awsRegion": "us-east-1", "sourceIPAddress": "23.93.193.7",
"userAgent": "aws-cli/2.7.25 Python/3.10.6 Darwin/21.6.0 source/x86_64 prompt/off
command/iam.get-account-password-policy", "requestParameters": null, "responseElements":
null, "requestID": "098fd0dd-e42e-4249-91fb-9637925bf2fe", "eventID": "5eb0fb9b-18ff-4be9-b90d-107a290e1d5c",
"readOnly": true, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId":
"111111111111", "eventCategory": "Management", "tlsDetails": {"tlsVersion": "TLSv1.2",
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256", "clientProvidedHostHeader": "iam.amazonaws.com"}}'
+113
View File
@@ -0,0 +1,113 @@
name: AWS CloudTrail GetObject
id: 5063cb10-84c0-44af-ade4-ab9ecad11dfe
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
description: Data source object for AWS CloudTrail GetObject
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
supported_TA:
- name: Splunk Add-on for Amazon Web Services (AWS)
url: https://splunkbase.splunk.com/app/1876
version: 7.4.1
fields:
- _time
- additionalEventData.AuthenticationMethod
- additionalEventData.CipherSuite
- additionalEventData.SignatureVersion
- additionalEventData.bytesTransferredIn
- additionalEventData.bytesTransferredOut
- additionalEventData.x-amz-id-2
- app
- awsRegion
- aws_account_id
- command
- date_hour
- date_mday
- date_minute
- date_month
- date_second
- date_wday
- date_year
- date_zone
- dest
- dvc
- errorCode
- eventCategory
- eventID
- eventName
- eventSource
- eventTime
- eventType
- eventVersion
- host
- index
- linecount
- managementEvent
- msg
- object_category
- product
- punct
- readOnly
- recipientAccountId
- region
- requestID
- requestParameters.Host
- requestParameters.bucketName
- requestParameters.key
- requestParameters.x-amz-request-payer
- resources{}.ARN
- resources{}.accountId
- resources{}.type
- responseElements
- signature
- source
- sourceIPAddress
- sourcetype
- splunk_server
- src
- src_ip
- start_time
- timeendpos
- timestartpos
- tlsDetails.cipherSuite
- tlsDetails.clientProvidedHostHeader
- tlsDetails.tlsVersion
- user
- userAgent
- userIdentity.accessKeyId
- userIdentity.accountId
- userIdentity.arn
- userIdentity.principalId
- userIdentity.type
- userIdentity.userName
- userName
- user_access_key
- user_agent
- user_arn
- user_group_id
- user_id
- user_name
- user_type
- vendor
- vendor_account
- vendor_product
- vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId":
"AIDAYTOGP2RLCNEAQXWZV", "arn": "arn:aws:iam::111111111111:user/console", "accountId":
"111111111111", "accessKeyId": "AKIAYTOGP2RLF5EAXXXX", "userName": "console"}, "eventTime":
"2023-04-11T01:18:47Z", "eventSource": "s3.amazonaws.com", "eventName": "GetObject",
"awsRegion": "us-west-2", "sourceIPAddress": "12.26.0.38", "userAgent": "[aws-cli/2.11.2
Python/3.11.2 Darwin/22.3.0 exe/x86_64 prompt/off command/s3.cp]", "requestParameters":
{"bucketName": "security-content", "Host": "security-content.s3.us-west-2.amazonaws.com",
"x-amz-request-payer": "requester", "key": "stories/windows_discovery_techniques.yml"},
"responseElements": null, "additionalEventData": {"SignatureVersion": "SigV4", "CipherSuite":
"ECDHE-RSA-AES128-GCM-SHA256", "bytesTransferredIn": 0, "AuthenticationMethod":
"AuthHeader", "x-amz-id-2": "dcha0yrujT+O4FHsYxHx48KxMk4+wtO7MaNRwFOFs46R1PynKWcCsbLScYEFytN+Vt35hyq1cek=",
"bytesTransferredOut": 1136}, "requestID": "GVSEBM08Z93FB3BT", "eventID": "2b7231c2-892d-464e-8880-1e4f81ae7eb2",
"readOnly": true, "resources": [{"type": "AWS::S3::Object", "ARN": "arn:aws:s3:::security-content/stories/windows_discovery_techniques.yml"},
{"accountId": "111111111111", "type": "AWS::S3::Bucket", "ARN": "arn:aws:s3:::security-content"}],
"eventType": "AwsApiCall", "managementEvent": false, "recipientAccountId": "111111111111",
"eventCategory": "Data", "tlsDetails": {"tlsVersion": "TLSv1.2", "cipherSuite":
"ECDHE-RSA-AES128-GCM-SHA256", "clientProvidedHostHeader": "security-content.s3.us-west-2.amazonaws.com"}}'
@@ -0,0 +1,115 @@
name: AWS CloudTrail GetPasswordData
id: 6ff2ce99-85b1-4c17-888a-56dbc3570671
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
description: Data source object for AWS CloudTrail GetPasswordData
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
supported_TA:
- name: Splunk Add-on for Amazon Web Services (AWS)
url: https://splunkbase.splunk.com/app/1876
version: 7.4.1
fields:
- _time
- app
- awsRegion
- aws_account_id
- change_type
- command
- date_hour
- date_mday
- date_minute
- date_month
- date_second
- date_wday
- date_year
- date_zone
- dest
- dvc
- errorCode
- errorMessage
- eventCategory
- eventID
- eventName
- eventSource
- eventTime
- eventType
- eventVersion
- eventtype
- host
- index
- linecount
- managementEvent
- msg
- object_category
- product
- punct
- readOnly
- reason
- recipientAccountId
- region
- requestID
- requestParameters.instanceId
- responseElements
- result
- result_id
- signature
- source
- sourceIPAddress
- sourcetype
- splunk_server
- src
- src_ip
- start_time
- tag
- tag::eventtype
- timeendpos
- timestartpos
- tlsDetails.cipherSuite
- tlsDetails.clientProvidedHostHeader
- tlsDetails.tlsVersion
- user
- userAgent
- userIdentity.accessKeyId
- userIdentity.accountId
- userIdentity.arn
- userIdentity.principalId
- userIdentity.sessionContext.attributes.creationDate
- userIdentity.sessionContext.attributes.mfaAuthenticated
- userIdentity.sessionContext.sessionIssuer.accountId
- userIdentity.sessionContext.sessionIssuer.arn
- userIdentity.sessionContext.sessionIssuer.principalId
- userIdentity.sessionContext.sessionIssuer.type
- userIdentity.sessionContext.sessionIssuer.userName
- userIdentity.type
- userName
- user_access_key
- user_agent
- user_arn
- user_group_id
- user_id
- user_name
- user_type
- vendor
- vendor_account
- vendor_product
- vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "principalId":
"AROAYTOGP2RLP5AASA6I5:aws-go-sdk-1660169051746043000", "arn": "arn:aws:sts::111111111111:assumed-role/sample-role-used-by-stratus-for-ec2-password-data/aws-go-sdk-1660169051746043000",
"accountId": "111111111111", "accessKeyId": "ASIAYTOGP2RLLY5RQXEF", "sessionContext":
{"sessionIssuer": {"type": "Role", "principalId": "AROAYTOGP2RLP5AASA6I5", "arn":
"arn:aws:iam::111111111111:role/sample-role-used-by-stratus-for-ec2-password-data",
"accountId": "111111111111", "userName": "sample-role-used-by-stratus-for-ec2-password-data"},
"webIdFederationData": {}, "attributes": {"creationDate": "2022-08-10T22:04:12Z",
"mfaAuthenticated": "false"}}}, "eventTime": "2022-08-10T22:04:13Z", "eventSource":
"ec2.amazonaws.com", "eventName": "GetPasswordData", "awsRegion": "us-west-2", "sourceIPAddress":
"142.254.89.27", "userAgent": "stratus-red-team_e3e4b259-63a4-4d89-acd5-a7286a279bb8",
"errorCode": "Client.UnauthorizedOperation", "errorMessage": "You are not authorized
to perform this operation. Encoded authorization failure message: OwnXKlWs2vtfsyXhkYTFO35PfDwIeH4oGadP2dmbdguXBDpSfP-65XwZU4JdWht_u8p9BlgIZ0QOYIzmm5-ApXc7HsgOynmQvF4vFNUxxiuY0w-VRNBiuPmphwnJqYln8pTJogn0DfcleY5TIuDEFwmGvZHnGMmK1kXJ1VcUiQvbK_vuDpSqIDFz-jqcnOTjzsC4DXlTZkHLL1HEeNVIjI9HCEWYG4CuG9Ti8BQ0AnGVkU8oqvtS6iyVlnPI9oId5_AWpfmE1ijhNKbgFH77DjRn6QyR5rGkGYYFpvaIyMvX33Vti4RzfAyJdpuzMgp6tV-q_Rbh0ikwBJvUtiiGfmqzdQynfRNDQmXJ3ruifOjGmUz34M90SGFJKi5CVHGThtO3UWj9EqYXpKdu_JgTYEqxWvRBopB--V7tOap8XKuz7W3rWyHN2clHA0yooLZ3DV34LWgzzDp9Iv66829HSTwGz7h2P0sGdCNuV_FCxwQzWYa8f6_h1By90MvWUvmEDLSzOfA_PF6BcqCmV8XBiPUvCMPebDSGmPwSa371J5Yn2xEiuQadfuNYRLZnd2i1V_NF9ax67BdZ",
"requestParameters": {"instanceId": "i-7sap2krlslv6adrs"}, "responseElements": null,
"requestID": "87368810-7b30-4ff9-b097-702778a53f22", "eventID": "0cdd3757-296a-4454-9619-d0f8be335081",
"readOnly": true, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId":
"111111111111", "eventCategory": "Management", "tlsDetails": {"tlsVersion": "TLSv1.2",
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256", "clientProvidedHostHeader": "ec2.us-west-2.amazonaws.com"}}'
@@ -0,0 +1,84 @@
name: AWS CloudTrail JobCreated
id: 6473289b-d097-4c86-a837-3cc5ae408155
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
description: Data source object for AWS CloudTrail JobCreated
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
supported_TA:
- name: Splunk Add-on for Amazon Web Services (AWS)
url: https://splunkbase.splunk.com/app/1876
version: 7.4.1
fields:
- _time
- app
- awsRegion
- aws_account_id
- command
- date_hour
- date_mday
- date_minute
- date_month
- date_second
- date_wday
- date_year
- date_zone
- desc
- dest
- dvc
- errorCode
- eventCategory
- eventID
- eventName
- eventSource
- eventTime
- eventType
- eventVersion
- host
- index
- linecount
- managementEvent
- msg
- object_category
- product
- punct
- readOnly
- recipientAccountId
- region
- requestParameters
- responseElements
- serviceEventDetails.jobArn
- serviceEventDetails.jobEventId
- serviceEventDetails.jobId
- serviceEventDetails.status
- signature
- source
- sourceIPAddress
- sourcetype
- splunk_server
- src
- src_ip
- start_time
- timeendpos
- timestartpos
- userAgent
- userIdentity.accountId
- userIdentity.invokedBy
- user_agent
- user_group_id
- vendor
- vendor_account
- vendor_product
- vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"accountId": "111111111111",
"invokedBy": "s3.amazonaws.com"}, "eventTime": "2023-04-24T23:51:17Z", "eventSource":
"s3.amazonaws.com", "eventName": "JobCreated", "awsRegion": "us-west-2", "sourceIPAddress":
"s3.amazonaws.com", "userAgent": "s3.amazonaws.com", "requestParameters": null,
"responseElements": null, "eventID": "894153ad-ed86-4719-bb66-6c52ef7dc767", "readOnly":
false, "eventType": "AwsServiceEvent", "managementEvent": true, "recipientAccountId":
"111111111111", "serviceEventDetails": {"jobId": "bb54efd8-937d-4f0c-967d-aa8443998dac",
"jobArn": "arn:aws:s3:us-west-2:111111111111:job/bb54efd8-937d-4f0c-967d-aa8443998dac",
"status": "New", "jobEventId": "4e70d2f1053c07a79d9be9a14e486020", "failureCodes":
[], "statusChangeReason": []}, "eventCategory": "Management"}'
@@ -0,0 +1,193 @@
name: AWS CloudTrail ModifyDBInstance
id: bfa2912d-1a33-4b05-be46-543874d68241
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
description: Data source object for AWS CloudTrail ModifyDBInstance
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
supported_TA:
- name: Splunk Add-on for Amazon Web Services (AWS)
url: https://splunkbase.splunk.com/app/1876
version: 7.4.1
fields:
- _time
- app
- awsRegion
- aws_account_id
- command
- date_hour
- date_mday
- date_minute
- date_month
- date_second
- date_wday
- date_year
- date_zone
- dest
- dvc
- errorCode
- eventCategory
- eventID
- eventName
- eventSource
- eventTime
- eventType
- eventVersion
- host
- index
- linecount
- managementEvent
- msg
- object_category
- product
- punct
- readOnly
- recipientAccountId
- region
- requestID
- requestParameters.allowMajorVersionUpgrade
- requestParameters.applyImmediately
- requestParameters.dBInstanceIdentifier
- requestParameters.deletionProtection
- requestParameters.masterUserPassword
- responseElements.allocatedStorage
- responseElements.autoMinorVersionUpgrade
- responseElements.availabilityZone
- responseElements.backupRetentionPeriod
- responseElements.backupTarget
- responseElements.cACertificateIdentifier
- responseElements.copyTagsToSnapshot
- responseElements.customerOwnedIpEnabled
- responseElements.dBInstanceArn
- responseElements.dBInstanceClass
- responseElements.dBInstanceIdentifier
- responseElements.dBInstanceStatus
- responseElements.dBParameterGroups{}.dBParameterGroupName
- responseElements.dBParameterGroups{}.parameterApplyStatus
- responseElements.dBSubnetGroup.dBSubnetGroupDescription
- responseElements.dBSubnetGroup.dBSubnetGroupName
- responseElements.dBSubnetGroup.subnetGroupStatus
- responseElements.dBSubnetGroup.subnets{}.subnetAvailabilityZone.name
- responseElements.dBSubnetGroup.subnets{}.subnetIdentifier
- responseElements.dBSubnetGroup.subnets{}.subnetStatus
- responseElements.dBSubnetGroup.vpcId
- responseElements.dbInstancePort
- responseElements.dbiResourceId
- responseElements.deletionProtection
- responseElements.endpoint.address
- responseElements.endpoint.hostedZoneId
- responseElements.endpoint.port
- responseElements.engine
- responseElements.engineVersion
- responseElements.enhancedMonitoringResourceArn
- responseElements.httpEndpointEnabled
- responseElements.iAMDatabaseAuthenticationEnabled
- responseElements.instanceCreateTime
- responseElements.kmsKeyId
- responseElements.latestRestorableTime
- responseElements.licenseModel
- responseElements.masterUsername
- responseElements.monitoringInterval
- responseElements.monitoringRoleArn
- responseElements.multiAZ
- responseElements.networkType
- responseElements.optionGroupMemberships{}.optionGroupName
- responseElements.optionGroupMemberships{}.status
- responseElements.pendingModifiedValues.masterUserPassword
- responseElements.performanceInsightsEnabled
- responseElements.performanceInsightsKMSKeyId
- responseElements.performanceInsightsRetentionPeriod
- responseElements.preferredBackupWindow
- responseElements.preferredMaintenanceWindow
- responseElements.publiclyAccessible
- responseElements.storageEncrypted
- responseElements.storageThroughput
- responseElements.storageType
- responseElements.vpcSecurityGroups{}.status
- responseElements.vpcSecurityGroups{}.vpcSecurityGroupId
- sessionCredentialFromConsole
- signature
- source
- sourceIPAddress
- sourcetype
- splunk_server
- src
- src_ip
- start_time
- timeendpos
- timestartpos
- user
- userAgent
- userIdentity.accessKeyId
- userIdentity.accountId
- userIdentity.arn
- userIdentity.principalId
- userIdentity.sessionContext.attributes.creationDate
- userIdentity.sessionContext.attributes.mfaAuthenticated
- userIdentity.sessionContext.sessionIssuer.accountId
- userIdentity.sessionContext.sessionIssuer.arn
- userIdentity.sessionContext.sessionIssuer.principalId
- userIdentity.sessionContext.sessionIssuer.type
- userIdentity.sessionContext.sessionIssuer.userName
- userIdentity.type
- userName
- user_access_key
- user_agent
- user_arn
- user_group_id
- user_id
- user_name
- user_type
- vendor
- vendor_account
- vendor_product
- vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "principalId":
"AROAYTOGP2RLDF6WP4HD6:gowthamarajr@splunk.com", "arn": "arn:aws:sts::111111111111:assumed-role/AWSReservedSSO_SPLKAdministratorAccess_d9ce1347d0a6dd3f/gowthamarajr@splunk.com",
"accountId": "111111111111", "accessKeyId": "ASIAYTOGP2RLAKJDBQGB", "sessionContext":
{"sessionIssuer": {"type": "Role", "principalId": "AROAYTOGP2RLDF6WP4HD6", "arn":
"arn:aws:iam::111111111111:role/aws-reserved/sso.amazonaws.com/us-west-2/AWSReservedSSO_SPLKAdministratorAccess_d9ce1347d0a6dd3f",
"accountId": "111111111111", "userName": "AWSReservedSSO_SPLKAdministratorAccess_d9ce1347d0a6dd3f"},
"webIdFederationData": {}, "attributes": {"creationDate": "2022-08-05T08:47:55Z",
"mfaAuthenticated": "false"}}}, "eventTime": "2022-08-05T09:19:15Z", "eventSource":
"rds.amazonaws.com", "eventName": "ModifyDBInstance", "awsRegion": "us-west-2",
"sourceIPAddress": "AWS Internal", "userAgent": "AWS Internal", "requestParameters":
{"dBInstanceIdentifier": "database-1", "applyImmediately": true, "masterUserPassword":
"****", "allowMajorVersionUpgrade": false, "deletionProtection": true}, "responseElements":
{"dBInstanceIdentifier": "database-1", "dBInstanceClass": "db.m6g.large", "engine":
"postgres", "dBInstanceStatus": "available", "masterUsername": "postgres", "endpoint":
{"address": "database-1.ce6wk5bvtc0t.us-west-2.rds.amazonaws.com", "port": 5432,
"hostedZoneId": "Z1PVIF0B656C1W"}, "allocatedStorage": 5, "instanceCreateTime":
"Aug 5, 2022 9:02:51 AM", "preferredBackupWindow": "06:35-07:05", "backupRetentionPeriod":
7, "dBSecurityGroups": [], "vpcSecurityGroups": [{"vpcSecurityGroupId": "sg-46cfd020",
"status": "active"}], "dBParameterGroups": [{"dBParameterGroupName": "default.postgres14",
"parameterApplyStatus": "in-sync"}], "availabilityZone": "us-west-2a", "dBSubnetGroup":
{"dBSubnetGroupName": "default", "dBSubnetGroupDescription": "default", "vpcId":
"vpc-5f02343b", "subnetGroupStatus": "Complete", "subnets": [{"subnetIdentifier":
"subnet-43225f35", "subnetAvailabilityZone": {"name": "us-west-2b"}, "subnetOutpost":
{}, "subnetStatus": "Active"}, {"subnetIdentifier": "subnet-e55d7881", "subnetAvailabilityZone":
{"name": "us-west-2a"}, "subnetOutpost": {}, "subnetStatus": "Active"}, {"subnetIdentifier":
"subnet-0beddb972f034bdaa", "subnetAvailabilityZone": {"name": "us-west-2c"}, "subnetOutpost":
{}, "subnetStatus": "Active"}, {"subnetIdentifier": "subnet-2d70cd75", "subnetAvailabilityZone":
{"name": "us-west-2c"}, "subnetOutpost": {}, "subnetStatus": "Active"}]}, "preferredMaintenanceWindow":
"sat:11:44-sat:12:14", "pendingModifiedValues": {"masterUserPassword": "****"},
"latestRestorableTime": "Aug 5, 2022 9:12:31 AM", "multiAZ": false, "engineVersion":
"14.2", "autoMinorVersionUpgrade": true, "readReplicaDBInstanceIdentifiers": [],
"licenseModel": "postgresql-license", "storageThroughput": 0, "optionGroupMemberships":
[{"optionGroupName": "default:postgres-14", "status": "in-sync"}], "publiclyAccessible":
false, "storageType": "standard", "dbInstancePort": 0, "storageEncrypted": true,
"kmsKeyId": "arn:aws:kms:us-west-2:111111111111:key/318bcd5d-c453-489d-b63a-07753eab0623",
"dbiResourceId": "db-IX2K4LYFLBVZDHBYNPEAVFHFQM", "cACertificateIdentifier": "rds-ca-2019",
"domainMemberships": [], "copyTagsToSnapshot": true, "monitoringInterval": 60, "enhancedMonitoringResourceArn":
"arn:aws:logs:us-west-2:111111111111:log-group:RDSOSMetrics:log-stream:db-IX2K4LYFLBVZDHBYNPEAVFHFQM",
"monitoringRoleArn": "arn:aws:iam::111111111111:role/rds-monitoring-role", "dBInstanceArn":
"arn:aws:rds:us-west-2:111111111111:db:database-1", "iAMDatabaseAuthenticationEnabled":
false, "performanceInsightsEnabled": true, "performanceInsightsKMSKeyId": "arn:aws:kms:us-west-2:111111111111:key/318bcd5d-c453-489d-b63a-07753eab0623",
"performanceInsightsRetentionPeriod": 7, "deletionProtection": true, "associatedRoles":
[], "httpEndpointEnabled": false, "tagList": [], "customerOwnedIpEnabled": false,
"networkType": "IPV4", "backupTarget": "region"}, "requestID": "59e6b621-2f12-415b-bde4-21fa2dc7c113",
"eventID": "46351ca1-760e-4eef-b3ff-19723e13fbf8", "readOnly": false, "eventType":
"AwsApiCall", "managementEvent": true, "recipientAccountId": "111111111111", "eventCategory":
"Management", "sessionCredentialFromConsole": "true"}'
@@ -0,0 +1,108 @@
name: AWS CloudTrail ModifyImageAttribute
id: 667c2115-8082-419e-b541-8150066bda4d
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
description: Data source object for AWS CloudTrail ModifyImageAttribute
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
supported_TA:
- name: Splunk Add-on for Amazon Web Services (AWS)
url: https://splunkbase.splunk.com/app/1876
version: 7.4.1
fields:
- _time
- app
- awsRegion
- aws_account_id
- change_type
- command
- date_hour
- date_mday
- date_minute
- date_month
- date_second
- date_wday
- date_year
- date_zone
- dest
- dvc
- errorCode
- eventCategory
- eventID
- eventName
- eventSource
- eventTime
- eventType
- eventVersion
- host
- index
- linecount
- managementEvent
- msg
- object_category
- product
- punct
- readOnly
- recipientAccountId
- region
- requestID
- requestParameters.attributeType
- requestParameters.imageId
- requestParameters.launchPermission.add.items{}.userId
- responseElements._return
- responseElements.requestId
- sessionCredentialFromConsole
- signature
- source
- sourceIPAddress
- sourcetype
- splunk_server
- src
- src_ip
- start_time
- timeendpos
- timestartpos
- user
- userAgent
- userIdentity.accessKeyId
- userIdentity.accountId
- userIdentity.arn
- userIdentity.principalId
- userIdentity.sessionContext.attributes.creationDate
- userIdentity.sessionContext.attributes.mfaAuthenticated
- userIdentity.sessionContext.sessionIssuer.accountId
- userIdentity.sessionContext.sessionIssuer.arn
- userIdentity.sessionContext.sessionIssuer.principalId
- userIdentity.sessionContext.sessionIssuer.type
- userIdentity.sessionContext.sessionIssuer.userName
- userIdentity.type
- userName
- user_access_key
- user_agent
- user_arn
- user_group_id
- user_id
- user_name
- user_type
- vendor
- vendor_account
- vendor_product
- vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "principalId":
"AROAYTOGP2RLDF6WP4HD6:bonobo@bo.com", "arn": "arn:aws:sts::111111111111:assumed-role/AWSReservedSSO_SPLKAdministratorAccess_d9ce1347d0a6dd3f/bonobo@bo.com",
"accountId": "111111111111", "accessKeyId": "ASIAYTOGP2RLBHIEEEPN", "sessionContext":
{"sessionIssuer": {"type": "Role", "principalId": "AROAYTOGP2RLDF6WP4HD6", "arn":
"arn:aws:iam::111111111111:role/aws-reserved/sso.amazonaws.com/us-west-2/AWSReservedSSO_SPLKAdministratorAccess_d9ce1347d0a6dd3f",
"accountId": "111111111111", "userName": "AWSReservedSSO_SPLKAdministratorAccess_d9ce1347d0a6dd3f"},
"webIdFederationData": {}, "attributes": {"creationDate": "2023-03-23T19:27:44Z",
"mfaAuthenticated": "false"}}}, "eventTime": "2023-03-23T21:47:28Z", "eventSource":
"ec2.amazonaws.com", "eventName": "ModifyImageAttribute", "awsRegion": "us-west-2",
"sourceIPAddress": "72.135.245.10", "userAgent": "AWS Internal", "requestParameters":
{"imageId": "ami-06dac31db29508566", "launchPermission": {"add": {"items": [{"userId":
"140429656527"}]}}, "attributeType": "launchPermission"}, "responseElements": {"requestId":
"84c431ce-6268-4218-aaf8-b4cdc1cd4055", "_return": true}, "requestID": "84c431ce-6268-4218-aaf8-b4cdc1cd4055",
"eventID": "957e1b12-ea17-4006-aefd-20677ace72b8", "readOnly": false, "eventType":
"AwsApiCall", "managementEvent": true, "recipientAccountId": "111111111111", "eventCategory":
"Management", "sessionCredentialFromConsole": "true"}'
@@ -0,0 +1,101 @@
name: AWS CloudTrail ModifySnapshotAttribute
id: 7e5aa947-3a0d-4ee5-b800-0c10b555da05
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
description: Data source object for AWS CloudTrail ModifySnapshotAttribute
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
supported_TA:
- name: Splunk Add-on for Amazon Web Services (AWS)
url: https://splunkbase.splunk.com/app/1876
version: 7.4.1
fields:
- _time
- app
- awsRegion
- aws_account_id
- change_type
- command
- date_hour
- date_mday
- date_minute
- date_month
- date_second
- date_wday
- date_year
- date_zone
- dest
- dvc
- errorCode
- eventCategory
- eventID
- eventName
- eventSource
- eventTime
- eventType
- eventVersion
- host
- index
- linecount
- managementEvent
- msg
- object_category
- product
- punct
- readOnly
- recipientAccountId
- region
- requestID
- requestParameters.attributeType
- requestParameters.createVolumePermission.add.items{}.userId
- requestParameters.snapshotId
- responseElements._return
- responseElements.requestId
- signature
- source
- sourceIPAddress
- sourcetype
- splunk_server
- src
- src_ip
- start_time
- timeendpos
- timestartpos
- tlsDetails.cipherSuite
- tlsDetails.clientProvidedHostHeader
- tlsDetails.tlsVersion
- user
- userAgent
- userIdentity.accessKeyId
- userIdentity.accountId
- userIdentity.arn
- userIdentity.principalId
- userIdentity.type
- userIdentity.userName
- userName
- user_access_key
- user_agent
- user_arn
- user_group_id
- user_id
- user_name
- user_type
- vendor
- vendor_account
- vendor_product
- vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId":
"AIDAYTOGP2RLCNEAQXWZV", "arn": "arn:aws:iam::111111111111:user/bhavin_console",
"accountId": "111111111111", "accessKeyId": "AKIAYTOGP2RLF5EAXXXX", "userName":
"bhavin_console"}, "eventTime": "2023-03-20T22:31:36Z", "eventSource": "ec2.amazonaws.com",
"eventName": "ModifySnapshotAttribute", "awsRegion": "us-west-2", "sourceIPAddress":
"72.135.1.1", "userAgent": "stratus-red-team_46665bb8-dc15-4aba-a5ad-a362772b3f0d",
"requestParameters": {"snapshotId": "snap-02effb3bb62786b18", "createVolumePermission":
{"add": {"items": [{"userId": "012345678912"}]}}, "attributeType": "CREATE_VOLUME_PERMISSION"},
"responseElements": {"requestId": "f58433e6-a7f4-4e63-9cba-7ecc60ab74b2", "_return":
true}, "requestID": "f58433e6-a7f4-4e63-9cba-7ecc60ab74b2", "eventID": "62e027d3-7191-48f4-b5fe-4b66c58b3008",
"readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId":
"111111111111", "eventCategory": "Management", "tlsDetails": {"tlsVersion": "TLSv1.2",
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256", "clientProvidedHostHeader": "ec2.us-west-2.amazonaws.com"}}'
@@ -0,0 +1,116 @@
name: AWS CloudTrail PutBucketAcl
id: 28fffbfd-d98d-4a42-990b-b04ab47422eb
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
description: Data source object for AWS CloudTrail PutBucketAcl
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
supported_TA:
- name: Splunk Add-on for Amazon Web Services (AWS)
url: https://splunkbase.splunk.com/app/1876
version: 7.4.1
fields:
- _time
- action
- additionalEventData.AuthenticationMethod
- additionalEventData.CipherSuite
- additionalEventData.SignatureVersion
- additionalEventData.bytesTransferredIn
- additionalEventData.bytesTransferredOut
- additionalEventData.x-amz-id-2
- app
- awsRegion
- aws_account_id
- change_type
- command
- date_hour
- date_mday
- date_minute
- date_month
- date_second
- date_wday
- date_year
- date_zone
- dest
- dvc
- errorCode
- eventCategory
- eventID
- eventName
- eventSource
- eventTime
- eventType
- eventVersion
- eventtype
- host
- index
- linecount
- managementEvent
- msg
- object
- object_category
- object_id
- product
- punct
- readOnly
- recipientAccountId
- region
- requestID
- requestParameters.Host
- requestParameters.accessControlList.x-amz-grant-write-acp
- requestParameters.acl
- requestParameters.bucketName
- resources{}.ARN
- resources{}.accountId
- resources{}.type
- responseElements
- signature
- source
- sourceIPAddress
- sourcetype
- splunk_server
- src
- src_ip
- src_user
- start_time
- status
- tag
- tag::eventtype
- timeendpos
- timestartpos
- user
- userAgent
- userIdentity.accessKeyId
- userIdentity.accountId
- userIdentity.arn
- userIdentity.principalId
- userIdentity.type
- userIdentity.userName
- userName
- user_access_key
- user_agent
- user_arn
- user_group_id
- user_id
- user_name
- vendor
- vendor_account
- vendor_product
- vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId":
"AIDAYTOGP2RLNALZHZ6KX", "arn": "arn:aws:iam::111111111111:user/patrick_cli", "accountId":
"111111111111", "accessKeyId": "AKIAYTOGP2RLJ2OYSF6E", "userName": "patrick_cli"},
"eventTime": "2021-01-12T14:03:17Z", "eventSource": "s3.amazonaws.com", "eventName":
"PutBucketAcl", "awsRegion": "eu-central-1", "sourceIPAddress": "95.90.199.65",
"userAgent": "[aws-cli/2.0.45 Python/3.7.4 Darwin/20.2.0 exe/x86_64 command/s3api.put-bucket-acl]",
"requestParameters": {"bucketName": "patricktestbucket19", "Host": "patricktestbucket19.s3.eu-central-1.amazonaws.com",
"acl": "", "accessControlList": {"x-amz-grant-write-acp": "uri=http://acs.amazonaws.com/groups/global/AuthenticatedUsers"}},
"responseElements": null, "additionalEventData": {"SignatureVersion": "SigV4", "CipherSuite":
"ECDHE-RSA-AES128-GCM-SHA256", "bytesTransferredIn": 0, "AuthenticationMethod":
"AuthHeader", "x-amz-id-2": "qb+xR18y4+4serdq8conds+tNROklOFRYciGHof4z1pcnTnT9SCrx6iYHuupPNaiMnZ9kdB43yE=",
"bytesTransferredOut": 0}, "requestID": "23FAB394417ECFCD", "eventID": "9feee3c9-711f-4f7d-af4c-992907a2a521",
"readOnly": false, "resources": [{"accountId": "111111111111", "type": "AWS::S3::Bucket",
"ARN": "arn:aws:s3:::patricktestbucket19"}], "eventType": "AwsApiCall", "managementEvent":
true, "eventCategory": "Management", "recipientAccountId": "111111111111"}'
@@ -0,0 +1,120 @@
name: AWS CloudTrail PutBucketLifecycle
id: 1c73e954-87b6-4bd7-ac6a-5db7c4082b22
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
description: Data source object for AWS CloudTrail PutBucketLifecycle
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
supported_TA:
- name: Splunk Add-on for Amazon Web Services (AWS)
url: https://splunkbase.splunk.com/app/1876
version: 7.4.1
fields:
- _time
- additionalEventData.AuthenticationMethod
- additionalEventData.CipherSuite
- additionalEventData.SignatureVersion
- additionalEventData.bytesTransferredIn
- additionalEventData.bytesTransferredOut
- additionalEventData.x-amz-id-2
- app
- awsRegion
- aws_account_id
- command
- date_hour
- date_mday
- date_minute
- date_month
- date_second
- date_wday
- date_year
- date_zone
- dest
- dvc
- errorCode
- eventCategory
- eventID
- eventName
- eventSource
- eventTime
- eventType
- eventVersion
- host
- index
- linecount
- managementEvent
- msg
- object
- object_category
- object_id
- product
- punct
- readOnly
- recipientAccountId
- region
- requestID
- requestParameters.Host
- requestParameters.LifecycleConfiguration.Rule.Expiration.Days
- requestParameters.LifecycleConfiguration.Rule.Filter.Prefix
- requestParameters.LifecycleConfiguration.Rule.ID
- requestParameters.LifecycleConfiguration.Rule.Status
- requestParameters.LifecycleConfiguration.xmlns
- requestParameters.bucketName
- requestParameters.lifecycle
- resources{}.ARN
- resources{}.accountId
- resources{}.type
- responseElements
- signature
- source
- sourceIPAddress
- sourcetype
- splunk_server
- src
- src_ip
- start_time
- timeendpos
- timestartpos
- tlsDetails.cipherSuite
- tlsDetails.clientProvidedHostHeader
- tlsDetails.tlsVersion
- user
- userAgent
- userIdentity.accessKeyId
- userIdentity.accountId
- userIdentity.arn
- userIdentity.principalId
- userIdentity.type
- userIdentity.userName
- userName
- user_access_key
- user_agent
- user_arn
- user_group_id
- user_id
- user_name
- user_type
- vendor
- vendor_account
- vendor_product
- vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId":
"AIDAYTOGP2RLEHRX5YWNV", "arn": "arn:aws:iam::111111111111:user/bhavin_cli", "accountId":
"111111111111", "accessKeyId": "AKIAYTOGP2RLKQ3U2PDY", "userName": "bhavin_cli"},
"eventTime": "2022-07-13T21:58:27Z", "eventSource": "s3.amazonaws.com", "eventName":
"PutBucketLifecycle", "awsRegion": "us-west-2", "sourceIPAddress": "192.184.242.57",
"userAgent": "[stratus-red-team_d73089cf-1905-430c-b6d3-4dc4d669190f]", "requestParameters":
{"lifecycle": "", "bucketName": "my-cloudtrail-bucket-alfsujjpnbpguqrh", "LifecycleConfiguration":
{"xmlns": "http://s3.amazonaws.com/doc/2006-03-01/", "Rule": {"Status": "Enabled",
"Filter": {"Prefix": "*"}, "Expiration": {"Days": 1}, "ID": "nuke-cloudtrail-logs-after-1-day"}},
"Host": "my-cloudtrail-bucket-alfsujjpnbpguqrh.s3.us-west-2.amazonaws.com"}, "responseElements":
null, "additionalEventData": {"SignatureVersion": "SigV4", "CipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"bytesTransferredIn": 249, "AuthenticationMethod": "AuthHeader", "x-amz-id-2": "TVXZE5kOVTMLqYlmKK+j/5g6flwkiFXFfw8PyNivFO4/9YXnDsyzFlGEzAy2rukTTiukLdEwtuM=",
"bytesTransferredOut": 0}, "requestID": "1P8X27T2BCMY93Y9", "eventID": "25d92cd1-f366-4b11-b408-967a17ce70f3",
"readOnly": false, "resources": [{"accountId": "111111111111", "type": "AWS::S3::Bucket",
"ARN": "arn:aws:s3:::my-cloudtrail-bucket-alfsujjpnbpguqrh"}], "eventType": "AwsApiCall",
"managementEvent": true, "recipientAccountId": "111111111111", "eventCategory":
"Management", "tlsDetails": {"tlsVersion": "TLSv1.2", "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "my-cloudtrail-bucket-alfsujjpnbpguqrh.s3.us-west-2.amazonaws.com"}}'
@@ -0,0 +1,141 @@
name: AWS CloudTrail PutBucketReplication
id: 0e1362eb-e592-419f-8fa5-556d3a122417
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
description: Data source object for AWS CloudTrail PutBucketReplication
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
supported_TA:
- name: Splunk Add-on for Amazon Web Services (AWS)
url: https://splunkbase.splunk.com/app/1876
version: 7.4.1
fields:
- _time
- additionalEventData.AuthenticationMethod
- additionalEventData.CipherSuite
- additionalEventData.SignatureVersion
- additionalEventData.bytesTransferredIn
- additionalEventData.bytesTransferredOut
- additionalEventData.x-amz-id-2
- app
- awsRegion
- aws_account_id
- command
- date_hour
- date_mday
- date_minute
- date_month
- date_second
- date_wday
- date_year
- date_zone
- dest
- dvc
- errorCode
- eventCategory
- eventID
- eventName
- eventSource
- eventTime
- eventType
- eventVersion
- eventtype
- host
- index
- linecount
- managementEvent
- msg
- object
- object_category
- object_id
- product
- punct
- readOnly
- recipientAccountId
- region
- requestID
- requestParameters.Host
- requestParameters.ReplicationConfiguration.Role
- requestParameters.ReplicationConfiguration.Rule.DeleteMarkerReplication.Status
- requestParameters.ReplicationConfiguration.Rule.Destination.Bucket
- requestParameters.ReplicationConfiguration.Rule.Filter
- requestParameters.ReplicationConfiguration.Rule.ID
- requestParameters.ReplicationConfiguration.Rule.Priority
- requestParameters.ReplicationConfiguration.Rule.Status
- requestParameters.ReplicationConfiguration.xmlns
- requestParameters.bucketName
- requestParameters.replication
- resources{}.ARN
- resources{}.accountId
- resources{}.type
- responseElements
- signature
- source
- sourceIPAddress
- sourcetype
- splunk_server
- src
- src_ip
- start_time
- tag
- tag::eventtype
- timeendpos
- timestartpos
- tlsDetails.cipherSuite
- tlsDetails.clientProvidedHostHeader
- tlsDetails.tlsVersion
- user
- userAgent
- userIdentity.accessKeyId
- userIdentity.accountId
- userIdentity.arn
- userIdentity.principalId
- userIdentity.sessionContext.attributes.creationDate
- userIdentity.sessionContext.attributes.mfaAuthenticated
- userIdentity.sessionContext.sessionIssuer.accountId
- userIdentity.sessionContext.sessionIssuer.arn
- userIdentity.sessionContext.sessionIssuer.principalId
- userIdentity.sessionContext.sessionIssuer.type
- userIdentity.sessionContext.sessionIssuer.userName
- userIdentity.type
- userName
- user_access_key
- user_agent
- user_arn
- user_group_id
- user_id
- user_name
- user_type
- vendor
- vendor_account
- vendor_product
- vendor_region
- vpcEndpointId
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "principalId":
"AROAYTOGP2RLDF6WP4H11:bpatel@splunk.com", "arn": "arn:aws:sts::111111111111:assumed-role/AWSReservedSSO_SPLKAdministratorAccess_d9ce1347d0a6dd3f/bpatel@splunk.com",
"accountId": "111111111111", "accessKeyId": "ASIAYTOGP2RLJOVYQHW2", "sessionContext":
{"sessionIssuer": {"type": "Role", "principalId": "AROAYTOGP2RLDF6WP4H11", "arn":
"arn:aws:iam::111111111111:role/aws-reserved/sso.amazonaws.com/us-west-2/AWSReservedSSO_SPLKAdministratorAccess_d9ce1347d0a6dd3f",
"accountId": "111111111111", "userName": "AWSReservedSSO_SPLKAdministratorAccess_d9ce1347d0a6dd3f"},
"webIdFederationData": {}, "attributes": {"creationDate": "2023-04-24T23:45:42Z",
"mfaAuthenticated": "false"}}}, "eventTime": "2023-04-24T23:49:33Z", "eventSource":
"s3.amazonaws.com", "eventName": "PutBucketReplication", "awsRegion": "us-west-2",
"sourceIPAddress": "23.93.193.6", "userAgent": "[S3Console/0.4, aws-internal/3 aws-sdk-java/1.11.1030
Linux/5.4.238-155.347.amzn2int.x86_64 OpenJDK_64-Bit_Server_VM/25.362-b10 java/1.8.0_362
vendor/Oracle_Corporation cfg/retry-mode/standard]", "requestParameters": {"replication":
"", "bucketName": "git-wild-hunt-results", "Host": "s3.us-west-2.amazonaws.com",
"ReplicationConfiguration": {"Role": "arn:aws:iam::111111111111:role/attack_range_bpatel",
"xmlns": "http://s3.amazonaws.com/doc/2006-03-01/", "Rule": {"Status": "Enabled",
"Destination": {"Bucket": "arn:aws:s3:::badpublicbuckettest"}, "Filter": "", "Priority":
0, "ID": "replication_x_test", "DeleteMarkerReplication": {"Status": "Disabled"}}}},
"responseElements": null, "additionalEventData": {"SignatureVersion": "SigV4", "CipherSuite":
"ECDHE-RSA-AES128-GCM-SHA256", "bytesTransferredIn": 416, "AuthenticationMethod":
"AuthHeader", "x-amz-id-2": "8UoliFe/sG2/v8qB2g763/g0Fy+kfaUqtKrzLHEILnHUisC3rL1dQfJ3NSIYcA/kzpIHQ955pGo=",
"bytesTransferredOut": 0}, "requestID": "14SAVMJNEJMTZN91", "eventID": "fbe079d1-bc6b-4ee0-8893-d2b412c5550f",
"readOnly": false, "resources": [{"accountId": "111111111111", "type": "AWS::S3::Bucket",
"ARN": "arn:aws:s3:::git-wild-hunt-results"}], "eventType": "AwsApiCall", "managementEvent":
true, "recipientAccountId": "111111111111", "vpcEndpointId": "vpce-a0d039c9", "eventCategory":
"Management", "tlsDetails": {"tlsVersion": "TLSv1.2", "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "s3.us-west-2.amazonaws.com"}}'
@@ -0,0 +1,129 @@
name: AWS CloudTrail PutBucketVersioning
id: 17b2fc7d-c8ce-487c-8815-f9a65a09e980
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
description: Data source object for AWS CloudTrail PutBucketVersioning
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
supported_TA:
- name: Splunk Add-on for Amazon Web Services (AWS)
url: https://splunkbase.splunk.com/app/1876
version: 7.4.1
fields:
- _time
- additionalEventData.AuthenticationMethod
- additionalEventData.CipherSuite
- additionalEventData.SignatureVersion
- additionalEventData.bytesTransferredIn
- additionalEventData.bytesTransferredOut
- additionalEventData.x-amz-id-2
- app
- awsRegion
- aws_account_id
- command
- date_hour
- date_mday
- date_minute
- date_month
- date_second
- date_wday
- date_year
- date_zone
- dest
- dvc
- errorCode
- eventCategory
- eventID
- eventName
- eventSource
- eventTime
- eventType
- eventVersion
- host
- index
- linecount
- managementEvent
- msg
- object
- object_category
- object_id
- product
- punct
- readOnly
- recipientAccountId
- region
- requestID
- requestParameters.Host
- requestParameters.VersioningConfiguration.Status
- requestParameters.VersioningConfiguration.xmlns
- requestParameters.bucketName
- requestParameters.versioning
- resources{}.ARN
- resources{}.accountId
- resources{}.type
- responseElements
- signature
- source
- sourceIPAddress
- sourcetype
- splunk_server
- src
- src_ip
- start_time
- timeendpos
- timestartpos
- tlsDetails.cipherSuite
- tlsDetails.clientProvidedHostHeader
- tlsDetails.tlsVersion
- user
- userAgent
- userIdentity.accessKeyId
- userIdentity.accountId
- userIdentity.arn
- userIdentity.principalId
- userIdentity.sessionContext.attributes.creationDate
- userIdentity.sessionContext.attributes.mfaAuthenticated
- userIdentity.sessionContext.sessionIssuer.accountId
- userIdentity.sessionContext.sessionIssuer.arn
- userIdentity.sessionContext.sessionIssuer.principalId
- userIdentity.sessionContext.sessionIssuer.type
- userIdentity.sessionContext.sessionIssuer.userName
- userIdentity.type
- userName
- user_access_key
- user_agent
- user_arn
- user_group_id
- user_id
- user_name
- user_type
- vendor
- vendor_account
- vendor_product
- vendor_region
- vpcEndpointId
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "principalId":
"AROAYTOGP2RLDF6WP4HD6:daftpunk@splunk.com", "arn": "arn:aws:sts::111111111111:assumed-role/AWSReservedSSO_SPLKAdministratorAccess_d9ce1347d0a6dd3f/daftpunk@splunk.com",
"accountId": "111111111111", "accessKeyId": "ASIAYTOGP2RLAQ5VXXXX", "sessionContext":
{"sessionIssuer": {"type": "Role", "principalId": "AROAYTOGP2RLDF6WP4HD6", "arn":
"arn:aws:iam::111111111111:role/aws-reserved/sso.amazonaws.com/us-west-2/AWSReservedSSO_SPLKAdministratorAccess_d9ce1347d0a6dd3f",
"accountId": "111111111111", "userName": "AWSReservedSSO_SPLKAdministratorAccess_d9ce1347d0a6dd3f"},
"webIdFederationData": {}, "attributes": {"creationDate": "2022-08-04T15:18:37Z",
"mfaAuthenticated": "false"}}}, "eventTime": "2022-08-04T15:19:25Z", "eventSource":
"s3.amazonaws.com", "eventName": "PutBucketVersioning", "awsRegion": "us-west-2",
"sourceIPAddress": "73.57.168.38", "userAgent": "[S3Console/0.4, aws-internal/3
aws-sdk-java/1.11.1030 Linux/5.4.196-119.356.amzn2int.x86_64 OpenJDK_64-Bit_Server_VM/25.302-b08
java/1.8.0_302 vendor/Oracle_Corporation cfg/retry-mode/standard]", "requestParameters":
{"bucketName": "git-wild-hunt-results", "Host": "s3.us-west-2.amazonaws.com", "versioning":
"", "VersioningConfiguration": {"Status": "Suspended", "xmlns": "http://s3.amazonaws.com/doc/2006-03-01/"}},
"responseElements": null, "additionalEventData": {"SignatureVersion": "SigV4", "CipherSuite":
"ECDHE-RSA-AES128-GCM-SHA256", "bytesTransferredIn": 125, "AuthenticationMethod":
"AuthHeader", "x-amz-id-2": "F3tJSu/C2DMkRNLldcWTRzApxQa6v197ImcuQDA++vaeaLj9UvcIkEFgDIrMYUdXLI4t+Uih5hk=",
"bytesTransferredOut": 0}, "requestID": "5KXZDSNDYXWC8Q4M", "eventID": "42d7a97e-9d35-4c8e-8d0a-4a82d91aab55",
"readOnly": false, "resources": [{"accountId": "111111111111", "type": "AWS::S3::Bucket",
"ARN": "arn:aws:s3:::git-wild-hunt-results"}], "eventType": "AwsApiCall", "managementEvent":
true, "recipientAccountId": "111111111111", "vpcEndpointId": "vpce-a0d039c9", "eventCategory":
"Management", "tlsDetails": {"tlsVersion": "TLSv1.2", "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "s3.us-west-2.amazonaws.com"}}'
+151
View File
@@ -0,0 +1,151 @@
name: AWS CloudTrail PutImage
id: bb13f10d-0d8c-4fde-9136-b7cfd930e87c
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
description: Data source object for AWS CloudTrail PutImage
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
supported_TA:
- name: Splunk Add-on for Amazon Web Services (AWS)
url: https://splunkbase.splunk.com/app/1876
version: 7.4.1
fields:
- _time
- app
- awsRegion
- aws_account_id
- command
- date_hour
- date_mday
- date_minute
- date_month
- date_second
- date_wday
- date_year
- date_zone
- dest
- dvc
- errorCode
- eventCategory
- eventID
- eventName
- eventSource
- eventTime
- eventType
- eventVersion
- host
- index
- linecount
- managementEvent
- msg
- object_category
- product
- punct
- readOnly
- recipientAccountId
- region
- requestID
- requestParameters.imageManifest
- requestParameters.imageManifestMediaType
- requestParameters.imageTag
- requestParameters.registryId
- requestParameters.repositoryName
- resources{}.ARN
- resources{}.accountId
- responseElements.image.imageId.imageDigest
- responseElements.image.imageId.imageTag
- responseElements.image.imageManifest
- responseElements.image.imageManifestMediaType
- responseElements.image.registryId
- responseElements.image.repositoryName
- signature
- source
- sourceIPAddress
- sourcetype
- splunk_server
- src
- src_ip
- start_time
- timeendpos
- timestartpos
- user
- userAgent
- userIdentity.accessKeyId
- userIdentity.accountId
- userIdentity.arn
- userIdentity.invokedBy
- userIdentity.principalId
- userIdentity.sessionContext.attributes.creationDate
- userIdentity.sessionContext.attributes.mfaAuthenticated
- userIdentity.type
- userIdentity.userName
- userName
- user_access_key
- user_agent
- user_arn
- user_group_id
- user_id
- user_name
- user_type
- vendor
- vendor_account
- vendor_product
- vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId":
"AAAAAAAAAAAAAAAAAAAAA", "arn": "arn:aws:iam::111111111111:user/test", "accountId":
"111111111111", "accessKeyId": "AAAAAAAAAAAAAAAAAAAAA", "userName": "test", "sessionContext":
{"sessionIssuer": {}, "webIdFederationData": {}, "attributes": {"creationDate":
"2021-08-18T23:15:39Z", "mfaAuthenticated": "false"}}, "invokedBy": "AWS Internal"},
"eventTime": "2021-08-18T23:17:30Z", "eventSource": "ecr.amazonaws.com", "eventName":
"PutImage", "awsRegion": "eu-central-1", "sourceIPAddress": "AWS Internal", "userAgent":
"AWS Internal", "requestParameters": {"registryId": "111111111112", "repositoryName":
"devsecops/cat_dog_server", "imageManifest": "{\n \"schemaVersion\": 2,\n \"mediaType\":
\"application/vnd.docker.distribution.manifest.v2+json\",\n \"config\": {\n \"mediaType\":
\"application/vnd.docker.container.image.v1+json\",\n \"size\": 6591,\n \"digest\":
\"sha256:547fc07c53533763d68ebdfdc45529b1db45301d07824410bcc30df866d67df1\"\n },\n \"layers\":
[\n {\n \"mediaType\": \"application/vnd.docker.image.rootfs.diff.tar.gzip\",\n \"size\":
2811969,\n \"digest\": \"sha256:540db60ca9383eac9e418f78490994d0af424aab7bf6d0e47ac8ed4e2e9bcbba\"\n },\n {\n \"mediaType\":
\"application/vnd.docker.image.rootfs.diff.tar.gzip\",\n \"size\": 35426616,\n \"digest\":
\"sha256:f4fa1ac42c97abe89e0cc807af0ae4b63fbec2a5209a75a7239d099702c7fd80\"\n },\n {\n \"mediaType\":
\"application/vnd.docker.image.rootfs.diff.tar.gzip\",\n \"size\": 2347076,\n \"digest\":
\"sha256:2b3e10d0c87c453eed1378e102ff1cc17aa4e3eed2159b7505959777a6225059\"\n },\n {\n \"mediaType\":
\"application/vnd.docker.image.rootfs.diff.tar.gzip\",\n \"size\": 280,\n \"digest\":
\"sha256:43bd2fc3ba418e309449b8c82d723d9069ebb81863050dc0d6ad6e6ec0683808\"\n },\n {\n \"mediaType\":
\"application/vnd.docker.image.rootfs.diff.tar.gzip\",\n \"size\": 92,\n \"digest\":
\"sha256:803d6b58954d4daee18ed071281627f8214f3d2ba1b9a419ab8834029310942a\"\n },\n {\n \"mediaType\":
\"application/vnd.docker.image.rootfs.diff.tar.gzip\",\n \"size\": 373,\n \"digest\":
\"sha256:e664d5491b5c81e901a2293fbc025532a7cae0dcc75ce7418f854209aaa2474c\"\n },\n {\n \"mediaType\":
\"application/vnd.docker.image.rootfs.diff.tar.gzip\",\n \"size\": 2383293,\n \"digest\":
\"sha256:b827c586a783ce490b79907607d535f99f42360b6ba86a4b2ac3e7f01542144d\"\n },\n {\n \"mediaType\":
\"application/vnd.docker.image.rootfs.diff.tar.gzip\",\n \"size\": 10001,\n \"digest\":
\"sha256:0dd85ef396bcaded88fab4a8079d6b8bd5e3f8cf7eeb9b93306ffdb63401ba0a\"\n }\n ]\n}",
"imageManifestMediaType": "application/vnd.docker.distribution.manifest.v2+json",
"imageTag": "latest"}, "responseElements": {"image": {"registryId": "111111111112",
"repositoryName": "devsecops/cat_dog_server", "imageId": {"imageDigest": "sha256:b7798f35949cc1a2d435c9ac59ab69e857fe635a359c96e4f56a8498ce02019c",
"imageTag": "latest"}, "imageManifest": "{\n \"schemaVersion\": 2,\n \"mediaType\":
\"application/vnd.docker.distribution.manifest.v2+json\",\n \"config\": {\n \"mediaType\":
\"application/vnd.docker.container.image.v1+json\",\n \"size\": 6591,\n \"digest\":
\"sha256:547fc07c53533763d68ebdfdc45529b1db45301d07824410bcc30df866d67df1\"\n },\n \"layers\":
[\n {\n \"mediaType\": \"application/vnd.docker.image.rootfs.diff.tar.gzip\",\n \"size\":
2811969,\n \"digest\": \"sha256:540db60ca9383eac9e418f78490994d0af424aab7bf6d0e47ac8ed4e2e9bcbba\"\n },\n {\n \"mediaType\":
\"application/vnd.docker.image.rootfs.diff.tar.gzip\",\n \"size\": 35426616,\n \"digest\":
\"sha256:f4fa1ac42c97abe89e0cc807af0ae4b63fbec2a5209a75a7239d099702c7fd80\"\n },\n {\n \"mediaType\":
\"application/vnd.docker.image.rootfs.diff.tar.gzip\",\n \"size\": 2347076,\n \"digest\":
\"sha256:2b3e10d0c87c453eed1378e102ff1cc17aa4e3eed2159b7505959777a6225059\"\n },\n {\n \"mediaType\":
\"application/vnd.docker.image.rootfs.diff.tar.gzip\",\n \"size\": 280,\n \"digest\":
\"sha256:43bd2fc3ba418e309449b8c82d723d9069ebb81863050dc0d6ad6e6ec0683808\"\n },\n {\n \"mediaType\":
\"application/vnd.docker.image.rootfs.diff.tar.gzip\",\n \"size\": 92,\n \"digest\":
\"sha256:803d6b58954d4daee18ed071281627f8214f3d2ba1b9a419ab8834029310942a\"\n },\n {\n \"mediaType\":
\"application/vnd.docker.image.rootfs.diff.tar.gzip\",\n \"size\": 373,\n \"digest\":
\"sha256:e664d5491b5c81e901a2293fbc025532a7cae0dcc75ce7418f854209aaa2474c\"\n },\n {\n \"mediaType\":
\"application/vnd.docker.image.rootfs.diff.tar.gzip\",\n \"size\": 2383293,\n \"digest\":
\"sha256:b827c586a783ce490b79907607d535f99f42360b6ba86a4b2ac3e7f01542144d\"\n },\n {\n \"mediaType\":
\"application/vnd.docker.image.rootfs.diff.tar.gzip\",\n \"size\": 10001,\n \"digest\":
\"sha256:0dd85ef396bcaded88fab4a8079d6b8bd5e3f8cf7eeb9b93306ffdb63401ba0a\"\n }\n ]\n}",
"imageManifestMediaType": "application/vnd.docker.distribution.manifest.v2+json"}},
"requestID": "805a31e6-0fed-433b-b393-f463c6881334", "eventID": "1aef3588-ae84-4f1f-9276-8ec94ee6a7e9",
"readOnly": false, "resources": [{"accountId": "111111111111", "ARN": "arn:aws:ecr:eu-central-1:1111111111111:repository/devsecops/cat_dog_server"}],
"eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId": "111111111111",
"eventCategory": "Management"}'
@@ -0,0 +1,132 @@
name: AWS CloudTrail PutKeyPolicy
id: 9c54c86b-43b9-4bb8-915d-6838beb7f07c
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
description: Data source object for AWS CloudTrail PutKeyPolicy
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
supported_TA:
- name: Splunk Add-on for Amazon Web Services (AWS)
url: https://splunkbase.splunk.com/app/1876
version: 7.4.1
fields:
- _time
- app
- awsRegion
- aws_account_id
- command
- date_hour
- date_mday
- date_minute
- date_month
- date_second
- date_wday
- date_year
- date_zone
- dest
- dvc
- errorCode
- eventCategory
- eventID
- eventName
- eventSource
- eventTime
- eventType
- eventVersion
- eventtype
- host
- index
- linecount
- managementEvent
- msg
- object_category
- product
- punct
- readOnly
- recipientAccountId
- region
- requestID
- requestParameters.bypassPolicyLockoutSafetyCheck
- requestParameters.keyId
- requestParameters.policy
- requestParameters.policyName
- resources{}.ARN
- resources{}.accountId
- resources{}.type
- responseElements
- signature
- source
- sourceIPAddress
- sourcetype
- splunk_server
- src
- src_ip
- start_time
- tag
- tag::eventtype
- timeendpos
- timestartpos
- user
- userAgent
- userIdentity.accessKeyId
- userIdentity.accountId
- userIdentity.arn
- userIdentity.principalId
- userIdentity.sessionContext.attributes.creationDate
- userIdentity.sessionContext.attributes.mfaAuthenticated
- userIdentity.sessionContext.sessionIssuer.accountId
- userIdentity.sessionContext.sessionIssuer.arn
- userIdentity.sessionContext.sessionIssuer.principalId
- userIdentity.sessionContext.sessionIssuer.type
- userIdentity.sessionContext.sessionIssuer.userName
- userIdentity.type
- userName
- user_access_key
- user_agent
- user_arn
- user_group_id
- user_id
- user_name
- user_type
- vendor
- vendor_account
- vendor_product
- vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "principalId":
"AROAIJIESMXKGCJRCTPR6:pbareiss@splunk.local", "arn": "arn:aws:sts::111111111111:assumed-role/okta_adm_role/pbareiss@splunk.local",
"accountId": "111111111111", "accessKeyId": "ASIAYTOGP2RLK74OPBDR", "sessionContext":
{"sessionIssuer": {"type": "Role", "principalId": "AROAIJIESMXKGCJRCTPR6", "arn":
"arn:aws:iam::111111111111:role/okta_adm_role", "accountId": "111111111111", "userName":
"okta_adm_role"}, "webIdFederationData": {}, "attributes": {"mfaAuthenticated":
"false", "creationDate": "2021-01-11T09:03:18Z"}}}, "eventTime": "2021-01-11T11:04:39Z",
"eventSource": "kms.amazonaws.com", "eventName": "PutKeyPolicy", "awsRegion": "us-west-2",
"sourceIPAddress": "95.90.199.65", "userAgent": "aws-internal/3 aws-sdk-java/1.11.893
Linux/4.9.230-0.1.ac.223.84.332.metal1.x86_64 OpenJDK_64-Bit_Server_VM/25.272-b10
java/1.8.0_272 vendor/Oracle_Corporation", "requestParameters": {"keyId": "f2a82583-a7d3-4c92-8787-fe2baab1cee1",
"policyName": "default", "policy": "{\n \"Version\": \"2012-10-17\",\n \"Id\":
\"key-consolepolicy-3\",\n \"Statement\": [\n {\n \"Sid\":
\"Enable IAM User Permissions\",\n \"Effect\": \"Allow\",\n \"Principal\":
{\n \"AWS\": \"arn:aws:iam::111111111111:root\"\n },\n \"Action\":
\"kms:*\",\n \"Resource\": \"*\"\n },\n {\n \"Sid\":
\"Allow access for Key Administrators\",\n \"Effect\": \"Allow\",\n \"Principal\":
{\n \"AWS\": \"arn:aws:iam::111111111111:user/patrick_cli\"\n },\n \"Action\":
[\n \"kms:Create*\",\n \"kms:Describe*\",\n \"kms:Enable*\",\n \"kms:List*\",\n \"kms:Put*\",\n \"kms:Update*\",\n \"kms:Revoke*\",\n \"kms:Disable*\",\n \"kms:Get*\",\n \"kms:Delete*\",\n \"kms:TagResource\",\n \"kms:UntagResource\",\n \"kms:ScheduleKeyDeletion\",\n \"kms:CancelKeyDeletion\"\n ],\n \"Resource\":
\"*\"\n },\n {\n \"Sid\": \"Allow use of the key\",\n \"Effect\":
\"Allow\",\n \"Principal\": {\n \"AWS\": \"arn:aws:iam::111111111111:user/patrick_cli\"\n },\n \"Action\":
[\n \"kms:Encrypt\",\n \"kms:Decrypt\",\n \"kms:ReEncrypt*\",\n \"kms:GenerateDataKey*\",\n \"kms:DescribeKey\"\n ],\n \"Resource\":
\"*\"\n },\n {\n \"Sid\": \"Allow attachment of persistent
resources\",\n \"Effect\": \"Allow\",\n \"Principal\": {\n \"AWS\":
\"arn:aws:iam::111111111111:user/patrick_cli\"\n },\n \"Action\":
[\n \"kms:CreateGrant\",\n \"kms:ListGrants\",\n \"kms:RevokeGrant\"\n ],\n \"Resource\":
\"*\",\n \"Condition\": {\n \"Bool\": {\n \"kms:GrantIsForAWSResource\":
\"true\"\n }\n }\n },\n {\n \"Sid\":
\"Allow use of the key\",\n \"Effect\": \"Allow\",\n \"Principal\":
{\n \"AWS\": \"*\"\n },\n \"Action\": [\n \"kms:Encrypt\"\n ],\n \"Resource\":
\"*\"\n }\n ]\n}", "bypassPolicyLockoutSafetyCheck": false}, "responseElements":
null, "requestID": "c7836c7a-ca95-47aa-a3fb-a7db0d66fec8", "eventID": "612f17e3-2317-4dd9-8aa3-393bc8a7961b",
"readOnly": false, "resources": [{"accountId": "111111111111", "type": "AWS::KMS::Key",
"ARN": "arn:aws:kms:us-west-2:111111111111:key/f2a82583-a7d3-4c92-8787-fe2baab1cee1"}],
"eventType": "AwsApiCall", "managementEvent": true, "eventCategory": "Management",
"recipientAccountId": "111111111111"}'
@@ -0,0 +1,118 @@
name: AWS CloudTrail ReplaceNetworkAclEntry
id: db0c240e-3754-40e4-86ef-cde018ee9f65
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
description: Data source object for AWS CloudTrail ReplaceNetworkAclEntry
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
supported_TA:
- name: Splunk Add-on for Amazon Web Services (AWS)
url: https://splunkbase.splunk.com/app/1876
version: 7.4.1
fields:
- _time
- action
- app
- awsRegion
- aws_account_id
- change_type
- command
- date_hour
- date_mday
- date_minute
- date_month
- date_second
- date_wday
- date_year
- date_zone
- direction
- dvc
- errorCode
- eventCategory
- eventID
- eventName
- eventSource
- eventTime
- eventType
- eventVersion
- eventtype
- host
- index
- linecount
- managementEvent
- msg
- object_category
- product
- protocol
- protocol_code
- punct
- readOnly
- recipientAccountId
- region
- requestID
- requestParameters.aclProtocol
- requestParameters.cidrBlock
- requestParameters.egress
- requestParameters.networkAclId
- requestParameters.ruleAction
- requestParameters.ruleNumber
- responseElements._return
- responseElements.requestId
- rule_action
- signature
- source
- sourceIPAddress
- sourcetype
- splunk_server
- src
- src_ip
- src_ip_range
- start_time
- status
- tag
- tag::eventtype
- timeendpos
- timestartpos
- user
- userAgent
- userIdentity.accessKeyId
- userIdentity.accountId
- userIdentity.arn
- userIdentity.principalId
- userIdentity.sessionContext.attributes.creationDate
- userIdentity.sessionContext.attributes.mfaAuthenticated
- userIdentity.sessionContext.sessionIssuer.accountId
- userIdentity.sessionContext.sessionIssuer.arn
- userIdentity.sessionContext.sessionIssuer.principalId
- userIdentity.sessionContext.sessionIssuer.type
- userIdentity.sessionContext.sessionIssuer.userName
- userIdentity.type
- userName
- user_access_key
- user_agent
- user_arn
- user_group_id
- user_id
- user_name
- user_type
- vendor
- vendor_account
- vendor_product
- vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "principalId":
"AROAIJIESMXKGCJRCTPR6:pbareiss@splunk.local", "arn": "arn:aws:sts::111111111111:assumed-role/okta_adm_role/pbareiss@splunk.local",
"accountId": "111111111111", "accessKeyId": "ASIAYTOGP2RLF3F7BXZK", "sessionContext":
{"sessionIssuer": {"type": "Role", "principalId": "AROAIJIESMXKGCJRCTPR6", "arn":
"arn:aws:iam::111111111111:role/okta_adm_role", "accountId": "111111111111", "userName":
"okta_adm_role"}, "webIdFederationData": {}, "attributes": {"mfaAuthenticated":
"false", "creationDate": "2021-01-12T08:36:15Z"}}}, "eventTime": "2021-01-12T08:49:49Z",
"eventSource": "ec2.amazonaws.com", "eventName": "ReplaceNetworkAclEntry", "awsRegion":
"eu-central-1", "sourceIPAddress": "95.90.199.65", "userAgent": "console.ec2.amazonaws.com",
"requestParameters": {"networkAclId": "acl-078ccebebcbabe175", "ruleNumber": 20,
"egress": false, "ruleAction": "allow", "icmpTypeCode": {}, "portRange": {}, "aclProtocol":
"-1", "cidrBlock": "0.0.0.0/0"}, "responseElements": {"requestId": "97b40da9-9291-4a92-8e9e-892b6887ffc9",
"_return": true}, "requestID": "97b40da9-9291-4a92-8e9e-892b6887ffc9", "eventID":
"46fe04b8-d007-4933-8bb8-c8b65c1121fa", "readOnly": false, "eventType": "AwsApiCall",
"managementEvent": true, "eventCategory": "Management", "recipientAccountId": "111111111111"}'
@@ -0,0 +1,99 @@
name: AWS CloudTrail SetDefaultPolicyVersion
id: 06e0b5a0-8d36-485e-befc-4ae79d77ef6c
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
description: Data source object for AWS CloudTrail SetDefaultPolicyVersion
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
supported_TA:
- name: Splunk Add-on for Amazon Web Services (AWS)
url: https://splunkbase.splunk.com/app/1876
version: 7.4.1
fields:
- _time
- action
- app
- awsRegion
- aws_account_id
- change_type
- command
- date_hour
- date_mday
- date_minute
- date_month
- date_second
- date_wday
- date_year
- date_zone
- dest
- dvc
- errorCode
- eventCategory
- eventID
- eventName
- eventSource
- eventTime
- eventType
- eventVersion
- eventtype
- host
- index
- linecount
- managementEvent
- msg
- object_category
- product
- punct
- readOnly
- recipientAccountId
- region
- requestID
- requestParameters.policyArn
- requestParameters.versionId
- responseElements
- signature
- source
- sourceIPAddress
- sourcetype
- splunk_server
- src
- src_ip
- start_time
- status
- tag
- tag::eventtype
- timeendpos
- timestartpos
- user
- userAgent
- userIdentity.accessKeyId
- userIdentity.accountId
- userIdentity.arn
- userIdentity.principalId
- userIdentity.type
- userIdentity.userName
- userName
- user_access_key
- user_agent
- user_arn
- user_group_id
- user_id
- user_name
- user_type
- vendor
- vendor_account
- vendor_product
- vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId":
"AIDAYTOGP2RLESDK2NOSX", "arn": "arn:aws:iam::111111111111:user/AtomicRedTeam",
"accountId": "111111111111", "accessKeyId": "AKIAYTOGP2RLKMZDMPVA", "userName":
"AtomicRedTeam"}, "eventTime": "2021-03-02T21:05:49Z", "eventSource": "iam.amazonaws.com",
"eventName": "SetDefaultPolicyVersion", "awsRegion": "us-east-1", "sourceIPAddress":
"73.15.72.101", "userAgent": "aws-cli/2.0.62 Python/3.9.0 Darwin/19.6.0 source/x86_64
command/iam.set-default-policy-version", "requestParameters": {"policyArn": "arn:aws:iam::111111111111:policy/VulnerablePolicy",
"versionId": "v1"}, "responseElements": null, "requestID": "3bdf8738-2eab-4ae8-a858-2e2a4ccfc66b",
"eventID": "742f6e55-4bc7-49e2-965f-56ffbc46a980", "readOnly": false, "eventType":
"AwsApiCall", "managementEvent": true, "eventCategory": "Management", "recipientAccountId":
"111111111111"}'
@@ -0,0 +1,95 @@
name: AWS CloudTrail StopLogging
id: c5de7c54-4809-4659-bf9f-3bacf8bdfd35
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
description: Data source object for AWS CloudTrail StopLogging
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
supported_TA:
- name: Splunk Add-on for Amazon Web Services (AWS)
url: https://splunkbase.splunk.com/app/1876
version: 7.4.1
fields:
- _time
- app
- awsRegion
- aws_account_id
- command
- date_hour
- date_mday
- date_minute
- date_month
- date_second
- date_wday
- date_year
- date_zone
- dest
- dvc
- errorCode
- eventCategory
- eventID
- eventName
- eventSource
- eventTime
- eventType
- eventVersion
- host
- index
- linecount
- managementEvent
- msg
- object_category
- product
- punct
- readOnly
- recipientAccountId
- region
- requestID
- requestParameters.name
- responseElements
- signature
- source
- sourceIPAddress
- sourcetype
- splunk_server
- src
- src_ip
- start_time
- timeendpos
- timestartpos
- tlsDetails.cipherSuite
- tlsDetails.clientProvidedHostHeader
- tlsDetails.tlsVersion
- user
- userAgent
- userIdentity.accessKeyId
- userIdentity.accountId
- userIdentity.arn
- userIdentity.principalId
- userIdentity.type
- userIdentity.userName
- userName
- user_access_key
- user_agent
- user_arn
- user_group_id
- user_id
- user_name
- user_type
- vendor
- vendor_account
- vendor_product
- vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId":
"AIDAYTOGP2RLEHRX5YWNV", "arn": "arn:aws:iam::111111111111:user/bhavin_cli", "accountId":
"111111111111", "accessKeyId": "AKIAYTOGP2RLKQ3U2PDY", "userName": "bhavin_cli"},
"eventTime": "2022-06-30T21:26:49Z", "eventSource": "cloudtrail.amazonaws.com",
"eventName": "StopLogging", "awsRegion": "us-west-2", "sourceIPAddress": "72.193.184.209",
"userAgent": "stratus-red-team_a6a8f8f2-d560-4062-bd0d-c232130cfcc5", "requestParameters":
{"name": "my-cloudtrail-trail"}, "responseElements": null, "requestID": "d8b79caa-08d2-4f7e-b93a-73bb7b85f260",
"eventID": "9f8d2b82-6e9d-45b8-9055-78d8c00ca416", "readOnly": false, "eventType":
"AwsApiCall", "managementEvent": true, "recipientAccountId": "111111111111", "eventCategory":
"Management", "tlsDetails": {"tlsVersion": "TLSv1.2", "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "cloudtrail.us-west-2.amazonaws.com"}}'
@@ -0,0 +1,107 @@
name: AWS CloudTrail UpdateAccountPasswordPolicy
id: 35a8cc97-3600-40e1-a5d1-1c2ad5060be0
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
description: Data source object for AWS CloudTrail UpdateAccountPasswordPolicy
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
supported_TA:
- name: Splunk Add-on for Amazon Web Services (AWS)
url: https://splunkbase.splunk.com/app/1876
version: 7.4.1
fields:
- _time
- action
- app
- awsRegion
- aws_account_id
- change_type
- command
- date_hour
- date_mday
- date_minute
- date_month
- date_second
- date_wday
- date_year
- date_zone
- dest
- dvc
- errorCode
- eventCategory
- eventID
- eventName
- eventSource
- eventTime
- eventType
- eventVersion
- eventtype
- host
- index
- linecount
- managementEvent
- msg
- object_category
- product
- punct
- readOnly
- recipientAccountId
- region
- requestID
- requestParameters.allowUsersToChangePassword
- requestParameters.hardExpiry
- requestParameters.minimumPasswordLength
- requestParameters.requireLowercaseCharacters
- requestParameters.requireNumbers
- requestParameters.requireSymbols
- requestParameters.requireUppercaseCharacters
- responseElements
- sessionCredentialFromConsole
- signature
- source
- sourceIPAddress
- sourcetype
- splunk_server
- src
- src_ip
- start_time
- status
- tag
- tag::eventtype
- timeendpos
- timestartpos
- user
- userAgent
- userIdentity.accessKeyId
- userIdentity.accountId
- userIdentity.arn
- userIdentity.principalId
- userIdentity.sessionContext.attributes.creationDate
- userIdentity.sessionContext.attributes.mfaAuthenticated
- userIdentity.type
- userName
- user_access_key
- user_agent
- user_arn
- user_group_id
- user_id
- user_name
- user_type
- vendor
- vendor_account
- vendor_product
- vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "Root", "principalId":
"111111111111", "arn": "arn:aws:iam::111111111111:root", "accountId": "111111111111",
"accessKeyId": "ASIASBMSCQHHZZ4THONS", "sessionContext": {"sessionIssuer": {}, "webIdFederationData":
{}, "attributes": {"creationDate": "2023-01-26T22:10:41Z", "mfaAuthenticated": "false"}}},
"eventTime": "2023-01-26T22:38:59Z", "eventSource": "iam.amazonaws.com", "eventName":
"UpdateAccountPasswordPolicy", "awsRegion": "us-east-1", "sourceIPAddress": "23.93.193.7",
"userAgent": "AWS Internal", "requestParameters": {"minimumPasswordLength": 6, "requireSymbols":
true, "requireNumbers": false, "requireUppercaseCharacters": false, "requireLowercaseCharacters":
false, "allowUsersToChangePassword": false, "hardExpiry": false}, "responseElements":
null, "requestID": "7685efa9-5c56-451a-bd25-3db520108589", "eventID": "ccc1d5c2-dd72-4798-8023-ed5a4205f2d5",
"readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId":
"111111111111", "eventCategory": "Management", "sessionCredentialFromConsole": "true"}'
@@ -0,0 +1,97 @@
name: AWS CloudTrail UpdateLoginProfile
id: 1db79158-e5d3-4d35-9d3c-586e44e09f1c
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
description: Data source object for AWS CloudTrail UpdateLoginProfile
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
supported_TA:
- name: Splunk Add-on for Amazon Web Services (AWS)
url: https://splunkbase.splunk.com/app/1876
version: 7.4.1
fields:
- _time
- action
- app
- awsRegion
- aws_account_id
- change_type
- command
- date_hour
- date_mday
- date_minute
- date_month
- date_second
- date_wday
- date_year
- date_zone
- dest
- dvc
- errorCode
- eventCategory
- eventID
- eventName
- eventSource
- eventTime
- eventType
- eventVersion
- eventtype
- host
- index
- linecount
- managementEvent
- msg
- object_category
- product
- punct
- readOnly
- recipientAccountId
- region
- requestID
- requestParameters.userName
- responseElements
- signature
- source
- sourceIPAddress
- sourcetype
- splunk_server
- src
- src_ip
- start_time
- status
- tag
- tag::eventtype
- timeendpos
- timestartpos
- user
- userAgent
- userIdentity.accessKeyId
- userIdentity.accountId
- userIdentity.arn
- userIdentity.principalId
- userIdentity.type
- userIdentity.userName
- userName
- user_access_key
- user_agent
- user_arn
- user_group_id
- user_id
- user_name
- user_type
- vendor
- vendor_account
- vendor_product
- vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId":
"AIDAYTOGP2RLEHRX5YWNV", "arn": "arn:aws:iam::111111111111:user/bhavin_cli", "accountId":
"111111111111", "accessKeyId": "AKIAYTOGP2RLLAA6NJUM", "userName": "bhavin_cli"},
"eventTime": "2021-03-05T01:02:59Z", "eventSource": "iam.amazonaws.com", "eventName":
"UpdateLoginProfile", "awsRegion": "us-east-1", "sourceIPAddress": "73.15.72.101",
"userAgent": "aws-cli/2.0.62 Python/3.9.2 Darwin/19.6.0 source/x86_64 command/iam.update-login-profile",
"requestParameters": {"userName": "AtomicRedTeam"}, "responseElements": null, "requestID":
"08f38478-1749-4fb5-b07c-469d3448777a", "eventID": "033580e7-bbba-4b70-be63-7eeddb04b842",
"readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "eventCategory":
"Management", "recipientAccountId": "111111111111"}'
@@ -0,0 +1,187 @@
name: AWS CloudTrail UpdateSAMLProvider
id: e5eb628d-711e-499c-87d9-8fa5dee419ec
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
description: Data source object for AWS CloudTrail UpdateSAMLProvider
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
supported_TA:
- name: Splunk Add-on for Amazon Web Services (AWS)
url: https://splunkbase.splunk.com/app/1876
version: 7.4.1
fields:
- _time
- action
- app
- awsRegion
- aws_account_id
- change_type
- command
- date_hour
- date_mday
- date_minute
- date_month
- date_second
- date_wday
- date_year
- date_zone
- dest
- dvc
- errorCode
- eventCategory
- eventID
- eventName
- eventSource
- eventTime
- eventType
- eventVersion
- eventtype
- host
- index
- linecount
- managementEvent
- msg
- object_category
- product
- punct
- readOnly
- recipientAccountId
- region
- requestID
- requestParameters.sAMLMetadataDocument
- requestParameters.sAMLProviderArn
- responseElements.sAMLProviderArn
- signature
- source
- sourceIPAddress
- sourcetype
- splunk_server
- src
- src_ip
- start_time
- status
- tag
- tag::eventtype
- timeendpos
- timestartpos
- user
- userAgent
- userIdentity.accessKeyId
- userIdentity.accountId
- userIdentity.arn
- userIdentity.principalId
- userIdentity.sessionContext.attributes.creationDate
- userIdentity.sessionContext.attributes.mfaAuthenticated
- userIdentity.sessionContext.sessionIssuer.accountId
- userIdentity.sessionContext.sessionIssuer.arn
- userIdentity.sessionContext.sessionIssuer.principalId
- userIdentity.sessionContext.sessionIssuer.type
- userIdentity.sessionContext.sessionIssuer.userName
- userIdentity.type
- userName
- user_access_key
- user_agent
- user_arn
- user_group_id
- user_id
- user_name
- user_type
- vendor
- vendor_account
- vendor_product
- vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "principalId":
"AROAYTOGP2RLKFUVAQAIJ:rodsoto@rodsoto.onmicrosoft.com", "arn": "arn:aws:sts::111111111111:assumed-role/rodonmicrotestrole/rodsoto@rodsoto.onmicrosoft.com",
"accountId": "111111111111", "accessKeyId": "ASIAYTOGP2RLMZGPIW6C", "sessionContext":
{"sessionIssuer": {"type": "Role", "principalId": "AROAYTOGP2RLKFUVAQAIJ", "arn":
"arn:aws:iam::111111111111:role/rodonmicrotestrole", "accountId": "111111111111",
"userName": "rodonmicrotestrole"}, "webIdFederationData": {}, "attributes": {"mfaAuthenticated":
"false", "creationDate": "2021-01-20T03:10:32Z"}}}, "eventTime": "2021-01-20T03:12:39Z",
"eventSource": "iam.amazonaws.com", "eventName": "UpdateSAMLProvider", "awsRegion":
"us-east-1", "sourceIPAddress": "66.176.252.11", "userAgent": "aws-internal/3 aws-sdk-java/1.11.930
Linux/4.9.230-0.1.ac.223.84.332.metal1.x86_64 OpenJDK_64-Bit_Server_VM/25.275-b01
java/1.8.0_275 vendor/Oracle_Corporation", "requestParameters": {"sAMLMetadataDocument":
"<?xml version=\"1.0\" encoding=\"utf-8\"?><EntityDescriptor ID=\"_6898aaf1-1639-44d4-956b-5bf936af37f1\"
entityID=\"https://sts.windows.net/0e8108b1-18e9-41a4-961b-dfcddf92ef08/\" xmlns=\"urn:oasis:names:tc:SAML:2.0:metadata\"><Signature
xmlns=\"http://www.w3.org/2000/09/xmldsig#\"><SignedInfo><CanonicalizationMethod
Algorithm=\"http://www.w3.org/2001/10/xml-exc-c14n#\" /><SignatureMethod Algorithm=\"http://www.w3.org/2001/04/xmldsig-more#rsa-sha256\"
/><Reference URI=\"#_6898aaf1-1639-44d4-956b-5bf936af37f1\"><Transforms><Transform
Algorithm=\"http://www.w3.org/2000/09/xmldsig#enveloped-signature\" /><Transform
Algorithm=\"http://www.w3.org/2001/10/xml-exc-c14n#\" /></Transforms><DigestMethod
Algorithm=\"http://www.w3.org/2001/04/xmlenc#sha256\" /><DigestValue>ncp+pf0e75KdoRTy1PQeu74OKXjcVNM+bnT7Ns6cwQI=</DigestValue></Reference></SignedInfo><SignatureValue>J9PRCq201gGMzMtt4Ye+gsM7xOgrNvDg/usqIMvsyUy2r/MeTBz5FKCK+Okjwm49vyTWUoUioYGiwm/TD2Knv59g1zy+/OjZcmBJgDrCmksFJdkwG/fDlOZQNGuj2qh1CEKL5n6Ipy2z1dQ9XUmhhndtXNnjdZ0fJ9QWufWoxveSCLHcU7eUB9obwq96pbAp+6as0XreMNC/xPv5gDdHfKaIppsXtEwcZY7m1c25jDWqPUTQrtbVC0uryffg1Yu0JLTr646GMTzxulBSpQGRfNf5UT0bUiLtKngi++UHrngKdv3ovWwpVmY82JhG7rMDhkuWZu3LdEFvY3svNxGtsQ==</SignatureValue><KeyInfo><X509Data><X509Certificate>MIIDPzCCAiegAwIBAgIQOpwRqLOiO5dOnZepSd5yJzANBgkqhkiG9w0BAQsFADAhMR8wHQYDVQQDDBZhZGZzLmF0dGFja3JhbmdlLmxvY2FsMB4XDTIxMDEwNjIyMzAyMloXDTIyMDEwNjIyNTAyMlowITEfMB0GA1UEAwwWYWRmcy5hdHRhY2tyYW5nZS5sb2NhbDCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAKCwp37iASl3qvAbIyYGI1HOwIlZCAuwLZF+ROf0SVpl+KC19nR+ws7NjacsxsugHMUT1gc9On/l0Jn5pF6VFFcPyPsVvaxLJ+YMY0SBcIHp1iQOKfA2jIFXs4eoLzcrOpX0vqkKsZEPsUAN8tz7OYOPyIP4gylV6hh3nNJXQ2ogeTHXmrpI7wDrAY72g9tDCAitRvAu+nZOLnYaQ3YmnJJGZd+YvmRUd7WAwngYEbJss55ZcL/JU3VJQMJ7OGtjFhjayDT/dUdtvBUqsfF27cArbT5WgGm8WX+WWrJTJgqhQ9YpRUXFajt7Ky5fDLG1cuL6FCHpfrBuRsy7MdY/B+0CAwEAAaNzMHEwDgYDVR0PAQH/BAQDAgWgMB0GA1UdJQQWMBQGCCsGAQUFBwMCBggrBgEFBQcDATAhBgNVHREEGjAYghZhZGZzLmF0dGFja3JhbmdlLmxvY2FsMB0GA1UdDgQWBBQCPwpG/CPNUFbkjPjBuXJr1AOIdzANBgkqhkiG9w0BAQsFAAOCAQEAlzPZxjHF8tLmpf2KLeu9OlVSdcJ/vER7H/3gZmDEnNET/FHbY20npgiQgyk2XoM9WBe9zsuDcORfhndUnW+NHaAHZfdTvtvq1wPoqnEFdedRKMoXU7DtcHHnK533/4ysdcpI8rMS4Tg/WTmFHmubs0xc1TGHL4nVPC1p7Tz6ijkluHxkZFjf0VER/lc6LBXxhEgPuX+aYFvMq1Ty8dYbYjQ9C1sKWYavOnR11pB3uGTRYaj0FwTGhP/UfpkKuaKRhx0j1Iwe01rNDl1+tWhAwZXGDFFcJMTx/Z+vCcSlijBLeVCP7mmm0QgFn7AWrqhAUKkqfcVVvYLgi+FTcuJuSA==</X509Certificate></X509Data></KeyInfo></Signature><RoleDescriptor
xsi:type=\"fed:SecurityTokenServiceType\" protocolSupportEnumeration=\"http://docs.oasis-open.org/wsfed/federation/200706\"
xmlns:xsi=\"http://www.w3.org/2001/XMLSchema-instance\" xmlns:fed=\"http://docs.oasis-open.org/wsfed/federation/200706\"><KeyDescriptor
use=\"signing\"><KeyInfo xmlns=\"http://www.w3.org/2000/09/xmldsig#\"><X509Data><X509Certificate>MIIDPzCCAiegAwIBAgIQOpwRqLOiO5dOnZepSd5yJzANBgkqhkiG9w0BAQsFADAhMR8wHQYDVQQDDBZhZGZzLmF0dGFja3JhbmdlLmxvY2FsMB4XDTIxMDEwNjIyMzAyMloXDTIyMDEwNjIyNTAyMlowITEfMB0GA1UEAwwWYWRmcy5hdHRhY2tyYW5nZS5sb2NhbDCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAKCwp37iASl3qvAbIyYGI1HOwIlZCAuwLZF+ROf0SVpl+KC19nR+ws7NjacsxsugHMUT1gc9On/l0Jn5pF6VFFcPyPsVvaxLJ+YMY0SBcIHp1iQOKfA2jIFXs4eoLzcrOpX0vqkKsZEPsUAN8tz7OYOPyIP4gylV6hh3nNJXQ2ogeTHXmrpI7wDrAY72g9tDCAitRvAu+nZOLnYaQ3YmnJJGZd+YvmRUd7WAwngYEbJss55ZcL/JU3VJQMJ7OGtjFhjayDT/dUdtvBUqsfF27cArbT5WgGm8WX+WWrJTJgqhQ9YpRUXFajt7Ky5fDLG1cuL6FCHpfrBuRsy7MdY/B+0CAwEAAaNzMHEwDgYDVR0PAQH/BAQDAgWgMB0GA1UdJQQWMBQGCCsGAQUFBwMCBggrBgEFBQcDATAhBgNVHREEGjAYghZhZGZzLmF0dGFja3JhbmdlLmxvY2FsMB0GA1UdDgQWBBQCPwpG/CPNUFbkjPjBuXJr1AOIdzANBgkqhkiG9w0BAQsFAAOCAQEAlzPZxjHF8tLmpf2KLeu9OlVSdcJ/vER7H/3gZmDEnNET/FHbY20npgiQgyk2XoM9WBe9zsuDcORfhndUnW+NHaAHZfdTvtvq1wPoqnEFdedRKMoXU7DtcHHnK533/4ysdcpI8rMS4Tg/WTmFHmubs0xc1TGHL4nVPC1p7Tz6ijkluHxkZFjf0VER/lc6LBXxhEgPuX+aYFvMq1Ty8dYbYjQ9C1sKWYavOnR11pB3uGTRYaj0FwTGhP/UfpkKuaKRhx0j1Iwe01rNDl1+tWhAwZXGDFFcJMTx/Z+vCcSlijBLeVCP7mmm0QgFn7AWrqhAUKkqfcVVvYLgi+FTcuJuSA==</X509Certificate></X509Data></KeyInfo></KeyDescriptor><KeyDescriptor
use=\"signing\"><KeyInfo xmlns=\"http://www.w3.org/2000/09/xmldsig#\"><X509Data><X509Certificate>MIIC8DCCAdigAwIBAgIQMN9XaFEOfIpMuOqq+1JFzzANBgkqhkiG9w0BAQsFADA0MTIwMAYDVQQDEylNaWNyb3NvZnQgQXp1cmUgRmVkZXJhdGVkIFNTTyBDZXJ0aWZpY2F0ZTAeFw0yMTAxMTcxODU2MTZaFw0yNDAxMTcyMTU2MTRaMDQxMjAwBgNVBAMTKU1pY3Jvc29mdCBBenVyZSBGZWRlcmF0ZWQgU1NPIENlcnRpZmljYXRlMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA2GO3vs2HPr+EXEVnWNRDOIjxS5tP2i9xq/399CAl/sWSbJkooGjcCKWf0DN1cGbbbrzL/V+Hor/htEFBpsbUsL8NbaE5pZOnH3oWquiHFiMs1t3Dh4dSVViKyMgIx/i5j4qUW74fYHvgead3kTIV7oSIYHXPNSF6SGLR8qWgRSCLre5P80PnzQmFoI1MbfJbJWf4rWBRVylJaamRFi8X/9byGAQKNYtrjnxCPtdvqUG03EMvwrUCTOM49qnuUhHUCtrIk8MQ1/xzHePkWT3OXmfCi0ABDFAnb9GH763rLlrawVaZKMzmICQ/Rts3+NUm0urSbPlUq1+IfbCsRCwz/QIDAQABMA0GCSqGSIb3DQEBCwUAA4IBAQA+ZOJcY1oGsj/LLa0KLhlUolA7dojhwDtZFPRInLcyBQ6G2fkEZr7jdgY0vg8X86vFCw2JLIC5UmUrXsC1YGxD0kzdMAqr06uVOxGKD/QCRKfes3AYqv/axoJpSm1uZP2066816bYIpOMjcc5yQaEzFh6Y2d5Ovd+DJ/BLVmTFuKs9p9q5JCpOQQT73c0actHdXsjZeM0iHbuWtQOu6LHJuQRbl7BCdKblLvpnoF7DrAHLq1xArcSUEuXa590aga7Ld9P/6BrTQ26QdGGfmJlRiaWh5iu22lbI169NlFd+EmgXIFWK0Qu6i7zyNkGTTA2GOOG9Z/vNIGKRxmV4l7KN</X509Certificate></X509Data></KeyInfo></KeyDescriptor><fed:ClaimTypesOffered><auth:ClaimType
Uri=\"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name\" xmlns:auth=\"http://docs.oasis-open.org/wsfed/authorization/200706\"><auth:DisplayName>Name</auth:DisplayName><auth:Description>The
mutable display name of the user.</auth:Description></auth:ClaimType><auth:ClaimType
Uri=\"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier\" xmlns:auth=\"http://docs.oasis-open.org/wsfed/authorization/200706\"><auth:DisplayName>Subject</auth:DisplayName><auth:Description>An
immutable, globally unique, non-reusable identifier of the user that is unique to
the application for which a token is issued.</auth:Description></auth:ClaimType><auth:ClaimType
Uri=\"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname\" xmlns:auth=\"http://docs.oasis-open.org/wsfed/authorization/200706\"><auth:DisplayName>Given
Name</auth:DisplayName><auth:Description>First name of the user.</auth:Description></auth:ClaimType><auth:ClaimType
Uri=\"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname\" xmlns:auth=\"http://docs.oasis-open.org/wsfed/authorization/200706\"><auth:DisplayName>Surname</auth:DisplayName><auth:Description>Last
name of the user.</auth:Description></auth:ClaimType><auth:ClaimType Uri=\"http://schemas.microsoft.com/identity/claims/displayname\"
xmlns:auth=\"http://docs.oasis-open.org/wsfed/authorization/200706\"><auth:DisplayName>Display
Name</auth:DisplayName><auth:Description>Display name of the user.</auth:Description></auth:ClaimType><auth:ClaimType
Uri=\"http://schemas.microsoft.com/identity/claims/nickname\" xmlns:auth=\"http://docs.oasis-open.org/wsfed/authorization/200706\"><auth:DisplayName>Nick
Name</auth:DisplayName><auth:Description>Nick name of the user.</auth:Description></auth:ClaimType><auth:ClaimType
Uri=\"http://schemas.microsoft.com/ws/2008/06/identity/claims/authenticationinstant\"
xmlns:auth=\"http://docs.oasis-open.org/wsfed/authorization/200706\"><auth:DisplayName>Authentication
Instant</auth:DisplayName><auth:Description>The time (UTC) when the user is authenticated
to Windows Azure Active Directory.</auth:Description></auth:ClaimType><auth:ClaimType
Uri=\"http://schemas.microsoft.com/ws/2008/06/identity/claims/authenticationmethod\"
xmlns:auth=\"http://docs.oasis-open.org/wsfed/authorization/200706\"><auth:DisplayName>Authentication
Method</auth:DisplayName><auth:Description>The method that Windows Azure Active
Directory uses to authenticate users.</auth:Description></auth:ClaimType><auth:ClaimType
Uri=\"http://schemas.microsoft.com/identity/claims/objectidentifier\" xmlns:auth=\"http://docs.oasis-open.org/wsfed/authorization/200706\"><auth:DisplayName>ObjectIdentifier</auth:DisplayName><auth:Description>Primary
identifier for the user in the directory. Immutable, globally unique, non-reusable.</auth:Description></auth:ClaimType><auth:ClaimType
Uri=\"http://schemas.microsoft.com/identity/claims/tenantid\" xmlns:auth=\"http://docs.oasis-open.org/wsfed/authorization/200706\"><auth:DisplayName>TenantId</auth:DisplayName><auth:Description>Identifier
for the user''s tenant.</auth:Description></auth:ClaimType><auth:ClaimType Uri=\"http://schemas.microsoft.com/identity/claims/identityprovider\"
xmlns:auth=\"http://docs.oasis-open.org/wsfed/authorization/200706\"><auth:DisplayName>IdentityProvider</auth:DisplayName><auth:Description>Identity
provider for the user.</auth:Description></auth:ClaimType><auth:ClaimType Uri=\"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress\"
xmlns:auth=\"http://docs.oasis-open.org/wsfed/authorization/200706\"><auth:DisplayName>Email</auth:DisplayName><auth:Description>Email
address of the user.</auth:Description></auth:ClaimType><auth:ClaimType Uri=\"http://schemas.microsoft.com/ws/2008/06/identity/claims/groups\"
xmlns:auth=\"http://docs.oasis-open.org/wsfed/authorization/200706\"><auth:DisplayName>Groups</auth:DisplayName><auth:Description>Groups
of the user.</auth:Description></auth:ClaimType><auth:ClaimType Uri=\"http://schemas.microsoft.com/identity/claims/accesstoken\"
xmlns:auth=\"http://docs.oasis-open.org/wsfed/authorization/200706\"><auth:DisplayName>External
Access Token</auth:DisplayName><auth:Description>Access token issued by external
identity provider.</auth:Description></auth:ClaimType><auth:ClaimType Uri=\"http://schemas.microsoft.com/ws/2008/06/identity/claims/expiration\"
xmlns:auth=\"http://docs.oasis-open.org/wsfed/authorization/200706\"><auth:DisplayName>External
Access Token Expiration</auth:DisplayName><auth:Description>UTC expiration time
of access token issued by external identity provider.</auth:Description></auth:ClaimType><auth:ClaimType
Uri=\"http://schemas.microsoft.com/identity/claims/openid2_id\" xmlns:auth=\"http://docs.oasis-open.org/wsfed/authorization/200706\"><auth:DisplayName>External
OpenID 2.0 Identifier</auth:DisplayName><auth:Description>OpenID 2.0 identifier
issued by external identity provider.</auth:Description></auth:ClaimType><auth:ClaimType
Uri=\"http://schemas.microsoft.com/claims/groups.link\" xmlns:auth=\"http://docs.oasis-open.org/wsfed/authorization/200706\"><auth:DisplayName>GroupsOverageClaim</auth:DisplayName><auth:Description>Issued
when number of user''s group claims exceeds return limit.</auth:Description></auth:ClaimType><auth:ClaimType
Uri=\"http://schemas.microsoft.com/ws/2008/06/identity/claims/role\" xmlns:auth=\"http://docs.oasis-open.org/wsfed/authorization/200706\"><auth:DisplayName>Role
Claim</auth:DisplayName><auth:Description>Roles that the user or Service Principal
is attached to</auth:Description></auth:ClaimType><auth:ClaimType Uri=\"http://schemas.microsoft.com/ws/2008/06/identity/claims/wids\"
xmlns:auth=\"http://docs.oasis-open.org/wsfed/authorization/200706\"><auth:DisplayName>RoleTemplate
Id Claim</auth:DisplayName><auth:Description>Role template id of the Built-in Directory
Roles that the user is a member of</auth:Description></auth:ClaimType></fed:ClaimTypesOffered><fed:SecurityTokenServiceEndpoint><wsa:EndpointReference
xmlns:wsa=\"http://www.w3.org/2005/08/addressing\"><wsa:Address>https://login.microsoftonline.com/0e8108b1-18e9-41a4-961b-dfcddf92ef08/wsfed</wsa:Address></wsa:EndpointReference></fed:SecurityTokenServiceEndpoint><fed:PassiveRequestorEndpoint><wsa:EndpointReference
xmlns:wsa=\"http://www.w3.org/2005/08/addressing\"><wsa:Address>https://login.microsoftonline.com/0e8108b1-18e9-41a4-961b-dfcddf92ef08/wsfed</wsa:Address></wsa:EndpointReference></fed:PassiveRequestorEndpoint></RoleDescriptor><RoleDescriptor
xsi:type=\"fed:ApplicationServiceType\" protocolSupportEnumeration=\"http://docs.oasis-open.org/wsfed/federation/200706\"
xmlns:xsi=\"http://www.w3.org/2001/XMLSchema-instance\" xmlns:fed=\"http://docs.oasis-open.org/wsfed/federation/200706\"><KeyDescriptor
use=\"signing\"><KeyInfo xmlns=\"http://www.w3.org/2000/09/xmldsig#\"><X509Data><X509Certificate>MIIDPzCCAiegAwIBAgIQOpwRqLOiO5dOnZepSd5yJzANBgkqhkiG9w0BAQsFADAhMR8wHQYDVQQDDBZhZGZzLmF0dGFja3JhbmdlLmxvY2FsMB4XDTIxMDEwNjIyMzAyMloXDTIyMDEwNjIyNTAyMlowITEfMB0GA1UEAwwWYWRmcy5hdHRhY2tyYW5nZS5sb2NhbDCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAKCwp37iASl3qvAbIyYGI1HOwIlZCAuwLZF+ROf0SVpl+KC19nR+ws7NjacsxsugHMUT1gc9On/l0Jn5pF6VFFcPyPsVvaxLJ+YMY0SBcIHp1iQOKfA2jIFXs4eoLzcrOpX0vqkKsZEPsUAN8tz7OYOPyIP4gylV6hh3nNJXQ2ogeTHXmrpI7wDrAY72g9tDCAitRvAu+nZOLnYaQ3YmnJJGZd+YvmRUd7WAwngYEbJss55ZcL/JU3VJQMJ7OGtjFhjayDT/dUdtvBUqsfF27cArbT5WgGm8WX+WWrJTJgqhQ9YpRUXFajt7Ky5fDLG1cuL6FCHpfrBuRsy7MdY/B+0CAwEAAaNzMHEwDgYDVR0PAQH/BAQDAgWgMB0GA1UdJQQWMBQGCCsGAQUFBwMCBggrBgEFBQcDATAhBgNVHREEGjAYghZhZGZzLmF0dGFja3JhbmdlLmxvY2FsMB0GA1UdDgQWBBQCPwpG/CPNUFbkjPjBuXJr1AOIdzANBgkqhkiG9w0BAQsFAAOCAQEAlzPZxjHF8tLmpf2KLeu9OlVSdcJ/vER7H/3gZmDEnNET/FHbY20npgiQgyk2XoM9WBe9zsuDcORfhndUnW+NHaAHZfdTvtvq1wPoqnEFdedRKMoXU7DtcHHnK533/4ysdcpI8rMS4Tg/WTmFHmubs0xc1TGHL4nVPC1p7Tz6ijkluHxkZFjf0VER/lc6LBXxhEgPuX+aYFvMq1Ty8dYbYjQ9C1sKWYavOnR11pB3uGTRYaj0FwTGhP/UfpkKuaKRhx0j1Iwe01rNDl1+tWhAwZXGDFFcJMTx/Z+vCcSlijBLeVCP7mmm0QgFn7AWrqhAUKkqfcVVvYLgi+FTcuJuSA==</X509Certificate></X509Data></KeyInfo></KeyDescriptor><KeyDescriptor
use=\"signing\"><KeyInfo xmlns=\"http://www.w3.org/2000/09/xmldsig#\"><X509Data><X509Certificate>MIIC8DCCAdigAwIBAgIQMN9XaFEOfIpMuOqq+1JFzzANBgkqhkiG9w0BAQsFADA0MTIwMAYDVQQDEylNaWNyb3NvZnQgQXp1cmUgRmVkZXJhdGVkIFNTTyBDZXJ0aWZpY2F0ZTAeFw0yMTAxMTcxODU2MTZaFw0yNDAxMTcyMTU2MTRaMDQxMjAwBgNVBAMTKU1pY3Jvc29mdCBBenVyZSBGZWRlcmF0ZWQgU1NPIENlcnRpZmljYXRlMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA2GO3vs2HPr+EXEVnWNRDOIjxS5tP2i9xq/399CAl/sWSbJkooGjcCKWf0DN1cGbbbrzL/V+Hor/htEFBpsbUsL8NbaE5pZOnH3oWquiHFiMs1t3Dh4dSVViKyMgIx/i5j4qUW74fYHvgead3kTIV7oSIYHXPNSF6SGLR8qWgRSCLre5P80PnzQmFoI1MbfJbJWf4rWBRVylJaamRFi8X/9byGAQKNYtrjnxCPtdvqUG03EMvwrUCTOM49qnuUhHUCtrIk8MQ1/xzHePkWT3OXmfCi0ABDFAnb9GH763rLlrawVaZKMzmICQ/Rts3+NUm0urSbPlUq1+IfbCsRCwz/QIDAQABMA0GCSqGSIb3DQEBCwUAA4IBAQA+ZOJcY1oGsj/LLa0KLhlUolA7dojhwDtZFPRInLcyBQ6G2fkEZr7jdgY0vg8X86vFCw2JLIC5UmUrXsC1YGxD0kzdMAqr06uVOxGKD/QCRKfes3AYqv/axoJpSm1uZP2066816bYIpOMjcc5yQaEzFh6Y2d5Ovd+DJ/BLVmTFuKs9p9q5JCpOQQT73c0actHdXsjZeM0iHbuWtQOu6LHJuQRbl7BCdKblLvpnoF7DrAHLq1xArcSUEuXa590aga7Ld9P/6BrTQ26QdGGfmJlRiaWh5iu22lbI169NlFd+EmgXIFWK0Qu6i7zyNkGTTA2GOOG9Z/vNIGKRxmV4l7KN</X509Certificate></X509Data></KeyInfo></KeyDescriptor><fed:TargetScopes><wsa:EndpointReference
xmlns:wsa=\"http://www.w3.org/2005/08/addressing\"><wsa:Address>https://sts.windows.net/0e8108b1-18e9-41a4-961b-dfcddf92ef08/</wsa:Address></wsa:EndpointReference></fed:TargetScopes><fed:ApplicationServiceEndpoint><wsa:EndpointReference
xmlns:wsa=\"http://www.w3.org/2005/08/addressing\"><wsa:Address>https://login.microsoftonline.com/0e8108b1-18e9-41a4-961b-dfcddf92ef08/wsfed</wsa:Address></wsa:EndpointReference></fed:ApplicationServiceEndpoint><fed:PassiveRequestorEndpoint><wsa:EndpointReference
xmlns:wsa=\"http://www.w3.org/2005/08/addressing\"><wsa:Address>https://login.microsoftonline.com/0e8108b1-18e9-41a4-961b-dfcddf92ef08/wsfed</wsa:Address></wsa:EndpointReference></fed:PassiveRequestorEndpoint></RoleDescriptor><IDPSSODescriptor
protocolSupportEnumeration=\"urn:oasis:names:tc:SAML:2.0:protocol\"><KeyDescriptor
use=\"signing\"><KeyInfo xmlns=\"http://www.w3.org/2000/09/xmldsig#\"><X509Data><X509Certificate>MIIDPzCCAiegAwIBAgIQOpwRqLOiO5dOnZepSd5yJzANBgkqhkiG9w0BAQsFADAhMR8wHQYDVQQDDBZhZGZzLmF0dGFja3JhbmdlLmxvY2FsMB4XDTIxMDEwNjIyMzAyMloXDTIyMDEwNjIyNTAyMlowITEfMB0GA1UEAwwWYWRmcy5hdHRhY2tyYW5nZS5sb2NhbDCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAKCwp37iASl3qvAbIyYGI1HOwIlZCAuwLZF+ROf0SVpl+KC19nR+ws7NjacsxsugHMUT1gc9On/l0Jn5pF6VFFcPyPsVvaxLJ+YMY0SBcIHp1iQOKfA2jIFXs4eoLzcrOpX0vqkKsZEPsUAN8tz7OYOPyIP4gylV6hh3nNJXQ2ogeTHXmrpI7wDrAY72g9tDCAitRvAu+nZOLnYaQ3YmnJJGZd+YvmRUd7WAwngYEbJss55ZcL/JU3VJQMJ7OGtjFhjayDT/dUdtvBUqsfF27cArbT5WgGm8WX+WWrJTJgqhQ9YpRUXFajt7Ky5fDLG1cuL6FCHpfrBuRsy7MdY/B+0CAwEAAaNzMHEwDgYDVR0PAQH/BAQDAgWgMB0GA1UdJQQWMBQGCCsGAQUFBwMCBggrBgEFBQcDATAhBgNVHREEGjAYghZhZGZzLmF0dGFja3JhbmdlLmxvY2FsMB0GA1UdDgQWBBQCPwpG/CPNUFbkjPjBuXJr1AOIdzANBgkqhkiG9w0BAQsFAAOCAQEAlzPZxjHF8tLmpf2KLeu9OlVSdcJ/vER7H/3gZmDEnNET/FHbY20npgiQgyk2XoM9WBe9zsuDcORfhndUnW+NHaAHZfdTvtvq1wPoqnEFdedRKMoXU7DtcHHnK533/4ysdcpI8rMS4Tg/WTmFHmubs0xc1TGHL4nVPC1p7Tz6ijkluHxkZFjf0VER/lc6LBXxhEgPuX+aYFvMq1Ty8dYbYjQ9C1sKWYavOnR11pB3uGTRYaj0FwTGhP/UfpkKuaKRhx0j1Iwe01rNDl1+tWhAwZXGDFFcJMTx/Z+vCcSlijBLeVCP7mmm0QgFn7AWrqhAUKkqfcVVvYLgi+FTcuJuSA==</X509Certificate></X509Data></KeyInfo></KeyDescriptor><KeyDescriptor
use=\"signing\"><KeyInfo xmlns=\"http://www.w3.org/2000/09/xmldsig#\"><X509Data><X509Certificate>MIIC8DCCAdigAwIBAgIQMN9XaFEOfIpMuOqq+1JFzzANBgkqhkiG9w0BAQsFADA0MTIwMAYDVQQDEylNaWNyb3NvZnQgQXp1cmUgRmVkZXJhdGVkIFNTTyBDZXJ0aWZpY2F0ZTAeFw0yMTAxMTcxODU2MTZaFw0yNDAxMTcyMTU2MTRaMDQxMjAwBgNVBAMTKU1pY3Jvc29mdCBBenVyZSBGZWRlcmF0ZWQgU1NPIENlcnRpZmljYXRlMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA2GO3vs2HPr+EXEVnWNRDOIjxS5tP2i9xq/399CAl/sWSbJkooGjcCKWf0DN1cGbbbrzL/V+Hor/htEFBpsbUsL8NbaE5pZOnH3oWquiHFiMs1t3Dh4dSVViKyMgIx/i5j4qUW74fYHvgead3kTIV7oSIYHXPNSF6SGLR8qWgRSCLre5P80PnzQmFoI1MbfJbJWf4rWBRVylJaamRFi8X/9byGAQKNYtrjnxCPtdvqUG03EMvwrUCTOM49qnuUhHUCtrIk8MQ1/xzHePkWT3OXmfCi0ABDFAnb9GH763rLlrawVaZKMzmICQ/Rts3+NUm0urSbPlUq1+IfbCsRCwz/QIDAQABMA0GCSqGSIb3DQEBCwUAA4IBAQA+ZOJcY1oGsj/LLa0KLhlUolA7dojhwDtZFPRInLcyBQ6G2fkEZr7jdgY0vg8X86vFCw2JLIC5UmUrXsC1YGxD0kzdMAqr06uVOxGKD/QCRKfes3AYqv/axoJpSm1uZP2066816bYIpOMjcc5yQaEzFh6Y2d5Ovd+DJ/BLVmTFuKs9p9q5JCpOQQT73c0actHdXsjZeM0iHbuWtQOu6LHJuQRbl7BCdKblLvpnoF7DrAHLq1xArcSUEuXa590aga7Ld9P/6BrTQ26QdGGfmJlRiaWh5iu22lbI169NlFd+EmgXIFWK0Qu6i7zyNkGTTA2GOOG9Z/vNIGKRxmV4l7KN</X509Certificate></X509Data></KeyInfo></KeyDescriptor><SingleLogoutService
Binding=\"urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect\" Location=\"https://login.microsoftonline.com/0e8108b1-18e9-41a4-961b-dfcddf92ef08/saml2\"
/><SingleSignOnService Binding=\"urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect\"
Location=\"https://login.microsoftonline.com/0e8108b1-18e9-41a4-961b-dfcddf92ef08/saml2\"
/><SingleSignOnService Binding=\"urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST\"
Location=\"https://login.microsoftonline.com/0e8108b1-18e9-41a4-961b-dfcddf92ef08/saml2\"
/></IDPSSODescriptor></EntityDescriptor>", "sAMLProviderArn": "arn:aws:iam::111111111111:saml-provider/rodsotoonmicrosoft"},
"responseElements": {"sAMLProviderArn": "arn:aws:iam::111111111111:saml-provider/rodsotoonmicrosoft"},
"requestID": "83d621ad-5b33-4ff0-acf4-0043cb432844", "eventID": "51b6d859-0cc4-4591-ba76-3494f3f43832",
"readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "eventCategory":
"Management", "recipientAccountId": "111111111111"}'
+107
View File
@@ -0,0 +1,107 @@
name: AWS CloudTrail UpdateTrail
id: d5b7a1eb-711a-4c96-aa93-235fe3c8a939
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
description: Data source object for AWS CloudTrail UpdateTrail
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
supported_TA:
- name: Splunk Add-on for Amazon Web Services (AWS)
url: https://splunkbase.splunk.com/app/1876
version: 7.4.1
fields:
- _time
- app
- awsRegion
- aws_account_id
- command
- date_hour
- date_mday
- date_minute
- date_month
- date_second
- date_wday
- date_year
- date_zone
- dest
- dvc
- errorCode
- eventCategory
- eventID
- eventName
- eventSource
- eventTime
- eventType
- eventVersion
- host
- index
- linecount
- managementEvent
- msg
- object_category
- product
- punct
- readOnly
- recipientAccountId
- region
- requestID
- requestParameters.includeGlobalServiceEvents
- requestParameters.isMultiRegionTrail
- requestParameters.name
- responseElements.includeGlobalServiceEvents
- responseElements.isMultiRegionTrail
- responseElements.isOrganizationTrail
- responseElements.logFileValidationEnabled
- responseElements.name
- responseElements.s3BucketName
- responseElements.trailARN
- signature
- source
- sourceIPAddress
- sourcetype
- splunk_server
- src
- src_ip
- start_time
- timeendpos
- timestartpos
- tlsDetails.cipherSuite
- tlsDetails.clientProvidedHostHeader
- tlsDetails.tlsVersion
- user
- userAgent
- userIdentity.accessKeyId
- userIdentity.accountId
- userIdentity.arn
- userIdentity.principalId
- userIdentity.type
- userIdentity.userName
- userName
- user_access_key
- user_agent
- user_arn
- user_group_id
- user_id
- user_name
- user_type
- vendor
- vendor_account
- vendor_product
- vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId":
"AIDAYTOGP2RLI4PXTGCEU", "arn": "arn:aws:iam::111111111111:user/gowthamaraj_cli",
"accountId": "111111111111", "accessKeyId": "AKIAYTOGP2RLFLKADUVG", "userName":
"gowthamaraj_cli"}, "eventTime": "2022-07-19T08:42:26Z", "eventSource": "cloudtrail.amazonaws.com",
"eventName": "UpdateTrail", "awsRegion": "us-west-2", "sourceIPAddress": "67.171.71.185",
"userAgent": "aws-cli/2.7.3 Python/3.9.13 Darwin/21.5.0 source/x86_64 prompt/off
command/cloudtrail.update-trail", "requestParameters": {"name": "Regulatory", "includeGlobalServiceEvents":
true, "isMultiRegionTrail": true}, "responseElements": {"name": "Regulatory", "s3BucketName":
"s3-for-cloudtrail-logs111", "includeGlobalServiceEvents": true, "isMultiRegionTrail":
true, "trailARN": "arn:aws:cloudtrail:us-west-2:111111111111:trail/Regulatory",
"logFileValidationEnabled": false, "isOrganizationTrail": false}, "requestID": "0da61466-5bba-43f9-b7e1-27437de120b2",
"eventID": "ce02af60-f29e-4bc2-8b29-31c12f408fed", "readOnly": false, "eventType":
"AwsApiCall", "managementEvent": true, "recipientAccountId": "111111111111", "eventCategory":
"Management", "tlsDetails": {"tlsVersion": "TLSv1.2", "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "cloudtrail.us-west-2.amazonaws.com"}}'
@@ -1,119 +1,120 @@
name: AWS Security Hub
id: b02bfbf3-294f-478e-99a1-e24b8c692d7e
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
description: Data source object for AWS Security Hub
source: aws_securityhub_finding
sourcetype: aws:securityhub:finding
supported_TA:
name: Splunk Add-on for Amazon Web Services (AWS)
version: 7.4.1
- name: Splunk Add-on for Amazon Web Services (AWS)
url: https://splunkbase.splunk.com/app/1876
event_names: []
version: 7.4.1
fields:
- _time
- AwsAccountId
- CreatedAt
- Description
- FirstObservedAt
- GeneratorId
- Id
- LastObservedAt
- ProductArn
- ProductFields.aws/guardduty/service/action/actionType
- ProductFields.aws/guardduty/service/action/awsApiCallAction/affectedResources/AWS::S3::Bucket
- ProductFields.aws/guardduty/service/action/awsApiCallAction/api
- ProductFields.aws/guardduty/service/action/awsApiCallAction/callerType
- ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/city/cityName
- ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/country/countryName
- ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/geoLocation/lat
- ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/geoLocation/lon
- ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/ipAddressV4
- ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/organization/asn
- ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/organization/asnOrg
- ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/organization/isp
- ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/organization/org
- ProductFields.aws/guardduty/service/action/awsApiCallAction/serviceName
- ProductFields.aws/guardduty/service/additionalInfo/sample
- ProductFields.aws/guardduty/service/additionalInfo/unusual/hoursOfDay.0_
- ProductFields.aws/guardduty/service/additionalInfo/unusual/userNames.0_
- ProductFields.aws/guardduty/service/archived
- ProductFields.aws/guardduty/service/count
- ProductFields.aws/guardduty/service/detectorId
- ProductFields.aws/guardduty/service/eventFirstSeen
- ProductFields.aws/guardduty/service/eventLastSeen
- ProductFields.aws/guardduty/service/resourceRole
- ProductFields.aws/guardduty/service/serviceName
- ProductFields.aws/securityhub/CompanyName
- ProductFields.aws/securityhub/FindingId
- ProductFields.aws/securityhub/ProductName
- RecordState
- Resources{}.Details.AwsEc2Instance.IamInstanceProfileArn
- Resources{}.Details.AwsEc2Instance.ImageId
- Resources{}.Details.AwsEc2Instance.IpV4Addresses{}
- Resources{}.Details.AwsEc2Instance.LaunchedAt
- Resources{}.Details.AwsEc2Instance.SubnetId
- Resources{}.Details.AwsEc2Instance.Type
- Resources{}.Details.AwsEc2Instance.VpcId
- Resources{}.Details.AwsIamAccessKey.PrincipalId
- Resources{}.Details.AwsIamAccessKey.PrincipalName
- Resources{}.Details.AwsIamAccessKey.PrincipalType
- Resources{}.Details.AwsS3Bucket.CreatedAt
- Resources{}.Details.AwsS3Bucket.OwnerId
- Resources{}.Details.AwsS3Bucket.ServerSideEncryptionConfiguration.Rules{}.ApplyServerSideEncryptionByDefault.KMSMasterKeyID
- Resources{}.Details.AwsS3Bucket.ServerSideEncryptionConfiguration.Rules{}.ApplyServerSideEncryptionByDefault.SSEAlgorithm
- Resources{}.Id
- Resources{}.Partition
- Resources{}.Region
- Resources{}.Tags.GeneratedFindingInstaceTag1
- Resources{}.Tags.GeneratedFindingInstaceTag2
- Resources{}.Tags.GeneratedFindingInstaceTag3
- Resources{}.Tags.GeneratedFindingInstaceTag4
- Resources{}.Tags.GeneratedFindingInstaceTag5
- Resources{}.Tags.GeneratedFindingInstaceTag6
- Resources{}.Tags.GeneratedFindingInstaceTag7
- Resources{}.Tags.GeneratedFindingInstaceTag8
- Resources{}.Tags.GeneratedFindingInstaceTag9
- Resources{}.Tags.foo
- Resources{}.Type
- SchemaVersion
- Severity.Label
- Severity.Normalized
- Severity.Product
- SourceUrl
- Title
- Types{}
- UpdatedAt
- Workflow.Status
- WorkflowState
- accesskey_extract
- app
- body
- description
- dest
- dest_type
- eventtype
- host
- id
- index
- instance_extract
- linecount
- punct
- s3bucket_extract
- severity
- severity_id
- signature
- signature_id
- source
- sourcetype
- splunk_server
- subject
- tag
- tag::eventtype
- timestamp
- type
- vendor_account
- vendor_region
example_log:
'{"ProductArn":"arn:aws:securityhub:us-east-1::product/aws/guardduty","Types":["Software
- _time
- AwsAccountId
- CreatedAt
- Description
- FirstObservedAt
- GeneratorId
- Id
- LastObservedAt
- ProductArn
- ProductFields.aws/guardduty/service/action/actionType
- ProductFields.aws/guardduty/service/action/awsApiCallAction/affectedResources/AWS::S3::Bucket
- ProductFields.aws/guardduty/service/action/awsApiCallAction/api
- ProductFields.aws/guardduty/service/action/awsApiCallAction/callerType
- ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/city/cityName
- ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/country/countryName
- ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/geoLocation/lat
- ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/geoLocation/lon
- ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/ipAddressV4
- ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/organization/asn
- ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/organization/asnOrg
- ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/organization/isp
- ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/organization/org
- ProductFields.aws/guardduty/service/action/awsApiCallAction/serviceName
- ProductFields.aws/guardduty/service/additionalInfo/sample
- ProductFields.aws/guardduty/service/additionalInfo/unusual/hoursOfDay.0_
- ProductFields.aws/guardduty/service/additionalInfo/unusual/userNames.0_
- ProductFields.aws/guardduty/service/archived
- ProductFields.aws/guardduty/service/count
- ProductFields.aws/guardduty/service/detectorId
- ProductFields.aws/guardduty/service/eventFirstSeen
- ProductFields.aws/guardduty/service/eventLastSeen
- ProductFields.aws/guardduty/service/resourceRole
- ProductFields.aws/guardduty/service/serviceName
- ProductFields.aws/securityhub/CompanyName
- ProductFields.aws/securityhub/FindingId
- ProductFields.aws/securityhub/ProductName
- RecordState
- Resources{}.Details.AwsEc2Instance.IamInstanceProfileArn
- Resources{}.Details.AwsEc2Instance.ImageId
- Resources{}.Details.AwsEc2Instance.IpV4Addresses{}
- Resources{}.Details.AwsEc2Instance.LaunchedAt
- Resources{}.Details.AwsEc2Instance.SubnetId
- Resources{}.Details.AwsEc2Instance.Type
- Resources{}.Details.AwsEc2Instance.VpcId
- Resources{}.Details.AwsIamAccessKey.PrincipalId
- Resources{}.Details.AwsIamAccessKey.PrincipalName
- Resources{}.Details.AwsIamAccessKey.PrincipalType
- Resources{}.Details.AwsS3Bucket.CreatedAt
- Resources{}.Details.AwsS3Bucket.OwnerId
- Resources{}.Details.AwsS3Bucket.ServerSideEncryptionConfiguration.Rules{}.ApplyServerSideEncryptionByDefault.KMSMasterKeyID
- Resources{}.Details.AwsS3Bucket.ServerSideEncryptionConfiguration.Rules{}.ApplyServerSideEncryptionByDefault.SSEAlgorithm
- Resources{}.Id
- Resources{}.Partition
- Resources{}.Region
- Resources{}.Tags.GeneratedFindingInstaceTag1
- Resources{}.Tags.GeneratedFindingInstaceTag2
- Resources{}.Tags.GeneratedFindingInstaceTag3
- Resources{}.Tags.GeneratedFindingInstaceTag4
- Resources{}.Tags.GeneratedFindingInstaceTag5
- Resources{}.Tags.GeneratedFindingInstaceTag6
- Resources{}.Tags.GeneratedFindingInstaceTag7
- Resources{}.Tags.GeneratedFindingInstaceTag8
- Resources{}.Tags.GeneratedFindingInstaceTag9
- Resources{}.Tags.foo
- Resources{}.Type
- SchemaVersion
- Severity.Label
- Severity.Normalized
- Severity.Product
- SourceUrl
- Title
- Types{}
- UpdatedAt
- Workflow.Status
- WorkflowState
- accesskey_extract
- app
- body
- description
- dest
- dest_type
- eventtype
- host
- id
- index
- instance_extract
- linecount
- punct
- s3bucket_extract
- severity
- severity_id
- signature
- signature_id
- source
- sourcetype
- splunk_server
- subject
- tag
- tag::eventtype
- timestamp
- type
- vendor_account
- vendor_region
example_log: '{"ProductArn":"arn:aws:securityhub:us-east-1::product/aws/guardduty","Types":["Software
and Configuration Checks/Exfiltration:S3.ObjectRead.Unusual"],"SourceUrl":"https://us-east-1.console.aws.amazon.com/guardduty/home?region=us-east-1#/findings?macros=current&fId=6aba6b696aea10606e8b336f68d98819","Description":"Principal
GeneratedFindingUserName read objects from S3 bucket GeneratedFindingS3Bucket in
an unusual way.","SchemaVersion":"2018-10-08","GeneratorId":"arn:aws:guardduty:us-east-1:802684071507:detector/48ba636359b884eb132865311fdeb317","FirstObservedAt":"2020-09-28T22:26:15.636Z","CreatedAt":"2020-09-28T22:26:15.636Z","RecordState":"ACTIVE","Title":"Unusual
+13
View File
@@ -0,0 +1,13 @@
name: Azure Active Directory
id: 51ca21e5-bda2-4652-bb29-27c7bc18a81c
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
description: Data source object for Azure Active Directory
source: Azure AD
sourcetype: azure:monitor:aad
separator: operationName
supported_TA:
- name: Splunk Add-on for Microsoft Cloud Services
url: https://splunkbase.splunk.com/app/3110
version: 5.2.2
@@ -0,0 +1,120 @@
name: Azure Active Directory Add app role assignment to service principal
id: 8b2e84cd-6db0-47e9-badc-75c17df1995f
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
description: Data source object for Azure Active Directory Add app role assignment
to service principal
source: Azure AD
sourcetype: azure:monitor:aad
separator: operationName
supported_TA:
- name: Splunk Add-on for Microsoft Cloud Services
url: https://splunkbase.splunk.com/app/3110
version: 5.2.2
fields:
- _time
- Level
- additional_details
- additional_details_name
- additional_details_value
- category
- command
- correlationId
- date_hour
- date_mday
- date_minute
- date_month
- date_second
- date_wday
- date_year
- date_zone
- dest
- dest_type
- durationMs
- dvc
- eventtype
- host
- id
- identity
- index
- linecount
- object_attrs
- object_id
- operationName
- operationVersion
- path_from_resourceId
- properties.activityDateTime
- properties.activityDisplayName
- properties.additionalDetails{}.key
- properties.additionalDetails{}.value
- properties.category
- properties.correlationId
- properties.id
- properties.initiatedBy.app.appId
- properties.initiatedBy.app.displayName
- properties.initiatedBy.app.servicePrincipalId
- properties.initiatedBy.app.servicePrincipalName
- properties.loggedByService
- properties.operationType
- properties.result
- properties.resultReason
- properties.targetResources{}.displayName
- properties.targetResources{}.id
- properties.targetResources{}.modifiedProperties{}.displayName
- properties.targetResources{}.modifiedProperties{}.newValue
- properties.targetResources{}.modifiedProperties{}.oldValue
- properties.targetResources{}.type
- properties.userAgent
- punct
- resourceId
- result
- resultSignature
- result_id
- signature
- source
- sourcetype
- splunk_server
- src_user_type
- status
- tag
- tag::eventtype
- tenantId
- time
- timeendpos
- timestartpos
- user_agent
- user_type
- vendor_account
- vendor_product
example_log: '{"time": "2024-02-08T21:49:53.7643129Z", "resourceId": "/tenants/75243ab2-44f8-435c-a7a6-b479385df6d4/providers/Microsoft.aadiam",
"operationName": "Add app role assignment to service principal", "operationVersion":
"1.0", "category": "AuditLogs", "tenantId": "75243ab2-44f8-435c-a7a6-b479385df6d4",
"resultSignature": "None", "durationMs": 0, "correlationId": "ed53faec-49b5-444f-b6af-b928558ca433",
"identity": "LegacyTestOAuthApp", "Level": 4, "properties": {"id": "Directory_ed53faec-49b5-444f-b6af-b928558ca433_XH34Q_29215277",
"category": "ApplicationManagement", "correlationId": "ed53faec-49b5-444f-b6af-b928558ca433",
"result": "success", "resultReason": "", "activityDisplayName": "Add app role assignment
to service principal", "activityDateTime": "2024-02-08T21:49:53.7643129+00:00",
"loggedByService": "Core Directory", "operationType": "Assign", "userAgent": null,
"initiatedBy": {"app": {"appId": null, "displayName": "LegacyTestOAuthApp", "servicePrincipalId":
"fc8c8125-bc0c-499d-8344-e53c6e3caa81", "servicePrincipalName": null}}, "targetResources":
[{"id": "8429eb5c-faeb-4ade-8eac-acc003790769", "displayName": "Office 365 Exchange
Online", "type": "ServicePrincipal", "modifiedProperties": [{"displayName": "AppRole.Id",
"oldValue": null, "newValue": "\"dc890d15-9560-4a4c-9b7f-a736ec74ec40\""}, {"displayName":
"AppRole.Value", "oldValue": null, "newValue": "\"full_access_as_app\""}, {"displayName":
"AppRole.DisplayName", "oldValue": null, "newValue": "\"Use Exchange Web Services
with full access to all mailboxes\""}, {"displayName": "AppRoleAssignment.CreatedDateTime",
"oldValue": null, "newValue": "\"2024-02-08T21:49:53.6813076Z\""}, {"displayName":
"AppRoleAssignment.LastModifiedDateTime", "oldValue": null, "newValue": "\"2024-02-08T21:49:53.6813076Z\""},
{"displayName": "ServicePrincipal.ObjectID", "oldValue": null, "newValue": "\"2e5c2fd0-cca4-452c-9891-a07c0dafd964\""},
{"displayName": "ServicePrincipal.DisplayName", "oldValue": null, "newValue": "\"STRT_Oauth\""},
{"displayName": "ServicePrincipal.AppId", "oldValue": null, "newValue": "\"5f91ce94-4cc5-4ebe-aeb6-f074e57201bb\""},
{"displayName": "ServicePrincipal.Name", "oldValue": null, "newValue": "\"5f91ce94-4cc5-4ebe-aeb6-f074e57201bb\""},
{"displayName": "TargetId.ServicePrincipalNames", "oldValue": null, "newValue":
"\"https://outlook.office.com;Microsoft.Exchange;00000002-0000-0ff1-ce00-000000000000;00000002-0000-0ff1-ce00-000000000000/*.outlook.com;00000002-0000-0ff1-ce00-000000000000/outlook.com;00000002-0000-0ff1-ce00-000000000000/mail.office365.com;00000002-0000-0ff1-ce00-000000000000/outlook.office365.com;https://webmail.apps.mil/;https://ps.protection.outlook.com/;https://outlook-dod.office365.us/;https://outlook.com/;https://outlook.office365.com/;https://outlook.office.com/;https://outlook.office365.com:443/;https://outlook-sdf.office365.com/;https://outlook-sdf.office.com/;https://outlook.office365.us/;https://autodiscover-s.office365.us/;https://ps.compliance.protection.outlook.com;https://manage.protection.apps.mil;https://outlook-tdf.office.com/;https://outlook-tdf-2.office.com/;https://ps.outlook.com\""}],
"administrativeUnits": []}, {"id": "2e5c2fd0-cca4-452c-9891-a07c0dafd964", "displayName":
"5f91ce94-4cc5-4ebe-aeb6-f074e57201bb", "type": "ServicePrincipal", "modifiedProperties":
[], "administrativeUnits": []}], "additionalDetails": [{"key": "User-Agent", "value":
"Mozilla/5.0 (Macintosh; Darwin 23.3.0 Darwin Kernel Version 23.3.0: Wed Dec 20
21:28:58 PST 2023; root:xnu-10002.81.5~7/RELEASE_X86_64; en-US) PowerShell/7.3.4"},
{"key": "AppId", "value": "00000002-0000-0ff1-ce00-000000000000"}]}}'
@@ -0,0 +1,85 @@
name: Azure Active Directory Add member to role
id: 1660d196-127f-4678-81b2-472d51711b07
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
description: Data source object for Azure Active Directory Add member to role
source: Azure AD
sourcetype: azure:monitor:aad
separator: operationName
supported_TA:
- name: Splunk Add-on for Microsoft Cloud Services
url: https://splunkbase.splunk.com/app/3110
version: 5.2.2
fields:
- _time
- Level
- callerIpAddress
- category
- correlationId
- date_hour
- date_mday
- date_minute
- date_month
- date_second
- date_wday
- date_year
- date_zone
- durationMs
- host
- index
- linecount
- operationName
- operationVersion
- properties.activityDateTime
- properties.activityDisplayName
- properties.category
- properties.correlationId
- properties.id
- properties.initiatedBy.user.displayName
- properties.initiatedBy.user.id
- properties.initiatedBy.user.ipAddress
- properties.initiatedBy.user.userPrincipalName
- properties.loggedByService
- properties.operationType
- properties.result
- properties.resultReason
- properties.targetResources{}.displayName
- properties.targetResources{}.id
- properties.targetResources{}.modifiedProperties{}.displayName
- properties.targetResources{}.modifiedProperties{}.newValue
- properties.targetResources{}.modifiedProperties{}.oldValue
- properties.targetResources{}.type
- properties.targetResources{}.userPrincipalName
- properties.userAgent
- punct
- resourceId
- resultSignature
- source
- sourcetype
- splunk_server
- tenantId
- time
- timeendpos
- timestartpos
example_log: '{"time": "2023-04-28T16:39:51.9312625Z", "resourceId": "/tenants/fc69e276-e9e8-4af9-9002-1e410d77244e/providers/Microsoft.aadiam",
"operationName": "Add member to role", "operationVersion": "1.0", "category": "AuditLogs",
"tenantId": "fc69e276-e9e8-4af9-9002-1e410d77244e", "resultSignature": "None", "durationMs":
0, "callerIpAddress": "52.177.250.168", "correlationId": "b425f2d7-2245-4952-b599-61dff8054f2b",
"Level": 4, "properties": {"id": "Directory_b425f2d7-2245-4952-b599-61dff8054f2b_FLAW0_72812697",
"category": "RoleManagement", "correlationId": "b425f2d7-2245-4952-b599-61dff8054f2b",
"result": "success", "resultReason": "", "activityDisplayName": "Add member to role",
"activityDateTime": "2023-04-28T16:39:51.9312625+00:00", "loggedByService": "Core
Directory", "operationType": "Assign", "userAgent": null, "initiatedBy": {"user":
{"id": "3bd47e42-37c9-442f-a2b4-f04de61ef0ce", "displayName": null, "userPrincipalName":
"strt_admin@splunkresearch.com", "ipAddress": "52.177.250.168", "roles": []}}, "targetResources":
[{"id": "0d664d57-a3ee-4049-8642-280a5c7243ef", "displayName": null, "type": "User",
"userPrincipalName": "User1@splunkresearch.com", "modifiedProperties": [{"displayName":
"Role.ObjectID", "oldValue": null, "newValue": "\"38bf5baf-7ec7-4bc2-8920-6d4044da12c2\""},
{"displayName": "Role.DisplayName", "oldValue": null, "newValue": "\"Privileged
Role Administrator\""}, {"displayName": "Role.TemplateId", "oldValue": null, "newValue":
"\"9b895d92-2cd3-44c7-9d02-a6ac2d5ea5c3\""}, {"displayName": "Role.WellKnownObjectName",
"oldValue": null, "newValue": "\"ApplicationAdministrators\""}], "administrativeUnits":
[]}, {"id": "38bf5baf-7ec7-4bc2-8920-6d4044da12c2", "displayName": null, "type":
"Role", "modifiedProperties": [], "administrativeUnits": []}], "additionalDetails":
[]}}'
@@ -0,0 +1,90 @@
name: Azure Active Directory Add owner to application
id: e895ed56-7be4-4b3a-b782-ecd0f594ec4c
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
description: Data source object for Azure Active Directory Add owner to application
source: Azure AD
sourcetype: azure:monitor:aad
separator: operationName
supported_TA:
- name: Splunk Add-on for Microsoft Cloud Services
url: https://splunkbase.splunk.com/app/3110
version: 5.2.2
fields:
- _time
- Level
- callerIpAddress
- category
- correlationId
- date_hour
- date_mday
- date_minute
- date_month
- date_second
- date_wday
- date_year
- date_zone
- durationMs
- eventtype
- host
- index
- linecount
- operationName
- operationVersion
- properties.activityDateTime
- properties.activityDisplayName
- properties.additionalDetails{}.key
- properties.additionalDetails{}.value
- properties.category
- properties.correlationId
- properties.id
- properties.initiatedBy.user.displayName
- properties.initiatedBy.user.id
- properties.initiatedBy.user.ipAddress
- properties.initiatedBy.user.userPrincipalName
- properties.loggedByService
- properties.operationType
- properties.result
- properties.resultReason
- properties.targetResources{}.displayName
- properties.targetResources{}.id
- properties.targetResources{}.modifiedProperties{}.displayName
- properties.targetResources{}.modifiedProperties{}.newValue
- properties.targetResources{}.modifiedProperties{}.oldValue
- properties.targetResources{}.type
- properties.targetResources{}.userPrincipalName
- properties.userAgent
- punct
- resourceId
- resultSignature
- source
- sourcetype
- splunk_server
- tag
- tag::eventtype
- tenantId
- time
- timeendpos
- timestartpos
example_log: '{"time": "2023-06-20T15:54:13.2420879Z", "resourceId": "/tenants/fc69e276-e9e8-4af9-9002-1e410d77244e/providers/Microsoft.aadiam",
"operationName": "Add owner to application", "operationVersion": "1.0", "category":
"AuditLogs", "tenantId": "fc69e276-e9e8-4af9-9002-1e410d77244e", "resultSignature":
"None", "durationMs": 0, "callerIpAddress": "20.190.135.43", "correlationId": "231de5d4-2156-433a-8163-48956bdaa040",
"Level": 4, "properties": {"id": "Directory_231de5d4-2156-433a-8163-48956bdaa040_C21RW_365283677",
"category": "ApplicationManagement", "correlationId": "231de5d4-2156-433a-8163-48956bdaa040",
"result": "success", "resultReason": "", "activityDisplayName": "Add owner to application",
"activityDateTime": "2023-06-20T15:54:13.2420879+00:00", "loggedByService": "Core
Directory", "operationType": "Assign", "userAgent": null, "initiatedBy": {"user":
{"id": "4d3f1865-b395-4430-91dc-1b9dd337712e", "displayName": null, "userPrincipalName":
"globaladmin@splunkresearch.com", "ipAddress": "20.190.135.43", "roles": []}}, "targetResources":
[{"id": "dd92f1af-43d7-47d9-b93c-a78c6b635180", "displayName": null, "type": "User",
"userPrincipalName": "Abigail.Clark@splunkresearch.com", "modifiedProperties": [{"displayName":
"Application.ObjectID", "oldValue": null, "newValue": "\"bb2479d8-5e89-4480-bb7e-3178d5a5d469\""},
{"displayName": "Application.DisplayName", "oldValue": null, "newValue": "\"CloudForge\""},
{"displayName": "Application.AppId", "oldValue": null, "newValue": "\"f0748f3d-45f2-4e2e-a4e1-f2e2b5271bdf\""}],
"administrativeUnits": []}, {"id": "bb2479d8-5e89-4480-bb7e-3178d5a5d469", "displayName":
null, "type": "Application", "modifiedProperties": [], "administrativeUnits": []}],
"additionalDetails": [{"key": "User-Agent", "value": "Mozilla/5.0 (Macintosh; Darwin
22.4.0 Darwin Kernel Version 22.4.0: Mon Mar 6 21:00:17 PST 2023; root:xnu-8796.101.5~3/RELEASE_X86_64;
en-US) PowerShell/7.3.4"}]}}'
@@ -0,0 +1,88 @@
name: Azure Active Directory Add service principal
id: fd89d337-e4c0-4162-ad13-bca36f096fe6
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
description: Data source object for Azure Active Directory Add service principal
source: Azure AD
sourcetype: azure:monitor:aad
separator: operationName
supported_TA:
- name: Splunk Add-on for Microsoft Cloud Services
url: https://splunkbase.splunk.com/app/3110
version: 5.2.2
fields:
- _time
- Level
- category
- correlationId
- date_hour
- date_mday
- date_minute
- date_month
- date_second
- date_wday
- date_year
- date_zone
- durationMs
- host
- index
- linecount
- operationName
- operationVersion
- properties.activityDateTime
- properties.activityDisplayName
- properties.additionalDetails{}.key
- properties.additionalDetails{}.value
- properties.category
- properties.correlationId
- properties.id
- properties.initiatedBy.user.displayName
- properties.initiatedBy.user.id
- properties.initiatedBy.user.ipAddress
- properties.initiatedBy.user.userPrincipalName
- properties.loggedByService
- properties.operationType
- properties.result
- properties.resultReason
- properties.targetResources{}.displayName
- properties.targetResources{}.id
- properties.targetResources{}.modifiedProperties{}.displayName
- properties.targetResources{}.modifiedProperties{}.newValue
- properties.targetResources{}.modifiedProperties{}.oldValue
- properties.targetResources{}.type
- properties.userAgent
- punct
- resourceId
- resultSignature
- source
- sourcetype
- splunk_server
- tenantId
- time
- timeendpos
- timestartpos
example_log: '{"time": "2024-02-07T22:31:14.4970418Z", "resourceId": "/tenants/a417c578-c7ee-480d-a225-d48057e74df5/providers/Microsoft.aadiam",
"operationName": "Add service principal", "operationVersion": "1.0", "category":
"AuditLogs", "tenantId": "a417c578-c7ee-480d-a225-d48057e74df5", "resultSignature":
"None", "durationMs": 0, "correlationId": "ea473f15-64b3-435a-a885-6ee3908919e2",
"Level": 4, "properties": {"id": "Directory_ea473f15-64b3-435a-a885-6ee3908919e2_GSOLK_21152854",
"category": "ApplicationManagement", "correlationId": "ea473f15-64b3-435a-a885-6ee3908919e2",
"result": "success", "resultReason": "", "activityDisplayName": "Add service principal",
"activityDateTime": "2024-02-07T22:31:14.4970418+00:00", "loggedByService": "Core
Directory", "operationType": "Add", "userAgent": null, "initiatedBy": {"user": {"id":
"e4c722ac-3b83-478d-8f52-c388885dc30f", "displayName": null, "userPrincipalName":
"Herman@phantomengineering.onmicrosoft.com", "ipAddress": "", "roles": []}}, "targetResources":
[{"id": "2dedf863-ac93-4f45-87b3-e32f48145380", "displayName": "Malicious11", "type":
"ServicePrincipal", "modifiedProperties": [{"displayName": "AccountEnabled", "oldValue":
"[]", "newValue": "[true]"}, {"displayName": "AppPrincipalId", "oldValue": "[]",
"newValue": "[\"e06366ca-8489-4748-b6a2-d7e4332f45c1\"]"}, {"displayName": "DisplayName",
"oldValue": "[]", "newValue": "[\"Malicious11\"]"}, {"displayName": "ServicePrincipalName",
"oldValue": "[]", "newValue": "[\"e06366ca-8489-4748-b6a2-d7e4332f45c1\"]"}, {"displayName":
"Credential", "oldValue": "[]", "newValue": "[{\"CredentialType\":2,\"KeyStoreId\":\"291154f0-a9f5-45bb-87be-9c8ee5b6d62c\",\"KeyGroupId\":\"291154f0-a9f5-45bb-87be-9c8ee5b6d62c\"}]"},
{"displayName": "Included Updated Properties", "oldValue": null, "newValue": "\"AccountEnabled,
AppPrincipalId, DisplayName, ServicePrincipalName, Credential\""}, {"displayName":
"TargetId.ServicePrincipalNames", "oldValue": null, "newValue": "\"e06366ca-8489-4748-b6a2-d7e4332f45c1\""}],
"administrativeUnits": []}], "additionalDetails": [{"key": "User-Agent", "value":
"Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like
Gecko) Chrome/121.0.0.0 Safari/537.36"}, {"key": "AppId", "value": "e06366ca-8489-4748-b6a2-d7e4332f45c1"}]}}'
@@ -0,0 +1,83 @@
name: Azure Active Directory Add unverified domain
id: d4c01fb1-3b88-46d3-bd12-9b9e256450f7
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
description: Data source object for Azure Active Directory Add unverified domain
source: Azure AD
sourcetype: azure:monitor:aad
separator: operationName
supported_TA:
- name: Splunk Add-on for Microsoft Cloud Services
url: https://splunkbase.splunk.com/app/3110
version: 5.2.2
fields:
- _time
- Level
- callerIpAddress
- category
- correlationId
- date_hour
- date_mday
- date_minute
- date_month
- date_second
- date_wday
- date_year
- date_zone
- durationMs
- host
- index
- linecount
- operationName
- operationVersion
- properties.activityDateTime
- properties.activityDisplayName
- properties.additionalDetails{}.key
- properties.additionalDetails{}.value
- properties.category
- properties.correlationId
- properties.id
- properties.initiatedBy.user.displayName
- properties.initiatedBy.user.id
- properties.initiatedBy.user.ipAddress
- properties.initiatedBy.user.userPrincipalName
- properties.loggedByService
- properties.operationType
- properties.result
- properties.resultReason
- properties.targetResources{}.displayName
- properties.targetResources{}.id
- properties.targetResources{}.modifiedProperties{}.displayName
- properties.targetResources{}.modifiedProperties{}.newValue
- properties.targetResources{}.modifiedProperties{}.oldValue
- properties.userAgent
- punct
- resourceId
- resultSignature
- source
- sourcetype
- splunk_server
- tenantId
- time
- timeendpos
- timestartpos
example_log: '{"time": "2023-07-26T13:45:54.1582053Z", "resourceId": "/tenants/fc69e276-e9e8-4af9-9002-1e410d77244e/providers/Microsoft.aadiam",
"operationName": "Add unverified domain", "operationVersion": "1.0", "category":
"AuditLogs", "tenantId": "fc69e276-e9e8-4af9-9002-1e410d77244e", "resultSignature":
"None", "durationMs": 0, "callerIpAddress": "2601:646:a000:200:6419:f55c:946d:17d1",
"correlationId": "bdab88f3-69a4-4e66-883d-5b1e1558e61b", "Level": 4, "properties":
{"id": "Directory_bdab88f3-69a4-4e66-883d-5b1e1558e61b_311NT_82497138", "category":
"DirectoryManagement", "correlationId": "bdab88f3-69a4-4e66-883d-5b1e1558e61b",
"result": "success", "resultReason": "", "activityDisplayName": "Add unverified
domain", "activityDateTime": "2023-07-26T13:45:54.1582053+00:00", "loggedByService":
"Core Directory", "operationType": "Add", "userAgent": null, "initiatedBy": {"user":
{"id": "728989f4-eb3d-45c2-8741-2f2af4e485ce", "displayName": null, "userPrincipalName":
"tommyr@splunkresearch.com", "ipAddress": "2601:646:a000:200:6419:f55c:946d:17d1",
"roles": []}}, "targetResources": [{"id": null, "displayName": "newdomain.com",
"modifiedProperties": [{"displayName": "Name", "oldValue": "[\"\"]", "newValue":
"[\"newdomain.com\"]"}, {"displayName": "LiveType", "oldValue": "[\"None\"]", "newValue":
"[\"Managed\"]"}, {"displayName": "Included Updated Properties", "oldValue": null,
"newValue": "\"Name,LiveType\""}], "administrativeUnits": []}], "additionalDetails":
[{"key": "User-Agent", "value": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7)
AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36"}]}}'
@@ -0,0 +1,98 @@
name: Azure Active Directory Consent to application
id: 4c5d6c49-53e3-4980-a4de-c63e26291ed0
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
description: Data source object for Azure Active Directory Consent to application
source: Azure AD
sourcetype: azure:monitor:aad
separator: operationName
supported_TA:
- name: Splunk Add-on for Microsoft Cloud Services
url: https://splunkbase.splunk.com/app/3110
version: 5.2.2
fields:
- _time
- Level
- callerIpAddress
- category
- correlationId
- date_hour
- date_mday
- date_minute
- date_month
- date_second
- date_wday
- date_year
- date_zone
- durationMs
- eventtype
- host
- index
- linecount
- operationName
- operationVersion
- properties.activityDateTime
- properties.activityDisplayName
- properties.additionalDetails{}.key
- properties.additionalDetails{}.value
- properties.category
- properties.correlationId
- properties.id
- properties.initiatedBy.user.displayName
- properties.initiatedBy.user.id
- properties.initiatedBy.user.ipAddress
- properties.initiatedBy.user.userPrincipalName
- properties.loggedByService
- properties.operationType
- properties.result
- properties.resultReason
- properties.targetResources{}.displayName
- properties.targetResources{}.id
- properties.targetResources{}.modifiedProperties{}.displayName
- properties.targetResources{}.modifiedProperties{}.newValue
- properties.targetResources{}.modifiedProperties{}.oldValue
- properties.targetResources{}.type
- properties.userAgent
- punct
- resourceId
- resultDescription
- resultSignature
- source
- sourcetype
- splunk_server
- tag
- tag::eventtype
- tenantId
- time
- timeendpos
- timestartpos
example_log: '{"time": "2023-10-27T16:14:14.9747033Z", "resourceId": "/tenants/75243ab2-44f8-435c-a7a6-b479385df6d4/providers/Microsoft.aadiam",
"operationName": "Consent to application", "operationVersion": "1.0", "category":
"AuditLogs", "tenantId": "75243ab2-44f8-435c-a7a6-b479385df6d4", "resultSignature":
"None", "resultDescription": "Microsoft.Online.Security.UserConsentBlockedForRiskyAppsException",
"durationMs": 0, "callerIpAddress": "13.85.188.242", "correlationId": "864210f1-2950-47cb-9e12-1a71dcbdb1d5",
"Level": 4, "properties": {"id": "Directory_864210f1-2950-47cb-9e12-1a71dcbdb1d5_DO21D_338329364",
"category": "ApplicationManagement", "correlationId": "864210f1-2950-47cb-9e12-1a71dcbdb1d5",
"result": "failure", "resultReason": "Microsoft.Online.Security.UserConsentBlockedForRiskyAppsException",
"activityDisplayName": "Consent to application", "activityDateTime": "2023-10-27T16:14:14.9747033+00:00",
"loggedByService": "Core Directory", "operationType": "Assign", "userAgent": null,
"initiatedBy": {"user": {"id": "57e4bd36-9722-4a4a-9729-7203d8e00b72", "displayName":
null, "userPrincipalName": "user15@splunkresearch.onmicrosoft.com", "ipAddress":
"13.85.188.242", "roles": []}}, "targetResources": [{"id": "6228c72e-8895-4681-bbda-238132dc4f3c",
"displayName": "Bad App 1", "type": "Application", "modifiedProperties": [{"displayName":
"ConsentContext.IsAdminConsent", "oldValue": null, "newValue": "\"False\""}, {"displayName":
"ConsentContext.IsAppOnly", "oldValue": null, "newValue": "\"False\""}, {"displayName":
"ConsentContext.OnBehalfOfAll", "oldValue": null, "newValue": "\"False\""}, {"displayName":
"ConsentContext.Tags", "oldValue": null, "newValue": "\"WindowsAzureActiveDirectoryIntegratedApp\""},
{"displayName": "ConsentAction.Permissions", "oldValue": null, "newValue": "\"[]
=> [[Id: AAAAAAAAAAAAAAAAAAAAALSZcc5Sj_NGtUtP2B3pYeI2veRXIpdKSpcpcgPY4Aty, ClientId:
00000000-0000-0000-0000-000000000000, PrincipalId: 57e4bd36-9722-4a4a-9729-7203d8e00b72,
ResourceId: ce7199b4-8f52-46f3-b54b-4fd81de961e2, ConsentType: Principal, Scope:
Mail.Read Mail.Read.Shared Mail.ReadBasic Mail.ReadBasic.Shared Mail.ReadWrite Mail.ReadWrite.Shared
Mail.Send Mail.Send.Shared User.Read, CreatedDateTime: , LastModifiedDateTime ]];
\""}, {"displayName": "ConsentAction.Reason", "oldValue": null, "newValue": "\"Risky
application detected\""}, {"displayName": "MethodExecutionResult.", "oldValue":
null, "newValue": "\"Microsoft.Online.Security.UserConsentBlockedForRiskyAppsException\""}],
"administrativeUnits": []}], "additionalDetails": [{"key": "User-Agent", "value":
"EvoSTS"}, {"key": "AppId", "value": "96f6a3d6-d5aa-4af5-a77a-9319b5283712"}]}}'
@@ -0,0 +1,80 @@
name: Azure Active Directory Disable Strong Authentication
id: 8f31966d-c496-496d-8837-f7fd11f31255
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
description: Data source object for Azure Active Directory Disable Strong Authentication
source: Azure AD
sourcetype: azure:monitor:aad
separator: operationName
supported_TA:
- name: Splunk Add-on for Microsoft Cloud Services
url: https://splunkbase.splunk.com/app/3110
version: 5.2.2
fields:
- _time
- Level
- category
- correlationId
- date_hour
- date_mday
- date_minute
- date_month
- date_second
- date_wday
- date_year
- date_zone
- durationMs
- host
- index
- linecount
- operationName
- operationVersion
- properties.activityDateTime
- properties.activityDisplayName
- properties.category
- properties.correlationId
- properties.id
- properties.initiatedBy.user.displayName
- properties.initiatedBy.user.id
- properties.initiatedBy.user.ipAddress
- properties.initiatedBy.user.userPrincipalName
- properties.loggedByService
- properties.operationType
- properties.result
- properties.resultReason
- properties.targetResources{}.displayName
- properties.targetResources{}.id
- properties.targetResources{}.modifiedProperties{}.displayName
- properties.targetResources{}.modifiedProperties{}.newValue
- properties.targetResources{}.modifiedProperties{}.oldValue
- properties.targetResources{}.type
- properties.targetResources{}.userPrincipalName
- properties.userAgent
- punct
- resourceId
- resultSignature
- source
- sourcetype
- splunk_server
- tenantId
- time
- timeendpos
- timestartpos
example_log: '{"time": "2023-07-11T00:01:35.0251899Z", "resourceId": "/tenants/fc69e276-e9e8-4af9-9002-1e410d77244e/providers/Microsoft.aadiam",
"operationName": "Disable Strong Authentication", "operationVersion": "1.0", "category":
"AuditLogs", "tenantId": "fc69e276-e9e8-4af9-9002-1e410d77244e", "resultSignature":
"None", "durationMs": 0, "correlationId": "7e3ee05c-ce4f-4ff1-8230-55555c25c97e",
"Level": 4, "properties": {"id": "Directory_7e3ee05c-ce4f-4ff1-8230-55555c25c97e_DADCR_14299826",
"category": "UserManagement", "correlationId": "7e3ee05c-ce4f-4ff1-8230-55555c25c97e",
"result": "success", "resultReason": "", "activityDisplayName": "Disable Strong
Authentication", "activityDateTime": "2023-07-11T00:01:35.0251899+00:00", "loggedByService":
"Core Directory", "operationType": "Update", "userAgent": null, "initiatedBy": {"user":
{"id": "728989f4-eb3d-45c2-8741-2f2af4e485ce", "displayName": null, "userPrincipalName":
"oops@splunkresearch.com", "ipAddress": "", "roles": []}}, "targetResources": [{"id":
"94b969a3-11cb-4075-a1fd-9fee3daf692e", "displayName": null, "type": "User", "userPrincipalName":
"Abigail.Clark@splunkresearch.com", "modifiedProperties": [{"displayName": "StrongAuthenticationRequirement",
"oldValue": "[{\"RelyingParty\":\"*\",\"State\":1,\"RememberDevicesNotIssuedBefore\":\"2023-07-11T00:01:26+00:00\"}]",
"newValue": "[]"}, {"displayName": "Included Updated Properties", "oldValue": null,
"newValue": "\"StrongAuthenticationRequirement\""}], "administrativeUnits": []}],
"additionalDetails": []}}'
@@ -0,0 +1,81 @@
name: Azure Active Directory Enable account
id: cb49f3cd-04ad-415c-a5ed-9b27b2829fa7
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
description: Data source object for Azure Active Directory Enable account
source: Azure AD
sourcetype: azure:monitor:aad
separator: operationName
supported_TA:
- name: Splunk Add-on for Microsoft Cloud Services
url: https://splunkbase.splunk.com/app/3110
version: 5.2.2
fields:
- _time
- Level
- callerIpAddress
- category
- correlationId
- date_hour
- date_mday
- date_minute
- date_month
- date_second
- date_wday
- date_year
- date_zone
- durationMs
- host
- index
- linecount
- operationName
- operationVersion
- properties.activityDateTime
- properties.activityDisplayName
- properties.category
- properties.correlationId
- properties.id
- properties.initiatedBy.user.displayName
- properties.initiatedBy.user.id
- properties.initiatedBy.user.ipAddress
- properties.initiatedBy.user.userPrincipalName
- properties.loggedByService
- properties.operationType
- properties.result
- properties.resultReason
- properties.targetResources{}.displayName
- properties.targetResources{}.id
- properties.targetResources{}.modifiedProperties{}.displayName
- properties.targetResources{}.modifiedProperties{}.newValue
- properties.targetResources{}.modifiedProperties{}.oldValue
- properties.targetResources{}.type
- properties.targetResources{}.userPrincipalName
- properties.userAgent
- punct
- resourceId
- resultSignature
- source
- sourcetype
- splunk_server
- tenantId
- time
- timeendpos
- timestartpos
example_log: '{"time": "2023-07-24T14:28:15.2223487Z", "resourceId": "/tenants/fc69e276-e9e8-4af9-9002-1e410d77244e/providers/Microsoft.aadiam",
"operationName": "Enable account", "operationVersion": "1.0", "category": "AuditLogs",
"tenantId": "fc69e276-e9e8-4af9-9002-1e410d77244e", "resultSignature": "None", "durationMs":
0, "callerIpAddress": "2601:646:a000:200:b0ee:600c:de8a:c7d5", "correlationId":
"d34f6d2e-3120-4b96-b922-e06090f6a497", "Level": 4, "properties": {"id": "Directory_d34f6d2e-3120-4b96-b922-e06090f6a497_VPRLA_316413188",
"category": "UserManagement", "correlationId": "d34f6d2e-3120-4b96-b922-e06090f6a497",
"result": "success", "resultReason": "", "activityDisplayName": "Enable account",
"activityDateTime": "2023-07-24T14:28:15.2223487+00:00", "loggedByService": "Core
Directory", "operationType": "Update", "userAgent": null, "initiatedBy": {"user":
{"id": "728989f4-eb3d-45c2-8741-2f2af4e485ce", "displayName": null, "userPrincipalName":
"tommyr@splunkresearch.com", "ipAddress": "2601:646:a000:200:b0ee:600c:de8a:c7d5",
"roles": []}}, "targetResources": [{"id": "83a3158c-1d08-4686-b5f9-72fb34cb606e",
"displayName": null, "type": "User", "userPrincipalName": "testuser@splunkresearch.com",
"modifiedProperties": [{"displayName": "AccountEnabled", "oldValue": "[false]",
"newValue": "[true]"}, {"displayName": "Included Updated Properties", "oldValue":
null, "newValue": "\"AccountEnabled\""}], "administrativeUnits": []}], "additionalDetails":
[]}}'
@@ -0,0 +1,82 @@
name: Azure Active Directory Invite external user
id: d3818bd5-f283-4518-8b67-df19240c3e40
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
description: Data source object for Azure Active Directory Invite external user
source: Azure AD
sourcetype: azure:monitor:aad
separator: operationName
supported_TA:
- name: Splunk Add-on for Microsoft Cloud Services
url: https://splunkbase.splunk.com/app/3110
version: 5.2.2
fields:
- _time
- Level
- callerIpAddress
- category
- correlationId
- date_hour
- date_mday
- date_minute
- date_month
- date_second
- date_wday
- date_year
- date_zone
- durationMs
- host
- index
- linecount
- operationName
- operationVersion
- properties.activityDateTime
- properties.activityDisplayName
- properties.additionalDetails{}.key
- properties.additionalDetails{}.value
- properties.category
- properties.correlationId
- properties.id
- properties.initiatedBy.user.displayName
- properties.initiatedBy.user.id
- properties.initiatedBy.user.ipAddress
- properties.initiatedBy.user.userPrincipalName
- properties.loggedByService
- properties.operationType
- properties.result
- properties.resultReason
- properties.targetResources{}.displayName
- properties.targetResources{}.id
- properties.targetResources{}.type
- properties.targetResources{}.userPrincipalName
- properties.userAgent
- punct
- resourceId
- resultSignature
- source
- sourcetype
- splunk_server
- tenantId
- time
- timeendpos
- timestartpos
example_log: '{"time": "2023-07-13T00:29:59.5100003Z", "resourceId": "/tenants/fc69e276-e9e8-4af9-9002-1e410d77244e/providers/Microsoft.aadiam",
"operationName": "Invite external user", "operationVersion": "1.0", "category":
"AuditLogs", "tenantId": "fc69e276-e9e8-4af9-9002-1e410d77244e", "resultSignature":
"None", "durationMs": 0, "callerIpAddress": "40.126.4.40", "correlationId": "e7d580a6-eaac-4f82-843c-40b0b5f3cf99",
"Level": 4, "properties": {"id": "Invited Users_e7d580a6-eaac-4f82-843c-40b0b5f3cf99_YNUMP_7291793",
"category": "UserManagement", "correlationId": "e7d580a6-eaac-4f82-843c-40b0b5f3cf99",
"result": "success", "resultReason": null, "activityDisplayName": "Invite external
user", "activityDateTime": "2023-07-13T00:29:59.5100003+00:00", "loggedByService":
"Invited Users", "operationType": "Add", "userAgent": null, "initiatedBy": {"user":
{"id": "728989f4-eb3d-45c2-8741-2f2af4e485ce", "displayName": null, "userPrincipalName":
"oopsr@splunkresearch.com", "ipAddress": "40.126.4.40", "roles": []}}, "targetResources":
[{"id": "f416526a-17ee-4129-8ca9-f5ee55f69f34", "displayName": "oops", "type": "User",
"userPrincipalName": "oops360_gmail.com#EXT#@strtadminsplunkresearch.onmicrosoft.com",
"modifiedProperties": [], "administrativeUnits": []}], "additionalDetails": [{"key":
"oid", "value": "728989f4-eb3d-45c2-8741-2f2af4e485ce"}, {"key": "tid", "value":
"fc69e276-e9e8-4af9-9002-1e410d77244e"}, {"key": "ipaddr", "value": "2601:646:a000:200:c4db:f288:7e28:21b3"},
{"key": "wids", "value": "62e90394-69f5-4237-9190-012177145e10"}, {"key": "InvitationId",
"value": "65c7d12f-c6f3-44f0-8fad-4f57a1020484"}, {"key": "invitedUserEmailAddress",
"value": "oops360@gmail.com"}]}}'
@@ -0,0 +1,79 @@
name: Azure Active Directory Reset password (by admin)
id: dcd0e4dc-68f8-4b77-a66f-89c57b3afa6b
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
description: Data source object for Azure Active Directory Reset password (by admin)
source: Azure AD
sourcetype: azure:monitor:aad
separator: operationName
supported_TA:
- name: Splunk Add-on for Microsoft Cloud Services
url: https://splunkbase.splunk.com/app/3110
version: 5.2.2
fields:
- _time
- Level
- callerIpAddress
- category
- correlationId
- date_hour
- date_mday
- date_minute
- date_month
- date_second
- date_wday
- date_year
- date_zone
- durationMs
- host
- index
- linecount
- operationName
- operationVersion
- properties.activityDateTime
- properties.activityDisplayName
- properties.additionalDetails{}.key
- properties.additionalDetails{}.value
- properties.category
- properties.correlationId
- properties.id
- properties.initiatedBy.user.displayName
- properties.initiatedBy.user.id
- properties.initiatedBy.user.ipAddress
- properties.initiatedBy.user.userPrincipalName
- properties.loggedByService
- properties.operationType
- properties.result
- properties.resultReason
- properties.targetResources{}.displayName
- properties.targetResources{}.id
- properties.targetResources{}.type
- properties.targetResources{}.userPrincipalName
- properties.userAgent
- punct
- resourceId
- resultDescription
- resultSignature
- source
- sourcetype
- splunk_server
- tenantId
- time
- timeendpos
- timestartpos
example_log: '{"time": "2023-07-24T14:28:55.0648789Z", "resourceId": "/tenants/fc69e276-e9e8-4af9-9002-1e410d77244e/providers/Microsoft.aadiam",
"operationName": "Reset password (by admin)", "operationVersion": "1.0", "category":
"AuditLogs", "tenantId": "fc69e276-e9e8-4af9-9002-1e410d77244e", "resultSignature":
"None", "resultDescription": "None", "durationMs": 0, "callerIpAddress": "40.81.4.144",
"correlationId": "724ff6ae-0f36-4f2f-a20f-f043e0c73006", "Level": 4, "properties":
{"id": "SSPR_724ff6ae-0f36-4f2f-a20f-f043e0c73006_P1CQE_8605821", "category": "UserManagement",
"correlationId": "724ff6ae-0f36-4f2f-a20f-f043e0c73006", "result": "success", "resultReason":
"None", "activityDisplayName": "Reset password (by admin)", "activityDateTime":
"2023-07-24T14:28:55.0648789+00:00", "loggedByService": "Self-service Password Management",
"operationType": "Update", "userAgent": null, "initiatedBy": {"user": {"id": "728989f4-eb3d-45c2-8741-2f2af4e485ce",
"displayName": null, "userPrincipalName": "tommyr@splunkresearch.com", "ipAddress":
"40.81.4.144", "roles": []}}, "targetResources": [{"id": "83a3158c-1d08-4686-b5f9-72fb34cb606e",
"displayName": "test", "type": "User", "userPrincipalName": "testuser@splunkresearch.com",
"modifiedProperties": [], "administrativeUnits": []}], "additionalDetails": [{"key":
"OnPremisesAgent", "value": "None"}]}}'
@@ -0,0 +1,83 @@
name: Azure Active Directory Set domain authentication
id: e7bcdab9-908c-40ab-ba38-5db54fa87750
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
description: Data source object for Azure Active Directory Set domain authentication
source: Azure AD
sourcetype: azure:monitor:aad
separator: operationName
supported_TA:
- name: Splunk Add-on for Microsoft Cloud Services
url: https://splunkbase.splunk.com/app/3110
version: 5.2.2
fields:
- _time
- Level
- callerIpAddress
- category
- correlationId
- date_hour
- date_mday
- date_minute
- date_month
- date_second
- date_wday
- date_year
- date_zone
- durationMs
- host
- index
- linecount
- operationName
- operationVersion
- properties.activityDateTime
- properties.activityDisplayName
- properties.additionalDetails{}.key
- properties.additionalDetails{}.value
- properties.category
- properties.correlationId
- properties.id
- properties.initiatedBy.user.displayName
- properties.initiatedBy.user.id
- properties.initiatedBy.user.ipAddress
- properties.initiatedBy.user.userPrincipalName
- properties.loggedByService
- properties.operationType
- properties.result
- properties.resultReason
- properties.targetResources{}.displayName
- properties.targetResources{}.id
- properties.targetResources{}.modifiedProperties{}.displayName
- properties.targetResources{}.modifiedProperties{}.newValue
- properties.targetResources{}.modifiedProperties{}.oldValue
- properties.userAgent
- punct
- resourceId
- resultSignature
- source
- sourcetype
- splunk_server
- tenantId
- time
- timeendpos
- timestartpos
example_log: '{"time": "2023-07-26T13:44:59.0372448Z", "resourceId": "/tenants/fc69e276-e9e8-4af9-9002-1e410d77244e/providers/Microsoft.aadiam",
"operationName": "Set domain authentication", "operationVersion": "1.0", "category":
"AuditLogs", "tenantId": "fc69e276-e9e8-4af9-9002-1e410d77244e", "resultSignature":
"None", "durationMs": 0, "callerIpAddress": "2601:646:a000:200:6419:f55c:946d:17d1",
"correlationId": "57e60ecc-17b8-4ab5-815e-d538e1ca32a4", "Level": 4, "properties":
{"id": "Directory_57e60ecc-17b8-4ab5-815e-d538e1ca32a4_XDHHZ_434456733", "category":
"DirectoryManagement", "correlationId": "57e60ecc-17b8-4ab5-815e-d538e1ca32a4",
"result": "success", "resultReason": "", "activityDisplayName": "Add unverified
domain", "activityDateTime": "2023-07-26T13:44:59.0372448+00:00", "loggedByService":
"Core Directory", "operationType": "Add", "userAgent": null, "initiatedBy": {"user":
{"id": "728989f4-eb3d-45c2-8741-2f2af4e485ce", "displayName": null, "userPrincipalName":
"tommyr@splunkresearch.com", "ipAddress": "2601:646:a000:200:6419:f55c:946d:17d1",
"roles": []}}, "targetResources": [{"id": null, "displayName": "newdomain.com",
"modifiedProperties": [{"displayName": "Name", "oldValue": "[\"\"]", "newValue":
"[\"newdomain.com\"]"}, {"displayName": "LiveType", "oldValue": "[\"None\"]", "newValue":
"[\"Managed\"]"}, {"displayName": "Included Updated Properties", "oldValue": null,
"newValue": "\"Name,LiveType\""}], "administrativeUnits": []}], "additionalDetails":
[{"key": "User-Agent", "value": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7)
AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36"}]}}'
@@ -0,0 +1,161 @@
name: Azure Active Directory Sign-in activity
id: f9ed0a3a-9e20-4198-a035-d0a29593fbe0
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
description: Data source object for Azure Active Directory Sign-in activity
source: Azure AD
sourcetype: azure:monitor:aad
separator: operationName
supported_TA:
- name: Splunk Add-on for Microsoft Cloud Services
url: https://splunkbase.splunk.com/app/3110
version: 5.2.2
fields:
- _time
- Level
- callerIpAddress
- category
- correlationId
- date_hour
- date_mday
- date_minute
- date_month
- date_second
- date_wday
- date_year
- date_zone
- durationMs
- host
- identity
- index
- linecount
- location
- operationName
- operationVersion
- properties.alternateSignInName
- properties.appDisplayName
- properties.appId
- properties.appServicePrincipalId
- properties.authenticationDetails{}.RequestSequence
- properties.authenticationDetails{}.StatusSequence
- properties.authenticationDetails{}.authenticationMethod
- properties.authenticationDetails{}.authenticationMethodDetail
- properties.authenticationDetails{}.authenticationStepDateTime
- properties.authenticationDetails{}.authenticationStepRequirement
- properties.authenticationDetails{}.authenticationStepResultDetail
- properties.authenticationDetails{}.succeeded
- properties.authenticationProcessingDetails{}.key
- properties.authenticationProcessingDetails{}.value
- properties.authenticationProtocol
- properties.authenticationRequirement
- properties.authenticationRequirementPolicies{}.detail
- properties.authenticationRequirementPolicies{}.requirementProvider
- properties.autonomousSystemNumber
- properties.clientAppUsed
- properties.clientCredentialType
- properties.conditionalAccessStatus
- properties.correlationId
- properties.createdDateTime
- properties.crossTenantAccessType
- properties.deviceDetail.deviceId
- properties.deviceDetail.operatingSystem
- properties.flaggedForReview
- properties.homeTenantId
- properties.id
- properties.incomingTokenType
- properties.ipAddress
- properties.isInteractive
- properties.isTenantRestricted
- properties.location.city
- properties.location.countryOrRegion
- properties.location.geoCoordinates.latitude
- properties.location.geoCoordinates.longitude
- properties.location.state
- properties.originalRequestId
- properties.originalTransferMethod
- properties.processingTimeInMilliseconds
- properties.resourceDisplayName
- properties.resourceId
- properties.resourceServicePrincipalId
- properties.resourceTenantId
- properties.riskDetail
- properties.riskLevelAggregated
- properties.riskLevelDuringSignIn
- properties.riskState
- properties.rngcStatus
- properties.servicePrincipalId
- properties.signInIdentifier
- properties.signInTokenProtectionStatus
- properties.ssoExtensionVersion
- properties.status.additionalDetails
- properties.status.errorCode
- properties.status.failureReason
- properties.tenantId
- properties.tokenIssuerName
- properties.tokenIssuerType
- properties.uniqueTokenIdentifier
- properties.userAgent
- properties.userDisplayName
- properties.userId
- properties.userPrincipalName
- properties.userType
- punct
- resourceId
- resultDescription
- resultSignature
- resultType
- source
- sourcetype
- splunk_server
- tenantId
- time
- timeendpos
- timestartpos
example_log: '{"time": "2023-10-24T20:13:31.4449614Z", "resourceId": "/tenants/887c9144-28b8-431b-885b-764fdeefcf62/providers/Microsoft.aadiam",
"operationName": "Sign-in activity", "operationVersion": "1.0", "category": "SignInLogs",
"tenantId": "887c9144-28b8-431b-885b-764fdeefcf62", "resultType": "50076", "resultSignature":
"None", "resultDescription": "Due to a configuration change made by your administrator,
or because you moved to a new location, you must use multi-factor authentication
to access the resource.", "durationMs": 0, "callerIpAddress": "1.2.3.4", "correlationId":
"1f577997-0710-4bd4-848e-5854f748f7dc", "identity": "user15", "Level": 4, "location":
"US", "properties": {"id": "22608a25-1d9b-44b5-b0f2-cb94f06b2d00", "createdDateTime":
"2023-10-24T20:01:11.9490387+00:00", "userDisplayName": "user15", "userPrincipalName":
"user15@splunkresearch.onmicrosoft.com", "userId": "57e4bd36-9722-4a4a-9729-7203d8e00b72",
"appId": "1b730954-1685-4b74-9bfd-dac224a7b894", "appDisplayName": "Azure Active
Directory PowerShell", "ipAddress": "1.2.3.4", "status": {"errorCode": 50076, "failureReason":
"Due to a configuration change made by your administrator, or because you moved
to a new location, you must use multi-factor authentication to access the resource.",
"additionalDetails": "MFA required in Azure AD"}, "clientAppUsed": "Mobile Apps
and Desktop clients", "userAgent": "Mozilla/5.0 (Windows NT; Windows NT 10.0; en-US)
WindowsPowerShell/5.1.22621.2428", "deviceDetail": {"deviceId": "", "operatingSystem":
"Windows"}, "location": {"city": "Rochester", "state": "New York", "countryOrRegion":
"US", "geoCoordinates": {"latitude": 20.756160123483984, "longitude": -73.99697875976562}},
"mfaDetail": {}, "correlationId": "1f577997-0710-4bd4-848e-5854f748f7dc", "conditionalAccessStatus":
"notApplied", "appliedConditionalAccessPolicies": [], "authenticationContextClassReferences":
[], "originalRequestId": "22608a25-1d9b-44b5-b0f2-cb94f06b2d00", "isInteractive":
true, "tokenIssuerName": "", "tokenIssuerType": "AzureAD", "authenticationProcessingDetails":
[{"key": "Legacy TLS (TLS 1.0, 1.1, 3DES)", "value": "False"}, {"key": "Is CAE Token",
"value": "False"}], "networkLocationDetails": [], "clientCredentialType": "none",
"processingTimeInMilliseconds": 72, "riskDetail": "none", "riskLevelAggregated":
"none", "riskLevelDuringSignIn": "none", "riskState": "none", "riskEventTypes":
[], "riskEventTypes_v2": [], "resourceDisplayName": "Windows Azure Active Directory",
"resourceId": "00000002-0000-0000-c000-000000000000", "resourceTenantId": "887c9144-28b8-431b-885b-764fdeefcf62",
"homeTenantId": "887c9144-28b8-431b-885b-764fdeefcf62", "tenantId": "887c9144-28b8-431b-885b-764fdeefcf62",
"authenticationDetails": [{"authenticationStepDateTime": "2023-10-24T20:01:11.9490387+00:00",
"authenticationMethod": "Password", "authenticationMethodDetail": "Password in the
cloud", "succeeded": true, "authenticationStepResultDetail": "Correct password",
"authenticationStepRequirement": "Primary authentication", "StatusSequence": 0,
"RequestSequence": 1}, {"authenticationStepDateTime": "2023-10-24T20:01:11.9490387+00:00",
"succeeded": false, "authenticationStepResultDetail": "MFA required in Azure AD",
"authenticationStepRequirement": "Primary authentication"}], "authenticationRequirementPolicies":
[{"requirementProvider": "user", "detail": "Per-user MFA"}], "sessionLifetimePolicies":
[], "authenticationRequirement": "multiFactorAuthentication", "alternateSignInName":
"user15@splunkresearch.onmicrosoft.com", "signInIdentifier": "user15@splunkresearch.onmicrosoft.com",
"servicePrincipalId": "", "userType": "Member", "flaggedForReview": false, "isTenantRestricted":
false, "autonomousSystemNumber": 12271, "crossTenantAccessType": "none", "privateLinkDetails":
{}, "ssoExtensionVersion": "", "uniqueTokenIdentifier": "JYpgIpsdtUSw8suU8GstAA",
"authenticationStrengths": [], "incomingTokenType": "none", "authenticationProtocol":
"ropc", "appServicePrincipalId": null, "resourceServicePrincipalId": "56ad242f-e13b-47fc-8de8-19e3bf6f6575",
"rngcStatus": 0, "signInTokenProtectionStatus": "none", "originalTransferMethod":
"none"}}'
@@ -0,0 +1,83 @@
name: Azure Active Directory Update application
id: 2c08188a-ba25-496e-87c7-803cf28b6c90
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
description: Data source object for Azure Active Directory Update application
source: Azure AD
sourcetype: azure:monitor:aad
separator: operationName
supported_TA:
- name: Splunk Add-on for Microsoft Cloud Services
url: https://splunkbase.splunk.com/app/3110
version: 5.2.2
fields:
- _time
- Level
- category
- correlationId
- date_hour
- date_mday
- date_minute
- date_month
- date_second
- date_wday
- date_year
- date_zone
- durationMs
- host
- index
- linecount
- operationName
- operationVersion
- properties.activityDateTime
- properties.activityDisplayName
- properties.additionalDetails{}.key
- properties.additionalDetails{}.value
- properties.category
- properties.correlationId
- properties.id
- properties.initiatedBy.user.displayName
- properties.initiatedBy.user.id
- properties.initiatedBy.user.ipAddress
- properties.initiatedBy.user.userPrincipalName
- properties.loggedByService
- properties.operationType
- properties.result
- properties.resultReason
- properties.targetResources{}.displayName
- properties.targetResources{}.id
- properties.targetResources{}.modifiedProperties{}.displayName
- properties.targetResources{}.modifiedProperties{}.newValue
- properties.targetResources{}.modifiedProperties{}.oldValue
- properties.targetResources{}.type
- properties.userAgent
- punct
- resourceId
- resultSignature
- source
- sourcetype
- splunk_server
- tenantId
- time
- timeendpos
- timestartpos
example_log: '{"time": "2024-01-29T21:31:03.0102031Z", "resourceId": "/tenants/75243ab2-44f8-435c-a7a6-b479385df6d4/providers/Microsoft.aadiam",
"operationName": "Update application", "operationVersion": "1.0", "category": "AuditLogs",
"tenantId": "75243ab2-44f8-435c-a7a6-b479385df6d4", "resultSignature": "None", "durationMs":
0, "correlationId": "a5396d2b-fcf6-41e7-9219-c6239f1298e3", "Level": 4, "properties":
{"id": "Directory_a5396d2b-fcf6-41e7-9219-c6239f1298e3_DGBDP_1548236", "category":
"ApplicationManagement", "correlationId": "a5396d2b-fcf6-41e7-9219-c6239f1298e3",
"result": "success", "resultReason": "", "activityDisplayName": "Update application",
"activityDateTime": "2024-01-29T21:31:03.0102031+00:00", "loggedByService": "Core
Directory", "operationType": "Update", "userAgent": null, "initiatedBy": {"user":
{"id": "e4c722ac-3b83-478d-8f52-c388885dc30f", "displayName": null, "userPrincipalName":
"user30@splunkresearch.onmicrosoft.com", "ipAddress": "", "roles": []}}, "targetResources":
[{"id": "75924835-d844-4947-96ba-18074e997386", "displayName": "MaliciousApp", "type":
"Application", "modifiedProperties": [{"displayName": "RequiredResourceAccess",
"oldValue": "[{\"ResourceAppId\":\"00000003-0000-0000-c000-000000000000\",\"RequiredAppPermissions\":[{\"EntitlementId\":\"570282fd-fa5c-430d-a7fd-fc8dc98a9dca\",\"DirectAccessGrant\":false,\"ImpersonationAccessGrants\":[20]},{\"EntitlementId\":\"7427e0e9-2fba-42fe-b0c0-848c9e6a8182\",\"DirectAccessGrant\":false,\"ImpersonationAccessGrants\":[20]},{\"EntitlementId\":\"e1fe6dd8-ba31-4d61-89e7-88639da4683d\",\"DirectAccessGrant\":false,\"ImpersonationAccessGrants\":[20]},{\"EntitlementId\":\"810c84a8-4a9e-49e6-bf7d-12d183f40d01\",\"DirectAccessGrant\":true,\"ImpersonationAccessGrants\":[]}],\"EncodingVersion\":1}]",
"newValue": "[{\"ResourceAppId\":\"00000003-0000-0000-c000-000000000000\",\"RequiredAppPermissions\":[{\"EntitlementId\":\"570282fd-fa5c-430d-a7fd-fc8dc98a9dca\",\"DirectAccessGrant\":false,\"ImpersonationAccessGrants\":[20]},{\"EntitlementId\":\"7427e0e9-2fba-42fe-b0c0-848c9e6a8182\",\"DirectAccessGrant\":false,\"ImpersonationAccessGrants\":[20]},{\"EntitlementId\":\"e1fe6dd8-ba31-4d61-89e7-88639da4683d\",\"DirectAccessGrant\":false,\"ImpersonationAccessGrants\":[20]},{\"EntitlementId\":\"810c84a8-4a9e-49e6-bf7d-12d183f40d01\",\"DirectAccessGrant\":true,\"ImpersonationAccessGrants\":[]}],\"EncodingVersion\":1},{\"ResourceAppId\":\"00000002-0000-0ff1-ce00-000000000000\",\"RequiredAppPermissions\":[{\"EntitlementId\":\"dc890d15-9560-4a4c-9b7f-a736ec74ec40\",\"DirectAccessGrant\":true,\"ImpersonationAccessGrants\":[]}],\"EncodingVersion\":1}]"},
{"displayName": "Included Updated Properties", "oldValue": null, "newValue": "\"RequiredResourceAccess\""}],
"administrativeUnits": []}], "additionalDetails": [{"key": "User-Agent", "value":
"Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like
Gecko) Chrome/120.0.0.0 Safari/537.36"}, {"key": "AppId", "value": "867f0d29-0eab-4017-b691-c4713cc7d7b0"}]}}'
@@ -0,0 +1,84 @@
name: Azure Active Directory Update authorization policy
id: c5b7ffcd-73d8-4fe5-afd8-b1218d715c0c
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
description: Data source object for Azure Active Directory Update authorization policy
source: Azure AD
sourcetype: azure:monitor:aad
separator: operationName
supported_TA:
- name: Splunk Add-on for Microsoft Cloud Services
url: https://splunkbase.splunk.com/app/3110
version: 5.2.2
fields:
- _time
- Level
- callerIpAddress
- category
- correlationId
- date_hour
- date_mday
- date_minute
- date_month
- date_second
- date_wday
- date_year
- date_zone
- durationMs
- host
- index
- linecount
- operationName
- operationVersion
- properties.activityDateTime
- properties.activityDisplayName
- properties.additionalDetails{}.key
- properties.additionalDetails{}.value
- properties.category
- properties.correlationId
- properties.id
- properties.initiatedBy.user.displayName
- properties.initiatedBy.user.id
- properties.initiatedBy.user.ipAddress
- properties.initiatedBy.user.userPrincipalName
- properties.loggedByService
- properties.operationType
- properties.result
- properties.resultReason
- properties.targetResources{}.displayName
- properties.targetResources{}.id
- properties.targetResources{}.modifiedProperties{}.displayName
- properties.targetResources{}.modifiedProperties{}.newValue
- properties.targetResources{}.modifiedProperties{}.oldValue
- properties.targetResources{}.type
- properties.userAgent
- punct
- resourceId
- resultSignature
- source
- sourcetype
- splunk_server
- tenantId
- time
- timeendpos
- timestartpos
example_log: '{"time": "2023-10-26T19:22:20.2814027Z", "resourceId": "/tenants/5f210575-a69b-41a7-b623-3f6d79ccd432/providers/Microsoft.aadiam",
"operationName": "Update authorization policy", "operationVersion": "1.0", "category":
"AuditLogs", "tenantId": "5f210575-a69b-41a7-b623-3f6d79ccd432", "resultSignature":
"None", "durationMs": 0, "callerIpAddress": "1.2.3.4", "correlationId": "cc46d719-4c0f-4b78-8795-b0d6ca5b2065",
"Level": 4, "properties": {"id": "Directory_cc46d719-4c0f-4b78-8795-b0d6ca5b2065_6CH7M_196574953",
"category": "AuthorizationPolicy", "correlationId": "cc46d719-4c0f-4b78-8795-b0d6ca5b2065",
"result": "success", "resultReason": "", "activityDisplayName": "Update authorization
policy", "activityDateTime": "2023-10-26T19:22:20.2814027+00:00", "loggedByService":
"Core Directory", "operationType": "Update", "userAgent": null, "initiatedBy": {"user":
{"id": "e4c722ac-3b83-478d-8f52-c388885dc30f", "displayName": null, "userPrincipalName":
"attacker@splunkresearch.onmicrosoft.com", "ipAddress": "1.2.3.4", "roles": []}},
"targetResources": [{"id": "24484114-1daa-4700-aaf7-44ee5cbe5678", "displayName":
"Authorization Policy", "type": "Other", "modifiedProperties": [{"displayName":
"AllowUserConsentForRiskyApps", "oldValue": "[false]", "newValue": "[true]"}, {"displayName":
"PermissionGrantPolicyIdsAssignedToDefaultUserRole", "oldValue": "[\"ManagePermissionGrantsForSelf.microsoft-user-default-legacy\"]",
"newValue": "[\"microsoft-user-default-legacy\"]"}, {"displayName": "Included Updated
Properties", "oldValue": null, "newValue": "\"AllowUserConsentForRiskyApps, PermissionGrantPolicyIdsAssignedToDefaultUserRole\""}],
"administrativeUnits": []}], "additionalDetails": [{"key": "User-Agent", "value":
"Swagger-Codegen/1.0.0.0/csharp/msal"}]}}'
@@ -0,0 +1,83 @@
name: Azure Active Directory Update user
id: 5495c90a-047c-4b8e-b2fe-1db6282d3872
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
description: Data source object for Azure Active Directory Update user
source: Azure AD
sourcetype: azure:monitor:aad
separator: operationName
supported_TA:
- name: Splunk Add-on for Microsoft Cloud Services
url: https://splunkbase.splunk.com/app/3110
version: 5.2.2
fields:
- _time
- Level
- callerIpAddress
- category
- correlationId
- date_hour
- date_mday
- date_minute
- date_month
- date_second
- date_wday
- date_year
- date_zone
- durationMs
- host
- index
- linecount
- operationName
- operationVersion
- properties.activityDateTime
- properties.activityDisplayName
- properties.additionalDetails{}.key
- properties.additionalDetails{}.value
- properties.category
- properties.correlationId
- properties.id
- properties.initiatedBy.user.displayName
- properties.initiatedBy.user.id
- properties.initiatedBy.user.ipAddress
- properties.initiatedBy.user.userPrincipalName
- properties.loggedByService
- properties.operationType
- properties.result
- properties.resultReason
- properties.targetResources{}.displayName
- properties.targetResources{}.id
- properties.targetResources{}.modifiedProperties{}.displayName
- properties.targetResources{}.modifiedProperties{}.newValue
- properties.targetResources{}.modifiedProperties{}.oldValue
- properties.targetResources{}.type
- properties.targetResources{}.userPrincipalName
- properties.userAgent
- punct
- resourceId
- resultSignature
- source
- sourcetype
- splunk_server
- tenantId
- time
- timeendpos
- timestartpos
example_log: '{"time": "2023-07-24T14:28:15.2233481Z", "resourceId": "/tenants/fc69e276-e9e8-4af9-9002-1e410d77244e/providers/Microsoft.aadiam",
"operationName": "Update user", "operationVersion": "1.0", "category": "AuditLogs",
"tenantId": "fc69e276-e9e8-4af9-9002-1e410d77244e", "resultSignature": "None", "durationMs":
0, "callerIpAddress": "2601:646:a000:200:b0ee:600c:de8a:c7d5", "correlationId":
"d34f6d2e-3120-4b96-b922-e06090f6a497", "Level": 4, "properties": {"id": "Directory_d34f6d2e-3120-4b96-b922-e06090f6a497_VPRLA_316413199",
"category": "UserManagement", "correlationId": "d34f6d2e-3120-4b96-b922-e06090f6a497",
"result": "success", "resultReason": "", "activityDisplayName": "Update user", "activityDateTime":
"2023-07-24T14:28:15.2233481+00:00", "loggedByService": "Core Directory", "operationType":
"Update", "userAgent": null, "initiatedBy": {"user": {"id": "728989f4-eb3d-45c2-8741-2f2af4e485ce",
"displayName": null, "userPrincipalName": "tommyr@splunkresearch.com", "ipAddress":
"2601:646:a000:200:b0ee:600c:de8a:c7d5", "roles": []}}, "targetResources": [{"id":
"83a3158c-1d08-4686-b5f9-72fb34cb606e", "displayName": null, "type": "User", "userPrincipalName":
"testuser@splunkresearch.com", "modifiedProperties": [{"displayName": "AccountEnabled",
"oldValue": "[false]", "newValue": "[true]"}, {"displayName": "Included Updated
Properties", "oldValue": null, "newValue": "\"AccountEnabled\""}, {"displayName":
"TargetId.UserType", "oldValue": null, "newValue": "\"Member\""}], "administrativeUnits":
[]}], "additionalDetails": [{"key": "UserType", "value": "Member"}]}}'
@@ -0,0 +1,78 @@
name: Azure Active Directory User registered security info
id: b63240de-8a01-4ba8-8987-89d18d4b375d
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
description: Data source object for Azure Active Directory User registered security
info
source: Azure AD
sourcetype: azure:monitor:aad
separator: operationName
supported_TA:
- name: Splunk Add-on for Microsoft Cloud Services
url: https://splunkbase.splunk.com/app/3110
version: 5.2.2
fields:
- _time
- Level
- callerIpAddress
- category
- correlationId
- date_hour
- date_mday
- date_minute
- date_month
- date_second
- date_wday
- date_year
- date_zone
- durationMs
- host
- index
- linecount
- operationName
- operationVersion
- properties.activityDateTime
- properties.activityDisplayName
- properties.category
- properties.correlationId
- properties.id
- properties.initiatedBy.user.displayName
- properties.initiatedBy.user.id
- properties.initiatedBy.user.ipAddress
- properties.initiatedBy.user.userPrincipalName
- properties.loggedByService
- properties.operationType
- properties.result
- properties.resultReason
- properties.targetResources{}.displayName
- properties.targetResources{}.id
- properties.targetResources{}.type
- properties.targetResources{}.userPrincipalName
- properties.userAgent
- punct
- resourceId
- resultDescription
- resultSignature
- source
- sourcetype
- splunk_server
- tenantId
- time
- timeendpos
- timestartpos
example_log: '{"time": "2023-01-30T21:11:30.8690619Z", "resourceId": "/tenants/91da745f-8abb-4a7d-ba94-5667c6f9e01a/providers/Microsoft.aadiam",
"operationName": "User registered security info", "operationVersion": "1.0", "category":
"AuditLogs", "tenantId": "91da745f-8abb-4a7d-ba94-5667c6f9e01a", "resultSignature":
"None", "resultDescription": "User registered App Password", "durationMs": 0, "callerIpAddress":
"72.1.2.43", "correlationId": "14279c94-7ebc-409f-be4e-7861f13c8a79", "Level": 4,
"properties": {"id": "IAMUX_14279c94-7ebc-409f-be4e-7861f13c8a79_K2ATV_323947358",
"category": "UserManagement", "correlationId": "14279c94-7ebc-409f-be4e-7861f13c8a79",
"result": "success", "resultReason": "User registered App Password", "activityDisplayName":
"User registered security info", "activityDateTime": "2023-01-30T21:11:30.8690619+00:00",
"loggedByService": "Authentication Methods", "operationType": "Add", "userAgent":
null, "initiatedBy": {"user": {"id": "40b61050-e814-4ae5-8ffe-66b6f0c53998", "displayName":
null, "userPrincipalName": "User30@splunkresearch.com", "ipAddress": "72.1.2.43",
"roles": []}}, "targetResources": [{"id": "40b61050-e814-4ae5-8ffe-66b6f0c53998",
"displayName": "User30", "type": "User", "userPrincipalName": "User30@splunkresearch.com",
"modifiedProperties": [], "administrativeUnits": []}], "additionalDetails": []}}'
@@ -0,0 +1,135 @@
name: Azure Audit Create or Update an Azure Automation account
id: 2ab182e7-feda-4249-9418-32710b55a885
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
description: Data source object for Azure Audit Create or Update an Azure Automation
account
source: mscs:azure:audit
sourcetype: mscs:azure:audit
separator: operationName.localizedValue
supported_TA:
- name: Splunk Add-on for Microsoft Cloud Services
url: https://splunkbase.splunk.com/app/3110
version: 5.2.2
fields:
- _time
- authorization.action
- authorization.scope
- caller
- channels
- claims.aio
- claims.altsecid
- claims.appid
- claims.appidacr
- claims.aud
- claims.exp
- claims.groups
- claims.http://schemas.microsoft.com/claims/authnclassreference
- claims.http://schemas.microsoft.com/claims/authnmethodsreferences
- claims.http://schemas.microsoft.com/identity/claims/identityprovider
- claims.http://schemas.microsoft.com/identity/claims/objectidentifier
- claims.http://schemas.microsoft.com/identity/claims/scope
- claims.http://schemas.microsoft.com/identity/claims/tenantid
- claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress
- claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname
- claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
- claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier
- claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname
- claims.iat
- claims.ipaddr
- claims.iss
- claims.name
- claims.nbf
- claims.puid
- claims.rh
- claims.uti
- claims.ver
- claims.wids
- claims.xms_tcdt
- correlationId
- date_hour
- date_mday
- date_minute
- date_month
- date_second
- date_wday
- date_year
- date_zone
- dest
- dvc
- eventDataId
- eventName.localizedValue
- eventName.value
- eventSource.localizedValue
- eventSource.value
- eventTimestamp
- host
- id
- index
- level
- linecount
- object
- object_id
- object_path
- operationId
- operationName.localizedValue
- operationName.value
- product
- properties.entity
- properties.eventCategory
- properties.hierarchy
- properties.message
- punct
- resourceGroupName
- resourceProviderName.localizedValue
- resourceProviderName.value
- resourceUri
- source
- sourcetype
- splunk_server
- status
- status.localizedValue
- status.value
- subStatus.value
- submissionTimestamp
- subscriptionId
- timeendpos
- timestartpos
- user
- user_name
- vendor
- vendor_product
- vendor_res_code
example_log: '{"authorization": {"action": "Microsoft.Automation/automationAccounts/write",
"scope": "/subscriptions/67165197-75ea-4ca3-96a5-3e23868eacd0/resourcegroups/ResourceGroup1/providers/Microsoft.Automation/automationAccounts/TestAutomationAccount"},
"caller": "evilAdmin@contoso.com", "channels": "Operation", "claims": {"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/ad251139-d600-4f45-a8ba-9f6ca1e5a93d/", "iat": "1661179930",
"nbf": "1661179930", "exp": "1661185179", "http://schemas.microsoft.com/claims/authnclassreference":
"1", "aio": "AWQAm/8TAAAATFEszAxfULi02mHZwJPr322a2w4m7xjhs9xgc61bVQITM6lcvJI17c8SKQGIWgIA0FysfS1bmLHdxImNfT26qJ5Sfc5UdTncHkz3UYu+AvgCW1gg1mRxOZEFXYdIlQ/h",
"altsecid": "1:live.com:000161008492EF5F", "http://schemas.microsoft.com/claims/authnmethodsreferences":
"pwd,mfa", "appid": "c44b4083-3bb0-49c1-b47d-974e53cbdf3c", "appidacr": "2", "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress":
"evilAdmin@contoso.com", "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname":
"Doe", "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "John",
"groups": "ecb1fc87-1938-45ff-aaf3-661cee183b11", "http://schemas.microsoft.com/identity/claims/identityprovider":
"live.com", "ipaddr": "190.0.0.1", "name": "John Doe", "http://schemas.microsoft.com/identity/claims/objectidentifier":
"74b87c49-c202-4101-a8aa-ef18ecc815e8", "puid": "1003200203ECE231", "rh": "0.AX0AORElrQDWRU-oup9soeWpPUZIf3kAutdPukPawfj2MBOaAIM.",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation", "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier":
"VVjyH6MJP7pqXTBGCn4NMckGNjX-aYB_Oh7LcI9kaDw", "http://schemas.microsoft.com/identity/claims/tenantid":
"ad251139-d600-4f45-a8ba-9f6ca1e5a93d", "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name":
"contoso.com#evilAdmin@contoso.com", "uti": "OyNAqM760kmqzxVr6jwtAA", "ver": "1.0",
"wids": "62e90394-69f5-4237-9190-012177145e10", "xms_tcdt": "1654791641"}, "correlationId":
"59e3de3b-b8c6-4360-9bc5-f094ebce6422", "description": "", "eventDataId": "b0a0bf02-57e5-4eb3-a36d-f2681d874637",
"eventName": {"value": "EndRequest", "localizedValue": "End request"}, "eventSource":
{"value": "Administrative", "localizedValue": "Administrative"}, "id": "/subscriptions/67165197-75ea-4ca3-96a5-3e23868eacd0/resourcegroups/ResourceGroup1/providers/Microsoft.Automation/automationAccounts/TestAutomationAccount/events/b0a0bf02-57e5-4eb3-a36d-f2681d874637/ticks/637967777618694806",
"level": "Informational", "resourceGroupName": "ResourceGroup1", "resourceProviderName":
{"value": "Microsoft.Automation", "localizedValue": "Microsoft.Automation"}, "resourceUri":
"/subscriptions/67165197-75ea-4ca3-96a5-3e23868eacd0/resourcegroups/ResourceGroup1/providers/Microsoft.Automation/automationAccounts/TestAutomationAccount",
"operationId": "6a420172-1ccd-4144-ac12-3095b4019ed5", "operationName": {"value":
"Microsoft.Automation/automationAccounts/write", "localizedValue": "Create or Update
an Azure Automation account"}, "properties": {"eventCategory": "Administrative",
"entity": "/subscriptions/67165197-75ea-4ca3-96a5-3e23868eacd0/resourcegroups/ResourceGroup1/providers/Microsoft.Automation/automationAccounts/TestAutomationAccount",
"message": "Microsoft.Automation/automationAccounts/write", "hierarchy": "67165197-75ea-4ca3-96a5-3e23868eacd0"},
"status": {"value": "Succeeded", "localizedValue": "Succeeded"}, "subStatus": {"value":
"", "localizedValue": ""}, "eventTimestamp": "2022-08-22T15:09:21.8694806Z", "submissionTimestamp":
"2022-08-22T15:10:51.152208Z", "subscriptionId": "67165197-75ea-4ca3-96a5-3e23868eacd0"}'
@@ -0,0 +1,136 @@
name: Azure Audit Create or Update an Azure Automation Runbook
id: 2bd83221-7a8b-436f-9b2b-efa1d44d009e
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
description: Data source object for Azure Audit Create or Update an Azure Automation
Runbook
source: mscs:azure:audit
sourcetype: mscs:azure:audit
separator: operationName.localizedValue
supported_TA:
- name: Splunk Add-on for Microsoft Cloud Services
url: https://splunkbase.splunk.com/app/3110
version: 5.2.2
fields:
- _time
- authorization.action
- authorization.scope
- caller
- channels
- claims.aio
- claims.altsecid
- claims.appid
- claims.appidacr
- claims.aud
- claims.exp
- claims.groups
- claims.http://schemas.microsoft.com/claims/authnclassreference
- claims.http://schemas.microsoft.com/claims/authnmethodsreferences
- claims.http://schemas.microsoft.com/identity/claims/identityprovider
- claims.http://schemas.microsoft.com/identity/claims/objectidentifier
- claims.http://schemas.microsoft.com/identity/claims/scope
- claims.http://schemas.microsoft.com/identity/claims/tenantid
- claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress
- claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname
- claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
- claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier
- claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname
- claims.iat
- claims.ipaddr
- claims.iss
- claims.name
- claims.nbf
- claims.puid
- claims.rh
- claims.uti
- claims.ver
- claims.wids
- claims.xms_tcdt
- correlationId
- date_hour
- date_mday
- date_minute
- date_month
- date_second
- date_wday
- date_year
- date_zone
- dest
- dvc
- eventDataId
- eventName.localizedValue
- eventName.value
- eventSource.localizedValue
- eventSource.value
- eventTimestamp
- host
- id
- index
- level
- linecount
- object
- object_id
- object_path
- operationId
- operationName.localizedValue
- operationName.value
- product
- properties.entity
- properties.eventCategory
- properties.hierarchy
- properties.message
- punct
- resourceGroupName
- resourceProviderName.localizedValue
- resourceProviderName.value
- resourceUri
- source
- sourcetype
- splunk_server
- status
- status.localizedValue
- status.value
- subStatus.value
- submissionTimestamp
- subscriptionId
- timeendpos
- timestartpos
- user
- user_name
- vendor
- vendor_product
- vendor_res_code
example_log: '{"authorization": {"action": "Microsoft.Automation/automationAccounts/runbooks/write",
"scope": "/subscriptions/1aee0e3d-b75b-440a-a927-76f0552a14e6/resourceGroups/resourceGroup1/providers/Microsoft.Automation/automationAccounts/SuspiciousAutomationAccount/runbooks/SuspiciousRunbook"},
"caller": "evilAdmin@contoso.com", "channels": "Operation", "claims": {"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/ad251139-d600-4f45-a8ba-9f6ca1e5a93d/", "iat": "1661194261",
"nbf": "1661194261", "exp": "1661198249", "http://schemas.microsoft.com/claims/authnclassreference":
"1", "aio": "AWQAm/8TAAAA3iMcbqqPPdXPATT7oalIKsh6wEFsyQ+zUVCshaLu77xsLlt067TtI11gy5hAx+z905hrX1VBehDGaedvEg2UF0BSbHVL9bJrry4zk3Xt+HNt5dTXDDgABOFuNB4QJBUW",
"altsecid": "1:live.com:000161008492EF5F", "http://schemas.microsoft.com/claims/authnmethodsreferences":
"pwd,mfa", "appid": "c44b4083-3bb0-49c1-b47d-974e53cbdf3c", "appidacr": "2", "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress":
"evilAdmin@contoso.com", "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname":
"Doe", "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "John",
"groups": "ecb1fc87-1938-45ff-aaf3-661cee183b11", "http://schemas.microsoft.com/identity/claims/identityprovider":
"live.com", "ipaddr": "190.0.0.1", "name": "John Doe", "http://schemas.microsoft.com/identity/claims/objectidentifier":
"74b87c49-c202-4101-a8aa-ef18ecc815e8", "puid": "1003200203ECE231", "rh": "0.AX0AORElrQDWRU-oup9soeWpPUZIf3kAutdPukPawfj2MBOaAIM.",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation", "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier":
"VVjyH6MJP7pqXTBGCn4NMckGNjX-aYB_Oh7LcI9kaDw", "http://schemas.microsoft.com/identity/claims/tenantid":
"ad251139-d600-4f45-a8ba-9f6ca1e5a93d", "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name":
"contoso.com#evilAdmin@contoso.com", "uti": "YMAP5fOmMkuuBUgBe-Z5AA", "ver": "1.0",
"wids": "62e90394-69f5-4237-9190-012177145e10", "xms_tcdt": "1654791641"}, "correlationId":
"49b945c0-966a-48d8-b79b-31f184544594", "description": "", "eventDataId": "303f17eb-10cb-458f-8a80-683f40f123a2",
"eventName": {"value": "EndRequest", "localizedValue": "End request"}, "eventSource":
{"value": "Administrative", "localizedValue": "Administrative"}, "id": "/subscriptions/1aee0e3d-b75b-440a-a927-76f0552a14e6/resourcegroups/resourceGroup1/providers/Microsoft.Automation/automationAccounts/SuspiciousAutomationAccount/runbooks/SuspiciousRunbook/events/303f17eb-10cb-458f-8a80-683f40f123a2/ticks/637967920541346086",
"level": "Informational", "resourceGroupName": "resourceGroup1", "resourceProviderName":
{"value": "Microsoft.Automation", "localizedValue": "Microsoft.Automation"}, "resourceUri":
"/subscriptions/1aee0e3d-b75b-440a-a927-76f0552a14e6/resourcegroups/resourceGroup1/providers/Microsoft.Automation/automationAccounts/SuspiciousAutomationAccount/runbooks/SuspiciousRunbook",
"operationId": "b6e30ace-986c-4735-980f-926db0b43336", "operationName": {"value":
"Microsoft.Automation/automationAccounts/runbooks/write", "localizedValue": "Create
or Update an Azure Automation Runbook"}, "properties": {"eventCategory": "Administrative",
"entity": "/subscriptions/1aee0e3d-b75b-440a-a927-76f0552a14e6/resourcegroups/resourceGroup1/providers/Microsoft.Automation/automationAccounts/SuspiciousAutomationAccount/runbooks/SuspiciousRunbook",
"message": "Microsoft.Automation/automationAccounts/runbooks/write", "hierarchy":
"1aee0e3d-b75b-440a-a927-76f0552a14e6"}, "status": {"value": "Succeeded", "localizedValue":
"Succeeded"}, "subStatus": {"value": "", "localizedValue": ""}, "eventTimestamp":
"2022-08-22T19:07:34.1346086Z", "submissionTimestamp": "2022-08-22T19:08:54.1547383Z",
"subscriptionId": "1aee0e3d-b75b-440a-a927-76f0552a14e6"}'
@@ -0,0 +1,147 @@
name: Azure Audit Create or Update an Azure Automation webhook
id: 575faeb2-09d0-4849-b1f6-eae241f26ff2
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
description: Data source object for Azure Audit Create or Update an Azure Automation
webhook
source: mscs:azure:audit
sourcetype: mscs:azure:audit
separator: operationName.localizedValue
supported_TA:
- name: Splunk Add-on for Microsoft Cloud Services
url: https://splunkbase.splunk.com/app/3110
version: 5.2.2
fields:
- _time
- authorization.action
- authorization.scope
- caller
- channels
- claims.aio
- claims.altsecid
- claims.appid
- claims.appidacr
- claims.aud
- claims.exp
- claims.groups
- claims.http://schemas.microsoft.com/claims/authnclassreference
- claims.http://schemas.microsoft.com/claims/authnmethodsreferences
- claims.http://schemas.microsoft.com/identity/claims/identityprovider
- claims.http://schemas.microsoft.com/identity/claims/objectidentifier
- claims.http://schemas.microsoft.com/identity/claims/scope
- claims.http://schemas.microsoft.com/identity/claims/tenantid
- claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress
- claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname
- claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
- claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier
- claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname
- claims.iat
- claims.ipaddr
- claims.iss
- claims.name
- claims.nbf
- claims.puid
- claims.rh
- claims.uti
- claims.ver
- claims.wids
- claims.xms_tcdt
- correlationId
- date_hour
- date_mday
- date_minute
- date_month
- date_second
- date_wday
- date_year
- date_zone
- dest
- dvc
- eventDataId
- eventName.localizedValue
- eventName.value
- eventSource.localizedValue
- eventSource.value
- eventTimestamp
- host
- httpRequest.clientIpAddress
- httpRequest.clientRequestId
- httpRequest.method
- id
- index
- level
- linecount
- object
- object_id
- object_path
- operationId
- operationName.localizedValue
- operationName.value
- product
- properties.entity
- properties.eventCategory
- properties.hierarchy
- properties.message
- properties.serviceRequestId
- properties.statusCode
- punct
- resourceGroupName
- resourceProviderName.localizedValue
- resourceProviderName.value
- resourceUri
- result
- result_id
- source
- sourcetype
- splunk_server
- src
- status
- status.localizedValue
- status.value
- subStatus.localizedValue
- subStatus.value
- submissionTimestamp
- subscriptionId
- timeendpos
- timestartpos
- user
- user_name
- vendor
- vendor_product
- vendor_res_code
example_log: '{"authorization": {"action": "Microsoft.Automation/automationAccounts/webhooks/write",
"scope": "/subscriptions/e0c00901-96b2-4151-80f7-746e24c03e98/resourceGroups/resourceGroup1providers/Microsoft.Automation/automationAccounts/SuspiciousAutomationAccount/webhooks/MaliciousWebHook"},
"caller": "evilAdmin@contoso.com", "channels": "Operation", "claims": {"aud": "https://management.core.windows.net/",
"iss": "https://sts.windows.net/ad251139-d600-4f45-a8ba-9f6ca1e5a93d/", "iat": "1661287859",
"nbf": "1661287859", "exp": "1661293423", "http://schemas.microsoft.com/claims/authnclassreference":
"1", "aio": "AWQAm/8TAAAAEendcgWjYQFuDhNNhoecwU3dpXjjenSsIvjamk77+TjLK/o1xkFGcFb1A+OVyuY+xefe0X39n8lx1iFWFqGo0GSNNKhm9OQcv/0UyXiaNIbKD7wisgQhAa9DoIyObMpO",
"altsecid": "1:contoso.com:000161008492EF5F", "http://schemas.microsoft.com/claims/authnmethodsreferences":
"pwd,mfa", "appid": "c44b4083-3bb0-49c1-b47d-974e53cbdf3c", "appidacr": "2", "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress":
"evilAdmin@contosol.com", "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname":
"Doe", "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "John",
"groups": "ecb1fc87-1938-45ff-aaf3-661cee183b11", "http://schemas.microsoft.com/identity/claims/identityprovider":
"contoso.com", "ipaddr": "190.0.0.1", "name": "John Doe", "http://schemas.microsoft.com/identity/claims/objectidentifier":
"74b87c49-c202-4101-a8aa-ef18ecc815e8", "puid": "1003200203ECE231", "rh": "0.AX0AORElrQDWRU-oup9soeWpPUZIf3kAutdPukPawfj2MBOaAIM.",
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation", "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier":
"VVjyH6MJP7pqXTBGCn4NMckGNjX-aYB_Oh7LcI9kaDw", "http://schemas.microsoft.com/identity/claims/tenantid":
"ad251139-d600-4f45-a8ba-9f6ca1e5a93d", "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name":
"contoso.com#evilAdmin@contoso.com", "uti": "epgtY-85CUeb6aJpaE0KAQ", "ver": "1.0",
"wids": "62e90394-69f5-4237-9190-012177145e10", "xms_tcdt": "1654791641"}, "correlationId":
"74e18a58-ee2e-40de-890d-de0c155f7086", "description": "", "eventDataId": "35b9db88-8041-413e-8dd7-f8dc243eafdd",
"eventName": {"value": "EndRequest", "localizedValue": "End request"}, "eventSource":
{"value": "Administrative", "localizedValue": "Administrative"}, "httpRequest":
{"clientRequestId": "6934b40a-c11f-4379-9ef1-c6fa3cee5015", "clientIpAddress": "190.0.0.1",
"method": "PUT"}, "id": "/subscriptions/e0c00901-96b2-4151-80f7-746e24c03e98/resourceGroups/resourceGroup1providers/Microsoft.Automation/automationAccounts/SuspiciousAutomationAccount/webhooks/MaliciousWebHook/events/35b9db88-8041-413e-8dd7-f8dc243eafdd/ticks/637968850422707386",
"level": "Informational", "resourceGroupName": "eventhub_rg", "resourceProviderName":
{"value": "Microsoft.Automation", "localizedValue": "Microsoft.Automation"}, "resourceUri":
"/subscriptions/e0c00901-96b2-4151-80f7-746e24c03e98/resourceGroups/resourceGroup1providers/Microsoft.Automation/automationAccounts/SuspiciousAutomationAccount/webhooks/MaliciousWebHook",
"operationId": "74e18a58-ee2e-40de-890d-de0c155f7086", "operationName": {"value":
"Microsoft.Automation/automationAccounts/webhooks/write", "localizedValue": "Create
or Update an Azure Automation webhook"}, "properties": {"statusCode": "Created",
"serviceRequestId": null, "eventCategory": "Administrative", "entity": "/subscriptions/e0c00901-96b2-4151-80f7-746e24c03e98/resourceGroups/resourceGroup1providers/Microsoft.Automation/automationAccounts/SuspiciousAutomationAccount/webhooks/MaliciousWebHook",
"message": "Microsoft.Automation/automationAccounts/webhooks/write", "hierarchy":
"e0c00901-96b2-4151-80f7-746e24c03e98"}, "status": {"value": "Succeeded", "localizedValue":
"Succeeded"}, "subStatus": {"value": "Created", "localizedValue": "Created (HTTP
Status Code: 201)"}, "eventTimestamp": "2022-08-23T20:57:22.2707386Z", "submissionTimestamp":
"2022-08-23T20:58:54.2071536Z", "subscriptionId": "e0c00901-96b2-4151-80f7-746e24c03e98"}'
@@ -1,7 +1,10 @@
name: Bro
id: c5d9612b-0ffd-44d3-8247-3cf3486ec5e2
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
description: Data source object for Bro
source: bro:http:json
sourcetype: bro:http:json
supported_TA: {}
event_names: []
supported_TA:
- {}
-27
View File
@@ -1,27 +0,0 @@
name: Endpoint.Filesystem
prefix: Filesystem
fields:
- action
- dest
- dest_bunit
- dest_category
- dest_priority
- dest_requires_av
- dest_should_timesync
- dest_should_update
- file_access_time
- file_create_time
- file_hash
- file_modify_time
- file_name
- file_path
- file_acl
- file_size
- process_guid
- process_id
- tag
- user
- user_bunit
- user_category
- user_priority
- vendor_product
-39
View File
@@ -1,39 +0,0 @@
name: Endpoint.Processes
prefix: Processes
fields:
- action
- cpu_load_percent
- dest
- dest_bunit
- dest_category
- dest_is_expected
- dest_priority
- dest_requires_av
- dest_should_timesync
- dest_should_update
- loaded_file
- mem_used
- original_file_name
- os
- parent_process
- parent_process_exec
- parent_process_id
- parent_process_guid
- parent_process_name
- parent_process_path
- process
- process_current_directory
- process_exec
- process_hash
- process_guid
- process_id
- process_integrity_level
- process_name
- process_path
- tag
- user
- user_id
- user_bunit
- user_category
- user_priority
- vendor_product
-27
View File
@@ -1,27 +0,0 @@
name: Endpoint.Registry
prefix: Registry
fields:
- action
- dest
- dest_bunit
- dest_category
- dest_priority
- dest_requires_av
- dest_should_timesync
- dest_should_update
- process_guid
- process_id
- registry_hive
- registry_path
- registry_key_name
- registry_value_data
- registry_value_name
- registry_value_text
- registry_value_type
- status
- tag
- user
- user_bunit
- user_category
- user_priority
- vendor_product
-35
View File
@@ -1,35 +0,0 @@
name: Endpoint.Services
prefix: Services
fields:
- description
- dest
- dest_bunit
- dest_category
- dest_is_expected
- dest_priority
- dest_requires_av
- dest_should_timesync
- dest_should_update
- process_guid
- process_id
- service
- service_dll
- service_dll_path
- service_dll_hash
- service_dll_signature_exists
- service_dll_signature_verified
- service_exec
- service_hash
- service_id
- service_name
- service_path
- service_signature_exists
- service_signature_verified
- start_mode
- status
- tag
- user
- user_bunit
- user_category
- user_priority
- vendor_product
-32
View File
@@ -1,32 +0,0 @@
name: Network_Resolution.DNS
prefix: DNS
fields:
- additional_answer_count
- answer
- answer_count
- authority_answer_count
- dest
- dest_bunit
- dest_category
- dest_port
- dest_priority
- duration
- message_type
- name
- query
- query_count
- query_type
- record_type
- reply_code
- reply_code_id
- response_time
- src
- src_bunit
- src_category
- src_port
- src_priority
- tag
- transaction_id
- transport
- ttl
- vendor_product
-66
View File
@@ -1,66 +0,0 @@
name: Network_Traffic.All_Traffic
prefix: All_Traffic
fields:
- action
- app
- bytes
- bytes_in
- bytes_out
- channel
- dest
- dest_bunit
- dest_category
- dest_interface
- dest_ip
- dest_mac
- dest_port
- dest_priority
- dest_translated_ip
- dest_translated_port
- dest_zone
- direction
- duration
- dvc
- dvc_bunit
- dvc_category
- dvc_ip
- dvc_mac
- dvc_priority
- dvc_zone
- flow_id
- icmp_code
- icmp_type
- packets
- packets_in
- packets_out
- process_id
- protocol
- protocol_version
- response_time
- rule
- session_id
- src
- src_bunit
- src_category
- src_interface
- src_ip
- src_mac
- src_port
- src_priority
- src_translated_ip
- src_translated_port
- src_zone
- ssid
- tag
- tcp_flag
- transport
- tos
- ttl
- user
- user_bunit
- user_category
- user_priority
- vendor_account
- vendor_product
- vlan
- wifi
-41
View File
@@ -1,41 +0,0 @@
name: Web.Web
prefix: Web
fields:
- action
- app
- bytes
- bytes_in
- bytes_out
- cached
- category
- cookie
- dest
- dest_bunit
- dest_category
- dest_priority
- dest_port
- duration
- http_content_type
- http_method
- http_referrer
- http_referrer_domain
- http_user_agent
- http_user_agent_length
- response_time
- site
- src
- src_bunit
- src_category
- src_priority
- status
- tag
- uri_path
- uri_query
- url
- url_domain
- url_length
- user
- user_bunit
- user_category
- user_priority
- vendor_product
@@ -1,68 +1,69 @@
name: CircleCI
id: 34ad06fc-a296-4ab5-8315-2f07714948e3
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
description: Data source object for CircleCI
source: circleci
sourcetype: circleci
supported_TA:
name: App for CircleCI
version: 0.1.1
- name: App for CircleCI
url: https://splunkbase.splunk.com/app/5162
event_names: []
version: 0.1.1
fields:
- _time
- author_name
- avatar_url
- branch
- build_num
- build_time_millis
- build_url
- date_hour
- date_mday
- date_minute
- date_month
- date_second
- date_wday
- date_year
- date_zone
- eventtype
- fail_reason
- host
- index
- job_name
- job_time
- linecount
- owners{}
- project_slug
- punct
- queued_time
- reponame
- source
- sourcetype
- splunk_server
- start_time
- status
- stop_time
- tag
- tag::eventtype
- timedout
- timeendpos
- timestartpos
- username
- vcs.commit_time
- vcs.committer_name
- vcs.revision
- vcs.subject
- vcs.tag
- vcs.type
- vcs.url
- workflows.job_id
- workflows.job_name
- workflows.upstream_job_ids{}
- workflows.workflow_id
- workflows.workflow_name
- workflows.workspace_id
example_log:
'{"job_time": "2021-09-02T08:13:34.273Z", "stop_time": "2021-09-02T08:13:34.273Z",
- _time
- author_name
- avatar_url
- branch
- build_num
- build_time_millis
- build_url
- date_hour
- date_mday
- date_minute
- date_month
- date_second
- date_wday
- date_year
- date_zone
- eventtype
- fail_reason
- host
- index
- job_name
- job_time
- linecount
- owners{}
- project_slug
- punct
- queued_time
- reponame
- source
- sourcetype
- splunk_server
- start_time
- status
- stop_time
- tag
- tag::eventtype
- timedout
- timeendpos
- timestartpos
- username
- vcs.commit_time
- vcs.committer_name
- vcs.revision
- vcs.subject
- vcs.tag
- vcs.type
- vcs.url
- workflows.job_id
- workflows.job_name
- workflows.upstream_job_ids{}
- workflows.workflow_id
- workflows.workflow_name
- workflows.workspace_id
example_log: '{"job_time": "2021-09-02T08:13:34.273Z", "stop_time": "2021-09-02T08:13:34.273Z",
"start_time": "2021-09-02T08:10:15.829Z", "queued_time": "2021-09-02T08:10:12.764Z",
"job_name": "Unknown", "reponame": "devsecops_poc", "build_num": 94, "build_url":
"https://circleci.com/gh/splunk/devsecops_poc/94", "branch": "main", "status": "success",
-229
View File
@@ -1,229 +0,0 @@
name: AWS CloudTrail
id: aa8d90bf-8ab1-4a9f-8c1b-24a67b1cd0b0
author: Patrick Bareiss, Splunk
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
supported_TA:
name: Splunk Add-on for Amazon Web Services (AWS)
version: 7.4.1
url: https://splunkbase.splunk.com/app/1876
event_names:
- event_name: AWS CloudTrail
data_source: data_sources/cloud/event_sources/AWS_CloudTrail.yml
- event_name: AWS CloudTrail AssumeRoleWithSAML
data_source: data_sources/cloud/event_sources/AWS_CloudTrail_AssumeRoleWithSAML.yml
- event_name: AWS CloudTrail ConsoleLogin
data_source: data_sources/cloud/event_sources/AWS_CloudTrail_ConsoleLogin.yml
- event_name: AWS CloudTrail CopyObject
data_source: data_sources/cloud/event_sources/AWS_CloudTrail_CopyObject.yml
- event_name: AWS CloudTrail CreateAccessKey
data_source: data_sources/cloud/event_sources/AWS_CloudTrail_CreateAccessKey.yml
- event_name: AWS CloudTrail CreateKey
data_source: data_sources/cloud/event_sources/AWS_CloudTrail_CreateKey.yml
- event_name: AWS CloudTrail CreateLoginProfile
data_source: data_sources/cloud/event_sources/AWS_CloudTrail_CreateLoginProfile.yml
- event_name: AWS CloudTrail CreateNetworkAclEntry
data_source: data_sources/cloud/event_sources/AWS_CloudTrail_CreateNetworkAclEntry.yml
- event_name: AWS CloudTrail CreatePolicyVersion
data_source: data_sources/cloud/event_sources/AWS_CloudTrail_CreatePolicyVersion.yml
- event_name: AWS CloudTrail CreateSnapshot
data_source: data_sources/cloud/event_sources/AWS_CloudTrail_CreateSnapshot.yml
- event_name: AWS CloudTrail CreateTask
data_source: data_sources/cloud/event_sources/AWS_CloudTrail_CreateTask.yml
- event_name: AWS CloudTrail CreateVirtualMFADevice
data_source: data_sources/cloud/event_sources/AWS_CloudTrail_CreateVirtualMFADevice.yml
- event_name: AWS CloudTrail DeactivateMFADevice
data_source: data_sources/cloud/event_sources/AWS_CloudTrail_DeactivateMFADevice.yml
- event_name: AWS CloudTrail DeleteAccountPasswordPolicy
data_source: data_sources/cloud/event_sources/AWS_CloudTrail_DeleteAccountPasswordPolicy.yml
- event_name: AWS CloudTrail DeleteAlarms
data_source: data_sources/cloud/event_sources/AWS_CloudTrail_DeleteAlarms.yml
- event_name: AWS CloudTrail DeleteDetector
data_source: data_sources/cloud/event_sources/AWS_CloudTrail_DeleteDetector.yml
- event_name: AWS CloudTrail DeleteGroup
data_source: data_sources/cloud/event_sources/AWS_CloudTrail_DeleteGroup.yml
- event_name: AWS CloudTrail DeleteIPSet
data_source: data_sources/cloud/event_sources/AWS_CloudTrail_DeleteIPSet.yml
- event_name: AWS CloudTrail DeleteLogGroup
data_source: data_sources/cloud/event_sources/AWS_CloudTrail_DeleteLogGroup.yml
- event_name: AWS CloudTrail DeleteLogStream
data_source: data_sources/cloud/event_sources/AWS_CloudTrail_DeleteLogStream.yml
- event_name: AWS CloudTrail DeleteLoggingConfiguration
data_source: data_sources/cloud/event_sources/AWS_CloudTrail_DeleteLoggingConfiguration.yml
- event_name: AWS CloudTrail DeleteNetworkAclEntry
data_source: data_sources/cloud/event_sources/AWS_CloudTrail_DeleteNetworkAclEntry.yml
- event_name: AWS CloudTrail DeletePolicy
data_source: data_sources/cloud/event_sources/AWS_CloudTrail_DeletePolicy.yml
- event_name: AWS CloudTrail DeleteRule
data_source: data_sources/cloud/event_sources/AWS_CloudTrail_DeleteRule.yml
- event_name: AWS CloudTrail DeleteRuleGroup
data_source: data_sources/cloud/event_sources/AWS_CloudTrail_DeleteRuleGroup.yml
- event_name: AWS CloudTrail DeleteSnapshot
data_source: data_sources/cloud/event_sources/AWS_CloudTrail_DeleteSnapshot.yml
- event_name: AWS CloudTrail DeleteTrail
data_source: data_sources/cloud/event_sources/AWS_CloudTrail_DeleteTrail.yml
- event_name: AWS CloudTrail DeleteVirtualMFADevice
data_source: data_sources/cloud/event_sources/AWS_CloudTrail_DeleteVirtualMFADevice.yml
- event_name: AWS CloudTrail DeleteWebACL
data_source: data_sources/cloud/event_sources/AWS_CloudTrail_DeleteWebACL.yml
- event_name: AWS CloudTrail DescribeEventAggregates
data_source: data_sources/cloud/event_sources/AWS_CloudTrail_DescribeEventAggregates.yml
- event_name: AWS CloudTrail DescribeImageScanFindings
data_source: data_sources/cloud/event_sources/AWS_CloudTrail_DescribeImageScanFindings.yml
- event_name: AWS CloudTrail DescribeSnapshotAttribute
data_source: data_sources/cloud/event_sources/AWS_CloudTrail_DescribeSnapshotAttribute.yml
- event_name: AWS CloudTrail GetAccountPasswordPolicy
data_source: data_sources/cloud/event_sources/AWS_CloudTrail_GetAccountPasswordPolicy.yml
- event_name: AWS CloudTrail GetObject
data_source: data_sources/cloud/event_sources/AWS_CloudTrail_GetObject.yml
- event_name: AWS CloudTrail GetPasswordData
data_source: data_sources/cloud/event_sources/AWS_CloudTrail_GetPasswordData.yml
- event_name: AWS CloudTrail JobCreated
data_source: data_sources/cloud/event_sources/AWS_CloudTrail_JobCreated.yml
- event_name: AWS CloudTrail ModifyDBInstance
data_source: data_sources/cloud/event_sources/AWS_CloudTrail_ModifyDBInstance.yml
- event_name: AWS CloudTrail ModifyImageAttribute
data_source: data_sources/cloud/event_sources/AWS_CloudTrail_ModifyImageAttribute.yml
- event_name: AWS CloudTrail ModifySnapshotAttribute
data_source: data_sources/cloud/event_sources/AWS_CloudTrail_ModifySnapshotAttribute.yml
- event_name: AWS CloudTrail PutBucketAcl
data_source: data_sources/cloud/event_sources/AWS_CloudTrail_PutBucketAcl.yml
- event_name: AWS CloudTrail PutBucketLifecycle
data_source: data_sources/cloud/event_sources/AWS_CloudTrail_PutBucketLifecycle.yml
- event_name: AWS CloudTrail PutBucketReplication
data_source: data_sources/cloud/event_sources/AWS_CloudTrail_PutBucketReplication.yml
- event_name: AWS CloudTrail PutBucketVersioning
data_source: data_sources/cloud/event_sources/AWS_CloudTrail_PutBucketVersioning.yml
- event_name: AWS CloudTrail PutImage
data_source: data_sources/cloud/event_sources/AWS_CloudTrail_PutImage.yml
- event_name: AWS CloudTrail PutKeyPolicy
data_source: data_sources/cloud/event_sources/AWS_CloudTrail_PutKeyPolicy.yml
- event_name: AWS CloudTrail ReplaceNetworkAclEntry
data_source: data_sources/cloud/event_sources/AWS_CloudTrail_ReplaceNetworkAclEntry.yml
- event_name: AWS CloudTrail SetDefaultPolicyVersion
data_source: data_sources/cloud/event_sources/AWS_CloudTrail_SetDefaultPolicyVersion.yml
- event_name: AWS CloudTrail StopLogging
data_source: data_sources/cloud/event_sources/AWS_CloudTrail_StopLogging.yml
- event_name: AWS CloudTrail UpdateAccountPasswordPolicy
data_source: data_sources/cloud/event_sources/AWS_CloudTrail_UpdateAccountPasswordPolicy.yml
- event_name: AWS CloudTrail UpdateLoginProfile
data_source: data_sources/cloud/event_sources/AWS_CloudTrail_UpdateLoginProfile.yml
- event_name: AWS CloudTrail UpdateSAMLProvider
data_source: data_sources/cloud/event_sources/AWS_CloudTrail_UpdateSAMLProvider.yml
- event_name: AWS CloudTrail UpdateTrail
data_source: data_sources/cloud/event_sources/AWS_CloudTrail_UpdateTrail.yml
fields:
- _time
- action
- app
- awsRegion
- aws_account_id
- change_type
- command
- date_hour
- date_mday
- date_minute
- date_month
- date_second
- date_wday
- date_year
- date_zone
- dest
- direction
- dvc
- errorCode
- eventCategory
- eventID
- eventName
- eventSource
- eventTime
- eventType
- eventVersion
- eventtype
- host
- index
- linecount
- managementEvent
- msg
- object
- object_category
- object_id
- product
- protocol
- punct
- readOnly
- recipientAccountId
- region
- requestID
- requestParameters.groupId
- requestParameters.ipPermissions.items{}.fromPort
- requestParameters.ipPermissions.items{}.ipProtocol
- requestParameters.ipPermissions.items{}.ipRanges.items{}.cidrIp
- requestParameters.ipPermissions.items{}.toPort
- responseElements._return
- responseElements.requestId
- responseElements.securityGroupRuleSet.items{}.cidrIpv4
- responseElements.securityGroupRuleSet.items{}.fromPort
- responseElements.securityGroupRuleSet.items{}.groupId
- responseElements.securityGroupRuleSet.items{}.groupOwnerId
- responseElements.securityGroupRuleSet.items{}.ipProtocol
- responseElements.securityGroupRuleSet.items{}.isEgress
- responseElements.securityGroupRuleSet.items{}.securityGroupRuleId
- responseElements.securityGroupRuleSet.items{}.toPort
- signature
- source
- sourceIPAddress
- sourcetype
- splunk_server
- src
- src_ip
- src_ip_range
- src_port_range
- start_time
- status
- tag
- tag::eventtype
- timeendpos
- timestartpos
- tlsDetails.cipherSuite
- tlsDetails.clientProvidedHostHeader
- tlsDetails.tlsVersion
- user
- userAgent
- userIdentity.accessKeyId
- userIdentity.accountId
- userIdentity.arn
- userIdentity.principalId
- userIdentity.type
- userIdentity.userName
- userName
- user_access_key
- user_agent
- user_arn
- user_group_id
- user_id
- user_name
- user_type
- vendor
- vendor_account
- vendor_product
- vendor_region
example_log: '{"eventVersion": "1.09", "userIdentity": {"type": "IAMUser", "principalId":
"AIDAAAAAAAAAAAAAAAAAA", "arn": "arn:aws:iam::111111111111:user/daftpunk_cli", "accountId":
"111111111111", "accessKeyId": "AKIAAAAAAAAAAAAAAAAA", "userName": "daftpunk_cli"},
"eventTime": "2024-02-21T19:19:40Z", "eventSource": "ec2.amazonaws.com", "eventName":
"AuthorizeSecurityGroupIngress", "awsRegion": "us-west-2", "sourceIPAddress": "2.2.2.2",
"userAgent": "aws-cli/2.13.22 Python/3.11.5 Darwin/22.5.0 source/arm64 prompt/off
command/ec2.authorize-security-group-ingress", "requestParameters": {"groupId":
"sg-07ffb1896dcd3713e", "ipPermissions": {"items": [{"ipProtocol": "-1", "fromPort":
-1, "toPort": -1, "groups": {}, "ipRanges": {"items": [{"cidrIp": "0.0.0.0/0"}]},
"ipv6Ranges": {}, "prefixListIds": {}}]}}, "responseElements": {"requestId": "4950930b-2129-423c-95b0-1b87c8fa115a",
"_return": true, "securityGroupRuleSet": {"items": [{"groupOwnerId": "111111111111",
"groupId": "sg-07ffb1896dcd3713e", "securityGroupRuleId": "sgr-0217c1b508cc6b76c",
"isEgress": false, "ipProtocol": "-1", "fromPort": -1, "toPort": -1, "cidrIpv4":
"0.0.0.0/0"}]}}, "requestID": "4950930b-2129-423c-95b0-1b87c8fa115a", "eventID":
"bdade96f-6272-468a-b084-413b9711e92f", "readOnly": false, "eventType": "AwsApiCall",
"managementEvent": true, "recipientAccountId": "111111111111", "eventCategory":
"Management", "tlsDetails": {"tlsVersion": "TLSv1.3", "cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-2.amazonaws.com"}}'
@@ -1,66 +0,0 @@
name: AWS CloudWatchLogs VPCflow
id: 38a34fc4-e128-4478-a8f4-7835d51d5135
author: Bhavin Patel, Splunk
source: aws_cloudwatchlogs_vpcflow
sourcetype: aws:cloudwatchlogs:vpcflow
separator: eventName
supported_TA:
name: Splunk Add-on for Amazon Web Services (AWS)
version: 7.4.1
url: https://splunkbase.splunk.com/app/1876
event_names: []
fields:
- _raw
- _time
- account_id
- action
- app
- aws_account_id
- bytes
- date_hour
- date_mday
- date_minute
- date_month
- date_second
- date_wday
- date_year
- date_zone
- dest
- dest_ip
- dest_port
- duration
- dvc
- end_time
- eventtype
- host
- index
- interface_id
- linecount
- log_status
- packets
- protocol
- protocol_code
- protocol_full_name
- protocol_version
- punct
- region
- source
- sourcetype
- splunk_server
- splunk_server_group
- src
- src_ip
- src_port
- start_time
- tag
- tag::action
- tag::eventtype
- timeendpos
- timestartpos
- transport
- user_id
- vendor_account
- vendor_product
- version
- vpcflow_action
example_log: '2 123397614277 eni-0b0f9f261f45e6489 10.0.1.30 10.0.1.1 47254 22 17 2 98 1697608042 1697608070 ACCEPT OK'
@@ -1,180 +0,0 @@
name: Azure Active Directory
id: 7c12d2b2-2679-4806-b258-c17eaffbc66d
author: Patrick Bareiss, Splunk
source: Azure AD
sourcetype: azure:monitor:aad
separator: operationName
supported_TA:
name: Splunk Add-on for Microsoft Cloud Services
version: 5.2.2
url: https://splunkbase.splunk.com/app/3110
event_names:
- event_name: Azure Active Directory
data_source: data_sources/cloud/event_sources/Azure_Active_Directory.yml
- event_name: Azure Active Directory Add app role assignment to service principal
data_source: data_sources/cloud/event_sources/Azure_Active_Directory_Add_app_role_assignment_to_service_principal.yml
- event_name: Azure Active Directory Add member to role
data_source: data_sources/cloud/event_sources/Azure_Active_Directory_Add_member_to_role.yml
- event_name: Azure Active Directory Add owner to application
data_source: data_sources/cloud/event_sources/Azure_Active_Directory_Add_owner_to_application.yml
- event_name: Azure Active Directory Add service principal
data_source: data_sources/cloud/event_sources/Azure_Active_Directory_Add_service_principal.yml
- event_name: Azure Active Directory Add unverified domain
data_source: data_sources/cloud/event_sources/Azure_Active_Directory_Add_unverified_domain.yml
- event_name: Azure Active Directory Consent to application
data_source: data_sources/cloud/event_sources/Azure_Active_Directory_Consent_to_application.yml
- event_name: Azure Active Directory Disable Strong Authentication
data_source: data_sources/cloud/event_sources/Azure_Active_Directory_Disable_Strong_Authentication.yml
- event_name: Azure Active Directory Enable account
data_source: data_sources/cloud/event_sources/Azure_Active_Directory_Enable_account.yml
- event_name: Azure Active Directory Invite external user
data_source: data_sources/cloud/event_sources/Azure_Active_Directory_Invite_external_user.yml
- event_name: Azure Active Directory Reset password (by admin)
data_source: data_sources/cloud/event_sources/Azure_Active_Directory_Reset_password_(by_admin).yml
- event_name: Azure Active Directory Set domain authentication
data_source: data_sources/cloud/event_sources/Azure_Active_Directory_Set_domain_authentication.yml
- event_name: Azure Active Directory Sign-in activity
data_source: data_sources/cloud/event_sources/Azure_Active_Directory_Sign-in_activity.yml
- event_name: Azure Active Directory Update application
data_source: data_sources/cloud/event_sources/Azure_Active_Directory_Update_application.yml
- event_name: Azure Active Directory Update authorization policy
data_source: data_sources/cloud/event_sources/Azure_Active_Directory_Update_authorization_policy.yml
- event_name: Azure Active Directory Update user
data_source: data_sources/cloud/event_sources/Azure_Active_Directory_Update_user.yml
- event_name: Azure Active Directory User registered security info
data_source: data_sources/cloud/event_sources/Azure_Active_Directory_User_registered_security_info.yml
fields:
- _time
- Level
- callerIpAddress
- category
- correlationId
- date_hour
- date_mday
- date_minute
- date_month
- date_second
- date_wday
- date_year
- date_zone
- durationMs
- host
- identity
- index
- linecount
- location
- operationName
- operationVersion
- properties.alternateSignInName
- properties.appDisplayName
- properties.appId
- properties.appServicePrincipalId
- properties.authenticationDetails{}.RequestSequence
- properties.authenticationDetails{}.StatusSequence
- properties.authenticationDetails{}.authenticationMethod
- properties.authenticationDetails{}.authenticationMethodDetail
- properties.authenticationDetails{}.authenticationStepDateTime
- properties.authenticationDetails{}.authenticationStepRequirement
- properties.authenticationDetails{}.authenticationStepResultDetail
- properties.authenticationDetails{}.succeeded
- properties.authenticationProcessingDetails{}.key
- properties.authenticationProcessingDetails{}.value
- properties.authenticationProtocol
- properties.authenticationRequirement
- properties.autonomousSystemNumber
- properties.clientAppUsed
- properties.clientCredentialType
- properties.conditionalAccessStatus
- properties.correlationId
- properties.createdDateTime
- properties.crossTenantAccessType
- properties.deviceDetail.deviceId
- properties.deviceDetail.operatingSystem
- properties.flaggedForReview
- properties.homeTenantId
- properties.id
- properties.incomingTokenType
- properties.ipAddress
- properties.isInteractive
- properties.isTenantRestricted
- properties.location.city
- properties.location.countryOrRegion
- properties.location.geoCoordinates.latitude
- properties.location.geoCoordinates.longitude
- properties.location.state
- properties.originalRequestId
- properties.processingTimeInMilliseconds
- properties.resourceDisplayName
- properties.resourceId
- properties.resourceServicePrincipalId
- properties.resourceTenantId
- properties.riskDetail
- properties.riskLevelAggregated
- properties.riskLevelDuringSignIn
- properties.riskState
- properties.rngcStatus
- properties.servicePrincipalId
- properties.signInIdentifier
- properties.ssoExtensionVersion
- properties.status.errorCode
- properties.status.failureReason
- properties.tokenIssuerName
- properties.tokenIssuerType
- properties.uniqueTokenIdentifier
- properties.userAgent
- properties.userDisplayName
- properties.userId
- properties.userPrincipalName
- properties.userType
- punct
- resourceId
- resultDescription
- resultSignature
- resultType
- source
- sourcetype
- splunk_server
- tenantId
- time
- timeendpos
- timestartpos
example_log: '{"time": "2023-01-23T21:29:14.1490728Z", "resourceId": "/tenants/fc69e276-e9e8-4af9-9002-1e410d77244e/providers/Microsoft.aadiam",
"operationName": "Sign-in activity", "operationVersion": "1.0", "category": "SignInLogs",
"tenantId": "fc69e276-e9e8-4af9-9002-1e410d77244e", "resultType": "50126", "resultSignature":
"None", "resultDescription": "Invalid username or password or Invalid on-premise
username or password.", "durationMs": 0, "callerIpAddress": "35.80.10.10", "correlationId":
"1634ad3a-1f98-4964-add5-92fc58621944", "identity": "User30", "Level": 4, "location":
"US", "properties": {"id": "13148568-d61e-45eb-b38b-1fa63c106d00", "createdDateTime":
"2023-01-23T21:29:14.1490728+00:00", "userDisplayName": "User30", "userPrincipalName":
"user30@splunkresearch.com", "userId": "40b61050-e814-4ae5-8ffe-66b6f0c53998", "appId":
"1b730954-1685-4b74-9bfd-dac224a7b894", "appDisplayName": "Azure Active Directory
PowerShell", "ipAddress": "35.80.10.10", "status": {"errorCode": 50126, "failureReason":
"Invalid username or password or Invalid on-premise username or password."}, "clientAppUsed":
"Mobile Apps and Desktop clients", "userAgent": "Mozilla/5.0 (Windows NT; Windows
NT 10.0; en-US) WindowsPowerShell/5.1.14393.5127", "deviceDetail": {"deviceId":
"", "operatingSystem": "Windows 10"}, "location": {"city": "Boardman", "state":
"Oregon", "countryOrRegion": "US", "geoCoordinates": {"latitude": 45.83599853515625,
"longitude": -119.6989974975586}}, "correlationId": "1634ad3a-1f98-4964-add5-92fc58621944",
"conditionalAccessStatus": "notApplied", "appliedConditionalAccessPolicies": [],
"authenticationContextClassReferences": [], "originalRequestId": "13148568-d61e-45eb-b38b-1fa63c106d00",
"isInteractive": true, "tokenIssuerName": "", "tokenIssuerType": "AzureAD", "authenticationProcessingDetails":
[{"key": "Legacy TLS (TLS 1.0, 1.1, 3DES)", "value": "False"}, {"key": "Is CAE Token",
"value": "False"}], "networkLocationDetails": [], "clientCredentialType": "none",
"processingTimeInMilliseconds": 47, "riskDetail": "none", "riskLevelAggregated":
"none", "riskLevelDuringSignIn": "none", "riskState": "none", "riskEventTypes":
[], "riskEventTypes_v2": [], "resourceDisplayName": "Windows Azure Active Directory",
"resourceId": "00000002-0000-0000-c000-000000000000", "resourceTenantId": "fc69e276-e9e8-4af9-9002-1e410d77244e",
"homeTenantId": "fc69e276-e9e8-4af9-9002-1e410d77244e", "authenticationDetails":
[{"authenticationStepDateTime": "2023-01-23T21:29:14.1490728+00:00", "authenticationMethod":
"Password", "authenticationMethodDetail": "Password in the cloud", "succeeded":
false, "authenticationStepResultDetail": "Invalid username or password or Invalid
on-premise username or password.", "authenticationStepRequirement": "Primary authentication",
"StatusSequence": 0, "RequestSequence": 1}], "authenticationRequirementPolicies":
[], "authenticationRequirement": "singleFactorAuthentication", "alternateSignInName":
"user30@splunkresearch.com", "signInIdentifier": "user30@splunkresearch.com", "servicePrincipalId":
"", "userType": "Member", "flaggedForReview": false, "isTenantRestricted": false,
"autonomousSystemNumber": 16509, "crossTenantAccessType": "none", "privateLinkDetails":
{}, "ssoExtensionVersion": "", "uniqueTokenIdentifier": "aIUUEx7W60Wzix-mPBBtAA",
"authenticationStrengths": [], "incomingTokenType": "none", "authenticationProtocol":
"none", "appServicePrincipalId": null, "resourceServicePrincipalId": "4d6bd7de-c9bc-45cc-b8ec-ae315f66bf77",
"rngcStatus": 0}}'
-17
View File
@@ -1,17 +0,0 @@
name: Azure Audit
id: 62e2f93e-4e9c-4d38-bb2c-6d59c4565318
author: Patrick Bareiss, Splunk
source: mscs:azure:audit
sourcetype: mscs:azure:audit
separator: operationName.localizedValue
supported_TA:
name: Splunk Add-on for Microsoft Cloud Services
version: 5.2.2
url: https://splunkbase.splunk.com/app/3110
event_names:
- event_name: Azure Audit Create or Update an Azure Automation Runbook
data_source: data_sources/cloud/event_sources/Azure_Audit_Create_or_Update_an_Azure_Automation_Runbook.yml
- event_name: Azure Audit Create or Update an Azure Automation account
data_source: data_sources/cloud/event_sources/Azure_Audit_Create_or_Update_an_Azure_Automation_account.yml
- event_name: Azure Audit Create or Update an Azure Automation webhook
data_source: data_sources/cloud/event_sources/Azure_Audit_Create_or_Update_an_Azure_Automation_webhook.yml
-205
View File
@@ -1,205 +0,0 @@
name: GitHub
id: 88aa4632-3c3e-43f6-a00a-998d71f558e3
author: Patrick Bareiss, Splunk
source: github
sourcetype: aws:firehose:json
supported_TA:
name: Splunk Add-on for Github
version: 2.2.1
url: https://splunkbase.splunk.com/app/6254
event_names: []
fields:
- _time
- action
- host
- index
- linecount
- meta
- punct
- source
- sourcetype
- splunk_server
- timestamp
- workflow_run.actor.avatar_url
- workflow_run.actor.events_url
- workflow_run.actor.followers_url
- workflow_run.actor.following_url
- workflow_run.actor.gists_url
- workflow_run.actor.gravatar_id
- workflow_run.actor.html_url
- workflow_run.actor.id
- workflow_run.actor.login
- workflow_run.actor.node_id
- workflow_run.actor.organizations_url
- workflow_run.actor.received_events_url
- workflow_run.actor.repos_url
- workflow_run.actor.site_admin
- workflow_run.actor.starred_url
- workflow_run.actor.subscriptions_url
- workflow_run.actor.type
- workflow_run.actor.url
- workflow_run.artifacts_url
- workflow_run.cancel_url
- workflow_run.check_suite_id
- workflow_run.check_suite_node_id
- workflow_run.check_suite_url
- workflow_run.conclusion
- workflow_run.created_at
- workflow_run.event
- workflow_run.head_branch
- workflow_run.head_commit.author.email
- workflow_run.head_commit.author.name
- workflow_run.head_commit.committer.email
- workflow_run.head_commit.committer.name
- workflow_run.head_commit.id
- workflow_run.head_commit.message
- workflow_run.head_commit.timestamp
- workflow_run.head_commit.tree_id
- workflow_run.head_repository.collaborators_url
- workflow_run.head_repository.description
- workflow_run.head_repository.fork
- workflow_run.head_repository.forks_url
- workflow_run.head_repository.full_name
- workflow_run.head_repository.hooks_url
- workflow_run.head_repository.html_url
- workflow_run.head_repository.id
- workflow_run.head_repository.keys_url
- workflow_run.head_repository.name
- workflow_run.head_repository.node_id
- workflow_run.head_repository.owner.avatar_url
- workflow_run.head_repository.owner.events_url
- workflow_run.head_repository.owner.followers_url
- workflow_run.head_repository.owner.following_url
- workflow_run.head_repository.owner.gists_url
- workflow_run.head_repository.owner.gravatar_id
- workflow_run.head_repository.owner.html_url
- workflow_run.head_repository.owner.id
- workflow_run.head_repository.owner.login
- workflow_run.head_repository.owner.node_id
- workflow_run.head_repository.owner.organizations_url
- workflow_run.head_repository.owner.received_events_url
- workflow_run.head_repository.owner.repos_url
- workflow_run.head_repository.owner.site_admin
- workflow_run.head_repository.owner.starred_url
- workflow_run.head_repository.owner.subscriptions_url
- workflow_run.head_repository.owner.type
- workflow_run.head_repository.owner.url
- workflow_run.head_repository.private
- workflow_run.head_repository.teams_url
- workflow_run.head_repository.url
- workflow_run.head_sha
- workflow_run.html_url
- workflow_run.id
- workflow_run.jobs_url
- workflow_run.logs_url
- workflow_run.name
- workflow_run.node_id
- workflow_run.previous_attempt_url
- workflow_run.pull_requests{}.base.ref
- workflow_run.pull_requests{}.base.repo.id
- workflow_run.pull_requests{}.base.repo.name
- workflow_run.pull_requests{}.base.repo.url
- workflow_run.pull_requests{}.base.sha
- workflow_run.pull_requests{}.head.ref
- workflow_run.pull_requests{}.head.repo.id
- workflow_run.pull_requests{}.head.repo.name
- workflow_run.pull_requests{}.head.repo.url
- workflow_run.pull_requests{}.head.sha
- workflow_run.pull_requests{}.id
- workflow_run.pull_requests{}.number
- workflow_run.pull_requests{}.url
- workflow_run.repository.archive_url
- workflow_run.repository.assignees_url
- workflow_run.repository.blobs_url
- workflow_run.repository.branches_url
- workflow_run.repository.collaborators_url
- workflow_run.repository.comments_url
- workflow_run.repository.commits_url
- workflow_run.repository.compare_url
- workflow_run.repository.contents_url
- workflow_run.repository.contributors_url
- workflow_run.repository.deployments_url
- workflow_run.repository.description
- workflow_run.repository.downloads_url
- workflow_run.repository.events_url
- workflow_run.repository.fork
- workflow_run.repository.forks_url
- workflow_run.repository.full_name
- workflow_run.repository.git_commits_url
- workflow_run.repository.git_refs_url
- workflow_run.repository.git_tags_url
- workflow_run.repository.hooks_url
- workflow_run.repository.html_url
- workflow_run.repository.id
- workflow_run.repository.issue_comment_url
- workflow_run.repository.issue_events_url
- workflow_run.repository.issues_url
- workflow_run.repository.keys_url
- workflow_run.repository.labels_url
- workflow_run.repository.languages_url
- workflow_run.repository.merges_url
- workflow_run.repository.milestones_url
- workflow_run.repository.name
- workflow_run.repository.node_id
- workflow_run.repository.notifications_url
- workflow_run.repository.owner.avatar_url
- workflow_run.repository.owner.events_url
- workflow_run.repository.owner.followers_url
- workflow_run.repository.owner.following_url
- workflow_run.repository.owner.gists_url
- workflow_run.repository.owner.gravatar_id
- workflow_run.repository.owner.html_url
- workflow_run.repository.owner.id
- workflow_run.repository.owner.login
- workflow_run.repository.owner.node_id
- workflow_run.repository.owner.organizations_url
- workflow_run.repository.owner.received_events_url
- workflow_run.repository.owner.repos_url
- workflow_run.repository.owner.site_admin
- workflow_run.repository.owner.starred_url
- workflow_run.repository.owner.subscriptions_url
- workflow_run.repository.owner.type
- workflow_run.repository.owner.url
- workflow_run.repository.private
- workflow_run.repository.pulls_url
- workflow_run.repository.releases_url
- workflow_run.repository.stargazers_url
- workflow_run.repository.statuses_url
- workflow_run.repository.subscribers_url
- workflow_run.repository.subscription_url
- workflow_run.repository.tags_url
- workflow_run.repository.teams_url
- workflow_run.repository.trees_url
- workflow_run.repository.url
- workflow_run.rerun_url
- workflow_run.run_attempt
- workflow_run.run_number
- workflow_run.run_started_at
- workflow_run.status
- workflow_run.triggering_actor.avatar_url
- workflow_run.triggering_actor.events_url
- workflow_run.triggering_actor.followers_url
- workflow_run.triggering_actor.following_url
- workflow_run.triggering_actor.gists_url
- workflow_run.triggering_actor.gravatar_id
- workflow_run.triggering_actor.html_url
- workflow_run.triggering_actor.id
- workflow_run.triggering_actor.login
- workflow_run.triggering_actor.node_id
- workflow_run.triggering_actor.organizations_url
- workflow_run.triggering_actor.received_events_url
- workflow_run.triggering_actor.repos_url
- workflow_run.triggering_actor.site_admin
- workflow_run.triggering_actor.starred_url
- workflow_run.triggering_actor.subscriptions_url
- workflow_run.triggering_actor.type
- workflow_run.triggering_actor.url
- workflow_run.updated_at
- workflow_run.url
- workflow_run.workflow_id
- workflow_run.workflow_url
example_log:
'{"action":"requested","workflow_run":{"id":2088708615,"name":"auto-update","node_id":"WFR_kwLOCa00Ec58fyoH","head_branch":"mac_os_detections","head_sha":"4049334910ea3d52a917ca35aed66d11c80ed966","run_number":9504,"event":"push","status":"queued","conclusion":null,"workflow_id":4692335,"check_suite_id":5918781611,"check_suite_node_id":"CS_kwDOCa00Ec8AAAABYMlwqw","url":"https://api.github.com/repos/splunk/security_content/actions/runs/2088708615","html_url":"https://github.com/splunk/security_content/actions/runs/2088708615","pull_requests":[{"url":"https://api.github.com/repos/splunk/security_content/pulls/2131","id":893091277,"number":2131,"head":{"ref":"mac_os_detections","sha":"4049334910ea3d52a917ca35aed66d11c80ed966","repo":{"id":162346001,"url":"https://api.github.com/repos/splunk/security_content","name":"security_content"}},"base":{"ref":"develop","sha":"a7d3d1dc57f9bf36fe22e470bcf518fcc2c89283","repo":{"id":162346001,"url":"https://api.github.com/repos/splunk/security_content","name":"security_content"}}}],"created_at":"2022-04-04T08:43:15Z","updated_at":"2022-04-04T08:43:15Z","actor":{"login":"jsmith","id":8362376,"node_id":"MDQ6VXNlcjgzNjIzNzY=","avatar_url":"https://avatars.githubusercontent.com/u/8362376?v=4","gravatar_id":"","url":"https://api.github.com/users/jsmith","html_url":"https://github.com/jsmith","followers_url":"https://api.github.com/users/jsmith/followers","following_url":"https://api.github.com/users/jsmith/following{/other_user}","gists_url":"https://api.github.com/users/jsmith/gists{/gist_id}","starred_url":"https://api.github.com/users/jsmith/starred{/owner}{/repo}","subscriptions_url":"https://api.github.com/users/jsmith/subscriptions","organizations_url":"https://api.github.com/users/jsmith/orgs","repos_url":"https://api.github.com/users/jsmith/repos","events_url":"https://api.github.com/users/jsmith/events{/privacy}","received_events_url":"https://api.github.com/users/jsmith/received_events","type":"User","site_admin":false},"run_attempt":1,"run_started_at":"2022-04-04T08:43:15Z","triggering_actor":{"login":"jsmith","id":8362376,"node_id":"MDQ6VXNlcjgzNjIzNzY=","avatar_url":"https://avatars.githubusercontent.com/u/8362376?v=4","gravatar_id":"","url":"https://api.github.com/users/jsmith","html_url":"https://github.com/jsmith","followers_url":"https://api.github.com/users/jsmith/followers","following_url":"https://api.github.com/users/jsmith/following{/other_user}","gists_url":"https://api.github.com/users/jsmith/gists{/gist_id}","starred_url":"https://api.github.com/users/jsmith/starred{/owner}{/repo}","subscriptions_url":"https://api.github.com/users/jsmith/subscriptions","organizations_url":"https://api.github.com/users/jsmith/orgs","repos_url":"https://api.github.com/users/jsmith/repos","events_url":"https://api.github.com/users/jsmith/events{/privacy}","received_events_url":"https://api.github.com/users/jsmith/received_events","type":"User","site_admin":false},"jobs_url":"https://api.github.com/repos/splunk/security_content/actions/runs/2088708615/jobs","logs_url":"https://api.github.com/repos/splunk/security_content/actions/runs/2088708615/logs","check_suite_url":"https://api.github.com/repos/splunk/security_content/check-suites/5918781611","artifacts_url":"https://api.github.com/repos/splunk/security_content/actions/runs/2088708615/artifacts","cancel_url":"https://api.github.com/repos/splunk/security_content/actions/runs/2088708615/cancel","rerun_url":"https://api.github.com/repos/splunk/security_content/actions/runs/2088708615/rerun","previous_attempt_url":null,"workflow_url":"https://api.github.com/repos/splunk/security_content/actions/workflows/4692335","head_commit":{"id":"4049334910ea3d52a917ca35aed66d11c80ed966","tree_id":"df4ddc1359be3b19f093b7a27dbf5708187743a0","message":"small
change","timestamp":"2022-04-04T08:43:01Z","author":{"name":"jsmith","email":"jsmith@evilcorp.com"},"committer":{"name":"jsmith","email":"jsmith@evilcorp.com"}},"repository":{"id":162346001,"node_id":"MDEwOlJlcG9zaXRvcnkxNjIzNDYwMDE=","name":"security_content","full_name":"splunk/security_content","private":false,"owner":{"login":"splunk","id":651467,"node_id":"MDEyOk9yZ2FuaXphdGlvbjY1MTQ2Nw==","avatar_url":"https://avatars.githubusercontent.com/u/651467?v=4","gravatar_id":"","url":"https://api.github.com/users/splunk","html_url":"https://github.com/splunk","followers_url":"https://api.github.com/users/splunk/followers","following_url":"https://api.github.com/users/splunk/following{/other_user}","gists_url":"https://api.github.com/users/splunk/gists{/gist_id}","starred_url":"https://api.github.com/users/splunk/starred{/owner}{/repo}","subscriptions_url":"https://api.github.com/users/splunk/subscriptions","organizations_url":"https://api.github.com/users/splunk/orgs","repos_url":"https://api.github.com/users/splunk/repos","events_url":"https://api.github.com/users/splunk/events{/privacy}","received_events_url":"https://api.github.com/users/splunk/received_events","type":"Organization","site_admin":false},"html_url":"https://github.com/splunk/security_content","description":"Splunk
Security Content","fork":false,"url":"https://api.github.com/repos/splunk/security_content","forks_url":"https://api.github.com/repos/splunk/security_content/forks","keys_url":"https://api.github.com/repos/splunk/security_content/keys{/key_id}","collaborators_url":"https://api.github.com/repos/splunk/security_content/collaborators{/collaborator}","teams_url":"https://api.github.com/repos/splunk/security_content/teams","hooks_url":"https://api.github.com/repos/splunk/security_content/hooks","issue_events_url":"https://api.github.com/repos/splunk/security_content/issues/events{/number}","events_url":"https://api.github.com/repos/splunk/security_content/events","assignees_url":"https://api.github.com/repos/splunk/security_content/assignees{/user}","branches_url":"https://api.github.com/repos/splunk/security_content/branches{/branch}","tags_url":"https://api.github.com/repos/splunk/security_content/tags","blobs_url":"https://api.github.com/repos/splunk/security_content/git/blobs{/sha}","git_tags_url":"https://api.github.com/repos/splunk/security_content/git/tags{/sha}","git_refs_url":"https://api.github.com/repos/splunk/security_content/git/refs{/sha}","trees_url":"https://api.github.com/repos/splunk/security_content/git/trees{/sha}","statuses_url":"https://api.github.com/repos/splunk/security_content/statuses/{sha}","languages_url":"https://api.github.com/repos/splunk/security_content/languages","stargazers_url":"https://api.github.com/repos/splunk/security_content/stargazers","contributors_url":"https://api.github.com/repos/splunk/security_content/contributors","subscribers_url":"https://api.github.com/repos/splunk/security_content/subscribers","subscription_url":"https://api.github.com/repos/splunk/security_content/subscription","commits_url":"https://api.github.com/repos/splunk/security_content/commits{/sha}","git_commits_url":"https://api.github.com/repos/splunk/security_content/git/commits{/sha}","comments_url":"https://api.github.com/repos/splunk/security_content/comments{/number}","issue_comment_url":"https://api.github.com/repos/splunk/security_content/issues/comments{/number}","contents_url":"https://api.github.com/repos/splunk/security_content/contents/{+path}","compare_url":"https://api.github.com/repos/splunk/security_content/compare/{base}...{head}","merges_url":"https://api.github.com/repos/splunk/security_content/merges","archive_url":"https://api.github.com/repos/splunk/security_content/{archive_format}{/ref}","downloads_url":"https://api.github.com/repos/splunk/security_content/downloads","issues_url":"https://api.github.com/repos/splunk/security_content/issues{/number}","pulls_url":"https://api.github.com/repos/splunk/security_content/pulls{/number}","milestones_url":"https://api.github.com/repos/splunk/security_content/milestones{/number}","notifications_url":"https://api.github.com/repos/splunk/security_content/notifications{?since,all,participating}","labels_url":"https://api.github.com/repos/splunk/security_content/labels{/name}","releases_url":"https://api.github.com/repos/splunk/security_content/releases{/id}","deployments_url":"https://api.github.com/repos/splunk/security_content/deployments"},"head_repository":{"id":162346001,"node_id":"MDEwOlJlcG9zaXRvcnkxNjIzNDYwMDE=","name":"security_content","full_name":"splunk/security_content","private":false,"owner":{"login":"splunk","id":651467,"node_id":"MDEyOk9yZ2FuaXphdGlvbjY1MTQ2Nw==","avatar_url":"https://avatars.githubusercontent.com/u/651467?v=4","gravatar_id":"","url":"https://api.github.com/users/splunk","html_url":"https://github.com/splunk","followers_url":"https://api.github.com/users/splunk/followers","following_url":"https://api.github.com/users/splunk/following{/other_user}","gists_url":"https://api.github.com/users/splunk/gists{/gist_id}","starred_url":"https://api.github.com/users/splunk/starred{/owner}{/repo}","subscriptions_url":"https://api.github.com/users/splunk/subscriptions","organizations_url":"https://api.github.com/users/splunk/orgs","repos_url":"https://api.github.com/users/splunk/repos","events_url":"https://api.github.com/users/splunk/events{/privacy}","received_events_url":"https://api.github.com/users/splunk/received_events","type":"Organization","site_admin":false},"html_url":"https://github.com/splunk/security_content","description":"Splunk
Security Content","fork":false,"url":"https://api.github.com/repos/splunk/security_content","forks_url":"https://api.github.com/repos/splunk/security_content/forks","keys_url":"https://api.github.com/repos/splunk/security_content/keys{/key_id}","collaborators_url":"https://api.github.com/repos/splunk/security_content/collaborators{/collaborator}","teams_url":"https://api.github.com/repos/splunk/security_content/teams","hooks_url":"https://api.github.com/repos/splunk/security_content/hooks","issue_events_url":"https://api.github.com/repos/splunk/security_content/issues/events{/num'
-17
View File
@@ -1,17 +0,0 @@
name: Google Workspace
id: 9ef3a321-c641-4798-8a92-9c10c714a004
author: Patrick Bareiss, Splunk
source: gws:reports:admin
sourcetype: gws:reports:admin
separator: event.name
supported_TA:
name: Splunk Add-on for Google Workspace
version: 2.6.3
url: https://splunkbase.splunk.com/app/5556
event_names:
- event_name: Google Workspace
data_source: data_sources/cloud/event_sources/Google_Workspace.yml
- event_name: Google Workspace login_failure
data_source: data_sources/cloud/event_sources/Google_Workspace_login_failure.yml
- event_name: Google Workspace login_success
data_source: data_sources/cloud/event_sources/Google_Workspace_login_success.yml
-61
View File
@@ -1,61 +0,0 @@
name: Kubernetes Audit
id: 6c25181a-0c07-4aaf-90e6-77ab1f0e6699
author: Patrick Bareiss, Splunk
source: kubernetes
sourcetype: _json
supported_TA: {}
event_names: []
fields:
- _time
- annotations.authorization.k8s.io/decision
- annotations.authorization.k8s.io/reason
- apiVersion
- auditID
- eventtype
- host
- index
- kind
- level
- linecount
- objectRef.apiGroup
- objectRef.apiVersion
- objectRef.namespace
- objectRef.resource
- punct
- requestReceivedTimestamp
- requestURI
- responseObject.apiVersion
- responseObject.code
- responseObject.details.group
- responseObject.details.kind
- responseObject.kind
- responseObject.message
- responseObject.reason
- responseObject.status
- responseStatus.code
- responseStatus.details.group
- responseStatus.details.kind
- responseStatus.message
- responseStatus.reason
- responseStatus.status
- source
- sourceIPs{}
- sourcetype
- splunk_server
- stage
- stageTimestamp
- tag
- tag::eventtype
- timestamp
- user.groups{}
- user.uid
- user.username
- userAgent
- verb
example_log:
'{"kind":"Event","apiVersion":"audit.k8s.io/v1","level":"RequestResponse","auditID":"582c31ab-4906-49bb-9ff9-872f980ccb84","stage":"ResponseComplete","requestURI":"/apis/batch/v1/namespaces/test2/jobs?fieldManager=kubectl-create\u0026fieldValidation=Strict","verb":"create","user":{"username":"k8s-test-user","uid":"aws-iam-authenticator:591511147606:AROAYTOGP2RLFHNBOTP5J","groups":["system:authenticated"]},"sourceIPs":["176.95.188.101"],"userAgent":"kubectl/v1.27.2
(darwin/arm64) kubernetes/7f6f68f","objectRef":{"resource":"jobs","namespace":"test2","apiGroup":"batch","apiVersion":"v1"},"responseStatus":{"metadata":{},"status":"Failure","message":"jobs.batch
is forbidden: User \"k8s-test-user\" cannot create resource \"jobs\" in API group
\"batch\" in the namespace \"test2\"","reason":"Forbidden","details":{"group":"batch","kind":"jobs"},"code":403},"responseObject":{"kind":"Status","apiVersion":"v1","metadata":{},"status":"Failure","message":"jobs.batch
is forbidden: User \"k8s-test-user\" cannot create resource \"jobs\" in API group
\"batch\" in the namespace \"test2\"","reason":"Forbidden","details":{"group":"batch","kind":"jobs"},"code":403},"requestReceivedTimestamp":"2023-12-07T14:44:53.358394Z","stageTimestamp":"2023-12-07T14:44:53.375985Z","annotations":{"authorization.k8s.io/decision":"forbid","authorization.k8s.io/reason":""}}'
-48
View File
@@ -1,48 +0,0 @@
name: Kubernetes Falco
id: 23c0eeed-840a-4711-a41b-6819c1ffbba5
author: Patrick Bareiss, Splunk
source: kubernetes
sourcetype: kube:container:falco
supported_TA: {}
event_names: []
fields:
- _time
- command
- container_id
- container_image
- container_image_tag
- container_name
- date_hour
- date_mday
- date_minute
- date_month
- date_second
- date_wday
- date_year
- date_zone
- evt_type
- exe_flags
- host
- index
- k8s_ns
- k8s_pod_name
- linecount
- parent
- proc_exepath
- process
- punct
- source
- sourcetype
- splunk_server
- terminal
- timeendpos
- timestartpos
- user
- user_loginuid
- user_uid
example_log:
"12:18:18.691725165: Notice A shell was spawned in a container with an
attached terminal (evt_type=execve user=root user_uid=0 user_loginuid=-1 process=bash
proc_exepath=/usr/lib/splunk-otel-collector/agent-bundle/bin/bash parent=runc command=bash
-il terminal=34816 exe_flags=EXE_WRITABLE container_id=7a2566e8e462 container_image=quay.io/signalfx/splunk-otel-collector
container_image_tag=0.88.0 container_name=otel-collector k8s_ns=default k8s_pod_name=my-splunk-otel-collector-agent-9sdhr)"
-123
View File
@@ -1,123 +0,0 @@
name: O365
id: 11c0eed5-3f3f-42e4-bf72-30f11295a686
author: Patrick Bareiss, Splunk
source: o365
sourcetype: o365:management:activity
separator: Operation
supported_TA:
name: Splunk Add-on for Microsoft Office 365
version: 4.5.1
url: https://splunkbase.splunk.com/app/4055
event_names:
- event_name: O365
data_source: data_sources/cloud/event_sources/O365.yml
- event_name: O365 Add app role assignment grant to user.
data_source: data_sources/cloud/event_sources/O365_Add_app_role_assignment_grant_to_user..yml
- event_name: O365 Add app role assignment to service principal.
data_source: data_sources/cloud/event_sources/O365_Add_app_role_assignment_to_service_principal..yml
- event_name: O365 Add member to role.
data_source: data_sources/cloud/event_sources/O365_Add_member_to_role..yml
- event_name: O365 Add owner to application.
data_source: data_sources/cloud/event_sources/O365_Add_owner_to_application..yml
- event_name: O365 Add service principal.
data_source: data_sources/cloud/event_sources/O365_Add_service_principal..yml
- event_name: O365 Add-MailboxPermission
data_source: data_sources/cloud/event_sources/O365_Add-MailboxPermission.yml
- event_name: O365 Change user license.
data_source: data_sources/cloud/event_sources/O365_Change_user_license..yml
- event_name: O365 Consent to application.
data_source: data_sources/cloud/event_sources/O365_Consent_to_application..yml
- event_name: O365 Disable Strong Authentication.
data_source: data_sources/cloud/event_sources/O365_Disable_Strong_Authentication..yml
- event_name: O365 MailItemsAccessed
data_source: data_sources/cloud/event_sources/O365_MailItemsAccessed.yml
- event_name: O365 ModifyFolderPermissions
data_source: data_sources/cloud/event_sources/O365_ModifyFolderPermissions.yml
- event_name: O365 Set Company Information.
data_source: data_sources/cloud/event_sources/O365_Set_Company_Information..yml
- event_name: O365 Set-Mailbox
data_source: data_sources/cloud/event_sources/O365_Set-Mailbox.yml
- event_name: O365 Update application.
data_source: data_sources/cloud/event_sources/O365_Update_application..yml
- event_name: O365 Update authorization policy.
data_source: data_sources/cloud/event_sources/O365_Update_authorization_policy..yml
- event_name: O365 Update user.
data_source: data_sources/cloud/event_sources/O365_Update_user..yml
- event_name: O365 UserLoggedIn
data_source: data_sources/cloud/event_sources/O365_UserLoggedIn.yml
- event_name: O365 UserLoginFailed
data_source: data_sources/cloud/event_sources/O365_UserLoginFailed.yml
fields:
- _time
- AppAccessContext.IssuedAtTime
- AppAccessContext.UniqueTokenId
- AppId
- ClientAppId
- ClientIP
- CreationTime
- ExternalAccess
- Id
- Name
- ObjectId
- Operation
- OrganizationId
- OrganizationName
- OriginatingServer
- Parameters{}.Name
- Parameters{}.Value
- RecordType
- RequestId
- ResultStatus
- Role
- SessionId
- User
- UserId
- UserKey
- UserType
- Version
- Workload
- app
- authentication_service
- command
- date_hour
- date_mday
- date_minute
- date_month
- date_second
- date_wday
- date_year
- date_zone
- dest
- dest_name
- dvc
- host
- index
- linecount
- object
- punct
- record_type
- signature
- source
- sourcetype
- splunk_server
- src
- src_ip
- status
- timeendpos
- timestartpos
- user
- user_id
- user_type
- vendor_account
- vendor_product
example_log: '{"AppAccessContext": {"IssuedAtTime": "2023-10-17T19:13:05", "UniqueTokenId":
"g7oAmNhLoU-8qJVeWeAwAA"}, "CreationTime": "2023-10-17T19:19:59", "Id": "3d26a8cd-d8f4-42f9-1898-08dbcf460e5a",
"Operation": "New-ManagementRoleAssignment", "OrganizationId": "aeb12f6b-1ff3-4a18-9ea2-29aa57e2ae08",
"RecordType": 1, "ResultStatus": "True", "UserKey": "1003BFFD98415B4E", "UserType":
2, "Version": 1, "Workload": "Exchange", "ClientIP": "71.1.1.1:61528", "ObjectId":
"splunkresearch.onmicrosoft.com\\attack-test", "UserId": "compromisedAdmin@splunkresearch.onmicrosoft.com",
"AppId": "fb78d390-0c51-40cd-8e17-fdbfab77341b", "ClientAppId": "", "ExternalAccess":
false, "OrganizationName": "splunkresearch.onmicrosoft.com", "OriginatingServer":
"BYAPR18MB2408 (15.20.6863.047)", "Parameters": [{"Name": "User", "Value": "lowpriv@splunkresearch.onmicrosoft.com"},
{"Name": "Name", "Value": "attack-test"}, {"Name": "Role", "Value": "ApplicationImpersonation"}],
"RequestId": "53a50583-e429-63a4-c9f7-8fbb14437e8a", "SessionId": "e2a028f1-d0e1-4ddb-a5a7-ec57343457ad"}'
@@ -1,92 +0,0 @@
event_name: AWS CloudTrail AssumeRoleWithSAML
fields:
- _time
- action
- app
- awsRegion
- change_type
- command
- date_hour
- date_mday
- date_minute
- date_month
- date_second
- date_wday
- date_year
- date_zone
- dest
- dvc
- errorCode
- eventCategory
- eventID
- eventName
- eventSource
- eventTime
- eventType
- eventVersion
- eventtype
- host
- index
- linecount
- managementEvent
- msg
- object_category
- product
- punct
- readOnly
- recipientAccountId
- region
- requestID
- requestParameters.durationSeconds
- requestParameters.principalArn
- requestParameters.roleArn
- requestParameters.roleSessionName
- requestParameters.sAMLAssertionID
- resources{}.ARN
- resources{}.accountId
- resources{}.type
- responseElements.assumedRoleUser.arn
- responseElements.assumedRoleUser.assumedRoleId
- responseElements.audience
- responseElements.credentials.accessKeyId
- responseElements.credentials.expiration
- responseElements.credentials.sessionToken
- responseElements.issuer
- responseElements.nameQualifier
- responseElements.subject
- responseElements.subjectType
- signature
- source
- sourceIPAddress
- sourcetype
- splunk_server
- src
- src_ip
- src_user
- src_user_id
- src_user_type
- start_time
- status
- tag
- tag::action
- tag::eventtype
- temp_access_key
- timeendpos
- timestartpos
- user
- userAgent
- userIdentity.identityProvider
- userIdentity.principalId
- userIdentity.type
- userIdentity.userName
- user_agent
- user_arn
- user_id
- user_name
- user_role
- user_type
- vendor
- vendor_account
- vendor_product
- vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "SAMLUser", "principalId": "ZRu9MRAjiG9tvi1QBNfdI664G5A=:rodsoto@rodsoto.onmicrosoft.com", "userName": "rodsoto@rodsoto.onmicrosoft.com", "identityProvider": "ZRu9MRAjiG9tvi1QBNfdI664G5A="}, "eventTime": "2021-01-22T03:44:16Z", "eventSource": "sts.amazonaws.com", "eventName": "AssumeRoleWithSAML", "awsRegion": "us-east-1", "sourceIPAddress": "72.21.217.152", "userAgent": "AWS Signin, aws-internal/3 aws-sdk-java/1.11.898 Linux/4.9.230-0.1.ac.223.84.332.metal1.x86_64 OpenJDK_64-Bit_Server_VM/25.275-b01 java/1.8.0_275 kotlin/1.3.72 vendor/Oracle_Corporation", "requestParameters": {"sAMLAssertionID": "_d33ba0ad-0c88-4b83-80a6-27c08027d000", "roleSessionName": "rodsoto@rodsoto.onmicrosoft.com", "durationSeconds": 3600, "roleArn": "arn:aws:iam::111111111111:role/rodonmicrotestrole", "principalArn": "arn:aws:iam::111111111111:saml-provider/rodsotoonmicrosoft"}, "responseElements": {"subjectType": "urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress", "issuer": "https://sts.windows.net/0e8108b1-18e9-41a4-961b-dfcddf92ef08/", "credentials": {"accessKeyId": "ASIAYTOGP2RLKJXOV7VR", "expiration": "Jan 22, 2021 3:59:16 AM", "sessionToken": "IQoJb3JpZ2luX2VjENz//////////wEaCXVzLWVhc3QtMSJGMEQCIHl/WQdLq53ULYl10fPtpeV3H7da9mOXGuIStvhdDA6kAiAdO/7rocOXAtyDV+0MJhSj/piqlqEI/BcAKm8zqBhOgiqgAwi1//////////8BEAIaDDU5MTUxMTE0NzYwNiIMAFP8GfyI/x1fKCHYKvQCznxxgKnEdcuvrr/fBLmHxEDjQ9vQxjasA8gZF8GawZ5SFH9ViKqoZh93bYkOwKqZD8cdqJIo9SYL17RGhVqxzvsjU4+QsRXTN5eGgh+LyF9EZqeCl6oCkaTJqNrXHuenzTi0yiL510LKsSckrAm8+SuwI/jQu3oE1BEcJQieAc4RjYx3II+1cUvyfRlFvR2NDfZhdWcQvAivV06KJg9c2zfCF0Agzn/YZSNvsRL5UhnKhJ2wktSvT8lR0mS3n9xR1j3iYNxVDHab180cnfkP3G6tAmxj5U29diNQrusJxKWWhr/Q9wHRdDj5dO2QUZzSymKKU/UiRJ8nyYPINaJ8XWVAPiT4QgzpMxotkvSkDLEG/brB9yEr2p7W8Y3xMGZ37qSGkuU4z9x40RU9G1XPhv27NO9aaGs/VXYTMCzWRNxnsLfNkk/DihrcaR0SclRcvs+zmfe1ZUoGnfjNYm+AIyJi4D7OrXF5/Mt46Z2y76DnULlAMJCUqYAGOpsBw4fyafV8OizX7Lebh2JRXFZsWBY1GTpyGvO5otrw++4axud44vYVi5iU5rbJxtTBm4vtJartxgXoPJFnQuat9gLrIlXhjmg+m50a5xs1Ut2UWEsWY2Duu4jA9ap7P7dYv9kIK9P2uyhsjKQhCjTpfe4I/llcupbDotYBJuvlB5n85a5kgiSriFk5zetoXQIweuYEWQZsD/AN+LE="}, "nameQualifier": "ZRu9MRAjiG9tvi1QBNfdI664G5A=", "assumedRoleUser": {"assumedRoleId": "AROAYTOGP2RLKFUVAQAIJ:rodsoto@rodsoto.onmicrosoft.com", "arn": "arn:aws:sts::111111111111:assumed-role/rodonmicrotestrole/rodsoto@rodsoto.onmicrosoft.com"}, "subject": "rodsoto@rodsoto.onmicrosoft.com", "audience": "https://signin.aws.amazon.com/saml"}, "requestID": "e19c7a7f-cd96-4642-9ee6-2360a7b01b12", "eventID": "b25b825d-9c9b-49d3-9ecd-290dbe8f2c29", "readOnly": true, "resources": [{"accountId": "111111111111", "type": "AWS::IAM::Role", "ARN": "arn:aws:iam::111111111111:role/rodonmicrotestrole"}, {"accountId": "111111111111", "type": "AWS::IAM::SAMLProvider", "ARN": "arn:aws:iam::111111111111:saml-provider/rodsotoonmicrosoft"}], "eventType": "AwsApiCall", "managementEvent": true, "eventCategory": "Management", "recipientAccountId": "111111111111"}'
@@ -1,80 +0,0 @@
event_name: AWS CloudTrail ConsoleLogin
fields:
- _time
- action
- additionalEventData.LoginTo
- additionalEventData.MFAUsed
- additionalEventData.MobileVersion
- app
- authentication_method
- awsRegion
- aws_account_id
- command
- date_hour
- date_mday
- date_minute
- date_month
- date_second
- date_wday
- date_year
- date_zone
- desc
- dest
- dvc
- errorCode
- errorMessage
- eventCategory
- eventID
- eventName
- eventSource
- eventTime
- eventType
- eventVersion
- eventtype
- host
- index
- linecount
- managementEvent
- msg
- object_category
- product
- punct
- readOnly
- reason
- recipientAccountId
- region
- requestParameters
- responseElements.ConsoleLogin
- result
- signature
- source
- sourceIPAddress
- sourcetype
- splunk_server
- src
- src_ip
- start_time
- status
- tag
- tag::action
- tag::eventtype
- timeendpos
- timestartpos
- tlsDetails.cipherSuite
- tlsDetails.clientProvidedHostHeader
- tlsDetails.tlsVersion
- userAgent
- userIdentity.accessKeyId
- userIdentity.accountId
- userIdentity.type
- userIdentity.userName
- user_access_key
- user_agent
- user_group_id
- user_name
- user_type
- vendor
- vendor_account
- vendor_product
- vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "accountId": "140429656527", "accessKeyId": "", "userName": "HIDDEN_DUE_TO_SECURITY_REASONS"}, "eventTime": "2022-10-19T20:33:38Z", "eventSource": "signin.amazonaws.com", "eventName": "ConsoleLogin", "awsRegion": "us-east-1", "sourceIPAddress": "142.254.89.27", "userAgent": "Go-http-client/1.1", "errorMessage": "No username found in supplied account", "requestParameters": null, "responseElements": {"ConsoleLogin": "Failure"}, "additionalEventData": {"LoginTo": "https://console.aws.amazon.com", "MobileVersion": "No", "MFAUsed": "No"}, "eventID": "9fcfb8c3-3fca-48db-85d2-7b107f9d95d0", "readOnly": false, "eventType": "AwsConsoleSignIn", "managementEvent": true, "recipientAccountId": "140429656527", "eventCategory": "Management", "tlsDetails": {"tlsVersion": "TLSv1.2", "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256", "clientProvidedHostHeader": "signin.aws.amazon.com"}}'
@@ -1,86 +0,0 @@
event_name: AWS CloudTrail CopyObject
fields:
- _time
- additionalEventData.AuthenticationMethod
- additionalEventData.CipherSuite
- additionalEventData.SSEApplied
- additionalEventData.SignatureVersion
- additionalEventData.bytesTransferredIn
- additionalEventData.bytesTransferredOut
- additionalEventData.x-amz-id-2
- app
- awsRegion
- aws_account_id
- command
- date_hour
- date_mday
- date_minute
- date_month
- date_second
- date_wday
- date_year
- date_zone
- dest
- dvc
- errorCode
- eventCategory
- eventID
- eventName
- eventSource
- eventTime
- eventType
- eventVersion
- host
- index
- linecount
- managementEvent
- msg
- object_category
- product
- punct
- readOnly
- recipientAccountId
- region
- requestID
- requestParameters.Host
- requestParameters.bucketName
- requestParameters.key
- requestParameters.x-amz-copy-source
- requestParameters.x-amz-server-side-encryption
- requestParameters.x-amz-server-side-encryption-aws-kms-key-id
- resources{}.ARN
- resources{}.accountId
- resources{}.type
- responseElements.x-amz-server-side-encryption
- responseElements.x-amz-server-side-encryption-aws-kms-key-id
- signature
- source
- sourceIPAddress
- sourcetype
- splunk_server
- src
- src_ip
- start_time
- timeendpos
- timestartpos
- user
- userAgent
- userIdentity.accessKeyId
- userIdentity.accountId
- userIdentity.arn
- userIdentity.principalId
- userIdentity.type
- userIdentity.userName
- userName
- user_access_key
- user_agent
- user_arn
- user_group_id
- user_id
- user_name
- user_type
- vendor
- vendor_account
- vendor_product
- vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId": "AIDAYTOGP2RLNALZHZ6KX", "arn": "arn:aws:iam::111111111111:user/patrick_cli", "accountId": "111111111111", "accessKeyId": "AKIAYTOGP2RLJ2OYSF6E", "userName": "patrick_cli"}, "eventTime": "2021-01-11T12:40:47Z", "eventSource": "s3.amazonaws.com", "eventName": "CopyObject", "awsRegion": "us-west-2", "sourceIPAddress": "95.90.199.65", "userAgent": "[aws-cli/2.0.45 Python/3.7.4 Darwin/20.2.0 exe/x86_64 command/s3.cp]", "requestParameters": {"bucketName": "patricktestbucketencrypt", "x-amz-server-side-encryption-aws-kms-key-id": "arn:aws:kms:us-west-2:111111111111:key/f2a82583-a7d3-4c92-8787-fe2baab1cee1", "Host": "patricktestbucketencrypt.s3.us-west-2.amazonaws.com", "x-amz-server-side-encryption": "aws:kms", "x-amz-copy-source": "patricktestbucketencrypt/kms_aws_events.json", "key": "kms_aws_events_encrypted.json"}, "responseElements": {"x-amz-server-side-encryption": "aws:kms", "x-amz-server-side-encryption-aws-kms-key-id": "arn:aws:kms:us-west-2:111111111111:key/f2a82583-a7d3-4c92-8787-fe2baab1cee1"}, "additionalEventData": {"SignatureVersion": "SigV4", "CipherSuite": "ECDHE-RSA-AES128-GCM-SHA256", "bytesTransferredIn": 0.0, "SSEApplied": "SSE_KMS", "AuthenticationMethod": "AuthHeader", "x-amz-id-2": "fqzX1iZV6ImDtkFxbGvziOE6fUwryRa+PhnLckfVAkLNHdbCAHNq4l/yckUd1a2HNJPL6NAS01U=", "bytesTransferredOut": 234.0}, "requestID": "6A7359F7A9414B02", "eventID": "b20d43de-175d-4443-acd7-f5f3e587ae00", "readOnly": false, "resources": [{"type": "AWS::S3::Object", "ARN": "arn:aws:s3:::patricktestbucketencrypt/kms_aws_events_encrypted.json"}, {"accountId": "111111111111", "type": "AWS::S3::Bucket", "ARN": "arn:aws:s3:::patricktestbucketencrypt"}, {"accountId": "111111111111", "type": "AWS::S3::Bucket", "ARN": "arn:aws:s3:::patricktestbucketencrypt"}, {"type": "AWS::S3::Object", "ARN": "arn:aws:s3:::patricktestbucketencrypt/kms_aws_events.json"}], "eventType": "AwsApiCall", "managementEvent": false, "recipientAccountId": "111111111111", "eventCategory": "Data"}'
@@ -1,80 +0,0 @@
event_name: AWS CloudTrail CreateAccessKey
fields:
- _time
- action
- app
- awsRegion
- aws_account_id
- change_type
- command
- date_hour
- date_mday
- date_minute
- date_month
- date_second
- date_wday
- date_year
- date_zone
- dest
- dvc
- errorCode
- eventCategory
- eventID
- eventName
- eventSource
- eventTime
- eventType
- eventVersion
- eventtype
- host
- index
- linecount
- managementEvent
- msg
- object_category
- product
- punct
- readOnly
- recipientAccountId
- region
- requestID
- requestParameters.userName
- responseElements.accessKey.accessKeyId
- responseElements.accessKey.createDate
- responseElements.accessKey.status
- responseElements.accessKey.userName
- signature
- source
- sourceIPAddress
- sourcetype
- splunk_server
- src
- src_ip
- src_user_name
- start_time
- status
- tag
- tag::eventtype
- timeendpos
- timestartpos
- user
- userAgent
- userIdentity.accessKeyId
- userIdentity.accountId
- userIdentity.arn
- userIdentity.principalId
- userIdentity.type
- userIdentity.userName
- userName
- user_access_key
- user_agent
- user_arn
- user_group_id
- user_id
- user_name
- user_type
- vendor
- vendor_account
- vendor_product
- vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId": "AIDAYTOGP2RLEHRX5YWNV", "arn": "arn:aws:iam::121521347698:user/bhavin_cli", "accountId": "121521347698", "accessKeyId": "AKIAYTOGP2RLLAA6NJUM", "userName": "bhavin_cli"}, "eventTime": "2021-03-02T21:18:24Z", "eventSource": "iam.amazonaws.com", "eventName": "CreateAccessKey", "awsRegion": "us-east-1", "sourceIPAddress": "12.25.72.12", "userAgent": "aws-cli/2.0.62 Python/3.9.0 Darwin/19.6.0 source/x86_64 command/iam.create-access-key", "requestParameters": {"userName": "AtomicRedTeam"}, "responseElements": {"accessKey": {"userName": "AtomicRedTeam", "accessKeyId": "AKIAYTOGP2RLOQ4ULYGT", "status": "Active", "createDate": "Mar 2, 2021 9:18:24 PM"}}, "requestID": "12c8773d-6c78-46bf-a8e4-f841adc8f70d", "eventID": "5772e8d5-cccc-470d-81ef-acacfe85a804", "readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "eventCategory": "Management", "recipientAccountId": "121521347698"}'
@@ -1,98 +0,0 @@
event_name: AWS CloudTrail CreateKey
fields:
- _time
- app
- awsRegion
- aws_account_id
- command
- date_hour
- date_mday
- date_minute
- date_month
- date_second
- date_wday
- date_year
- date_zone
- dest
- dvc
- errorCode
- eventCategory
- eventID
- eventName
- eventSource
- eventTime
- eventType
- eventVersion
- eventtype
- host
- index
- linecount
- managementEvent
- msg
- object_category
- product
- punct
- readOnly
- recipientAccountId
- region
- requestID
- requestParameters.bypassPolicyLockoutSafetyCheck
- requestParameters.customerMasterKeySpec
- requestParameters.description
- requestParameters.keyUsage
- requestParameters.origin
- requestParameters.policy
- resources{}.ARN
- resources{}.accountId
- resources{}.type
- responseElements.keyMetadata.aWSAccountId
- responseElements.keyMetadata.arn
- responseElements.keyMetadata.creationDate
- responseElements.keyMetadata.customerMasterKeySpec
- responseElements.keyMetadata.description
- responseElements.keyMetadata.enabled
- responseElements.keyMetadata.encryptionAlgorithms{}
- responseElements.keyMetadata.keyId
- responseElements.keyMetadata.keyManager
- responseElements.keyMetadata.keyState
- responseElements.keyMetadata.keyUsage
- responseElements.keyMetadata.origin
- signature
- source
- sourceIPAddress
- sourcetype
- splunk_server
- src
- src_ip
- start_time
- tag
- tag::eventtype
- timeendpos
- timestartpos
- user
- userAgent
- userIdentity.accessKeyId
- userIdentity.accountId
- userIdentity.arn
- userIdentity.principalId
- userIdentity.sessionContext.attributes.creationDate
- userIdentity.sessionContext.attributes.mfaAuthenticated
- userIdentity.sessionContext.sessionIssuer.accountId
- userIdentity.sessionContext.sessionIssuer.arn
- userIdentity.sessionContext.sessionIssuer.principalId
- userIdentity.sessionContext.sessionIssuer.type
- userIdentity.sessionContext.sessionIssuer.userName
- userIdentity.type
- userName
- user_access_key
- user_agent
- user_arn
- user_group_id
- user_id
- user_name
- user_type
- vendor
- vendor_account
- vendor_product
- vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "principalId": "AROAIJIESMXKGCJRCTPR6:pbareiss@splunk.local", "arn": "arn:aws:sts::111111111111:assumed-role/okta_adm_role/pbareiss@splunk.local", "accountId": "111111111111", "accessKeyId": "ASIAYTOGP2RLK74OPBDR", "sessionContext": {"sessionIssuer": {"type": "Role", "principalId": "AROAIJIESMXKGCJRCTPR6", "arn": "arn:aws:iam::111111111111:role/okta_adm_role", "accountId": "111111111111", "userName": "okta_adm_role"}, "webIdFederationData": {}, "attributes": {"mfaAuthenticated": "false", "creationDate": "2021-01-11T09:03:18Z"}}}, "eventTime": "2021-01-11T09:56:31Z", "eventSource": "kms.amazonaws.com", "eventName": "CreateKey", "awsRegion": "us-west-2", "sourceIPAddress": "95.90.199.65", "userAgent": "aws-internal/3 aws-sdk-java/1.11.893 Linux/4.9.230-0.1.ac.223.84.332.metal1.x86_64 OpenJDK_64-Bit_Server_VM/25.272-b10 java/1.8.0_272 vendor/Oracle_Corporation", "requestParameters": {"origin": "AWS_KMS", "policy": "{\n \"Id\": \"key-consolepolicy-3\",\n \"Version\": \"2012-10-17\",\n \"Statement\": [\n {\n \"Sid\": \"Enable IAM User Permissions\",\n \"Effect\": \"Allow\",\n \"Principal\": {\n \"AWS\": \"arn:aws:iam::111111111111:root\"\n },\n \"Action\": \"kms:*\",\n \"Resource\": \"*\"\n },\n {\n \"Sid\": \"Allow access for Key Administrators\",\n \"Effect\": \"Allow\",\n \"Principal\": {\n \"AWS\": \"arn:aws:iam::111111111111:user/patrick_cli\"\n },\n \"Action\": [\n \"kms:Create*\",\n \"kms:Describe*\",\n \"kms:Enable*\",\n \"kms:List*\",\n \"kms:Put*\",\n \"kms:Update*\",\n \"kms:Revoke*\",\n \"kms:Disable*\",\n \"kms:Get*\",\n \"kms:Delete*\",\n \"kms:TagResource\",\n \"kms:UntagResource\",\n \"kms:ScheduleKeyDeletion\",\n \"kms:CancelKeyDeletion\"\n ],\n \"Resource\": \"*\"\n },\n {\n \"Sid\": \"Allow use of the key\",\n \"Effect\": \"Allow\",\n \"Principal\": {\n \"AWS\": \"arn:aws:iam::111111111111:user/patrick_cli\"\n },\n \"Action\": [\n \"kms:Encrypt\",\n \"kms:Decrypt\",\n \"kms:ReEncrypt*\",\n \"kms:GenerateDataKey*\",\n \"kms:DescribeKey\"\n ],\n \"Resource\": \"*\"\n },\n {\n \"Sid\": \"Allow attachment of persistent resources\",\n \"Effect\": \"Allow\",\n \"Principal\": {\n \"AWS\": \"arn:aws:iam::111111111111:user/patrick_cli\"\n },\n \"Action\": [\n \"kms:CreateGrant\",\n \"kms:ListGrants\",\n \"kms:RevokeGrant\"\n ],\n \"Resource\": \"*\",\n \"Condition\": {\n \"Bool\": {\n \"kms:GrantIsForAWSResource\": \"true\"\n }\n }\n },\n {\n \"Sid\": \"Allow use of the key\",\n \"Effect\": \"Allow\",\n \"Principal\": {\n \"AWS\": \"*\"\n },\n \"Action\": [\n \"kms:Encrypt\"\n ],\n \"Resource\": \"*\"\n }\n ]\n}", "description": "", "customerMasterKeySpec": "SYMMETRIC_DEFAULT", "bypassPolicyLockoutSafetyCheck": false, "tags": [], "keyUsage": "ENCRYPT_DECRYPT"}, "responseElements": {"keyMetadata": {"aWSAccountId": "111111111111", "keyId": "f2a82583-a7d3-4c92-8787-fe2baab1cee1", "arn": "arn:aws:kms:us-west-2:111111111111:key/f2a82583-a7d3-4c92-8787-fe2baab1cee1", "creationDate": "Jan 11, 2021, 9:56:30 AM", "enabled": true, "description": "", "keyUsage": "ENCRYPT_DECRYPT", "keyState": "Enabled", "origin": "AWS_KMS", "keyManager": "CUSTOMER", "customerMasterKeySpec": "SYMMETRIC_DEFAULT", "encryptionAlgorithms": ["SYMMETRIC_DEFAULT"]}}, "requestID": "3356af25-a237-471f-ba5e-abb37d4a256f", "eventID": "f09518ac-5ae5-4214-80ee-4f23ccdedd4c", "readOnly": false, "resources": [{"accountId": "111111111111", "type": "AWS::KMS::Key", "ARN": "arn:aws:kms:us-west-2:111111111111:key/f2a82583-a7d3-4c92-8787-fe2baab1cee1"}], "eventType": "AwsApiCall", "managementEvent": true, "eventCategory": "Management", "recipientAccountId": "111111111111"}'
@@ -1,79 +0,0 @@
event_name: AWS CloudTrail CreateLoginProfile
fields:
- _time
- action
- app
- awsRegion
- aws_account_id
- change_type
- command
- date_hour
- date_mday
- date_minute
- date_month
- date_second
- date_wday
- date_year
- date_zone
- dest
- dvc
- errorCode
- eventCategory
- eventID
- eventName
- eventSource
- eventTime
- eventType
- eventVersion
- eventtype
- host
- index
- linecount
- managementEvent
- msg
- object_category
- product
- punct
- readOnly
- recipientAccountId
- region
- requestID
- requestParameters.passwordResetRequired
- requestParameters.userName
- responseElements.loginProfile.createDate
- responseElements.loginProfile.passwordResetRequired
- responseElements.loginProfile.userName
- signature
- source
- sourceIPAddress
- sourcetype
- splunk_server
- src
- src_ip
- start_time
- status
- tag
- tag::eventtype
- timeendpos
- timestartpos
- user
- userAgent
- userIdentity.accessKeyId
- userIdentity.accountId
- userIdentity.arn
- userIdentity.principalId
- userIdentity.type
- userIdentity.userName
- userName
- user_access_key
- user_agent
- user_arn
- user_group_id
- user_id
- user_name
- user_type
- vendor
- vendor_account
- vendor_product
- vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId": "AIDAYTOGP2RLEHRX5YWNV", "arn": "arn:aws:iam::111111111111:user/bhavin_cli", "accountId": "111111111111", "accessKeyId": "AKIAYTOGP2RLLAA6NJUM", "userName": "bhavin_cli"}, "eventTime": "2021-03-05T01:02:38Z", "eventSource": "iam.amazonaws.com", "eventName": "CreateLoginProfile", "awsRegion": "us-east-1", "sourceIPAddress": "73.15.72.101", "userAgent": "aws-cli/2.0.62 Python/3.9.2 Darwin/19.6.0 source/x86_64 command/iam.create-login-profile", "requestParameters": {"userName": "AtomicRedTeam", "passwordResetRequired": false}, "responseElements": {"loginProfile": {"userName": "AtomicRedTeam", "createDate": "Mar 5, 2021 1:02:38 AM", "passwordResetRequired": false}}, "requestID": "f1b90364-8aed-4559-96cf-f5f2009bb7cb", "eventID": "ffb76906-6dd1-4219-adfe-e26b92036a1e", "readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "eventCategory": "Management", "recipientAccountId": "111111111111"}'
@@ -1,95 +0,0 @@
event_name: AWS CloudTrail CreateNetworkAclEntry
fields:
- _time
- action
- app
- awsRegion
- aws_account_id
- change_type
- command
- date_hour
- date_mday
- date_minute
- date_month
- date_second
- date_wday
- date_year
- date_zone
- dest
- direction
- dvc
- errorCode
- eventCategory
- eventID
- eventName
- eventSource
- eventTime
- eventType
- eventVersion
- eventtype
- host
- index
- linecount
- managementEvent
- msg
- object
- object_category
- object_id
- product
- protocol
- protocol_code
- punct
- readOnly
- recipientAccountId
- region
- requestID
- requestParameters.aclProtocol
- requestParameters.cidrBlock
- requestParameters.egress
- requestParameters.networkAclId
- requestParameters.ruleAction
- requestParameters.ruleNumber
- responseElements._return
- responseElements.requestId
- rule_action
- signature
- source
- sourceIPAddress
- sourcetype
- splunk_server
- src
- src_ip
- src_ip_range
- start_time
- status
- tag
- tag::eventtype
- timeendpos
- timestartpos
- user
- userAgent
- userIdentity.accessKeyId
- userIdentity.accountId
- userIdentity.arn
- userIdentity.principalId
- userIdentity.sessionContext.attributes.creationDate
- userIdentity.sessionContext.attributes.mfaAuthenticated
- userIdentity.sessionContext.sessionIssuer.accountId
- userIdentity.sessionContext.sessionIssuer.arn
- userIdentity.sessionContext.sessionIssuer.principalId
- userIdentity.sessionContext.sessionIssuer.type
- userIdentity.sessionContext.sessionIssuer.userName
- userIdentity.type
- userName
- user_access_key
- user_agent
- user_arn
- user_group_id
- user_id
- user_name
- user_type
- vendor
- vendor_account
- vendor_product
- vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "principalId": "AROAIJIESMXKGCJRCTPR6:pbareiss@splunk.local", "arn": "arn:aws:sts::111111111111:assumed-role/okta_adm_role/pbareiss@splunk.local", "accountId": "111111111111", "accessKeyId": "ASIAYTOGP2RLF3F7BXZK", "sessionContext": {"sessionIssuer": {"type": "Role", "principalId": "AROAIJIESMXKGCJRCTPR6", "arn": "arn:aws:iam::111111111111:role/okta_adm_role", "accountId": "111111111111", "userName": "okta_adm_role"}, "webIdFederationData": {}, "attributes": {"mfaAuthenticated": "false", "creationDate": "2021-01-12T08:36:15Z"}}}, "eventTime": "2021-01-12T08:38:39Z", "eventSource": "ec2.amazonaws.com", "eventName": "CreateNetworkAclEntry", "awsRegion": "eu-central-1", "sourceIPAddress": "95.90.199.65", "userAgent": "console.ec2.amazonaws.com", "requestParameters": {"networkAclId": "acl-078ccebebcbabe175", "ruleNumber": 10, "egress": false, "ruleAction": "allow", "icmpTypeCode": {}, "portRange": {}, "aclProtocol": "-1", "cidrBlock": "0.0.0.0/0"}, "responseElements": {"requestId": "d29c9c32-3a72-48d3-b612-6ba795e9ec64", "_return": true}, "requestID": "d29c9c32-3a72-48d3-b612-6ba795e9ec64", "eventID": "6d1ce00e-4099-463c-8a4d-2af2fb2178ba", "readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "eventCategory": "Management", "recipientAccountId": "111111111111"}'
@@ -1,80 +0,0 @@
event_name: AWS CloudTrail CreatePolicyVersion
fields:
- _time
- action
- app
- awsRegion
- aws_account_id
- change_type
- command
- date_hour
- date_mday
- date_minute
- date_month
- date_second
- date_wday
- date_year
- date_zone
- dest
- dvc
- errorCode
- eventCategory
- eventID
- eventName
- eventSource
- eventTime
- eventType
- eventVersion
- eventtype
- host
- index
- linecount
- managementEvent
- msg
- object_category
- product
- punct
- readOnly
- recipientAccountId
- region
- requestID
- requestParameters.policyArn
- requestParameters.policyDocument
- requestParameters.setAsDefault
- responseElements.policyVersion.createDate
- responseElements.policyVersion.isDefaultVersion
- responseElements.policyVersion.versionId
- signature
- source
- sourceIPAddress
- sourcetype
- splunk_server
- src
- src_ip
- start_time
- status
- tag
- tag::eventtype
- timeendpos
- timestartpos
- user
- userAgent
- userIdentity.accessKeyId
- userIdentity.accountId
- userIdentity.arn
- userIdentity.principalId
- userIdentity.type
- userIdentity.userName
- userName
- user_access_key
- user_agent
- user_arn
- user_group_id
- user_id
- user_name
- user_type
- vendor
- vendor_account
- vendor_product
- vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId": "AIDAYTOGP2RLNMCDVJZAY", "arn": "arn:aws:iam::111111111111:user/rhino_escalate", "accountId": "111111111111", "accessKeyId": "AKIAYTOGP2RLHSQZPZFZ", "userName": "rhino_escalate"}, "eventTime": "2021-02-23T00:02:30Z", "eventSource": "iam.amazonaws.com", "eventName": "CreatePolicyVersion", "awsRegion": "us-east-1", "sourceIPAddress": "73.15.72.101", "userAgent": "aws-cli/2.0.62 Python/3.9.0 Darwin/19.6.0 source/x86_64 command/iam.create-policy-version", "requestParameters": {"policyArn": "arn:aws:iam::111111111111:policy/rhino_escalate", "policyDocument": "{\n \"Version\": \"2012-10-17\",\n \"Statement\": [\n {\n \"Sid\": \"AllowEverything\",\n \"Effect\": \"Allow\",\n \"Action\": \"iam:*\",\n \"Resource\": \"*\"\n }\n ]\n }", "setAsDefault": true}, "responseElements": {"policyVersion": {"versionId": "v2", "isDefaultVersion": true, "createDate": "Feb 23, 2021 12:02:30 AM"}}, "requestID": "fa42b4b2-f34a-4673-8f9f-b25cf1f5005a", "eventID": "33149175-90fd-4cff-a43b-408e4f848c1c", "readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "eventCategory": "Management", "recipientAccountId": "111111111111"}'
@@ -1,89 +0,0 @@
event_name: AWS CloudTrail CreateSnapshot
fields:
- _time
- app
- awsRegion
- aws_account_id
- change_type
- command
- date_hour
- date_mday
- date_minute
- date_month
- date_second
- date_wday
- date_year
- date_zone
- dest
- dvc
- errorCode
- eventCategory
- eventID
- eventName
- eventSource
- eventTime
- eventType
- eventVersion
- eventtype
- host
- index
- linecount
- managementEvent
- msg
- object_category
- product
- punct
- readOnly
- recipientAccountId
- region
- requestID
- requestParameters.tagSpecificationSet.items{}.resourceType
- requestParameters.tagSpecificationSet.items{}.tags{}.key
- requestParameters.tagSpecificationSet.items{}.tags{}.value
- requestParameters.volumeId
- responseElements.encrypted
- responseElements.ownerId
- responseElements.requestId
- responseElements.snapshotId
- responseElements.startTime
- responseElements.status
- responseElements.tagSet.items{}.key
- responseElements.tagSet.items{}.value
- responseElements.volumeId
- responseElements.volumeSize
- signature
- source
- sourceIPAddress
- sourcetype
- splunk_server
- src
- src_ip
- start_time
- tag
- tag::eventtype
- timeendpos
- timestartpos
- tlsDetails.cipherSuite
- tlsDetails.clientProvidedHostHeader
- tlsDetails.tlsVersion
- user
- userAgent
- userIdentity.accessKeyId
- userIdentity.accountId
- userIdentity.arn
- userIdentity.principalId
- userIdentity.type
- userIdentity.userName
- userName
- user_access_key
- user_agent
- user_arn
- user_group_id
- user_id
- user_name
- user_type
- vendor
- vendor_account
- vendor_product
- vendor_region
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId": "AIDAYTOGP2RLCNEAQXWZV", "arn": "arn:aws:iam::111111111111:user/bhavin_console", "accountId": "111111111111", "accessKeyId": "AKIAYTOGP2RLF5EAXXXX", "userName": "bhavin_console"}, "eventTime": "2023-03-20T22:31:18Z", "eventSource": "ec2.amazonaws.com", "eventName": "CreateSnapshot", "awsRegion": "us-west-2", "sourceIPAddress": "72.135.1.1", "userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.157 (go1.19.3; darwin; amd64) stratus-red-team_46665bb8-dc15-4aba-a5ad-a362772b3f0d HashiCorp-terraform-exec/0.17.3", "requestParameters": {"volumeId": "vol-0363e53e12f67c9b7", "tagSpecificationSet": {"items": [{"resourceType": "snapshot", "tags": [{"key": "StratusRedTeam", "value": "true"}]}]}}, "responseElements": {"requestId": "fefed928-d461-45f0-802f-a99d94c833a8", "snapshotId": "snap-02effb3bb62786b18", "volumeId": "vol-0363e53e12f67c9b7", "status": "pending", "startTime": 1679351478226, "ownerId": "111111111111", "volumeSize": "1", "encrypted": false, "tagSet": {"items": [{"key": "StratusRedTeam", "value": "true"}]}}, "requestID": "fefed928-d461-45f0-802f-a99d94c833a8", "eventID": "2d52d141-d1e6-4d1f-a380-1461c1bf9f83", "readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId": "111111111111", "eventCategory": "Management", "tlsDetails": {"tlsVersion": "TLSv1.2", "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256", "clientProvidedHostHeader": "ec2.us-west-2.amazonaws.com"}}'

Some files were not shown because too many files have changed in this diff Show More