mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
Merge branch 'develop' into nterl0k-rmm_must_die_update_1
This commit is contained in:
@@ -23,7 +23,7 @@ jobs:
|
||||
|
||||
- name: Install Python Dependencies and ContentCTL and Atomic Red Team
|
||||
run: |
|
||||
pip install contentctl==4.1.5
|
||||
pip install contentctl==4.2.0
|
||||
git clone --depth=1 --single-branch --branch=master https://github.com/redcanaryco/atomic-red-team.git
|
||||
|
||||
- name: Running build with enrichments
|
||||
|
||||
@@ -24,7 +24,7 @@ jobs:
|
||||
- name: Install Python Dependencies and ContentCTL
|
||||
run: |
|
||||
python -m pip install --upgrade pip
|
||||
pip install contentctl==4.1.5
|
||||
pip install contentctl==4.2.0
|
||||
|
||||
# Running contentctl test with a few arguments, before running the command make sure you checkout into the current branch of the pull request. This step only performs unit testing on all the changes against the target-branch. In most cases this target branch will be develop
|
||||
# Make sure we check out the PR, even if it actually lives in a fork
|
||||
|
||||
@@ -1,38 +0,0 @@
|
||||
name: PingID
|
||||
id: 17890675-61c1-40bd-a88e-6a8e9e246b43
|
||||
author: Patrick Bareiss, Splunk
|
||||
source: XmlWinEventLog:Security
|
||||
sourcetype: XmlWinEventLog
|
||||
supported_TA: {}
|
||||
event_names: []
|
||||
fields:
|
||||
- _time
|
||||
- actors{}.name
|
||||
- actors{}.type
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- extracted_source
|
||||
- host
|
||||
- id
|
||||
- index
|
||||
- linecount
|
||||
- punct
|
||||
- recorded
|
||||
- resources{}.ipaddress
|
||||
- resources{}.websession
|
||||
- result.message
|
||||
- result.status
|
||||
- source
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
example_log:
|
||||
'{"source":"PINGID","id":"b2eb1fef-651b-11ee-b38b-0ac7a554ed19","recorded":"2023-10-05T14:10:53.538Z","actors":[{"type":"user","name":"victim_user"}],"resources":[{"ipaddress":"174.235.80.142","websession":"webs_ijkF-T_bAC_G3w2TfvdpAEQeC545KFlqVFOsolCXdjo"}],"result":{"status":"SUCCESS","message":"Device
|
||||
Paired SMS \"Mobile 1\""}}'
|
||||
@@ -1,34 +0,0 @@
|
||||
name: Splunk
|
||||
id: d8a2c791-460b-4756-a8e5-ecade77b21e3
|
||||
author: Patrick Bareiss, Splunk
|
||||
source: splunkd_ui_access.log
|
||||
sourcetype: splunkd_ui_access
|
||||
supported_TA: {}
|
||||
event_names: []
|
||||
fields:
|
||||
- _time
|
||||
- action
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- dest
|
||||
- host
|
||||
- index
|
||||
- info
|
||||
- linecount
|
||||
- punct
|
||||
- source
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- timeendpos
|
||||
- timestamp
|
||||
- timestartpos
|
||||
- user
|
||||
example_log:
|
||||
"Audit:[timestamp=01-25-2023 22:08:54.818, user=admin, action=search,
|
||||
info=granted REST: /search/jobs/rt_1674684525.24/events]"
|
||||
@@ -0,0 +1,98 @@
|
||||
name: AWS Cloudfront
|
||||
id: 780086dc-2384-45b6-ade7-56cb00105464
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for AWS Cloudfront
|
||||
source: aws
|
||||
sourcetype: aws:cloudfront:accesslogs
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Amazon Web Services (AWS)
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.4.1
|
||||
fields:
|
||||
- _time
|
||||
- action
|
||||
- app
|
||||
- bytes
|
||||
- bytes_in
|
||||
- bytes_out
|
||||
- c_ip
|
||||
- c_port
|
||||
- cached
|
||||
- category
|
||||
- client_ip
|
||||
- cs_bytes
|
||||
- cs_cookie
|
||||
- cs_host
|
||||
- cs_method
|
||||
- cs_protocol
|
||||
- cs_protocol_version
|
||||
- cs_referer
|
||||
- cs_uri_query
|
||||
- cs_uri_stem
|
||||
- cs_user_agent
|
||||
- date
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- dest
|
||||
- duration
|
||||
- edge_location_name
|
||||
- eventtype
|
||||
- fle_encrypted_fields
|
||||
- fle_status
|
||||
- host
|
||||
- http_content_type
|
||||
- http_method
|
||||
- http_user_agent
|
||||
- http_user_agent_length
|
||||
- index
|
||||
- linecount
|
||||
- punct
|
||||
- response_time
|
||||
- sc_bytes
|
||||
- sc_content_len
|
||||
- sc_content_type
|
||||
- sc_range_end
|
||||
- sc_range_start
|
||||
- sc_status
|
||||
- source
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- src
|
||||
- src_ip
|
||||
- src_port
|
||||
- ssl_cipher
|
||||
- ssl_protocol
|
||||
- status
|
||||
- tag
|
||||
- tag::eventtype
|
||||
- time
|
||||
- time_taken
|
||||
- time_to_first_byte
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
- uri_path
|
||||
- url
|
||||
- url_domain
|
||||
- url_length
|
||||
- vendor_product
|
||||
- x_edge_detail_result_type
|
||||
- x_edge_location
|
||||
- x_edge_request_id
|
||||
- x_edge_response_result_type
|
||||
- x_edge_result_type
|
||||
- x_forwarded_for
|
||||
- x_host_header
|
||||
example_log: "2023-11-07\t16:58:21\tIAD55-P5\t921\t44.192.78.55\tGET\td3u5aue66f5ui4.cloudfront.net\t\
|
||||
/plugins/servlet/com.jsos.shell/ShellServlet\t200\t-\tSlackbot-LinkExpanding%201.0%20(+https://api.slack.com/robots)\t\
|
||||
-\t-\tLambdaGeneratedResponse\tsGwvFCkFU4qlMxatCoJRgW87P7Ee8bKQor3U6lRt6I6jaFvLC7vcPA==\t\
|
||||
confluence.catjamfest.com\thttps\t232\t0.276\t-\tTLSv1.3\tTLS_AES_128_GCM_SHA256\t\
|
||||
LambdaGeneratedResponse\tHTTP/1.1\t-\t-\t57232\t0.276\tLambdaGeneratedResponse\t\
|
||||
text/html\t527\t-\t-"
|
||||
@@ -0,0 +1,14 @@
|
||||
name: AWS CloudTrail
|
||||
id: e8ace6db-1dbd-4c72-a1fb-334684619a38
|
||||
version: 1
|
||||
date: '2024-07-24'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for AWS CloudTrail
|
||||
source: aws_cloudtrail
|
||||
sourcetype: aws:cloudtrail
|
||||
separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Amazon Web Services (AWS)
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.4.1
|
||||
|
||||
@@ -0,0 +1,126 @@
|
||||
name: AWS CloudTrail AssumeRoleWithSAML
|
||||
id: 1e28f2a6-2db9-405f-b298-18734a293f77
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for AWS CloudTrail AssumeRoleWithSAML
|
||||
source: aws_cloudtrail
|
||||
sourcetype: aws:cloudtrail
|
||||
separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Amazon Web Services (AWS)
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.4.1
|
||||
fields:
|
||||
- _time
|
||||
- action
|
||||
- app
|
||||
- awsRegion
|
||||
- change_type
|
||||
- command
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- dest
|
||||
- dvc
|
||||
- errorCode
|
||||
- eventCategory
|
||||
- eventID
|
||||
- eventName
|
||||
- eventSource
|
||||
- eventTime
|
||||
- eventType
|
||||
- eventVersion
|
||||
- eventtype
|
||||
- host
|
||||
- index
|
||||
- linecount
|
||||
- managementEvent
|
||||
- msg
|
||||
- object_category
|
||||
- product
|
||||
- punct
|
||||
- readOnly
|
||||
- recipientAccountId
|
||||
- region
|
||||
- requestID
|
||||
- requestParameters.durationSeconds
|
||||
- requestParameters.principalArn
|
||||
- requestParameters.roleArn
|
||||
- requestParameters.roleSessionName
|
||||
- requestParameters.sAMLAssertionID
|
||||
- resources{}.ARN
|
||||
- resources{}.accountId
|
||||
- resources{}.type
|
||||
- responseElements.assumedRoleUser.arn
|
||||
- responseElements.assumedRoleUser.assumedRoleId
|
||||
- responseElements.audience
|
||||
- responseElements.credentials.accessKeyId
|
||||
- responseElements.credentials.expiration
|
||||
- responseElements.credentials.sessionToken
|
||||
- responseElements.issuer
|
||||
- responseElements.nameQualifier
|
||||
- responseElements.subject
|
||||
- responseElements.subjectType
|
||||
- signature
|
||||
- source
|
||||
- sourceIPAddress
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- src
|
||||
- src_ip
|
||||
- src_user
|
||||
- src_user_id
|
||||
- src_user_type
|
||||
- start_time
|
||||
- status
|
||||
- tag
|
||||
- tag::action
|
||||
- tag::eventtype
|
||||
- temp_access_key
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
- user
|
||||
- userAgent
|
||||
- userIdentity.identityProvider
|
||||
- userIdentity.principalId
|
||||
- userIdentity.type
|
||||
- userIdentity.userName
|
||||
- user_agent
|
||||
- user_arn
|
||||
- user_id
|
||||
- user_name
|
||||
- user_role
|
||||
- user_type
|
||||
- vendor
|
||||
- vendor_account
|
||||
- vendor_product
|
||||
- vendor_region
|
||||
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "SAMLUser", "principalId":
|
||||
"ZRu9MRAjiG9tvi1QBNfdI664G5A=:rodsoto@rodsoto.onmicrosoft.com", "userName": "rodsoto@rodsoto.onmicrosoft.com",
|
||||
"identityProvider": "ZRu9MRAjiG9tvi1QBNfdI664G5A="}, "eventTime": "2021-01-22T03:44:16Z",
|
||||
"eventSource": "sts.amazonaws.com", "eventName": "AssumeRoleWithSAML", "awsRegion":
|
||||
"us-east-1", "sourceIPAddress": "72.21.217.152", "userAgent": "AWS Signin, aws-internal/3
|
||||
aws-sdk-java/1.11.898 Linux/4.9.230-0.1.ac.223.84.332.metal1.x86_64 OpenJDK_64-Bit_Server_VM/25.275-b01
|
||||
java/1.8.0_275 kotlin/1.3.72 vendor/Oracle_Corporation", "requestParameters": {"sAMLAssertionID":
|
||||
"_d33ba0ad-0c88-4b83-80a6-27c08027d000", "roleSessionName": "rodsoto@rodsoto.onmicrosoft.com",
|
||||
"durationSeconds": 3600, "roleArn": "arn:aws:iam::111111111111:role/rodonmicrotestrole",
|
||||
"principalArn": "arn:aws:iam::111111111111:saml-provider/rodsotoonmicrosoft"}, "responseElements":
|
||||
{"subjectType": "urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress", "issuer":
|
||||
"https://sts.windows.net/0e8108b1-18e9-41a4-961b-dfcddf92ef08/", "credentials":
|
||||
{"accessKeyId": "ASIAYTOGP2RLKJXOV7VR", "expiration": "Jan 22, 2021 3:59:16 AM",
|
||||
"sessionToken": "IQoJb3JpZ2luX2VjENz//////////wEaCXVzLWVhc3QtMSJGMEQCIHl/WQdLq53ULYl10fPtpeV3H7da9mOXGuIStvhdDA6kAiAdO/7rocOXAtyDV+0MJhSj/piqlqEI/BcAKm8zqBhOgiqgAwi1//////////8BEAIaDDU5MTUxMTE0NzYwNiIMAFP8GfyI/x1fKCHYKvQCznxxgKnEdcuvrr/fBLmHxEDjQ9vQxjasA8gZF8GawZ5SFH9ViKqoZh93bYkOwKqZD8cdqJIo9SYL17RGhVqxzvsjU4+QsRXTN5eGgh+LyF9EZqeCl6oCkaTJqNrXHuenzTi0yiL510LKsSckrAm8+SuwI/jQu3oE1BEcJQieAc4RjYx3II+1cUvyfRlFvR2NDfZhdWcQvAivV06KJg9c2zfCF0Agzn/YZSNvsRL5UhnKhJ2wktSvT8lR0mS3n9xR1j3iYNxVDHab180cnfkP3G6tAmxj5U29diNQrusJxKWWhr/Q9wHRdDj5dO2QUZzSymKKU/UiRJ8nyYPINaJ8XWVAPiT4QgzpMxotkvSkDLEG/brB9yEr2p7W8Y3xMGZ37qSGkuU4z9x40RU9G1XPhv27NO9aaGs/VXYTMCzWRNxnsLfNkk/DihrcaR0SclRcvs+zmfe1ZUoGnfjNYm+AIyJi4D7OrXF5/Mt46Z2y76DnULlAMJCUqYAGOpsBw4fyafV8OizX7Lebh2JRXFZsWBY1GTpyGvO5otrw++4axud44vYVi5iU5rbJxtTBm4vtJartxgXoPJFnQuat9gLrIlXhjmg+m50a5xs1Ut2UWEsWY2Duu4jA9ap7P7dYv9kIK9P2uyhsjKQhCjTpfe4I/llcupbDotYBJuvlB5n85a5kgiSriFk5zetoXQIweuYEWQZsD/AN+LE="},
|
||||
"nameQualifier": "ZRu9MRAjiG9tvi1QBNfdI664G5A=", "assumedRoleUser": {"assumedRoleId":
|
||||
"AROAYTOGP2RLKFUVAQAIJ:rodsoto@rodsoto.onmicrosoft.com", "arn": "arn:aws:sts::111111111111:assumed-role/rodonmicrotestrole/rodsoto@rodsoto.onmicrosoft.com"},
|
||||
"subject": "rodsoto@rodsoto.onmicrosoft.com", "audience": "https://signin.aws.amazon.com/saml"},
|
||||
"requestID": "e19c7a7f-cd96-4642-9ee6-2360a7b01b12", "eventID": "b25b825d-9c9b-49d3-9ecd-290dbe8f2c29",
|
||||
"readOnly": true, "resources": [{"accountId": "111111111111", "type": "AWS::IAM::Role",
|
||||
"ARN": "arn:aws:iam::111111111111:role/rodonmicrotestrole"}, {"accountId": "111111111111",
|
||||
"type": "AWS::IAM::SAMLProvider", "ARN": "arn:aws:iam::111111111111:saml-provider/rodsotoonmicrosoft"}],
|
||||
"eventType": "AwsApiCall", "managementEvent": true, "eventCategory": "Management",
|
||||
"recipientAccountId": "111111111111"}'
|
||||
@@ -0,0 +1,102 @@
|
||||
name: AWS CloudTrail ConsoleLogin
|
||||
id: b68b3f26-bd21-4fa8-b593-616fe75ac0ae
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for AWS CloudTrail ConsoleLogin
|
||||
source: aws_cloudtrail
|
||||
sourcetype: aws:cloudtrail
|
||||
separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Amazon Web Services (AWS)
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.4.1
|
||||
fields:
|
||||
- _time
|
||||
- action
|
||||
- additionalEventData.LoginTo
|
||||
- additionalEventData.MFAUsed
|
||||
- additionalEventData.MobileVersion
|
||||
- app
|
||||
- authentication_method
|
||||
- awsRegion
|
||||
- aws_account_id
|
||||
- command
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- desc
|
||||
- dest
|
||||
- dvc
|
||||
- errorCode
|
||||
- errorMessage
|
||||
- eventCategory
|
||||
- eventID
|
||||
- eventName
|
||||
- eventSource
|
||||
- eventTime
|
||||
- eventType
|
||||
- eventVersion
|
||||
- eventtype
|
||||
- host
|
||||
- index
|
||||
- linecount
|
||||
- managementEvent
|
||||
- msg
|
||||
- object_category
|
||||
- product
|
||||
- punct
|
||||
- readOnly
|
||||
- reason
|
||||
- recipientAccountId
|
||||
- region
|
||||
- requestParameters
|
||||
- responseElements.ConsoleLogin
|
||||
- result
|
||||
- signature
|
||||
- source
|
||||
- sourceIPAddress
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- src
|
||||
- src_ip
|
||||
- start_time
|
||||
- status
|
||||
- tag
|
||||
- tag::action
|
||||
- tag::eventtype
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
- tlsDetails.cipherSuite
|
||||
- tlsDetails.clientProvidedHostHeader
|
||||
- tlsDetails.tlsVersion
|
||||
- userAgent
|
||||
- userIdentity.accessKeyId
|
||||
- userIdentity.accountId
|
||||
- userIdentity.type
|
||||
- userIdentity.userName
|
||||
- user_access_key
|
||||
- user_agent
|
||||
- user_group_id
|
||||
- user_name
|
||||
- user_type
|
||||
- vendor
|
||||
- vendor_account
|
||||
- vendor_product
|
||||
- vendor_region
|
||||
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "accountId":
|
||||
"140429656527", "accessKeyId": "", "userName": "HIDDEN_DUE_TO_SECURITY_REASONS"},
|
||||
"eventTime": "2022-10-19T20:33:38Z", "eventSource": "signin.amazonaws.com", "eventName":
|
||||
"ConsoleLogin", "awsRegion": "us-east-1", "sourceIPAddress": "142.254.89.27", "userAgent":
|
||||
"Go-http-client/1.1", "errorMessage": "No username found in supplied account", "requestParameters":
|
||||
null, "responseElements": {"ConsoleLogin": "Failure"}, "additionalEventData": {"LoginTo":
|
||||
"https://console.aws.amazon.com", "MobileVersion": "No", "MFAUsed": "No"}, "eventID":
|
||||
"9fcfb8c3-3fca-48db-85d2-7b107f9d95d0", "readOnly": false, "eventType": "AwsConsoleSignIn",
|
||||
"managementEvent": true, "recipientAccountId": "140429656527", "eventCategory":
|
||||
"Management", "tlsDetails": {"tlsVersion": "TLSv1.2", "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
|
||||
"clientProvidedHostHeader": "signin.aws.amazon.com"}}'
|
||||
@@ -0,0 +1,119 @@
|
||||
name: AWS CloudTrail CopyObject
|
||||
id: 965083f4-64a8-403f-99cc-252e1a6bd3b6
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for AWS CloudTrail CopyObject
|
||||
source: aws_cloudtrail
|
||||
sourcetype: aws:cloudtrail
|
||||
separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Amazon Web Services (AWS)
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.4.1
|
||||
fields:
|
||||
- _time
|
||||
- additionalEventData.AuthenticationMethod
|
||||
- additionalEventData.CipherSuite
|
||||
- additionalEventData.SSEApplied
|
||||
- additionalEventData.SignatureVersion
|
||||
- additionalEventData.bytesTransferredIn
|
||||
- additionalEventData.bytesTransferredOut
|
||||
- additionalEventData.x-amz-id-2
|
||||
- app
|
||||
- awsRegion
|
||||
- aws_account_id
|
||||
- command
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- dest
|
||||
- dvc
|
||||
- errorCode
|
||||
- eventCategory
|
||||
- eventID
|
||||
- eventName
|
||||
- eventSource
|
||||
- eventTime
|
||||
- eventType
|
||||
- eventVersion
|
||||
- host
|
||||
- index
|
||||
- linecount
|
||||
- managementEvent
|
||||
- msg
|
||||
- object_category
|
||||
- product
|
||||
- punct
|
||||
- readOnly
|
||||
- recipientAccountId
|
||||
- region
|
||||
- requestID
|
||||
- requestParameters.Host
|
||||
- requestParameters.bucketName
|
||||
- requestParameters.key
|
||||
- requestParameters.x-amz-copy-source
|
||||
- requestParameters.x-amz-server-side-encryption
|
||||
- requestParameters.x-amz-server-side-encryption-aws-kms-key-id
|
||||
- resources{}.ARN
|
||||
- resources{}.accountId
|
||||
- resources{}.type
|
||||
- responseElements.x-amz-server-side-encryption
|
||||
- responseElements.x-amz-server-side-encryption-aws-kms-key-id
|
||||
- signature
|
||||
- source
|
||||
- sourceIPAddress
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- src
|
||||
- src_ip
|
||||
- start_time
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
- user
|
||||
- userAgent
|
||||
- userIdentity.accessKeyId
|
||||
- userIdentity.accountId
|
||||
- userIdentity.arn
|
||||
- userIdentity.principalId
|
||||
- userIdentity.type
|
||||
- userIdentity.userName
|
||||
- userName
|
||||
- user_access_key
|
||||
- user_agent
|
||||
- user_arn
|
||||
- user_group_id
|
||||
- user_id
|
||||
- user_name
|
||||
- user_type
|
||||
- vendor
|
||||
- vendor_account
|
||||
- vendor_product
|
||||
- vendor_region
|
||||
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId":
|
||||
"AIDAYTOGP2RLNALZHZ6KX", "arn": "arn:aws:iam::111111111111:user/patrick_cli", "accountId":
|
||||
"111111111111", "accessKeyId": "AKIAYTOGP2RLJ2OYSF6E", "userName": "patrick_cli"},
|
||||
"eventTime": "2021-01-11T12:40:47Z", "eventSource": "s3.amazonaws.com", "eventName":
|
||||
"CopyObject", "awsRegion": "us-west-2", "sourceIPAddress": "95.90.199.65", "userAgent":
|
||||
"[aws-cli/2.0.45 Python/3.7.4 Darwin/20.2.0 exe/x86_64 command/s3.cp]", "requestParameters":
|
||||
{"bucketName": "patricktestbucketencrypt", "x-amz-server-side-encryption-aws-kms-key-id":
|
||||
"arn:aws:kms:us-west-2:111111111111:key/f2a82583-a7d3-4c92-8787-fe2baab1cee1", "Host":
|
||||
"patricktestbucketencrypt.s3.us-west-2.amazonaws.com", "x-amz-server-side-encryption":
|
||||
"aws:kms", "x-amz-copy-source": "patricktestbucketencrypt/kms_aws_events.json",
|
||||
"key": "kms_aws_events_encrypted.json"}, "responseElements": {"x-amz-server-side-encryption":
|
||||
"aws:kms", "x-amz-server-side-encryption-aws-kms-key-id": "arn:aws:kms:us-west-2:111111111111:key/f2a82583-a7d3-4c92-8787-fe2baab1cee1"},
|
||||
"additionalEventData": {"SignatureVersion": "SigV4", "CipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
|
||||
"bytesTransferredIn": 0.0, "SSEApplied": "SSE_KMS", "AuthenticationMethod": "AuthHeader",
|
||||
"x-amz-id-2": "fqzX1iZV6ImDtkFxbGvziOE6fUwryRa+PhnLckfVAkLNHdbCAHNq4l/yckUd1a2HNJPL6NAS01U=",
|
||||
"bytesTransferredOut": 234.0}, "requestID": "6A7359F7A9414B02", "eventID": "b20d43de-175d-4443-acd7-f5f3e587ae00",
|
||||
"readOnly": false, "resources": [{"type": "AWS::S3::Object", "ARN": "arn:aws:s3:::patricktestbucketencrypt/kms_aws_events_encrypted.json"},
|
||||
{"accountId": "111111111111", "type": "AWS::S3::Bucket", "ARN": "arn:aws:s3:::patricktestbucketencrypt"},
|
||||
{"accountId": "111111111111", "type": "AWS::S3::Bucket", "ARN": "arn:aws:s3:::patricktestbucketencrypt"},
|
||||
{"type": "AWS::S3::Object", "ARN": "arn:aws:s3:::patricktestbucketencrypt/kms_aws_events.json"}],
|
||||
"eventType": "AwsApiCall", "managementEvent": false, "recipientAccountId": "111111111111",
|
||||
"eventCategory": "Data"}'
|
||||
@@ -0,0 +1,103 @@
|
||||
name: AWS CloudTrail CreateAccessKey
|
||||
id: 0460f7da-3254-4d90-b8c0-2ca657d0cea0
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for AWS CloudTrail CreateAccessKey
|
||||
source: aws_cloudtrail
|
||||
sourcetype: aws:cloudtrail
|
||||
separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Amazon Web Services (AWS)
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.4.1
|
||||
fields:
|
||||
- _time
|
||||
- action
|
||||
- app
|
||||
- awsRegion
|
||||
- aws_account_id
|
||||
- change_type
|
||||
- command
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- dest
|
||||
- dvc
|
||||
- errorCode
|
||||
- eventCategory
|
||||
- eventID
|
||||
- eventName
|
||||
- eventSource
|
||||
- eventTime
|
||||
- eventType
|
||||
- eventVersion
|
||||
- eventtype
|
||||
- host
|
||||
- index
|
||||
- linecount
|
||||
- managementEvent
|
||||
- msg
|
||||
- object_category
|
||||
- product
|
||||
- punct
|
||||
- readOnly
|
||||
- recipientAccountId
|
||||
- region
|
||||
- requestID
|
||||
- requestParameters.userName
|
||||
- responseElements.accessKey.accessKeyId
|
||||
- responseElements.accessKey.createDate
|
||||
- responseElements.accessKey.status
|
||||
- responseElements.accessKey.userName
|
||||
- signature
|
||||
- source
|
||||
- sourceIPAddress
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- src
|
||||
- src_ip
|
||||
- src_user_name
|
||||
- start_time
|
||||
- status
|
||||
- tag
|
||||
- tag::eventtype
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
- user
|
||||
- userAgent
|
||||
- userIdentity.accessKeyId
|
||||
- userIdentity.accountId
|
||||
- userIdentity.arn
|
||||
- userIdentity.principalId
|
||||
- userIdentity.type
|
||||
- userIdentity.userName
|
||||
- userName
|
||||
- user_access_key
|
||||
- user_agent
|
||||
- user_arn
|
||||
- user_group_id
|
||||
- user_id
|
||||
- user_name
|
||||
- user_type
|
||||
- vendor
|
||||
- vendor_account
|
||||
- vendor_product
|
||||
- vendor_region
|
||||
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId":
|
||||
"AIDAYTOGP2RLEHRX5YWNV", "arn": "arn:aws:iam::121521347698:user/bhavin_cli", "accountId":
|
||||
"121521347698", "accessKeyId": "AKIAYTOGP2RLLAA6NJUM", "userName": "bhavin_cli"},
|
||||
"eventTime": "2021-03-02T21:18:24Z", "eventSource": "iam.amazonaws.com", "eventName":
|
||||
"CreateAccessKey", "awsRegion": "us-east-1", "sourceIPAddress": "12.25.72.12", "userAgent":
|
||||
"aws-cli/2.0.62 Python/3.9.0 Darwin/19.6.0 source/x86_64 command/iam.create-access-key",
|
||||
"requestParameters": {"userName": "AtomicRedTeam"}, "responseElements": {"accessKey":
|
||||
{"userName": "AtomicRedTeam", "accessKeyId": "AKIAYTOGP2RLOQ4ULYGT", "status": "Active",
|
||||
"createDate": "Mar 2, 2021 9:18:24 PM"}}, "requestID": "12c8773d-6c78-46bf-a8e4-f841adc8f70d",
|
||||
"eventID": "5772e8d5-cccc-470d-81ef-acacfe85a804", "readOnly": false, "eventType":
|
||||
"AwsApiCall", "managementEvent": true, "eventCategory": "Management", "recipientAccountId":
|
||||
"121521347698"}'
|
||||
@@ -0,0 +1,150 @@
|
||||
name: AWS CloudTrail CreateKey
|
||||
id: fcfc1593-b6b5-4a0f-91c5-3c395116a8b9
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for AWS CloudTrail CreateKey
|
||||
source: aws_cloudtrail
|
||||
sourcetype: aws:cloudtrail
|
||||
separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Amazon Web Services (AWS)
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.4.1
|
||||
fields:
|
||||
- _time
|
||||
- app
|
||||
- awsRegion
|
||||
- aws_account_id
|
||||
- command
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- dest
|
||||
- dvc
|
||||
- errorCode
|
||||
- eventCategory
|
||||
- eventID
|
||||
- eventName
|
||||
- eventSource
|
||||
- eventTime
|
||||
- eventType
|
||||
- eventVersion
|
||||
- eventtype
|
||||
- host
|
||||
- index
|
||||
- linecount
|
||||
- managementEvent
|
||||
- msg
|
||||
- object_category
|
||||
- product
|
||||
- punct
|
||||
- readOnly
|
||||
- recipientAccountId
|
||||
- region
|
||||
- requestID
|
||||
- requestParameters.bypassPolicyLockoutSafetyCheck
|
||||
- requestParameters.customerMasterKeySpec
|
||||
- requestParameters.description
|
||||
- requestParameters.keyUsage
|
||||
- requestParameters.origin
|
||||
- requestParameters.policy
|
||||
- resources{}.ARN
|
||||
- resources{}.accountId
|
||||
- resources{}.type
|
||||
- responseElements.keyMetadata.aWSAccountId
|
||||
- responseElements.keyMetadata.arn
|
||||
- responseElements.keyMetadata.creationDate
|
||||
- responseElements.keyMetadata.customerMasterKeySpec
|
||||
- responseElements.keyMetadata.description
|
||||
- responseElements.keyMetadata.enabled
|
||||
- responseElements.keyMetadata.encryptionAlgorithms{}
|
||||
- responseElements.keyMetadata.keyId
|
||||
- responseElements.keyMetadata.keyManager
|
||||
- responseElements.keyMetadata.keyState
|
||||
- responseElements.keyMetadata.keyUsage
|
||||
- responseElements.keyMetadata.origin
|
||||
- signature
|
||||
- source
|
||||
- sourceIPAddress
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- src
|
||||
- src_ip
|
||||
- start_time
|
||||
- tag
|
||||
- tag::eventtype
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
- user
|
||||
- userAgent
|
||||
- userIdentity.accessKeyId
|
||||
- userIdentity.accountId
|
||||
- userIdentity.arn
|
||||
- userIdentity.principalId
|
||||
- userIdentity.sessionContext.attributes.creationDate
|
||||
- userIdentity.sessionContext.attributes.mfaAuthenticated
|
||||
- userIdentity.sessionContext.sessionIssuer.accountId
|
||||
- userIdentity.sessionContext.sessionIssuer.arn
|
||||
- userIdentity.sessionContext.sessionIssuer.principalId
|
||||
- userIdentity.sessionContext.sessionIssuer.type
|
||||
- userIdentity.sessionContext.sessionIssuer.userName
|
||||
- userIdentity.type
|
||||
- userName
|
||||
- user_access_key
|
||||
- user_agent
|
||||
- user_arn
|
||||
- user_group_id
|
||||
- user_id
|
||||
- user_name
|
||||
- user_type
|
||||
- vendor
|
||||
- vendor_account
|
||||
- vendor_product
|
||||
- vendor_region
|
||||
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "principalId":
|
||||
"AROAIJIESMXKGCJRCTPR6:pbareiss@splunk.local", "arn": "arn:aws:sts::111111111111:assumed-role/okta_adm_role/pbareiss@splunk.local",
|
||||
"accountId": "111111111111", "accessKeyId": "ASIAYTOGP2RLK74OPBDR", "sessionContext":
|
||||
{"sessionIssuer": {"type": "Role", "principalId": "AROAIJIESMXKGCJRCTPR6", "arn":
|
||||
"arn:aws:iam::111111111111:role/okta_adm_role", "accountId": "111111111111", "userName":
|
||||
"okta_adm_role"}, "webIdFederationData": {}, "attributes": {"mfaAuthenticated":
|
||||
"false", "creationDate": "2021-01-11T09:03:18Z"}}}, "eventTime": "2021-01-11T09:56:31Z",
|
||||
"eventSource": "kms.amazonaws.com", "eventName": "CreateKey", "awsRegion": "us-west-2",
|
||||
"sourceIPAddress": "95.90.199.65", "userAgent": "aws-internal/3 aws-sdk-java/1.11.893
|
||||
Linux/4.9.230-0.1.ac.223.84.332.metal1.x86_64 OpenJDK_64-Bit_Server_VM/25.272-b10
|
||||
java/1.8.0_272 vendor/Oracle_Corporation", "requestParameters": {"origin": "AWS_KMS",
|
||||
"policy": "{\n \"Id\": \"key-consolepolicy-3\",\n \"Version\": \"2012-10-17\",\n \"Statement\":
|
||||
[\n {\n \"Sid\": \"Enable IAM User Permissions\",\n \"Effect\":
|
||||
\"Allow\",\n \"Principal\": {\n \"AWS\": \"arn:aws:iam::111111111111:root\"\n },\n \"Action\":
|
||||
\"kms:*\",\n \"Resource\": \"*\"\n },\n {\n \"Sid\":
|
||||
\"Allow access for Key Administrators\",\n \"Effect\": \"Allow\",\n \"Principal\":
|
||||
{\n \"AWS\": \"arn:aws:iam::111111111111:user/patrick_cli\"\n },\n \"Action\":
|
||||
[\n \"kms:Create*\",\n \"kms:Describe*\",\n \"kms:Enable*\",\n \"kms:List*\",\n \"kms:Put*\",\n \"kms:Update*\",\n \"kms:Revoke*\",\n \"kms:Disable*\",\n \"kms:Get*\",\n \"kms:Delete*\",\n \"kms:TagResource\",\n \"kms:UntagResource\",\n \"kms:ScheduleKeyDeletion\",\n \"kms:CancelKeyDeletion\"\n ],\n \"Resource\":
|
||||
\"*\"\n },\n {\n \"Sid\": \"Allow use of the key\",\n \"Effect\":
|
||||
\"Allow\",\n \"Principal\": {\n \"AWS\": \"arn:aws:iam::111111111111:user/patrick_cli\"\n },\n \"Action\":
|
||||
[\n \"kms:Encrypt\",\n \"kms:Decrypt\",\n \"kms:ReEncrypt*\",\n \"kms:GenerateDataKey*\",\n \"kms:DescribeKey\"\n ],\n \"Resource\":
|
||||
\"*\"\n },\n {\n \"Sid\": \"Allow attachment of persistent
|
||||
resources\",\n \"Effect\": \"Allow\",\n \"Principal\": {\n \"AWS\":
|
||||
\"arn:aws:iam::111111111111:user/patrick_cli\"\n },\n \"Action\":
|
||||
[\n \"kms:CreateGrant\",\n \"kms:ListGrants\",\n \"kms:RevokeGrant\"\n ],\n \"Resource\":
|
||||
\"*\",\n \"Condition\": {\n \"Bool\": {\n \"kms:GrantIsForAWSResource\":
|
||||
\"true\"\n }\n }\n },\n {\n \"Sid\":
|
||||
\"Allow use of the key\",\n \"Effect\": \"Allow\",\n \"Principal\":
|
||||
{\n \"AWS\": \"*\"\n },\n \"Action\": [\n \"kms:Encrypt\"\n ],\n \"Resource\":
|
||||
\"*\"\n }\n ]\n}", "description": "", "customerMasterKeySpec": "SYMMETRIC_DEFAULT",
|
||||
"bypassPolicyLockoutSafetyCheck": false, "tags": [], "keyUsage": "ENCRYPT_DECRYPT"},
|
||||
"responseElements": {"keyMetadata": {"aWSAccountId": "111111111111", "keyId": "f2a82583-a7d3-4c92-8787-fe2baab1cee1",
|
||||
"arn": "arn:aws:kms:us-west-2:111111111111:key/f2a82583-a7d3-4c92-8787-fe2baab1cee1",
|
||||
"creationDate": "Jan 11, 2021, 9:56:30 AM", "enabled": true, "description": "",
|
||||
"keyUsage": "ENCRYPT_DECRYPT", "keyState": "Enabled", "origin": "AWS_KMS", "keyManager":
|
||||
"CUSTOMER", "customerMasterKeySpec": "SYMMETRIC_DEFAULT", "encryptionAlgorithms":
|
||||
["SYMMETRIC_DEFAULT"]}}, "requestID": "3356af25-a237-471f-ba5e-abb37d4a256f", "eventID":
|
||||
"f09518ac-5ae5-4214-80ee-4f23ccdedd4c", "readOnly": false, "resources": [{"accountId":
|
||||
"111111111111", "type": "AWS::KMS::Key", "ARN": "arn:aws:kms:us-west-2:111111111111:key/f2a82583-a7d3-4c92-8787-fe2baab1cee1"}],
|
||||
"eventType": "AwsApiCall", "managementEvent": true, "eventCategory": "Management",
|
||||
"recipientAccountId": "111111111111"}'
|
||||
@@ -0,0 +1,102 @@
|
||||
name: AWS CloudTrail CreateLoginProfile
|
||||
id: 0024fdb1-0d62-4449-970a-746952cf80b6
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for AWS CloudTrail CreateLoginProfile
|
||||
source: aws_cloudtrail
|
||||
sourcetype: aws:cloudtrail
|
||||
separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Amazon Web Services (AWS)
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.4.1
|
||||
fields:
|
||||
- _time
|
||||
- action
|
||||
- app
|
||||
- awsRegion
|
||||
- aws_account_id
|
||||
- change_type
|
||||
- command
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- dest
|
||||
- dvc
|
||||
- errorCode
|
||||
- eventCategory
|
||||
- eventID
|
||||
- eventName
|
||||
- eventSource
|
||||
- eventTime
|
||||
- eventType
|
||||
- eventVersion
|
||||
- eventtype
|
||||
- host
|
||||
- index
|
||||
- linecount
|
||||
- managementEvent
|
||||
- msg
|
||||
- object_category
|
||||
- product
|
||||
- punct
|
||||
- readOnly
|
||||
- recipientAccountId
|
||||
- region
|
||||
- requestID
|
||||
- requestParameters.passwordResetRequired
|
||||
- requestParameters.userName
|
||||
- responseElements.loginProfile.createDate
|
||||
- responseElements.loginProfile.passwordResetRequired
|
||||
- responseElements.loginProfile.userName
|
||||
- signature
|
||||
- source
|
||||
- sourceIPAddress
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- src
|
||||
- src_ip
|
||||
- start_time
|
||||
- status
|
||||
- tag
|
||||
- tag::eventtype
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
- user
|
||||
- userAgent
|
||||
- userIdentity.accessKeyId
|
||||
- userIdentity.accountId
|
||||
- userIdentity.arn
|
||||
- userIdentity.principalId
|
||||
- userIdentity.type
|
||||
- userIdentity.userName
|
||||
- userName
|
||||
- user_access_key
|
||||
- user_agent
|
||||
- user_arn
|
||||
- user_group_id
|
||||
- user_id
|
||||
- user_name
|
||||
- user_type
|
||||
- vendor
|
||||
- vendor_account
|
||||
- vendor_product
|
||||
- vendor_region
|
||||
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId":
|
||||
"AIDAYTOGP2RLEHRX5YWNV", "arn": "arn:aws:iam::111111111111:user/bhavin_cli", "accountId":
|
||||
"111111111111", "accessKeyId": "AKIAYTOGP2RLLAA6NJUM", "userName": "bhavin_cli"},
|
||||
"eventTime": "2021-03-05T01:02:38Z", "eventSource": "iam.amazonaws.com", "eventName":
|
||||
"CreateLoginProfile", "awsRegion": "us-east-1", "sourceIPAddress": "73.15.72.101",
|
||||
"userAgent": "aws-cli/2.0.62 Python/3.9.2 Darwin/19.6.0 source/x86_64 command/iam.create-login-profile",
|
||||
"requestParameters": {"userName": "AtomicRedTeam", "passwordResetRequired": false},
|
||||
"responseElements": {"loginProfile": {"userName": "AtomicRedTeam", "createDate":
|
||||
"Mar 5, 2021 1:02:38 AM", "passwordResetRequired": false}}, "requestID": "f1b90364-8aed-4559-96cf-f5f2009bb7cb",
|
||||
"eventID": "ffb76906-6dd1-4219-adfe-e26b92036a1e", "readOnly": false, "eventType":
|
||||
"AwsApiCall", "managementEvent": true, "eventCategory": "Management", "recipientAccountId":
|
||||
"111111111111"}'
|
||||
@@ -0,0 +1,121 @@
|
||||
name: AWS CloudTrail CreateNetworkAclEntry
|
||||
id: 45934028-10ec-4ab5-a7b1-a6349b833e67
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for AWS CloudTrail CreateNetworkAclEntry
|
||||
source: aws_cloudtrail
|
||||
sourcetype: aws:cloudtrail
|
||||
separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Amazon Web Services (AWS)
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.4.1
|
||||
fields:
|
||||
- _time
|
||||
- action
|
||||
- app
|
||||
- awsRegion
|
||||
- aws_account_id
|
||||
- change_type
|
||||
- command
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- dest
|
||||
- direction
|
||||
- dvc
|
||||
- errorCode
|
||||
- eventCategory
|
||||
- eventID
|
||||
- eventName
|
||||
- eventSource
|
||||
- eventTime
|
||||
- eventType
|
||||
- eventVersion
|
||||
- eventtype
|
||||
- host
|
||||
- index
|
||||
- linecount
|
||||
- managementEvent
|
||||
- msg
|
||||
- object
|
||||
- object_category
|
||||
- object_id
|
||||
- product
|
||||
- protocol
|
||||
- protocol_code
|
||||
- punct
|
||||
- readOnly
|
||||
- recipientAccountId
|
||||
- region
|
||||
- requestID
|
||||
- requestParameters.aclProtocol
|
||||
- requestParameters.cidrBlock
|
||||
- requestParameters.egress
|
||||
- requestParameters.networkAclId
|
||||
- requestParameters.ruleAction
|
||||
- requestParameters.ruleNumber
|
||||
- responseElements._return
|
||||
- responseElements.requestId
|
||||
- rule_action
|
||||
- signature
|
||||
- source
|
||||
- sourceIPAddress
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- src
|
||||
- src_ip
|
||||
- src_ip_range
|
||||
- start_time
|
||||
- status
|
||||
- tag
|
||||
- tag::eventtype
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
- user
|
||||
- userAgent
|
||||
- userIdentity.accessKeyId
|
||||
- userIdentity.accountId
|
||||
- userIdentity.arn
|
||||
- userIdentity.principalId
|
||||
- userIdentity.sessionContext.attributes.creationDate
|
||||
- userIdentity.sessionContext.attributes.mfaAuthenticated
|
||||
- userIdentity.sessionContext.sessionIssuer.accountId
|
||||
- userIdentity.sessionContext.sessionIssuer.arn
|
||||
- userIdentity.sessionContext.sessionIssuer.principalId
|
||||
- userIdentity.sessionContext.sessionIssuer.type
|
||||
- userIdentity.sessionContext.sessionIssuer.userName
|
||||
- userIdentity.type
|
||||
- userName
|
||||
- user_access_key
|
||||
- user_agent
|
||||
- user_arn
|
||||
- user_group_id
|
||||
- user_id
|
||||
- user_name
|
||||
- user_type
|
||||
- vendor
|
||||
- vendor_account
|
||||
- vendor_product
|
||||
- vendor_region
|
||||
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "principalId":
|
||||
"AROAIJIESMXKGCJRCTPR6:pbareiss@splunk.local", "arn": "arn:aws:sts::111111111111:assumed-role/okta_adm_role/pbareiss@splunk.local",
|
||||
"accountId": "111111111111", "accessKeyId": "ASIAYTOGP2RLF3F7BXZK", "sessionContext":
|
||||
{"sessionIssuer": {"type": "Role", "principalId": "AROAIJIESMXKGCJRCTPR6", "arn":
|
||||
"arn:aws:iam::111111111111:role/okta_adm_role", "accountId": "111111111111", "userName":
|
||||
"okta_adm_role"}, "webIdFederationData": {}, "attributes": {"mfaAuthenticated":
|
||||
"false", "creationDate": "2021-01-12T08:36:15Z"}}}, "eventTime": "2021-01-12T08:38:39Z",
|
||||
"eventSource": "ec2.amazonaws.com", "eventName": "CreateNetworkAclEntry", "awsRegion":
|
||||
"eu-central-1", "sourceIPAddress": "95.90.199.65", "userAgent": "console.ec2.amazonaws.com",
|
||||
"requestParameters": {"networkAclId": "acl-078ccebebcbabe175", "ruleNumber": 10,
|
||||
"egress": false, "ruleAction": "allow", "icmpTypeCode": {}, "portRange": {}, "aclProtocol":
|
||||
"-1", "cidrBlock": "0.0.0.0/0"}, "responseElements": {"requestId": "d29c9c32-3a72-48d3-b612-6ba795e9ec64",
|
||||
"_return": true}, "requestID": "d29c9c32-3a72-48d3-b612-6ba795e9ec64", "eventID":
|
||||
"6d1ce00e-4099-463c-8a4d-2af2fb2178ba", "readOnly": false, "eventType": "AwsApiCall",
|
||||
"managementEvent": true, "eventCategory": "Management", "recipientAccountId": "111111111111"}'
|
||||
@@ -0,0 +1,106 @@
|
||||
name: AWS CloudTrail CreatePolicyVersion
|
||||
id: f9f0f3da-37ec-4164-9ea0-0ae46645a86b
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for AWS CloudTrail CreatePolicyVersion
|
||||
source: aws_cloudtrail
|
||||
sourcetype: aws:cloudtrail
|
||||
separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Amazon Web Services (AWS)
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.4.1
|
||||
fields:
|
||||
- _time
|
||||
- action
|
||||
- app
|
||||
- awsRegion
|
||||
- aws_account_id
|
||||
- change_type
|
||||
- command
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- dest
|
||||
- dvc
|
||||
- errorCode
|
||||
- eventCategory
|
||||
- eventID
|
||||
- eventName
|
||||
- eventSource
|
||||
- eventTime
|
||||
- eventType
|
||||
- eventVersion
|
||||
- eventtype
|
||||
- host
|
||||
- index
|
||||
- linecount
|
||||
- managementEvent
|
||||
- msg
|
||||
- object_category
|
||||
- product
|
||||
- punct
|
||||
- readOnly
|
||||
- recipientAccountId
|
||||
- region
|
||||
- requestID
|
||||
- requestParameters.policyArn
|
||||
- requestParameters.policyDocument
|
||||
- requestParameters.setAsDefault
|
||||
- responseElements.policyVersion.createDate
|
||||
- responseElements.policyVersion.isDefaultVersion
|
||||
- responseElements.policyVersion.versionId
|
||||
- signature
|
||||
- source
|
||||
- sourceIPAddress
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- src
|
||||
- src_ip
|
||||
- start_time
|
||||
- status
|
||||
- tag
|
||||
- tag::eventtype
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
- user
|
||||
- userAgent
|
||||
- userIdentity.accessKeyId
|
||||
- userIdentity.accountId
|
||||
- userIdentity.arn
|
||||
- userIdentity.principalId
|
||||
- userIdentity.type
|
||||
- userIdentity.userName
|
||||
- userName
|
||||
- user_access_key
|
||||
- user_agent
|
||||
- user_arn
|
||||
- user_group_id
|
||||
- user_id
|
||||
- user_name
|
||||
- user_type
|
||||
- vendor
|
||||
- vendor_account
|
||||
- vendor_product
|
||||
- vendor_region
|
||||
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId":
|
||||
"AIDAYTOGP2RLNMCDVJZAY", "arn": "arn:aws:iam::111111111111:user/rhino_escalate",
|
||||
"accountId": "111111111111", "accessKeyId": "AKIAYTOGP2RLHSQZPZFZ", "userName":
|
||||
"rhino_escalate"}, "eventTime": "2021-02-23T00:02:30Z", "eventSource": "iam.amazonaws.com",
|
||||
"eventName": "CreatePolicyVersion", "awsRegion": "us-east-1", "sourceIPAddress":
|
||||
"73.15.72.101", "userAgent": "aws-cli/2.0.62 Python/3.9.0 Darwin/19.6.0 source/x86_64
|
||||
command/iam.create-policy-version", "requestParameters": {"policyArn": "arn:aws:iam::111111111111:policy/rhino_escalate",
|
||||
"policyDocument": "{\n \"Version\": \"2012-10-17\",\n \"Statement\": [\n {\n \"Sid\":
|
||||
\"AllowEverything\",\n \"Effect\": \"Allow\",\n \"Action\":
|
||||
\"iam:*\",\n \"Resource\": \"*\"\n }\n ]\n }", "setAsDefault":
|
||||
true}, "responseElements": {"policyVersion": {"versionId": "v2", "isDefaultVersion":
|
||||
true, "createDate": "Feb 23, 2021 12:02:30 AM"}}, "requestID": "fa42b4b2-f34a-4673-8f9f-b25cf1f5005a",
|
||||
"eventID": "33149175-90fd-4cff-a43b-408e4f848c1c", "readOnly": false, "eventType":
|
||||
"AwsApiCall", "managementEvent": true, "eventCategory": "Management", "recipientAccountId":
|
||||
"111111111111"}'
|
||||
@@ -0,0 +1,118 @@
|
||||
name: AWS CloudTrail CreateSnapshot
|
||||
id: 514135a2-f4b2-4d32-8f31-d87824887f9f
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for AWS CloudTrail CreateSnapshot
|
||||
source: aws_cloudtrail
|
||||
sourcetype: aws:cloudtrail
|
||||
separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Amazon Web Services (AWS)
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.4.1
|
||||
fields:
|
||||
- _time
|
||||
- app
|
||||
- awsRegion
|
||||
- aws_account_id
|
||||
- change_type
|
||||
- command
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- dest
|
||||
- dvc
|
||||
- errorCode
|
||||
- eventCategory
|
||||
- eventID
|
||||
- eventName
|
||||
- eventSource
|
||||
- eventTime
|
||||
- eventType
|
||||
- eventVersion
|
||||
- eventtype
|
||||
- host
|
||||
- index
|
||||
- linecount
|
||||
- managementEvent
|
||||
- msg
|
||||
- object_category
|
||||
- product
|
||||
- punct
|
||||
- readOnly
|
||||
- recipientAccountId
|
||||
- region
|
||||
- requestID
|
||||
- requestParameters.tagSpecificationSet.items{}.resourceType
|
||||
- requestParameters.tagSpecificationSet.items{}.tags{}.key
|
||||
- requestParameters.tagSpecificationSet.items{}.tags{}.value
|
||||
- requestParameters.volumeId
|
||||
- responseElements.encrypted
|
||||
- responseElements.ownerId
|
||||
- responseElements.requestId
|
||||
- responseElements.snapshotId
|
||||
- responseElements.startTime
|
||||
- responseElements.status
|
||||
- responseElements.tagSet.items{}.key
|
||||
- responseElements.tagSet.items{}.value
|
||||
- responseElements.volumeId
|
||||
- responseElements.volumeSize
|
||||
- signature
|
||||
- source
|
||||
- sourceIPAddress
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- src
|
||||
- src_ip
|
||||
- start_time
|
||||
- tag
|
||||
- tag::eventtype
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
- tlsDetails.cipherSuite
|
||||
- tlsDetails.clientProvidedHostHeader
|
||||
- tlsDetails.tlsVersion
|
||||
- user
|
||||
- userAgent
|
||||
- userIdentity.accessKeyId
|
||||
- userIdentity.accountId
|
||||
- userIdentity.arn
|
||||
- userIdentity.principalId
|
||||
- userIdentity.type
|
||||
- userIdentity.userName
|
||||
- userName
|
||||
- user_access_key
|
||||
- user_agent
|
||||
- user_arn
|
||||
- user_group_id
|
||||
- user_id
|
||||
- user_name
|
||||
- user_type
|
||||
- vendor
|
||||
- vendor_account
|
||||
- vendor_product
|
||||
- vendor_region
|
||||
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId":
|
||||
"AIDAYTOGP2RLCNEAQXWZV", "arn": "arn:aws:iam::111111111111:user/bhavin_console",
|
||||
"accountId": "111111111111", "accessKeyId": "AKIAYTOGP2RLF5EAXXXX", "userName":
|
||||
"bhavin_console"}, "eventTime": "2023-03-20T22:31:18Z", "eventSource": "ec2.amazonaws.com",
|
||||
"eventName": "CreateSnapshot", "awsRegion": "us-west-2", "sourceIPAddress": "72.135.1.1",
|
||||
"userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io)
|
||||
terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws)
|
||||
aws-sdk-go/1.44.157 (go1.19.3; darwin; amd64) stratus-red-team_46665bb8-dc15-4aba-a5ad-a362772b3f0d
|
||||
HashiCorp-terraform-exec/0.17.3", "requestParameters": {"volumeId": "vol-0363e53e12f67c9b7",
|
||||
"tagSpecificationSet": {"items": [{"resourceType": "snapshot", "tags": [{"key":
|
||||
"StratusRedTeam", "value": "true"}]}]}}, "responseElements": {"requestId": "fefed928-d461-45f0-802f-a99d94c833a8",
|
||||
"snapshotId": "snap-02effb3bb62786b18", "volumeId": "vol-0363e53e12f67c9b7", "status":
|
||||
"pending", "startTime": 1679351478226, "ownerId": "111111111111", "volumeSize":
|
||||
"1", "encrypted": false, "tagSet": {"items": [{"key": "StratusRedTeam", "value":
|
||||
"true"}]}}, "requestID": "fefed928-d461-45f0-802f-a99d94c833a8", "eventID": "2d52d141-d1e6-4d1f-a380-1461c1bf9f83",
|
||||
"readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId":
|
||||
"111111111111", "eventCategory": "Management", "tlsDetails": {"tlsVersion": "TLSv1.2",
|
||||
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256", "clientProvidedHostHeader": "ec2.us-west-2.amazonaws.com"}}'
|
||||
@@ -0,0 +1,121 @@
|
||||
name: AWS CloudTrail CreateTask
|
||||
id: 6501e4fe-05b2-45f1-bd51-9e06a94fa7d9
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for AWS CloudTrail CreateTask
|
||||
source: aws_cloudtrail
|
||||
sourcetype: aws:cloudtrail
|
||||
separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Amazon Web Services (AWS)
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.4.1
|
||||
fields:
|
||||
- _time
|
||||
- app
|
||||
- awsRegion
|
||||
- aws_account_id
|
||||
- command
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- dest
|
||||
- dvc
|
||||
- errorCode
|
||||
- eventCategory
|
||||
- eventID
|
||||
- eventName
|
||||
- eventSource
|
||||
- eventTime
|
||||
- eventType
|
||||
- eventVersion
|
||||
- eventtype
|
||||
- host
|
||||
- index
|
||||
- linecount
|
||||
- managementEvent
|
||||
- msg
|
||||
- object_category
|
||||
- product
|
||||
- punct
|
||||
- readOnly
|
||||
- recipientAccountId
|
||||
- region
|
||||
- requestID
|
||||
- requestParameters.cloudWatchLogGroupArn
|
||||
- requestParameters.destinationLocationArn
|
||||
- requestParameters.options.logLevel
|
||||
- requestParameters.options.verifyMode
|
||||
- requestParameters.schedule.scheduleExpression
|
||||
- requestParameters.sourceLocationArn
|
||||
- responseElements.taskArn
|
||||
- sessionCredentialFromConsole
|
||||
- signature
|
||||
- source
|
||||
- sourceIPAddress
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- src
|
||||
- src_ip
|
||||
- start_time
|
||||
- tag
|
||||
- tag::eventtype
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
- tlsDetails.cipherSuite
|
||||
- tlsDetails.clientProvidedHostHeader
|
||||
- tlsDetails.tlsVersion
|
||||
- user
|
||||
- userAgent
|
||||
- userIdentity.accessKeyId
|
||||
- userIdentity.accountId
|
||||
- userIdentity.arn
|
||||
- userIdentity.principalId
|
||||
- userIdentity.sessionContext.attributes.creationDate
|
||||
- userIdentity.sessionContext.attributes.mfaAuthenticated
|
||||
- userIdentity.sessionContext.sessionIssuer.accountId
|
||||
- userIdentity.sessionContext.sessionIssuer.arn
|
||||
- userIdentity.sessionContext.sessionIssuer.principalId
|
||||
- userIdentity.sessionContext.sessionIssuer.type
|
||||
- userIdentity.sessionContext.sessionIssuer.userName
|
||||
- userIdentity.type
|
||||
- userName
|
||||
- user_access_key
|
||||
- user_agent
|
||||
- user_arn
|
||||
- user_group_id
|
||||
- user_id
|
||||
- user_name
|
||||
- user_type
|
||||
- vendor
|
||||
- vendor_account
|
||||
- vendor_product
|
||||
- vendor_region
|
||||
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "principalId":
|
||||
"AROAYTOGP2RLDF6WQQQQQ:abc@acme.com", "arn": "arn:aws:sts::111111111111:assumed-role/AWSReservedSSO_SPLKAdministratorAccess_d9ce1347d0a6dd3f/abc@acme.com",
|
||||
"accountId": "111111111111", "accessKeyId": "ASIAYTOGP2RLOB2GM111", "sessionContext":
|
||||
{"sessionIssuer": {"type": "Role", "principalId": "AROAYTOGP2RLDF6WQQQQQ", "arn":
|
||||
"arn:aws:iam::111111111111:role/aws-reserved/sso.amazonaws.com/us-west-2/AWSReservedSSO_SPLKAdministratorAccess_d9ce1347d0a6dd3f",
|
||||
"accountId": "111111111111", "userName": "AWSReservedSSO_SPLKAdministratorAccess_d9ce1347d0a6dd3f"},
|
||||
"webIdFederationData": {}, "attributes": {"creationDate": "2023-03-14T21:53:15Z",
|
||||
"mfaAuthenticated": "false"}}}, "eventTime": "2023-03-14T22:05:36Z", "eventSource":
|
||||
"datasync.amazonaws.com", "eventName": "CreateTask", "awsRegion": "us-west-2", "sourceIPAddress":
|
||||
"1.1.1.1", "userAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36
|
||||
(KHTML, like Gecko) Chrome/111.0.0.0 Safari/537.36", "requestParameters": {"sourceLocationArn":
|
||||
"arn:aws:datasync:us-west-2:111111111111:location/loc-0921d426f7955d416", "destinationLocationArn":
|
||||
"arn:aws:datasync:us-west-1:111111111111:location/loc-0b94cf657c358ef06", "cloudWatchLogGroupArn":
|
||||
"arn:aws:logs:us-west-2:111111111111:log-group:/aws/datasync", "options": {"verifyMode":
|
||||
"ONLY_FILES_TRANSFERRED", "logLevel": "BASIC"}, "excludes": [], "schedule": {"scheduleExpression":
|
||||
"cron(6 * * * ? *)"}, "tags": [], "includes": []}, "responseElements": {"taskArn":
|
||||
"arn:aws:datasync:us-west-2:111111111111:task/task-0c77dc0d4b0792ce6"}, "requestID":
|
||||
"de5f4282-aa2b-49b8-8d1b-c3bdb11e2fba", "eventID": "def4cd05-f845-4aec-bc96-07d6ce420d16",
|
||||
"readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId":
|
||||
"111111111111", "eventCategory": "Management", "tlsDetails": {"tlsVersion": "TLSv1.2",
|
||||
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256", "clientProvidedHostHeader": "datasync.us-west-2.amazonaws.com"},
|
||||
"sessionCredentialFromConsole": "true"}'
|
||||
@@ -0,0 +1,100 @@
|
||||
name: AWS CloudTrail CreateVirtualMFADevice
|
||||
id: 13e6e952-0dad-4190-865c-fb5911725f7a
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for AWS CloudTrail CreateVirtualMFADevice
|
||||
source: aws_cloudtrail
|
||||
sourcetype: aws:cloudtrail
|
||||
separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Amazon Web Services (AWS)
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.4.1
|
||||
fields:
|
||||
- _time
|
||||
- action
|
||||
- app
|
||||
- awsRegion
|
||||
- aws_account_id
|
||||
- change_type
|
||||
- command
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- dest
|
||||
- dvc
|
||||
- errorCode
|
||||
- eventCategory
|
||||
- eventID
|
||||
- eventName
|
||||
- eventSource
|
||||
- eventTime
|
||||
- eventType
|
||||
- eventVersion
|
||||
- eventtype
|
||||
- host
|
||||
- index
|
||||
- linecount
|
||||
- managementEvent
|
||||
- msg
|
||||
- object_category
|
||||
- product
|
||||
- punct
|
||||
- readOnly
|
||||
- recipientAccountId
|
||||
- region
|
||||
- requestID
|
||||
- requestParameters.path
|
||||
- requestParameters.virtualMFADeviceName
|
||||
- responseElements.virtualMFADevice.serialNumber
|
||||
- sessionCredentialFromConsole
|
||||
- signature
|
||||
- source
|
||||
- sourceIPAddress
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- src
|
||||
- src_ip
|
||||
- start_time
|
||||
- status
|
||||
- tag
|
||||
- tag::eventtype
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
- user
|
||||
- userAgent
|
||||
- userIdentity.accessKeyId
|
||||
- userIdentity.accountId
|
||||
- userIdentity.arn
|
||||
- userIdentity.principalId
|
||||
- userIdentity.sessionContext.attributes.creationDate
|
||||
- userIdentity.sessionContext.attributes.mfaAuthenticated
|
||||
- userIdentity.type
|
||||
- userName
|
||||
- user_access_key
|
||||
- user_agent
|
||||
- user_arn
|
||||
- user_group_id
|
||||
- user_id
|
||||
- user_type
|
||||
- vendor
|
||||
- vendor_account
|
||||
- vendor_product
|
||||
- vendor_region
|
||||
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "Root", "principalId":
|
||||
"140429656527", "arn": "arn:aws:iam::140429656527:root", "accountId": "140429656527",
|
||||
"accessKeyId": "ASIASBMSCQHH2YXNXJBU", "sessionContext": {"sessionIssuer": {}, "webIdFederationData":
|
||||
{}, "attributes": {"creationDate": "2023-01-30T22:59:36Z", "mfaAuthenticated": "false"}}},
|
||||
"eventTime": "2023-01-30T23:02:23Z", "eventSource": "iam.amazonaws.com", "eventName":
|
||||
"CreateVirtualMFADevice", "awsRegion": "us-east-1", "sourceIPAddress": "23.93.193.6",
|
||||
"userAgent": "AWS Internal", "requestParameters": {"path": "/", "virtualMFADeviceName":
|
||||
"strt_mfa_2"}, "responseElements": {"virtualMFADevice": {"serialNumber": "arn:aws:iam::140429656527:mfa/strt_mfa_2"}},
|
||||
"requestID": "2fbe2074-55f8-4ec6-ad32-0b250803cf46", "eventID": "7e1c493d-c3c3-4f4a-ae4f-8cdd38970027",
|
||||
"readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId":
|
||||
"140429656527", "eventCategory": "Management", "sessionCredentialFromConsole": "true"}'
|
||||
@@ -0,0 +1,100 @@
|
||||
name: AWS CloudTrail DeactivateMFADevice
|
||||
id: 7397a10b-1150-4de9-8062-a96454ae53b2
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for AWS CloudTrail DeactivateMFADevice
|
||||
source: aws_cloudtrail
|
||||
sourcetype: aws:cloudtrail
|
||||
separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Amazon Web Services (AWS)
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.4.1
|
||||
fields:
|
||||
- _time
|
||||
- action
|
||||
- app
|
||||
- awsRegion
|
||||
- aws_account_id
|
||||
- change_type
|
||||
- command
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- dest
|
||||
- dvc
|
||||
- errorCode
|
||||
- eventCategory
|
||||
- eventID
|
||||
- eventName
|
||||
- eventSource
|
||||
- eventTime
|
||||
- eventType
|
||||
- eventVersion
|
||||
- eventtype
|
||||
- host
|
||||
- index
|
||||
- linecount
|
||||
- managementEvent
|
||||
- msg
|
||||
- object_category
|
||||
- product
|
||||
- punct
|
||||
- readOnly
|
||||
- recipientAccountId
|
||||
- region
|
||||
- requestID
|
||||
- requestParameters.serialNumber
|
||||
- requestParameters.userName
|
||||
- responseElements
|
||||
- signature
|
||||
- source
|
||||
- sourceIPAddress
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- src
|
||||
- src_ip
|
||||
- start_time
|
||||
- status
|
||||
- tag
|
||||
- tag::eventtype
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
- user
|
||||
- userAgent
|
||||
- userIdentity.accessKeyId
|
||||
- userIdentity.accountId
|
||||
- userIdentity.arn
|
||||
- userIdentity.principalId
|
||||
- userIdentity.sessionContext.attributes.creationDate
|
||||
- userIdentity.sessionContext.attributes.mfaAuthenticated
|
||||
- userIdentity.type
|
||||
- userName
|
||||
- user_access_key
|
||||
- user_agent
|
||||
- user_arn
|
||||
- user_group_id
|
||||
- user_id
|
||||
- user_name
|
||||
- user_type
|
||||
- vendor
|
||||
- vendor_account
|
||||
- vendor_product
|
||||
- vendor_region
|
||||
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "Root", "principalId":
|
||||
"111111111111", "arn": "arn:aws:iam::111111111111:root", "accountId": "111111111111",
|
||||
"accessKeyId": "ASIASBMSCQHHWAIHMHUX", "sessionContext": {"sessionIssuer": {}, "webIdFederationData":
|
||||
{}, "attributes": {"creationDate": "2022-10-04T16:13:23Z", "mfaAuthenticated": "true"}}},
|
||||
"eventTime": "2022-10-04T16:13:45Z", "eventSource": "iam.amazonaws.com", "eventName":
|
||||
"DeactivateMFADevice", "awsRegion": "us-east-1", "sourceIPAddress": "142.254.89.27",
|
||||
"userAgent": "Coral/Netty4", "requestParameters": {"userName": "AWS ROOT USER",
|
||||
"serialNumber": "arn:aws:iam::111111111111:mfa/root-account-mfa-device"}, "responseElements":
|
||||
null, "requestID": "d27cfb15-34b4-4c16-82bc-a55d15b4e47d", "eventID": "bfe9fd91-0b4d-470a-9c03-77839151806d",
|
||||
"readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId":
|
||||
"111111111111", "eventCategory": "Management"}'
|
||||
@@ -0,0 +1,100 @@
|
||||
name: AWS CloudTrail DeleteAccountPasswordPolicy
|
||||
id: b0730ac8-0992-4de8-b000-2c7d0fc7a67f
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for AWS CloudTrail DeleteAccountPasswordPolicy
|
||||
source: aws_cloudtrail
|
||||
sourcetype: aws:cloudtrail
|
||||
separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Amazon Web Services (AWS)
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.4.1
|
||||
fields:
|
||||
- _time
|
||||
- action
|
||||
- app
|
||||
- awsRegion
|
||||
- aws_account_id
|
||||
- change_type
|
||||
- command
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- desc
|
||||
- dest
|
||||
- dvc
|
||||
- errorCode
|
||||
- eventCategory
|
||||
- eventID
|
||||
- eventName
|
||||
- eventSource
|
||||
- eventTime
|
||||
- eventType
|
||||
- eventVersion
|
||||
- eventtype
|
||||
- host
|
||||
- index
|
||||
- linecount
|
||||
- managementEvent
|
||||
- msg
|
||||
- object_category
|
||||
- product
|
||||
- punct
|
||||
- readOnly
|
||||
- recipientAccountId
|
||||
- region
|
||||
- requestID
|
||||
- requestParameters
|
||||
- responseElements
|
||||
- sessionCredentialFromConsole
|
||||
- signature
|
||||
- source
|
||||
- sourceIPAddress
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- src
|
||||
- src_ip
|
||||
- start_time
|
||||
- status
|
||||
- tag
|
||||
- tag::eventtype
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
- user
|
||||
- userAgent
|
||||
- userIdentity.accessKeyId
|
||||
- userIdentity.accountId
|
||||
- userIdentity.arn
|
||||
- userIdentity.principalId
|
||||
- userIdentity.sessionContext.attributes.creationDate
|
||||
- userIdentity.sessionContext.attributes.mfaAuthenticated
|
||||
- userIdentity.type
|
||||
- userName
|
||||
- user_access_key
|
||||
- user_agent
|
||||
- user_arn
|
||||
- user_group_id
|
||||
- user_id
|
||||
- user_name
|
||||
- user_type
|
||||
- vendor
|
||||
- vendor_account
|
||||
- vendor_product
|
||||
- vendor_region
|
||||
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "Root", "principalId":
|
||||
"111111111111", "arn": "arn:aws:iam::111111111111:root", "accountId": "111111111111",
|
||||
"accessKeyId": "ASIASBMSCQHHWMDJXSE6", "sessionContext": {"sessionIssuer": {}, "webIdFederationData":
|
||||
{}, "attributes": {"creationDate": "2023-01-26T18:44:21Z", "mfaAuthenticated": "false"}}},
|
||||
"eventTime": "2023-01-26T21:23:22Z", "eventSource": "iam.amazonaws.com", "eventName":
|
||||
"DeleteAccountPasswordPolicy", "awsRegion": "us-east-1", "sourceIPAddress": "23.93.193.7",
|
||||
"userAgent": "AWS Internal", "requestParameters": null, "responseElements": null,
|
||||
"requestID": "e3616938-1aac-4abd-9ea3-3b0367b85082", "eventID": "bbd8cb02-22ba-4d1b-b23d-b82975463376",
|
||||
"readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId":
|
||||
"111111111111", "eventCategory": "Management", "sessionCredentialFromConsole": "true"}'
|
||||
@@ -0,0 +1,98 @@
|
||||
name: AWS CloudTrail DeleteDetector
|
||||
id: 5d8bd475-c8bc-4447-b27f-efa508728b90
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for AWS CloudTrail DeleteDetector
|
||||
source: aws_cloudtrail
|
||||
sourcetype: aws:cloudtrail
|
||||
separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Amazon Web Services (AWS)
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.4.1
|
||||
fields:
|
||||
- _time
|
||||
- app
|
||||
- awsRegion
|
||||
- aws_account_id
|
||||
- command
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- dest
|
||||
- dvc
|
||||
- errorCode
|
||||
- eventCategory
|
||||
- eventID
|
||||
- eventName
|
||||
- eventSource
|
||||
- eventTime
|
||||
- eventType
|
||||
- eventVersion
|
||||
- eventtype
|
||||
- host
|
||||
- index
|
||||
- linecount
|
||||
- managementEvent
|
||||
- msg
|
||||
- object_category
|
||||
- product
|
||||
- punct
|
||||
- readOnly
|
||||
- recipientAccountId
|
||||
- region
|
||||
- requestID
|
||||
- requestParameters.detectorId
|
||||
- responseElements.__type
|
||||
- responseElements.message
|
||||
- result_id
|
||||
- signature
|
||||
- source
|
||||
- sourceIPAddress
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- src
|
||||
- src_ip
|
||||
- start_time
|
||||
- tag
|
||||
- tag::eventtype
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
- user
|
||||
- userAgent
|
||||
- userIdentity.accessKeyId
|
||||
- userIdentity.accountId
|
||||
- userIdentity.arn
|
||||
- userIdentity.principalId
|
||||
- userIdentity.type
|
||||
- userIdentity.userName
|
||||
- userName
|
||||
- user_access_key
|
||||
- user_agent
|
||||
- user_arn
|
||||
- user_group_id
|
||||
- user_id
|
||||
- user_name
|
||||
- user_type
|
||||
- vendor
|
||||
- vendor_account
|
||||
- vendor_product
|
||||
- vendor_region
|
||||
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId":
|
||||
"AIDAYTOGP2RLI4PXTGCEU", "arn": "arn:aws:iam::111111111111:user/gowthamaraj_cli",
|
||||
"accountId": "111111111111", "accessKeyId": "AKIAYTOGP2RLFLKADUVG", "userName":
|
||||
"gowthamaraj_cli"}, "eventTime": "2022-07-21T20:27:54Z", "eventSource": "guardduty.amazonaws.com",
|
||||
"eventName": "DeleteDetector", "awsRegion": "us-west-2", "sourceIPAddress": "67.171.71.185",
|
||||
"userAgent": "aws-cli/2.7.3 Python/3.9.13 Darwin/21.5.0 source/x86_64 prompt/off
|
||||
command/guardduty.delete-detector", "errorCode": "BadRequestException", "requestParameters":
|
||||
{"detectorId": "123"}, "responseElements": {"message": "The request is rejected
|
||||
because the parameter detectorId has an invalid value.", "__type": "InvalidInputException"},
|
||||
"requestID": "1e832076-d7a8-432b-b0df-54ba62f6b62c", "eventID": "c1367a2f-8910-4e64-9256-a854d2e9f37d",
|
||||
"readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId":
|
||||
"111111111111", "eventCategory": "Management"}'
|
||||
@@ -0,0 +1,102 @@
|
||||
name: AWS CloudTrail DeleteGroup
|
||||
id: c95308a4-a943-42ca-b112-f90a05c21bd3
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for AWS CloudTrail DeleteGroup
|
||||
source: aws_cloudtrail
|
||||
sourcetype: aws:cloudtrail
|
||||
separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Amazon Web Services (AWS)
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.4.1
|
||||
fields:
|
||||
- _time
|
||||
- action
|
||||
- app
|
||||
- awsRegion
|
||||
- aws_account_id
|
||||
- change_type
|
||||
- command
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- dest
|
||||
- dvc
|
||||
- errorCode
|
||||
- errorMessage
|
||||
- eventCategory
|
||||
- eventID
|
||||
- eventName
|
||||
- eventSource
|
||||
- eventTime
|
||||
- eventType
|
||||
- eventVersion
|
||||
- eventtype
|
||||
- host
|
||||
- index
|
||||
- linecount
|
||||
- managementEvent
|
||||
- msg
|
||||
- object_category
|
||||
- product
|
||||
- punct
|
||||
- readOnly
|
||||
- reason
|
||||
- recipientAccountId
|
||||
- region
|
||||
- requestID
|
||||
- requestParameters.groupName
|
||||
- responseElements
|
||||
- result
|
||||
- result_id
|
||||
- signature
|
||||
- source
|
||||
- sourceIPAddress
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- src
|
||||
- src_ip
|
||||
- start_time
|
||||
- status
|
||||
- tag
|
||||
- tag::eventtype
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
- user
|
||||
- userAgent
|
||||
- userIdentity.accessKeyId
|
||||
- userIdentity.accountId
|
||||
- userIdentity.arn
|
||||
- userIdentity.principalId
|
||||
- userIdentity.type
|
||||
- userIdentity.userName
|
||||
- userName
|
||||
- user_access_key
|
||||
- user_agent
|
||||
- user_arn
|
||||
- user_group_id
|
||||
- user_id
|
||||
- user_name
|
||||
- user_type
|
||||
- vendor
|
||||
- vendor_account
|
||||
- vendor_product
|
||||
- vendor_region
|
||||
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId":
|
||||
"AIDAYTOGP2RLEHRX5YWNV", "arn": "arn:aws:iam::121522247101:user/bhavin_cli", "accountId":
|
||||
"121522247101", "accessKeyId": "AKIAYTOGP2RLLAA6NJUM", "userName": "bhavin_cli"},
|
||||
"eventTime": "2021-04-07T00:17:50Z", "eventSource": "iam.amazonaws.com", "eventName":
|
||||
"DeleteGroup", "awsRegion": "us-east-1", "sourceIPAddress": "12.12.12.20", "userAgent":
|
||||
"aws-cli/2.0.62 Python/3.9.2 Darwin/19.6.0 source/x86_64 command/iam.delete-group",
|
||||
"errorCode": "NoSuchEntityException", "errorMessage": "The group with name AtomicRedTeam_Victim
|
||||
cannot be found.", "requestParameters": {"groupName": "AtomicRedTeam_Victim"}, "responseElements":
|
||||
null, "requestID": "15684d3b-a8c5-4334-a996-16619e901c17", "eventID": "ab65dca3-3d28-41f4-9f99-443606cc49fe",
|
||||
"readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "eventCategory":
|
||||
"Management", "recipientAccountId": "121522247101"}'
|
||||
@@ -0,0 +1,99 @@
|
||||
name: AWS CloudTrail DeleteIPSet
|
||||
id: ebdeeb63-77a0-4808-a6fe-549956731377
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for AWS CloudTrail DeleteIPSet
|
||||
source: aws_cloudtrail
|
||||
sourcetype: aws:cloudtrail
|
||||
separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Amazon Web Services (AWS)
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.4.1
|
||||
fields:
|
||||
- _time
|
||||
- app
|
||||
- awsRegion
|
||||
- aws_account_id
|
||||
- command
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- dest
|
||||
- dvc
|
||||
- errorCode
|
||||
- eventCategory
|
||||
- eventID
|
||||
- eventName
|
||||
- eventSource
|
||||
- eventTime
|
||||
- eventType
|
||||
- eventVersion
|
||||
- eventtype
|
||||
- host
|
||||
- index
|
||||
- linecount
|
||||
- managementEvent
|
||||
- msg
|
||||
- object_category
|
||||
- product
|
||||
- punct
|
||||
- readOnly
|
||||
- recipientAccountId
|
||||
- region
|
||||
- requestID
|
||||
- requestParameters.detectorId
|
||||
- requestParameters.ipSetId
|
||||
- responseElements.__type
|
||||
- responseElements.message
|
||||
- result_id
|
||||
- signature
|
||||
- source
|
||||
- sourceIPAddress
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- src
|
||||
- src_ip
|
||||
- start_time
|
||||
- tag
|
||||
- tag::eventtype
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
- user
|
||||
- userAgent
|
||||
- userIdentity.accessKeyId
|
||||
- userIdentity.accountId
|
||||
- userIdentity.arn
|
||||
- userIdentity.principalId
|
||||
- userIdentity.type
|
||||
- userIdentity.userName
|
||||
- userName
|
||||
- user_access_key
|
||||
- user_agent
|
||||
- user_arn
|
||||
- user_group_id
|
||||
- user_id
|
||||
- user_name
|
||||
- user_type
|
||||
- vendor
|
||||
- vendor_account
|
||||
- vendor_product
|
||||
- vendor_region
|
||||
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId":
|
||||
"AIDAYTOGP2RLEHRX5YWNV", "arn": "arn:aws:iam::111111111111:user/bhavin_cli", "accountId":
|
||||
"111111111111", "accessKeyId": "AKIAYTOGP2RLKQ3U2PDY", "userName": "bhavin_cli"},
|
||||
"eventTime": "2022-07-26T23:14:57Z", "eventSource": "guardduty.amazonaws.com", "eventName":
|
||||
"DeleteIPSet", "awsRegion": "us-west-2", "sourceIPAddress": "142.254.89.27", "userAgent":
|
||||
"aws-cli/2.0.62 Python/3.9.2 Darwin/21.5.0 source/x86_64 command/guardduty.delete-ip-set",
|
||||
"errorCode": "BadRequestException", "requestParameters": {"detectorId": "11111",
|
||||
"ipSetId": "1111"}, "responseElements": {"message": "The request is rejected because
|
||||
the parameter detectorId has an invalid value.", "__type": "InvalidInputException"},
|
||||
"requestID": "70d36916-4ce7-4b6e-9226-9da47d58d554", "eventID": "884dc529-d98f-4529-bfa1-8cdd6c06d02f",
|
||||
"readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId":
|
||||
"111111111111", "eventCategory": "Management"}'
|
||||
@@ -0,0 +1,100 @@
|
||||
name: AWS CloudTrail DeleteLogGroup
|
||||
id: 60cf6a69-fa43-4a6c-8808-e9fb46bf387f
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for AWS CloudTrail DeleteLogGroup
|
||||
source: aws_cloudtrail
|
||||
sourcetype: aws:cloudtrail
|
||||
separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Amazon Web Services (AWS)
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.4.1
|
||||
fields:
|
||||
- _time
|
||||
- apiVersion
|
||||
- app
|
||||
- awsRegion
|
||||
- aws_account_id
|
||||
- command
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- dest
|
||||
- dvc
|
||||
- errorCode
|
||||
- eventCategory
|
||||
- eventID
|
||||
- eventName
|
||||
- eventSource
|
||||
- eventTime
|
||||
- eventType
|
||||
- eventVersion
|
||||
- eventtype
|
||||
- host
|
||||
- index
|
||||
- linecount
|
||||
- managementEvent
|
||||
- msg
|
||||
- object_category
|
||||
- product
|
||||
- punct
|
||||
- readOnly
|
||||
- recipientAccountId
|
||||
- region
|
||||
- requestID
|
||||
- requestParameters.logGroupName
|
||||
- responseElements
|
||||
- signature
|
||||
- source
|
||||
- sourceIPAddress
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- src
|
||||
- src_ip
|
||||
- start_time
|
||||
- tag
|
||||
- tag::eventtype
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
- tlsDetails.cipherSuite
|
||||
- tlsDetails.clientProvidedHostHeader
|
||||
- tlsDetails.tlsVersion
|
||||
- user
|
||||
- userAgent
|
||||
- userIdentity.accessKeyId
|
||||
- userIdentity.accountId
|
||||
- userIdentity.arn
|
||||
- userIdentity.principalId
|
||||
- userIdentity.type
|
||||
- userIdentity.userName
|
||||
- userName
|
||||
- user_access_key
|
||||
- user_agent
|
||||
- user_arn
|
||||
- user_group_id
|
||||
- user_id
|
||||
- user_name
|
||||
- user_type
|
||||
- vendor
|
||||
- vendor_account
|
||||
- vendor_product
|
||||
- vendor_region
|
||||
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId":
|
||||
"AIDAYTOGP2RLI4PXTGCEU", "arn": "arn:aws:iam::111111111111:user/gowthamaraj_cli",
|
||||
"accountId": "111111111111", "accessKeyId": "AKIAYTOGP2RLFLKADUVG", "userName":
|
||||
"gowthamaraj_cli"}, "eventTime": "2022-07-19T08:58:48Z", "eventSource": "logs.amazonaws.com",
|
||||
"eventName": "DeleteLogGroup", "awsRegion": "us-west-2", "sourceIPAddress": "67.171.71.185",
|
||||
"userAgent": "aws-cli/2.7.3 Python/3.9.13 Darwin/21.5.0 source/x86_64 prompt/off
|
||||
command/logs.delete-log-group", "requestParameters": {"logGroupName": "test-logs"},
|
||||
"responseElements": null, "requestID": "76089b03-d749-4f83-bc0e-b857c83bba5f", "eventID":
|
||||
"5aba96c4-e7f9-4e4f-b5e6-49694162195d", "readOnly": false, "eventType": "AwsApiCall",
|
||||
"apiVersion": "20140328", "managementEvent": true, "recipientAccountId": "111111111111",
|
||||
"eventCategory": "Management", "tlsDetails": {"tlsVersion": "TLSv1.2", "cipherSuite":
|
||||
"ECDHE-RSA-AES128-GCM-SHA256", "clientProvidedHostHeader": "logs.us-west-2.amazonaws.com"}}'
|
||||
@@ -0,0 +1,101 @@
|
||||
name: AWS CloudTrail DeleteLogStream
|
||||
id: 6f8bb808-89f8-465e-a34d-229df2f46402
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for AWS CloudTrail DeleteLogStream
|
||||
source: aws_cloudtrail
|
||||
sourcetype: aws:cloudtrail
|
||||
separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Amazon Web Services (AWS)
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.4.1
|
||||
fields:
|
||||
- _time
|
||||
- apiVersion
|
||||
- app
|
||||
- awsRegion
|
||||
- aws_account_id
|
||||
- command
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- dest
|
||||
- dvc
|
||||
- errorCode
|
||||
- eventCategory
|
||||
- eventID
|
||||
- eventName
|
||||
- eventSource
|
||||
- eventTime
|
||||
- eventType
|
||||
- eventVersion
|
||||
- eventtype
|
||||
- host
|
||||
- index
|
||||
- linecount
|
||||
- managementEvent
|
||||
- msg
|
||||
- object_category
|
||||
- product
|
||||
- punct
|
||||
- readOnly
|
||||
- recipientAccountId
|
||||
- region
|
||||
- requestID
|
||||
- requestParameters.logGroupName
|
||||
- requestParameters.logStreamName
|
||||
- responseElements
|
||||
- signature
|
||||
- source
|
||||
- sourceIPAddress
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- src
|
||||
- src_ip
|
||||
- start_time
|
||||
- tag
|
||||
- tag::eventtype
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
- tlsDetails.cipherSuite
|
||||
- tlsDetails.clientProvidedHostHeader
|
||||
- tlsDetails.tlsVersion
|
||||
- user
|
||||
- userAgent
|
||||
- userIdentity.accessKeyId
|
||||
- userIdentity.accountId
|
||||
- userIdentity.arn
|
||||
- userIdentity.principalId
|
||||
- userIdentity.type
|
||||
- userIdentity.userName
|
||||
- userName
|
||||
- user_access_key
|
||||
- user_agent
|
||||
- user_arn
|
||||
- user_group_id
|
||||
- user_id
|
||||
- user_name
|
||||
- user_type
|
||||
- vendor
|
||||
- vendor_account
|
||||
- vendor_product
|
||||
- vendor_region
|
||||
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId":
|
||||
"AIDAYTOGP2RLI4PXTGCEU", "arn": "arn:aws:iam::111111111111:user/gowthamaraj_cli",
|
||||
"accountId": "111111111111", "accessKeyId": "AKIAYTOGP2RLFLKADUVG", "userName":
|
||||
"gowthamaraj_cli"}, "eventTime": "2022-07-20T21:09:51Z", "eventSource": "logs.amazonaws.com",
|
||||
"eventName": "DeleteLogStream", "awsRegion": "us-west-2", "sourceIPAddress": "67.171.71.185",
|
||||
"userAgent": "aws-cli/2.7.3 Python/3.9.13 Darwin/21.5.0 source/x86_64 prompt/off
|
||||
command/logs.delete-log-stream", "requestParameters": {"logGroupName": "test-logs",
|
||||
"logStreamName": "20150601"}, "responseElements": null, "requestID": "2d7e859e-d697-426f-8b56-c4c11c4055f3",
|
||||
"eventID": "561c3f4e-17ca-4438-b15d-29903baf7b13", "readOnly": false, "eventType":
|
||||
"AwsApiCall", "apiVersion": "20140328", "managementEvent": true, "recipientAccountId":
|
||||
"111111111111", "eventCategory": "Management", "tlsDetails": {"tlsVersion": "TLSv1.2",
|
||||
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256", "clientProvidedHostHeader": "logs.us-west-2.amazonaws.com"}}'
|
||||
@@ -0,0 +1,110 @@
|
||||
name: AWS CloudTrail DeleteNetworkAclEntry
|
||||
id: a0dd0f10-cc03-425d-bd5a-e1e0d954b856
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for AWS CloudTrail DeleteNetworkAclEntry
|
||||
source: aws_cloudtrail
|
||||
sourcetype: aws:cloudtrail
|
||||
separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Amazon Web Services (AWS)
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.4.1
|
||||
fields:
|
||||
- _time
|
||||
- action
|
||||
- app
|
||||
- awsRegion
|
||||
- aws_account_id
|
||||
- change_type
|
||||
- command
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- direction
|
||||
- dvc
|
||||
- errorCode
|
||||
- eventCategory
|
||||
- eventID
|
||||
- eventName
|
||||
- eventSource
|
||||
- eventTime
|
||||
- eventType
|
||||
- eventVersion
|
||||
- eventtype
|
||||
- host
|
||||
- index
|
||||
- linecount
|
||||
- managementEvent
|
||||
- msg
|
||||
- object_category
|
||||
- product
|
||||
- punct
|
||||
- readOnly
|
||||
- recipientAccountId
|
||||
- region
|
||||
- requestID
|
||||
- requestParameters.egress
|
||||
- requestParameters.networkAclId
|
||||
- requestParameters.ruleNumber
|
||||
- responseElements._return
|
||||
- responseElements.requestId
|
||||
- signature
|
||||
- source
|
||||
- sourceIPAddress
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- src
|
||||
- src_ip
|
||||
- start_time
|
||||
- status
|
||||
- tag
|
||||
- tag::eventtype
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
- user
|
||||
- userAgent
|
||||
- userIdentity.accessKeyId
|
||||
- userIdentity.accountId
|
||||
- userIdentity.arn
|
||||
- userIdentity.principalId
|
||||
- userIdentity.sessionContext.attributes.creationDate
|
||||
- userIdentity.sessionContext.attributes.mfaAuthenticated
|
||||
- userIdentity.sessionContext.sessionIssuer.accountId
|
||||
- userIdentity.sessionContext.sessionIssuer.arn
|
||||
- userIdentity.sessionContext.sessionIssuer.principalId
|
||||
- userIdentity.sessionContext.sessionIssuer.type
|
||||
- userIdentity.sessionContext.sessionIssuer.userName
|
||||
- userIdentity.type
|
||||
- userName
|
||||
- user_access_key
|
||||
- user_agent
|
||||
- user_arn
|
||||
- user_group_id
|
||||
- user_id
|
||||
- user_name
|
||||
- user_type
|
||||
- vendor
|
||||
- vendor_account
|
||||
- vendor_product
|
||||
- vendor_region
|
||||
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "principalId":
|
||||
"AROAIJIESMXKGCJRCTPR6:pbareiss@splunk.local", "arn": "arn:aws:sts::111111111111:assumed-role/okta_adm_role/pbareiss@splunk.local",
|
||||
"accountId": "111111111111", "accessKeyId": "ASIAYTOGP2RLF3F7BXZK", "sessionContext":
|
||||
{"sessionIssuer": {"type": "Role", "principalId": "AROAIJIESMXKGCJRCTPR6", "arn":
|
||||
"arn:aws:iam::111111111111:role/okta_adm_role", "accountId": "111111111111", "userName":
|
||||
"okta_adm_role"}, "webIdFederationData": {}, "attributes": {"mfaAuthenticated":
|
||||
"false", "creationDate": "2021-01-12T08:36:15Z"}}}, "eventTime": "2021-01-12T09:26:26Z",
|
||||
"eventSource": "ec2.amazonaws.com", "eventName": "DeleteNetworkAclEntry", "awsRegion":
|
||||
"eu-central-1", "sourceIPAddress": "95.90.199.65", "userAgent": "console.ec2.amazonaws.com",
|
||||
"requestParameters": {"networkAclId": "acl-078ccebebcbabe175", "ruleNumber": 40,
|
||||
"egress": false}, "responseElements": {"requestId": "607474bb-836b-46be-be4a-351ebbef67d6",
|
||||
"_return": true}, "requestID": "607474bb-836b-46be-be4a-351ebbef67d6", "eventID":
|
||||
"b9e05770-e9b0-4ba1-91e8-6537097e06e7", "readOnly": false, "eventType": "AwsApiCall",
|
||||
"managementEvent": true, "eventCategory": "Management", "recipientAccountId": "111111111111"}'
|
||||
@@ -0,0 +1,102 @@
|
||||
name: AWS CloudTrail DeletePolicy
|
||||
id: d190d23a-2c59-4a0e-9c55-a53ebef28ee5
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for AWS CloudTrail DeletePolicy
|
||||
source: aws_cloudtrail
|
||||
sourcetype: aws:cloudtrail
|
||||
separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Amazon Web Services (AWS)
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.4.1
|
||||
fields:
|
||||
- _time
|
||||
- action
|
||||
- app
|
||||
- awsRegion
|
||||
- aws_account_id
|
||||
- change_type
|
||||
- command
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- dest
|
||||
- dvc
|
||||
- errorCode
|
||||
- errorMessage
|
||||
- eventCategory
|
||||
- eventID
|
||||
- eventName
|
||||
- eventSource
|
||||
- eventTime
|
||||
- eventType
|
||||
- eventVersion
|
||||
- eventtype
|
||||
- host
|
||||
- index
|
||||
- linecount
|
||||
- managementEvent
|
||||
- msg
|
||||
- object_category
|
||||
- product
|
||||
- punct
|
||||
- readOnly
|
||||
- reason
|
||||
- recipientAccountId
|
||||
- region
|
||||
- requestID
|
||||
- requestParameters.policyArn
|
||||
- responseElements
|
||||
- result
|
||||
- result_id
|
||||
- signature
|
||||
- source
|
||||
- sourceIPAddress
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- src
|
||||
- src_ip
|
||||
- start_time
|
||||
- status
|
||||
- tag
|
||||
- tag::eventtype
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
- user
|
||||
- userAgent
|
||||
- userIdentity.accessKeyId
|
||||
- userIdentity.accountId
|
||||
- userIdentity.arn
|
||||
- userIdentity.principalId
|
||||
- userIdentity.type
|
||||
- userIdentity.userName
|
||||
- userName
|
||||
- user_access_key
|
||||
- user_agent
|
||||
- user_arn
|
||||
- user_group_id
|
||||
- user_id
|
||||
- user_name
|
||||
- user_type
|
||||
- vendor
|
||||
- vendor_account
|
||||
- vendor_product
|
||||
- vendor_region
|
||||
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId":
|
||||
"AIDAYTOGP2RLEHRX5YWNV", "arn": "arn:aws:iam::151521547504:user/bhavin_cli", "accountId":
|
||||
"151521547504", "accessKeyId": "AKIAYTOGP2RLLAA6NJUM", "userName": "bhavin_cli"},
|
||||
"eventTime": "2021-04-02T18:01:00Z", "eventSource": "iam.amazonaws.com", "eventName":
|
||||
"DeletePolicy", "awsRegion": "us-east-1", "sourceIPAddress": "61.25.42.212", "userAgent":
|
||||
"aws-cli/2.0.62 Python/3.9.2 Darwin/19.6.0 source/x86_64 command/iam.delete-policy",
|
||||
"errorCode": "NoSuchEntityException", "errorMessage": "Policy arn:aws:iam::151521547504:policy/AtomicRedTeam
|
||||
was not found.", "requestParameters": {"policyArn": "arn:aws:iam::151521547504:policy/AtomicRedTeam"},
|
||||
"responseElements": null, "requestID": "90cbe52f-e744-4bba-9f5c-1843c9ca1855", "eventID":
|
||||
"abd071bf-0a38-4fab-af4a-5eee55f0935e", "readOnly": false, "eventType": "AwsApiCall",
|
||||
"managementEvent": true, "eventCategory": "Management", "recipientAccountId": "151521547504"}'
|
||||
@@ -0,0 +1,102 @@
|
||||
name: AWS CloudTrail DeleteRule
|
||||
id: b5760623-f3ca-492d-a372-d5c2b3567dfc
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for AWS CloudTrail DeleteRule
|
||||
source: aws_cloudtrail
|
||||
sourcetype: aws:cloudtrail
|
||||
separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Amazon Web Services (AWS)
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.4.1
|
||||
fields:
|
||||
- _time
|
||||
- apiVersion
|
||||
- app
|
||||
- awsRegion
|
||||
- aws_account_id
|
||||
- command
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- dest
|
||||
- dvc
|
||||
- errorCode
|
||||
- eventCategory
|
||||
- eventID
|
||||
- eventName
|
||||
- eventSource
|
||||
- eventTime
|
||||
- eventType
|
||||
- eventVersion
|
||||
- eventtype
|
||||
- host
|
||||
- index
|
||||
- linecount
|
||||
- managementEvent
|
||||
- msg
|
||||
- object_category
|
||||
- product
|
||||
- punct
|
||||
- readOnly
|
||||
- recipientAccountId
|
||||
- region
|
||||
- requestID
|
||||
- requestParameters.changeToken
|
||||
- requestParameters.ruleId
|
||||
- responseElements.changeToken
|
||||
- signature
|
||||
- source
|
||||
- sourceIPAddress
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- src
|
||||
- src_ip
|
||||
- start_time
|
||||
- tag
|
||||
- tag::eventtype
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
- tlsDetails.cipherSuite
|
||||
- tlsDetails.clientProvidedHostHeader
|
||||
- tlsDetails.tlsVersion
|
||||
- user
|
||||
- userAgent
|
||||
- userIdentity.accessKeyId
|
||||
- userIdentity.accountId
|
||||
- userIdentity.arn
|
||||
- userIdentity.principalId
|
||||
- userIdentity.type
|
||||
- userIdentity.userName
|
||||
- userName
|
||||
- user_access_key
|
||||
- user_agent
|
||||
- user_arn
|
||||
- user_group_id
|
||||
- user_id
|
||||
- user_name
|
||||
- user_type
|
||||
- vendor
|
||||
- vendor_account
|
||||
- vendor_product
|
||||
- vendor_region
|
||||
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId":
|
||||
"AIDAYTOGP2RLI4PXTGCEU", "arn": "arn:aws:iam::111111111111:user/gowthamaraj_cli",
|
||||
"accountId": "111111111111", "accessKeyId": "AKIAYTOGP2RLFLKADUVG", "userName":
|
||||
"gowthamaraj_cli"}, "eventTime": "2022-07-20T21:40:42Z", "eventSource": "waf.amazonaws.com",
|
||||
"eventName": "DeleteRule", "awsRegion": "us-east-1", "sourceIPAddress": "67.171.71.185",
|
||||
"userAgent": "aws-cli/2.7.3 Python/3.9.13 Darwin/21.5.0 source/x86_64 prompt/off
|
||||
command/waf.delete-rule", "requestParameters": {"changeToken": "c5daf4cb-68e1-425f-b52d-49a32a7f187f",
|
||||
"ruleId": "5a9b1c4a-a999-4bb2-9f51-555f086ff34f"}, "responseElements": {"changeToken":
|
||||
"c5daf4cb-68e1-425f-b52d-49a32a7f187f"}, "requestID": "2089be3e-28ea-4349-b505-db72c81c272a",
|
||||
"eventID": "0f815483-f6bb-42d9-b870-0dcc64ddc9a4", "readOnly": false, "eventType":
|
||||
"AwsApiCall", "apiVersion": "2015-08-24", "managementEvent": true, "recipientAccountId":
|
||||
"111111111111", "eventCategory": "Management", "tlsDetails": {"tlsVersion": "TLSv1.2",
|
||||
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256", "clientProvidedHostHeader": "waf.amazonaws.com"}}'
|
||||
@@ -0,0 +1,98 @@
|
||||
name: AWS CloudTrail DeleteTrail
|
||||
id: a5af09ff-07b6-4df6-92a0-2146bfe402c8
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for AWS CloudTrail DeleteTrail
|
||||
source: aws_cloudtrail
|
||||
sourcetype: aws:cloudtrail
|
||||
separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Amazon Web Services (AWS)
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.4.1
|
||||
fields:
|
||||
- _time
|
||||
- app
|
||||
- awsRegion
|
||||
- aws_account_id
|
||||
- command
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- dest
|
||||
- dvc
|
||||
- errorCode
|
||||
- eventCategory
|
||||
- eventID
|
||||
- eventName
|
||||
- eventSource
|
||||
- eventTime
|
||||
- eventType
|
||||
- eventVersion
|
||||
- eventtype
|
||||
- host
|
||||
- index
|
||||
- linecount
|
||||
- managementEvent
|
||||
- msg
|
||||
- object_category
|
||||
- product
|
||||
- punct
|
||||
- readOnly
|
||||
- recipientAccountId
|
||||
- region
|
||||
- requestID
|
||||
- requestParameters.name
|
||||
- responseElements
|
||||
- signature
|
||||
- source
|
||||
- sourceIPAddress
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- src
|
||||
- src_ip
|
||||
- start_time
|
||||
- tag
|
||||
- tag::eventtype
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
- tlsDetails.cipherSuite
|
||||
- tlsDetails.clientProvidedHostHeader
|
||||
- tlsDetails.tlsVersion
|
||||
- user
|
||||
- userAgent
|
||||
- userIdentity.accessKeyId
|
||||
- userIdentity.accountId
|
||||
- userIdentity.arn
|
||||
- userIdentity.principalId
|
||||
- userIdentity.type
|
||||
- userIdentity.userName
|
||||
- userName
|
||||
- user_access_key
|
||||
- user_agent
|
||||
- user_arn
|
||||
- user_group_id
|
||||
- user_id
|
||||
- user_name
|
||||
- user_type
|
||||
- vendor
|
||||
- vendor_account
|
||||
- vendor_product
|
||||
- vendor_region
|
||||
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId":
|
||||
"AIDAYTOGP2RLEHRX5YWNV", "arn": "arn:aws:iam::111111111111:user/bhavin_cli", "accountId":
|
||||
"111111111111", "accessKeyId": "AKIAYTOGP2RLKQ3U2PDY", "userName": "bhavin_cli"},
|
||||
"eventTime": "2022-07-13T19:03:51Z", "eventSource": "cloudtrail.amazonaws.com",
|
||||
"eventName": "DeleteTrail", "awsRegion": "us-west-2", "sourceIPAddress": "192.184.242.57",
|
||||
"userAgent": "aws-cli/2.0.62 Python/3.9.2 Darwin/21.5.0 source/x86_64 command/cloudtrail.delete-trail",
|
||||
"requestParameters": {"name": "redatomictesttrail"}, "responseElements": null, "requestID":
|
||||
"2ba0af54-1451-4a2c-846e-18436bcee01e", "eventID": "1c53bcce-650d-486a-b3f6-f64fd853e509",
|
||||
"readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId":
|
||||
"111111111111", "eventCategory": "Management", "tlsDetails": {"tlsVersion": "TLSv1.2",
|
||||
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256", "clientProvidedHostHeader": "cloudtrail.us-west-2.amazonaws.com"}}'
|
||||
@@ -0,0 +1,100 @@
|
||||
name: AWS CloudTrail DeleteVirtualMFADevice
|
||||
id: 84a08d6b-3d59-4260-8cab-84278ada262f
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for AWS CloudTrail DeleteVirtualMFADevice
|
||||
source: aws_cloudtrail
|
||||
sourcetype: aws:cloudtrail
|
||||
separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Amazon Web Services (AWS)
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.4.1
|
||||
fields:
|
||||
- _time
|
||||
- action
|
||||
- app
|
||||
- awsRegion
|
||||
- aws_account_id
|
||||
- change_type
|
||||
- command
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- dest
|
||||
- dvc
|
||||
- errorCode
|
||||
- eventCategory
|
||||
- eventID
|
||||
- eventName
|
||||
- eventSource
|
||||
- eventTime
|
||||
- eventType
|
||||
- eventVersion
|
||||
- eventtype
|
||||
- host
|
||||
- index
|
||||
- linecount
|
||||
- managementEvent
|
||||
- msg
|
||||
- object_category
|
||||
- product
|
||||
- punct
|
||||
- readOnly
|
||||
- recipientAccountId
|
||||
- region
|
||||
- requestID
|
||||
- requestParameters.serialNumber
|
||||
- responseElements
|
||||
- sessionCredentialFromConsole
|
||||
- signature
|
||||
- source
|
||||
- sourceIPAddress
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- src
|
||||
- src_ip
|
||||
- start_time
|
||||
- status
|
||||
- tag
|
||||
- tag::eventtype
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
- user
|
||||
- userAgent
|
||||
- userIdentity.accessKeyId
|
||||
- userIdentity.accountId
|
||||
- userIdentity.arn
|
||||
- userIdentity.principalId
|
||||
- userIdentity.sessionContext.attributes.creationDate
|
||||
- userIdentity.sessionContext.attributes.mfaAuthenticated
|
||||
- userIdentity.type
|
||||
- userName
|
||||
- user_access_key
|
||||
- user_agent
|
||||
- user_arn
|
||||
- user_group_id
|
||||
- user_id
|
||||
- user_name
|
||||
- user_type
|
||||
- vendor
|
||||
- vendor_account
|
||||
- vendor_product
|
||||
- vendor_region
|
||||
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "Root", "principalId":
|
||||
"111111111111", "arn": "arn:aws:iam::111111111111:root", "accountId": "111111111111",
|
||||
"accessKeyId": "ASIASBMSCQHHWAIHMHUX", "sessionContext": {"sessionIssuer": {}, "webIdFederationData":
|
||||
{}, "attributes": {"creationDate": "2022-10-04T16:13:23Z", "mfaAuthenticated": "true"}}},
|
||||
"eventTime": "2022-10-04T16:13:46Z", "eventSource": "iam.amazonaws.com", "eventName":
|
||||
"DeleteVirtualMFADevice", "awsRegion": "us-east-1", "sourceIPAddress": "AWS Internal",
|
||||
"userAgent": "AWS Internal", "requestParameters": {"serialNumber": "arn:aws:iam::111111111111:mfa/root-account-mfa-device"},
|
||||
"responseElements": null, "requestID": "5f192b01-d59d-4cee-8880-cc5cc6fd9b43", "eventID":
|
||||
"01f0258f-b83f-4c0f-8fd3-380473840db8", "readOnly": false, "eventType": "AwsApiCall",
|
||||
"managementEvent": true, "recipientAccountId": "111111111111", "eventCategory":
|
||||
"Management", "sessionCredentialFromConsole": "true"}'
|
||||
@@ -0,0 +1,102 @@
|
||||
name: AWS CloudTrail DeleteWebACL
|
||||
id: 90da5f08-7961-4c29-8de8-01364982aadf
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for AWS CloudTrail DeleteWebACL
|
||||
source: aws_cloudtrail
|
||||
sourcetype: aws:cloudtrail
|
||||
separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Amazon Web Services (AWS)
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.4.1
|
||||
fields:
|
||||
- _time
|
||||
- apiVersion
|
||||
- app
|
||||
- awsRegion
|
||||
- aws_account_id
|
||||
- command
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- dest
|
||||
- dvc
|
||||
- errorCode
|
||||
- eventCategory
|
||||
- eventID
|
||||
- eventName
|
||||
- eventSource
|
||||
- eventTime
|
||||
- eventType
|
||||
- eventVersion
|
||||
- eventtype
|
||||
- host
|
||||
- index
|
||||
- linecount
|
||||
- managementEvent
|
||||
- msg
|
||||
- object_category
|
||||
- product
|
||||
- punct
|
||||
- readOnly
|
||||
- recipientAccountId
|
||||
- region
|
||||
- requestID
|
||||
- requestParameters.changeToken
|
||||
- requestParameters.webACLId
|
||||
- responseElements.changeToken
|
||||
- signature
|
||||
- source
|
||||
- sourceIPAddress
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- src
|
||||
- src_ip
|
||||
- start_time
|
||||
- tag
|
||||
- tag::eventtype
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
- tlsDetails.cipherSuite
|
||||
- tlsDetails.clientProvidedHostHeader
|
||||
- tlsDetails.tlsVersion
|
||||
- user
|
||||
- userAgent
|
||||
- userIdentity.accessKeyId
|
||||
- userIdentity.accountId
|
||||
- userIdentity.arn
|
||||
- userIdentity.principalId
|
||||
- userIdentity.type
|
||||
- userIdentity.userName
|
||||
- userName
|
||||
- user_access_key
|
||||
- user_agent
|
||||
- user_arn
|
||||
- user_group_id
|
||||
- user_id
|
||||
- user_name
|
||||
- user_type
|
||||
- vendor
|
||||
- vendor_account
|
||||
- vendor_product
|
||||
- vendor_region
|
||||
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId":
|
||||
"AIDAYTOGP2RLI4PXTGCEU", "arn": "arn:aws:iam::111111111111:user/gowthamaraj_cli",
|
||||
"accountId": "111111111111", "accessKeyId": "AKIAYTOGP2RLFLKADUVG", "userName":
|
||||
"gowthamaraj_cli"}, "eventTime": "2022-07-20T21:32:54Z", "eventSource": "waf.amazonaws.com",
|
||||
"eventName": "DeleteWebACL", "awsRegion": "us-east-1", "sourceIPAddress": "67.171.71.185",
|
||||
"userAgent": "aws-cli/2.7.3 Python/3.9.13 Darwin/21.5.0 source/x86_64 prompt/off
|
||||
command/waf.delete-web-acl", "requestParameters": {"changeToken": "11eb19d6-d960-4398-8761-6a8fbf8fc425",
|
||||
"webACLId": "6a9771ff-7d94-4fec-a049-e42da0bc7347"}, "responseElements": {"changeToken":
|
||||
"11eb19d6-d960-4398-8761-6a8fbf8fc425"}, "requestID": "55fd5189-5f86-4052-8e8e-993faf1753e8",
|
||||
"eventID": "c8fd51ac-676d-4d5d-aa5a-7e642cf5bb97", "readOnly": false, "eventType":
|
||||
"AwsApiCall", "apiVersion": "2015-08-24", "managementEvent": true, "recipientAccountId":
|
||||
"111111111111", "eventCategory": "Management", "tlsDetails": {"tlsVersion": "TLSv1.2",
|
||||
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256", "clientProvidedHostHeader": "waf.amazonaws.com"}}'
|
||||
@@ -0,0 +1,97 @@
|
||||
name: AWS CloudTrail DescribeEventAggregates
|
||||
id: 7efe4afe-62ae-4f96-81d1-76598ea37fc2
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for AWS CloudTrail DescribeEventAggregates
|
||||
source: aws_cloudtrail
|
||||
sourcetype: aws:cloudtrail
|
||||
separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Amazon Web Services (AWS)
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.4.1
|
||||
fields:
|
||||
- _time
|
||||
- app
|
||||
- awsRegion
|
||||
- aws_account_id
|
||||
- command
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- dest
|
||||
- dvc
|
||||
- errorCode
|
||||
- eventCategory
|
||||
- eventID
|
||||
- eventName
|
||||
- eventSource
|
||||
- eventTime
|
||||
- eventType
|
||||
- eventVersion
|
||||
- host
|
||||
- index
|
||||
- linecount
|
||||
- managementEvent
|
||||
- msg
|
||||
- object_category
|
||||
- product
|
||||
- punct
|
||||
- readOnly
|
||||
- recipientAccountId
|
||||
- region
|
||||
- requestID
|
||||
- requestParameters.aggregateField
|
||||
- requestParameters.filter.eventStatusCodes{}
|
||||
- requestParameters.filter.startTimes{}.from
|
||||
- responseElements
|
||||
- sessionCredentialFromConsole
|
||||
- signature
|
||||
- source
|
||||
- sourceIPAddress
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- src
|
||||
- src_ip
|
||||
- start_time
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
- user
|
||||
- userAgent
|
||||
- userIdentity.accessKeyId
|
||||
- userIdentity.accountId
|
||||
- userIdentity.arn
|
||||
- userIdentity.principalId
|
||||
- userIdentity.sessionContext.attributes.creationDate
|
||||
- userIdentity.sessionContext.attributes.mfaAuthenticated
|
||||
- userIdentity.type
|
||||
- userName
|
||||
- user_access_key
|
||||
- user_agent
|
||||
- user_arn
|
||||
- user_group_id
|
||||
- user_id
|
||||
- user_name
|
||||
- user_type
|
||||
- vendor
|
||||
- vendor_account
|
||||
- vendor_product
|
||||
- vendor_region
|
||||
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "Root", "principalId":
|
||||
"140429656527", "arn": "arn:aws:iam::140429656527:root", "accountId": "140429656527",
|
||||
"accessKeyId": "ASIASBMSCQHHQQ6LB24V", "sessionContext": {"sessionIssuer": {}, "webIdFederationData":
|
||||
{}, "attributes": {"creationDate": "2023-01-31T21:58:17Z", "mfaAuthenticated": "true"}}},
|
||||
"eventTime": "2023-02-01T02:52:34Z", "eventSource": "health.amazonaws.com", "eventName":
|
||||
"DescribeEventAggregates", "awsRegion": "us-east-1", "sourceIPAddress": "54.188.0.152",
|
||||
"userAgent": "AWS Internal", "requestParameters": {"aggregateField": "eventTypeCategory",
|
||||
"filter": {"eventStatusCodes": ["open", "upcoming"], "startTimes": [{"from": "Jan
|
||||
25, 2023 2:54:32 AM"}]}}, "responseElements": null, "requestID": "d6adf050-1d7a-4c25-9d48-0319e33f6f9a",
|
||||
"eventID": "201cee69-61ab-4ffb-80b7-bd31e81e0d82", "readOnly": true, "eventType":
|
||||
"AwsApiCall", "managementEvent": true, "recipientAccountId": "140429656527", "eventCategory":
|
||||
"Management", "sessionCredentialFromConsole": "true"}'
|
||||
@@ -0,0 +1,895 @@
|
||||
name: AWS CloudTrail DescribeImageScanFindings
|
||||
id: 688ea789-9ba2-4970-90a2-17e541e273c9
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for AWS CloudTrail DescribeImageScanFindings
|
||||
source: aws_cloudtrail
|
||||
sourcetype: aws:cloudtrail
|
||||
separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Amazon Web Services (AWS)
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.4.1
|
||||
fields:
|
||||
- _time
|
||||
- app
|
||||
- awsRegion
|
||||
- aws_account_id
|
||||
- command
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- dest
|
||||
- dvc
|
||||
- errorCode
|
||||
- eventCategory
|
||||
- eventID
|
||||
- eventName
|
||||
- eventSource
|
||||
- eventTime
|
||||
- eventType
|
||||
- eventVersion
|
||||
- eventtype
|
||||
- host
|
||||
- index
|
||||
- linecount
|
||||
- managementEvent
|
||||
- msg
|
||||
- object_category
|
||||
- product
|
||||
- punct
|
||||
- readOnly
|
||||
- recipientAccountId
|
||||
- region
|
||||
- requestID
|
||||
- requestParameters.imageId.imageDigest
|
||||
- requestParameters.maxResults
|
||||
- requestParameters.repositoryName
|
||||
- responseElements.imageId.imageDigest
|
||||
- responseElements.imageScanFindings.findingSeverityCounts.HIGH
|
||||
- responseElements.imageScanFindings.findingSeverityCounts.INFORMATIONAL
|
||||
- responseElements.imageScanFindings.findingSeverityCounts.LOW
|
||||
- responseElements.imageScanFindings.findingSeverityCounts.MEDIUM
|
||||
- responseElements.imageScanFindings.findingSeverityCounts.UNDEFINED
|
||||
- responseElements.imageScanFindings.findings{}.attributes{}.key
|
||||
- responseElements.imageScanFindings.findings{}.attributes{}.value
|
||||
- responseElements.imageScanFindings.findings{}.description
|
||||
- responseElements.imageScanFindings.findings{}.name
|
||||
- responseElements.imageScanFindings.findings{}.severity
|
||||
- responseElements.imageScanFindings.findings{}.uri
|
||||
- responseElements.imageScanFindings.imageScanCompletedAt
|
||||
- responseElements.imageScanFindings.vulnerabilitySourceUpdatedAt
|
||||
- responseElements.imageScanStatus.description
|
||||
- responseElements.imageScanStatus.status
|
||||
- responseElements.registryId
|
||||
- responseElements.repositoryName
|
||||
- signature
|
||||
- source
|
||||
- sourceIPAddress
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- src
|
||||
- src_ip
|
||||
- start_time
|
||||
- tag
|
||||
- tag::eventtype
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
- user
|
||||
- userAgent
|
||||
- userIdentity.accessKeyId
|
||||
- userIdentity.accountId
|
||||
- userIdentity.arn
|
||||
- userIdentity.principalId
|
||||
- userIdentity.sessionContext.attributes.creationDate
|
||||
- userIdentity.sessionContext.attributes.mfaAuthenticated
|
||||
- userIdentity.sessionContext.sessionIssuer.accountId
|
||||
- userIdentity.sessionContext.sessionIssuer.arn
|
||||
- userIdentity.sessionContext.sessionIssuer.principalId
|
||||
- userIdentity.sessionContext.sessionIssuer.type
|
||||
- userIdentity.sessionContext.sessionIssuer.userName
|
||||
- userIdentity.type
|
||||
- userName
|
||||
- user_access_key
|
||||
- user_agent
|
||||
- user_arn
|
||||
- user_group_id
|
||||
- user_id
|
||||
- user_name
|
||||
- user_type
|
||||
- vendor
|
||||
- vendor_account
|
||||
- vendor_product
|
||||
- vendor_region
|
||||
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "principalId":
|
||||
"AAAAAAAAAAAAAAAAAAAAA:test@test.com", "arn": "arn:aws:sts::111111111111:assumed-role/role_name/test@test.com",
|
||||
"accountId": "111111111111", "accessKeyId": "AKIAIOSFODNN7EXAMPLE", "sessionContext":
|
||||
{"sessionIssuer": {"type": "Role", "principalId": "AKIAIOSFODNN7EXAMPLE", "arn":
|
||||
"arn:aws:iam::111111111111:role/aws-reserved/test/region/group", "accountId": "111111111111",
|
||||
"userName": "test"}, "webIdFederationData": {}, "attributes": {"creationDate": "2021-08-11T09:42:53Z",
|
||||
"mfaAuthenticated": "false"}}}, "eventTime": "2021-08-11T11:52:27Z", "eventSource":
|
||||
"ecr.amazonaws.com", "eventName": "DescribeImageScanFindings", "awsRegion": "eu-central-1",
|
||||
"sourceIPAddress": "154.16.165.133", "userAgent": "aws-internal/3 aws-sdk-java/1.11.1030
|
||||
Linux/4.9.273-0.1.ac.226.84.332.metal1.x86_64 OpenJDK_64-Bit_Server_VM/25.302-b08
|
||||
java/1.8.0_302 vendor/Oracle_Corporation cfg/retry-mode/legacy", "requestParameters":
|
||||
{"repositoryName": "devsecops/cat_dog_client", "imageId": {"imageDigest": "sha256:a27d73188718a511a1ec1ec788826674b21e097f29873dde734a4dedfbfab1c6"},
|
||||
"maxResults": 1000}, "responseElements": {"registryId": "111111111111", "repositoryName":
|
||||
"devsecops/cat_dog_client", "imageId": {"imageDigest": "sha256:a27d73188718a511a1ec1ec788826674b21e097f29873dde734a4dedfbfab1c6"},
|
||||
"imageScanStatus": {"status": "COMPLETE", "description": "The scan was completed
|
||||
successfully."}, "imageScanFindings": {"imageScanCompletedAt": "Aug 11, 2021, 11:30:16
|
||||
AM", "vulnerabilitySourceUpdatedAt": "Aug 11, 2021, 1:17:52 AM", "findings": [{"name":
|
||||
"CVE-2019-25013", "description": "The iconv feature in the GNU C Library (aka glibc
|
||||
or libc6) through 2.32, when processing invalid multi-byte input sequences in the
|
||||
EUC-KR encoding, may have a buffer over-read.", "uri": "https://security-tracker.debian.org/tracker/CVE-2019-25013",
|
||||
"severity": "HIGH", "attributes": [{"key": "package_version", "value": "2.28-10"},
|
||||
{"key": "package_name", "value": "glibc"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:N/I:N/A:C"},
|
||||
{"key": "CVSS2_SCORE", "value": "7.1"}]}, {"name": "CVE-2021-33574", "description":
|
||||
"The mq_notify function in the GNU C Library (aka glibc) versions 2.32 and 2.33
|
||||
has a use-after-free. It may use the notification thread attributes object (passed
|
||||
through its struct sigevent parameter) after it has been freed by the caller, leading
|
||||
to a denial of service (application crash) or possibly unspecified other impact.",
|
||||
"uri": "https://security-tracker.debian.org/tracker/CVE-2021-33574", "severity":
|
||||
"HIGH", "attributes": [{"key": "package_version", "value": "2.28-10"}, {"key": "package_name",
|
||||
"value": "glibc"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:L/Au:N/C:P/I:P/A:P"},
|
||||
{"key": "CVSS2_SCORE", "value": "7.5"}]}, {"name": "CVE-2018-12886", "description":
|
||||
"stack_protect_prologue in cfgexpand.c and stack_protect_epilogue in function.c
|
||||
in GNU Compiler Collection (GCC) 4.1 through 8 (under certain circumstances) generate
|
||||
instruction sequences when targeting ARM targets that spill the address of the stack
|
||||
protector guard, which allows an attacker to bypass the protection of -fstack-protector,
|
||||
-fstack-protector-all, -fstack-protector-strong, and -fstack-protector-explicit
|
||||
against stack overflow by controlling what the stack canary is compared against.",
|
||||
"uri": "https://security-tracker.debian.org/tracker/CVE-2018-12886", "severity":
|
||||
"MEDIUM", "attributes": [{"key": "package_version", "value": "8.3.0-6"}, {"key":
|
||||
"package_name", "value": "gcc-8"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:P/I:P/A:P"},
|
||||
{"key": "CVSS2_SCORE", "value": "6.8"}]}, {"name": "CVE-2020-1751", "description":
|
||||
"An out-of-bounds write vulnerability was found in glibc before 2.31 when handling
|
||||
signal trampolines on PowerPC. Specifically, the backtrace function did not properly
|
||||
check the array bounds when storing the frame address, resulting in a denial of
|
||||
service or potential code execution. The highest threat from this vulnerability
|
||||
is to system availability.", "uri": "https://security-tracker.debian.org/tracker/CVE-2020-1751",
|
||||
"severity": "MEDIUM", "attributes": [{"key": "package_version", "value": "2.28-10"},
|
||||
{"key": "package_name", "value": "glibc"}, {"key": "CVSS2_VECTOR", "value": "AV:L/AC:M/Au:N/C:P/I:P/A:C"},
|
||||
{"key": "CVSS2_SCORE", "value": "5.9"}]}, {"name": "CVE-2021-3326", "description":
|
||||
"The iconv function in the GNU C Library (aka glibc or libc6) 2.32 and earlier,
|
||||
when processing invalid input sequences in the ISO-2022-JP-3 encoding, fails an
|
||||
assertion in the code path and aborts the program, potentially resulting in a denial
|
||||
of service.", "uri": "https://security-tracker.debian.org/tracker/CVE-2021-3326",
|
||||
"severity": "MEDIUM", "attributes": [{"key": "package_version", "value": "2.28-10"},
|
||||
{"key": "package_name", "value": "glibc"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:L/Au:N/C:N/I:N/A:P"},
|
||||
{"key": "CVSS2_SCORE", "value": "5"}]}, {"name": "CVE-2021-35942", "description":
|
||||
"The wordexp function in the GNU C Library (aka glibc) through 2.33 may crash or
|
||||
read arbitrary memory in parse_param (in posix/wordexp.c) when called with an untrusted,
|
||||
crafted pattern, potentially resulting in a denial of service or disclosure of information.
|
||||
This occurs because atoi was used but strtoul should have been used to ensure correct
|
||||
calculations.", "uri": "https://security-tracker.debian.org/tracker/CVE-2021-35942",
|
||||
"severity": "MEDIUM", "attributes": [{"key": "package_version", "value": "2.28-10"},
|
||||
{"key": "package_name", "value": "glibc"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:L/Au:N/C:P/I:N/A:P"},
|
||||
{"key": "CVSS2_SCORE", "value": "6.4"}]}, {"name": "CVE-2019-12904", "description":
|
||||
"In Libgcrypt 1.8.4, the C implementation of AES is vulnerable to a flush-and-reload
|
||||
side-channel attack because physical addresses are available to other processes.
|
||||
(The C implementation is used on platforms where an assembly-language implementation
|
||||
is unavailable.)", "uri": "https://security-tracker.debian.org/tracker/CVE-2019-12904",
|
||||
"severity": "MEDIUM", "attributes": [{"key": "package_version", "value": "1.8.4-5+deb10u1"},
|
||||
{"key": "package_name", "value": "libgcrypt20"}, {"key": "CVSS2_VECTOR", "value":
|
||||
"AV:N/AC:M/Au:N/C:P/I:N/A:N"}, {"key": "CVSS2_SCORE", "value": "4.3"}]}, {"name":
|
||||
"CVE-2017-6363", "description": "** DISPUTED ** In the GD Graphics Library (aka
|
||||
LibGD) through 2.2.5, there is a heap-based buffer over-read in tiffWriter in gd_tiff.c.
|
||||
NOTE: the vendor says \"In my opinion this issue should not have a CVE, since the
|
||||
GD and GD2 formats are documented to be ''obsolete, and should only be used for
|
||||
development and testing purposes.''\"", "uri": "https://security-tracker.debian.org/tracker/CVE-2017-6363",
|
||||
"severity": "MEDIUM", "attributes": [{"key": "package_version", "value": "2.2.5-5.2"},
|
||||
{"key": "package_name", "value": "libgd2"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:P/I:N/A:P"},
|
||||
{"key": "CVSS2_SCORE", "value": "5.8"}]}, {"name": "CVE-2019-12290", "description":
|
||||
"GNU libidn2 before 2.2.0 fails to perform the roundtrip checks specified in RFC3490
|
||||
Section 4.2 when converting A-labels to U-labels. This makes it possible in some
|
||||
circumstances for one domain to impersonate another. By creating a malicious domain
|
||||
that matches a target domain except for the inclusion of certain punycoded Unicode
|
||||
characters (that would be discarded when converted first to a Unicode label and
|
||||
then back to an ASCII label), arbitrary domains can be impersonated.", "uri": "https://security-tracker.debian.org/tracker/CVE-2019-12290",
|
||||
"severity": "MEDIUM", "attributes": [{"key": "package_version", "value": "2.0.5-1+deb10u1"},
|
||||
{"key": "package_name", "value": "libidn2"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:L/Au:N/C:N/I:P/A:N"},
|
||||
{"key": "CVSS2_SCORE", "value": "5"}]}, {"name": "CVE-2019-13115", "description":
|
||||
"In libssh2 before 1.9.0, kex_method_diffie_hellman_group_exchange_sha256_key_exchange
|
||||
in kex.c has an integer overflow that could lead to an out-of-bounds read in the
|
||||
way packets are read from the server. A remote attacker who compromises a SSH server
|
||||
may be able to disclose sensitive information or cause a denial of service condition
|
||||
on the client system when a user connects to the server. This is related to an _libssh2_check_length
|
||||
mistake, and is different from the various issues fixed in 1.8.1, such as CVE-2019-3855.",
|
||||
"uri": "https://security-tracker.debian.org/tracker/CVE-2019-13115", "severity":
|
||||
"MEDIUM", "attributes": [{"key": "package_version", "value": "1.8.0-2.1"}, {"key":
|
||||
"package_name", "value": "libssh2"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:P/I:N/A:P"},
|
||||
{"key": "CVSS2_SCORE", "value": "5.8"}]}, {"name": "CVE-2016-9318", "description":
|
||||
"libxml2 2.9.4 and earlier, as used in XMLSec 1.2.23 and earlier and other products,
|
||||
does not offer a flag directly indicating that the current document may be read
|
||||
but other files may not be opened, which makes it easier for remote attackers to
|
||||
conduct XML External Entity (XXE) attacks via a crafted document.", "uri": "https://security-tracker.debian.org/tracker/CVE-2016-9318",
|
||||
"severity": "MEDIUM", "attributes": [{"key": "package_version", "value": "2.9.4+dfsg1-7+deb10u2"},
|
||||
{"key": "package_name", "value": "libxml2"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:P/I:N/A:N"},
|
||||
{"key": "CVSS2_SCORE", "value": "4.3"}]}, {"name": "CVE-2017-16932", "description":
|
||||
"parser.c in libxml2 before 2.9.5 does not prevent infinite recursion in parameter
|
||||
entities.", "uri": "https://security-tracker.debian.org/tracker/CVE-2017-16932",
|
||||
"severity": "MEDIUM", "attributes": [{"key": "package_version", "value": "2.9.4+dfsg1-7+deb10u2"},
|
||||
{"key": "package_name", "value": "libxml2"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:L/Au:N/C:N/I:N/A:P"},
|
||||
{"key": "CVSS2_SCORE", "value": "5"}]}, {"name": "CVE-2020-36309", "description":
|
||||
"ngx_http_lua_module (aka lua-nginx-module) before 0.10.16 in OpenResty allows unsafe
|
||||
characters in an argument when using the API to mutate a URI, or a request or response
|
||||
header.", "uri": "https://security-tracker.debian.org/tracker/CVE-2020-36309", "severity":
|
||||
"MEDIUM", "attributes": [{"key": "package_version", "value": "1.21.1-1~buster"},
|
||||
{"key": "package_name", "value": "nginx"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:L/Au:N/C:N/I:P/A:N"},
|
||||
{"key": "CVSS2_SCORE", "value": "5"}]}, {"name": "CVE-2020-14155", "description":
|
||||
"libpcre in PCRE before 8.44 allows an integer overflow via a large number after
|
||||
a (?C substring.", "uri": "https://security-tracker.debian.org/tracker/CVE-2020-14155",
|
||||
"severity": "MEDIUM", "attributes": [{"key": "package_version", "value": "2:8.39-12"},
|
||||
{"key": "package_name", "value": "pcre3"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:L/Au:N/C:N/I:N/A:P"},
|
||||
{"key": "CVSS2_SCORE", "value": "5"}]}, {"name": "CVE-2019-3843", "description":
|
||||
"It was discovered that a systemd service that uses DynamicUser property can create
|
||||
a SUID/SGID binary that would be allowed to run as the transient service UID/GID
|
||||
even after the service is terminated. A local attacker may use this flaw to access
|
||||
resources that will be owned by a potentially different service in the future, when
|
||||
the UID/GID will be recycled.", "uri": "https://security-tracker.debian.org/tracker/CVE-2019-3843",
|
||||
"severity": "MEDIUM", "attributes": [{"key": "package_version", "value": "241-7~deb10u8"},
|
||||
{"key": "package_name", "value": "systemd"}, {"key": "CVSS2_VECTOR", "value": "AV:L/AC:L/Au:N/C:P/I:P/A:P"},
|
||||
{"key": "CVSS2_SCORE", "value": "4.6"}]}, {"name": "CVE-2019-3844", "description":
|
||||
"It was discovered that a systemd service that uses DynamicUser property can get
|
||||
new privileges through the execution of SUID binaries, which would allow to create
|
||||
binaries owned by the service transient group with the setgid bit set. A local attacker
|
||||
may use this flaw to access resources that will be owned by a potentially different
|
||||
service in the future, when the GID will be recycled.", "uri": "https://security-tracker.debian.org/tracker/CVE-2019-3844",
|
||||
"severity": "MEDIUM", "attributes": [{"key": "package_version", "value": "241-7~deb10u8"},
|
||||
{"key": "package_name", "value": "systemd"}, {"key": "CVSS2_VECTOR", "value": "AV:L/AC:L/Au:N/C:P/I:P/A:P"},
|
||||
{"key": "CVSS2_SCORE", "value": "4.6"}]}, {"name": "CVE-2016-2781", "description":
|
||||
"chroot in GNU coreutils, when used with --userspec, allows local users to escape
|
||||
to the parent session via a crafted TIOCSTI ioctl call, which pushes characters
|
||||
to the terminal''s input buffer.", "uri": "https://security-tracker.debian.org/tracker/CVE-2016-2781",
|
||||
"severity": "LOW", "attributes": [{"key": "package_version", "value": "8.30-3"},
|
||||
{"key": "package_name", "value": "coreutils"}, {"key": "CVSS2_VECTOR", "value":
|
||||
"AV:L/AC:L/Au:N/C:N/I:P/A:N"}, {"key": "CVSS2_SCORE", "value": "2.1"}]}, {"name":
|
||||
"CVE-2021-22898", "description": "curl 7.7 through 7.76.1 suffers from an information
|
||||
disclosure when the `-t` command line option, known as `CURLOPT_TELNETOPTIONS` in
|
||||
libcurl, is used to send variable=content pairs to TELNET servers. Due to a flaw
|
||||
in the option parser for sending NEW_ENV variables, libcurl could be made to pass
|
||||
on uninitialized data from a stack based buffer to the server, resulting in potentially
|
||||
revealing sensitive internal information to the server using a clear-text network
|
||||
protocol.", "uri": "https://security-tracker.debian.org/tracker/CVE-2021-22898",
|
||||
"severity": "LOW", "attributes": [{"key": "package_version", "value": "7.64.0-4+deb10u2"},
|
||||
{"key": "package_name", "value": "curl"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:H/Au:N/C:P/I:N/A:N"},
|
||||
{"key": "CVSS2_SCORE", "value": "2.6"}]}, {"name": "CVE-2019-15847", "description":
|
||||
"The POWER9 backend in GNU Compiler Collection (GCC) before version 10 could optimize
|
||||
multiple calls of the __builtin_darn intrinsic into a single call, thus reducing
|
||||
the entropy of the random number generator. This occurred because a volatile operation
|
||||
was not specified. For example, within a single execution of a program, the output
|
||||
of every __builtin_darn() call may be the same.", "uri": "https://security-tracker.debian.org/tracker/CVE-2019-15847",
|
||||
"severity": "LOW", "attributes": [{"key": "package_version", "value": "8.3.0-6"},
|
||||
{"key": "package_name", "value": "gcc-8"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:L/Au:N/C:P/I:N/A:N"},
|
||||
{"key": "CVSS2_SCORE", "value": "5"}]}, {"name": "CVE-2020-1752", "description":
|
||||
"A use-after-free vulnerability introduced in glibc upstream version 2.14 was found
|
||||
in the way the tilde expansion was carried out. Directory paths containing an initial
|
||||
tilde followed by a valid username were affected by this issue. A local attacker
|
||||
could exploit this flaw by creating a specially crafted path that, when processed
|
||||
by the glob function, would potentially lead to arbitrary code execution. This was
|
||||
fixed in version 2.32.", "uri": "https://security-tracker.debian.org/tracker/CVE-2020-1752",
|
||||
"severity": "LOW", "attributes": [{"key": "package_version", "value": "2.28-10"},
|
||||
{"key": "package_name", "value": "glibc"}, {"key": "CVSS2_VECTOR", "value": "AV:L/AC:H/Au:N/C:P/I:P/A:P"},
|
||||
{"key": "CVSS2_SCORE", "value": "3.7"}]}, {"name": "CVE-2020-6096", "description":
|
||||
"An exploitable signed comparison vulnerability exists in the ARMv7 memcpy() implementation
|
||||
of GNU glibc 2.30.9000. Calling memcpy() (on ARMv7 targets that utilize the GNU
|
||||
glibc implementation) with a negative value for the ''num'' parameter results in
|
||||
a signed comparison vulnerability. If an attacker underflows the ''num'' parameter
|
||||
to memcpy(), this vulnerability could lead to undefined behavior such as writing
|
||||
to out-of-bounds memory and potentially remote code execution. Furthermore, this
|
||||
memcpy() implementation allows for program execution to continue in scenarios where
|
||||
a segmentation fault or crash should have occurred. The dangers occur in that subsequent
|
||||
execution and iterations of this code will be executed with this corrupted data.",
|
||||
"uri": "https://security-tracker.debian.org/tracker/CVE-2020-6096", "severity":
|
||||
"LOW", "attributes": [{"key": "package_version", "value": "2.28-10"}, {"key": "package_name",
|
||||
"value": "glibc"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:P/I:P/A:P"},
|
||||
{"key": "CVSS2_SCORE", "value": "6.8"}]}, {"name": "CVE-2020-10029", "description":
|
||||
"The GNU C Library (aka glibc or libc6) before 2.32 could overflow an on-stack buffer
|
||||
during range reduction if an input to an 80-bit long double function contains a
|
||||
non-canonical bit pattern, a seen when passing a 0x5d414141414141410000 value to
|
||||
sinl on x86 targets. This is related to sysdeps/ieee754/ldbl-96/e_rem_pio2l.c.",
|
||||
"uri": "https://security-tracker.debian.org/tracker/CVE-2020-10029", "severity":
|
||||
"LOW", "attributes": [{"key": "package_version", "value": "2.28-10"}, {"key": "package_name",
|
||||
"value": "glibc"}, {"key": "CVSS2_VECTOR", "value": "AV:L/AC:L/Au:N/C:N/I:N/A:P"},
|
||||
{"key": "CVSS2_SCORE", "value": "2.1"}]}, {"name": "CVE-2020-27618", "description":
|
||||
"The iconv function in the GNU C Library (aka glibc or libc6) 2.32 and earlier,
|
||||
when processing invalid multi-byte input sequences in IBM1364, IBM1371, IBM1388,
|
||||
IBM1390, and IBM1399 encodings, fails to advance the input state, which could lead
|
||||
to an infinite loop in applications, resulting in a denial of service, a different
|
||||
vulnerability from CVE-2016-10228.", "uri": "https://security-tracker.debian.org/tracker/CVE-2020-27618",
|
||||
"severity": "LOW", "attributes": [{"key": "package_version", "value": "2.28-10"},
|
||||
{"key": "package_name", "value": "glibc"}, {"key": "CVSS2_VECTOR", "value": "AV:L/AC:L/Au:N/C:N/I:N/A:P"},
|
||||
{"key": "CVSS2_SCORE", "value": "2.1"}]}, {"name": "CVE-2016-10228", "description":
|
||||
"The iconv program in the GNU C Library (aka glibc or libc6) 2.31 and earlier, when
|
||||
invoked with multiple suffixes in the destination encoding (TRANSLATE or IGNORE)
|
||||
along with the -c option, enters an infinite loop when processing invalid multi-byte
|
||||
input sequences, leading to a denial of service.", "uri": "https://security-tracker.debian.org/tracker/CVE-2016-10228",
|
||||
"severity": "LOW", "attributes": [{"key": "package_version", "value": "2.28-10"},
|
||||
{"key": "package_name", "value": "glibc"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:N/I:N/A:P"},
|
||||
{"key": "CVSS2_SCORE", "value": "4.3"}]}, {"name": "CVE-2019-19126", "description":
|
||||
"On the x86-64 architecture, the GNU C Library (aka glibc) before 2.31 fails to
|
||||
ignore the LD_PREFER_MAP_32BIT_EXEC environment variable during program execution
|
||||
after a security transition, allowing local attackers to restrict the possible mapping
|
||||
addresses for loaded libraries and thus bypass ASLR for a setuid program.", "uri":
|
||||
"https://security-tracker.debian.org/tracker/CVE-2019-19126", "severity": "LOW",
|
||||
"attributes": [{"key": "package_version", "value": "2.28-10"}, {"key": "package_name",
|
||||
"value": "glibc"}, {"key": "CVSS2_VECTOR", "value": "AV:L/AC:L/Au:N/C:P/I:N/A:N"},
|
||||
{"key": "CVSS2_SCORE", "value": "2.1"}]}, {"name": "CVE-2021-27645", "description":
|
||||
"The nameserver caching daemon (nscd) in the GNU C Library (aka glibc or libc6)
|
||||
2.29 through 2.33, when processing a request for netgroup lookup, may crash due
|
||||
to a double-free, potentially resulting in degraded service or Denial of Service
|
||||
on the local system. This is related to netgroupcache.c.", "uri": "https://security-tracker.debian.org/tracker/CVE-2021-27645",
|
||||
"severity": "LOW", "attributes": [{"key": "package_version", "value": "2.28-10"},
|
||||
{"key": "package_name", "value": "glibc"}, {"key": "CVSS2_VECTOR", "value": "AV:L/AC:M/Au:N/C:N/I:N/A:P"},
|
||||
{"key": "CVSS2_SCORE", "value": "1.9"}]}, {"name": "CVE-2019-14855", "description":
|
||||
"A flaw was found in the way certificate signatures could be forged using collisions
|
||||
found in the SHA-1 algorithm. An attacker could use this weakness to create forged
|
||||
certificate signatures. This issue affects GnuPG versions before 2.2.18.", "uri":
|
||||
"https://security-tracker.debian.org/tracker/CVE-2019-14855", "severity": "LOW",
|
||||
"attributes": [{"key": "package_version", "value": "2.2.12-1+deb10u1"}, {"key":
|
||||
"package_name", "value": "gnupg2"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:L/Au:N/C:P/I:N/A:N"},
|
||||
{"key": "CVSS2_SCORE", "value": "5"}]}, {"name": "CVE-2019-13627", "description":
|
||||
"It was discovered that there was a ECDSA timing attack in the libgcrypt20 cryptographic
|
||||
library. Version affected: 1.8.4-5, 1.7.6-2+deb9u3, and 1.6.3-2+deb8u4. Versions
|
||||
fixed: 1.8.5-2 and 1.6.3-2+deb8u7.", "uri": "https://security-tracker.debian.org/tracker/CVE-2019-13627",
|
||||
"severity": "LOW", "attributes": [{"key": "package_version", "value": "1.8.4-5+deb10u1"},
|
||||
{"key": "package_name", "value": "libgcrypt20"}, {"key": "CVSS2_VECTOR", "value":
|
||||
"AV:L/AC:H/Au:N/C:P/I:P/A:N"}, {"key": "CVSS2_SCORE", "value": "2.6"}]}, {"name":
|
||||
"CVE-2018-14553", "description": "gdImageClone in gd.c in libgd 2.1.0-rc2 through
|
||||
2.2.5 has a NULL pointer dereference allowing attackers to crash an application
|
||||
via a specific function call sequence. Only affects PHP when linked with an external
|
||||
libgd (not bundled).", "uri": "https://security-tracker.debian.org/tracker/CVE-2018-14553",
|
||||
"severity": "LOW", "attributes": [{"key": "package_version", "value": "2.2.5-5.2"},
|
||||
{"key": "package_name", "value": "libgd2"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:L/Au:N/C:N/I:N/A:P"},
|
||||
{"key": "CVSS2_SCORE", "value": "5"}]}, {"name": "CVE-2021-36086", "description":
|
||||
"The CIL compiler in SELinux 3.2 has a use-after-free in cil_reset_classpermission
|
||||
(called from cil_reset_classperms_set and cil_reset_classperms_list).", "uri": "https://security-tracker.debian.org/tracker/CVE-2021-36086",
|
||||
"severity": "LOW", "attributes": [{"key": "package_version", "value": "2.8-1"},
|
||||
{"key": "package_name", "value": "libsepol"}, {"key": "CVSS2_VECTOR", "value": "AV:L/AC:L/Au:N/C:N/I:N/A:P"},
|
||||
{"key": "CVSS2_SCORE", "value": "2.1"}]}, {"name": "CVE-2021-36085", "description":
|
||||
"The CIL compiler in SELinux 3.2 has a use-after-free in __cil_verify_classperms
|
||||
(called from __verify_map_perm_classperms and hashtab_map).", "uri": "https://security-tracker.debian.org/tracker/CVE-2021-36085",
|
||||
"severity": "LOW", "attributes": [{"key": "package_version", "value": "2.8-1"},
|
||||
{"key": "package_name", "value": "libsepol"}, {"key": "CVSS2_VECTOR", "value": "AV:L/AC:L/Au:N/C:N/I:N/A:P"},
|
||||
{"key": "CVSS2_SCORE", "value": "2.1"}]}, {"name": "CVE-2021-36087", "description":
|
||||
"The CIL compiler in SELinux 3.2 has a heap-based buffer over-read in ebitmap_match_any
|
||||
(called indirectly from cil_check_neverallow). This occurs because there is sometimes
|
||||
a lack of checks for invalid statements in an optional block.", "uri": "https://security-tracker.debian.org/tracker/CVE-2021-36087",
|
||||
"severity": "LOW", "attributes": [{"key": "package_version", "value": "2.8-1"},
|
||||
{"key": "package_name", "value": "libsepol"}, {"key": "CVSS2_VECTOR", "value": "AV:L/AC:L/Au:N/C:N/I:N/A:P"},
|
||||
{"key": "CVSS2_SCORE", "value": "2.1"}]}, {"name": "CVE-2021-36084", "description":
|
||||
"The CIL compiler in SELinux 3.2 has a use-after-free in __cil_verify_classperms
|
||||
(called from __cil_verify_classpermission and __cil_pre_verify_helper).", "uri":
|
||||
"https://security-tracker.debian.org/tracker/CVE-2021-36084", "severity": "LOW",
|
||||
"attributes": [{"key": "package_version", "value": "2.8-1"}, {"key": "package_name",
|
||||
"value": "libsepol"}, {"key": "CVSS2_VECTOR", "value": "AV:L/AC:L/Au:N/C:N/I:N/A:P"},
|
||||
{"key": "CVSS2_SCORE", "value": "2.1"}]}, {"name": "CVE-2019-17498", "description":
|
||||
"In libssh2 v1.9.0 and earlier versions, the SSH_MSG_DISCONNECT logic in packet.c
|
||||
has an integer overflow in a bounds check, enabling an attacker to specify an arbitrary
|
||||
(out-of-bounds) offset for a subsequent memory read. A crafted SSH server may be
|
||||
able to disclose sensitive information or cause a denial of service condition on
|
||||
the client system when a user connects to the server.", "uri": "https://security-tracker.debian.org/tracker/CVE-2019-17498",
|
||||
"severity": "LOW", "attributes": [{"key": "package_version", "value": "1.8.0-2.1"},
|
||||
{"key": "package_name", "value": "libssh2"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:P/I:N/A:P"},
|
||||
{"key": "CVSS2_SCORE", "value": "5.8"}]}, {"name": "CVE-2019-17543", "description":
|
||||
"LZ4 before 1.9.2 has a heap-based buffer overflow in LZ4_write32 (related to LZ4_compress_destSize),
|
||||
affecting applications that call LZ4_compress_fast with a large input. (This issue
|
||||
can also lead to data corruption.) NOTE: the vendor states \"only a few specific
|
||||
/ uncommon usages of the API are at risk.\"", "uri": "https://security-tracker.debian.org/tracker/CVE-2019-17543",
|
||||
"severity": "LOW", "attributes": [{"key": "package_version", "value": "1.8.3-1+deb10u1"},
|
||||
{"key": "package_name", "value": "lz4"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:P/I:P/A:P"},
|
||||
{"key": "CVSS2_SCORE", "value": "6.8"}]}, {"name": "CVE-2013-0337", "description":
|
||||
"The default configuration of nginx, possibly 1.3.13 and earlier, uses world-readable
|
||||
permissions for the (1) access.log and (2) error.log files, which allows local users
|
||||
to obtain sensitive information by reading the files.", "uri": "https://security-tracker.debian.org/tracker/CVE-2013-0337",
|
||||
"severity": "LOW", "attributes": [{"key": "package_version", "value": "1.21.1-1~buster"},
|
||||
{"key": "package_name", "value": "nginx"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:L/Au:N/C:P/I:P/A:P"},
|
||||
{"key": "CVSS2_SCORE", "value": "7.5"}]}, {"name": "CVE-2018-7169", "description":
|
||||
"An issue was discovered in shadow 4.5. newgidmap (in shadow-utils) is setuid and
|
||||
allows an unprivileged user to be placed in a user namespace where setgroups(2)
|
||||
is permitted. This allows an attacker to remove themselves from a supplementary
|
||||
group, which may allow access to certain filesystem paths if the administrator has
|
||||
used \"group blacklisting\" (e.g., chmod g-rwx) to restrict access to paths. This
|
||||
flaw effectively reverts a security feature in the kernel (in particular, the /proc/self/setgroups
|
||||
knob) to prevent this sort of privilege escalation.", "uri": "https://security-tracker.debian.org/tracker/CVE-2018-7169",
|
||||
"severity": "LOW", "attributes": [{"key": "package_version", "value": "1:4.5-1.1"},
|
||||
{"key": "package_name", "value": "shadow"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:L/Au:N/C:P/I:N/A:N"},
|
||||
{"key": "CVSS2_SCORE", "value": "5"}]}, {"name": "CVE-2021-37600", "description":
|
||||
"An integer overflow in util-linux through 2.37.1 can potentially cause a buffer
|
||||
overflow if an attacker were able to use system resources in a way that leads to
|
||||
a large number in the /proc/sysvipc/sem file.", "uri": "https://security-tracker.debian.org/tracker/CVE-2021-37600",
|
||||
"severity": "LOW", "attributes": [{"key": "package_version", "value": "2.33.1-0.1"},
|
||||
{"key": "package_name", "value": "util-linux"}, {"key": "CVSS2_VECTOR", "value":
|
||||
"AV:N/AC:L/Au:N/C:P/I:P/A:P"}, {"key": "CVSS2_SCORE", "value": "7.5"}]}, {"name":
|
||||
"CVE-2011-3374", "description": "It was found that apt-key in apt, all versions,
|
||||
do not correctly validate gpg keys with the master keyring, leading to a potential
|
||||
man-in-the-middle attack.", "uri": "https://security-tracker.debian.org/tracker/CVE-2011-3374",
|
||||
"severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
|
||||
"1.8.2.3"}, {"key": "package_name", "value": "apt"}, {"key": "CVSS2_VECTOR", "value":
|
||||
"AV:N/AC:M/Au:N/C:N/I:P/A:N"}, {"key": "CVSS2_SCORE", "value": "4.3"}]}, {"name":
|
||||
"CVE-2019-18276", "description": "An issue was discovered in disable_priv_mode in
|
||||
shell.c in GNU Bash through 5.0 patch 11. By default, if Bash is run with its effective
|
||||
UID not equal to its real UID, it will drop privileges by setting its effective
|
||||
UID to its real UID. However, it does so incorrectly. On Linux and other systems
|
||||
that support \"saved UID\" functionality, the saved UID is not dropped. An attacker
|
||||
with command execution in the shell can use \"enable -f\" for runtime loading of
|
||||
a new builtin, which can be a shared object that calls setuid() and therefore regains
|
||||
privileges. However, binaries running with an effective UID of 0 are unaffected.",
|
||||
"uri": "https://security-tracker.debian.org/tracker/CVE-2019-18276", "severity":
|
||||
"INFORMATIONAL", "attributes": [{"key": "package_version", "value": "5.0-4"}, {"key":
|
||||
"package_name", "value": "bash"}, {"key": "CVSS2_VECTOR", "value": "AV:L/AC:L/Au:N/C:C/I:C/A:C"},
|
||||
{"key": "CVSS2_SCORE", "value": "7.2"}]}, {"name": "CVE-2017-18018", "description":
|
||||
"In GNU Coreutils through 8.29, chown-core.c in chown and chgrp does not prevent
|
||||
replacement of a plain file with a symlink during use of the POSIX \"-R -L\" options,
|
||||
which allows local users to modify the ownership of arbitrary files by leveraging
|
||||
a race condition.", "uri": "https://security-tracker.debian.org/tracker/CVE-2017-18018",
|
||||
"severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
|
||||
"8.30-3"}, {"key": "package_name", "value": "coreutils"}, {"key": "CVSS2_VECTOR",
|
||||
"value": "AV:L/AC:M/Au:N/C:N/I:P/A:N"}, {"key": "CVSS2_SCORE", "value": "1.9"}]},
|
||||
{"name": "CVE-2021-22923", "description": "When curl is instructed to get content
|
||||
using the metalink feature, and a user name and password are used to download the
|
||||
metalink XML file, those same credentials are then subsequently passed on to each
|
||||
of the servers from which curl will download or try to download the contents from.
|
||||
Often contrary to the user''s expectations and intentions and without telling the
|
||||
user it happened.", "uri": "https://security-tracker.debian.org/tracker/CVE-2021-22923",
|
||||
"severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
|
||||
"7.64.0-4+deb10u2"}, {"key": "package_name", "value": "curl"}]}, {"name": "CVE-2021-22922",
|
||||
"description": "When curl is instructed to download content using the metalink feature,
|
||||
thecontents is verified against a hash provided in the metalink XML file.The metalink
|
||||
XML file points out to the client how to get the same contentfrom a set of different
|
||||
URLs, potentially hosted by different servers and theclient can then download the
|
||||
file from one or several of them. In a serial orparallel manner.If one of the servers
|
||||
hosting the contents has been breached and the contentsof the specific file on that
|
||||
server is replaced with a modified payload, curlshould detect this when the hash
|
||||
of the file mismatches after a completeddownload. It should remove the contents
|
||||
and instead try getting the contentsfrom another URL. This is not done, and instead
|
||||
such a hash mismatch is onlymentioned in text and the potentially malicious content
|
||||
is kept in the file ondisk.", "uri": "https://security-tracker.debian.org/tracker/CVE-2021-22922",
|
||||
"severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
|
||||
"7.64.0-4+deb10u2"}, {"key": "package_name", "value": "curl"}]}, {"name": "CVE-2013-0340",
|
||||
"description": "expat 2.1.0 and earlier does not properly handle entities expansion
|
||||
unless an application developer uses the XML_SetEntityDeclHandler function, which
|
||||
allows remote attackers to cause a denial of service (resource consumption), send
|
||||
HTTP requests to intranet servers, or read arbitrary files via a crafted XML document,
|
||||
aka an XML External Entity (XXE) issue. NOTE: it could be argued that because expat
|
||||
already provides the ability to disable external entity expansion, the responsibility
|
||||
for resolving this issue lies with application developers; according to this argument,
|
||||
this entry should be REJECTed, and each affected application would need its own
|
||||
CVE.", "uri": "https://security-tracker.debian.org/tracker/CVE-2013-0340", "severity":
|
||||
"INFORMATIONAL", "attributes": [{"key": "package_version", "value": "2.2.6-2+deb10u1"},
|
||||
{"key": "package_name", "value": "expat"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:P/I:P/A:P"},
|
||||
{"key": "CVSS2_SCORE", "value": "6.8"}]}, {"name": "CVE-2019-1010023", "description":
|
||||
"** DISPUTED ** GNU Libc current is affected by: Re-mapping current loaded library
|
||||
with malicious ELF file. The impact is: In worst case attacker may evaluate privileges.
|
||||
The component is: libld. The attack vector is: Attacker sends 2 ELF files to victim
|
||||
and asks to run ldd on it. ldd execute code. NOTE: Upstream comments indicate \"this
|
||||
is being treated as a non-security bug and no real threat.\"", "uri": "https://security-tracker.debian.org/tracker/CVE-2019-1010023",
|
||||
"severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
|
||||
"2.28-10"}, {"key": "package_name", "value": "glibc"}, {"key": "CVSS2_VECTOR", "value":
|
||||
"AV:N/AC:M/Au:N/C:P/I:P/A:P"}, {"key": "CVSS2_SCORE", "value": "6.8"}]}, {"name":
|
||||
"CVE-2010-4051", "description": "The regcomp implementation in the GNU C Library
|
||||
(aka glibc or libc6) through 2.11.3, and 2.12.x through 2.12.2, allows context-dependent
|
||||
attackers to cause a denial of service (application crash) via a regular expression
|
||||
containing adjacent bounded repetitions that bypass the intended RE_DUP_MAX limitation,
|
||||
as demonstrated by a {10,}{10,}{10,}{10,}{10,} sequence in the proftpd.gnu.c exploit
|
||||
for ProFTPD, related to a \"RE_DUP_MAX overflow.\"", "uri": "https://security-tracker.debian.org/tracker/CVE-2010-4051",
|
||||
"severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
|
||||
"2.28-10"}, {"key": "package_name", "value": "glibc"}, {"key": "CVSS2_VECTOR", "value":
|
||||
"AV:N/AC:L/Au:N/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value": "5"}]}, {"name":
|
||||
"CVE-2019-1010022", "description": "** DISPUTED ** GNU Libc current is affected
|
||||
by: Mitigation bypass. The impact is: Attacker may bypass stack guard protection.
|
||||
The component is: nptl. The attack vector is: Exploit stack buffer overflow vulnerability
|
||||
and use this bypass vulnerability to bypass stack guard. NOTE: Upstream comments
|
||||
indicate \"this is being treated as a non-security bug and no real threat.\"", "uri":
|
||||
"https://security-tracker.debian.org/tracker/CVE-2019-1010022", "severity": "INFORMATIONAL",
|
||||
"attributes": [{"key": "package_version", "value": "2.28-10"}, {"key": "package_name",
|
||||
"value": "glibc"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:L/Au:N/C:P/I:P/A:P"},
|
||||
{"key": "CVSS2_SCORE", "value": "7.5"}]}, {"name": "CVE-2010-4052", "description":
|
||||
"Stack consumption vulnerability in the regcomp implementation in the GNU C Library
|
||||
(aka glibc or libc6) through 2.11.3, and 2.12.x through 2.12.2, allows context-dependent
|
||||
attackers to cause a denial of service (resource exhaustion) via a regular expression
|
||||
containing adjacent repetition operators, as demonstrated by a {10,}{10,}{10,}{10,}
|
||||
sequence in the proftpd.gnu.c exploit for ProFTPD.", "uri": "https://security-tracker.debian.org/tracker/CVE-2010-4052",
|
||||
"severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
|
||||
"2.28-10"}, {"key": "package_name", "value": "glibc"}, {"key": "CVSS2_VECTOR", "value":
|
||||
"AV:N/AC:L/Au:N/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value": "5"}]}, {"name":
|
||||
"CVE-2019-1010024", "description": "** DISPUTED ** GNU Libc current is affected
|
||||
by: Mitigation bypass. The impact is: Attacker may bypass ASLR using cache of thread
|
||||
stack and heap. The component is: glibc. NOTE: Upstream comments indicate \"this
|
||||
is being treated as a non-security bug and no real threat.\"", "uri": "https://security-tracker.debian.org/tracker/CVE-2019-1010024",
|
||||
"severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
|
||||
"2.28-10"}, {"key": "package_name", "value": "glibc"}, {"key": "CVSS2_VECTOR", "value":
|
||||
"AV:N/AC:L/Au:N/C:P/I:N/A:N"}, {"key": "CVSS2_SCORE", "value": "5"}]}, {"name":
|
||||
"CVE-2010-4756", "description": "The glob implementation in the GNU C Library (aka
|
||||
glibc or libc6) allows remote authenticated users to cause a denial of service (CPU
|
||||
and memory consumption) via crafted glob expressions that do not match any pathnames,
|
||||
as demonstrated by glob expressions in STAT commands to an FTP daemon, a different
|
||||
vulnerability than CVE-2010-2632.", "uri": "https://security-tracker.debian.org/tracker/CVE-2010-4756",
|
||||
"severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
|
||||
"2.28-10"}, {"key": "package_name", "value": "glibc"}, {"key": "CVSS2_VECTOR", "value":
|
||||
"AV:N/AC:L/Au:S/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value": "4"}]}, {"name":
|
||||
"CVE-2019-1010025", "description": "** DISPUTED ** GNU Libc current is affected
|
||||
by: Mitigation bypass. The impact is: Attacker may guess the heap addresses of pthread_created
|
||||
thread. The component is: glibc. NOTE: the vendor''s position is \"ASLR bypass itself
|
||||
is not a vulnerability.\"", "uri": "https://security-tracker.debian.org/tracker/CVE-2019-1010025",
|
||||
"severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
|
||||
"2.28-10"}, {"key": "package_name", "value": "glibc"}, {"key": "CVSS2_VECTOR", "value":
|
||||
"AV:N/AC:L/Au:N/C:P/I:N/A:N"}, {"key": "CVSS2_SCORE", "value": "5"}]}, {"name":
|
||||
"CVE-2018-20796", "description": "In the GNU C Library (aka glibc or libc6) through
|
||||
2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion,
|
||||
as demonstrated by ''(\\227|)(\\\\1\\\\1|t1|\\\\\\2537)+'' in grep.", "uri": "https://security-tracker.debian.org/tracker/CVE-2018-20796",
|
||||
"severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
|
||||
"2.28-10"}, {"key": "package_name", "value": "glibc"}, {"key": "CVSS2_VECTOR", "value":
|
||||
"AV:N/AC:L/Au:N/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value": "5"}]}, {"name":
|
||||
"CVE-2019-9192", "description": "** DISPUTED ** In the GNU C Library (aka glibc
|
||||
or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled
|
||||
Recursion, as demonstrated by ''(|)(\\\\1\\\\1)*'' in grep, a different issue than
|
||||
CVE-2018-20796. NOTE: the software maintainer disputes that this is a vulnerability
|
||||
because the behavior occurs only with a crafted pattern.", "uri": "https://security-tracker.debian.org/tracker/CVE-2019-9192",
|
||||
"severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
|
||||
"2.28-10"}, {"key": "package_name", "value": "glibc"}, {"key": "CVSS2_VECTOR", "value":
|
||||
"AV:N/AC:L/Au:N/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value": "5"}]}, {"name":
|
||||
"CVE-2011-3389", "description": "The SSL protocol, as used in certain configurations
|
||||
in Microsoft Windows and Microsoft Internet Explorer, Mozilla Firefox, Google Chrome,
|
||||
Opera, and other products, encrypts data by using CBC mode with chained initialization
|
||||
vectors, which allows man-in-the-middle attackers to obtain plaintext HTTP headers
|
||||
via a blockwise chosen-boundary attack (BCBA) on an HTTPS session, in conjunction
|
||||
with JavaScript code that uses (1) the HTML5 WebSocket API, (2) the Java URLConnection
|
||||
API, or (3) the Silverlight WebClient API, aka a \"BEAST\" attack.", "uri": "https://security-tracker.debian.org/tracker/CVE-2011-3389",
|
||||
"severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
|
||||
"3.6.7-4+deb10u7"}, {"key": "package_name", "value": "gnutls28"}, {"key": "CVSS2_VECTOR",
|
||||
"value": "AV:N/AC:M/Au:N/C:P/I:N/A:N"}, {"key": "CVSS2_SCORE", "value": "4.3"}]},
|
||||
{"name": "CVE-2021-30535", "description": "Double free in ICU in Google Chrome prior
|
||||
to 91.0.4472.77 allowed a remote attacker to potentially exploit heap corruption
|
||||
via a crafted HTML page.", "uri": "https://security-tracker.debian.org/tracker/CVE-2021-30535",
|
||||
"severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
|
||||
"63.1-6+deb10u1"}, {"key": "package_name", "value": "icu"}, {"key": "CVSS2_VECTOR",
|
||||
"value": "AV:N/AC:M/Au:N/C:P/I:P/A:P"}, {"key": "CVSS2_SCORE", "value": "6.8"}]},
|
||||
{"name": "CVE-2017-9937", "description": "In LibTIFF 4.0.8, there is a memory malloc
|
||||
failure in tif_jbig.c. A crafted TIFF document can lead to an abort resulting in
|
||||
a remote denial of service attack.", "uri": "https://security-tracker.debian.org/tracker/CVE-2017-9937",
|
||||
"severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
|
||||
"2.1-3.1"}, {"key": "package_name", "value": "jbigkit"}, {"key": "CVSS2_VECTOR",
|
||||
"value": "AV:N/AC:M/Au:N/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value": "4.3"}]},
|
||||
{"name": "CVE-2018-5709", "description": "An issue was discovered in MIT Kerberos
|
||||
5 (aka krb5) through 1.16. There is a variable \"dbentry->n_key_data\" in kadmin/dbutil/dump.c
|
||||
that can store 16-bit data but unknowingly the developer has assigned a \"u4\" variable
|
||||
to it, which is for 32-bit data. An attacker can use this vulnerability to affect
|
||||
other artifacts of the database as we know that a Kerberos database dump file contains
|
||||
trusted data.", "uri": "https://security-tracker.debian.org/tracker/CVE-2018-5709",
|
||||
"severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
|
||||
"1.17-3+deb10u1"}, {"key": "package_name", "value": "krb5"}, {"key": "CVSS2_VECTOR",
|
||||
"value": "AV:N/AC:L/Au:N/C:N/I:P/A:N"}, {"key": "CVSS2_SCORE", "value": "5"}]},
|
||||
{"name": "CVE-2021-36222", "description": "ec_verify in kdc/kdc_preauth_ec.c in
|
||||
the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.18.4 and
|
||||
1.19.x before 1.19.2 allows remote attackers to cause a NULL pointer dereference
|
||||
and daemon crash. This occurs because a return value is not properly managed in
|
||||
a certain situation.", "uri": "https://security-tracker.debian.org/tracker/CVE-2021-36222",
|
||||
"severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
|
||||
"1.17-3+deb10u1"}, {"key": "package_name", "value": "krb5"}, {"key": "CVSS2_VECTOR",
|
||||
"value": "AV:N/AC:L/Au:N/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value": "5"}]},
|
||||
{"name": "CVE-2004-0971", "description": "The krb5-send-pr script in the kerberos5
|
||||
(krb5) package in Trustix Secure Linux 1.5 through 2.1, and possibly other operating
|
||||
systems, allows local users to overwrite files via a symlink attack on temporary
|
||||
files.", "uri": "https://security-tracker.debian.org/tracker/CVE-2004-0971", "severity":
|
||||
"INFORMATIONAL", "attributes": [{"key": "package_version", "value": "1.17-3+deb10u1"},
|
||||
{"key": "package_name", "value": "krb5"}, {"key": "CVSS2_VECTOR", "value": "AV:L/AC:L/Au:N/C:N/I:P/A:N"},
|
||||
{"key": "CVSS2_SCORE", "value": "2.1"}]}, {"name": "CVE-2018-6829", "description":
|
||||
"cipher/elgamal.c in Libgcrypt through 1.8.2, when used to encrypt messages directly,
|
||||
improperly encodes plaintexts, which allows attackers to obtain sensitive information
|
||||
by reading ciphertext data (i.e., it does not have semantic security in face of
|
||||
a ciphertext-only attack). The Decisional Diffie-Hellman (DDH) assumption does not
|
||||
hold for Libgcrypt''s ElGamal implementation.", "uri": "https://security-tracker.debian.org/tracker/CVE-2018-6829",
|
||||
"severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
|
||||
"1.8.4-5+deb10u1"}, {"key": "package_name", "value": "libgcrypt20"}, {"key": "CVSS2_VECTOR",
|
||||
"value": "AV:N/AC:L/Au:N/C:P/I:N/A:N"}, {"key": "CVSS2_SCORE", "value": "5"}]},
|
||||
{"name": "CVE-2018-11813", "description": "libjpeg 9c has a large loop because read_pixel
|
||||
in rdtarga.c mishandles EOF.", "uri": "https://security-tracker.debian.org/tracker/CVE-2018-11813",
|
||||
"severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
|
||||
"1:1.5.2-2+deb10u1"}, {"key": "package_name", "value": "libjpeg-turbo"}, {"key":
|
||||
"CVSS2_VECTOR", "value": "AV:N/AC:L/Au:N/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value":
|
||||
"5"}]}, {"name": "CVE-2020-17541", "description": "Libjpeg-turbo all version have
|
||||
a stack-based buffer overflow in the \"transform\" component. A remote attacker
|
||||
can send a malformed jpeg file to the service and cause arbitrary code execution
|
||||
or denial of service of the target service.", "uri": "https://security-tracker.debian.org/tracker/CVE-2020-17541",
|
||||
"severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
|
||||
"1:1.5.2-2+deb10u1"}, {"key": "package_name", "value": "libjpeg-turbo"}, {"key":
|
||||
"CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:P/I:P/A:P"}, {"key": "CVSS2_SCORE", "value":
|
||||
"6.8"}]}, {"name": "CVE-2017-15232", "description": "libjpeg-turbo 1.5.2 has a NULL
|
||||
Pointer Dereference in jdpostct.c and jquant1.c via a crafted JPEG file.", "uri":
|
||||
"https://security-tracker.debian.org/tracker/CVE-2017-15232", "severity": "INFORMATIONAL",
|
||||
"attributes": [{"key": "package_version", "value": "1:1.5.2-2+deb10u1"}, {"key":
|
||||
"package_name", "value": "libjpeg-turbo"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:N/I:N/A:P"},
|
||||
{"key": "CVSS2_SCORE", "value": "4.3"}]}, {"name": "CVE-2018-14048", "description":
|
||||
"An issue has been found in libpng 1.6.34. It is a SEGV in the function png_free_data
|
||||
in png.c, related to the recommended error handling for png_read_image.", "uri":
|
||||
"https://security-tracker.debian.org/tracker/CVE-2018-14048", "severity": "INFORMATIONAL",
|
||||
"attributes": [{"key": "package_version", "value": "1.6.36-6"}, {"key": "package_name",
|
||||
"value": "libpng1.6"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:N/I:N/A:P"},
|
||||
{"key": "CVSS2_SCORE", "value": "4.3"}]}, {"name": "CVE-2019-6129", "description":
|
||||
"** DISPUTED ** png_create_info_struct in png.c in libpng 1.6.36 has a memory leak,
|
||||
as demonstrated by pngcp. NOTE: a third party has stated \"I don''t think it is
|
||||
libpng''s job to free this buffer.\"", "uri": "https://security-tracker.debian.org/tracker/CVE-2019-6129",
|
||||
"severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
|
||||
"1.6.36-6"}, {"key": "package_name", "value": "libpng1.6"}, {"key": "CVSS2_VECTOR",
|
||||
"value": "AV:N/AC:M/Au:N/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value": "4.3"}]},
|
||||
{"name": "CVE-2018-14550", "description": "An issue has been found in third-party
|
||||
PNM decoding associated with libpng 1.6.35. It is a stack-based buffer overflow
|
||||
in the function get_token in pnm2png.c in pnm2png.", "uri": "https://security-tracker.debian.org/tracker/CVE-2018-14550",
|
||||
"severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
|
||||
"1.6.36-6"}, {"key": "package_name", "value": "libpng1.6"}, {"key": "CVSS2_VECTOR",
|
||||
"value": "AV:N/AC:M/Au:N/C:P/I:P/A:P"}, {"key": "CVSS2_SCORE", "value": "6.8"}]},
|
||||
{"name": "CVE-2019-9893", "description": "libseccomp before 2.4.0 did not correctly
|
||||
generate 64-bit syscall argument comparisons using the arithmetic operators (LT,
|
||||
GT, LE, GE), which might able to lead to bypassing seccomp filters and potential
|
||||
privilege escalations.", "uri": "https://security-tracker.debian.org/tracker/CVE-2019-9893",
|
||||
"severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
|
||||
"2.3.3-4"}, {"key": "package_name", "value": "libseccomp"}, {"key": "CVSS2_VECTOR",
|
||||
"value": "AV:N/AC:L/Au:N/C:P/I:P/A:P"}, {"key": "CVSS2_SCORE", "value": "7.5"}]},
|
||||
{"name": "CVE-2018-1000654", "description": "GNU Libtasn1-4.13 libtasn1-4.13 version
|
||||
libtasn1-4.13, libtasn1-4.12 contains a DoS, specifically CPU usage will reach 100%
|
||||
when running asn1Paser against the POC due to an issue in _asn1_expand_object_id(p_tree),
|
||||
after a long time, the program will be killed. This attack appears to be exploitable
|
||||
via parsing a crafted file.", "uri": "https://security-tracker.debian.org/tracker/CVE-2018-1000654",
|
||||
"severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
|
||||
"4.13-3"}, {"key": "package_name", "value": "libtasn1-6"}, {"key": "CVSS2_VECTOR",
|
||||
"value": "AV:N/AC:M/Au:N/C:N/I:N/A:C"}, {"key": "CVSS2_SCORE", "value": "7.1"}]},
|
||||
{"name": "CVE-2016-9085", "description": "Multiple integer overflows in libwebp
|
||||
allows attackers to have unspecified impact via unknown vectors.", "uri": "https://security-tracker.debian.org/tracker/CVE-2016-9085",
|
||||
"severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
|
||||
"0.6.1-2+deb10u1"}, {"key": "package_name", "value": "libwebp"}, {"key": "CVSS2_VECTOR",
|
||||
"value": "AV:L/AC:L/Au:N/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value": "2.1"}]},
|
||||
{"name": "CVE-2015-9019", "description": "In libxslt 1.1.29 and earlier, the EXSLT
|
||||
math.random function was not initialized with a random seed during startup, which
|
||||
could cause usage of this function to produce predictable outputs.", "uri": "https://security-tracker.debian.org/tracker/CVE-2015-9019",
|
||||
"severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
|
||||
"1.1.32-2.2~deb10u1"}, {"key": "package_name", "value": "libxslt"}, {"key": "CVSS2_VECTOR",
|
||||
"value": "AV:N/AC:L/Au:N/C:P/I:N/A:N"}, {"key": "CVSS2_SCORE", "value": "5"}]},
|
||||
{"name": "CVE-2009-4487", "description": "nginx 0.7.64 writes data to a log file
|
||||
without sanitizing non-printable characters, which might allow remote attackers
|
||||
to modify a window''s title, or possibly execute arbitrary commands or overwrite
|
||||
files, via an HTTP request containing an escape sequence for a terminal emulator.",
|
||||
"uri": "https://security-tracker.debian.org/tracker/CVE-2009-4487", "severity":
|
||||
"INFORMATIONAL", "attributes": [{"key": "package_version", "value": "1.21.1-1~buster"},
|
||||
{"key": "package_name", "value": "nginx"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:P/I:P/A:P"},
|
||||
{"key": "CVSS2_SCORE", "value": "6.8"}]}, {"name": "CVE-2020-15719", "description":
|
||||
"libldap in certain third-party OpenLDAP packages has a certificate-validation flaw
|
||||
when the third-party package is asserting RFC6125 support. It considers CN even
|
||||
when there is a non-matching subjectAltName (SAN). This is fixed in, for example,
|
||||
openldap-2.4.46-10.el8 in Red Hat Enterprise Linux.", "uri": "https://security-tracker.debian.org/tracker/CVE-2020-15719",
|
||||
"severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
|
||||
"2.4.47+dfsg-3+deb10u6"}, {"key": "package_name", "value": "openldap"}, {"key":
|
||||
"CVSS2_VECTOR", "value": "AV:N/AC:H/Au:N/C:P/I:P/A:N"}, {"key": "CVSS2_SCORE", "value":
|
||||
"4"}]}, {"name": "CVE-2015-3276", "description": "The nss_parse_ciphers function
|
||||
in libraries/libldap/tls_m.c in OpenLDAP does not properly parse OpenSSL-style multi-keyword
|
||||
mode cipher strings, which might cause a weaker than intended cipher to be used
|
||||
and allow remote attackers to have unspecified impact via unknown vectors.", "uri":
|
||||
"https://security-tracker.debian.org/tracker/CVE-2015-3276", "severity": "INFORMATIONAL",
|
||||
"attributes": [{"key": "package_version", "value": "2.4.47+dfsg-3+deb10u6"}, {"key":
|
||||
"package_name", "value": "openldap"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:L/Au:N/C:N/I:P/A:N"},
|
||||
{"key": "CVSS2_SCORE", "value": "5"}]}, {"name": "CVE-2017-14159", "description":
|
||||
"slapd in OpenLDAP 2.4.45 and earlier creates a PID file after dropping privileges
|
||||
to a non-root account, which might allow local users to kill arbitrary processes
|
||||
by leveraging access to this non-root account for PID file modification before a
|
||||
root script executes a \"kill `cat /pathname`\" command, as demonstrated by openldap-initscript.",
|
||||
"uri": "https://security-tracker.debian.org/tracker/CVE-2017-14159", "severity":
|
||||
"INFORMATIONAL", "attributes": [{"key": "package_version", "value": "2.4.47+dfsg-3+deb10u6"},
|
||||
{"key": "package_name", "value": "openldap"}, {"key": "CVSS2_VECTOR", "value": "AV:L/AC:M/Au:N/C:N/I:N/A:P"},
|
||||
{"key": "CVSS2_SCORE", "value": "1.9"}]}, {"name": "CVE-2017-17740", "description":
|
||||
"contrib/slapd-modules/nops/nops.c in OpenLDAP through 2.4.45, when both the nops
|
||||
module and the memberof overlay are enabled, attempts to free a buffer that was
|
||||
allocated on the stack, which allows remote attackers to cause a denial of service
|
||||
(slapd crash) via a member MODDN operation.", "uri": "https://security-tracker.debian.org/tracker/CVE-2017-17740",
|
||||
"severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
|
||||
"2.4.47+dfsg-3+deb10u6"}, {"key": "package_name", "value": "openldap"}, {"key":
|
||||
"CVSS2_VECTOR", "value": "AV:N/AC:L/Au:N/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value":
|
||||
"5"}]}, {"name": "CVE-2010-0928", "description": "OpenSSL 0.9.8i on the Gaisler
|
||||
Research LEON3 SoC on the Xilinx Virtex-II Pro FPGA uses a Fixed Width Exponentiation
|
||||
(FWE) algorithm for certain signature calculations, and does not verify the signature
|
||||
before providing it to a caller, which makes it easier for physically proximate
|
||||
attackers to determine the private key via a modified supply voltage for the microprocessor,
|
||||
related to a \"fault-based attack.\"", "uri": "https://security-tracker.debian.org/tracker/CVE-2010-0928",
|
||||
"severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
|
||||
"1.1.1d-0+deb10u6"}, {"key": "package_name", "value": "openssl"}, {"key": "CVSS2_VECTOR",
|
||||
"value": "AV:L/AC:H/Au:N/C:C/I:N/A:N"}, {"key": "CVSS2_SCORE", "value": "4"}]},
|
||||
{"name": "CVE-2007-6755", "description": "The NIST SP 800-90A default statement
|
||||
of the Dual Elliptic Curve Deterministic Random Bit Generation (Dual_EC_DRBG) algorithm
|
||||
contains point Q constants with a possible relationship to certain \"skeleton key\"
|
||||
values, which might allow context-dependent attackers to defeat cryptographic protection
|
||||
mechanisms by leveraging knowledge of those values. NOTE: this is a preliminary
|
||||
CVE for Dual_EC_DRBG; future research may provide additional details about point
|
||||
Q and associated attacks, and could potentially lead to a RECAST or REJECT of this
|
||||
CVE.", "uri": "https://security-tracker.debian.org/tracker/CVE-2007-6755", "severity":
|
||||
"INFORMATIONAL", "attributes": [{"key": "package_version", "value": "1.1.1d-0+deb10u6"},
|
||||
{"key": "package_name", "value": "openssl"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:P/I:P/A:N"},
|
||||
{"key": "CVSS2_SCORE", "value": "5.8"}]}, {"name": "CVE-2017-7246", "description":
|
||||
"Stack-based buffer overflow in the pcre32_copy_substring function in pcre_get.c
|
||||
in libpcre1 in PCRE 8.40 allows remote attackers to cause a denial of service (WRITE
|
||||
of size 268) or possibly have unspecified other impact via a crafted file.", "uri":
|
||||
"https://security-tracker.debian.org/tracker/CVE-2017-7246", "severity": "INFORMATIONAL",
|
||||
"attributes": [{"key": "package_version", "value": "2:8.39-12"}, {"key": "package_name",
|
||||
"value": "pcre3"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:P/I:P/A:P"},
|
||||
{"key": "CVSS2_SCORE", "value": "6.8"}]}, {"name": "CVE-2019-20838", "description":
|
||||
"libpcre in PCRE before 8.43 allows a subject buffer over-read in JIT when UTF is
|
||||
disabled, and \\X or \\R has more than one fixed quantifier, a related issue to
|
||||
CVE-2019-20454.", "uri": "https://security-tracker.debian.org/tracker/CVE-2019-20838",
|
||||
"severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
|
||||
"2:8.39-12"}, {"key": "package_name", "value": "pcre3"}, {"key": "CVSS2_VECTOR",
|
||||
"value": "AV:N/AC:M/Au:N/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value": "4.3"}]},
|
||||
{"name": "CVE-2017-7245", "description": "Stack-based buffer overflow in the pcre32_copy_substring
|
||||
function in pcre_get.c in libpcre1 in PCRE 8.40 allows remote attackers to cause
|
||||
a denial of service (WRITE of size 4) or possibly have unspecified other impact
|
||||
via a crafted file.", "uri": "https://security-tracker.debian.org/tracker/CVE-2017-7245",
|
||||
"severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
|
||||
"2:8.39-12"}, {"key": "package_name", "value": "pcre3"}, {"key": "CVSS2_VECTOR",
|
||||
"value": "AV:N/AC:M/Au:N/C:P/I:P/A:P"}, {"key": "CVSS2_SCORE", "value": "6.8"}]},
|
||||
{"name": "CVE-2017-16231", "description": "** DISPUTED ** In PCRE 8.41, after compiling,
|
||||
a pcretest load test PoC produces a crash overflow in the function match() in pcre_exec.c
|
||||
because of a self-recursive call. NOTE: third parties dispute the relevance of this
|
||||
report, noting that there are options that can be used to limit the amount of stack
|
||||
that is used.", "uri": "https://security-tracker.debian.org/tracker/CVE-2017-16231",
|
||||
"severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
|
||||
"2:8.39-12"}, {"key": "package_name", "value": "pcre3"}, {"key": "CVSS2_VECTOR",
|
||||
"value": "AV:L/AC:L/Au:N/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value": "2.1"}]},
|
||||
{"name": "CVE-2017-11164", "description": "In PCRE 8.41, the OP_KETRMAX feature
|
||||
in the match function in pcre_exec.c allows stack exhaustion (uncontrolled recursion)
|
||||
when processing a crafted regular expression.", "uri": "https://security-tracker.debian.org/tracker/CVE-2017-11164",
|
||||
"severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
|
||||
"2:8.39-12"}, {"key": "package_name", "value": "pcre3"}, {"key": "CVSS2_VECTOR",
|
||||
"value": "AV:N/AC:L/Au:N/C:N/I:N/A:C"}, {"key": "CVSS2_SCORE", "value": "7.8"}]},
|
||||
{"name": "CVE-2011-4116", "description": "_is_safe in the File::Temp module for
|
||||
Perl does not properly handle symlinks.", "uri": "https://security-tracker.debian.org/tracker/CVE-2011-4116",
|
||||
"severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
|
||||
"5.28.1-6+deb10u1"}, {"key": "package_name", "value": "perl"}, {"key": "CVSS2_VECTOR",
|
||||
"value": "AV:N/AC:L/Au:N/C:N/I:P/A:N"}, {"key": "CVSS2_SCORE", "value": "5"}]},
|
||||
{"name": "CVE-2019-19882", "description": "shadow 4.8, in certain circumstances
|
||||
affecting at least Gentoo, Arch Linux, and Void Linux, allows local users to obtain
|
||||
root access because setuid programs are misconfigured. Specifically, this affects
|
||||
shadow 4.8 when compiled using --with-libpam but without explicitly passing --disable-account-tools-setuid,
|
||||
and without a PAM configuration suitable for use with setuid account management
|
||||
tools. This combination leads to account management tools (groupadd, groupdel, groupmod,
|
||||
useradd, userdel, usermod) that can easily be used by unprivileged local users to
|
||||
escalate privileges to root in multiple ways. This issue became much more relevant
|
||||
in approximately December 2019 when an unrelated bug was fixed (i.e., the chmod
|
||||
calls to suidusbins were fixed in the upstream Makefile which is now included in
|
||||
the release version 4.8).", "uri": "https://security-tracker.debian.org/tracker/CVE-2019-19882",
|
||||
"severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
|
||||
"1:4.5-1.1"}, {"key": "package_name", "value": "shadow"}, {"key": "CVSS2_VECTOR",
|
||||
"value": "AV:L/AC:M/Au:N/C:C/I:C/A:C"}, {"key": "CVSS2_SCORE", "value": "6.9"}]},
|
||||
{"name": "CVE-2007-5686", "description": "initscripts in rPath Linux 1 sets insecure
|
||||
permissions for the /var/log/btmp file, which allows local users to obtain sensitive
|
||||
information regarding authentication attempts. NOTE: because sshd detects the insecure
|
||||
permissions and does not log certain events, this also prevents sshd from logging
|
||||
failed authentication attempts by remote attackers.", "uri": "https://security-tracker.debian.org/tracker/CVE-2007-5686",
|
||||
"severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
|
||||
"1:4.5-1.1"}, {"key": "package_name", "value": "shadow"}, {"key": "CVSS2_VECTOR",
|
||||
"value": "AV:L/AC:L/Au:N/C:C/I:N/A:N"}, {"key": "CVSS2_SCORE", "value": "4.9"}]},
|
||||
{"name": "CVE-2013-4235", "description": "shadow: TOCTOU (time-of-check time-of-use)
|
||||
race condition when copying and removing directory trees", "uri": "https://security-tracker.debian.org/tracker/CVE-2013-4235",
|
||||
"severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
|
||||
"1:4.5-1.1"}, {"key": "package_name", "value": "shadow"}, {"key": "CVSS2_VECTOR",
|
||||
"value": "AV:L/AC:M/Au:N/C:N/I:P/A:P"}, {"key": "CVSS2_SCORE", "value": "3.3"}]},
|
||||
{"name": "CVE-2020-13529", "description": "An exploitable denial-of-service vulnerability
|
||||
exists in Systemd 245. A specially crafted DHCP FORCERENEW packet can cause a server
|
||||
running the DHCP client to be vulnerable to a DHCP ACK spoofing attack. An attacker
|
||||
can forge a pair of FORCERENEW and DCHP ACK packets to reconfigure the server.",
|
||||
"uri": "https://security-tracker.debian.org/tracker/CVE-2020-13529", "severity":
|
||||
"INFORMATIONAL", "attributes": [{"key": "package_version", "value": "241-7~deb10u8"},
|
||||
{"key": "package_name", "value": "systemd"}, {"key": "CVSS2_VECTOR", "value": "AV:A/AC:M/Au:N/C:N/I:N/A:P"},
|
||||
{"key": "CVSS2_SCORE", "value": "2.9"}]}, {"name": "CVE-2013-4392", "description":
|
||||
"systemd, when updating file permissions, allows local users to change the permissions
|
||||
and SELinux security contexts for arbitrary files via a symlink attack on unspecified
|
||||
files.", "uri": "https://security-tracker.debian.org/tracker/CVE-2013-4392", "severity":
|
||||
"INFORMATIONAL", "attributes": [{"key": "package_version", "value": "241-7~deb10u8"},
|
||||
{"key": "package_name", "value": "systemd"}, {"key": "CVSS2_VECTOR", "value": "AV:L/AC:M/Au:N/C:P/I:P/A:N"},
|
||||
{"key": "CVSS2_SCORE", "value": "3.3"}]}, {"name": "CVE-2020-13776", "description":
|
||||
"systemd through v245 mishandles numerical usernames such as ones composed of decimal
|
||||
digits or 0x followed by hex digits, as demonstrated by use of root privileges when
|
||||
privileges of the 0x0 user account were intended. NOTE: this issue exists because
|
||||
of an incomplete fix for CVE-2017-1000082.", "uri": "https://security-tracker.debian.org/tracker/CVE-2020-13776",
|
||||
"severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
|
||||
"241-7~deb10u8"}, {"key": "package_name", "value": "systemd"}, {"key": "CVSS2_VECTOR",
|
||||
"value": "AV:L/AC:H/Au:N/C:C/I:C/A:C"}, {"key": "CVSS2_SCORE", "value": "6.2"}]},
|
||||
{"name": "CVE-2019-20386", "description": "An issue was discovered in button_open
|
||||
in login/logind-button.c in systemd before 243. When executing the udevadm trigger
|
||||
command, a memory leak may occur.", "uri": "https://security-tracker.debian.org/tracker/CVE-2019-20386",
|
||||
"severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
|
||||
"241-7~deb10u8"}, {"key": "package_name", "value": "systemd"}, {"key": "CVSS2_VECTOR",
|
||||
"value": "AV:L/AC:L/Au:N/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value": "2.1"}]},
|
||||
{"name": "CVE-2019-9923", "description": "pax_decode_header in sparse.c in GNU Tar
|
||||
before 1.32 had a NULL pointer dereference when parsing certain archives that have
|
||||
malformed extended headers.", "uri": "https://security-tracker.debian.org/tracker/CVE-2019-9923",
|
||||
"severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
|
||||
"1.30+dfsg-6"}, {"key": "package_name", "value": "tar"}, {"key": "CVSS2_VECTOR",
|
||||
"value": "AV:N/AC:L/Au:N/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value": "5"}]},
|
||||
{"name": "CVE-2005-2541", "description": "Tar 1.15.1 does not properly warn the
|
||||
user when extracting setuid or setgid files, which may allow local users or remote
|
||||
attackers to gain privileges.", "uri": "https://security-tracker.debian.org/tracker/CVE-2005-2541",
|
||||
"severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
|
||||
"1.30+dfsg-6"}, {"key": "package_name", "value": "tar"}, {"key": "CVSS2_VECTOR",
|
||||
"value": "AV:N/AC:L/Au:N/C:C/I:C/A:C"}, {"key": "CVSS2_SCORE", "value": "10"}]},
|
||||
{"name": "CVE-2021-20193", "description": "A flaw was found in the src/list.c of
|
||||
tar 1.33 and earlier. This flaw allows an attacker who can submit a crafted input
|
||||
file to tar to cause uncontrolled consumption of memory. The highest threat from
|
||||
this vulnerability is to system availability.", "uri": "https://security-tracker.debian.org/tracker/CVE-2021-20193",
|
||||
"severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
|
||||
"1.30+dfsg-6"}, {"key": "package_name", "value": "tar"}, {"key": "CVSS2_VECTOR",
|
||||
"value": "AV:N/AC:M/Au:N/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value": "4.3"}]},
|
||||
{"name": "CVE-2017-17973", "description": "** DISPUTED ** In LibTIFF 4.0.8, there
|
||||
is a heap-based use-after-free in the t2p_writeproc function in tiff2pdf.c. NOTE:
|
||||
there is a third-party report of inability to reproduce this issue.", "uri": "https://security-tracker.debian.org/tracker/CVE-2017-17973",
|
||||
"severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
|
||||
"4.1.0+git191117-2~deb10u2"}, {"key": "package_name", "value": "tiff"}, {"key":
|
||||
"CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:P/I:P/A:P"}, {"key": "CVSS2_SCORE", "value":
|
||||
"6.8"}]}, {"name": "CVE-2020-35521", "description": "A flaw was found in libtiff.
|
||||
Due to a memory allocation failure in tif_read.c, a crafted TIFF file can lead to
|
||||
an abort, resulting in denial of service.", "uri": "https://security-tracker.debian.org/tracker/CVE-2020-35521",
|
||||
"severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
|
||||
"4.1.0+git191117-2~deb10u2"}, {"key": "package_name", "value": "tiff"}, {"key":
|
||||
"CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value":
|
||||
"4.3"}]}, {"name": "CVE-2014-8130", "description": "The _TIFFmalloc function in
|
||||
tif_unix.c in LibTIFF 4.0.3 does not reject a zero size, which allows remote attackers
|
||||
to cause a denial of service (divide-by-zero error and application crash) via a
|
||||
crafted TIFF image that is mishandled by the TIFFWriteScanline function in tif_write.c,
|
||||
as demonstrated by tiffdither.", "uri": "https://security-tracker.debian.org/tracker/CVE-2014-8130",
|
||||
"severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
|
||||
"4.1.0+git191117-2~deb10u2"}, {"key": "package_name", "value": "tiff"}, {"key":
|
||||
"CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value":
|
||||
"4.3"}]}, {"name": "CVE-2017-5563", "description": "LibTIFF version 4.0.7 is vulnerable
|
||||
to a heap-based buffer over-read in tif_lzw.c resulting in DoS or code execution
|
||||
via a crafted bmp image to tools/bmp2tiff.", "uri": "https://security-tracker.debian.org/tracker/CVE-2017-5563",
|
||||
"severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
|
||||
"4.1.0+git191117-2~deb10u2"}, {"key": "package_name", "value": "tiff"}, {"key":
|
||||
"CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:P/I:P/A:P"}, {"key": "CVSS2_SCORE", "value":
|
||||
"6.8"}]}, {"name": "CVE-2020-35522", "description": "In LibTIFF, there is a memory
|
||||
malloc failure in tif_pixarlog.c. A crafted TIFF document can lead to an abort,
|
||||
resulting in a remote denial of service attack.", "uri": "https://security-tracker.debian.org/tracker/CVE-2020-35522",
|
||||
"severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
|
||||
"4.1.0+git191117-2~deb10u2"}, {"key": "package_name", "value": "tiff"}, {"key":
|
||||
"CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value":
|
||||
"4.3"}]}, {"name": "CVE-2017-9117", "description": "In LibTIFF 4.0.7, the program
|
||||
processes BMP images without verifying that biWidth and biHeight in the bitmap-information
|
||||
header match the actual input, leading to a heap-based buffer over-read in bmp2tiff.",
|
||||
"uri": "https://security-tracker.debian.org/tracker/CVE-2017-9117", "severity":
|
||||
"INFORMATIONAL", "attributes": [{"key": "package_version", "value": "4.1.0+git191117-2~deb10u2"},
|
||||
{"key": "package_name", "value": "tiff"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:L/Au:N/C:P/I:P/A:P"},
|
||||
{"key": "CVSS2_SCORE", "value": "7.5"}]}, {"name": "CVE-2017-16232", "description":
|
||||
"** DISPUTED ** LibTIFF 4.0.8 has multiple memory leak vulnerabilities, which allow
|
||||
attackers to cause a denial of service (memory consumption), as demonstrated by
|
||||
tif_open.c, tif_lzw.c, and tif_aux.c. NOTE: Third parties were unable to reproduce
|
||||
the issue.", "uri": "https://security-tracker.debian.org/tracker/CVE-2017-16232",
|
||||
"severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
|
||||
"4.1.0+git191117-2~deb10u2"}, {"key": "package_name", "value": "tiff"}, {"key":
|
||||
"CVSS2_VECTOR", "value": "AV:N/AC:L/Au:N/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value":
|
||||
"5"}]}, {"name": "CVE-2018-10126", "description": "LibTIFF 4.0.9 has a NULL pointer
|
||||
dereference in the jpeg_fdct_16x16 function in jfdctint.c.", "uri": "https://security-tracker.debian.org/tracker/CVE-2018-10126",
|
||||
"severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
|
||||
"4.1.0+git191117-2~deb10u2"}, {"key": "package_name", "value": "tiff"}, {"key":
|
||||
"CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value":
|
||||
"4.3"}]}, {"name": "CVE-2021-22924", "description": "libcurl keeps previously used
|
||||
connections in a connection pool for subsequenttransfers to reuse, if one of them
|
||||
matches the setup.Due to errors in the logic, the config matching function did not
|
||||
take ''issuercert'' into account and it compared the involved paths *case insensitively*,which
|
||||
could lead to libcurl reusing wrong connections.File paths are, or can be, case
|
||||
sensitive on many systems but not all, and caneven vary depending on used file systems.The
|
||||
comparison also didn''t include the ''issuer cert'' which a transfer can setto qualify
|
||||
how to verify the server certificate.", "uri": "https://security-tracker.debian.org/tracker/CVE-2021-22924",
|
||||
"severity": "UNDEFINED", "attributes": [{"key": "package_version", "value": "7.64.0-4+deb10u2"},
|
||||
{"key": "package_name", "value": "curl"}]}, {"name": "CVE-2021-38115", "description":
|
||||
"read_header_tga in gd_tga.c in the GD Graphics Library (aka LibGD) through 2.3.2
|
||||
allows remote attackers to cause a denial of service (out-of-bounds read) via a
|
||||
crafted TGA file.", "uri": "https://security-tracker.debian.org/tracker/CVE-2021-38115",
|
||||
"severity": "UNDEFINED", "attributes": [{"key": "package_version", "value": "2.2.5-5.2"},
|
||||
{"key": "package_name", "value": "libgd2"}]}, {"name": "CVE-2021-3618", "uri": "https://security-tracker.debian.org/tracker/CVE-2021-3618",
|
||||
"severity": "UNDEFINED", "attributes": [{"key": "package_version", "value": "1.21.1-1~buster"},
|
||||
{"key": "package_name", "value": "nginx"}]}], "findingSeverityCounts": {"HIGH":
|
||||
2, "MEDIUM": 14, "INFORMATIONAL": 63, "LOW": 22, "UNDEFINED": 3}}}, "requestID":
|
||||
"23c19e2d-c48b-4265-b4eb-853e7b325780", "eventID": "6c94a9b2-36dc-43f8-a6dd-4ec839ded8af",
|
||||
"readOnly": true, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId":
|
||||
"111111111111", "eventCategory": "Management"}'
|
||||
@@ -0,0 +1,99 @@
|
||||
name: AWS CloudTrail GetAccountPasswordPolicy
|
||||
id: 439bdc53-6e4b-4cd7-b326-86c7317fd396
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for AWS CloudTrail GetAccountPasswordPolicy
|
||||
source: aws_cloudtrail
|
||||
sourcetype: aws:cloudtrail
|
||||
separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Amazon Web Services (AWS)
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.4.1
|
||||
fields:
|
||||
- _time
|
||||
- action
|
||||
- app
|
||||
- awsRegion
|
||||
- aws_account_id
|
||||
- change_type
|
||||
- command
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- desc
|
||||
- dest
|
||||
- dvc
|
||||
- errorCode
|
||||
- eventCategory
|
||||
- eventID
|
||||
- eventName
|
||||
- eventSource
|
||||
- eventTime
|
||||
- eventType
|
||||
- eventVersion
|
||||
- host
|
||||
- index
|
||||
- linecount
|
||||
- managementEvent
|
||||
- msg
|
||||
- object_category
|
||||
- product
|
||||
- punct
|
||||
- readOnly
|
||||
- recipientAccountId
|
||||
- region
|
||||
- requestID
|
||||
- requestParameters
|
||||
- responseElements
|
||||
- signature
|
||||
- source
|
||||
- sourceIPAddress
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- src
|
||||
- src_ip
|
||||
- start_time
|
||||
- status
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
- tlsDetails.cipherSuite
|
||||
- tlsDetails.clientProvidedHostHeader
|
||||
- tlsDetails.tlsVersion
|
||||
- user
|
||||
- userAgent
|
||||
- userIdentity.accessKeyId
|
||||
- userIdentity.accountId
|
||||
- userIdentity.arn
|
||||
- userIdentity.principalId
|
||||
- userIdentity.type
|
||||
- userIdentity.userName
|
||||
- userName
|
||||
- user_access_key
|
||||
- user_agent
|
||||
- user_arn
|
||||
- user_group_id
|
||||
- user_id
|
||||
- user_name
|
||||
- user_type
|
||||
- vendor
|
||||
- vendor_account
|
||||
- vendor_product
|
||||
- vendor_region
|
||||
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId":
|
||||
"AIDASBMSCQHHTH5NDF4GD", "arn": "arn:aws:iam::111111111111:user/strt_fonder", "accountId":
|
||||
"111111111111", "accessKeyId": "AKIASBMSCQHH5A5NJDM5", "userName": "strt_fonder"},
|
||||
"eventTime": "2023-01-26T22:39:06Z", "eventSource": "iam.amazonaws.com", "eventName":
|
||||
"GetAccountPasswordPolicy", "awsRegion": "us-east-1", "sourceIPAddress": "23.93.193.7",
|
||||
"userAgent": "aws-cli/2.7.25 Python/3.10.6 Darwin/21.6.0 source/x86_64 prompt/off
|
||||
command/iam.get-account-password-policy", "requestParameters": null, "responseElements":
|
||||
null, "requestID": "098fd0dd-e42e-4249-91fb-9637925bf2fe", "eventID": "5eb0fb9b-18ff-4be9-b90d-107a290e1d5c",
|
||||
"readOnly": true, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId":
|
||||
"111111111111", "eventCategory": "Management", "tlsDetails": {"tlsVersion": "TLSv1.2",
|
||||
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256", "clientProvidedHostHeader": "iam.amazonaws.com"}}'
|
||||
@@ -0,0 +1,113 @@
|
||||
name: AWS CloudTrail GetObject
|
||||
id: 5063cb10-84c0-44af-ade4-ab9ecad11dfe
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for AWS CloudTrail GetObject
|
||||
source: aws_cloudtrail
|
||||
sourcetype: aws:cloudtrail
|
||||
separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Amazon Web Services (AWS)
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.4.1
|
||||
fields:
|
||||
- _time
|
||||
- additionalEventData.AuthenticationMethod
|
||||
- additionalEventData.CipherSuite
|
||||
- additionalEventData.SignatureVersion
|
||||
- additionalEventData.bytesTransferredIn
|
||||
- additionalEventData.bytesTransferredOut
|
||||
- additionalEventData.x-amz-id-2
|
||||
- app
|
||||
- awsRegion
|
||||
- aws_account_id
|
||||
- command
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- dest
|
||||
- dvc
|
||||
- errorCode
|
||||
- eventCategory
|
||||
- eventID
|
||||
- eventName
|
||||
- eventSource
|
||||
- eventTime
|
||||
- eventType
|
||||
- eventVersion
|
||||
- host
|
||||
- index
|
||||
- linecount
|
||||
- managementEvent
|
||||
- msg
|
||||
- object_category
|
||||
- product
|
||||
- punct
|
||||
- readOnly
|
||||
- recipientAccountId
|
||||
- region
|
||||
- requestID
|
||||
- requestParameters.Host
|
||||
- requestParameters.bucketName
|
||||
- requestParameters.key
|
||||
- requestParameters.x-amz-request-payer
|
||||
- resources{}.ARN
|
||||
- resources{}.accountId
|
||||
- resources{}.type
|
||||
- responseElements
|
||||
- signature
|
||||
- source
|
||||
- sourceIPAddress
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- src
|
||||
- src_ip
|
||||
- start_time
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
- tlsDetails.cipherSuite
|
||||
- tlsDetails.clientProvidedHostHeader
|
||||
- tlsDetails.tlsVersion
|
||||
- user
|
||||
- userAgent
|
||||
- userIdentity.accessKeyId
|
||||
- userIdentity.accountId
|
||||
- userIdentity.arn
|
||||
- userIdentity.principalId
|
||||
- userIdentity.type
|
||||
- userIdentity.userName
|
||||
- userName
|
||||
- user_access_key
|
||||
- user_agent
|
||||
- user_arn
|
||||
- user_group_id
|
||||
- user_id
|
||||
- user_name
|
||||
- user_type
|
||||
- vendor
|
||||
- vendor_account
|
||||
- vendor_product
|
||||
- vendor_region
|
||||
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId":
|
||||
"AIDAYTOGP2RLCNEAQXWZV", "arn": "arn:aws:iam::111111111111:user/console", "accountId":
|
||||
"111111111111", "accessKeyId": "AKIAYTOGP2RLF5EAXXXX", "userName": "console"}, "eventTime":
|
||||
"2023-04-11T01:18:47Z", "eventSource": "s3.amazonaws.com", "eventName": "GetObject",
|
||||
"awsRegion": "us-west-2", "sourceIPAddress": "12.26.0.38", "userAgent": "[aws-cli/2.11.2
|
||||
Python/3.11.2 Darwin/22.3.0 exe/x86_64 prompt/off command/s3.cp]", "requestParameters":
|
||||
{"bucketName": "security-content", "Host": "security-content.s3.us-west-2.amazonaws.com",
|
||||
"x-amz-request-payer": "requester", "key": "stories/windows_discovery_techniques.yml"},
|
||||
"responseElements": null, "additionalEventData": {"SignatureVersion": "SigV4", "CipherSuite":
|
||||
"ECDHE-RSA-AES128-GCM-SHA256", "bytesTransferredIn": 0, "AuthenticationMethod":
|
||||
"AuthHeader", "x-amz-id-2": "dcha0yrujT+O4FHsYxHx48KxMk4+wtO7MaNRwFOFs46R1PynKWcCsbLScYEFytN+Vt35hyq1cek=",
|
||||
"bytesTransferredOut": 1136}, "requestID": "GVSEBM08Z93FB3BT", "eventID": "2b7231c2-892d-464e-8880-1e4f81ae7eb2",
|
||||
"readOnly": true, "resources": [{"type": "AWS::S3::Object", "ARN": "arn:aws:s3:::security-content/stories/windows_discovery_techniques.yml"},
|
||||
{"accountId": "111111111111", "type": "AWS::S3::Bucket", "ARN": "arn:aws:s3:::security-content"}],
|
||||
"eventType": "AwsApiCall", "managementEvent": false, "recipientAccountId": "111111111111",
|
||||
"eventCategory": "Data", "tlsDetails": {"tlsVersion": "TLSv1.2", "cipherSuite":
|
||||
"ECDHE-RSA-AES128-GCM-SHA256", "clientProvidedHostHeader": "security-content.s3.us-west-2.amazonaws.com"}}'
|
||||
@@ -0,0 +1,115 @@
|
||||
name: AWS CloudTrail GetPasswordData
|
||||
id: 6ff2ce99-85b1-4c17-888a-56dbc3570671
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for AWS CloudTrail GetPasswordData
|
||||
source: aws_cloudtrail
|
||||
sourcetype: aws:cloudtrail
|
||||
separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Amazon Web Services (AWS)
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.4.1
|
||||
fields:
|
||||
- _time
|
||||
- app
|
||||
- awsRegion
|
||||
- aws_account_id
|
||||
- change_type
|
||||
- command
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- dest
|
||||
- dvc
|
||||
- errorCode
|
||||
- errorMessage
|
||||
- eventCategory
|
||||
- eventID
|
||||
- eventName
|
||||
- eventSource
|
||||
- eventTime
|
||||
- eventType
|
||||
- eventVersion
|
||||
- eventtype
|
||||
- host
|
||||
- index
|
||||
- linecount
|
||||
- managementEvent
|
||||
- msg
|
||||
- object_category
|
||||
- product
|
||||
- punct
|
||||
- readOnly
|
||||
- reason
|
||||
- recipientAccountId
|
||||
- region
|
||||
- requestID
|
||||
- requestParameters.instanceId
|
||||
- responseElements
|
||||
- result
|
||||
- result_id
|
||||
- signature
|
||||
- source
|
||||
- sourceIPAddress
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- src
|
||||
- src_ip
|
||||
- start_time
|
||||
- tag
|
||||
- tag::eventtype
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
- tlsDetails.cipherSuite
|
||||
- tlsDetails.clientProvidedHostHeader
|
||||
- tlsDetails.tlsVersion
|
||||
- user
|
||||
- userAgent
|
||||
- userIdentity.accessKeyId
|
||||
- userIdentity.accountId
|
||||
- userIdentity.arn
|
||||
- userIdentity.principalId
|
||||
- userIdentity.sessionContext.attributes.creationDate
|
||||
- userIdentity.sessionContext.attributes.mfaAuthenticated
|
||||
- userIdentity.sessionContext.sessionIssuer.accountId
|
||||
- userIdentity.sessionContext.sessionIssuer.arn
|
||||
- userIdentity.sessionContext.sessionIssuer.principalId
|
||||
- userIdentity.sessionContext.sessionIssuer.type
|
||||
- userIdentity.sessionContext.sessionIssuer.userName
|
||||
- userIdentity.type
|
||||
- userName
|
||||
- user_access_key
|
||||
- user_agent
|
||||
- user_arn
|
||||
- user_group_id
|
||||
- user_id
|
||||
- user_name
|
||||
- user_type
|
||||
- vendor
|
||||
- vendor_account
|
||||
- vendor_product
|
||||
- vendor_region
|
||||
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "principalId":
|
||||
"AROAYTOGP2RLP5AASA6I5:aws-go-sdk-1660169051746043000", "arn": "arn:aws:sts::111111111111:assumed-role/sample-role-used-by-stratus-for-ec2-password-data/aws-go-sdk-1660169051746043000",
|
||||
"accountId": "111111111111", "accessKeyId": "ASIAYTOGP2RLLY5RQXEF", "sessionContext":
|
||||
{"sessionIssuer": {"type": "Role", "principalId": "AROAYTOGP2RLP5AASA6I5", "arn":
|
||||
"arn:aws:iam::111111111111:role/sample-role-used-by-stratus-for-ec2-password-data",
|
||||
"accountId": "111111111111", "userName": "sample-role-used-by-stratus-for-ec2-password-data"},
|
||||
"webIdFederationData": {}, "attributes": {"creationDate": "2022-08-10T22:04:12Z",
|
||||
"mfaAuthenticated": "false"}}}, "eventTime": "2022-08-10T22:04:13Z", "eventSource":
|
||||
"ec2.amazonaws.com", "eventName": "GetPasswordData", "awsRegion": "us-west-2", "sourceIPAddress":
|
||||
"142.254.89.27", "userAgent": "stratus-red-team_e3e4b259-63a4-4d89-acd5-a7286a279bb8",
|
||||
"errorCode": "Client.UnauthorizedOperation", "errorMessage": "You are not authorized
|
||||
to perform this operation. Encoded authorization failure message: OwnXKlWs2vtfsyXhkYTFO35PfDwIeH4oGadP2dmbdguXBDpSfP-65XwZU4JdWht_u8p9BlgIZ0QOYIzmm5-ApXc7HsgOynmQvF4vFNUxxiuY0w-VRNBiuPmphwnJqYln8pTJogn0DfcleY5TIuDEFwmGvZHnGMmK1kXJ1VcUiQvbK_vuDpSqIDFz-jqcnOTjzsC4DXlTZkHLL1HEeNVIjI9HCEWYG4CuG9Ti8BQ0AnGVkU8oqvtS6iyVlnPI9oId5_AWpfmE1ijhNKbgFH77DjRn6QyR5rGkGYYFpvaIyMvX33Vti4RzfAyJdpuzMgp6tV-q_Rbh0ikwBJvUtiiGfmqzdQynfRNDQmXJ3ruifOjGmUz34M90SGFJKi5CVHGThtO3UWj9EqYXpKdu_JgTYEqxWvRBopB--V7tOap8XKuz7W3rWyHN2clHA0yooLZ3DV34LWgzzDp9Iv66829HSTwGz7h2P0sGdCNuV_FCxwQzWYa8f6_h1By90MvWUvmEDLSzOfA_PF6BcqCmV8XBiPUvCMPebDSGmPwSa371J5Yn2xEiuQadfuNYRLZnd2i1V_NF9ax67BdZ",
|
||||
"requestParameters": {"instanceId": "i-7sap2krlslv6adrs"}, "responseElements": null,
|
||||
"requestID": "87368810-7b30-4ff9-b097-702778a53f22", "eventID": "0cdd3757-296a-4454-9619-d0f8be335081",
|
||||
"readOnly": true, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId":
|
||||
"111111111111", "eventCategory": "Management", "tlsDetails": {"tlsVersion": "TLSv1.2",
|
||||
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256", "clientProvidedHostHeader": "ec2.us-west-2.amazonaws.com"}}'
|
||||
@@ -0,0 +1,84 @@
|
||||
name: AWS CloudTrail JobCreated
|
||||
id: 6473289b-d097-4c86-a837-3cc5ae408155
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for AWS CloudTrail JobCreated
|
||||
source: aws_cloudtrail
|
||||
sourcetype: aws:cloudtrail
|
||||
separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Amazon Web Services (AWS)
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.4.1
|
||||
fields:
|
||||
- _time
|
||||
- app
|
||||
- awsRegion
|
||||
- aws_account_id
|
||||
- command
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- desc
|
||||
- dest
|
||||
- dvc
|
||||
- errorCode
|
||||
- eventCategory
|
||||
- eventID
|
||||
- eventName
|
||||
- eventSource
|
||||
- eventTime
|
||||
- eventType
|
||||
- eventVersion
|
||||
- host
|
||||
- index
|
||||
- linecount
|
||||
- managementEvent
|
||||
- msg
|
||||
- object_category
|
||||
- product
|
||||
- punct
|
||||
- readOnly
|
||||
- recipientAccountId
|
||||
- region
|
||||
- requestParameters
|
||||
- responseElements
|
||||
- serviceEventDetails.jobArn
|
||||
- serviceEventDetails.jobEventId
|
||||
- serviceEventDetails.jobId
|
||||
- serviceEventDetails.status
|
||||
- signature
|
||||
- source
|
||||
- sourceIPAddress
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- src
|
||||
- src_ip
|
||||
- start_time
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
- userAgent
|
||||
- userIdentity.accountId
|
||||
- userIdentity.invokedBy
|
||||
- user_agent
|
||||
- user_group_id
|
||||
- vendor
|
||||
- vendor_account
|
||||
- vendor_product
|
||||
- vendor_region
|
||||
example_log: '{"eventVersion": "1.08", "userIdentity": {"accountId": "111111111111",
|
||||
"invokedBy": "s3.amazonaws.com"}, "eventTime": "2023-04-24T23:51:17Z", "eventSource":
|
||||
"s3.amazonaws.com", "eventName": "JobCreated", "awsRegion": "us-west-2", "sourceIPAddress":
|
||||
"s3.amazonaws.com", "userAgent": "s3.amazonaws.com", "requestParameters": null,
|
||||
"responseElements": null, "eventID": "894153ad-ed86-4719-bb66-6c52ef7dc767", "readOnly":
|
||||
false, "eventType": "AwsServiceEvent", "managementEvent": true, "recipientAccountId":
|
||||
"111111111111", "serviceEventDetails": {"jobId": "bb54efd8-937d-4f0c-967d-aa8443998dac",
|
||||
"jobArn": "arn:aws:s3:us-west-2:111111111111:job/bb54efd8-937d-4f0c-967d-aa8443998dac",
|
||||
"status": "New", "jobEventId": "4e70d2f1053c07a79d9be9a14e486020", "failureCodes":
|
||||
[], "statusChangeReason": []}, "eventCategory": "Management"}'
|
||||
@@ -0,0 +1,193 @@
|
||||
name: AWS CloudTrail ModifyDBInstance
|
||||
id: bfa2912d-1a33-4b05-be46-543874d68241
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for AWS CloudTrail ModifyDBInstance
|
||||
source: aws_cloudtrail
|
||||
sourcetype: aws:cloudtrail
|
||||
separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Amazon Web Services (AWS)
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.4.1
|
||||
fields:
|
||||
- _time
|
||||
- app
|
||||
- awsRegion
|
||||
- aws_account_id
|
||||
- command
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- dest
|
||||
- dvc
|
||||
- errorCode
|
||||
- eventCategory
|
||||
- eventID
|
||||
- eventName
|
||||
- eventSource
|
||||
- eventTime
|
||||
- eventType
|
||||
- eventVersion
|
||||
- host
|
||||
- index
|
||||
- linecount
|
||||
- managementEvent
|
||||
- msg
|
||||
- object_category
|
||||
- product
|
||||
- punct
|
||||
- readOnly
|
||||
- recipientAccountId
|
||||
- region
|
||||
- requestID
|
||||
- requestParameters.allowMajorVersionUpgrade
|
||||
- requestParameters.applyImmediately
|
||||
- requestParameters.dBInstanceIdentifier
|
||||
- requestParameters.deletionProtection
|
||||
- requestParameters.masterUserPassword
|
||||
- responseElements.allocatedStorage
|
||||
- responseElements.autoMinorVersionUpgrade
|
||||
- responseElements.availabilityZone
|
||||
- responseElements.backupRetentionPeriod
|
||||
- responseElements.backupTarget
|
||||
- responseElements.cACertificateIdentifier
|
||||
- responseElements.copyTagsToSnapshot
|
||||
- responseElements.customerOwnedIpEnabled
|
||||
- responseElements.dBInstanceArn
|
||||
- responseElements.dBInstanceClass
|
||||
- responseElements.dBInstanceIdentifier
|
||||
- responseElements.dBInstanceStatus
|
||||
- responseElements.dBParameterGroups{}.dBParameterGroupName
|
||||
- responseElements.dBParameterGroups{}.parameterApplyStatus
|
||||
- responseElements.dBSubnetGroup.dBSubnetGroupDescription
|
||||
- responseElements.dBSubnetGroup.dBSubnetGroupName
|
||||
- responseElements.dBSubnetGroup.subnetGroupStatus
|
||||
- responseElements.dBSubnetGroup.subnets{}.subnetAvailabilityZone.name
|
||||
- responseElements.dBSubnetGroup.subnets{}.subnetIdentifier
|
||||
- responseElements.dBSubnetGroup.subnets{}.subnetStatus
|
||||
- responseElements.dBSubnetGroup.vpcId
|
||||
- responseElements.dbInstancePort
|
||||
- responseElements.dbiResourceId
|
||||
- responseElements.deletionProtection
|
||||
- responseElements.endpoint.address
|
||||
- responseElements.endpoint.hostedZoneId
|
||||
- responseElements.endpoint.port
|
||||
- responseElements.engine
|
||||
- responseElements.engineVersion
|
||||
- responseElements.enhancedMonitoringResourceArn
|
||||
- responseElements.httpEndpointEnabled
|
||||
- responseElements.iAMDatabaseAuthenticationEnabled
|
||||
- responseElements.instanceCreateTime
|
||||
- responseElements.kmsKeyId
|
||||
- responseElements.latestRestorableTime
|
||||
- responseElements.licenseModel
|
||||
- responseElements.masterUsername
|
||||
- responseElements.monitoringInterval
|
||||
- responseElements.monitoringRoleArn
|
||||
- responseElements.multiAZ
|
||||
- responseElements.networkType
|
||||
- responseElements.optionGroupMemberships{}.optionGroupName
|
||||
- responseElements.optionGroupMemberships{}.status
|
||||
- responseElements.pendingModifiedValues.masterUserPassword
|
||||
- responseElements.performanceInsightsEnabled
|
||||
- responseElements.performanceInsightsKMSKeyId
|
||||
- responseElements.performanceInsightsRetentionPeriod
|
||||
- responseElements.preferredBackupWindow
|
||||
- responseElements.preferredMaintenanceWindow
|
||||
- responseElements.publiclyAccessible
|
||||
- responseElements.storageEncrypted
|
||||
- responseElements.storageThroughput
|
||||
- responseElements.storageType
|
||||
- responseElements.vpcSecurityGroups{}.status
|
||||
- responseElements.vpcSecurityGroups{}.vpcSecurityGroupId
|
||||
- sessionCredentialFromConsole
|
||||
- signature
|
||||
- source
|
||||
- sourceIPAddress
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- src
|
||||
- src_ip
|
||||
- start_time
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
- user
|
||||
- userAgent
|
||||
- userIdentity.accessKeyId
|
||||
- userIdentity.accountId
|
||||
- userIdentity.arn
|
||||
- userIdentity.principalId
|
||||
- userIdentity.sessionContext.attributes.creationDate
|
||||
- userIdentity.sessionContext.attributes.mfaAuthenticated
|
||||
- userIdentity.sessionContext.sessionIssuer.accountId
|
||||
- userIdentity.sessionContext.sessionIssuer.arn
|
||||
- userIdentity.sessionContext.sessionIssuer.principalId
|
||||
- userIdentity.sessionContext.sessionIssuer.type
|
||||
- userIdentity.sessionContext.sessionIssuer.userName
|
||||
- userIdentity.type
|
||||
- userName
|
||||
- user_access_key
|
||||
- user_agent
|
||||
- user_arn
|
||||
- user_group_id
|
||||
- user_id
|
||||
- user_name
|
||||
- user_type
|
||||
- vendor
|
||||
- vendor_account
|
||||
- vendor_product
|
||||
- vendor_region
|
||||
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "principalId":
|
||||
"AROAYTOGP2RLDF6WP4HD6:gowthamarajr@splunk.com", "arn": "arn:aws:sts::111111111111:assumed-role/AWSReservedSSO_SPLKAdministratorAccess_d9ce1347d0a6dd3f/gowthamarajr@splunk.com",
|
||||
"accountId": "111111111111", "accessKeyId": "ASIAYTOGP2RLAKJDBQGB", "sessionContext":
|
||||
{"sessionIssuer": {"type": "Role", "principalId": "AROAYTOGP2RLDF6WP4HD6", "arn":
|
||||
"arn:aws:iam::111111111111:role/aws-reserved/sso.amazonaws.com/us-west-2/AWSReservedSSO_SPLKAdministratorAccess_d9ce1347d0a6dd3f",
|
||||
"accountId": "111111111111", "userName": "AWSReservedSSO_SPLKAdministratorAccess_d9ce1347d0a6dd3f"},
|
||||
"webIdFederationData": {}, "attributes": {"creationDate": "2022-08-05T08:47:55Z",
|
||||
"mfaAuthenticated": "false"}}}, "eventTime": "2022-08-05T09:19:15Z", "eventSource":
|
||||
"rds.amazonaws.com", "eventName": "ModifyDBInstance", "awsRegion": "us-west-2",
|
||||
"sourceIPAddress": "AWS Internal", "userAgent": "AWS Internal", "requestParameters":
|
||||
{"dBInstanceIdentifier": "database-1", "applyImmediately": true, "masterUserPassword":
|
||||
"****", "allowMajorVersionUpgrade": false, "deletionProtection": true}, "responseElements":
|
||||
{"dBInstanceIdentifier": "database-1", "dBInstanceClass": "db.m6g.large", "engine":
|
||||
"postgres", "dBInstanceStatus": "available", "masterUsername": "postgres", "endpoint":
|
||||
{"address": "database-1.ce6wk5bvtc0t.us-west-2.rds.amazonaws.com", "port": 5432,
|
||||
"hostedZoneId": "Z1PVIF0B656C1W"}, "allocatedStorage": 5, "instanceCreateTime":
|
||||
"Aug 5, 2022 9:02:51 AM", "preferredBackupWindow": "06:35-07:05", "backupRetentionPeriod":
|
||||
7, "dBSecurityGroups": [], "vpcSecurityGroups": [{"vpcSecurityGroupId": "sg-46cfd020",
|
||||
"status": "active"}], "dBParameterGroups": [{"dBParameterGroupName": "default.postgres14",
|
||||
"parameterApplyStatus": "in-sync"}], "availabilityZone": "us-west-2a", "dBSubnetGroup":
|
||||
{"dBSubnetGroupName": "default", "dBSubnetGroupDescription": "default", "vpcId":
|
||||
"vpc-5f02343b", "subnetGroupStatus": "Complete", "subnets": [{"subnetIdentifier":
|
||||
"subnet-43225f35", "subnetAvailabilityZone": {"name": "us-west-2b"}, "subnetOutpost":
|
||||
{}, "subnetStatus": "Active"}, {"subnetIdentifier": "subnet-e55d7881", "subnetAvailabilityZone":
|
||||
{"name": "us-west-2a"}, "subnetOutpost": {}, "subnetStatus": "Active"}, {"subnetIdentifier":
|
||||
"subnet-0beddb972f034bdaa", "subnetAvailabilityZone": {"name": "us-west-2c"}, "subnetOutpost":
|
||||
{}, "subnetStatus": "Active"}, {"subnetIdentifier": "subnet-2d70cd75", "subnetAvailabilityZone":
|
||||
{"name": "us-west-2c"}, "subnetOutpost": {}, "subnetStatus": "Active"}]}, "preferredMaintenanceWindow":
|
||||
"sat:11:44-sat:12:14", "pendingModifiedValues": {"masterUserPassword": "****"},
|
||||
"latestRestorableTime": "Aug 5, 2022 9:12:31 AM", "multiAZ": false, "engineVersion":
|
||||
"14.2", "autoMinorVersionUpgrade": true, "readReplicaDBInstanceIdentifiers": [],
|
||||
"licenseModel": "postgresql-license", "storageThroughput": 0, "optionGroupMemberships":
|
||||
[{"optionGroupName": "default:postgres-14", "status": "in-sync"}], "publiclyAccessible":
|
||||
false, "storageType": "standard", "dbInstancePort": 0, "storageEncrypted": true,
|
||||
"kmsKeyId": "arn:aws:kms:us-west-2:111111111111:key/318bcd5d-c453-489d-b63a-07753eab0623",
|
||||
"dbiResourceId": "db-IX2K4LYFLBVZDHBYNPEAVFHFQM", "cACertificateIdentifier": "rds-ca-2019",
|
||||
"domainMemberships": [], "copyTagsToSnapshot": true, "monitoringInterval": 60, "enhancedMonitoringResourceArn":
|
||||
"arn:aws:logs:us-west-2:111111111111:log-group:RDSOSMetrics:log-stream:db-IX2K4LYFLBVZDHBYNPEAVFHFQM",
|
||||
"monitoringRoleArn": "arn:aws:iam::111111111111:role/rds-monitoring-role", "dBInstanceArn":
|
||||
"arn:aws:rds:us-west-2:111111111111:db:database-1", "iAMDatabaseAuthenticationEnabled":
|
||||
false, "performanceInsightsEnabled": true, "performanceInsightsKMSKeyId": "arn:aws:kms:us-west-2:111111111111:key/318bcd5d-c453-489d-b63a-07753eab0623",
|
||||
"performanceInsightsRetentionPeriod": 7, "deletionProtection": true, "associatedRoles":
|
||||
[], "httpEndpointEnabled": false, "tagList": [], "customerOwnedIpEnabled": false,
|
||||
"networkType": "IPV4", "backupTarget": "region"}, "requestID": "59e6b621-2f12-415b-bde4-21fa2dc7c113",
|
||||
"eventID": "46351ca1-760e-4eef-b3ff-19723e13fbf8", "readOnly": false, "eventType":
|
||||
"AwsApiCall", "managementEvent": true, "recipientAccountId": "111111111111", "eventCategory":
|
||||
"Management", "sessionCredentialFromConsole": "true"}'
|
||||
@@ -0,0 +1,108 @@
|
||||
name: AWS CloudTrail ModifyImageAttribute
|
||||
id: 667c2115-8082-419e-b541-8150066bda4d
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for AWS CloudTrail ModifyImageAttribute
|
||||
source: aws_cloudtrail
|
||||
sourcetype: aws:cloudtrail
|
||||
separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Amazon Web Services (AWS)
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.4.1
|
||||
fields:
|
||||
- _time
|
||||
- app
|
||||
- awsRegion
|
||||
- aws_account_id
|
||||
- change_type
|
||||
- command
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- dest
|
||||
- dvc
|
||||
- errorCode
|
||||
- eventCategory
|
||||
- eventID
|
||||
- eventName
|
||||
- eventSource
|
||||
- eventTime
|
||||
- eventType
|
||||
- eventVersion
|
||||
- host
|
||||
- index
|
||||
- linecount
|
||||
- managementEvent
|
||||
- msg
|
||||
- object_category
|
||||
- product
|
||||
- punct
|
||||
- readOnly
|
||||
- recipientAccountId
|
||||
- region
|
||||
- requestID
|
||||
- requestParameters.attributeType
|
||||
- requestParameters.imageId
|
||||
- requestParameters.launchPermission.add.items{}.userId
|
||||
- responseElements._return
|
||||
- responseElements.requestId
|
||||
- sessionCredentialFromConsole
|
||||
- signature
|
||||
- source
|
||||
- sourceIPAddress
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- src
|
||||
- src_ip
|
||||
- start_time
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
- user
|
||||
- userAgent
|
||||
- userIdentity.accessKeyId
|
||||
- userIdentity.accountId
|
||||
- userIdentity.arn
|
||||
- userIdentity.principalId
|
||||
- userIdentity.sessionContext.attributes.creationDate
|
||||
- userIdentity.sessionContext.attributes.mfaAuthenticated
|
||||
- userIdentity.sessionContext.sessionIssuer.accountId
|
||||
- userIdentity.sessionContext.sessionIssuer.arn
|
||||
- userIdentity.sessionContext.sessionIssuer.principalId
|
||||
- userIdentity.sessionContext.sessionIssuer.type
|
||||
- userIdentity.sessionContext.sessionIssuer.userName
|
||||
- userIdentity.type
|
||||
- userName
|
||||
- user_access_key
|
||||
- user_agent
|
||||
- user_arn
|
||||
- user_group_id
|
||||
- user_id
|
||||
- user_name
|
||||
- user_type
|
||||
- vendor
|
||||
- vendor_account
|
||||
- vendor_product
|
||||
- vendor_region
|
||||
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "principalId":
|
||||
"AROAYTOGP2RLDF6WP4HD6:bonobo@bo.com", "arn": "arn:aws:sts::111111111111:assumed-role/AWSReservedSSO_SPLKAdministratorAccess_d9ce1347d0a6dd3f/bonobo@bo.com",
|
||||
"accountId": "111111111111", "accessKeyId": "ASIAYTOGP2RLBHIEEEPN", "sessionContext":
|
||||
{"sessionIssuer": {"type": "Role", "principalId": "AROAYTOGP2RLDF6WP4HD6", "arn":
|
||||
"arn:aws:iam::111111111111:role/aws-reserved/sso.amazonaws.com/us-west-2/AWSReservedSSO_SPLKAdministratorAccess_d9ce1347d0a6dd3f",
|
||||
"accountId": "111111111111", "userName": "AWSReservedSSO_SPLKAdministratorAccess_d9ce1347d0a6dd3f"},
|
||||
"webIdFederationData": {}, "attributes": {"creationDate": "2023-03-23T19:27:44Z",
|
||||
"mfaAuthenticated": "false"}}}, "eventTime": "2023-03-23T21:47:28Z", "eventSource":
|
||||
"ec2.amazonaws.com", "eventName": "ModifyImageAttribute", "awsRegion": "us-west-2",
|
||||
"sourceIPAddress": "72.135.245.10", "userAgent": "AWS Internal", "requestParameters":
|
||||
{"imageId": "ami-06dac31db29508566", "launchPermission": {"add": {"items": [{"userId":
|
||||
"140429656527"}]}}, "attributeType": "launchPermission"}, "responseElements": {"requestId":
|
||||
"84c431ce-6268-4218-aaf8-b4cdc1cd4055", "_return": true}, "requestID": "84c431ce-6268-4218-aaf8-b4cdc1cd4055",
|
||||
"eventID": "957e1b12-ea17-4006-aefd-20677ace72b8", "readOnly": false, "eventType":
|
||||
"AwsApiCall", "managementEvent": true, "recipientAccountId": "111111111111", "eventCategory":
|
||||
"Management", "sessionCredentialFromConsole": "true"}'
|
||||
@@ -0,0 +1,101 @@
|
||||
name: AWS CloudTrail ModifySnapshotAttribute
|
||||
id: 7e5aa947-3a0d-4ee5-b800-0c10b555da05
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for AWS CloudTrail ModifySnapshotAttribute
|
||||
source: aws_cloudtrail
|
||||
sourcetype: aws:cloudtrail
|
||||
separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Amazon Web Services (AWS)
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.4.1
|
||||
fields:
|
||||
- _time
|
||||
- app
|
||||
- awsRegion
|
||||
- aws_account_id
|
||||
- change_type
|
||||
- command
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- dest
|
||||
- dvc
|
||||
- errorCode
|
||||
- eventCategory
|
||||
- eventID
|
||||
- eventName
|
||||
- eventSource
|
||||
- eventTime
|
||||
- eventType
|
||||
- eventVersion
|
||||
- host
|
||||
- index
|
||||
- linecount
|
||||
- managementEvent
|
||||
- msg
|
||||
- object_category
|
||||
- product
|
||||
- punct
|
||||
- readOnly
|
||||
- recipientAccountId
|
||||
- region
|
||||
- requestID
|
||||
- requestParameters.attributeType
|
||||
- requestParameters.createVolumePermission.add.items{}.userId
|
||||
- requestParameters.snapshotId
|
||||
- responseElements._return
|
||||
- responseElements.requestId
|
||||
- signature
|
||||
- source
|
||||
- sourceIPAddress
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- src
|
||||
- src_ip
|
||||
- start_time
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
- tlsDetails.cipherSuite
|
||||
- tlsDetails.clientProvidedHostHeader
|
||||
- tlsDetails.tlsVersion
|
||||
- user
|
||||
- userAgent
|
||||
- userIdentity.accessKeyId
|
||||
- userIdentity.accountId
|
||||
- userIdentity.arn
|
||||
- userIdentity.principalId
|
||||
- userIdentity.type
|
||||
- userIdentity.userName
|
||||
- userName
|
||||
- user_access_key
|
||||
- user_agent
|
||||
- user_arn
|
||||
- user_group_id
|
||||
- user_id
|
||||
- user_name
|
||||
- user_type
|
||||
- vendor
|
||||
- vendor_account
|
||||
- vendor_product
|
||||
- vendor_region
|
||||
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId":
|
||||
"AIDAYTOGP2RLCNEAQXWZV", "arn": "arn:aws:iam::111111111111:user/bhavin_console",
|
||||
"accountId": "111111111111", "accessKeyId": "AKIAYTOGP2RLF5EAXXXX", "userName":
|
||||
"bhavin_console"}, "eventTime": "2023-03-20T22:31:36Z", "eventSource": "ec2.amazonaws.com",
|
||||
"eventName": "ModifySnapshotAttribute", "awsRegion": "us-west-2", "sourceIPAddress":
|
||||
"72.135.1.1", "userAgent": "stratus-red-team_46665bb8-dc15-4aba-a5ad-a362772b3f0d",
|
||||
"requestParameters": {"snapshotId": "snap-02effb3bb62786b18", "createVolumePermission":
|
||||
{"add": {"items": [{"userId": "012345678912"}]}}, "attributeType": "CREATE_VOLUME_PERMISSION"},
|
||||
"responseElements": {"requestId": "f58433e6-a7f4-4e63-9cba-7ecc60ab74b2", "_return":
|
||||
true}, "requestID": "f58433e6-a7f4-4e63-9cba-7ecc60ab74b2", "eventID": "62e027d3-7191-48f4-b5fe-4b66c58b3008",
|
||||
"readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId":
|
||||
"111111111111", "eventCategory": "Management", "tlsDetails": {"tlsVersion": "TLSv1.2",
|
||||
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256", "clientProvidedHostHeader": "ec2.us-west-2.amazonaws.com"}}'
|
||||
@@ -0,0 +1,116 @@
|
||||
name: AWS CloudTrail PutBucketAcl
|
||||
id: 28fffbfd-d98d-4a42-990b-b04ab47422eb
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for AWS CloudTrail PutBucketAcl
|
||||
source: aws_cloudtrail
|
||||
sourcetype: aws:cloudtrail
|
||||
separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Amazon Web Services (AWS)
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.4.1
|
||||
fields:
|
||||
- _time
|
||||
- action
|
||||
- additionalEventData.AuthenticationMethod
|
||||
- additionalEventData.CipherSuite
|
||||
- additionalEventData.SignatureVersion
|
||||
- additionalEventData.bytesTransferredIn
|
||||
- additionalEventData.bytesTransferredOut
|
||||
- additionalEventData.x-amz-id-2
|
||||
- app
|
||||
- awsRegion
|
||||
- aws_account_id
|
||||
- change_type
|
||||
- command
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- dest
|
||||
- dvc
|
||||
- errorCode
|
||||
- eventCategory
|
||||
- eventID
|
||||
- eventName
|
||||
- eventSource
|
||||
- eventTime
|
||||
- eventType
|
||||
- eventVersion
|
||||
- eventtype
|
||||
- host
|
||||
- index
|
||||
- linecount
|
||||
- managementEvent
|
||||
- msg
|
||||
- object
|
||||
- object_category
|
||||
- object_id
|
||||
- product
|
||||
- punct
|
||||
- readOnly
|
||||
- recipientAccountId
|
||||
- region
|
||||
- requestID
|
||||
- requestParameters.Host
|
||||
- requestParameters.accessControlList.x-amz-grant-write-acp
|
||||
- requestParameters.acl
|
||||
- requestParameters.bucketName
|
||||
- resources{}.ARN
|
||||
- resources{}.accountId
|
||||
- resources{}.type
|
||||
- responseElements
|
||||
- signature
|
||||
- source
|
||||
- sourceIPAddress
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- src
|
||||
- src_ip
|
||||
- src_user
|
||||
- start_time
|
||||
- status
|
||||
- tag
|
||||
- tag::eventtype
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
- user
|
||||
- userAgent
|
||||
- userIdentity.accessKeyId
|
||||
- userIdentity.accountId
|
||||
- userIdentity.arn
|
||||
- userIdentity.principalId
|
||||
- userIdentity.type
|
||||
- userIdentity.userName
|
||||
- userName
|
||||
- user_access_key
|
||||
- user_agent
|
||||
- user_arn
|
||||
- user_group_id
|
||||
- user_id
|
||||
- user_name
|
||||
- vendor
|
||||
- vendor_account
|
||||
- vendor_product
|
||||
- vendor_region
|
||||
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId":
|
||||
"AIDAYTOGP2RLNALZHZ6KX", "arn": "arn:aws:iam::111111111111:user/patrick_cli", "accountId":
|
||||
"111111111111", "accessKeyId": "AKIAYTOGP2RLJ2OYSF6E", "userName": "patrick_cli"},
|
||||
"eventTime": "2021-01-12T14:03:17Z", "eventSource": "s3.amazonaws.com", "eventName":
|
||||
"PutBucketAcl", "awsRegion": "eu-central-1", "sourceIPAddress": "95.90.199.65",
|
||||
"userAgent": "[aws-cli/2.0.45 Python/3.7.4 Darwin/20.2.0 exe/x86_64 command/s3api.put-bucket-acl]",
|
||||
"requestParameters": {"bucketName": "patricktestbucket19", "Host": "patricktestbucket19.s3.eu-central-1.amazonaws.com",
|
||||
"acl": "", "accessControlList": {"x-amz-grant-write-acp": "uri=http://acs.amazonaws.com/groups/global/AuthenticatedUsers"}},
|
||||
"responseElements": null, "additionalEventData": {"SignatureVersion": "SigV4", "CipherSuite":
|
||||
"ECDHE-RSA-AES128-GCM-SHA256", "bytesTransferredIn": 0, "AuthenticationMethod":
|
||||
"AuthHeader", "x-amz-id-2": "qb+xR18y4+4serdq8conds+tNROklOFRYciGHof4z1pcnTnT9SCrx6iYHuupPNaiMnZ9kdB43yE=",
|
||||
"bytesTransferredOut": 0}, "requestID": "23FAB394417ECFCD", "eventID": "9feee3c9-711f-4f7d-af4c-992907a2a521",
|
||||
"readOnly": false, "resources": [{"accountId": "111111111111", "type": "AWS::S3::Bucket",
|
||||
"ARN": "arn:aws:s3:::patricktestbucket19"}], "eventType": "AwsApiCall", "managementEvent":
|
||||
true, "eventCategory": "Management", "recipientAccountId": "111111111111"}'
|
||||
@@ -0,0 +1,120 @@
|
||||
name: AWS CloudTrail PutBucketLifecycle
|
||||
id: 1c73e954-87b6-4bd7-ac6a-5db7c4082b22
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for AWS CloudTrail PutBucketLifecycle
|
||||
source: aws_cloudtrail
|
||||
sourcetype: aws:cloudtrail
|
||||
separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Amazon Web Services (AWS)
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.4.1
|
||||
fields:
|
||||
- _time
|
||||
- additionalEventData.AuthenticationMethod
|
||||
- additionalEventData.CipherSuite
|
||||
- additionalEventData.SignatureVersion
|
||||
- additionalEventData.bytesTransferredIn
|
||||
- additionalEventData.bytesTransferredOut
|
||||
- additionalEventData.x-amz-id-2
|
||||
- app
|
||||
- awsRegion
|
||||
- aws_account_id
|
||||
- command
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- dest
|
||||
- dvc
|
||||
- errorCode
|
||||
- eventCategory
|
||||
- eventID
|
||||
- eventName
|
||||
- eventSource
|
||||
- eventTime
|
||||
- eventType
|
||||
- eventVersion
|
||||
- host
|
||||
- index
|
||||
- linecount
|
||||
- managementEvent
|
||||
- msg
|
||||
- object
|
||||
- object_category
|
||||
- object_id
|
||||
- product
|
||||
- punct
|
||||
- readOnly
|
||||
- recipientAccountId
|
||||
- region
|
||||
- requestID
|
||||
- requestParameters.Host
|
||||
- requestParameters.LifecycleConfiguration.Rule.Expiration.Days
|
||||
- requestParameters.LifecycleConfiguration.Rule.Filter.Prefix
|
||||
- requestParameters.LifecycleConfiguration.Rule.ID
|
||||
- requestParameters.LifecycleConfiguration.Rule.Status
|
||||
- requestParameters.LifecycleConfiguration.xmlns
|
||||
- requestParameters.bucketName
|
||||
- requestParameters.lifecycle
|
||||
- resources{}.ARN
|
||||
- resources{}.accountId
|
||||
- resources{}.type
|
||||
- responseElements
|
||||
- signature
|
||||
- source
|
||||
- sourceIPAddress
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- src
|
||||
- src_ip
|
||||
- start_time
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
- tlsDetails.cipherSuite
|
||||
- tlsDetails.clientProvidedHostHeader
|
||||
- tlsDetails.tlsVersion
|
||||
- user
|
||||
- userAgent
|
||||
- userIdentity.accessKeyId
|
||||
- userIdentity.accountId
|
||||
- userIdentity.arn
|
||||
- userIdentity.principalId
|
||||
- userIdentity.type
|
||||
- userIdentity.userName
|
||||
- userName
|
||||
- user_access_key
|
||||
- user_agent
|
||||
- user_arn
|
||||
- user_group_id
|
||||
- user_id
|
||||
- user_name
|
||||
- user_type
|
||||
- vendor
|
||||
- vendor_account
|
||||
- vendor_product
|
||||
- vendor_region
|
||||
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId":
|
||||
"AIDAYTOGP2RLEHRX5YWNV", "arn": "arn:aws:iam::111111111111:user/bhavin_cli", "accountId":
|
||||
"111111111111", "accessKeyId": "AKIAYTOGP2RLKQ3U2PDY", "userName": "bhavin_cli"},
|
||||
"eventTime": "2022-07-13T21:58:27Z", "eventSource": "s3.amazonaws.com", "eventName":
|
||||
"PutBucketLifecycle", "awsRegion": "us-west-2", "sourceIPAddress": "192.184.242.57",
|
||||
"userAgent": "[stratus-red-team_d73089cf-1905-430c-b6d3-4dc4d669190f]", "requestParameters":
|
||||
{"lifecycle": "", "bucketName": "my-cloudtrail-bucket-alfsujjpnbpguqrh", "LifecycleConfiguration":
|
||||
{"xmlns": "http://s3.amazonaws.com/doc/2006-03-01/", "Rule": {"Status": "Enabled",
|
||||
"Filter": {"Prefix": "*"}, "Expiration": {"Days": 1}, "ID": "nuke-cloudtrail-logs-after-1-day"}},
|
||||
"Host": "my-cloudtrail-bucket-alfsujjpnbpguqrh.s3.us-west-2.amazonaws.com"}, "responseElements":
|
||||
null, "additionalEventData": {"SignatureVersion": "SigV4", "CipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
|
||||
"bytesTransferredIn": 249, "AuthenticationMethod": "AuthHeader", "x-amz-id-2": "TVXZE5kOVTMLqYlmKK+j/5g6flwkiFXFfw8PyNivFO4/9YXnDsyzFlGEzAy2rukTTiukLdEwtuM=",
|
||||
"bytesTransferredOut": 0}, "requestID": "1P8X27T2BCMY93Y9", "eventID": "25d92cd1-f366-4b11-b408-967a17ce70f3",
|
||||
"readOnly": false, "resources": [{"accountId": "111111111111", "type": "AWS::S3::Bucket",
|
||||
"ARN": "arn:aws:s3:::my-cloudtrail-bucket-alfsujjpnbpguqrh"}], "eventType": "AwsApiCall",
|
||||
"managementEvent": true, "recipientAccountId": "111111111111", "eventCategory":
|
||||
"Management", "tlsDetails": {"tlsVersion": "TLSv1.2", "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
|
||||
"clientProvidedHostHeader": "my-cloudtrail-bucket-alfsujjpnbpguqrh.s3.us-west-2.amazonaws.com"}}'
|
||||
@@ -0,0 +1,141 @@
|
||||
name: AWS CloudTrail PutBucketReplication
|
||||
id: 0e1362eb-e592-419f-8fa5-556d3a122417
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for AWS CloudTrail PutBucketReplication
|
||||
source: aws_cloudtrail
|
||||
sourcetype: aws:cloudtrail
|
||||
separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Amazon Web Services (AWS)
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.4.1
|
||||
fields:
|
||||
- _time
|
||||
- additionalEventData.AuthenticationMethod
|
||||
- additionalEventData.CipherSuite
|
||||
- additionalEventData.SignatureVersion
|
||||
- additionalEventData.bytesTransferredIn
|
||||
- additionalEventData.bytesTransferredOut
|
||||
- additionalEventData.x-amz-id-2
|
||||
- app
|
||||
- awsRegion
|
||||
- aws_account_id
|
||||
- command
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- dest
|
||||
- dvc
|
||||
- errorCode
|
||||
- eventCategory
|
||||
- eventID
|
||||
- eventName
|
||||
- eventSource
|
||||
- eventTime
|
||||
- eventType
|
||||
- eventVersion
|
||||
- eventtype
|
||||
- host
|
||||
- index
|
||||
- linecount
|
||||
- managementEvent
|
||||
- msg
|
||||
- object
|
||||
- object_category
|
||||
- object_id
|
||||
- product
|
||||
- punct
|
||||
- readOnly
|
||||
- recipientAccountId
|
||||
- region
|
||||
- requestID
|
||||
- requestParameters.Host
|
||||
- requestParameters.ReplicationConfiguration.Role
|
||||
- requestParameters.ReplicationConfiguration.Rule.DeleteMarkerReplication.Status
|
||||
- requestParameters.ReplicationConfiguration.Rule.Destination.Bucket
|
||||
- requestParameters.ReplicationConfiguration.Rule.Filter
|
||||
- requestParameters.ReplicationConfiguration.Rule.ID
|
||||
- requestParameters.ReplicationConfiguration.Rule.Priority
|
||||
- requestParameters.ReplicationConfiguration.Rule.Status
|
||||
- requestParameters.ReplicationConfiguration.xmlns
|
||||
- requestParameters.bucketName
|
||||
- requestParameters.replication
|
||||
- resources{}.ARN
|
||||
- resources{}.accountId
|
||||
- resources{}.type
|
||||
- responseElements
|
||||
- signature
|
||||
- source
|
||||
- sourceIPAddress
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- src
|
||||
- src_ip
|
||||
- start_time
|
||||
- tag
|
||||
- tag::eventtype
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
- tlsDetails.cipherSuite
|
||||
- tlsDetails.clientProvidedHostHeader
|
||||
- tlsDetails.tlsVersion
|
||||
- user
|
||||
- userAgent
|
||||
- userIdentity.accessKeyId
|
||||
- userIdentity.accountId
|
||||
- userIdentity.arn
|
||||
- userIdentity.principalId
|
||||
- userIdentity.sessionContext.attributes.creationDate
|
||||
- userIdentity.sessionContext.attributes.mfaAuthenticated
|
||||
- userIdentity.sessionContext.sessionIssuer.accountId
|
||||
- userIdentity.sessionContext.sessionIssuer.arn
|
||||
- userIdentity.sessionContext.sessionIssuer.principalId
|
||||
- userIdentity.sessionContext.sessionIssuer.type
|
||||
- userIdentity.sessionContext.sessionIssuer.userName
|
||||
- userIdentity.type
|
||||
- userName
|
||||
- user_access_key
|
||||
- user_agent
|
||||
- user_arn
|
||||
- user_group_id
|
||||
- user_id
|
||||
- user_name
|
||||
- user_type
|
||||
- vendor
|
||||
- vendor_account
|
||||
- vendor_product
|
||||
- vendor_region
|
||||
- vpcEndpointId
|
||||
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "principalId":
|
||||
"AROAYTOGP2RLDF6WP4H11:bpatel@splunk.com", "arn": "arn:aws:sts::111111111111:assumed-role/AWSReservedSSO_SPLKAdministratorAccess_d9ce1347d0a6dd3f/bpatel@splunk.com",
|
||||
"accountId": "111111111111", "accessKeyId": "ASIAYTOGP2RLJOVYQHW2", "sessionContext":
|
||||
{"sessionIssuer": {"type": "Role", "principalId": "AROAYTOGP2RLDF6WP4H11", "arn":
|
||||
"arn:aws:iam::111111111111:role/aws-reserved/sso.amazonaws.com/us-west-2/AWSReservedSSO_SPLKAdministratorAccess_d9ce1347d0a6dd3f",
|
||||
"accountId": "111111111111", "userName": "AWSReservedSSO_SPLKAdministratorAccess_d9ce1347d0a6dd3f"},
|
||||
"webIdFederationData": {}, "attributes": {"creationDate": "2023-04-24T23:45:42Z",
|
||||
"mfaAuthenticated": "false"}}}, "eventTime": "2023-04-24T23:49:33Z", "eventSource":
|
||||
"s3.amazonaws.com", "eventName": "PutBucketReplication", "awsRegion": "us-west-2",
|
||||
"sourceIPAddress": "23.93.193.6", "userAgent": "[S3Console/0.4, aws-internal/3 aws-sdk-java/1.11.1030
|
||||
Linux/5.4.238-155.347.amzn2int.x86_64 OpenJDK_64-Bit_Server_VM/25.362-b10 java/1.8.0_362
|
||||
vendor/Oracle_Corporation cfg/retry-mode/standard]", "requestParameters": {"replication":
|
||||
"", "bucketName": "git-wild-hunt-results", "Host": "s3.us-west-2.amazonaws.com",
|
||||
"ReplicationConfiguration": {"Role": "arn:aws:iam::111111111111:role/attack_range_bpatel",
|
||||
"xmlns": "http://s3.amazonaws.com/doc/2006-03-01/", "Rule": {"Status": "Enabled",
|
||||
"Destination": {"Bucket": "arn:aws:s3:::badpublicbuckettest"}, "Filter": "", "Priority":
|
||||
0, "ID": "replication_x_test", "DeleteMarkerReplication": {"Status": "Disabled"}}}},
|
||||
"responseElements": null, "additionalEventData": {"SignatureVersion": "SigV4", "CipherSuite":
|
||||
"ECDHE-RSA-AES128-GCM-SHA256", "bytesTransferredIn": 416, "AuthenticationMethod":
|
||||
"AuthHeader", "x-amz-id-2": "8UoliFe/sG2/v8qB2g763/g0Fy+kfaUqtKrzLHEILnHUisC3rL1dQfJ3NSIYcA/kzpIHQ955pGo=",
|
||||
"bytesTransferredOut": 0}, "requestID": "14SAVMJNEJMTZN91", "eventID": "fbe079d1-bc6b-4ee0-8893-d2b412c5550f",
|
||||
"readOnly": false, "resources": [{"accountId": "111111111111", "type": "AWS::S3::Bucket",
|
||||
"ARN": "arn:aws:s3:::git-wild-hunt-results"}], "eventType": "AwsApiCall", "managementEvent":
|
||||
true, "recipientAccountId": "111111111111", "vpcEndpointId": "vpce-a0d039c9", "eventCategory":
|
||||
"Management", "tlsDetails": {"tlsVersion": "TLSv1.2", "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
|
||||
"clientProvidedHostHeader": "s3.us-west-2.amazonaws.com"}}'
|
||||
@@ -0,0 +1,129 @@
|
||||
name: AWS CloudTrail PutBucketVersioning
|
||||
id: 17b2fc7d-c8ce-487c-8815-f9a65a09e980
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for AWS CloudTrail PutBucketVersioning
|
||||
source: aws_cloudtrail
|
||||
sourcetype: aws:cloudtrail
|
||||
separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Amazon Web Services (AWS)
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.4.1
|
||||
fields:
|
||||
- _time
|
||||
- additionalEventData.AuthenticationMethod
|
||||
- additionalEventData.CipherSuite
|
||||
- additionalEventData.SignatureVersion
|
||||
- additionalEventData.bytesTransferredIn
|
||||
- additionalEventData.bytesTransferredOut
|
||||
- additionalEventData.x-amz-id-2
|
||||
- app
|
||||
- awsRegion
|
||||
- aws_account_id
|
||||
- command
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- dest
|
||||
- dvc
|
||||
- errorCode
|
||||
- eventCategory
|
||||
- eventID
|
||||
- eventName
|
||||
- eventSource
|
||||
- eventTime
|
||||
- eventType
|
||||
- eventVersion
|
||||
- host
|
||||
- index
|
||||
- linecount
|
||||
- managementEvent
|
||||
- msg
|
||||
- object
|
||||
- object_category
|
||||
- object_id
|
||||
- product
|
||||
- punct
|
||||
- readOnly
|
||||
- recipientAccountId
|
||||
- region
|
||||
- requestID
|
||||
- requestParameters.Host
|
||||
- requestParameters.VersioningConfiguration.Status
|
||||
- requestParameters.VersioningConfiguration.xmlns
|
||||
- requestParameters.bucketName
|
||||
- requestParameters.versioning
|
||||
- resources{}.ARN
|
||||
- resources{}.accountId
|
||||
- resources{}.type
|
||||
- responseElements
|
||||
- signature
|
||||
- source
|
||||
- sourceIPAddress
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- src
|
||||
- src_ip
|
||||
- start_time
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
- tlsDetails.cipherSuite
|
||||
- tlsDetails.clientProvidedHostHeader
|
||||
- tlsDetails.tlsVersion
|
||||
- user
|
||||
- userAgent
|
||||
- userIdentity.accessKeyId
|
||||
- userIdentity.accountId
|
||||
- userIdentity.arn
|
||||
- userIdentity.principalId
|
||||
- userIdentity.sessionContext.attributes.creationDate
|
||||
- userIdentity.sessionContext.attributes.mfaAuthenticated
|
||||
- userIdentity.sessionContext.sessionIssuer.accountId
|
||||
- userIdentity.sessionContext.sessionIssuer.arn
|
||||
- userIdentity.sessionContext.sessionIssuer.principalId
|
||||
- userIdentity.sessionContext.sessionIssuer.type
|
||||
- userIdentity.sessionContext.sessionIssuer.userName
|
||||
- userIdentity.type
|
||||
- userName
|
||||
- user_access_key
|
||||
- user_agent
|
||||
- user_arn
|
||||
- user_group_id
|
||||
- user_id
|
||||
- user_name
|
||||
- user_type
|
||||
- vendor
|
||||
- vendor_account
|
||||
- vendor_product
|
||||
- vendor_region
|
||||
- vpcEndpointId
|
||||
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "principalId":
|
||||
"AROAYTOGP2RLDF6WP4HD6:daftpunk@splunk.com", "arn": "arn:aws:sts::111111111111:assumed-role/AWSReservedSSO_SPLKAdministratorAccess_d9ce1347d0a6dd3f/daftpunk@splunk.com",
|
||||
"accountId": "111111111111", "accessKeyId": "ASIAYTOGP2RLAQ5VXXXX", "sessionContext":
|
||||
{"sessionIssuer": {"type": "Role", "principalId": "AROAYTOGP2RLDF6WP4HD6", "arn":
|
||||
"arn:aws:iam::111111111111:role/aws-reserved/sso.amazonaws.com/us-west-2/AWSReservedSSO_SPLKAdministratorAccess_d9ce1347d0a6dd3f",
|
||||
"accountId": "111111111111", "userName": "AWSReservedSSO_SPLKAdministratorAccess_d9ce1347d0a6dd3f"},
|
||||
"webIdFederationData": {}, "attributes": {"creationDate": "2022-08-04T15:18:37Z",
|
||||
"mfaAuthenticated": "false"}}}, "eventTime": "2022-08-04T15:19:25Z", "eventSource":
|
||||
"s3.amazonaws.com", "eventName": "PutBucketVersioning", "awsRegion": "us-west-2",
|
||||
"sourceIPAddress": "73.57.168.38", "userAgent": "[S3Console/0.4, aws-internal/3
|
||||
aws-sdk-java/1.11.1030 Linux/5.4.196-119.356.amzn2int.x86_64 OpenJDK_64-Bit_Server_VM/25.302-b08
|
||||
java/1.8.0_302 vendor/Oracle_Corporation cfg/retry-mode/standard]", "requestParameters":
|
||||
{"bucketName": "git-wild-hunt-results", "Host": "s3.us-west-2.amazonaws.com", "versioning":
|
||||
"", "VersioningConfiguration": {"Status": "Suspended", "xmlns": "http://s3.amazonaws.com/doc/2006-03-01/"}},
|
||||
"responseElements": null, "additionalEventData": {"SignatureVersion": "SigV4", "CipherSuite":
|
||||
"ECDHE-RSA-AES128-GCM-SHA256", "bytesTransferredIn": 125, "AuthenticationMethod":
|
||||
"AuthHeader", "x-amz-id-2": "F3tJSu/C2DMkRNLldcWTRzApxQa6v197ImcuQDA++vaeaLj9UvcIkEFgDIrMYUdXLI4t+Uih5hk=",
|
||||
"bytesTransferredOut": 0}, "requestID": "5KXZDSNDYXWC8Q4M", "eventID": "42d7a97e-9d35-4c8e-8d0a-4a82d91aab55",
|
||||
"readOnly": false, "resources": [{"accountId": "111111111111", "type": "AWS::S3::Bucket",
|
||||
"ARN": "arn:aws:s3:::git-wild-hunt-results"}], "eventType": "AwsApiCall", "managementEvent":
|
||||
true, "recipientAccountId": "111111111111", "vpcEndpointId": "vpce-a0d039c9", "eventCategory":
|
||||
"Management", "tlsDetails": {"tlsVersion": "TLSv1.2", "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
|
||||
"clientProvidedHostHeader": "s3.us-west-2.amazonaws.com"}}'
|
||||
@@ -0,0 +1,151 @@
|
||||
name: AWS CloudTrail PutImage
|
||||
id: bb13f10d-0d8c-4fde-9136-b7cfd930e87c
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for AWS CloudTrail PutImage
|
||||
source: aws_cloudtrail
|
||||
sourcetype: aws:cloudtrail
|
||||
separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Amazon Web Services (AWS)
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.4.1
|
||||
fields:
|
||||
- _time
|
||||
- app
|
||||
- awsRegion
|
||||
- aws_account_id
|
||||
- command
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- dest
|
||||
- dvc
|
||||
- errorCode
|
||||
- eventCategory
|
||||
- eventID
|
||||
- eventName
|
||||
- eventSource
|
||||
- eventTime
|
||||
- eventType
|
||||
- eventVersion
|
||||
- host
|
||||
- index
|
||||
- linecount
|
||||
- managementEvent
|
||||
- msg
|
||||
- object_category
|
||||
- product
|
||||
- punct
|
||||
- readOnly
|
||||
- recipientAccountId
|
||||
- region
|
||||
- requestID
|
||||
- requestParameters.imageManifest
|
||||
- requestParameters.imageManifestMediaType
|
||||
- requestParameters.imageTag
|
||||
- requestParameters.registryId
|
||||
- requestParameters.repositoryName
|
||||
- resources{}.ARN
|
||||
- resources{}.accountId
|
||||
- responseElements.image.imageId.imageDigest
|
||||
- responseElements.image.imageId.imageTag
|
||||
- responseElements.image.imageManifest
|
||||
- responseElements.image.imageManifestMediaType
|
||||
- responseElements.image.registryId
|
||||
- responseElements.image.repositoryName
|
||||
- signature
|
||||
- source
|
||||
- sourceIPAddress
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- src
|
||||
- src_ip
|
||||
- start_time
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
- user
|
||||
- userAgent
|
||||
- userIdentity.accessKeyId
|
||||
- userIdentity.accountId
|
||||
- userIdentity.arn
|
||||
- userIdentity.invokedBy
|
||||
- userIdentity.principalId
|
||||
- userIdentity.sessionContext.attributes.creationDate
|
||||
- userIdentity.sessionContext.attributes.mfaAuthenticated
|
||||
- userIdentity.type
|
||||
- userIdentity.userName
|
||||
- userName
|
||||
- user_access_key
|
||||
- user_agent
|
||||
- user_arn
|
||||
- user_group_id
|
||||
- user_id
|
||||
- user_name
|
||||
- user_type
|
||||
- vendor
|
||||
- vendor_account
|
||||
- vendor_product
|
||||
- vendor_region
|
||||
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId":
|
||||
"AAAAAAAAAAAAAAAAAAAAA", "arn": "arn:aws:iam::111111111111:user/test", "accountId":
|
||||
"111111111111", "accessKeyId": "AAAAAAAAAAAAAAAAAAAAA", "userName": "test", "sessionContext":
|
||||
{"sessionIssuer": {}, "webIdFederationData": {}, "attributes": {"creationDate":
|
||||
"2021-08-18T23:15:39Z", "mfaAuthenticated": "false"}}, "invokedBy": "AWS Internal"},
|
||||
"eventTime": "2021-08-18T23:17:30Z", "eventSource": "ecr.amazonaws.com", "eventName":
|
||||
"PutImage", "awsRegion": "eu-central-1", "sourceIPAddress": "AWS Internal", "userAgent":
|
||||
"AWS Internal", "requestParameters": {"registryId": "111111111112", "repositoryName":
|
||||
"devsecops/cat_dog_server", "imageManifest": "{\n \"schemaVersion\": 2,\n \"mediaType\":
|
||||
\"application/vnd.docker.distribution.manifest.v2+json\",\n \"config\": {\n \"mediaType\":
|
||||
\"application/vnd.docker.container.image.v1+json\",\n \"size\": 6591,\n \"digest\":
|
||||
\"sha256:547fc07c53533763d68ebdfdc45529b1db45301d07824410bcc30df866d67df1\"\n },\n \"layers\":
|
||||
[\n {\n \"mediaType\": \"application/vnd.docker.image.rootfs.diff.tar.gzip\",\n \"size\":
|
||||
2811969,\n \"digest\": \"sha256:540db60ca9383eac9e418f78490994d0af424aab7bf6d0e47ac8ed4e2e9bcbba\"\n },\n {\n \"mediaType\":
|
||||
\"application/vnd.docker.image.rootfs.diff.tar.gzip\",\n \"size\": 35426616,\n \"digest\":
|
||||
\"sha256:f4fa1ac42c97abe89e0cc807af0ae4b63fbec2a5209a75a7239d099702c7fd80\"\n },\n {\n \"mediaType\":
|
||||
\"application/vnd.docker.image.rootfs.diff.tar.gzip\",\n \"size\": 2347076,\n \"digest\":
|
||||
\"sha256:2b3e10d0c87c453eed1378e102ff1cc17aa4e3eed2159b7505959777a6225059\"\n },\n {\n \"mediaType\":
|
||||
\"application/vnd.docker.image.rootfs.diff.tar.gzip\",\n \"size\": 280,\n \"digest\":
|
||||
\"sha256:43bd2fc3ba418e309449b8c82d723d9069ebb81863050dc0d6ad6e6ec0683808\"\n },\n {\n \"mediaType\":
|
||||
\"application/vnd.docker.image.rootfs.diff.tar.gzip\",\n \"size\": 92,\n \"digest\":
|
||||
\"sha256:803d6b58954d4daee18ed071281627f8214f3d2ba1b9a419ab8834029310942a\"\n },\n {\n \"mediaType\":
|
||||
\"application/vnd.docker.image.rootfs.diff.tar.gzip\",\n \"size\": 373,\n \"digest\":
|
||||
\"sha256:e664d5491b5c81e901a2293fbc025532a7cae0dcc75ce7418f854209aaa2474c\"\n },\n {\n \"mediaType\":
|
||||
\"application/vnd.docker.image.rootfs.diff.tar.gzip\",\n \"size\": 2383293,\n \"digest\":
|
||||
\"sha256:b827c586a783ce490b79907607d535f99f42360b6ba86a4b2ac3e7f01542144d\"\n },\n {\n \"mediaType\":
|
||||
\"application/vnd.docker.image.rootfs.diff.tar.gzip\",\n \"size\": 10001,\n \"digest\":
|
||||
\"sha256:0dd85ef396bcaded88fab4a8079d6b8bd5e3f8cf7eeb9b93306ffdb63401ba0a\"\n }\n ]\n}",
|
||||
"imageManifestMediaType": "application/vnd.docker.distribution.manifest.v2+json",
|
||||
"imageTag": "latest"}, "responseElements": {"image": {"registryId": "111111111112",
|
||||
"repositoryName": "devsecops/cat_dog_server", "imageId": {"imageDigest": "sha256:b7798f35949cc1a2d435c9ac59ab69e857fe635a359c96e4f56a8498ce02019c",
|
||||
"imageTag": "latest"}, "imageManifest": "{\n \"schemaVersion\": 2,\n \"mediaType\":
|
||||
\"application/vnd.docker.distribution.manifest.v2+json\",\n \"config\": {\n \"mediaType\":
|
||||
\"application/vnd.docker.container.image.v1+json\",\n \"size\": 6591,\n \"digest\":
|
||||
\"sha256:547fc07c53533763d68ebdfdc45529b1db45301d07824410bcc30df866d67df1\"\n },\n \"layers\":
|
||||
[\n {\n \"mediaType\": \"application/vnd.docker.image.rootfs.diff.tar.gzip\",\n \"size\":
|
||||
2811969,\n \"digest\": \"sha256:540db60ca9383eac9e418f78490994d0af424aab7bf6d0e47ac8ed4e2e9bcbba\"\n },\n {\n \"mediaType\":
|
||||
\"application/vnd.docker.image.rootfs.diff.tar.gzip\",\n \"size\": 35426616,\n \"digest\":
|
||||
\"sha256:f4fa1ac42c97abe89e0cc807af0ae4b63fbec2a5209a75a7239d099702c7fd80\"\n },\n {\n \"mediaType\":
|
||||
\"application/vnd.docker.image.rootfs.diff.tar.gzip\",\n \"size\": 2347076,\n \"digest\":
|
||||
\"sha256:2b3e10d0c87c453eed1378e102ff1cc17aa4e3eed2159b7505959777a6225059\"\n },\n {\n \"mediaType\":
|
||||
\"application/vnd.docker.image.rootfs.diff.tar.gzip\",\n \"size\": 280,\n \"digest\":
|
||||
\"sha256:43bd2fc3ba418e309449b8c82d723d9069ebb81863050dc0d6ad6e6ec0683808\"\n },\n {\n \"mediaType\":
|
||||
\"application/vnd.docker.image.rootfs.diff.tar.gzip\",\n \"size\": 92,\n \"digest\":
|
||||
\"sha256:803d6b58954d4daee18ed071281627f8214f3d2ba1b9a419ab8834029310942a\"\n },\n {\n \"mediaType\":
|
||||
\"application/vnd.docker.image.rootfs.diff.tar.gzip\",\n \"size\": 373,\n \"digest\":
|
||||
\"sha256:e664d5491b5c81e901a2293fbc025532a7cae0dcc75ce7418f854209aaa2474c\"\n },\n {\n \"mediaType\":
|
||||
\"application/vnd.docker.image.rootfs.diff.tar.gzip\",\n \"size\": 2383293,\n \"digest\":
|
||||
\"sha256:b827c586a783ce490b79907607d535f99f42360b6ba86a4b2ac3e7f01542144d\"\n },\n {\n \"mediaType\":
|
||||
\"application/vnd.docker.image.rootfs.diff.tar.gzip\",\n \"size\": 10001,\n \"digest\":
|
||||
\"sha256:0dd85ef396bcaded88fab4a8079d6b8bd5e3f8cf7eeb9b93306ffdb63401ba0a\"\n }\n ]\n}",
|
||||
"imageManifestMediaType": "application/vnd.docker.distribution.manifest.v2+json"}},
|
||||
"requestID": "805a31e6-0fed-433b-b393-f463c6881334", "eventID": "1aef3588-ae84-4f1f-9276-8ec94ee6a7e9",
|
||||
"readOnly": false, "resources": [{"accountId": "111111111111", "ARN": "arn:aws:ecr:eu-central-1:1111111111111:repository/devsecops/cat_dog_server"}],
|
||||
"eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId": "111111111111",
|
||||
"eventCategory": "Management"}'
|
||||
@@ -0,0 +1,132 @@
|
||||
name: AWS CloudTrail PutKeyPolicy
|
||||
id: 9c54c86b-43b9-4bb8-915d-6838beb7f07c
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for AWS CloudTrail PutKeyPolicy
|
||||
source: aws_cloudtrail
|
||||
sourcetype: aws:cloudtrail
|
||||
separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Amazon Web Services (AWS)
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.4.1
|
||||
fields:
|
||||
- _time
|
||||
- app
|
||||
- awsRegion
|
||||
- aws_account_id
|
||||
- command
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- dest
|
||||
- dvc
|
||||
- errorCode
|
||||
- eventCategory
|
||||
- eventID
|
||||
- eventName
|
||||
- eventSource
|
||||
- eventTime
|
||||
- eventType
|
||||
- eventVersion
|
||||
- eventtype
|
||||
- host
|
||||
- index
|
||||
- linecount
|
||||
- managementEvent
|
||||
- msg
|
||||
- object_category
|
||||
- product
|
||||
- punct
|
||||
- readOnly
|
||||
- recipientAccountId
|
||||
- region
|
||||
- requestID
|
||||
- requestParameters.bypassPolicyLockoutSafetyCheck
|
||||
- requestParameters.keyId
|
||||
- requestParameters.policy
|
||||
- requestParameters.policyName
|
||||
- resources{}.ARN
|
||||
- resources{}.accountId
|
||||
- resources{}.type
|
||||
- responseElements
|
||||
- signature
|
||||
- source
|
||||
- sourceIPAddress
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- src
|
||||
- src_ip
|
||||
- start_time
|
||||
- tag
|
||||
- tag::eventtype
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
- user
|
||||
- userAgent
|
||||
- userIdentity.accessKeyId
|
||||
- userIdentity.accountId
|
||||
- userIdentity.arn
|
||||
- userIdentity.principalId
|
||||
- userIdentity.sessionContext.attributes.creationDate
|
||||
- userIdentity.sessionContext.attributes.mfaAuthenticated
|
||||
- userIdentity.sessionContext.sessionIssuer.accountId
|
||||
- userIdentity.sessionContext.sessionIssuer.arn
|
||||
- userIdentity.sessionContext.sessionIssuer.principalId
|
||||
- userIdentity.sessionContext.sessionIssuer.type
|
||||
- userIdentity.sessionContext.sessionIssuer.userName
|
||||
- userIdentity.type
|
||||
- userName
|
||||
- user_access_key
|
||||
- user_agent
|
||||
- user_arn
|
||||
- user_group_id
|
||||
- user_id
|
||||
- user_name
|
||||
- user_type
|
||||
- vendor
|
||||
- vendor_account
|
||||
- vendor_product
|
||||
- vendor_region
|
||||
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "principalId":
|
||||
"AROAIJIESMXKGCJRCTPR6:pbareiss@splunk.local", "arn": "arn:aws:sts::111111111111:assumed-role/okta_adm_role/pbareiss@splunk.local",
|
||||
"accountId": "111111111111", "accessKeyId": "ASIAYTOGP2RLK74OPBDR", "sessionContext":
|
||||
{"sessionIssuer": {"type": "Role", "principalId": "AROAIJIESMXKGCJRCTPR6", "arn":
|
||||
"arn:aws:iam::111111111111:role/okta_adm_role", "accountId": "111111111111", "userName":
|
||||
"okta_adm_role"}, "webIdFederationData": {}, "attributes": {"mfaAuthenticated":
|
||||
"false", "creationDate": "2021-01-11T09:03:18Z"}}}, "eventTime": "2021-01-11T11:04:39Z",
|
||||
"eventSource": "kms.amazonaws.com", "eventName": "PutKeyPolicy", "awsRegion": "us-west-2",
|
||||
"sourceIPAddress": "95.90.199.65", "userAgent": "aws-internal/3 aws-sdk-java/1.11.893
|
||||
Linux/4.9.230-0.1.ac.223.84.332.metal1.x86_64 OpenJDK_64-Bit_Server_VM/25.272-b10
|
||||
java/1.8.0_272 vendor/Oracle_Corporation", "requestParameters": {"keyId": "f2a82583-a7d3-4c92-8787-fe2baab1cee1",
|
||||
"policyName": "default", "policy": "{\n \"Version\": \"2012-10-17\",\n \"Id\":
|
||||
\"key-consolepolicy-3\",\n \"Statement\": [\n {\n \"Sid\":
|
||||
\"Enable IAM User Permissions\",\n \"Effect\": \"Allow\",\n \"Principal\":
|
||||
{\n \"AWS\": \"arn:aws:iam::111111111111:root\"\n },\n \"Action\":
|
||||
\"kms:*\",\n \"Resource\": \"*\"\n },\n {\n \"Sid\":
|
||||
\"Allow access for Key Administrators\",\n \"Effect\": \"Allow\",\n \"Principal\":
|
||||
{\n \"AWS\": \"arn:aws:iam::111111111111:user/patrick_cli\"\n },\n \"Action\":
|
||||
[\n \"kms:Create*\",\n \"kms:Describe*\",\n \"kms:Enable*\",\n \"kms:List*\",\n \"kms:Put*\",\n \"kms:Update*\",\n \"kms:Revoke*\",\n \"kms:Disable*\",\n \"kms:Get*\",\n \"kms:Delete*\",\n \"kms:TagResource\",\n \"kms:UntagResource\",\n \"kms:ScheduleKeyDeletion\",\n \"kms:CancelKeyDeletion\"\n ],\n \"Resource\":
|
||||
\"*\"\n },\n {\n \"Sid\": \"Allow use of the key\",\n \"Effect\":
|
||||
\"Allow\",\n \"Principal\": {\n \"AWS\": \"arn:aws:iam::111111111111:user/patrick_cli\"\n },\n \"Action\":
|
||||
[\n \"kms:Encrypt\",\n \"kms:Decrypt\",\n \"kms:ReEncrypt*\",\n \"kms:GenerateDataKey*\",\n \"kms:DescribeKey\"\n ],\n \"Resource\":
|
||||
\"*\"\n },\n {\n \"Sid\": \"Allow attachment of persistent
|
||||
resources\",\n \"Effect\": \"Allow\",\n \"Principal\": {\n \"AWS\":
|
||||
\"arn:aws:iam::111111111111:user/patrick_cli\"\n },\n \"Action\":
|
||||
[\n \"kms:CreateGrant\",\n \"kms:ListGrants\",\n \"kms:RevokeGrant\"\n ],\n \"Resource\":
|
||||
\"*\",\n \"Condition\": {\n \"Bool\": {\n \"kms:GrantIsForAWSResource\":
|
||||
\"true\"\n }\n }\n },\n {\n \"Sid\":
|
||||
\"Allow use of the key\",\n \"Effect\": \"Allow\",\n \"Principal\":
|
||||
{\n \"AWS\": \"*\"\n },\n \"Action\": [\n \"kms:Encrypt\"\n ],\n \"Resource\":
|
||||
\"*\"\n }\n ]\n}", "bypassPolicyLockoutSafetyCheck": false}, "responseElements":
|
||||
null, "requestID": "c7836c7a-ca95-47aa-a3fb-a7db0d66fec8", "eventID": "612f17e3-2317-4dd9-8aa3-393bc8a7961b",
|
||||
"readOnly": false, "resources": [{"accountId": "111111111111", "type": "AWS::KMS::Key",
|
||||
"ARN": "arn:aws:kms:us-west-2:111111111111:key/f2a82583-a7d3-4c92-8787-fe2baab1cee1"}],
|
||||
"eventType": "AwsApiCall", "managementEvent": true, "eventCategory": "Management",
|
||||
"recipientAccountId": "111111111111"}'
|
||||
@@ -0,0 +1,118 @@
|
||||
name: AWS CloudTrail ReplaceNetworkAclEntry
|
||||
id: db0c240e-3754-40e4-86ef-cde018ee9f65
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for AWS CloudTrail ReplaceNetworkAclEntry
|
||||
source: aws_cloudtrail
|
||||
sourcetype: aws:cloudtrail
|
||||
separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Amazon Web Services (AWS)
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.4.1
|
||||
fields:
|
||||
- _time
|
||||
- action
|
||||
- app
|
||||
- awsRegion
|
||||
- aws_account_id
|
||||
- change_type
|
||||
- command
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- direction
|
||||
- dvc
|
||||
- errorCode
|
||||
- eventCategory
|
||||
- eventID
|
||||
- eventName
|
||||
- eventSource
|
||||
- eventTime
|
||||
- eventType
|
||||
- eventVersion
|
||||
- eventtype
|
||||
- host
|
||||
- index
|
||||
- linecount
|
||||
- managementEvent
|
||||
- msg
|
||||
- object_category
|
||||
- product
|
||||
- protocol
|
||||
- protocol_code
|
||||
- punct
|
||||
- readOnly
|
||||
- recipientAccountId
|
||||
- region
|
||||
- requestID
|
||||
- requestParameters.aclProtocol
|
||||
- requestParameters.cidrBlock
|
||||
- requestParameters.egress
|
||||
- requestParameters.networkAclId
|
||||
- requestParameters.ruleAction
|
||||
- requestParameters.ruleNumber
|
||||
- responseElements._return
|
||||
- responseElements.requestId
|
||||
- rule_action
|
||||
- signature
|
||||
- source
|
||||
- sourceIPAddress
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- src
|
||||
- src_ip
|
||||
- src_ip_range
|
||||
- start_time
|
||||
- status
|
||||
- tag
|
||||
- tag::eventtype
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
- user
|
||||
- userAgent
|
||||
- userIdentity.accessKeyId
|
||||
- userIdentity.accountId
|
||||
- userIdentity.arn
|
||||
- userIdentity.principalId
|
||||
- userIdentity.sessionContext.attributes.creationDate
|
||||
- userIdentity.sessionContext.attributes.mfaAuthenticated
|
||||
- userIdentity.sessionContext.sessionIssuer.accountId
|
||||
- userIdentity.sessionContext.sessionIssuer.arn
|
||||
- userIdentity.sessionContext.sessionIssuer.principalId
|
||||
- userIdentity.sessionContext.sessionIssuer.type
|
||||
- userIdentity.sessionContext.sessionIssuer.userName
|
||||
- userIdentity.type
|
||||
- userName
|
||||
- user_access_key
|
||||
- user_agent
|
||||
- user_arn
|
||||
- user_group_id
|
||||
- user_id
|
||||
- user_name
|
||||
- user_type
|
||||
- vendor
|
||||
- vendor_account
|
||||
- vendor_product
|
||||
- vendor_region
|
||||
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "principalId":
|
||||
"AROAIJIESMXKGCJRCTPR6:pbareiss@splunk.local", "arn": "arn:aws:sts::111111111111:assumed-role/okta_adm_role/pbareiss@splunk.local",
|
||||
"accountId": "111111111111", "accessKeyId": "ASIAYTOGP2RLF3F7BXZK", "sessionContext":
|
||||
{"sessionIssuer": {"type": "Role", "principalId": "AROAIJIESMXKGCJRCTPR6", "arn":
|
||||
"arn:aws:iam::111111111111:role/okta_adm_role", "accountId": "111111111111", "userName":
|
||||
"okta_adm_role"}, "webIdFederationData": {}, "attributes": {"mfaAuthenticated":
|
||||
"false", "creationDate": "2021-01-12T08:36:15Z"}}}, "eventTime": "2021-01-12T08:49:49Z",
|
||||
"eventSource": "ec2.amazonaws.com", "eventName": "ReplaceNetworkAclEntry", "awsRegion":
|
||||
"eu-central-1", "sourceIPAddress": "95.90.199.65", "userAgent": "console.ec2.amazonaws.com",
|
||||
"requestParameters": {"networkAclId": "acl-078ccebebcbabe175", "ruleNumber": 20,
|
||||
"egress": false, "ruleAction": "allow", "icmpTypeCode": {}, "portRange": {}, "aclProtocol":
|
||||
"-1", "cidrBlock": "0.0.0.0/0"}, "responseElements": {"requestId": "97b40da9-9291-4a92-8e9e-892b6887ffc9",
|
||||
"_return": true}, "requestID": "97b40da9-9291-4a92-8e9e-892b6887ffc9", "eventID":
|
||||
"46fe04b8-d007-4933-8bb8-c8b65c1121fa", "readOnly": false, "eventType": "AwsApiCall",
|
||||
"managementEvent": true, "eventCategory": "Management", "recipientAccountId": "111111111111"}'
|
||||
@@ -0,0 +1,99 @@
|
||||
name: AWS CloudTrail SetDefaultPolicyVersion
|
||||
id: 06e0b5a0-8d36-485e-befc-4ae79d77ef6c
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for AWS CloudTrail SetDefaultPolicyVersion
|
||||
source: aws_cloudtrail
|
||||
sourcetype: aws:cloudtrail
|
||||
separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Amazon Web Services (AWS)
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.4.1
|
||||
fields:
|
||||
- _time
|
||||
- action
|
||||
- app
|
||||
- awsRegion
|
||||
- aws_account_id
|
||||
- change_type
|
||||
- command
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- dest
|
||||
- dvc
|
||||
- errorCode
|
||||
- eventCategory
|
||||
- eventID
|
||||
- eventName
|
||||
- eventSource
|
||||
- eventTime
|
||||
- eventType
|
||||
- eventVersion
|
||||
- eventtype
|
||||
- host
|
||||
- index
|
||||
- linecount
|
||||
- managementEvent
|
||||
- msg
|
||||
- object_category
|
||||
- product
|
||||
- punct
|
||||
- readOnly
|
||||
- recipientAccountId
|
||||
- region
|
||||
- requestID
|
||||
- requestParameters.policyArn
|
||||
- requestParameters.versionId
|
||||
- responseElements
|
||||
- signature
|
||||
- source
|
||||
- sourceIPAddress
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- src
|
||||
- src_ip
|
||||
- start_time
|
||||
- status
|
||||
- tag
|
||||
- tag::eventtype
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
- user
|
||||
- userAgent
|
||||
- userIdentity.accessKeyId
|
||||
- userIdentity.accountId
|
||||
- userIdentity.arn
|
||||
- userIdentity.principalId
|
||||
- userIdentity.type
|
||||
- userIdentity.userName
|
||||
- userName
|
||||
- user_access_key
|
||||
- user_agent
|
||||
- user_arn
|
||||
- user_group_id
|
||||
- user_id
|
||||
- user_name
|
||||
- user_type
|
||||
- vendor
|
||||
- vendor_account
|
||||
- vendor_product
|
||||
- vendor_region
|
||||
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId":
|
||||
"AIDAYTOGP2RLESDK2NOSX", "arn": "arn:aws:iam::111111111111:user/AtomicRedTeam",
|
||||
"accountId": "111111111111", "accessKeyId": "AKIAYTOGP2RLKMZDMPVA", "userName":
|
||||
"AtomicRedTeam"}, "eventTime": "2021-03-02T21:05:49Z", "eventSource": "iam.amazonaws.com",
|
||||
"eventName": "SetDefaultPolicyVersion", "awsRegion": "us-east-1", "sourceIPAddress":
|
||||
"73.15.72.101", "userAgent": "aws-cli/2.0.62 Python/3.9.0 Darwin/19.6.0 source/x86_64
|
||||
command/iam.set-default-policy-version", "requestParameters": {"policyArn": "arn:aws:iam::111111111111:policy/VulnerablePolicy",
|
||||
"versionId": "v1"}, "responseElements": null, "requestID": "3bdf8738-2eab-4ae8-a858-2e2a4ccfc66b",
|
||||
"eventID": "742f6e55-4bc7-49e2-965f-56ffbc46a980", "readOnly": false, "eventType":
|
||||
"AwsApiCall", "managementEvent": true, "eventCategory": "Management", "recipientAccountId":
|
||||
"111111111111"}'
|
||||
@@ -0,0 +1,95 @@
|
||||
name: AWS CloudTrail StopLogging
|
||||
id: c5de7c54-4809-4659-bf9f-3bacf8bdfd35
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for AWS CloudTrail StopLogging
|
||||
source: aws_cloudtrail
|
||||
sourcetype: aws:cloudtrail
|
||||
separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Amazon Web Services (AWS)
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.4.1
|
||||
fields:
|
||||
- _time
|
||||
- app
|
||||
- awsRegion
|
||||
- aws_account_id
|
||||
- command
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- dest
|
||||
- dvc
|
||||
- errorCode
|
||||
- eventCategory
|
||||
- eventID
|
||||
- eventName
|
||||
- eventSource
|
||||
- eventTime
|
||||
- eventType
|
||||
- eventVersion
|
||||
- host
|
||||
- index
|
||||
- linecount
|
||||
- managementEvent
|
||||
- msg
|
||||
- object_category
|
||||
- product
|
||||
- punct
|
||||
- readOnly
|
||||
- recipientAccountId
|
||||
- region
|
||||
- requestID
|
||||
- requestParameters.name
|
||||
- responseElements
|
||||
- signature
|
||||
- source
|
||||
- sourceIPAddress
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- src
|
||||
- src_ip
|
||||
- start_time
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
- tlsDetails.cipherSuite
|
||||
- tlsDetails.clientProvidedHostHeader
|
||||
- tlsDetails.tlsVersion
|
||||
- user
|
||||
- userAgent
|
||||
- userIdentity.accessKeyId
|
||||
- userIdentity.accountId
|
||||
- userIdentity.arn
|
||||
- userIdentity.principalId
|
||||
- userIdentity.type
|
||||
- userIdentity.userName
|
||||
- userName
|
||||
- user_access_key
|
||||
- user_agent
|
||||
- user_arn
|
||||
- user_group_id
|
||||
- user_id
|
||||
- user_name
|
||||
- user_type
|
||||
- vendor
|
||||
- vendor_account
|
||||
- vendor_product
|
||||
- vendor_region
|
||||
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId":
|
||||
"AIDAYTOGP2RLEHRX5YWNV", "arn": "arn:aws:iam::111111111111:user/bhavin_cli", "accountId":
|
||||
"111111111111", "accessKeyId": "AKIAYTOGP2RLKQ3U2PDY", "userName": "bhavin_cli"},
|
||||
"eventTime": "2022-06-30T21:26:49Z", "eventSource": "cloudtrail.amazonaws.com",
|
||||
"eventName": "StopLogging", "awsRegion": "us-west-2", "sourceIPAddress": "72.193.184.209",
|
||||
"userAgent": "stratus-red-team_a6a8f8f2-d560-4062-bd0d-c232130cfcc5", "requestParameters":
|
||||
{"name": "my-cloudtrail-trail"}, "responseElements": null, "requestID": "d8b79caa-08d2-4f7e-b93a-73bb7b85f260",
|
||||
"eventID": "9f8d2b82-6e9d-45b8-9055-78d8c00ca416", "readOnly": false, "eventType":
|
||||
"AwsApiCall", "managementEvent": true, "recipientAccountId": "111111111111", "eventCategory":
|
||||
"Management", "tlsDetails": {"tlsVersion": "TLSv1.2", "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
|
||||
"clientProvidedHostHeader": "cloudtrail.us-west-2.amazonaws.com"}}'
|
||||
@@ -0,0 +1,107 @@
|
||||
name: AWS CloudTrail UpdateAccountPasswordPolicy
|
||||
id: 35a8cc97-3600-40e1-a5d1-1c2ad5060be0
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for AWS CloudTrail UpdateAccountPasswordPolicy
|
||||
source: aws_cloudtrail
|
||||
sourcetype: aws:cloudtrail
|
||||
separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Amazon Web Services (AWS)
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.4.1
|
||||
fields:
|
||||
- _time
|
||||
- action
|
||||
- app
|
||||
- awsRegion
|
||||
- aws_account_id
|
||||
- change_type
|
||||
- command
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- dest
|
||||
- dvc
|
||||
- errorCode
|
||||
- eventCategory
|
||||
- eventID
|
||||
- eventName
|
||||
- eventSource
|
||||
- eventTime
|
||||
- eventType
|
||||
- eventVersion
|
||||
- eventtype
|
||||
- host
|
||||
- index
|
||||
- linecount
|
||||
- managementEvent
|
||||
- msg
|
||||
- object_category
|
||||
- product
|
||||
- punct
|
||||
- readOnly
|
||||
- recipientAccountId
|
||||
- region
|
||||
- requestID
|
||||
- requestParameters.allowUsersToChangePassword
|
||||
- requestParameters.hardExpiry
|
||||
- requestParameters.minimumPasswordLength
|
||||
- requestParameters.requireLowercaseCharacters
|
||||
- requestParameters.requireNumbers
|
||||
- requestParameters.requireSymbols
|
||||
- requestParameters.requireUppercaseCharacters
|
||||
- responseElements
|
||||
- sessionCredentialFromConsole
|
||||
- signature
|
||||
- source
|
||||
- sourceIPAddress
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- src
|
||||
- src_ip
|
||||
- start_time
|
||||
- status
|
||||
- tag
|
||||
- tag::eventtype
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
- user
|
||||
- userAgent
|
||||
- userIdentity.accessKeyId
|
||||
- userIdentity.accountId
|
||||
- userIdentity.arn
|
||||
- userIdentity.principalId
|
||||
- userIdentity.sessionContext.attributes.creationDate
|
||||
- userIdentity.sessionContext.attributes.mfaAuthenticated
|
||||
- userIdentity.type
|
||||
- userName
|
||||
- user_access_key
|
||||
- user_agent
|
||||
- user_arn
|
||||
- user_group_id
|
||||
- user_id
|
||||
- user_name
|
||||
- user_type
|
||||
- vendor
|
||||
- vendor_account
|
||||
- vendor_product
|
||||
- vendor_region
|
||||
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "Root", "principalId":
|
||||
"111111111111", "arn": "arn:aws:iam::111111111111:root", "accountId": "111111111111",
|
||||
"accessKeyId": "ASIASBMSCQHHZZ4THONS", "sessionContext": {"sessionIssuer": {}, "webIdFederationData":
|
||||
{}, "attributes": {"creationDate": "2023-01-26T22:10:41Z", "mfaAuthenticated": "false"}}},
|
||||
"eventTime": "2023-01-26T22:38:59Z", "eventSource": "iam.amazonaws.com", "eventName":
|
||||
"UpdateAccountPasswordPolicy", "awsRegion": "us-east-1", "sourceIPAddress": "23.93.193.7",
|
||||
"userAgent": "AWS Internal", "requestParameters": {"minimumPasswordLength": 6, "requireSymbols":
|
||||
true, "requireNumbers": false, "requireUppercaseCharacters": false, "requireLowercaseCharacters":
|
||||
false, "allowUsersToChangePassword": false, "hardExpiry": false}, "responseElements":
|
||||
null, "requestID": "7685efa9-5c56-451a-bd25-3db520108589", "eventID": "ccc1d5c2-dd72-4798-8023-ed5a4205f2d5",
|
||||
"readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId":
|
||||
"111111111111", "eventCategory": "Management", "sessionCredentialFromConsole": "true"}'
|
||||
@@ -0,0 +1,97 @@
|
||||
name: AWS CloudTrail UpdateLoginProfile
|
||||
id: 1db79158-e5d3-4d35-9d3c-586e44e09f1c
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for AWS CloudTrail UpdateLoginProfile
|
||||
source: aws_cloudtrail
|
||||
sourcetype: aws:cloudtrail
|
||||
separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Amazon Web Services (AWS)
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.4.1
|
||||
fields:
|
||||
- _time
|
||||
- action
|
||||
- app
|
||||
- awsRegion
|
||||
- aws_account_id
|
||||
- change_type
|
||||
- command
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- dest
|
||||
- dvc
|
||||
- errorCode
|
||||
- eventCategory
|
||||
- eventID
|
||||
- eventName
|
||||
- eventSource
|
||||
- eventTime
|
||||
- eventType
|
||||
- eventVersion
|
||||
- eventtype
|
||||
- host
|
||||
- index
|
||||
- linecount
|
||||
- managementEvent
|
||||
- msg
|
||||
- object_category
|
||||
- product
|
||||
- punct
|
||||
- readOnly
|
||||
- recipientAccountId
|
||||
- region
|
||||
- requestID
|
||||
- requestParameters.userName
|
||||
- responseElements
|
||||
- signature
|
||||
- source
|
||||
- sourceIPAddress
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- src
|
||||
- src_ip
|
||||
- start_time
|
||||
- status
|
||||
- tag
|
||||
- tag::eventtype
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
- user
|
||||
- userAgent
|
||||
- userIdentity.accessKeyId
|
||||
- userIdentity.accountId
|
||||
- userIdentity.arn
|
||||
- userIdentity.principalId
|
||||
- userIdentity.type
|
||||
- userIdentity.userName
|
||||
- userName
|
||||
- user_access_key
|
||||
- user_agent
|
||||
- user_arn
|
||||
- user_group_id
|
||||
- user_id
|
||||
- user_name
|
||||
- user_type
|
||||
- vendor
|
||||
- vendor_account
|
||||
- vendor_product
|
||||
- vendor_region
|
||||
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId":
|
||||
"AIDAYTOGP2RLEHRX5YWNV", "arn": "arn:aws:iam::111111111111:user/bhavin_cli", "accountId":
|
||||
"111111111111", "accessKeyId": "AKIAYTOGP2RLLAA6NJUM", "userName": "bhavin_cli"},
|
||||
"eventTime": "2021-03-05T01:02:59Z", "eventSource": "iam.amazonaws.com", "eventName":
|
||||
"UpdateLoginProfile", "awsRegion": "us-east-1", "sourceIPAddress": "73.15.72.101",
|
||||
"userAgent": "aws-cli/2.0.62 Python/3.9.2 Darwin/19.6.0 source/x86_64 command/iam.update-login-profile",
|
||||
"requestParameters": {"userName": "AtomicRedTeam"}, "responseElements": null, "requestID":
|
||||
"08f38478-1749-4fb5-b07c-469d3448777a", "eventID": "033580e7-bbba-4b70-be63-7eeddb04b842",
|
||||
"readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "eventCategory":
|
||||
"Management", "recipientAccountId": "111111111111"}'
|
||||
@@ -0,0 +1,187 @@
|
||||
name: AWS CloudTrail UpdateSAMLProvider
|
||||
id: e5eb628d-711e-499c-87d9-8fa5dee419ec
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for AWS CloudTrail UpdateSAMLProvider
|
||||
source: aws_cloudtrail
|
||||
sourcetype: aws:cloudtrail
|
||||
separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Amazon Web Services (AWS)
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.4.1
|
||||
fields:
|
||||
- _time
|
||||
- action
|
||||
- app
|
||||
- awsRegion
|
||||
- aws_account_id
|
||||
- change_type
|
||||
- command
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- dest
|
||||
- dvc
|
||||
- errorCode
|
||||
- eventCategory
|
||||
- eventID
|
||||
- eventName
|
||||
- eventSource
|
||||
- eventTime
|
||||
- eventType
|
||||
- eventVersion
|
||||
- eventtype
|
||||
- host
|
||||
- index
|
||||
- linecount
|
||||
- managementEvent
|
||||
- msg
|
||||
- object_category
|
||||
- product
|
||||
- punct
|
||||
- readOnly
|
||||
- recipientAccountId
|
||||
- region
|
||||
- requestID
|
||||
- requestParameters.sAMLMetadataDocument
|
||||
- requestParameters.sAMLProviderArn
|
||||
- responseElements.sAMLProviderArn
|
||||
- signature
|
||||
- source
|
||||
- sourceIPAddress
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- src
|
||||
- src_ip
|
||||
- start_time
|
||||
- status
|
||||
- tag
|
||||
- tag::eventtype
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
- user
|
||||
- userAgent
|
||||
- userIdentity.accessKeyId
|
||||
- userIdentity.accountId
|
||||
- userIdentity.arn
|
||||
- userIdentity.principalId
|
||||
- userIdentity.sessionContext.attributes.creationDate
|
||||
- userIdentity.sessionContext.attributes.mfaAuthenticated
|
||||
- userIdentity.sessionContext.sessionIssuer.accountId
|
||||
- userIdentity.sessionContext.sessionIssuer.arn
|
||||
- userIdentity.sessionContext.sessionIssuer.principalId
|
||||
- userIdentity.sessionContext.sessionIssuer.type
|
||||
- userIdentity.sessionContext.sessionIssuer.userName
|
||||
- userIdentity.type
|
||||
- userName
|
||||
- user_access_key
|
||||
- user_agent
|
||||
- user_arn
|
||||
- user_group_id
|
||||
- user_id
|
||||
- user_name
|
||||
- user_type
|
||||
- vendor
|
||||
- vendor_account
|
||||
- vendor_product
|
||||
- vendor_region
|
||||
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "principalId":
|
||||
"AROAYTOGP2RLKFUVAQAIJ:rodsoto@rodsoto.onmicrosoft.com", "arn": "arn:aws:sts::111111111111:assumed-role/rodonmicrotestrole/rodsoto@rodsoto.onmicrosoft.com",
|
||||
"accountId": "111111111111", "accessKeyId": "ASIAYTOGP2RLMZGPIW6C", "sessionContext":
|
||||
{"sessionIssuer": {"type": "Role", "principalId": "AROAYTOGP2RLKFUVAQAIJ", "arn":
|
||||
"arn:aws:iam::111111111111:role/rodonmicrotestrole", "accountId": "111111111111",
|
||||
"userName": "rodonmicrotestrole"}, "webIdFederationData": {}, "attributes": {"mfaAuthenticated":
|
||||
"false", "creationDate": "2021-01-20T03:10:32Z"}}}, "eventTime": "2021-01-20T03:12:39Z",
|
||||
"eventSource": "iam.amazonaws.com", "eventName": "UpdateSAMLProvider", "awsRegion":
|
||||
"us-east-1", "sourceIPAddress": "66.176.252.11", "userAgent": "aws-internal/3 aws-sdk-java/1.11.930
|
||||
Linux/4.9.230-0.1.ac.223.84.332.metal1.x86_64 OpenJDK_64-Bit_Server_VM/25.275-b01
|
||||
java/1.8.0_275 vendor/Oracle_Corporation", "requestParameters": {"sAMLMetadataDocument":
|
||||
"<?xml version=\"1.0\" encoding=\"utf-8\"?><EntityDescriptor ID=\"_6898aaf1-1639-44d4-956b-5bf936af37f1\"
|
||||
entityID=\"https://sts.windows.net/0e8108b1-18e9-41a4-961b-dfcddf92ef08/\" xmlns=\"urn:oasis:names:tc:SAML:2.0:metadata\"><Signature
|
||||
xmlns=\"http://www.w3.org/2000/09/xmldsig#\"><SignedInfo><CanonicalizationMethod
|
||||
Algorithm=\"http://www.w3.org/2001/10/xml-exc-c14n#\" /><SignatureMethod Algorithm=\"http://www.w3.org/2001/04/xmldsig-more#rsa-sha256\"
|
||||
/><Reference URI=\"#_6898aaf1-1639-44d4-956b-5bf936af37f1\"><Transforms><Transform
|
||||
Algorithm=\"http://www.w3.org/2000/09/xmldsig#enveloped-signature\" /><Transform
|
||||
Algorithm=\"http://www.w3.org/2001/10/xml-exc-c14n#\" /></Transforms><DigestMethod
|
||||
Algorithm=\"http://www.w3.org/2001/04/xmlenc#sha256\" /><DigestValue>ncp+pf0e75KdoRTy1PQeu74OKXjcVNM+bnT7Ns6cwQI=</DigestValue></Reference></SignedInfo><SignatureValue>J9PRCq201gGMzMtt4Ye+gsM7xOgrNvDg/usqIMvsyUy2r/MeTBz5FKCK+Okjwm49vyTWUoUioYGiwm/TD2Knv59g1zy+/OjZcmBJgDrCmksFJdkwG/fDlOZQNGuj2qh1CEKL5n6Ipy2z1dQ9XUmhhndtXNnjdZ0fJ9QWufWoxveSCLHcU7eUB9obwq96pbAp+6as0XreMNC/xPv5gDdHfKaIppsXtEwcZY7m1c25jDWqPUTQrtbVC0uryffg1Yu0JLTr646GMTzxulBSpQGRfNf5UT0bUiLtKngi++UHrngKdv3ovWwpVmY82JhG7rMDhkuWZu3LdEFvY3svNxGtsQ==</SignatureValue><KeyInfo><X509Data><X509Certificate>MIIDPzCCAiegAwIBAgIQOpwRqLOiO5dOnZepSd5yJzANBgkqhkiG9w0BAQsFADAhMR8wHQYDVQQDDBZhZGZzLmF0dGFja3JhbmdlLmxvY2FsMB4XDTIxMDEwNjIyMzAyMloXDTIyMDEwNjIyNTAyMlowITEfMB0GA1UEAwwWYWRmcy5hdHRhY2tyYW5nZS5sb2NhbDCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAKCwp37iASl3qvAbIyYGI1HOwIlZCAuwLZF+ROf0SVpl+KC19nR+ws7NjacsxsugHMUT1gc9On/l0Jn5pF6VFFcPyPsVvaxLJ+YMY0SBcIHp1iQOKfA2jIFXs4eoLzcrOpX0vqkKsZEPsUAN8tz7OYOPyIP4gylV6hh3nNJXQ2ogeTHXmrpI7wDrAY72g9tDCAitRvAu+nZOLnYaQ3YmnJJGZd+YvmRUd7WAwngYEbJss55ZcL/JU3VJQMJ7OGtjFhjayDT/dUdtvBUqsfF27cArbT5WgGm8WX+WWrJTJgqhQ9YpRUXFajt7Ky5fDLG1cuL6FCHpfrBuRsy7MdY/B+0CAwEAAaNzMHEwDgYDVR0PAQH/BAQDAgWgMB0GA1UdJQQWMBQGCCsGAQUFBwMCBggrBgEFBQcDATAhBgNVHREEGjAYghZhZGZzLmF0dGFja3JhbmdlLmxvY2FsMB0GA1UdDgQWBBQCPwpG/CPNUFbkjPjBuXJr1AOIdzANBgkqhkiG9w0BAQsFAAOCAQEAlzPZxjHF8tLmpf2KLeu9OlVSdcJ/vER7H/3gZmDEnNET/FHbY20npgiQgyk2XoM9WBe9zsuDcORfhndUnW+NHaAHZfdTvtvq1wPoqnEFdedRKMoXU7DtcHHnK533/4ysdcpI8rMS4Tg/WTmFHmubs0xc1TGHL4nVPC1p7Tz6ijkluHxkZFjf0VER/lc6LBXxhEgPuX+aYFvMq1Ty8dYbYjQ9C1sKWYavOnR11pB3uGTRYaj0FwTGhP/UfpkKuaKRhx0j1Iwe01rNDl1+tWhAwZXGDFFcJMTx/Z+vCcSlijBLeVCP7mmm0QgFn7AWrqhAUKkqfcVVvYLgi+FTcuJuSA==</X509Certificate></X509Data></KeyInfo></Signature><RoleDescriptor
|
||||
xsi:type=\"fed:SecurityTokenServiceType\" protocolSupportEnumeration=\"http://docs.oasis-open.org/wsfed/federation/200706\"
|
||||
xmlns:xsi=\"http://www.w3.org/2001/XMLSchema-instance\" xmlns:fed=\"http://docs.oasis-open.org/wsfed/federation/200706\"><KeyDescriptor
|
||||
use=\"signing\"><KeyInfo xmlns=\"http://www.w3.org/2000/09/xmldsig#\"><X509Data><X509Certificate>MIIDPzCCAiegAwIBAgIQOpwRqLOiO5dOnZepSd5yJzANBgkqhkiG9w0BAQsFADAhMR8wHQYDVQQDDBZhZGZzLmF0dGFja3JhbmdlLmxvY2FsMB4XDTIxMDEwNjIyMzAyMloXDTIyMDEwNjIyNTAyMlowITEfMB0GA1UEAwwWYWRmcy5hdHRhY2tyYW5nZS5sb2NhbDCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAKCwp37iASl3qvAbIyYGI1HOwIlZCAuwLZF+ROf0SVpl+KC19nR+ws7NjacsxsugHMUT1gc9On/l0Jn5pF6VFFcPyPsVvaxLJ+YMY0SBcIHp1iQOKfA2jIFXs4eoLzcrOpX0vqkKsZEPsUAN8tz7OYOPyIP4gylV6hh3nNJXQ2ogeTHXmrpI7wDrAY72g9tDCAitRvAu+nZOLnYaQ3YmnJJGZd+YvmRUd7WAwngYEbJss55ZcL/JU3VJQMJ7OGtjFhjayDT/dUdtvBUqsfF27cArbT5WgGm8WX+WWrJTJgqhQ9YpRUXFajt7Ky5fDLG1cuL6FCHpfrBuRsy7MdY/B+0CAwEAAaNzMHEwDgYDVR0PAQH/BAQDAgWgMB0GA1UdJQQWMBQGCCsGAQUFBwMCBggrBgEFBQcDATAhBgNVHREEGjAYghZhZGZzLmF0dGFja3JhbmdlLmxvY2FsMB0GA1UdDgQWBBQCPwpG/CPNUFbkjPjBuXJr1AOIdzANBgkqhkiG9w0BAQsFAAOCAQEAlzPZxjHF8tLmpf2KLeu9OlVSdcJ/vER7H/3gZmDEnNET/FHbY20npgiQgyk2XoM9WBe9zsuDcORfhndUnW+NHaAHZfdTvtvq1wPoqnEFdedRKMoXU7DtcHHnK533/4ysdcpI8rMS4Tg/WTmFHmubs0xc1TGHL4nVPC1p7Tz6ijkluHxkZFjf0VER/lc6LBXxhEgPuX+aYFvMq1Ty8dYbYjQ9C1sKWYavOnR11pB3uGTRYaj0FwTGhP/UfpkKuaKRhx0j1Iwe01rNDl1+tWhAwZXGDFFcJMTx/Z+vCcSlijBLeVCP7mmm0QgFn7AWrqhAUKkqfcVVvYLgi+FTcuJuSA==</X509Certificate></X509Data></KeyInfo></KeyDescriptor><KeyDescriptor
|
||||
use=\"signing\"><KeyInfo xmlns=\"http://www.w3.org/2000/09/xmldsig#\"><X509Data><X509Certificate>MIIC8DCCAdigAwIBAgIQMN9XaFEOfIpMuOqq+1JFzzANBgkqhkiG9w0BAQsFADA0MTIwMAYDVQQDEylNaWNyb3NvZnQgQXp1cmUgRmVkZXJhdGVkIFNTTyBDZXJ0aWZpY2F0ZTAeFw0yMTAxMTcxODU2MTZaFw0yNDAxMTcyMTU2MTRaMDQxMjAwBgNVBAMTKU1pY3Jvc29mdCBBenVyZSBGZWRlcmF0ZWQgU1NPIENlcnRpZmljYXRlMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA2GO3vs2HPr+EXEVnWNRDOIjxS5tP2i9xq/399CAl/sWSbJkooGjcCKWf0DN1cGbbbrzL/V+Hor/htEFBpsbUsL8NbaE5pZOnH3oWquiHFiMs1t3Dh4dSVViKyMgIx/i5j4qUW74fYHvgead3kTIV7oSIYHXPNSF6SGLR8qWgRSCLre5P80PnzQmFoI1MbfJbJWf4rWBRVylJaamRFi8X/9byGAQKNYtrjnxCPtdvqUG03EMvwrUCTOM49qnuUhHUCtrIk8MQ1/xzHePkWT3OXmfCi0ABDFAnb9GH763rLlrawVaZKMzmICQ/Rts3+NUm0urSbPlUq1+IfbCsRCwz/QIDAQABMA0GCSqGSIb3DQEBCwUAA4IBAQA+ZOJcY1oGsj/LLa0KLhlUolA7dojhwDtZFPRInLcyBQ6G2fkEZr7jdgY0vg8X86vFCw2JLIC5UmUrXsC1YGxD0kzdMAqr06uVOxGKD/QCRKfes3AYqv/axoJpSm1uZP2066816bYIpOMjcc5yQaEzFh6Y2d5Ovd+DJ/BLVmTFuKs9p9q5JCpOQQT73c0actHdXsjZeM0iHbuWtQOu6LHJuQRbl7BCdKblLvpnoF7DrAHLq1xArcSUEuXa590aga7Ld9P/6BrTQ26QdGGfmJlRiaWh5iu22lbI169NlFd+EmgXIFWK0Qu6i7zyNkGTTA2GOOG9Z/vNIGKRxmV4l7KN</X509Certificate></X509Data></KeyInfo></KeyDescriptor><fed:ClaimTypesOffered><auth:ClaimType
|
||||
Uri=\"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name\" xmlns:auth=\"http://docs.oasis-open.org/wsfed/authorization/200706\"><auth:DisplayName>Name</auth:DisplayName><auth:Description>The
|
||||
mutable display name of the user.</auth:Description></auth:ClaimType><auth:ClaimType
|
||||
Uri=\"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier\" xmlns:auth=\"http://docs.oasis-open.org/wsfed/authorization/200706\"><auth:DisplayName>Subject</auth:DisplayName><auth:Description>An
|
||||
immutable, globally unique, non-reusable identifier of the user that is unique to
|
||||
the application for which a token is issued.</auth:Description></auth:ClaimType><auth:ClaimType
|
||||
Uri=\"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname\" xmlns:auth=\"http://docs.oasis-open.org/wsfed/authorization/200706\"><auth:DisplayName>Given
|
||||
Name</auth:DisplayName><auth:Description>First name of the user.</auth:Description></auth:ClaimType><auth:ClaimType
|
||||
Uri=\"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname\" xmlns:auth=\"http://docs.oasis-open.org/wsfed/authorization/200706\"><auth:DisplayName>Surname</auth:DisplayName><auth:Description>Last
|
||||
name of the user.</auth:Description></auth:ClaimType><auth:ClaimType Uri=\"http://schemas.microsoft.com/identity/claims/displayname\"
|
||||
xmlns:auth=\"http://docs.oasis-open.org/wsfed/authorization/200706\"><auth:DisplayName>Display
|
||||
Name</auth:DisplayName><auth:Description>Display name of the user.</auth:Description></auth:ClaimType><auth:ClaimType
|
||||
Uri=\"http://schemas.microsoft.com/identity/claims/nickname\" xmlns:auth=\"http://docs.oasis-open.org/wsfed/authorization/200706\"><auth:DisplayName>Nick
|
||||
Name</auth:DisplayName><auth:Description>Nick name of the user.</auth:Description></auth:ClaimType><auth:ClaimType
|
||||
Uri=\"http://schemas.microsoft.com/ws/2008/06/identity/claims/authenticationinstant\"
|
||||
xmlns:auth=\"http://docs.oasis-open.org/wsfed/authorization/200706\"><auth:DisplayName>Authentication
|
||||
Instant</auth:DisplayName><auth:Description>The time (UTC) when the user is authenticated
|
||||
to Windows Azure Active Directory.</auth:Description></auth:ClaimType><auth:ClaimType
|
||||
Uri=\"http://schemas.microsoft.com/ws/2008/06/identity/claims/authenticationmethod\"
|
||||
xmlns:auth=\"http://docs.oasis-open.org/wsfed/authorization/200706\"><auth:DisplayName>Authentication
|
||||
Method</auth:DisplayName><auth:Description>The method that Windows Azure Active
|
||||
Directory uses to authenticate users.</auth:Description></auth:ClaimType><auth:ClaimType
|
||||
Uri=\"http://schemas.microsoft.com/identity/claims/objectidentifier\" xmlns:auth=\"http://docs.oasis-open.org/wsfed/authorization/200706\"><auth:DisplayName>ObjectIdentifier</auth:DisplayName><auth:Description>Primary
|
||||
identifier for the user in the directory. Immutable, globally unique, non-reusable.</auth:Description></auth:ClaimType><auth:ClaimType
|
||||
Uri=\"http://schemas.microsoft.com/identity/claims/tenantid\" xmlns:auth=\"http://docs.oasis-open.org/wsfed/authorization/200706\"><auth:DisplayName>TenantId</auth:DisplayName><auth:Description>Identifier
|
||||
for the user''s tenant.</auth:Description></auth:ClaimType><auth:ClaimType Uri=\"http://schemas.microsoft.com/identity/claims/identityprovider\"
|
||||
xmlns:auth=\"http://docs.oasis-open.org/wsfed/authorization/200706\"><auth:DisplayName>IdentityProvider</auth:DisplayName><auth:Description>Identity
|
||||
provider for the user.</auth:Description></auth:ClaimType><auth:ClaimType Uri=\"http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress\"
|
||||
xmlns:auth=\"http://docs.oasis-open.org/wsfed/authorization/200706\"><auth:DisplayName>Email</auth:DisplayName><auth:Description>Email
|
||||
address of the user.</auth:Description></auth:ClaimType><auth:ClaimType Uri=\"http://schemas.microsoft.com/ws/2008/06/identity/claims/groups\"
|
||||
xmlns:auth=\"http://docs.oasis-open.org/wsfed/authorization/200706\"><auth:DisplayName>Groups</auth:DisplayName><auth:Description>Groups
|
||||
of the user.</auth:Description></auth:ClaimType><auth:ClaimType Uri=\"http://schemas.microsoft.com/identity/claims/accesstoken\"
|
||||
xmlns:auth=\"http://docs.oasis-open.org/wsfed/authorization/200706\"><auth:DisplayName>External
|
||||
Access Token</auth:DisplayName><auth:Description>Access token issued by external
|
||||
identity provider.</auth:Description></auth:ClaimType><auth:ClaimType Uri=\"http://schemas.microsoft.com/ws/2008/06/identity/claims/expiration\"
|
||||
xmlns:auth=\"http://docs.oasis-open.org/wsfed/authorization/200706\"><auth:DisplayName>External
|
||||
Access Token Expiration</auth:DisplayName><auth:Description>UTC expiration time
|
||||
of access token issued by external identity provider.</auth:Description></auth:ClaimType><auth:ClaimType
|
||||
Uri=\"http://schemas.microsoft.com/identity/claims/openid2_id\" xmlns:auth=\"http://docs.oasis-open.org/wsfed/authorization/200706\"><auth:DisplayName>External
|
||||
OpenID 2.0 Identifier</auth:DisplayName><auth:Description>OpenID 2.0 identifier
|
||||
issued by external identity provider.</auth:Description></auth:ClaimType><auth:ClaimType
|
||||
Uri=\"http://schemas.microsoft.com/claims/groups.link\" xmlns:auth=\"http://docs.oasis-open.org/wsfed/authorization/200706\"><auth:DisplayName>GroupsOverageClaim</auth:DisplayName><auth:Description>Issued
|
||||
when number of user''s group claims exceeds return limit.</auth:Description></auth:ClaimType><auth:ClaimType
|
||||
Uri=\"http://schemas.microsoft.com/ws/2008/06/identity/claims/role\" xmlns:auth=\"http://docs.oasis-open.org/wsfed/authorization/200706\"><auth:DisplayName>Role
|
||||
Claim</auth:DisplayName><auth:Description>Roles that the user or Service Principal
|
||||
is attached to</auth:Description></auth:ClaimType><auth:ClaimType Uri=\"http://schemas.microsoft.com/ws/2008/06/identity/claims/wids\"
|
||||
xmlns:auth=\"http://docs.oasis-open.org/wsfed/authorization/200706\"><auth:DisplayName>RoleTemplate
|
||||
Id Claim</auth:DisplayName><auth:Description>Role template id of the Built-in Directory
|
||||
Roles that the user is a member of</auth:Description></auth:ClaimType></fed:ClaimTypesOffered><fed:SecurityTokenServiceEndpoint><wsa:EndpointReference
|
||||
xmlns:wsa=\"http://www.w3.org/2005/08/addressing\"><wsa:Address>https://login.microsoftonline.com/0e8108b1-18e9-41a4-961b-dfcddf92ef08/wsfed</wsa:Address></wsa:EndpointReference></fed:SecurityTokenServiceEndpoint><fed:PassiveRequestorEndpoint><wsa:EndpointReference
|
||||
xmlns:wsa=\"http://www.w3.org/2005/08/addressing\"><wsa:Address>https://login.microsoftonline.com/0e8108b1-18e9-41a4-961b-dfcddf92ef08/wsfed</wsa:Address></wsa:EndpointReference></fed:PassiveRequestorEndpoint></RoleDescriptor><RoleDescriptor
|
||||
xsi:type=\"fed:ApplicationServiceType\" protocolSupportEnumeration=\"http://docs.oasis-open.org/wsfed/federation/200706\"
|
||||
xmlns:xsi=\"http://www.w3.org/2001/XMLSchema-instance\" xmlns:fed=\"http://docs.oasis-open.org/wsfed/federation/200706\"><KeyDescriptor
|
||||
use=\"signing\"><KeyInfo xmlns=\"http://www.w3.org/2000/09/xmldsig#\"><X509Data><X509Certificate>MIIDPzCCAiegAwIBAgIQOpwRqLOiO5dOnZepSd5yJzANBgkqhkiG9w0BAQsFADAhMR8wHQYDVQQDDBZhZGZzLmF0dGFja3JhbmdlLmxvY2FsMB4XDTIxMDEwNjIyMzAyMloXDTIyMDEwNjIyNTAyMlowITEfMB0GA1UEAwwWYWRmcy5hdHRhY2tyYW5nZS5sb2NhbDCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAKCwp37iASl3qvAbIyYGI1HOwIlZCAuwLZF+ROf0SVpl+KC19nR+ws7NjacsxsugHMUT1gc9On/l0Jn5pF6VFFcPyPsVvaxLJ+YMY0SBcIHp1iQOKfA2jIFXs4eoLzcrOpX0vqkKsZEPsUAN8tz7OYOPyIP4gylV6hh3nNJXQ2ogeTHXmrpI7wDrAY72g9tDCAitRvAu+nZOLnYaQ3YmnJJGZd+YvmRUd7WAwngYEbJss55ZcL/JU3VJQMJ7OGtjFhjayDT/dUdtvBUqsfF27cArbT5WgGm8WX+WWrJTJgqhQ9YpRUXFajt7Ky5fDLG1cuL6FCHpfrBuRsy7MdY/B+0CAwEAAaNzMHEwDgYDVR0PAQH/BAQDAgWgMB0GA1UdJQQWMBQGCCsGAQUFBwMCBggrBgEFBQcDATAhBgNVHREEGjAYghZhZGZzLmF0dGFja3JhbmdlLmxvY2FsMB0GA1UdDgQWBBQCPwpG/CPNUFbkjPjBuXJr1AOIdzANBgkqhkiG9w0BAQsFAAOCAQEAlzPZxjHF8tLmpf2KLeu9OlVSdcJ/vER7H/3gZmDEnNET/FHbY20npgiQgyk2XoM9WBe9zsuDcORfhndUnW+NHaAHZfdTvtvq1wPoqnEFdedRKMoXU7DtcHHnK533/4ysdcpI8rMS4Tg/WTmFHmubs0xc1TGHL4nVPC1p7Tz6ijkluHxkZFjf0VER/lc6LBXxhEgPuX+aYFvMq1Ty8dYbYjQ9C1sKWYavOnR11pB3uGTRYaj0FwTGhP/UfpkKuaKRhx0j1Iwe01rNDl1+tWhAwZXGDFFcJMTx/Z+vCcSlijBLeVCP7mmm0QgFn7AWrqhAUKkqfcVVvYLgi+FTcuJuSA==</X509Certificate></X509Data></KeyInfo></KeyDescriptor><KeyDescriptor
|
||||
use=\"signing\"><KeyInfo xmlns=\"http://www.w3.org/2000/09/xmldsig#\"><X509Data><X509Certificate>MIIC8DCCAdigAwIBAgIQMN9XaFEOfIpMuOqq+1JFzzANBgkqhkiG9w0BAQsFADA0MTIwMAYDVQQDEylNaWNyb3NvZnQgQXp1cmUgRmVkZXJhdGVkIFNTTyBDZXJ0aWZpY2F0ZTAeFw0yMTAxMTcxODU2MTZaFw0yNDAxMTcyMTU2MTRaMDQxMjAwBgNVBAMTKU1pY3Jvc29mdCBBenVyZSBGZWRlcmF0ZWQgU1NPIENlcnRpZmljYXRlMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA2GO3vs2HPr+EXEVnWNRDOIjxS5tP2i9xq/399CAl/sWSbJkooGjcCKWf0DN1cGbbbrzL/V+Hor/htEFBpsbUsL8NbaE5pZOnH3oWquiHFiMs1t3Dh4dSVViKyMgIx/i5j4qUW74fYHvgead3kTIV7oSIYHXPNSF6SGLR8qWgRSCLre5P80PnzQmFoI1MbfJbJWf4rWBRVylJaamRFi8X/9byGAQKNYtrjnxCPtdvqUG03EMvwrUCTOM49qnuUhHUCtrIk8MQ1/xzHePkWT3OXmfCi0ABDFAnb9GH763rLlrawVaZKMzmICQ/Rts3+NUm0urSbPlUq1+IfbCsRCwz/QIDAQABMA0GCSqGSIb3DQEBCwUAA4IBAQA+ZOJcY1oGsj/LLa0KLhlUolA7dojhwDtZFPRInLcyBQ6G2fkEZr7jdgY0vg8X86vFCw2JLIC5UmUrXsC1YGxD0kzdMAqr06uVOxGKD/QCRKfes3AYqv/axoJpSm1uZP2066816bYIpOMjcc5yQaEzFh6Y2d5Ovd+DJ/BLVmTFuKs9p9q5JCpOQQT73c0actHdXsjZeM0iHbuWtQOu6LHJuQRbl7BCdKblLvpnoF7DrAHLq1xArcSUEuXa590aga7Ld9P/6BrTQ26QdGGfmJlRiaWh5iu22lbI169NlFd+EmgXIFWK0Qu6i7zyNkGTTA2GOOG9Z/vNIGKRxmV4l7KN</X509Certificate></X509Data></KeyInfo></KeyDescriptor><fed:TargetScopes><wsa:EndpointReference
|
||||
xmlns:wsa=\"http://www.w3.org/2005/08/addressing\"><wsa:Address>https://sts.windows.net/0e8108b1-18e9-41a4-961b-dfcddf92ef08/</wsa:Address></wsa:EndpointReference></fed:TargetScopes><fed:ApplicationServiceEndpoint><wsa:EndpointReference
|
||||
xmlns:wsa=\"http://www.w3.org/2005/08/addressing\"><wsa:Address>https://login.microsoftonline.com/0e8108b1-18e9-41a4-961b-dfcddf92ef08/wsfed</wsa:Address></wsa:EndpointReference></fed:ApplicationServiceEndpoint><fed:PassiveRequestorEndpoint><wsa:EndpointReference
|
||||
xmlns:wsa=\"http://www.w3.org/2005/08/addressing\"><wsa:Address>https://login.microsoftonline.com/0e8108b1-18e9-41a4-961b-dfcddf92ef08/wsfed</wsa:Address></wsa:EndpointReference></fed:PassiveRequestorEndpoint></RoleDescriptor><IDPSSODescriptor
|
||||
protocolSupportEnumeration=\"urn:oasis:names:tc:SAML:2.0:protocol\"><KeyDescriptor
|
||||
use=\"signing\"><KeyInfo xmlns=\"http://www.w3.org/2000/09/xmldsig#\"><X509Data><X509Certificate>MIIDPzCCAiegAwIBAgIQOpwRqLOiO5dOnZepSd5yJzANBgkqhkiG9w0BAQsFADAhMR8wHQYDVQQDDBZhZGZzLmF0dGFja3JhbmdlLmxvY2FsMB4XDTIxMDEwNjIyMzAyMloXDTIyMDEwNjIyNTAyMlowITEfMB0GA1UEAwwWYWRmcy5hdHRhY2tyYW5nZS5sb2NhbDCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAKCwp37iASl3qvAbIyYGI1HOwIlZCAuwLZF+ROf0SVpl+KC19nR+ws7NjacsxsugHMUT1gc9On/l0Jn5pF6VFFcPyPsVvaxLJ+YMY0SBcIHp1iQOKfA2jIFXs4eoLzcrOpX0vqkKsZEPsUAN8tz7OYOPyIP4gylV6hh3nNJXQ2ogeTHXmrpI7wDrAY72g9tDCAitRvAu+nZOLnYaQ3YmnJJGZd+YvmRUd7WAwngYEbJss55ZcL/JU3VJQMJ7OGtjFhjayDT/dUdtvBUqsfF27cArbT5WgGm8WX+WWrJTJgqhQ9YpRUXFajt7Ky5fDLG1cuL6FCHpfrBuRsy7MdY/B+0CAwEAAaNzMHEwDgYDVR0PAQH/BAQDAgWgMB0GA1UdJQQWMBQGCCsGAQUFBwMCBggrBgEFBQcDATAhBgNVHREEGjAYghZhZGZzLmF0dGFja3JhbmdlLmxvY2FsMB0GA1UdDgQWBBQCPwpG/CPNUFbkjPjBuXJr1AOIdzANBgkqhkiG9w0BAQsFAAOCAQEAlzPZxjHF8tLmpf2KLeu9OlVSdcJ/vER7H/3gZmDEnNET/FHbY20npgiQgyk2XoM9WBe9zsuDcORfhndUnW+NHaAHZfdTvtvq1wPoqnEFdedRKMoXU7DtcHHnK533/4ysdcpI8rMS4Tg/WTmFHmubs0xc1TGHL4nVPC1p7Tz6ijkluHxkZFjf0VER/lc6LBXxhEgPuX+aYFvMq1Ty8dYbYjQ9C1sKWYavOnR11pB3uGTRYaj0FwTGhP/UfpkKuaKRhx0j1Iwe01rNDl1+tWhAwZXGDFFcJMTx/Z+vCcSlijBLeVCP7mmm0QgFn7AWrqhAUKkqfcVVvYLgi+FTcuJuSA==</X509Certificate></X509Data></KeyInfo></KeyDescriptor><KeyDescriptor
|
||||
use=\"signing\"><KeyInfo xmlns=\"http://www.w3.org/2000/09/xmldsig#\"><X509Data><X509Certificate>MIIC8DCCAdigAwIBAgIQMN9XaFEOfIpMuOqq+1JFzzANBgkqhkiG9w0BAQsFADA0MTIwMAYDVQQDEylNaWNyb3NvZnQgQXp1cmUgRmVkZXJhdGVkIFNTTyBDZXJ0aWZpY2F0ZTAeFw0yMTAxMTcxODU2MTZaFw0yNDAxMTcyMTU2MTRaMDQxMjAwBgNVBAMTKU1pY3Jvc29mdCBBenVyZSBGZWRlcmF0ZWQgU1NPIENlcnRpZmljYXRlMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA2GO3vs2HPr+EXEVnWNRDOIjxS5tP2i9xq/399CAl/sWSbJkooGjcCKWf0DN1cGbbbrzL/V+Hor/htEFBpsbUsL8NbaE5pZOnH3oWquiHFiMs1t3Dh4dSVViKyMgIx/i5j4qUW74fYHvgead3kTIV7oSIYHXPNSF6SGLR8qWgRSCLre5P80PnzQmFoI1MbfJbJWf4rWBRVylJaamRFi8X/9byGAQKNYtrjnxCPtdvqUG03EMvwrUCTOM49qnuUhHUCtrIk8MQ1/xzHePkWT3OXmfCi0ABDFAnb9GH763rLlrawVaZKMzmICQ/Rts3+NUm0urSbPlUq1+IfbCsRCwz/QIDAQABMA0GCSqGSIb3DQEBCwUAA4IBAQA+ZOJcY1oGsj/LLa0KLhlUolA7dojhwDtZFPRInLcyBQ6G2fkEZr7jdgY0vg8X86vFCw2JLIC5UmUrXsC1YGxD0kzdMAqr06uVOxGKD/QCRKfes3AYqv/axoJpSm1uZP2066816bYIpOMjcc5yQaEzFh6Y2d5Ovd+DJ/BLVmTFuKs9p9q5JCpOQQT73c0actHdXsjZeM0iHbuWtQOu6LHJuQRbl7BCdKblLvpnoF7DrAHLq1xArcSUEuXa590aga7Ld9P/6BrTQ26QdGGfmJlRiaWh5iu22lbI169NlFd+EmgXIFWK0Qu6i7zyNkGTTA2GOOG9Z/vNIGKRxmV4l7KN</X509Certificate></X509Data></KeyInfo></KeyDescriptor><SingleLogoutService
|
||||
Binding=\"urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect\" Location=\"https://login.microsoftonline.com/0e8108b1-18e9-41a4-961b-dfcddf92ef08/saml2\"
|
||||
/><SingleSignOnService Binding=\"urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect\"
|
||||
Location=\"https://login.microsoftonline.com/0e8108b1-18e9-41a4-961b-dfcddf92ef08/saml2\"
|
||||
/><SingleSignOnService Binding=\"urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST\"
|
||||
Location=\"https://login.microsoftonline.com/0e8108b1-18e9-41a4-961b-dfcddf92ef08/saml2\"
|
||||
/></IDPSSODescriptor></EntityDescriptor>", "sAMLProviderArn": "arn:aws:iam::111111111111:saml-provider/rodsotoonmicrosoft"},
|
||||
"responseElements": {"sAMLProviderArn": "arn:aws:iam::111111111111:saml-provider/rodsotoonmicrosoft"},
|
||||
"requestID": "83d621ad-5b33-4ff0-acf4-0043cb432844", "eventID": "51b6d859-0cc4-4591-ba76-3494f3f43832",
|
||||
"readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "eventCategory":
|
||||
"Management", "recipientAccountId": "111111111111"}'
|
||||
@@ -0,0 +1,107 @@
|
||||
name: AWS CloudTrail UpdateTrail
|
||||
id: d5b7a1eb-711a-4c96-aa93-235fe3c8a939
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for AWS CloudTrail UpdateTrail
|
||||
source: aws_cloudtrail
|
||||
sourcetype: aws:cloudtrail
|
||||
separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Amazon Web Services (AWS)
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.4.1
|
||||
fields:
|
||||
- _time
|
||||
- app
|
||||
- awsRegion
|
||||
- aws_account_id
|
||||
- command
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- dest
|
||||
- dvc
|
||||
- errorCode
|
||||
- eventCategory
|
||||
- eventID
|
||||
- eventName
|
||||
- eventSource
|
||||
- eventTime
|
||||
- eventType
|
||||
- eventVersion
|
||||
- host
|
||||
- index
|
||||
- linecount
|
||||
- managementEvent
|
||||
- msg
|
||||
- object_category
|
||||
- product
|
||||
- punct
|
||||
- readOnly
|
||||
- recipientAccountId
|
||||
- region
|
||||
- requestID
|
||||
- requestParameters.includeGlobalServiceEvents
|
||||
- requestParameters.isMultiRegionTrail
|
||||
- requestParameters.name
|
||||
- responseElements.includeGlobalServiceEvents
|
||||
- responseElements.isMultiRegionTrail
|
||||
- responseElements.isOrganizationTrail
|
||||
- responseElements.logFileValidationEnabled
|
||||
- responseElements.name
|
||||
- responseElements.s3BucketName
|
||||
- responseElements.trailARN
|
||||
- signature
|
||||
- source
|
||||
- sourceIPAddress
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- src
|
||||
- src_ip
|
||||
- start_time
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
- tlsDetails.cipherSuite
|
||||
- tlsDetails.clientProvidedHostHeader
|
||||
- tlsDetails.tlsVersion
|
||||
- user
|
||||
- userAgent
|
||||
- userIdentity.accessKeyId
|
||||
- userIdentity.accountId
|
||||
- userIdentity.arn
|
||||
- userIdentity.principalId
|
||||
- userIdentity.type
|
||||
- userIdentity.userName
|
||||
- userName
|
||||
- user_access_key
|
||||
- user_agent
|
||||
- user_arn
|
||||
- user_group_id
|
||||
- user_id
|
||||
- user_name
|
||||
- user_type
|
||||
- vendor
|
||||
- vendor_account
|
||||
- vendor_product
|
||||
- vendor_region
|
||||
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId":
|
||||
"AIDAYTOGP2RLI4PXTGCEU", "arn": "arn:aws:iam::111111111111:user/gowthamaraj_cli",
|
||||
"accountId": "111111111111", "accessKeyId": "AKIAYTOGP2RLFLKADUVG", "userName":
|
||||
"gowthamaraj_cli"}, "eventTime": "2022-07-19T08:42:26Z", "eventSource": "cloudtrail.amazonaws.com",
|
||||
"eventName": "UpdateTrail", "awsRegion": "us-west-2", "sourceIPAddress": "67.171.71.185",
|
||||
"userAgent": "aws-cli/2.7.3 Python/3.9.13 Darwin/21.5.0 source/x86_64 prompt/off
|
||||
command/cloudtrail.update-trail", "requestParameters": {"name": "Regulatory", "includeGlobalServiceEvents":
|
||||
true, "isMultiRegionTrail": true}, "responseElements": {"name": "Regulatory", "s3BucketName":
|
||||
"s3-for-cloudtrail-logs111", "includeGlobalServiceEvents": true, "isMultiRegionTrail":
|
||||
true, "trailARN": "arn:aws:cloudtrail:us-west-2:111111111111:trail/Regulatory",
|
||||
"logFileValidationEnabled": false, "isOrganizationTrail": false}, "requestID": "0da61466-5bba-43f9-b7e1-27437de120b2",
|
||||
"eventID": "ce02af60-f29e-4bc2-8b29-31c12f408fed", "readOnly": false, "eventType":
|
||||
"AwsApiCall", "managementEvent": true, "recipientAccountId": "111111111111", "eventCategory":
|
||||
"Management", "tlsDetails": {"tlsVersion": "TLSv1.2", "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
|
||||
"clientProvidedHostHeader": "cloudtrail.us-west-2.amazonaws.com"}}'
|
||||
@@ -1,119 +1,120 @@
|
||||
name: AWS Security Hub
|
||||
id: b02bfbf3-294f-478e-99a1-e24b8c692d7e
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for AWS Security Hub
|
||||
source: aws_securityhub_finding
|
||||
sourcetype: aws:securityhub:finding
|
||||
supported_TA:
|
||||
name: Splunk Add-on for Amazon Web Services (AWS)
|
||||
version: 7.4.1
|
||||
- name: Splunk Add-on for Amazon Web Services (AWS)
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
event_names: []
|
||||
version: 7.4.1
|
||||
fields:
|
||||
- _time
|
||||
- AwsAccountId
|
||||
- CreatedAt
|
||||
- Description
|
||||
- FirstObservedAt
|
||||
- GeneratorId
|
||||
- Id
|
||||
- LastObservedAt
|
||||
- ProductArn
|
||||
- ProductFields.aws/guardduty/service/action/actionType
|
||||
- ProductFields.aws/guardduty/service/action/awsApiCallAction/affectedResources/AWS::S3::Bucket
|
||||
- ProductFields.aws/guardduty/service/action/awsApiCallAction/api
|
||||
- ProductFields.aws/guardduty/service/action/awsApiCallAction/callerType
|
||||
- ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/city/cityName
|
||||
- ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/country/countryName
|
||||
- ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/geoLocation/lat
|
||||
- ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/geoLocation/lon
|
||||
- ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/ipAddressV4
|
||||
- ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/organization/asn
|
||||
- ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/organization/asnOrg
|
||||
- ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/organization/isp
|
||||
- ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/organization/org
|
||||
- ProductFields.aws/guardduty/service/action/awsApiCallAction/serviceName
|
||||
- ProductFields.aws/guardduty/service/additionalInfo/sample
|
||||
- ProductFields.aws/guardduty/service/additionalInfo/unusual/hoursOfDay.0_
|
||||
- ProductFields.aws/guardduty/service/additionalInfo/unusual/userNames.0_
|
||||
- ProductFields.aws/guardduty/service/archived
|
||||
- ProductFields.aws/guardduty/service/count
|
||||
- ProductFields.aws/guardduty/service/detectorId
|
||||
- ProductFields.aws/guardduty/service/eventFirstSeen
|
||||
- ProductFields.aws/guardduty/service/eventLastSeen
|
||||
- ProductFields.aws/guardduty/service/resourceRole
|
||||
- ProductFields.aws/guardduty/service/serviceName
|
||||
- ProductFields.aws/securityhub/CompanyName
|
||||
- ProductFields.aws/securityhub/FindingId
|
||||
- ProductFields.aws/securityhub/ProductName
|
||||
- RecordState
|
||||
- Resources{}.Details.AwsEc2Instance.IamInstanceProfileArn
|
||||
- Resources{}.Details.AwsEc2Instance.ImageId
|
||||
- Resources{}.Details.AwsEc2Instance.IpV4Addresses{}
|
||||
- Resources{}.Details.AwsEc2Instance.LaunchedAt
|
||||
- Resources{}.Details.AwsEc2Instance.SubnetId
|
||||
- Resources{}.Details.AwsEc2Instance.Type
|
||||
- Resources{}.Details.AwsEc2Instance.VpcId
|
||||
- Resources{}.Details.AwsIamAccessKey.PrincipalId
|
||||
- Resources{}.Details.AwsIamAccessKey.PrincipalName
|
||||
- Resources{}.Details.AwsIamAccessKey.PrincipalType
|
||||
- Resources{}.Details.AwsS3Bucket.CreatedAt
|
||||
- Resources{}.Details.AwsS3Bucket.OwnerId
|
||||
- Resources{}.Details.AwsS3Bucket.ServerSideEncryptionConfiguration.Rules{}.ApplyServerSideEncryptionByDefault.KMSMasterKeyID
|
||||
- Resources{}.Details.AwsS3Bucket.ServerSideEncryptionConfiguration.Rules{}.ApplyServerSideEncryptionByDefault.SSEAlgorithm
|
||||
- Resources{}.Id
|
||||
- Resources{}.Partition
|
||||
- Resources{}.Region
|
||||
- Resources{}.Tags.GeneratedFindingInstaceTag1
|
||||
- Resources{}.Tags.GeneratedFindingInstaceTag2
|
||||
- Resources{}.Tags.GeneratedFindingInstaceTag3
|
||||
- Resources{}.Tags.GeneratedFindingInstaceTag4
|
||||
- Resources{}.Tags.GeneratedFindingInstaceTag5
|
||||
- Resources{}.Tags.GeneratedFindingInstaceTag6
|
||||
- Resources{}.Tags.GeneratedFindingInstaceTag7
|
||||
- Resources{}.Tags.GeneratedFindingInstaceTag8
|
||||
- Resources{}.Tags.GeneratedFindingInstaceTag9
|
||||
- Resources{}.Tags.foo
|
||||
- Resources{}.Type
|
||||
- SchemaVersion
|
||||
- Severity.Label
|
||||
- Severity.Normalized
|
||||
- Severity.Product
|
||||
- SourceUrl
|
||||
- Title
|
||||
- Types{}
|
||||
- UpdatedAt
|
||||
- Workflow.Status
|
||||
- WorkflowState
|
||||
- accesskey_extract
|
||||
- app
|
||||
- body
|
||||
- description
|
||||
- dest
|
||||
- dest_type
|
||||
- eventtype
|
||||
- host
|
||||
- id
|
||||
- index
|
||||
- instance_extract
|
||||
- linecount
|
||||
- punct
|
||||
- s3bucket_extract
|
||||
- severity
|
||||
- severity_id
|
||||
- signature
|
||||
- signature_id
|
||||
- source
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- subject
|
||||
- tag
|
||||
- tag::eventtype
|
||||
- timestamp
|
||||
- type
|
||||
- vendor_account
|
||||
- vendor_region
|
||||
example_log:
|
||||
'{"ProductArn":"arn:aws:securityhub:us-east-1::product/aws/guardduty","Types":["Software
|
||||
- _time
|
||||
- AwsAccountId
|
||||
- CreatedAt
|
||||
- Description
|
||||
- FirstObservedAt
|
||||
- GeneratorId
|
||||
- Id
|
||||
- LastObservedAt
|
||||
- ProductArn
|
||||
- ProductFields.aws/guardduty/service/action/actionType
|
||||
- ProductFields.aws/guardduty/service/action/awsApiCallAction/affectedResources/AWS::S3::Bucket
|
||||
- ProductFields.aws/guardduty/service/action/awsApiCallAction/api
|
||||
- ProductFields.aws/guardduty/service/action/awsApiCallAction/callerType
|
||||
- ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/city/cityName
|
||||
- ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/country/countryName
|
||||
- ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/geoLocation/lat
|
||||
- ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/geoLocation/lon
|
||||
- ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/ipAddressV4
|
||||
- ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/organization/asn
|
||||
- ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/organization/asnOrg
|
||||
- ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/organization/isp
|
||||
- ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/organization/org
|
||||
- ProductFields.aws/guardduty/service/action/awsApiCallAction/serviceName
|
||||
- ProductFields.aws/guardduty/service/additionalInfo/sample
|
||||
- ProductFields.aws/guardduty/service/additionalInfo/unusual/hoursOfDay.0_
|
||||
- ProductFields.aws/guardduty/service/additionalInfo/unusual/userNames.0_
|
||||
- ProductFields.aws/guardduty/service/archived
|
||||
- ProductFields.aws/guardduty/service/count
|
||||
- ProductFields.aws/guardduty/service/detectorId
|
||||
- ProductFields.aws/guardduty/service/eventFirstSeen
|
||||
- ProductFields.aws/guardduty/service/eventLastSeen
|
||||
- ProductFields.aws/guardduty/service/resourceRole
|
||||
- ProductFields.aws/guardduty/service/serviceName
|
||||
- ProductFields.aws/securityhub/CompanyName
|
||||
- ProductFields.aws/securityhub/FindingId
|
||||
- ProductFields.aws/securityhub/ProductName
|
||||
- RecordState
|
||||
- Resources{}.Details.AwsEc2Instance.IamInstanceProfileArn
|
||||
- Resources{}.Details.AwsEc2Instance.ImageId
|
||||
- Resources{}.Details.AwsEc2Instance.IpV4Addresses{}
|
||||
- Resources{}.Details.AwsEc2Instance.LaunchedAt
|
||||
- Resources{}.Details.AwsEc2Instance.SubnetId
|
||||
- Resources{}.Details.AwsEc2Instance.Type
|
||||
- Resources{}.Details.AwsEc2Instance.VpcId
|
||||
- Resources{}.Details.AwsIamAccessKey.PrincipalId
|
||||
- Resources{}.Details.AwsIamAccessKey.PrincipalName
|
||||
- Resources{}.Details.AwsIamAccessKey.PrincipalType
|
||||
- Resources{}.Details.AwsS3Bucket.CreatedAt
|
||||
- Resources{}.Details.AwsS3Bucket.OwnerId
|
||||
- Resources{}.Details.AwsS3Bucket.ServerSideEncryptionConfiguration.Rules{}.ApplyServerSideEncryptionByDefault.KMSMasterKeyID
|
||||
- Resources{}.Details.AwsS3Bucket.ServerSideEncryptionConfiguration.Rules{}.ApplyServerSideEncryptionByDefault.SSEAlgorithm
|
||||
- Resources{}.Id
|
||||
- Resources{}.Partition
|
||||
- Resources{}.Region
|
||||
- Resources{}.Tags.GeneratedFindingInstaceTag1
|
||||
- Resources{}.Tags.GeneratedFindingInstaceTag2
|
||||
- Resources{}.Tags.GeneratedFindingInstaceTag3
|
||||
- Resources{}.Tags.GeneratedFindingInstaceTag4
|
||||
- Resources{}.Tags.GeneratedFindingInstaceTag5
|
||||
- Resources{}.Tags.GeneratedFindingInstaceTag6
|
||||
- Resources{}.Tags.GeneratedFindingInstaceTag7
|
||||
- Resources{}.Tags.GeneratedFindingInstaceTag8
|
||||
- Resources{}.Tags.GeneratedFindingInstaceTag9
|
||||
- Resources{}.Tags.foo
|
||||
- Resources{}.Type
|
||||
- SchemaVersion
|
||||
- Severity.Label
|
||||
- Severity.Normalized
|
||||
- Severity.Product
|
||||
- SourceUrl
|
||||
- Title
|
||||
- Types{}
|
||||
- UpdatedAt
|
||||
- Workflow.Status
|
||||
- WorkflowState
|
||||
- accesskey_extract
|
||||
- app
|
||||
- body
|
||||
- description
|
||||
- dest
|
||||
- dest_type
|
||||
- eventtype
|
||||
- host
|
||||
- id
|
||||
- index
|
||||
- instance_extract
|
||||
- linecount
|
||||
- punct
|
||||
- s3bucket_extract
|
||||
- severity
|
||||
- severity_id
|
||||
- signature
|
||||
- signature_id
|
||||
- source
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- subject
|
||||
- tag
|
||||
- tag::eventtype
|
||||
- timestamp
|
||||
- type
|
||||
- vendor_account
|
||||
- vendor_region
|
||||
example_log: '{"ProductArn":"arn:aws:securityhub:us-east-1::product/aws/guardduty","Types":["Software
|
||||
and Configuration Checks/Exfiltration:S3.ObjectRead.Unusual"],"SourceUrl":"https://us-east-1.console.aws.amazon.com/guardduty/home?region=us-east-1#/findings?macros=current&fId=6aba6b696aea10606e8b336f68d98819","Description":"Principal
|
||||
GeneratedFindingUserName read objects from S3 bucket GeneratedFindingS3Bucket in
|
||||
an unusual way.","SchemaVersion":"2018-10-08","GeneratorId":"arn:aws:guardduty:us-east-1:802684071507:detector/48ba636359b884eb132865311fdeb317","FirstObservedAt":"2020-09-28T22:26:15.636Z","CreatedAt":"2020-09-28T22:26:15.636Z","RecordState":"ACTIVE","Title":"Unusual
|
||||
@@ -0,0 +1,13 @@
|
||||
name: Azure Active Directory
|
||||
id: 51ca21e5-bda2-4652-bb29-27c7bc18a81c
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for Azure Active Directory
|
||||
source: Azure AD
|
||||
sourcetype: azure:monitor:aad
|
||||
separator: operationName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Cloud Services
|
||||
url: https://splunkbase.splunk.com/app/3110
|
||||
version: 5.2.2
|
||||
@@ -0,0 +1,120 @@
|
||||
name: Azure Active Directory Add app role assignment to service principal
|
||||
id: 8b2e84cd-6db0-47e9-badc-75c17df1995f
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for Azure Active Directory Add app role assignment
|
||||
to service principal
|
||||
source: Azure AD
|
||||
sourcetype: azure:monitor:aad
|
||||
separator: operationName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Cloud Services
|
||||
url: https://splunkbase.splunk.com/app/3110
|
||||
version: 5.2.2
|
||||
fields:
|
||||
- _time
|
||||
- Level
|
||||
- additional_details
|
||||
- additional_details_name
|
||||
- additional_details_value
|
||||
- category
|
||||
- command
|
||||
- correlationId
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- dest
|
||||
- dest_type
|
||||
- durationMs
|
||||
- dvc
|
||||
- eventtype
|
||||
- host
|
||||
- id
|
||||
- identity
|
||||
- index
|
||||
- linecount
|
||||
- object_attrs
|
||||
- object_id
|
||||
- operationName
|
||||
- operationVersion
|
||||
- path_from_resourceId
|
||||
- properties.activityDateTime
|
||||
- properties.activityDisplayName
|
||||
- properties.additionalDetails{}.key
|
||||
- properties.additionalDetails{}.value
|
||||
- properties.category
|
||||
- properties.correlationId
|
||||
- properties.id
|
||||
- properties.initiatedBy.app.appId
|
||||
- properties.initiatedBy.app.displayName
|
||||
- properties.initiatedBy.app.servicePrincipalId
|
||||
- properties.initiatedBy.app.servicePrincipalName
|
||||
- properties.loggedByService
|
||||
- properties.operationType
|
||||
- properties.result
|
||||
- properties.resultReason
|
||||
- properties.targetResources{}.displayName
|
||||
- properties.targetResources{}.id
|
||||
- properties.targetResources{}.modifiedProperties{}.displayName
|
||||
- properties.targetResources{}.modifiedProperties{}.newValue
|
||||
- properties.targetResources{}.modifiedProperties{}.oldValue
|
||||
- properties.targetResources{}.type
|
||||
- properties.userAgent
|
||||
- punct
|
||||
- resourceId
|
||||
- result
|
||||
- resultSignature
|
||||
- result_id
|
||||
- signature
|
||||
- source
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- src_user_type
|
||||
- status
|
||||
- tag
|
||||
- tag::eventtype
|
||||
- tenantId
|
||||
- time
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
- user_agent
|
||||
- user_type
|
||||
- vendor_account
|
||||
- vendor_product
|
||||
example_log: '{"time": "2024-02-08T21:49:53.7643129Z", "resourceId": "/tenants/75243ab2-44f8-435c-a7a6-b479385df6d4/providers/Microsoft.aadiam",
|
||||
"operationName": "Add app role assignment to service principal", "operationVersion":
|
||||
"1.0", "category": "AuditLogs", "tenantId": "75243ab2-44f8-435c-a7a6-b479385df6d4",
|
||||
"resultSignature": "None", "durationMs": 0, "correlationId": "ed53faec-49b5-444f-b6af-b928558ca433",
|
||||
"identity": "LegacyTestOAuthApp", "Level": 4, "properties": {"id": "Directory_ed53faec-49b5-444f-b6af-b928558ca433_XH34Q_29215277",
|
||||
"category": "ApplicationManagement", "correlationId": "ed53faec-49b5-444f-b6af-b928558ca433",
|
||||
"result": "success", "resultReason": "", "activityDisplayName": "Add app role assignment
|
||||
to service principal", "activityDateTime": "2024-02-08T21:49:53.7643129+00:00",
|
||||
"loggedByService": "Core Directory", "operationType": "Assign", "userAgent": null,
|
||||
"initiatedBy": {"app": {"appId": null, "displayName": "LegacyTestOAuthApp", "servicePrincipalId":
|
||||
"fc8c8125-bc0c-499d-8344-e53c6e3caa81", "servicePrincipalName": null}}, "targetResources":
|
||||
[{"id": "8429eb5c-faeb-4ade-8eac-acc003790769", "displayName": "Office 365 Exchange
|
||||
Online", "type": "ServicePrincipal", "modifiedProperties": [{"displayName": "AppRole.Id",
|
||||
"oldValue": null, "newValue": "\"dc890d15-9560-4a4c-9b7f-a736ec74ec40\""}, {"displayName":
|
||||
"AppRole.Value", "oldValue": null, "newValue": "\"full_access_as_app\""}, {"displayName":
|
||||
"AppRole.DisplayName", "oldValue": null, "newValue": "\"Use Exchange Web Services
|
||||
with full access to all mailboxes\""}, {"displayName": "AppRoleAssignment.CreatedDateTime",
|
||||
"oldValue": null, "newValue": "\"2024-02-08T21:49:53.6813076Z\""}, {"displayName":
|
||||
"AppRoleAssignment.LastModifiedDateTime", "oldValue": null, "newValue": "\"2024-02-08T21:49:53.6813076Z\""},
|
||||
{"displayName": "ServicePrincipal.ObjectID", "oldValue": null, "newValue": "\"2e5c2fd0-cca4-452c-9891-a07c0dafd964\""},
|
||||
{"displayName": "ServicePrincipal.DisplayName", "oldValue": null, "newValue": "\"STRT_Oauth\""},
|
||||
{"displayName": "ServicePrincipal.AppId", "oldValue": null, "newValue": "\"5f91ce94-4cc5-4ebe-aeb6-f074e57201bb\""},
|
||||
{"displayName": "ServicePrincipal.Name", "oldValue": null, "newValue": "\"5f91ce94-4cc5-4ebe-aeb6-f074e57201bb\""},
|
||||
{"displayName": "TargetId.ServicePrincipalNames", "oldValue": null, "newValue":
|
||||
"\"https://outlook.office.com;Microsoft.Exchange;00000002-0000-0ff1-ce00-000000000000;00000002-0000-0ff1-ce00-000000000000/*.outlook.com;00000002-0000-0ff1-ce00-000000000000/outlook.com;00000002-0000-0ff1-ce00-000000000000/mail.office365.com;00000002-0000-0ff1-ce00-000000000000/outlook.office365.com;https://webmail.apps.mil/;https://ps.protection.outlook.com/;https://outlook-dod.office365.us/;https://outlook.com/;https://outlook.office365.com/;https://outlook.office.com/;https://outlook.office365.com:443/;https://outlook-sdf.office365.com/;https://outlook-sdf.office.com/;https://outlook.office365.us/;https://autodiscover-s.office365.us/;https://ps.compliance.protection.outlook.com;https://manage.protection.apps.mil;https://outlook-tdf.office.com/;https://outlook-tdf-2.office.com/;https://ps.outlook.com\""}],
|
||||
"administrativeUnits": []}, {"id": "2e5c2fd0-cca4-452c-9891-a07c0dafd964", "displayName":
|
||||
"5f91ce94-4cc5-4ebe-aeb6-f074e57201bb", "type": "ServicePrincipal", "modifiedProperties":
|
||||
[], "administrativeUnits": []}], "additionalDetails": [{"key": "User-Agent", "value":
|
||||
"Mozilla/5.0 (Macintosh; Darwin 23.3.0 Darwin Kernel Version 23.3.0: Wed Dec 20
|
||||
21:28:58 PST 2023; root:xnu-10002.81.5~7/RELEASE_X86_64; en-US) PowerShell/7.3.4"},
|
||||
{"key": "AppId", "value": "00000002-0000-0ff1-ce00-000000000000"}]}}'
|
||||
@@ -0,0 +1,85 @@
|
||||
name: Azure Active Directory Add member to role
|
||||
id: 1660d196-127f-4678-81b2-472d51711b07
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for Azure Active Directory Add member to role
|
||||
source: Azure AD
|
||||
sourcetype: azure:monitor:aad
|
||||
separator: operationName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Cloud Services
|
||||
url: https://splunkbase.splunk.com/app/3110
|
||||
version: 5.2.2
|
||||
fields:
|
||||
- _time
|
||||
- Level
|
||||
- callerIpAddress
|
||||
- category
|
||||
- correlationId
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- durationMs
|
||||
- host
|
||||
- index
|
||||
- linecount
|
||||
- operationName
|
||||
- operationVersion
|
||||
- properties.activityDateTime
|
||||
- properties.activityDisplayName
|
||||
- properties.category
|
||||
- properties.correlationId
|
||||
- properties.id
|
||||
- properties.initiatedBy.user.displayName
|
||||
- properties.initiatedBy.user.id
|
||||
- properties.initiatedBy.user.ipAddress
|
||||
- properties.initiatedBy.user.userPrincipalName
|
||||
- properties.loggedByService
|
||||
- properties.operationType
|
||||
- properties.result
|
||||
- properties.resultReason
|
||||
- properties.targetResources{}.displayName
|
||||
- properties.targetResources{}.id
|
||||
- properties.targetResources{}.modifiedProperties{}.displayName
|
||||
- properties.targetResources{}.modifiedProperties{}.newValue
|
||||
- properties.targetResources{}.modifiedProperties{}.oldValue
|
||||
- properties.targetResources{}.type
|
||||
- properties.targetResources{}.userPrincipalName
|
||||
- properties.userAgent
|
||||
- punct
|
||||
- resourceId
|
||||
- resultSignature
|
||||
- source
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- tenantId
|
||||
- time
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
example_log: '{"time": "2023-04-28T16:39:51.9312625Z", "resourceId": "/tenants/fc69e276-e9e8-4af9-9002-1e410d77244e/providers/Microsoft.aadiam",
|
||||
"operationName": "Add member to role", "operationVersion": "1.0", "category": "AuditLogs",
|
||||
"tenantId": "fc69e276-e9e8-4af9-9002-1e410d77244e", "resultSignature": "None", "durationMs":
|
||||
0, "callerIpAddress": "52.177.250.168", "correlationId": "b425f2d7-2245-4952-b599-61dff8054f2b",
|
||||
"Level": 4, "properties": {"id": "Directory_b425f2d7-2245-4952-b599-61dff8054f2b_FLAW0_72812697",
|
||||
"category": "RoleManagement", "correlationId": "b425f2d7-2245-4952-b599-61dff8054f2b",
|
||||
"result": "success", "resultReason": "", "activityDisplayName": "Add member to role",
|
||||
"activityDateTime": "2023-04-28T16:39:51.9312625+00:00", "loggedByService": "Core
|
||||
Directory", "operationType": "Assign", "userAgent": null, "initiatedBy": {"user":
|
||||
{"id": "3bd47e42-37c9-442f-a2b4-f04de61ef0ce", "displayName": null, "userPrincipalName":
|
||||
"strt_admin@splunkresearch.com", "ipAddress": "52.177.250.168", "roles": []}}, "targetResources":
|
||||
[{"id": "0d664d57-a3ee-4049-8642-280a5c7243ef", "displayName": null, "type": "User",
|
||||
"userPrincipalName": "User1@splunkresearch.com", "modifiedProperties": [{"displayName":
|
||||
"Role.ObjectID", "oldValue": null, "newValue": "\"38bf5baf-7ec7-4bc2-8920-6d4044da12c2\""},
|
||||
{"displayName": "Role.DisplayName", "oldValue": null, "newValue": "\"Privileged
|
||||
Role Administrator\""}, {"displayName": "Role.TemplateId", "oldValue": null, "newValue":
|
||||
"\"9b895d92-2cd3-44c7-9d02-a6ac2d5ea5c3\""}, {"displayName": "Role.WellKnownObjectName",
|
||||
"oldValue": null, "newValue": "\"ApplicationAdministrators\""}], "administrativeUnits":
|
||||
[]}, {"id": "38bf5baf-7ec7-4bc2-8920-6d4044da12c2", "displayName": null, "type":
|
||||
"Role", "modifiedProperties": [], "administrativeUnits": []}], "additionalDetails":
|
||||
[]}}'
|
||||
@@ -0,0 +1,90 @@
|
||||
name: Azure Active Directory Add owner to application
|
||||
id: e895ed56-7be4-4b3a-b782-ecd0f594ec4c
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for Azure Active Directory Add owner to application
|
||||
source: Azure AD
|
||||
sourcetype: azure:monitor:aad
|
||||
separator: operationName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Cloud Services
|
||||
url: https://splunkbase.splunk.com/app/3110
|
||||
version: 5.2.2
|
||||
fields:
|
||||
- _time
|
||||
- Level
|
||||
- callerIpAddress
|
||||
- category
|
||||
- correlationId
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- durationMs
|
||||
- eventtype
|
||||
- host
|
||||
- index
|
||||
- linecount
|
||||
- operationName
|
||||
- operationVersion
|
||||
- properties.activityDateTime
|
||||
- properties.activityDisplayName
|
||||
- properties.additionalDetails{}.key
|
||||
- properties.additionalDetails{}.value
|
||||
- properties.category
|
||||
- properties.correlationId
|
||||
- properties.id
|
||||
- properties.initiatedBy.user.displayName
|
||||
- properties.initiatedBy.user.id
|
||||
- properties.initiatedBy.user.ipAddress
|
||||
- properties.initiatedBy.user.userPrincipalName
|
||||
- properties.loggedByService
|
||||
- properties.operationType
|
||||
- properties.result
|
||||
- properties.resultReason
|
||||
- properties.targetResources{}.displayName
|
||||
- properties.targetResources{}.id
|
||||
- properties.targetResources{}.modifiedProperties{}.displayName
|
||||
- properties.targetResources{}.modifiedProperties{}.newValue
|
||||
- properties.targetResources{}.modifiedProperties{}.oldValue
|
||||
- properties.targetResources{}.type
|
||||
- properties.targetResources{}.userPrincipalName
|
||||
- properties.userAgent
|
||||
- punct
|
||||
- resourceId
|
||||
- resultSignature
|
||||
- source
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- tag
|
||||
- tag::eventtype
|
||||
- tenantId
|
||||
- time
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
example_log: '{"time": "2023-06-20T15:54:13.2420879Z", "resourceId": "/tenants/fc69e276-e9e8-4af9-9002-1e410d77244e/providers/Microsoft.aadiam",
|
||||
"operationName": "Add owner to application", "operationVersion": "1.0", "category":
|
||||
"AuditLogs", "tenantId": "fc69e276-e9e8-4af9-9002-1e410d77244e", "resultSignature":
|
||||
"None", "durationMs": 0, "callerIpAddress": "20.190.135.43", "correlationId": "231de5d4-2156-433a-8163-48956bdaa040",
|
||||
"Level": 4, "properties": {"id": "Directory_231de5d4-2156-433a-8163-48956bdaa040_C21RW_365283677",
|
||||
"category": "ApplicationManagement", "correlationId": "231de5d4-2156-433a-8163-48956bdaa040",
|
||||
"result": "success", "resultReason": "", "activityDisplayName": "Add owner to application",
|
||||
"activityDateTime": "2023-06-20T15:54:13.2420879+00:00", "loggedByService": "Core
|
||||
Directory", "operationType": "Assign", "userAgent": null, "initiatedBy": {"user":
|
||||
{"id": "4d3f1865-b395-4430-91dc-1b9dd337712e", "displayName": null, "userPrincipalName":
|
||||
"globaladmin@splunkresearch.com", "ipAddress": "20.190.135.43", "roles": []}}, "targetResources":
|
||||
[{"id": "dd92f1af-43d7-47d9-b93c-a78c6b635180", "displayName": null, "type": "User",
|
||||
"userPrincipalName": "Abigail.Clark@splunkresearch.com", "modifiedProperties": [{"displayName":
|
||||
"Application.ObjectID", "oldValue": null, "newValue": "\"bb2479d8-5e89-4480-bb7e-3178d5a5d469\""},
|
||||
{"displayName": "Application.DisplayName", "oldValue": null, "newValue": "\"CloudForge\""},
|
||||
{"displayName": "Application.AppId", "oldValue": null, "newValue": "\"f0748f3d-45f2-4e2e-a4e1-f2e2b5271bdf\""}],
|
||||
"administrativeUnits": []}, {"id": "bb2479d8-5e89-4480-bb7e-3178d5a5d469", "displayName":
|
||||
null, "type": "Application", "modifiedProperties": [], "administrativeUnits": []}],
|
||||
"additionalDetails": [{"key": "User-Agent", "value": "Mozilla/5.0 (Macintosh; Darwin
|
||||
22.4.0 Darwin Kernel Version 22.4.0: Mon Mar 6 21:00:17 PST 2023; root:xnu-8796.101.5~3/RELEASE_X86_64;
|
||||
en-US) PowerShell/7.3.4"}]}}'
|
||||
@@ -0,0 +1,88 @@
|
||||
name: Azure Active Directory Add service principal
|
||||
id: fd89d337-e4c0-4162-ad13-bca36f096fe6
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for Azure Active Directory Add service principal
|
||||
source: Azure AD
|
||||
sourcetype: azure:monitor:aad
|
||||
separator: operationName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Cloud Services
|
||||
url: https://splunkbase.splunk.com/app/3110
|
||||
version: 5.2.2
|
||||
fields:
|
||||
- _time
|
||||
- Level
|
||||
- category
|
||||
- correlationId
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- durationMs
|
||||
- host
|
||||
- index
|
||||
- linecount
|
||||
- operationName
|
||||
- operationVersion
|
||||
- properties.activityDateTime
|
||||
- properties.activityDisplayName
|
||||
- properties.additionalDetails{}.key
|
||||
- properties.additionalDetails{}.value
|
||||
- properties.category
|
||||
- properties.correlationId
|
||||
- properties.id
|
||||
- properties.initiatedBy.user.displayName
|
||||
- properties.initiatedBy.user.id
|
||||
- properties.initiatedBy.user.ipAddress
|
||||
- properties.initiatedBy.user.userPrincipalName
|
||||
- properties.loggedByService
|
||||
- properties.operationType
|
||||
- properties.result
|
||||
- properties.resultReason
|
||||
- properties.targetResources{}.displayName
|
||||
- properties.targetResources{}.id
|
||||
- properties.targetResources{}.modifiedProperties{}.displayName
|
||||
- properties.targetResources{}.modifiedProperties{}.newValue
|
||||
- properties.targetResources{}.modifiedProperties{}.oldValue
|
||||
- properties.targetResources{}.type
|
||||
- properties.userAgent
|
||||
- punct
|
||||
- resourceId
|
||||
- resultSignature
|
||||
- source
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- tenantId
|
||||
- time
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
example_log: '{"time": "2024-02-07T22:31:14.4970418Z", "resourceId": "/tenants/a417c578-c7ee-480d-a225-d48057e74df5/providers/Microsoft.aadiam",
|
||||
"operationName": "Add service principal", "operationVersion": "1.0", "category":
|
||||
"AuditLogs", "tenantId": "a417c578-c7ee-480d-a225-d48057e74df5", "resultSignature":
|
||||
"None", "durationMs": 0, "correlationId": "ea473f15-64b3-435a-a885-6ee3908919e2",
|
||||
"Level": 4, "properties": {"id": "Directory_ea473f15-64b3-435a-a885-6ee3908919e2_GSOLK_21152854",
|
||||
"category": "ApplicationManagement", "correlationId": "ea473f15-64b3-435a-a885-6ee3908919e2",
|
||||
"result": "success", "resultReason": "", "activityDisplayName": "Add service principal",
|
||||
"activityDateTime": "2024-02-07T22:31:14.4970418+00:00", "loggedByService": "Core
|
||||
Directory", "operationType": "Add", "userAgent": null, "initiatedBy": {"user": {"id":
|
||||
"e4c722ac-3b83-478d-8f52-c388885dc30f", "displayName": null, "userPrincipalName":
|
||||
"Herman@phantomengineering.onmicrosoft.com", "ipAddress": "", "roles": []}}, "targetResources":
|
||||
[{"id": "2dedf863-ac93-4f45-87b3-e32f48145380", "displayName": "Malicious11", "type":
|
||||
"ServicePrincipal", "modifiedProperties": [{"displayName": "AccountEnabled", "oldValue":
|
||||
"[]", "newValue": "[true]"}, {"displayName": "AppPrincipalId", "oldValue": "[]",
|
||||
"newValue": "[\"e06366ca-8489-4748-b6a2-d7e4332f45c1\"]"}, {"displayName": "DisplayName",
|
||||
"oldValue": "[]", "newValue": "[\"Malicious11\"]"}, {"displayName": "ServicePrincipalName",
|
||||
"oldValue": "[]", "newValue": "[\"e06366ca-8489-4748-b6a2-d7e4332f45c1\"]"}, {"displayName":
|
||||
"Credential", "oldValue": "[]", "newValue": "[{\"CredentialType\":2,\"KeyStoreId\":\"291154f0-a9f5-45bb-87be-9c8ee5b6d62c\",\"KeyGroupId\":\"291154f0-a9f5-45bb-87be-9c8ee5b6d62c\"}]"},
|
||||
{"displayName": "Included Updated Properties", "oldValue": null, "newValue": "\"AccountEnabled,
|
||||
AppPrincipalId, DisplayName, ServicePrincipalName, Credential\""}, {"displayName":
|
||||
"TargetId.ServicePrincipalNames", "oldValue": null, "newValue": "\"e06366ca-8489-4748-b6a2-d7e4332f45c1\""}],
|
||||
"administrativeUnits": []}], "additionalDetails": [{"key": "User-Agent", "value":
|
||||
"Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like
|
||||
Gecko) Chrome/121.0.0.0 Safari/537.36"}, {"key": "AppId", "value": "e06366ca-8489-4748-b6a2-d7e4332f45c1"}]}}'
|
||||
@@ -0,0 +1,83 @@
|
||||
name: Azure Active Directory Add unverified domain
|
||||
id: d4c01fb1-3b88-46d3-bd12-9b9e256450f7
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for Azure Active Directory Add unverified domain
|
||||
source: Azure AD
|
||||
sourcetype: azure:monitor:aad
|
||||
separator: operationName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Cloud Services
|
||||
url: https://splunkbase.splunk.com/app/3110
|
||||
version: 5.2.2
|
||||
fields:
|
||||
- _time
|
||||
- Level
|
||||
- callerIpAddress
|
||||
- category
|
||||
- correlationId
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- durationMs
|
||||
- host
|
||||
- index
|
||||
- linecount
|
||||
- operationName
|
||||
- operationVersion
|
||||
- properties.activityDateTime
|
||||
- properties.activityDisplayName
|
||||
- properties.additionalDetails{}.key
|
||||
- properties.additionalDetails{}.value
|
||||
- properties.category
|
||||
- properties.correlationId
|
||||
- properties.id
|
||||
- properties.initiatedBy.user.displayName
|
||||
- properties.initiatedBy.user.id
|
||||
- properties.initiatedBy.user.ipAddress
|
||||
- properties.initiatedBy.user.userPrincipalName
|
||||
- properties.loggedByService
|
||||
- properties.operationType
|
||||
- properties.result
|
||||
- properties.resultReason
|
||||
- properties.targetResources{}.displayName
|
||||
- properties.targetResources{}.id
|
||||
- properties.targetResources{}.modifiedProperties{}.displayName
|
||||
- properties.targetResources{}.modifiedProperties{}.newValue
|
||||
- properties.targetResources{}.modifiedProperties{}.oldValue
|
||||
- properties.userAgent
|
||||
- punct
|
||||
- resourceId
|
||||
- resultSignature
|
||||
- source
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- tenantId
|
||||
- time
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
example_log: '{"time": "2023-07-26T13:45:54.1582053Z", "resourceId": "/tenants/fc69e276-e9e8-4af9-9002-1e410d77244e/providers/Microsoft.aadiam",
|
||||
"operationName": "Add unverified domain", "operationVersion": "1.0", "category":
|
||||
"AuditLogs", "tenantId": "fc69e276-e9e8-4af9-9002-1e410d77244e", "resultSignature":
|
||||
"None", "durationMs": 0, "callerIpAddress": "2601:646:a000:200:6419:f55c:946d:17d1",
|
||||
"correlationId": "bdab88f3-69a4-4e66-883d-5b1e1558e61b", "Level": 4, "properties":
|
||||
{"id": "Directory_bdab88f3-69a4-4e66-883d-5b1e1558e61b_311NT_82497138", "category":
|
||||
"DirectoryManagement", "correlationId": "bdab88f3-69a4-4e66-883d-5b1e1558e61b",
|
||||
"result": "success", "resultReason": "", "activityDisplayName": "Add unverified
|
||||
domain", "activityDateTime": "2023-07-26T13:45:54.1582053+00:00", "loggedByService":
|
||||
"Core Directory", "operationType": "Add", "userAgent": null, "initiatedBy": {"user":
|
||||
{"id": "728989f4-eb3d-45c2-8741-2f2af4e485ce", "displayName": null, "userPrincipalName":
|
||||
"tommyr@splunkresearch.com", "ipAddress": "2601:646:a000:200:6419:f55c:946d:17d1",
|
||||
"roles": []}}, "targetResources": [{"id": null, "displayName": "newdomain.com",
|
||||
"modifiedProperties": [{"displayName": "Name", "oldValue": "[\"\"]", "newValue":
|
||||
"[\"newdomain.com\"]"}, {"displayName": "LiveType", "oldValue": "[\"None\"]", "newValue":
|
||||
"[\"Managed\"]"}, {"displayName": "Included Updated Properties", "oldValue": null,
|
||||
"newValue": "\"Name,LiveType\""}], "administrativeUnits": []}], "additionalDetails":
|
||||
[{"key": "User-Agent", "value": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7)
|
||||
AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36"}]}}'
|
||||
@@ -0,0 +1,98 @@
|
||||
name: Azure Active Directory Consent to application
|
||||
id: 4c5d6c49-53e3-4980-a4de-c63e26291ed0
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for Azure Active Directory Consent to application
|
||||
source: Azure AD
|
||||
sourcetype: azure:monitor:aad
|
||||
separator: operationName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Cloud Services
|
||||
url: https://splunkbase.splunk.com/app/3110
|
||||
version: 5.2.2
|
||||
fields:
|
||||
- _time
|
||||
- Level
|
||||
- callerIpAddress
|
||||
- category
|
||||
- correlationId
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- durationMs
|
||||
- eventtype
|
||||
- host
|
||||
- index
|
||||
- linecount
|
||||
- operationName
|
||||
- operationVersion
|
||||
- properties.activityDateTime
|
||||
- properties.activityDisplayName
|
||||
- properties.additionalDetails{}.key
|
||||
- properties.additionalDetails{}.value
|
||||
- properties.category
|
||||
- properties.correlationId
|
||||
- properties.id
|
||||
- properties.initiatedBy.user.displayName
|
||||
- properties.initiatedBy.user.id
|
||||
- properties.initiatedBy.user.ipAddress
|
||||
- properties.initiatedBy.user.userPrincipalName
|
||||
- properties.loggedByService
|
||||
- properties.operationType
|
||||
- properties.result
|
||||
- properties.resultReason
|
||||
- properties.targetResources{}.displayName
|
||||
- properties.targetResources{}.id
|
||||
- properties.targetResources{}.modifiedProperties{}.displayName
|
||||
- properties.targetResources{}.modifiedProperties{}.newValue
|
||||
- properties.targetResources{}.modifiedProperties{}.oldValue
|
||||
- properties.targetResources{}.type
|
||||
- properties.userAgent
|
||||
- punct
|
||||
- resourceId
|
||||
- resultDescription
|
||||
- resultSignature
|
||||
- source
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- tag
|
||||
- tag::eventtype
|
||||
- tenantId
|
||||
- time
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
example_log: '{"time": "2023-10-27T16:14:14.9747033Z", "resourceId": "/tenants/75243ab2-44f8-435c-a7a6-b479385df6d4/providers/Microsoft.aadiam",
|
||||
"operationName": "Consent to application", "operationVersion": "1.0", "category":
|
||||
"AuditLogs", "tenantId": "75243ab2-44f8-435c-a7a6-b479385df6d4", "resultSignature":
|
||||
"None", "resultDescription": "Microsoft.Online.Security.UserConsentBlockedForRiskyAppsException",
|
||||
"durationMs": 0, "callerIpAddress": "13.85.188.242", "correlationId": "864210f1-2950-47cb-9e12-1a71dcbdb1d5",
|
||||
"Level": 4, "properties": {"id": "Directory_864210f1-2950-47cb-9e12-1a71dcbdb1d5_DO21D_338329364",
|
||||
"category": "ApplicationManagement", "correlationId": "864210f1-2950-47cb-9e12-1a71dcbdb1d5",
|
||||
"result": "failure", "resultReason": "Microsoft.Online.Security.UserConsentBlockedForRiskyAppsException",
|
||||
"activityDisplayName": "Consent to application", "activityDateTime": "2023-10-27T16:14:14.9747033+00:00",
|
||||
"loggedByService": "Core Directory", "operationType": "Assign", "userAgent": null,
|
||||
"initiatedBy": {"user": {"id": "57e4bd36-9722-4a4a-9729-7203d8e00b72", "displayName":
|
||||
null, "userPrincipalName": "user15@splunkresearch.onmicrosoft.com", "ipAddress":
|
||||
"13.85.188.242", "roles": []}}, "targetResources": [{"id": "6228c72e-8895-4681-bbda-238132dc4f3c",
|
||||
"displayName": "Bad App 1", "type": "Application", "modifiedProperties": [{"displayName":
|
||||
"ConsentContext.IsAdminConsent", "oldValue": null, "newValue": "\"False\""}, {"displayName":
|
||||
"ConsentContext.IsAppOnly", "oldValue": null, "newValue": "\"False\""}, {"displayName":
|
||||
"ConsentContext.OnBehalfOfAll", "oldValue": null, "newValue": "\"False\""}, {"displayName":
|
||||
"ConsentContext.Tags", "oldValue": null, "newValue": "\"WindowsAzureActiveDirectoryIntegratedApp\""},
|
||||
{"displayName": "ConsentAction.Permissions", "oldValue": null, "newValue": "\"[]
|
||||
=> [[Id: AAAAAAAAAAAAAAAAAAAAALSZcc5Sj_NGtUtP2B3pYeI2veRXIpdKSpcpcgPY4Aty, ClientId:
|
||||
00000000-0000-0000-0000-000000000000, PrincipalId: 57e4bd36-9722-4a4a-9729-7203d8e00b72,
|
||||
ResourceId: ce7199b4-8f52-46f3-b54b-4fd81de961e2, ConsentType: Principal, Scope:
|
||||
Mail.Read Mail.Read.Shared Mail.ReadBasic Mail.ReadBasic.Shared Mail.ReadWrite Mail.ReadWrite.Shared
|
||||
Mail.Send Mail.Send.Shared User.Read, CreatedDateTime: , LastModifiedDateTime ]];
|
||||
\""}, {"displayName": "ConsentAction.Reason", "oldValue": null, "newValue": "\"Risky
|
||||
application detected\""}, {"displayName": "MethodExecutionResult.", "oldValue":
|
||||
null, "newValue": "\"Microsoft.Online.Security.UserConsentBlockedForRiskyAppsException\""}],
|
||||
"administrativeUnits": []}], "additionalDetails": [{"key": "User-Agent", "value":
|
||||
"EvoSTS"}, {"key": "AppId", "value": "96f6a3d6-d5aa-4af5-a77a-9319b5283712"}]}}'
|
||||
@@ -0,0 +1,80 @@
|
||||
name: Azure Active Directory Disable Strong Authentication
|
||||
id: 8f31966d-c496-496d-8837-f7fd11f31255
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for Azure Active Directory Disable Strong Authentication
|
||||
source: Azure AD
|
||||
sourcetype: azure:monitor:aad
|
||||
separator: operationName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Cloud Services
|
||||
url: https://splunkbase.splunk.com/app/3110
|
||||
version: 5.2.2
|
||||
fields:
|
||||
- _time
|
||||
- Level
|
||||
- category
|
||||
- correlationId
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- durationMs
|
||||
- host
|
||||
- index
|
||||
- linecount
|
||||
- operationName
|
||||
- operationVersion
|
||||
- properties.activityDateTime
|
||||
- properties.activityDisplayName
|
||||
- properties.category
|
||||
- properties.correlationId
|
||||
- properties.id
|
||||
- properties.initiatedBy.user.displayName
|
||||
- properties.initiatedBy.user.id
|
||||
- properties.initiatedBy.user.ipAddress
|
||||
- properties.initiatedBy.user.userPrincipalName
|
||||
- properties.loggedByService
|
||||
- properties.operationType
|
||||
- properties.result
|
||||
- properties.resultReason
|
||||
- properties.targetResources{}.displayName
|
||||
- properties.targetResources{}.id
|
||||
- properties.targetResources{}.modifiedProperties{}.displayName
|
||||
- properties.targetResources{}.modifiedProperties{}.newValue
|
||||
- properties.targetResources{}.modifiedProperties{}.oldValue
|
||||
- properties.targetResources{}.type
|
||||
- properties.targetResources{}.userPrincipalName
|
||||
- properties.userAgent
|
||||
- punct
|
||||
- resourceId
|
||||
- resultSignature
|
||||
- source
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- tenantId
|
||||
- time
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
example_log: '{"time": "2023-07-11T00:01:35.0251899Z", "resourceId": "/tenants/fc69e276-e9e8-4af9-9002-1e410d77244e/providers/Microsoft.aadiam",
|
||||
"operationName": "Disable Strong Authentication", "operationVersion": "1.0", "category":
|
||||
"AuditLogs", "tenantId": "fc69e276-e9e8-4af9-9002-1e410d77244e", "resultSignature":
|
||||
"None", "durationMs": 0, "correlationId": "7e3ee05c-ce4f-4ff1-8230-55555c25c97e",
|
||||
"Level": 4, "properties": {"id": "Directory_7e3ee05c-ce4f-4ff1-8230-55555c25c97e_DADCR_14299826",
|
||||
"category": "UserManagement", "correlationId": "7e3ee05c-ce4f-4ff1-8230-55555c25c97e",
|
||||
"result": "success", "resultReason": "", "activityDisplayName": "Disable Strong
|
||||
Authentication", "activityDateTime": "2023-07-11T00:01:35.0251899+00:00", "loggedByService":
|
||||
"Core Directory", "operationType": "Update", "userAgent": null, "initiatedBy": {"user":
|
||||
{"id": "728989f4-eb3d-45c2-8741-2f2af4e485ce", "displayName": null, "userPrincipalName":
|
||||
"oops@splunkresearch.com", "ipAddress": "", "roles": []}}, "targetResources": [{"id":
|
||||
"94b969a3-11cb-4075-a1fd-9fee3daf692e", "displayName": null, "type": "User", "userPrincipalName":
|
||||
"Abigail.Clark@splunkresearch.com", "modifiedProperties": [{"displayName": "StrongAuthenticationRequirement",
|
||||
"oldValue": "[{\"RelyingParty\":\"*\",\"State\":1,\"RememberDevicesNotIssuedBefore\":\"2023-07-11T00:01:26+00:00\"}]",
|
||||
"newValue": "[]"}, {"displayName": "Included Updated Properties", "oldValue": null,
|
||||
"newValue": "\"StrongAuthenticationRequirement\""}], "administrativeUnits": []}],
|
||||
"additionalDetails": []}}'
|
||||
@@ -0,0 +1,81 @@
|
||||
name: Azure Active Directory Enable account
|
||||
id: cb49f3cd-04ad-415c-a5ed-9b27b2829fa7
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for Azure Active Directory Enable account
|
||||
source: Azure AD
|
||||
sourcetype: azure:monitor:aad
|
||||
separator: operationName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Cloud Services
|
||||
url: https://splunkbase.splunk.com/app/3110
|
||||
version: 5.2.2
|
||||
fields:
|
||||
- _time
|
||||
- Level
|
||||
- callerIpAddress
|
||||
- category
|
||||
- correlationId
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- durationMs
|
||||
- host
|
||||
- index
|
||||
- linecount
|
||||
- operationName
|
||||
- operationVersion
|
||||
- properties.activityDateTime
|
||||
- properties.activityDisplayName
|
||||
- properties.category
|
||||
- properties.correlationId
|
||||
- properties.id
|
||||
- properties.initiatedBy.user.displayName
|
||||
- properties.initiatedBy.user.id
|
||||
- properties.initiatedBy.user.ipAddress
|
||||
- properties.initiatedBy.user.userPrincipalName
|
||||
- properties.loggedByService
|
||||
- properties.operationType
|
||||
- properties.result
|
||||
- properties.resultReason
|
||||
- properties.targetResources{}.displayName
|
||||
- properties.targetResources{}.id
|
||||
- properties.targetResources{}.modifiedProperties{}.displayName
|
||||
- properties.targetResources{}.modifiedProperties{}.newValue
|
||||
- properties.targetResources{}.modifiedProperties{}.oldValue
|
||||
- properties.targetResources{}.type
|
||||
- properties.targetResources{}.userPrincipalName
|
||||
- properties.userAgent
|
||||
- punct
|
||||
- resourceId
|
||||
- resultSignature
|
||||
- source
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- tenantId
|
||||
- time
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
example_log: '{"time": "2023-07-24T14:28:15.2223487Z", "resourceId": "/tenants/fc69e276-e9e8-4af9-9002-1e410d77244e/providers/Microsoft.aadiam",
|
||||
"operationName": "Enable account", "operationVersion": "1.0", "category": "AuditLogs",
|
||||
"tenantId": "fc69e276-e9e8-4af9-9002-1e410d77244e", "resultSignature": "None", "durationMs":
|
||||
0, "callerIpAddress": "2601:646:a000:200:b0ee:600c:de8a:c7d5", "correlationId":
|
||||
"d34f6d2e-3120-4b96-b922-e06090f6a497", "Level": 4, "properties": {"id": "Directory_d34f6d2e-3120-4b96-b922-e06090f6a497_VPRLA_316413188",
|
||||
"category": "UserManagement", "correlationId": "d34f6d2e-3120-4b96-b922-e06090f6a497",
|
||||
"result": "success", "resultReason": "", "activityDisplayName": "Enable account",
|
||||
"activityDateTime": "2023-07-24T14:28:15.2223487+00:00", "loggedByService": "Core
|
||||
Directory", "operationType": "Update", "userAgent": null, "initiatedBy": {"user":
|
||||
{"id": "728989f4-eb3d-45c2-8741-2f2af4e485ce", "displayName": null, "userPrincipalName":
|
||||
"tommyr@splunkresearch.com", "ipAddress": "2601:646:a000:200:b0ee:600c:de8a:c7d5",
|
||||
"roles": []}}, "targetResources": [{"id": "83a3158c-1d08-4686-b5f9-72fb34cb606e",
|
||||
"displayName": null, "type": "User", "userPrincipalName": "testuser@splunkresearch.com",
|
||||
"modifiedProperties": [{"displayName": "AccountEnabled", "oldValue": "[false]",
|
||||
"newValue": "[true]"}, {"displayName": "Included Updated Properties", "oldValue":
|
||||
null, "newValue": "\"AccountEnabled\""}], "administrativeUnits": []}], "additionalDetails":
|
||||
[]}}'
|
||||
@@ -0,0 +1,82 @@
|
||||
name: Azure Active Directory Invite external user
|
||||
id: d3818bd5-f283-4518-8b67-df19240c3e40
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for Azure Active Directory Invite external user
|
||||
source: Azure AD
|
||||
sourcetype: azure:monitor:aad
|
||||
separator: operationName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Cloud Services
|
||||
url: https://splunkbase.splunk.com/app/3110
|
||||
version: 5.2.2
|
||||
fields:
|
||||
- _time
|
||||
- Level
|
||||
- callerIpAddress
|
||||
- category
|
||||
- correlationId
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- durationMs
|
||||
- host
|
||||
- index
|
||||
- linecount
|
||||
- operationName
|
||||
- operationVersion
|
||||
- properties.activityDateTime
|
||||
- properties.activityDisplayName
|
||||
- properties.additionalDetails{}.key
|
||||
- properties.additionalDetails{}.value
|
||||
- properties.category
|
||||
- properties.correlationId
|
||||
- properties.id
|
||||
- properties.initiatedBy.user.displayName
|
||||
- properties.initiatedBy.user.id
|
||||
- properties.initiatedBy.user.ipAddress
|
||||
- properties.initiatedBy.user.userPrincipalName
|
||||
- properties.loggedByService
|
||||
- properties.operationType
|
||||
- properties.result
|
||||
- properties.resultReason
|
||||
- properties.targetResources{}.displayName
|
||||
- properties.targetResources{}.id
|
||||
- properties.targetResources{}.type
|
||||
- properties.targetResources{}.userPrincipalName
|
||||
- properties.userAgent
|
||||
- punct
|
||||
- resourceId
|
||||
- resultSignature
|
||||
- source
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- tenantId
|
||||
- time
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
example_log: '{"time": "2023-07-13T00:29:59.5100003Z", "resourceId": "/tenants/fc69e276-e9e8-4af9-9002-1e410d77244e/providers/Microsoft.aadiam",
|
||||
"operationName": "Invite external user", "operationVersion": "1.0", "category":
|
||||
"AuditLogs", "tenantId": "fc69e276-e9e8-4af9-9002-1e410d77244e", "resultSignature":
|
||||
"None", "durationMs": 0, "callerIpAddress": "40.126.4.40", "correlationId": "e7d580a6-eaac-4f82-843c-40b0b5f3cf99",
|
||||
"Level": 4, "properties": {"id": "Invited Users_e7d580a6-eaac-4f82-843c-40b0b5f3cf99_YNUMP_7291793",
|
||||
"category": "UserManagement", "correlationId": "e7d580a6-eaac-4f82-843c-40b0b5f3cf99",
|
||||
"result": "success", "resultReason": null, "activityDisplayName": "Invite external
|
||||
user", "activityDateTime": "2023-07-13T00:29:59.5100003+00:00", "loggedByService":
|
||||
"Invited Users", "operationType": "Add", "userAgent": null, "initiatedBy": {"user":
|
||||
{"id": "728989f4-eb3d-45c2-8741-2f2af4e485ce", "displayName": null, "userPrincipalName":
|
||||
"oopsr@splunkresearch.com", "ipAddress": "40.126.4.40", "roles": []}}, "targetResources":
|
||||
[{"id": "f416526a-17ee-4129-8ca9-f5ee55f69f34", "displayName": "oops", "type": "User",
|
||||
"userPrincipalName": "oops360_gmail.com#EXT#@strtadminsplunkresearch.onmicrosoft.com",
|
||||
"modifiedProperties": [], "administrativeUnits": []}], "additionalDetails": [{"key":
|
||||
"oid", "value": "728989f4-eb3d-45c2-8741-2f2af4e485ce"}, {"key": "tid", "value":
|
||||
"fc69e276-e9e8-4af9-9002-1e410d77244e"}, {"key": "ipaddr", "value": "2601:646:a000:200:c4db:f288:7e28:21b3"},
|
||||
{"key": "wids", "value": "62e90394-69f5-4237-9190-012177145e10"}, {"key": "InvitationId",
|
||||
"value": "65c7d12f-c6f3-44f0-8fad-4f57a1020484"}, {"key": "invitedUserEmailAddress",
|
||||
"value": "oops360@gmail.com"}]}}'
|
||||
@@ -0,0 +1,79 @@
|
||||
name: Azure Active Directory Reset password (by admin)
|
||||
id: dcd0e4dc-68f8-4b77-a66f-89c57b3afa6b
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for Azure Active Directory Reset password (by admin)
|
||||
source: Azure AD
|
||||
sourcetype: azure:monitor:aad
|
||||
separator: operationName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Cloud Services
|
||||
url: https://splunkbase.splunk.com/app/3110
|
||||
version: 5.2.2
|
||||
fields:
|
||||
- _time
|
||||
- Level
|
||||
- callerIpAddress
|
||||
- category
|
||||
- correlationId
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- durationMs
|
||||
- host
|
||||
- index
|
||||
- linecount
|
||||
- operationName
|
||||
- operationVersion
|
||||
- properties.activityDateTime
|
||||
- properties.activityDisplayName
|
||||
- properties.additionalDetails{}.key
|
||||
- properties.additionalDetails{}.value
|
||||
- properties.category
|
||||
- properties.correlationId
|
||||
- properties.id
|
||||
- properties.initiatedBy.user.displayName
|
||||
- properties.initiatedBy.user.id
|
||||
- properties.initiatedBy.user.ipAddress
|
||||
- properties.initiatedBy.user.userPrincipalName
|
||||
- properties.loggedByService
|
||||
- properties.operationType
|
||||
- properties.result
|
||||
- properties.resultReason
|
||||
- properties.targetResources{}.displayName
|
||||
- properties.targetResources{}.id
|
||||
- properties.targetResources{}.type
|
||||
- properties.targetResources{}.userPrincipalName
|
||||
- properties.userAgent
|
||||
- punct
|
||||
- resourceId
|
||||
- resultDescription
|
||||
- resultSignature
|
||||
- source
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- tenantId
|
||||
- time
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
example_log: '{"time": "2023-07-24T14:28:55.0648789Z", "resourceId": "/tenants/fc69e276-e9e8-4af9-9002-1e410d77244e/providers/Microsoft.aadiam",
|
||||
"operationName": "Reset password (by admin)", "operationVersion": "1.0", "category":
|
||||
"AuditLogs", "tenantId": "fc69e276-e9e8-4af9-9002-1e410d77244e", "resultSignature":
|
||||
"None", "resultDescription": "None", "durationMs": 0, "callerIpAddress": "40.81.4.144",
|
||||
"correlationId": "724ff6ae-0f36-4f2f-a20f-f043e0c73006", "Level": 4, "properties":
|
||||
{"id": "SSPR_724ff6ae-0f36-4f2f-a20f-f043e0c73006_P1CQE_8605821", "category": "UserManagement",
|
||||
"correlationId": "724ff6ae-0f36-4f2f-a20f-f043e0c73006", "result": "success", "resultReason":
|
||||
"None", "activityDisplayName": "Reset password (by admin)", "activityDateTime":
|
||||
"2023-07-24T14:28:55.0648789+00:00", "loggedByService": "Self-service Password Management",
|
||||
"operationType": "Update", "userAgent": null, "initiatedBy": {"user": {"id": "728989f4-eb3d-45c2-8741-2f2af4e485ce",
|
||||
"displayName": null, "userPrincipalName": "tommyr@splunkresearch.com", "ipAddress":
|
||||
"40.81.4.144", "roles": []}}, "targetResources": [{"id": "83a3158c-1d08-4686-b5f9-72fb34cb606e",
|
||||
"displayName": "test", "type": "User", "userPrincipalName": "testuser@splunkresearch.com",
|
||||
"modifiedProperties": [], "administrativeUnits": []}], "additionalDetails": [{"key":
|
||||
"OnPremisesAgent", "value": "None"}]}}'
|
||||
@@ -0,0 +1,83 @@
|
||||
name: Azure Active Directory Set domain authentication
|
||||
id: e7bcdab9-908c-40ab-ba38-5db54fa87750
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for Azure Active Directory Set domain authentication
|
||||
source: Azure AD
|
||||
sourcetype: azure:monitor:aad
|
||||
separator: operationName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Cloud Services
|
||||
url: https://splunkbase.splunk.com/app/3110
|
||||
version: 5.2.2
|
||||
fields:
|
||||
- _time
|
||||
- Level
|
||||
- callerIpAddress
|
||||
- category
|
||||
- correlationId
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- durationMs
|
||||
- host
|
||||
- index
|
||||
- linecount
|
||||
- operationName
|
||||
- operationVersion
|
||||
- properties.activityDateTime
|
||||
- properties.activityDisplayName
|
||||
- properties.additionalDetails{}.key
|
||||
- properties.additionalDetails{}.value
|
||||
- properties.category
|
||||
- properties.correlationId
|
||||
- properties.id
|
||||
- properties.initiatedBy.user.displayName
|
||||
- properties.initiatedBy.user.id
|
||||
- properties.initiatedBy.user.ipAddress
|
||||
- properties.initiatedBy.user.userPrincipalName
|
||||
- properties.loggedByService
|
||||
- properties.operationType
|
||||
- properties.result
|
||||
- properties.resultReason
|
||||
- properties.targetResources{}.displayName
|
||||
- properties.targetResources{}.id
|
||||
- properties.targetResources{}.modifiedProperties{}.displayName
|
||||
- properties.targetResources{}.modifiedProperties{}.newValue
|
||||
- properties.targetResources{}.modifiedProperties{}.oldValue
|
||||
- properties.userAgent
|
||||
- punct
|
||||
- resourceId
|
||||
- resultSignature
|
||||
- source
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- tenantId
|
||||
- time
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
example_log: '{"time": "2023-07-26T13:44:59.0372448Z", "resourceId": "/tenants/fc69e276-e9e8-4af9-9002-1e410d77244e/providers/Microsoft.aadiam",
|
||||
"operationName": "Set domain authentication", "operationVersion": "1.0", "category":
|
||||
"AuditLogs", "tenantId": "fc69e276-e9e8-4af9-9002-1e410d77244e", "resultSignature":
|
||||
"None", "durationMs": 0, "callerIpAddress": "2601:646:a000:200:6419:f55c:946d:17d1",
|
||||
"correlationId": "57e60ecc-17b8-4ab5-815e-d538e1ca32a4", "Level": 4, "properties":
|
||||
{"id": "Directory_57e60ecc-17b8-4ab5-815e-d538e1ca32a4_XDHHZ_434456733", "category":
|
||||
"DirectoryManagement", "correlationId": "57e60ecc-17b8-4ab5-815e-d538e1ca32a4",
|
||||
"result": "success", "resultReason": "", "activityDisplayName": "Add unverified
|
||||
domain", "activityDateTime": "2023-07-26T13:44:59.0372448+00:00", "loggedByService":
|
||||
"Core Directory", "operationType": "Add", "userAgent": null, "initiatedBy": {"user":
|
||||
{"id": "728989f4-eb3d-45c2-8741-2f2af4e485ce", "displayName": null, "userPrincipalName":
|
||||
"tommyr@splunkresearch.com", "ipAddress": "2601:646:a000:200:6419:f55c:946d:17d1",
|
||||
"roles": []}}, "targetResources": [{"id": null, "displayName": "newdomain.com",
|
||||
"modifiedProperties": [{"displayName": "Name", "oldValue": "[\"\"]", "newValue":
|
||||
"[\"newdomain.com\"]"}, {"displayName": "LiveType", "oldValue": "[\"None\"]", "newValue":
|
||||
"[\"Managed\"]"}, {"displayName": "Included Updated Properties", "oldValue": null,
|
||||
"newValue": "\"Name,LiveType\""}], "administrativeUnits": []}], "additionalDetails":
|
||||
[{"key": "User-Agent", "value": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7)
|
||||
AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36"}]}}'
|
||||
@@ -0,0 +1,161 @@
|
||||
name: Azure Active Directory Sign-in activity
|
||||
id: f9ed0a3a-9e20-4198-a035-d0a29593fbe0
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for Azure Active Directory Sign-in activity
|
||||
source: Azure AD
|
||||
sourcetype: azure:monitor:aad
|
||||
separator: operationName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Cloud Services
|
||||
url: https://splunkbase.splunk.com/app/3110
|
||||
version: 5.2.2
|
||||
fields:
|
||||
- _time
|
||||
- Level
|
||||
- callerIpAddress
|
||||
- category
|
||||
- correlationId
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- durationMs
|
||||
- host
|
||||
- identity
|
||||
- index
|
||||
- linecount
|
||||
- location
|
||||
- operationName
|
||||
- operationVersion
|
||||
- properties.alternateSignInName
|
||||
- properties.appDisplayName
|
||||
- properties.appId
|
||||
- properties.appServicePrincipalId
|
||||
- properties.authenticationDetails{}.RequestSequence
|
||||
- properties.authenticationDetails{}.StatusSequence
|
||||
- properties.authenticationDetails{}.authenticationMethod
|
||||
- properties.authenticationDetails{}.authenticationMethodDetail
|
||||
- properties.authenticationDetails{}.authenticationStepDateTime
|
||||
- properties.authenticationDetails{}.authenticationStepRequirement
|
||||
- properties.authenticationDetails{}.authenticationStepResultDetail
|
||||
- properties.authenticationDetails{}.succeeded
|
||||
- properties.authenticationProcessingDetails{}.key
|
||||
- properties.authenticationProcessingDetails{}.value
|
||||
- properties.authenticationProtocol
|
||||
- properties.authenticationRequirement
|
||||
- properties.authenticationRequirementPolicies{}.detail
|
||||
- properties.authenticationRequirementPolicies{}.requirementProvider
|
||||
- properties.autonomousSystemNumber
|
||||
- properties.clientAppUsed
|
||||
- properties.clientCredentialType
|
||||
- properties.conditionalAccessStatus
|
||||
- properties.correlationId
|
||||
- properties.createdDateTime
|
||||
- properties.crossTenantAccessType
|
||||
- properties.deviceDetail.deviceId
|
||||
- properties.deviceDetail.operatingSystem
|
||||
- properties.flaggedForReview
|
||||
- properties.homeTenantId
|
||||
- properties.id
|
||||
- properties.incomingTokenType
|
||||
- properties.ipAddress
|
||||
- properties.isInteractive
|
||||
- properties.isTenantRestricted
|
||||
- properties.location.city
|
||||
- properties.location.countryOrRegion
|
||||
- properties.location.geoCoordinates.latitude
|
||||
- properties.location.geoCoordinates.longitude
|
||||
- properties.location.state
|
||||
- properties.originalRequestId
|
||||
- properties.originalTransferMethod
|
||||
- properties.processingTimeInMilliseconds
|
||||
- properties.resourceDisplayName
|
||||
- properties.resourceId
|
||||
- properties.resourceServicePrincipalId
|
||||
- properties.resourceTenantId
|
||||
- properties.riskDetail
|
||||
- properties.riskLevelAggregated
|
||||
- properties.riskLevelDuringSignIn
|
||||
- properties.riskState
|
||||
- properties.rngcStatus
|
||||
- properties.servicePrincipalId
|
||||
- properties.signInIdentifier
|
||||
- properties.signInTokenProtectionStatus
|
||||
- properties.ssoExtensionVersion
|
||||
- properties.status.additionalDetails
|
||||
- properties.status.errorCode
|
||||
- properties.status.failureReason
|
||||
- properties.tenantId
|
||||
- properties.tokenIssuerName
|
||||
- properties.tokenIssuerType
|
||||
- properties.uniqueTokenIdentifier
|
||||
- properties.userAgent
|
||||
- properties.userDisplayName
|
||||
- properties.userId
|
||||
- properties.userPrincipalName
|
||||
- properties.userType
|
||||
- punct
|
||||
- resourceId
|
||||
- resultDescription
|
||||
- resultSignature
|
||||
- resultType
|
||||
- source
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- tenantId
|
||||
- time
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
example_log: '{"time": "2023-10-24T20:13:31.4449614Z", "resourceId": "/tenants/887c9144-28b8-431b-885b-764fdeefcf62/providers/Microsoft.aadiam",
|
||||
"operationName": "Sign-in activity", "operationVersion": "1.0", "category": "SignInLogs",
|
||||
"tenantId": "887c9144-28b8-431b-885b-764fdeefcf62", "resultType": "50076", "resultSignature":
|
||||
"None", "resultDescription": "Due to a configuration change made by your administrator,
|
||||
or because you moved to a new location, you must use multi-factor authentication
|
||||
to access the resource.", "durationMs": 0, "callerIpAddress": "1.2.3.4", "correlationId":
|
||||
"1f577997-0710-4bd4-848e-5854f748f7dc", "identity": "user15", "Level": 4, "location":
|
||||
"US", "properties": {"id": "22608a25-1d9b-44b5-b0f2-cb94f06b2d00", "createdDateTime":
|
||||
"2023-10-24T20:01:11.9490387+00:00", "userDisplayName": "user15", "userPrincipalName":
|
||||
"user15@splunkresearch.onmicrosoft.com", "userId": "57e4bd36-9722-4a4a-9729-7203d8e00b72",
|
||||
"appId": "1b730954-1685-4b74-9bfd-dac224a7b894", "appDisplayName": "Azure Active
|
||||
Directory PowerShell", "ipAddress": "1.2.3.4", "status": {"errorCode": 50076, "failureReason":
|
||||
"Due to a configuration change made by your administrator, or because you moved
|
||||
to a new location, you must use multi-factor authentication to access the resource.",
|
||||
"additionalDetails": "MFA required in Azure AD"}, "clientAppUsed": "Mobile Apps
|
||||
and Desktop clients", "userAgent": "Mozilla/5.0 (Windows NT; Windows NT 10.0; en-US)
|
||||
WindowsPowerShell/5.1.22621.2428", "deviceDetail": {"deviceId": "", "operatingSystem":
|
||||
"Windows"}, "location": {"city": "Rochester", "state": "New York", "countryOrRegion":
|
||||
"US", "geoCoordinates": {"latitude": 20.756160123483984, "longitude": -73.99697875976562}},
|
||||
"mfaDetail": {}, "correlationId": "1f577997-0710-4bd4-848e-5854f748f7dc", "conditionalAccessStatus":
|
||||
"notApplied", "appliedConditionalAccessPolicies": [], "authenticationContextClassReferences":
|
||||
[], "originalRequestId": "22608a25-1d9b-44b5-b0f2-cb94f06b2d00", "isInteractive":
|
||||
true, "tokenIssuerName": "", "tokenIssuerType": "AzureAD", "authenticationProcessingDetails":
|
||||
[{"key": "Legacy TLS (TLS 1.0, 1.1, 3DES)", "value": "False"}, {"key": "Is CAE Token",
|
||||
"value": "False"}], "networkLocationDetails": [], "clientCredentialType": "none",
|
||||
"processingTimeInMilliseconds": 72, "riskDetail": "none", "riskLevelAggregated":
|
||||
"none", "riskLevelDuringSignIn": "none", "riskState": "none", "riskEventTypes":
|
||||
[], "riskEventTypes_v2": [], "resourceDisplayName": "Windows Azure Active Directory",
|
||||
"resourceId": "00000002-0000-0000-c000-000000000000", "resourceTenantId": "887c9144-28b8-431b-885b-764fdeefcf62",
|
||||
"homeTenantId": "887c9144-28b8-431b-885b-764fdeefcf62", "tenantId": "887c9144-28b8-431b-885b-764fdeefcf62",
|
||||
"authenticationDetails": [{"authenticationStepDateTime": "2023-10-24T20:01:11.9490387+00:00",
|
||||
"authenticationMethod": "Password", "authenticationMethodDetail": "Password in the
|
||||
cloud", "succeeded": true, "authenticationStepResultDetail": "Correct password",
|
||||
"authenticationStepRequirement": "Primary authentication", "StatusSequence": 0,
|
||||
"RequestSequence": 1}, {"authenticationStepDateTime": "2023-10-24T20:01:11.9490387+00:00",
|
||||
"succeeded": false, "authenticationStepResultDetail": "MFA required in Azure AD",
|
||||
"authenticationStepRequirement": "Primary authentication"}], "authenticationRequirementPolicies":
|
||||
[{"requirementProvider": "user", "detail": "Per-user MFA"}], "sessionLifetimePolicies":
|
||||
[], "authenticationRequirement": "multiFactorAuthentication", "alternateSignInName":
|
||||
"user15@splunkresearch.onmicrosoft.com", "signInIdentifier": "user15@splunkresearch.onmicrosoft.com",
|
||||
"servicePrincipalId": "", "userType": "Member", "flaggedForReview": false, "isTenantRestricted":
|
||||
false, "autonomousSystemNumber": 12271, "crossTenantAccessType": "none", "privateLinkDetails":
|
||||
{}, "ssoExtensionVersion": "", "uniqueTokenIdentifier": "JYpgIpsdtUSw8suU8GstAA",
|
||||
"authenticationStrengths": [], "incomingTokenType": "none", "authenticationProtocol":
|
||||
"ropc", "appServicePrincipalId": null, "resourceServicePrincipalId": "56ad242f-e13b-47fc-8de8-19e3bf6f6575",
|
||||
"rngcStatus": 0, "signInTokenProtectionStatus": "none", "originalTransferMethod":
|
||||
"none"}}'
|
||||
@@ -0,0 +1,83 @@
|
||||
name: Azure Active Directory Update application
|
||||
id: 2c08188a-ba25-496e-87c7-803cf28b6c90
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for Azure Active Directory Update application
|
||||
source: Azure AD
|
||||
sourcetype: azure:monitor:aad
|
||||
separator: operationName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Cloud Services
|
||||
url: https://splunkbase.splunk.com/app/3110
|
||||
version: 5.2.2
|
||||
fields:
|
||||
- _time
|
||||
- Level
|
||||
- category
|
||||
- correlationId
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- durationMs
|
||||
- host
|
||||
- index
|
||||
- linecount
|
||||
- operationName
|
||||
- operationVersion
|
||||
- properties.activityDateTime
|
||||
- properties.activityDisplayName
|
||||
- properties.additionalDetails{}.key
|
||||
- properties.additionalDetails{}.value
|
||||
- properties.category
|
||||
- properties.correlationId
|
||||
- properties.id
|
||||
- properties.initiatedBy.user.displayName
|
||||
- properties.initiatedBy.user.id
|
||||
- properties.initiatedBy.user.ipAddress
|
||||
- properties.initiatedBy.user.userPrincipalName
|
||||
- properties.loggedByService
|
||||
- properties.operationType
|
||||
- properties.result
|
||||
- properties.resultReason
|
||||
- properties.targetResources{}.displayName
|
||||
- properties.targetResources{}.id
|
||||
- properties.targetResources{}.modifiedProperties{}.displayName
|
||||
- properties.targetResources{}.modifiedProperties{}.newValue
|
||||
- properties.targetResources{}.modifiedProperties{}.oldValue
|
||||
- properties.targetResources{}.type
|
||||
- properties.userAgent
|
||||
- punct
|
||||
- resourceId
|
||||
- resultSignature
|
||||
- source
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- tenantId
|
||||
- time
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
example_log: '{"time": "2024-01-29T21:31:03.0102031Z", "resourceId": "/tenants/75243ab2-44f8-435c-a7a6-b479385df6d4/providers/Microsoft.aadiam",
|
||||
"operationName": "Update application", "operationVersion": "1.0", "category": "AuditLogs",
|
||||
"tenantId": "75243ab2-44f8-435c-a7a6-b479385df6d4", "resultSignature": "None", "durationMs":
|
||||
0, "correlationId": "a5396d2b-fcf6-41e7-9219-c6239f1298e3", "Level": 4, "properties":
|
||||
{"id": "Directory_a5396d2b-fcf6-41e7-9219-c6239f1298e3_DGBDP_1548236", "category":
|
||||
"ApplicationManagement", "correlationId": "a5396d2b-fcf6-41e7-9219-c6239f1298e3",
|
||||
"result": "success", "resultReason": "", "activityDisplayName": "Update application",
|
||||
"activityDateTime": "2024-01-29T21:31:03.0102031+00:00", "loggedByService": "Core
|
||||
Directory", "operationType": "Update", "userAgent": null, "initiatedBy": {"user":
|
||||
{"id": "e4c722ac-3b83-478d-8f52-c388885dc30f", "displayName": null, "userPrincipalName":
|
||||
"user30@splunkresearch.onmicrosoft.com", "ipAddress": "", "roles": []}}, "targetResources":
|
||||
[{"id": "75924835-d844-4947-96ba-18074e997386", "displayName": "MaliciousApp", "type":
|
||||
"Application", "modifiedProperties": [{"displayName": "RequiredResourceAccess",
|
||||
"oldValue": "[{\"ResourceAppId\":\"00000003-0000-0000-c000-000000000000\",\"RequiredAppPermissions\":[{\"EntitlementId\":\"570282fd-fa5c-430d-a7fd-fc8dc98a9dca\",\"DirectAccessGrant\":false,\"ImpersonationAccessGrants\":[20]},{\"EntitlementId\":\"7427e0e9-2fba-42fe-b0c0-848c9e6a8182\",\"DirectAccessGrant\":false,\"ImpersonationAccessGrants\":[20]},{\"EntitlementId\":\"e1fe6dd8-ba31-4d61-89e7-88639da4683d\",\"DirectAccessGrant\":false,\"ImpersonationAccessGrants\":[20]},{\"EntitlementId\":\"810c84a8-4a9e-49e6-bf7d-12d183f40d01\",\"DirectAccessGrant\":true,\"ImpersonationAccessGrants\":[]}],\"EncodingVersion\":1}]",
|
||||
"newValue": "[{\"ResourceAppId\":\"00000003-0000-0000-c000-000000000000\",\"RequiredAppPermissions\":[{\"EntitlementId\":\"570282fd-fa5c-430d-a7fd-fc8dc98a9dca\",\"DirectAccessGrant\":false,\"ImpersonationAccessGrants\":[20]},{\"EntitlementId\":\"7427e0e9-2fba-42fe-b0c0-848c9e6a8182\",\"DirectAccessGrant\":false,\"ImpersonationAccessGrants\":[20]},{\"EntitlementId\":\"e1fe6dd8-ba31-4d61-89e7-88639da4683d\",\"DirectAccessGrant\":false,\"ImpersonationAccessGrants\":[20]},{\"EntitlementId\":\"810c84a8-4a9e-49e6-bf7d-12d183f40d01\",\"DirectAccessGrant\":true,\"ImpersonationAccessGrants\":[]}],\"EncodingVersion\":1},{\"ResourceAppId\":\"00000002-0000-0ff1-ce00-000000000000\",\"RequiredAppPermissions\":[{\"EntitlementId\":\"dc890d15-9560-4a4c-9b7f-a736ec74ec40\",\"DirectAccessGrant\":true,\"ImpersonationAccessGrants\":[]}],\"EncodingVersion\":1}]"},
|
||||
{"displayName": "Included Updated Properties", "oldValue": null, "newValue": "\"RequiredResourceAccess\""}],
|
||||
"administrativeUnits": []}], "additionalDetails": [{"key": "User-Agent", "value":
|
||||
"Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like
|
||||
Gecko) Chrome/120.0.0.0 Safari/537.36"}, {"key": "AppId", "value": "867f0d29-0eab-4017-b691-c4713cc7d7b0"}]}}'
|
||||
@@ -0,0 +1,84 @@
|
||||
name: Azure Active Directory Update authorization policy
|
||||
id: c5b7ffcd-73d8-4fe5-afd8-b1218d715c0c
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for Azure Active Directory Update authorization policy
|
||||
source: Azure AD
|
||||
sourcetype: azure:monitor:aad
|
||||
separator: operationName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Cloud Services
|
||||
url: https://splunkbase.splunk.com/app/3110
|
||||
version: 5.2.2
|
||||
fields:
|
||||
- _time
|
||||
- Level
|
||||
- callerIpAddress
|
||||
- category
|
||||
- correlationId
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- durationMs
|
||||
- host
|
||||
- index
|
||||
- linecount
|
||||
- operationName
|
||||
- operationVersion
|
||||
- properties.activityDateTime
|
||||
- properties.activityDisplayName
|
||||
- properties.additionalDetails{}.key
|
||||
- properties.additionalDetails{}.value
|
||||
- properties.category
|
||||
- properties.correlationId
|
||||
- properties.id
|
||||
- properties.initiatedBy.user.displayName
|
||||
- properties.initiatedBy.user.id
|
||||
- properties.initiatedBy.user.ipAddress
|
||||
- properties.initiatedBy.user.userPrincipalName
|
||||
- properties.loggedByService
|
||||
- properties.operationType
|
||||
- properties.result
|
||||
- properties.resultReason
|
||||
- properties.targetResources{}.displayName
|
||||
- properties.targetResources{}.id
|
||||
- properties.targetResources{}.modifiedProperties{}.displayName
|
||||
- properties.targetResources{}.modifiedProperties{}.newValue
|
||||
- properties.targetResources{}.modifiedProperties{}.oldValue
|
||||
- properties.targetResources{}.type
|
||||
- properties.userAgent
|
||||
- punct
|
||||
- resourceId
|
||||
- resultSignature
|
||||
- source
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- tenantId
|
||||
- time
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
example_log: '{"time": "2023-10-26T19:22:20.2814027Z", "resourceId": "/tenants/5f210575-a69b-41a7-b623-3f6d79ccd432/providers/Microsoft.aadiam",
|
||||
"operationName": "Update authorization policy", "operationVersion": "1.0", "category":
|
||||
"AuditLogs", "tenantId": "5f210575-a69b-41a7-b623-3f6d79ccd432", "resultSignature":
|
||||
"None", "durationMs": 0, "callerIpAddress": "1.2.3.4", "correlationId": "cc46d719-4c0f-4b78-8795-b0d6ca5b2065",
|
||||
"Level": 4, "properties": {"id": "Directory_cc46d719-4c0f-4b78-8795-b0d6ca5b2065_6CH7M_196574953",
|
||||
"category": "AuthorizationPolicy", "correlationId": "cc46d719-4c0f-4b78-8795-b0d6ca5b2065",
|
||||
"result": "success", "resultReason": "", "activityDisplayName": "Update authorization
|
||||
policy", "activityDateTime": "2023-10-26T19:22:20.2814027+00:00", "loggedByService":
|
||||
"Core Directory", "operationType": "Update", "userAgent": null, "initiatedBy": {"user":
|
||||
{"id": "e4c722ac-3b83-478d-8f52-c388885dc30f", "displayName": null, "userPrincipalName":
|
||||
"attacker@splunkresearch.onmicrosoft.com", "ipAddress": "1.2.3.4", "roles": []}},
|
||||
"targetResources": [{"id": "24484114-1daa-4700-aaf7-44ee5cbe5678", "displayName":
|
||||
"Authorization Policy", "type": "Other", "modifiedProperties": [{"displayName":
|
||||
"AllowUserConsentForRiskyApps", "oldValue": "[false]", "newValue": "[true]"}, {"displayName":
|
||||
"PermissionGrantPolicyIdsAssignedToDefaultUserRole", "oldValue": "[\"ManagePermissionGrantsForSelf.microsoft-user-default-legacy\"]",
|
||||
"newValue": "[\"microsoft-user-default-legacy\"]"}, {"displayName": "Included Updated
|
||||
Properties", "oldValue": null, "newValue": "\"AllowUserConsentForRiskyApps, PermissionGrantPolicyIdsAssignedToDefaultUserRole\""}],
|
||||
"administrativeUnits": []}], "additionalDetails": [{"key": "User-Agent", "value":
|
||||
"Swagger-Codegen/1.0.0.0/csharp/msal"}]}}'
|
||||
@@ -0,0 +1,83 @@
|
||||
name: Azure Active Directory Update user
|
||||
id: 5495c90a-047c-4b8e-b2fe-1db6282d3872
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for Azure Active Directory Update user
|
||||
source: Azure AD
|
||||
sourcetype: azure:monitor:aad
|
||||
separator: operationName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Cloud Services
|
||||
url: https://splunkbase.splunk.com/app/3110
|
||||
version: 5.2.2
|
||||
fields:
|
||||
- _time
|
||||
- Level
|
||||
- callerIpAddress
|
||||
- category
|
||||
- correlationId
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- durationMs
|
||||
- host
|
||||
- index
|
||||
- linecount
|
||||
- operationName
|
||||
- operationVersion
|
||||
- properties.activityDateTime
|
||||
- properties.activityDisplayName
|
||||
- properties.additionalDetails{}.key
|
||||
- properties.additionalDetails{}.value
|
||||
- properties.category
|
||||
- properties.correlationId
|
||||
- properties.id
|
||||
- properties.initiatedBy.user.displayName
|
||||
- properties.initiatedBy.user.id
|
||||
- properties.initiatedBy.user.ipAddress
|
||||
- properties.initiatedBy.user.userPrincipalName
|
||||
- properties.loggedByService
|
||||
- properties.operationType
|
||||
- properties.result
|
||||
- properties.resultReason
|
||||
- properties.targetResources{}.displayName
|
||||
- properties.targetResources{}.id
|
||||
- properties.targetResources{}.modifiedProperties{}.displayName
|
||||
- properties.targetResources{}.modifiedProperties{}.newValue
|
||||
- properties.targetResources{}.modifiedProperties{}.oldValue
|
||||
- properties.targetResources{}.type
|
||||
- properties.targetResources{}.userPrincipalName
|
||||
- properties.userAgent
|
||||
- punct
|
||||
- resourceId
|
||||
- resultSignature
|
||||
- source
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- tenantId
|
||||
- time
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
example_log: '{"time": "2023-07-24T14:28:15.2233481Z", "resourceId": "/tenants/fc69e276-e9e8-4af9-9002-1e410d77244e/providers/Microsoft.aadiam",
|
||||
"operationName": "Update user", "operationVersion": "1.0", "category": "AuditLogs",
|
||||
"tenantId": "fc69e276-e9e8-4af9-9002-1e410d77244e", "resultSignature": "None", "durationMs":
|
||||
0, "callerIpAddress": "2601:646:a000:200:b0ee:600c:de8a:c7d5", "correlationId":
|
||||
"d34f6d2e-3120-4b96-b922-e06090f6a497", "Level": 4, "properties": {"id": "Directory_d34f6d2e-3120-4b96-b922-e06090f6a497_VPRLA_316413199",
|
||||
"category": "UserManagement", "correlationId": "d34f6d2e-3120-4b96-b922-e06090f6a497",
|
||||
"result": "success", "resultReason": "", "activityDisplayName": "Update user", "activityDateTime":
|
||||
"2023-07-24T14:28:15.2233481+00:00", "loggedByService": "Core Directory", "operationType":
|
||||
"Update", "userAgent": null, "initiatedBy": {"user": {"id": "728989f4-eb3d-45c2-8741-2f2af4e485ce",
|
||||
"displayName": null, "userPrincipalName": "tommyr@splunkresearch.com", "ipAddress":
|
||||
"2601:646:a000:200:b0ee:600c:de8a:c7d5", "roles": []}}, "targetResources": [{"id":
|
||||
"83a3158c-1d08-4686-b5f9-72fb34cb606e", "displayName": null, "type": "User", "userPrincipalName":
|
||||
"testuser@splunkresearch.com", "modifiedProperties": [{"displayName": "AccountEnabled",
|
||||
"oldValue": "[false]", "newValue": "[true]"}, {"displayName": "Included Updated
|
||||
Properties", "oldValue": null, "newValue": "\"AccountEnabled\""}, {"displayName":
|
||||
"TargetId.UserType", "oldValue": null, "newValue": "\"Member\""}], "administrativeUnits":
|
||||
[]}], "additionalDetails": [{"key": "UserType", "value": "Member"}]}}'
|
||||
@@ -0,0 +1,78 @@
|
||||
name: Azure Active Directory User registered security info
|
||||
id: b63240de-8a01-4ba8-8987-89d18d4b375d
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for Azure Active Directory User registered security
|
||||
info
|
||||
source: Azure AD
|
||||
sourcetype: azure:monitor:aad
|
||||
separator: operationName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Cloud Services
|
||||
url: https://splunkbase.splunk.com/app/3110
|
||||
version: 5.2.2
|
||||
fields:
|
||||
- _time
|
||||
- Level
|
||||
- callerIpAddress
|
||||
- category
|
||||
- correlationId
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- durationMs
|
||||
- host
|
||||
- index
|
||||
- linecount
|
||||
- operationName
|
||||
- operationVersion
|
||||
- properties.activityDateTime
|
||||
- properties.activityDisplayName
|
||||
- properties.category
|
||||
- properties.correlationId
|
||||
- properties.id
|
||||
- properties.initiatedBy.user.displayName
|
||||
- properties.initiatedBy.user.id
|
||||
- properties.initiatedBy.user.ipAddress
|
||||
- properties.initiatedBy.user.userPrincipalName
|
||||
- properties.loggedByService
|
||||
- properties.operationType
|
||||
- properties.result
|
||||
- properties.resultReason
|
||||
- properties.targetResources{}.displayName
|
||||
- properties.targetResources{}.id
|
||||
- properties.targetResources{}.type
|
||||
- properties.targetResources{}.userPrincipalName
|
||||
- properties.userAgent
|
||||
- punct
|
||||
- resourceId
|
||||
- resultDescription
|
||||
- resultSignature
|
||||
- source
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- tenantId
|
||||
- time
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
example_log: '{"time": "2023-01-30T21:11:30.8690619Z", "resourceId": "/tenants/91da745f-8abb-4a7d-ba94-5667c6f9e01a/providers/Microsoft.aadiam",
|
||||
"operationName": "User registered security info", "operationVersion": "1.0", "category":
|
||||
"AuditLogs", "tenantId": "91da745f-8abb-4a7d-ba94-5667c6f9e01a", "resultSignature":
|
||||
"None", "resultDescription": "User registered App Password", "durationMs": 0, "callerIpAddress":
|
||||
"72.1.2.43", "correlationId": "14279c94-7ebc-409f-be4e-7861f13c8a79", "Level": 4,
|
||||
"properties": {"id": "IAMUX_14279c94-7ebc-409f-be4e-7861f13c8a79_K2ATV_323947358",
|
||||
"category": "UserManagement", "correlationId": "14279c94-7ebc-409f-be4e-7861f13c8a79",
|
||||
"result": "success", "resultReason": "User registered App Password", "activityDisplayName":
|
||||
"User registered security info", "activityDateTime": "2023-01-30T21:11:30.8690619+00:00",
|
||||
"loggedByService": "Authentication Methods", "operationType": "Add", "userAgent":
|
||||
null, "initiatedBy": {"user": {"id": "40b61050-e814-4ae5-8ffe-66b6f0c53998", "displayName":
|
||||
null, "userPrincipalName": "User30@splunkresearch.com", "ipAddress": "72.1.2.43",
|
||||
"roles": []}}, "targetResources": [{"id": "40b61050-e814-4ae5-8ffe-66b6f0c53998",
|
||||
"displayName": "User30", "type": "User", "userPrincipalName": "User30@splunkresearch.com",
|
||||
"modifiedProperties": [], "administrativeUnits": []}], "additionalDetails": []}}'
|
||||
@@ -0,0 +1,135 @@
|
||||
name: Azure Audit Create or Update an Azure Automation account
|
||||
id: 2ab182e7-feda-4249-9418-32710b55a885
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for Azure Audit Create or Update an Azure Automation
|
||||
account
|
||||
source: mscs:azure:audit
|
||||
sourcetype: mscs:azure:audit
|
||||
separator: operationName.localizedValue
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Cloud Services
|
||||
url: https://splunkbase.splunk.com/app/3110
|
||||
version: 5.2.2
|
||||
fields:
|
||||
- _time
|
||||
- authorization.action
|
||||
- authorization.scope
|
||||
- caller
|
||||
- channels
|
||||
- claims.aio
|
||||
- claims.altsecid
|
||||
- claims.appid
|
||||
- claims.appidacr
|
||||
- claims.aud
|
||||
- claims.exp
|
||||
- claims.groups
|
||||
- claims.http://schemas.microsoft.com/claims/authnclassreference
|
||||
- claims.http://schemas.microsoft.com/claims/authnmethodsreferences
|
||||
- claims.http://schemas.microsoft.com/identity/claims/identityprovider
|
||||
- claims.http://schemas.microsoft.com/identity/claims/objectidentifier
|
||||
- claims.http://schemas.microsoft.com/identity/claims/scope
|
||||
- claims.http://schemas.microsoft.com/identity/claims/tenantid
|
||||
- claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress
|
||||
- claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname
|
||||
- claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
|
||||
- claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier
|
||||
- claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname
|
||||
- claims.iat
|
||||
- claims.ipaddr
|
||||
- claims.iss
|
||||
- claims.name
|
||||
- claims.nbf
|
||||
- claims.puid
|
||||
- claims.rh
|
||||
- claims.uti
|
||||
- claims.ver
|
||||
- claims.wids
|
||||
- claims.xms_tcdt
|
||||
- correlationId
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- dest
|
||||
- dvc
|
||||
- eventDataId
|
||||
- eventName.localizedValue
|
||||
- eventName.value
|
||||
- eventSource.localizedValue
|
||||
- eventSource.value
|
||||
- eventTimestamp
|
||||
- host
|
||||
- id
|
||||
- index
|
||||
- level
|
||||
- linecount
|
||||
- object
|
||||
- object_id
|
||||
- object_path
|
||||
- operationId
|
||||
- operationName.localizedValue
|
||||
- operationName.value
|
||||
- product
|
||||
- properties.entity
|
||||
- properties.eventCategory
|
||||
- properties.hierarchy
|
||||
- properties.message
|
||||
- punct
|
||||
- resourceGroupName
|
||||
- resourceProviderName.localizedValue
|
||||
- resourceProviderName.value
|
||||
- resourceUri
|
||||
- source
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- status
|
||||
- status.localizedValue
|
||||
- status.value
|
||||
- subStatus.value
|
||||
- submissionTimestamp
|
||||
- subscriptionId
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
- user
|
||||
- user_name
|
||||
- vendor
|
||||
- vendor_product
|
||||
- vendor_res_code
|
||||
example_log: '{"authorization": {"action": "Microsoft.Automation/automationAccounts/write",
|
||||
"scope": "/subscriptions/67165197-75ea-4ca3-96a5-3e23868eacd0/resourcegroups/ResourceGroup1/providers/Microsoft.Automation/automationAccounts/TestAutomationAccount"},
|
||||
"caller": "evilAdmin@contoso.com", "channels": "Operation", "claims": {"aud": "https://management.core.windows.net/",
|
||||
"iss": "https://sts.windows.net/ad251139-d600-4f45-a8ba-9f6ca1e5a93d/", "iat": "1661179930",
|
||||
"nbf": "1661179930", "exp": "1661185179", "http://schemas.microsoft.com/claims/authnclassreference":
|
||||
"1", "aio": "AWQAm/8TAAAATFEszAxfULi02mHZwJPr322a2w4m7xjhs9xgc61bVQITM6lcvJI17c8SKQGIWgIA0FysfS1bmLHdxImNfT26qJ5Sfc5UdTncHkz3UYu+AvgCW1gg1mRxOZEFXYdIlQ/h",
|
||||
"altsecid": "1:live.com:000161008492EF5F", "http://schemas.microsoft.com/claims/authnmethodsreferences":
|
||||
"pwd,mfa", "appid": "c44b4083-3bb0-49c1-b47d-974e53cbdf3c", "appidacr": "2", "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress":
|
||||
"evilAdmin@contoso.com", "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname":
|
||||
"Doe", "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "John",
|
||||
"groups": "ecb1fc87-1938-45ff-aaf3-661cee183b11", "http://schemas.microsoft.com/identity/claims/identityprovider":
|
||||
"live.com", "ipaddr": "190.0.0.1", "name": "John Doe", "http://schemas.microsoft.com/identity/claims/objectidentifier":
|
||||
"74b87c49-c202-4101-a8aa-ef18ecc815e8", "puid": "1003200203ECE231", "rh": "0.AX0AORElrQDWRU-oup9soeWpPUZIf3kAutdPukPawfj2MBOaAIM.",
|
||||
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation", "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier":
|
||||
"VVjyH6MJP7pqXTBGCn4NMckGNjX-aYB_Oh7LcI9kaDw", "http://schemas.microsoft.com/identity/claims/tenantid":
|
||||
"ad251139-d600-4f45-a8ba-9f6ca1e5a93d", "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name":
|
||||
"contoso.com#evilAdmin@contoso.com", "uti": "OyNAqM760kmqzxVr6jwtAA", "ver": "1.0",
|
||||
"wids": "62e90394-69f5-4237-9190-012177145e10", "xms_tcdt": "1654791641"}, "correlationId":
|
||||
"59e3de3b-b8c6-4360-9bc5-f094ebce6422", "description": "", "eventDataId": "b0a0bf02-57e5-4eb3-a36d-f2681d874637",
|
||||
"eventName": {"value": "EndRequest", "localizedValue": "End request"}, "eventSource":
|
||||
{"value": "Administrative", "localizedValue": "Administrative"}, "id": "/subscriptions/67165197-75ea-4ca3-96a5-3e23868eacd0/resourcegroups/ResourceGroup1/providers/Microsoft.Automation/automationAccounts/TestAutomationAccount/events/b0a0bf02-57e5-4eb3-a36d-f2681d874637/ticks/637967777618694806",
|
||||
"level": "Informational", "resourceGroupName": "ResourceGroup1", "resourceProviderName":
|
||||
{"value": "Microsoft.Automation", "localizedValue": "Microsoft.Automation"}, "resourceUri":
|
||||
"/subscriptions/67165197-75ea-4ca3-96a5-3e23868eacd0/resourcegroups/ResourceGroup1/providers/Microsoft.Automation/automationAccounts/TestAutomationAccount",
|
||||
"operationId": "6a420172-1ccd-4144-ac12-3095b4019ed5", "operationName": {"value":
|
||||
"Microsoft.Automation/automationAccounts/write", "localizedValue": "Create or Update
|
||||
an Azure Automation account"}, "properties": {"eventCategory": "Administrative",
|
||||
"entity": "/subscriptions/67165197-75ea-4ca3-96a5-3e23868eacd0/resourcegroups/ResourceGroup1/providers/Microsoft.Automation/automationAccounts/TestAutomationAccount",
|
||||
"message": "Microsoft.Automation/automationAccounts/write", "hierarchy": "67165197-75ea-4ca3-96a5-3e23868eacd0"},
|
||||
"status": {"value": "Succeeded", "localizedValue": "Succeeded"}, "subStatus": {"value":
|
||||
"", "localizedValue": ""}, "eventTimestamp": "2022-08-22T15:09:21.8694806Z", "submissionTimestamp":
|
||||
"2022-08-22T15:10:51.152208Z", "subscriptionId": "67165197-75ea-4ca3-96a5-3e23868eacd0"}'
|
||||
@@ -0,0 +1,136 @@
|
||||
name: Azure Audit Create or Update an Azure Automation Runbook
|
||||
id: 2bd83221-7a8b-436f-9b2b-efa1d44d009e
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for Azure Audit Create or Update an Azure Automation
|
||||
Runbook
|
||||
source: mscs:azure:audit
|
||||
sourcetype: mscs:azure:audit
|
||||
separator: operationName.localizedValue
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Cloud Services
|
||||
url: https://splunkbase.splunk.com/app/3110
|
||||
version: 5.2.2
|
||||
fields:
|
||||
- _time
|
||||
- authorization.action
|
||||
- authorization.scope
|
||||
- caller
|
||||
- channels
|
||||
- claims.aio
|
||||
- claims.altsecid
|
||||
- claims.appid
|
||||
- claims.appidacr
|
||||
- claims.aud
|
||||
- claims.exp
|
||||
- claims.groups
|
||||
- claims.http://schemas.microsoft.com/claims/authnclassreference
|
||||
- claims.http://schemas.microsoft.com/claims/authnmethodsreferences
|
||||
- claims.http://schemas.microsoft.com/identity/claims/identityprovider
|
||||
- claims.http://schemas.microsoft.com/identity/claims/objectidentifier
|
||||
- claims.http://schemas.microsoft.com/identity/claims/scope
|
||||
- claims.http://schemas.microsoft.com/identity/claims/tenantid
|
||||
- claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress
|
||||
- claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname
|
||||
- claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
|
||||
- claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier
|
||||
- claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname
|
||||
- claims.iat
|
||||
- claims.ipaddr
|
||||
- claims.iss
|
||||
- claims.name
|
||||
- claims.nbf
|
||||
- claims.puid
|
||||
- claims.rh
|
||||
- claims.uti
|
||||
- claims.ver
|
||||
- claims.wids
|
||||
- claims.xms_tcdt
|
||||
- correlationId
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- dest
|
||||
- dvc
|
||||
- eventDataId
|
||||
- eventName.localizedValue
|
||||
- eventName.value
|
||||
- eventSource.localizedValue
|
||||
- eventSource.value
|
||||
- eventTimestamp
|
||||
- host
|
||||
- id
|
||||
- index
|
||||
- level
|
||||
- linecount
|
||||
- object
|
||||
- object_id
|
||||
- object_path
|
||||
- operationId
|
||||
- operationName.localizedValue
|
||||
- operationName.value
|
||||
- product
|
||||
- properties.entity
|
||||
- properties.eventCategory
|
||||
- properties.hierarchy
|
||||
- properties.message
|
||||
- punct
|
||||
- resourceGroupName
|
||||
- resourceProviderName.localizedValue
|
||||
- resourceProviderName.value
|
||||
- resourceUri
|
||||
- source
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- status
|
||||
- status.localizedValue
|
||||
- status.value
|
||||
- subStatus.value
|
||||
- submissionTimestamp
|
||||
- subscriptionId
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
- user
|
||||
- user_name
|
||||
- vendor
|
||||
- vendor_product
|
||||
- vendor_res_code
|
||||
example_log: '{"authorization": {"action": "Microsoft.Automation/automationAccounts/runbooks/write",
|
||||
"scope": "/subscriptions/1aee0e3d-b75b-440a-a927-76f0552a14e6/resourceGroups/resourceGroup1/providers/Microsoft.Automation/automationAccounts/SuspiciousAutomationAccount/runbooks/SuspiciousRunbook"},
|
||||
"caller": "evilAdmin@contoso.com", "channels": "Operation", "claims": {"aud": "https://management.core.windows.net/",
|
||||
"iss": "https://sts.windows.net/ad251139-d600-4f45-a8ba-9f6ca1e5a93d/", "iat": "1661194261",
|
||||
"nbf": "1661194261", "exp": "1661198249", "http://schemas.microsoft.com/claims/authnclassreference":
|
||||
"1", "aio": "AWQAm/8TAAAA3iMcbqqPPdXPATT7oalIKsh6wEFsyQ+zUVCshaLu77xsLlt067TtI11gy5hAx+z905hrX1VBehDGaedvEg2UF0BSbHVL9bJrry4zk3Xt+HNt5dTXDDgABOFuNB4QJBUW",
|
||||
"altsecid": "1:live.com:000161008492EF5F", "http://schemas.microsoft.com/claims/authnmethodsreferences":
|
||||
"pwd,mfa", "appid": "c44b4083-3bb0-49c1-b47d-974e53cbdf3c", "appidacr": "2", "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress":
|
||||
"evilAdmin@contoso.com", "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname":
|
||||
"Doe", "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "John",
|
||||
"groups": "ecb1fc87-1938-45ff-aaf3-661cee183b11", "http://schemas.microsoft.com/identity/claims/identityprovider":
|
||||
"live.com", "ipaddr": "190.0.0.1", "name": "John Doe", "http://schemas.microsoft.com/identity/claims/objectidentifier":
|
||||
"74b87c49-c202-4101-a8aa-ef18ecc815e8", "puid": "1003200203ECE231", "rh": "0.AX0AORElrQDWRU-oup9soeWpPUZIf3kAutdPukPawfj2MBOaAIM.",
|
||||
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation", "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier":
|
||||
"VVjyH6MJP7pqXTBGCn4NMckGNjX-aYB_Oh7LcI9kaDw", "http://schemas.microsoft.com/identity/claims/tenantid":
|
||||
"ad251139-d600-4f45-a8ba-9f6ca1e5a93d", "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name":
|
||||
"contoso.com#evilAdmin@contoso.com", "uti": "YMAP5fOmMkuuBUgBe-Z5AA", "ver": "1.0",
|
||||
"wids": "62e90394-69f5-4237-9190-012177145e10", "xms_tcdt": "1654791641"}, "correlationId":
|
||||
"49b945c0-966a-48d8-b79b-31f184544594", "description": "", "eventDataId": "303f17eb-10cb-458f-8a80-683f40f123a2",
|
||||
"eventName": {"value": "EndRequest", "localizedValue": "End request"}, "eventSource":
|
||||
{"value": "Administrative", "localizedValue": "Administrative"}, "id": "/subscriptions/1aee0e3d-b75b-440a-a927-76f0552a14e6/resourcegroups/resourceGroup1/providers/Microsoft.Automation/automationAccounts/SuspiciousAutomationAccount/runbooks/SuspiciousRunbook/events/303f17eb-10cb-458f-8a80-683f40f123a2/ticks/637967920541346086",
|
||||
"level": "Informational", "resourceGroupName": "resourceGroup1", "resourceProviderName":
|
||||
{"value": "Microsoft.Automation", "localizedValue": "Microsoft.Automation"}, "resourceUri":
|
||||
"/subscriptions/1aee0e3d-b75b-440a-a927-76f0552a14e6/resourcegroups/resourceGroup1/providers/Microsoft.Automation/automationAccounts/SuspiciousAutomationAccount/runbooks/SuspiciousRunbook",
|
||||
"operationId": "b6e30ace-986c-4735-980f-926db0b43336", "operationName": {"value":
|
||||
"Microsoft.Automation/automationAccounts/runbooks/write", "localizedValue": "Create
|
||||
or Update an Azure Automation Runbook"}, "properties": {"eventCategory": "Administrative",
|
||||
"entity": "/subscriptions/1aee0e3d-b75b-440a-a927-76f0552a14e6/resourcegroups/resourceGroup1/providers/Microsoft.Automation/automationAccounts/SuspiciousAutomationAccount/runbooks/SuspiciousRunbook",
|
||||
"message": "Microsoft.Automation/automationAccounts/runbooks/write", "hierarchy":
|
||||
"1aee0e3d-b75b-440a-a927-76f0552a14e6"}, "status": {"value": "Succeeded", "localizedValue":
|
||||
"Succeeded"}, "subStatus": {"value": "", "localizedValue": ""}, "eventTimestamp":
|
||||
"2022-08-22T19:07:34.1346086Z", "submissionTimestamp": "2022-08-22T19:08:54.1547383Z",
|
||||
"subscriptionId": "1aee0e3d-b75b-440a-a927-76f0552a14e6"}'
|
||||
@@ -0,0 +1,147 @@
|
||||
name: Azure Audit Create or Update an Azure Automation webhook
|
||||
id: 575faeb2-09d0-4849-b1f6-eae241f26ff2
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for Azure Audit Create or Update an Azure Automation
|
||||
webhook
|
||||
source: mscs:azure:audit
|
||||
sourcetype: mscs:azure:audit
|
||||
separator: operationName.localizedValue
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Cloud Services
|
||||
url: https://splunkbase.splunk.com/app/3110
|
||||
version: 5.2.2
|
||||
fields:
|
||||
- _time
|
||||
- authorization.action
|
||||
- authorization.scope
|
||||
- caller
|
||||
- channels
|
||||
- claims.aio
|
||||
- claims.altsecid
|
||||
- claims.appid
|
||||
- claims.appidacr
|
||||
- claims.aud
|
||||
- claims.exp
|
||||
- claims.groups
|
||||
- claims.http://schemas.microsoft.com/claims/authnclassreference
|
||||
- claims.http://schemas.microsoft.com/claims/authnmethodsreferences
|
||||
- claims.http://schemas.microsoft.com/identity/claims/identityprovider
|
||||
- claims.http://schemas.microsoft.com/identity/claims/objectidentifier
|
||||
- claims.http://schemas.microsoft.com/identity/claims/scope
|
||||
- claims.http://schemas.microsoft.com/identity/claims/tenantid
|
||||
- claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress
|
||||
- claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname
|
||||
- claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
|
||||
- claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier
|
||||
- claims.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname
|
||||
- claims.iat
|
||||
- claims.ipaddr
|
||||
- claims.iss
|
||||
- claims.name
|
||||
- claims.nbf
|
||||
- claims.puid
|
||||
- claims.rh
|
||||
- claims.uti
|
||||
- claims.ver
|
||||
- claims.wids
|
||||
- claims.xms_tcdt
|
||||
- correlationId
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- dest
|
||||
- dvc
|
||||
- eventDataId
|
||||
- eventName.localizedValue
|
||||
- eventName.value
|
||||
- eventSource.localizedValue
|
||||
- eventSource.value
|
||||
- eventTimestamp
|
||||
- host
|
||||
- httpRequest.clientIpAddress
|
||||
- httpRequest.clientRequestId
|
||||
- httpRequest.method
|
||||
- id
|
||||
- index
|
||||
- level
|
||||
- linecount
|
||||
- object
|
||||
- object_id
|
||||
- object_path
|
||||
- operationId
|
||||
- operationName.localizedValue
|
||||
- operationName.value
|
||||
- product
|
||||
- properties.entity
|
||||
- properties.eventCategory
|
||||
- properties.hierarchy
|
||||
- properties.message
|
||||
- properties.serviceRequestId
|
||||
- properties.statusCode
|
||||
- punct
|
||||
- resourceGroupName
|
||||
- resourceProviderName.localizedValue
|
||||
- resourceProviderName.value
|
||||
- resourceUri
|
||||
- result
|
||||
- result_id
|
||||
- source
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- src
|
||||
- status
|
||||
- status.localizedValue
|
||||
- status.value
|
||||
- subStatus.localizedValue
|
||||
- subStatus.value
|
||||
- submissionTimestamp
|
||||
- subscriptionId
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
- user
|
||||
- user_name
|
||||
- vendor
|
||||
- vendor_product
|
||||
- vendor_res_code
|
||||
example_log: '{"authorization": {"action": "Microsoft.Automation/automationAccounts/webhooks/write",
|
||||
"scope": "/subscriptions/e0c00901-96b2-4151-80f7-746e24c03e98/resourceGroups/resourceGroup1providers/Microsoft.Automation/automationAccounts/SuspiciousAutomationAccount/webhooks/MaliciousWebHook"},
|
||||
"caller": "evilAdmin@contoso.com", "channels": "Operation", "claims": {"aud": "https://management.core.windows.net/",
|
||||
"iss": "https://sts.windows.net/ad251139-d600-4f45-a8ba-9f6ca1e5a93d/", "iat": "1661287859",
|
||||
"nbf": "1661287859", "exp": "1661293423", "http://schemas.microsoft.com/claims/authnclassreference":
|
||||
"1", "aio": "AWQAm/8TAAAAEendcgWjYQFuDhNNhoecwU3dpXjjenSsIvjamk77+TjLK/o1xkFGcFb1A+OVyuY+xefe0X39n8lx1iFWFqGo0GSNNKhm9OQcv/0UyXiaNIbKD7wisgQhAa9DoIyObMpO",
|
||||
"altsecid": "1:contoso.com:000161008492EF5F", "http://schemas.microsoft.com/claims/authnmethodsreferences":
|
||||
"pwd,mfa", "appid": "c44b4083-3bb0-49c1-b47d-974e53cbdf3c", "appidacr": "2", "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress":
|
||||
"evilAdmin@contosol.com", "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname":
|
||||
"Doe", "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname": "John",
|
||||
"groups": "ecb1fc87-1938-45ff-aaf3-661cee183b11", "http://schemas.microsoft.com/identity/claims/identityprovider":
|
||||
"contoso.com", "ipaddr": "190.0.0.1", "name": "John Doe", "http://schemas.microsoft.com/identity/claims/objectidentifier":
|
||||
"74b87c49-c202-4101-a8aa-ef18ecc815e8", "puid": "1003200203ECE231", "rh": "0.AX0AORElrQDWRU-oup9soeWpPUZIf3kAutdPukPawfj2MBOaAIM.",
|
||||
"http://schemas.microsoft.com/identity/claims/scope": "user_impersonation", "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameidentifier":
|
||||
"VVjyH6MJP7pqXTBGCn4NMckGNjX-aYB_Oh7LcI9kaDw", "http://schemas.microsoft.com/identity/claims/tenantid":
|
||||
"ad251139-d600-4f45-a8ba-9f6ca1e5a93d", "http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name":
|
||||
"contoso.com#evilAdmin@contoso.com", "uti": "epgtY-85CUeb6aJpaE0KAQ", "ver": "1.0",
|
||||
"wids": "62e90394-69f5-4237-9190-012177145e10", "xms_tcdt": "1654791641"}, "correlationId":
|
||||
"74e18a58-ee2e-40de-890d-de0c155f7086", "description": "", "eventDataId": "35b9db88-8041-413e-8dd7-f8dc243eafdd",
|
||||
"eventName": {"value": "EndRequest", "localizedValue": "End request"}, "eventSource":
|
||||
{"value": "Administrative", "localizedValue": "Administrative"}, "httpRequest":
|
||||
{"clientRequestId": "6934b40a-c11f-4379-9ef1-c6fa3cee5015", "clientIpAddress": "190.0.0.1",
|
||||
"method": "PUT"}, "id": "/subscriptions/e0c00901-96b2-4151-80f7-746e24c03e98/resourceGroups/resourceGroup1providers/Microsoft.Automation/automationAccounts/SuspiciousAutomationAccount/webhooks/MaliciousWebHook/events/35b9db88-8041-413e-8dd7-f8dc243eafdd/ticks/637968850422707386",
|
||||
"level": "Informational", "resourceGroupName": "eventhub_rg", "resourceProviderName":
|
||||
{"value": "Microsoft.Automation", "localizedValue": "Microsoft.Automation"}, "resourceUri":
|
||||
"/subscriptions/e0c00901-96b2-4151-80f7-746e24c03e98/resourceGroups/resourceGroup1providers/Microsoft.Automation/automationAccounts/SuspiciousAutomationAccount/webhooks/MaliciousWebHook",
|
||||
"operationId": "74e18a58-ee2e-40de-890d-de0c155f7086", "operationName": {"value":
|
||||
"Microsoft.Automation/automationAccounts/webhooks/write", "localizedValue": "Create
|
||||
or Update an Azure Automation webhook"}, "properties": {"statusCode": "Created",
|
||||
"serviceRequestId": null, "eventCategory": "Administrative", "entity": "/subscriptions/e0c00901-96b2-4151-80f7-746e24c03e98/resourceGroups/resourceGroup1providers/Microsoft.Automation/automationAccounts/SuspiciousAutomationAccount/webhooks/MaliciousWebHook",
|
||||
"message": "Microsoft.Automation/automationAccounts/webhooks/write", "hierarchy":
|
||||
"e0c00901-96b2-4151-80f7-746e24c03e98"}, "status": {"value": "Succeeded", "localizedValue":
|
||||
"Succeeded"}, "subStatus": {"value": "Created", "localizedValue": "Created (HTTP
|
||||
Status Code: 201)"}, "eventTimestamp": "2022-08-23T20:57:22.2707386Z", "submissionTimestamp":
|
||||
"2022-08-23T20:58:54.2071536Z", "subscriptionId": "e0c00901-96b2-4151-80f7-746e24c03e98"}'
|
||||
@@ -1,7 +1,10 @@
|
||||
name: Bro
|
||||
id: c5d9612b-0ffd-44d3-8247-3cf3486ec5e2
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for Bro
|
||||
source: bro:http:json
|
||||
sourcetype: bro:http:json
|
||||
supported_TA: {}
|
||||
event_names: []
|
||||
supported_TA:
|
||||
- {}
|
||||
@@ -1,27 +0,0 @@
|
||||
name: Endpoint.Filesystem
|
||||
prefix: Filesystem
|
||||
fields:
|
||||
- action
|
||||
- dest
|
||||
- dest_bunit
|
||||
- dest_category
|
||||
- dest_priority
|
||||
- dest_requires_av
|
||||
- dest_should_timesync
|
||||
- dest_should_update
|
||||
- file_access_time
|
||||
- file_create_time
|
||||
- file_hash
|
||||
- file_modify_time
|
||||
- file_name
|
||||
- file_path
|
||||
- file_acl
|
||||
- file_size
|
||||
- process_guid
|
||||
- process_id
|
||||
- tag
|
||||
- user
|
||||
- user_bunit
|
||||
- user_category
|
||||
- user_priority
|
||||
- vendor_product
|
||||
@@ -1,39 +0,0 @@
|
||||
name: Endpoint.Processes
|
||||
prefix: Processes
|
||||
fields:
|
||||
- action
|
||||
- cpu_load_percent
|
||||
- dest
|
||||
- dest_bunit
|
||||
- dest_category
|
||||
- dest_is_expected
|
||||
- dest_priority
|
||||
- dest_requires_av
|
||||
- dest_should_timesync
|
||||
- dest_should_update
|
||||
- loaded_file
|
||||
- mem_used
|
||||
- original_file_name
|
||||
- os
|
||||
- parent_process
|
||||
- parent_process_exec
|
||||
- parent_process_id
|
||||
- parent_process_guid
|
||||
- parent_process_name
|
||||
- parent_process_path
|
||||
- process
|
||||
- process_current_directory
|
||||
- process_exec
|
||||
- process_hash
|
||||
- process_guid
|
||||
- process_id
|
||||
- process_integrity_level
|
||||
- process_name
|
||||
- process_path
|
||||
- tag
|
||||
- user
|
||||
- user_id
|
||||
- user_bunit
|
||||
- user_category
|
||||
- user_priority
|
||||
- vendor_product
|
||||
@@ -1,27 +0,0 @@
|
||||
name: Endpoint.Registry
|
||||
prefix: Registry
|
||||
fields:
|
||||
- action
|
||||
- dest
|
||||
- dest_bunit
|
||||
- dest_category
|
||||
- dest_priority
|
||||
- dest_requires_av
|
||||
- dest_should_timesync
|
||||
- dest_should_update
|
||||
- process_guid
|
||||
- process_id
|
||||
- registry_hive
|
||||
- registry_path
|
||||
- registry_key_name
|
||||
- registry_value_data
|
||||
- registry_value_name
|
||||
- registry_value_text
|
||||
- registry_value_type
|
||||
- status
|
||||
- tag
|
||||
- user
|
||||
- user_bunit
|
||||
- user_category
|
||||
- user_priority
|
||||
- vendor_product
|
||||
@@ -1,35 +0,0 @@
|
||||
name: Endpoint.Services
|
||||
prefix: Services
|
||||
fields:
|
||||
- description
|
||||
- dest
|
||||
- dest_bunit
|
||||
- dest_category
|
||||
- dest_is_expected
|
||||
- dest_priority
|
||||
- dest_requires_av
|
||||
- dest_should_timesync
|
||||
- dest_should_update
|
||||
- process_guid
|
||||
- process_id
|
||||
- service
|
||||
- service_dll
|
||||
- service_dll_path
|
||||
- service_dll_hash
|
||||
- service_dll_signature_exists
|
||||
- service_dll_signature_verified
|
||||
- service_exec
|
||||
- service_hash
|
||||
- service_id
|
||||
- service_name
|
||||
- service_path
|
||||
- service_signature_exists
|
||||
- service_signature_verified
|
||||
- start_mode
|
||||
- status
|
||||
- tag
|
||||
- user
|
||||
- user_bunit
|
||||
- user_category
|
||||
- user_priority
|
||||
- vendor_product
|
||||
@@ -1,32 +0,0 @@
|
||||
name: Network_Resolution.DNS
|
||||
prefix: DNS
|
||||
fields:
|
||||
- additional_answer_count
|
||||
- answer
|
||||
- answer_count
|
||||
- authority_answer_count
|
||||
- dest
|
||||
- dest_bunit
|
||||
- dest_category
|
||||
- dest_port
|
||||
- dest_priority
|
||||
- duration
|
||||
- message_type
|
||||
- name
|
||||
- query
|
||||
- query_count
|
||||
- query_type
|
||||
- record_type
|
||||
- reply_code
|
||||
- reply_code_id
|
||||
- response_time
|
||||
- src
|
||||
- src_bunit
|
||||
- src_category
|
||||
- src_port
|
||||
- src_priority
|
||||
- tag
|
||||
- transaction_id
|
||||
- transport
|
||||
- ttl
|
||||
- vendor_product
|
||||
@@ -1,66 +0,0 @@
|
||||
name: Network_Traffic.All_Traffic
|
||||
prefix: All_Traffic
|
||||
fields:
|
||||
- action
|
||||
- app
|
||||
- bytes
|
||||
- bytes_in
|
||||
- bytes_out
|
||||
- channel
|
||||
- dest
|
||||
- dest_bunit
|
||||
- dest_category
|
||||
- dest_interface
|
||||
- dest_ip
|
||||
- dest_mac
|
||||
- dest_port
|
||||
- dest_priority
|
||||
- dest_translated_ip
|
||||
- dest_translated_port
|
||||
- dest_zone
|
||||
- direction
|
||||
- duration
|
||||
- dvc
|
||||
- dvc_bunit
|
||||
- dvc_category
|
||||
- dvc_ip
|
||||
- dvc_mac
|
||||
- dvc_priority
|
||||
- dvc_zone
|
||||
- flow_id
|
||||
- icmp_code
|
||||
- icmp_type
|
||||
- packets
|
||||
- packets_in
|
||||
- packets_out
|
||||
- process_id
|
||||
- protocol
|
||||
- protocol_version
|
||||
- response_time
|
||||
- rule
|
||||
- session_id
|
||||
- src
|
||||
- src_bunit
|
||||
- src_category
|
||||
- src_interface
|
||||
- src_ip
|
||||
- src_mac
|
||||
- src_port
|
||||
- src_priority
|
||||
- src_translated_ip
|
||||
- src_translated_port
|
||||
- src_zone
|
||||
- ssid
|
||||
- tag
|
||||
- tcp_flag
|
||||
- transport
|
||||
- tos
|
||||
- ttl
|
||||
- user
|
||||
- user_bunit
|
||||
- user_category
|
||||
- user_priority
|
||||
- vendor_account
|
||||
- vendor_product
|
||||
- vlan
|
||||
- wifi
|
||||
@@ -1,41 +0,0 @@
|
||||
name: Web.Web
|
||||
prefix: Web
|
||||
fields:
|
||||
- action
|
||||
- app
|
||||
- bytes
|
||||
- bytes_in
|
||||
- bytes_out
|
||||
- cached
|
||||
- category
|
||||
- cookie
|
||||
- dest
|
||||
- dest_bunit
|
||||
- dest_category
|
||||
- dest_priority
|
||||
- dest_port
|
||||
- duration
|
||||
- http_content_type
|
||||
- http_method
|
||||
- http_referrer
|
||||
- http_referrer_domain
|
||||
- http_user_agent
|
||||
- http_user_agent_length
|
||||
- response_time
|
||||
- site
|
||||
- src
|
||||
- src_bunit
|
||||
- src_category
|
||||
- src_priority
|
||||
- status
|
||||
- tag
|
||||
- uri_path
|
||||
- uri_query
|
||||
- url
|
||||
- url_domain
|
||||
- url_length
|
||||
- user
|
||||
- user_bunit
|
||||
- user_category
|
||||
- user_priority
|
||||
- vendor_product
|
||||
@@ -1,68 +1,69 @@
|
||||
name: CircleCI
|
||||
id: 34ad06fc-a296-4ab5-8315-2f07714948e3
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for CircleCI
|
||||
source: circleci
|
||||
sourcetype: circleci
|
||||
supported_TA:
|
||||
name: App for CircleCI
|
||||
version: 0.1.1
|
||||
- name: App for CircleCI
|
||||
url: https://splunkbase.splunk.com/app/5162
|
||||
event_names: []
|
||||
version: 0.1.1
|
||||
fields:
|
||||
- _time
|
||||
- author_name
|
||||
- avatar_url
|
||||
- branch
|
||||
- build_num
|
||||
- build_time_millis
|
||||
- build_url
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- eventtype
|
||||
- fail_reason
|
||||
- host
|
||||
- index
|
||||
- job_name
|
||||
- job_time
|
||||
- linecount
|
||||
- owners{}
|
||||
- project_slug
|
||||
- punct
|
||||
- queued_time
|
||||
- reponame
|
||||
- source
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- start_time
|
||||
- status
|
||||
- stop_time
|
||||
- tag
|
||||
- tag::eventtype
|
||||
- timedout
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
- username
|
||||
- vcs.commit_time
|
||||
- vcs.committer_name
|
||||
- vcs.revision
|
||||
- vcs.subject
|
||||
- vcs.tag
|
||||
- vcs.type
|
||||
- vcs.url
|
||||
- workflows.job_id
|
||||
- workflows.job_name
|
||||
- workflows.upstream_job_ids{}
|
||||
- workflows.workflow_id
|
||||
- workflows.workflow_name
|
||||
- workflows.workspace_id
|
||||
example_log:
|
||||
'{"job_time": "2021-09-02T08:13:34.273Z", "stop_time": "2021-09-02T08:13:34.273Z",
|
||||
- _time
|
||||
- author_name
|
||||
- avatar_url
|
||||
- branch
|
||||
- build_num
|
||||
- build_time_millis
|
||||
- build_url
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- eventtype
|
||||
- fail_reason
|
||||
- host
|
||||
- index
|
||||
- job_name
|
||||
- job_time
|
||||
- linecount
|
||||
- owners{}
|
||||
- project_slug
|
||||
- punct
|
||||
- queued_time
|
||||
- reponame
|
||||
- source
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- start_time
|
||||
- status
|
||||
- stop_time
|
||||
- tag
|
||||
- tag::eventtype
|
||||
- timedout
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
- username
|
||||
- vcs.commit_time
|
||||
- vcs.committer_name
|
||||
- vcs.revision
|
||||
- vcs.subject
|
||||
- vcs.tag
|
||||
- vcs.type
|
||||
- vcs.url
|
||||
- workflows.job_id
|
||||
- workflows.job_name
|
||||
- workflows.upstream_job_ids{}
|
||||
- workflows.workflow_id
|
||||
- workflows.workflow_name
|
||||
- workflows.workspace_id
|
||||
example_log: '{"job_time": "2021-09-02T08:13:34.273Z", "stop_time": "2021-09-02T08:13:34.273Z",
|
||||
"start_time": "2021-09-02T08:10:15.829Z", "queued_time": "2021-09-02T08:10:12.764Z",
|
||||
"job_name": "Unknown", "reponame": "devsecops_poc", "build_num": 94, "build_url":
|
||||
"https://circleci.com/gh/splunk/devsecops_poc/94", "branch": "main", "status": "success",
|
||||
@@ -1,229 +0,0 @@
|
||||
name: AWS CloudTrail
|
||||
id: aa8d90bf-8ab1-4a9f-8c1b-24a67b1cd0b0
|
||||
author: Patrick Bareiss, Splunk
|
||||
source: aws_cloudtrail
|
||||
sourcetype: aws:cloudtrail
|
||||
separator: eventName
|
||||
supported_TA:
|
||||
name: Splunk Add-on for Amazon Web Services (AWS)
|
||||
version: 7.4.1
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
event_names:
|
||||
- event_name: AWS CloudTrail
|
||||
data_source: data_sources/cloud/event_sources/AWS_CloudTrail.yml
|
||||
- event_name: AWS CloudTrail AssumeRoleWithSAML
|
||||
data_source: data_sources/cloud/event_sources/AWS_CloudTrail_AssumeRoleWithSAML.yml
|
||||
- event_name: AWS CloudTrail ConsoleLogin
|
||||
data_source: data_sources/cloud/event_sources/AWS_CloudTrail_ConsoleLogin.yml
|
||||
- event_name: AWS CloudTrail CopyObject
|
||||
data_source: data_sources/cloud/event_sources/AWS_CloudTrail_CopyObject.yml
|
||||
- event_name: AWS CloudTrail CreateAccessKey
|
||||
data_source: data_sources/cloud/event_sources/AWS_CloudTrail_CreateAccessKey.yml
|
||||
- event_name: AWS CloudTrail CreateKey
|
||||
data_source: data_sources/cloud/event_sources/AWS_CloudTrail_CreateKey.yml
|
||||
- event_name: AWS CloudTrail CreateLoginProfile
|
||||
data_source: data_sources/cloud/event_sources/AWS_CloudTrail_CreateLoginProfile.yml
|
||||
- event_name: AWS CloudTrail CreateNetworkAclEntry
|
||||
data_source: data_sources/cloud/event_sources/AWS_CloudTrail_CreateNetworkAclEntry.yml
|
||||
- event_name: AWS CloudTrail CreatePolicyVersion
|
||||
data_source: data_sources/cloud/event_sources/AWS_CloudTrail_CreatePolicyVersion.yml
|
||||
- event_name: AWS CloudTrail CreateSnapshot
|
||||
data_source: data_sources/cloud/event_sources/AWS_CloudTrail_CreateSnapshot.yml
|
||||
- event_name: AWS CloudTrail CreateTask
|
||||
data_source: data_sources/cloud/event_sources/AWS_CloudTrail_CreateTask.yml
|
||||
- event_name: AWS CloudTrail CreateVirtualMFADevice
|
||||
data_source: data_sources/cloud/event_sources/AWS_CloudTrail_CreateVirtualMFADevice.yml
|
||||
- event_name: AWS CloudTrail DeactivateMFADevice
|
||||
data_source: data_sources/cloud/event_sources/AWS_CloudTrail_DeactivateMFADevice.yml
|
||||
- event_name: AWS CloudTrail DeleteAccountPasswordPolicy
|
||||
data_source: data_sources/cloud/event_sources/AWS_CloudTrail_DeleteAccountPasswordPolicy.yml
|
||||
- event_name: AWS CloudTrail DeleteAlarms
|
||||
data_source: data_sources/cloud/event_sources/AWS_CloudTrail_DeleteAlarms.yml
|
||||
- event_name: AWS CloudTrail DeleteDetector
|
||||
data_source: data_sources/cloud/event_sources/AWS_CloudTrail_DeleteDetector.yml
|
||||
- event_name: AWS CloudTrail DeleteGroup
|
||||
data_source: data_sources/cloud/event_sources/AWS_CloudTrail_DeleteGroup.yml
|
||||
- event_name: AWS CloudTrail DeleteIPSet
|
||||
data_source: data_sources/cloud/event_sources/AWS_CloudTrail_DeleteIPSet.yml
|
||||
- event_name: AWS CloudTrail DeleteLogGroup
|
||||
data_source: data_sources/cloud/event_sources/AWS_CloudTrail_DeleteLogGroup.yml
|
||||
- event_name: AWS CloudTrail DeleteLogStream
|
||||
data_source: data_sources/cloud/event_sources/AWS_CloudTrail_DeleteLogStream.yml
|
||||
- event_name: AWS CloudTrail DeleteLoggingConfiguration
|
||||
data_source: data_sources/cloud/event_sources/AWS_CloudTrail_DeleteLoggingConfiguration.yml
|
||||
- event_name: AWS CloudTrail DeleteNetworkAclEntry
|
||||
data_source: data_sources/cloud/event_sources/AWS_CloudTrail_DeleteNetworkAclEntry.yml
|
||||
- event_name: AWS CloudTrail DeletePolicy
|
||||
data_source: data_sources/cloud/event_sources/AWS_CloudTrail_DeletePolicy.yml
|
||||
- event_name: AWS CloudTrail DeleteRule
|
||||
data_source: data_sources/cloud/event_sources/AWS_CloudTrail_DeleteRule.yml
|
||||
- event_name: AWS CloudTrail DeleteRuleGroup
|
||||
data_source: data_sources/cloud/event_sources/AWS_CloudTrail_DeleteRuleGroup.yml
|
||||
- event_name: AWS CloudTrail DeleteSnapshot
|
||||
data_source: data_sources/cloud/event_sources/AWS_CloudTrail_DeleteSnapshot.yml
|
||||
- event_name: AWS CloudTrail DeleteTrail
|
||||
data_source: data_sources/cloud/event_sources/AWS_CloudTrail_DeleteTrail.yml
|
||||
- event_name: AWS CloudTrail DeleteVirtualMFADevice
|
||||
data_source: data_sources/cloud/event_sources/AWS_CloudTrail_DeleteVirtualMFADevice.yml
|
||||
- event_name: AWS CloudTrail DeleteWebACL
|
||||
data_source: data_sources/cloud/event_sources/AWS_CloudTrail_DeleteWebACL.yml
|
||||
- event_name: AWS CloudTrail DescribeEventAggregates
|
||||
data_source: data_sources/cloud/event_sources/AWS_CloudTrail_DescribeEventAggregates.yml
|
||||
- event_name: AWS CloudTrail DescribeImageScanFindings
|
||||
data_source: data_sources/cloud/event_sources/AWS_CloudTrail_DescribeImageScanFindings.yml
|
||||
- event_name: AWS CloudTrail DescribeSnapshotAttribute
|
||||
data_source: data_sources/cloud/event_sources/AWS_CloudTrail_DescribeSnapshotAttribute.yml
|
||||
- event_name: AWS CloudTrail GetAccountPasswordPolicy
|
||||
data_source: data_sources/cloud/event_sources/AWS_CloudTrail_GetAccountPasswordPolicy.yml
|
||||
- event_name: AWS CloudTrail GetObject
|
||||
data_source: data_sources/cloud/event_sources/AWS_CloudTrail_GetObject.yml
|
||||
- event_name: AWS CloudTrail GetPasswordData
|
||||
data_source: data_sources/cloud/event_sources/AWS_CloudTrail_GetPasswordData.yml
|
||||
- event_name: AWS CloudTrail JobCreated
|
||||
data_source: data_sources/cloud/event_sources/AWS_CloudTrail_JobCreated.yml
|
||||
- event_name: AWS CloudTrail ModifyDBInstance
|
||||
data_source: data_sources/cloud/event_sources/AWS_CloudTrail_ModifyDBInstance.yml
|
||||
- event_name: AWS CloudTrail ModifyImageAttribute
|
||||
data_source: data_sources/cloud/event_sources/AWS_CloudTrail_ModifyImageAttribute.yml
|
||||
- event_name: AWS CloudTrail ModifySnapshotAttribute
|
||||
data_source: data_sources/cloud/event_sources/AWS_CloudTrail_ModifySnapshotAttribute.yml
|
||||
- event_name: AWS CloudTrail PutBucketAcl
|
||||
data_source: data_sources/cloud/event_sources/AWS_CloudTrail_PutBucketAcl.yml
|
||||
- event_name: AWS CloudTrail PutBucketLifecycle
|
||||
data_source: data_sources/cloud/event_sources/AWS_CloudTrail_PutBucketLifecycle.yml
|
||||
- event_name: AWS CloudTrail PutBucketReplication
|
||||
data_source: data_sources/cloud/event_sources/AWS_CloudTrail_PutBucketReplication.yml
|
||||
- event_name: AWS CloudTrail PutBucketVersioning
|
||||
data_source: data_sources/cloud/event_sources/AWS_CloudTrail_PutBucketVersioning.yml
|
||||
- event_name: AWS CloudTrail PutImage
|
||||
data_source: data_sources/cloud/event_sources/AWS_CloudTrail_PutImage.yml
|
||||
- event_name: AWS CloudTrail PutKeyPolicy
|
||||
data_source: data_sources/cloud/event_sources/AWS_CloudTrail_PutKeyPolicy.yml
|
||||
- event_name: AWS CloudTrail ReplaceNetworkAclEntry
|
||||
data_source: data_sources/cloud/event_sources/AWS_CloudTrail_ReplaceNetworkAclEntry.yml
|
||||
- event_name: AWS CloudTrail SetDefaultPolicyVersion
|
||||
data_source: data_sources/cloud/event_sources/AWS_CloudTrail_SetDefaultPolicyVersion.yml
|
||||
- event_name: AWS CloudTrail StopLogging
|
||||
data_source: data_sources/cloud/event_sources/AWS_CloudTrail_StopLogging.yml
|
||||
- event_name: AWS CloudTrail UpdateAccountPasswordPolicy
|
||||
data_source: data_sources/cloud/event_sources/AWS_CloudTrail_UpdateAccountPasswordPolicy.yml
|
||||
- event_name: AWS CloudTrail UpdateLoginProfile
|
||||
data_source: data_sources/cloud/event_sources/AWS_CloudTrail_UpdateLoginProfile.yml
|
||||
- event_name: AWS CloudTrail UpdateSAMLProvider
|
||||
data_source: data_sources/cloud/event_sources/AWS_CloudTrail_UpdateSAMLProvider.yml
|
||||
- event_name: AWS CloudTrail UpdateTrail
|
||||
data_source: data_sources/cloud/event_sources/AWS_CloudTrail_UpdateTrail.yml
|
||||
fields:
|
||||
- _time
|
||||
- action
|
||||
- app
|
||||
- awsRegion
|
||||
- aws_account_id
|
||||
- change_type
|
||||
- command
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- dest
|
||||
- direction
|
||||
- dvc
|
||||
- errorCode
|
||||
- eventCategory
|
||||
- eventID
|
||||
- eventName
|
||||
- eventSource
|
||||
- eventTime
|
||||
- eventType
|
||||
- eventVersion
|
||||
- eventtype
|
||||
- host
|
||||
- index
|
||||
- linecount
|
||||
- managementEvent
|
||||
- msg
|
||||
- object
|
||||
- object_category
|
||||
- object_id
|
||||
- product
|
||||
- protocol
|
||||
- punct
|
||||
- readOnly
|
||||
- recipientAccountId
|
||||
- region
|
||||
- requestID
|
||||
- requestParameters.groupId
|
||||
- requestParameters.ipPermissions.items{}.fromPort
|
||||
- requestParameters.ipPermissions.items{}.ipProtocol
|
||||
- requestParameters.ipPermissions.items{}.ipRanges.items{}.cidrIp
|
||||
- requestParameters.ipPermissions.items{}.toPort
|
||||
- responseElements._return
|
||||
- responseElements.requestId
|
||||
- responseElements.securityGroupRuleSet.items{}.cidrIpv4
|
||||
- responseElements.securityGroupRuleSet.items{}.fromPort
|
||||
- responseElements.securityGroupRuleSet.items{}.groupId
|
||||
- responseElements.securityGroupRuleSet.items{}.groupOwnerId
|
||||
- responseElements.securityGroupRuleSet.items{}.ipProtocol
|
||||
- responseElements.securityGroupRuleSet.items{}.isEgress
|
||||
- responseElements.securityGroupRuleSet.items{}.securityGroupRuleId
|
||||
- responseElements.securityGroupRuleSet.items{}.toPort
|
||||
- signature
|
||||
- source
|
||||
- sourceIPAddress
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- src
|
||||
- src_ip
|
||||
- src_ip_range
|
||||
- src_port_range
|
||||
- start_time
|
||||
- status
|
||||
- tag
|
||||
- tag::eventtype
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
- tlsDetails.cipherSuite
|
||||
- tlsDetails.clientProvidedHostHeader
|
||||
- tlsDetails.tlsVersion
|
||||
- user
|
||||
- userAgent
|
||||
- userIdentity.accessKeyId
|
||||
- userIdentity.accountId
|
||||
- userIdentity.arn
|
||||
- userIdentity.principalId
|
||||
- userIdentity.type
|
||||
- userIdentity.userName
|
||||
- userName
|
||||
- user_access_key
|
||||
- user_agent
|
||||
- user_arn
|
||||
- user_group_id
|
||||
- user_id
|
||||
- user_name
|
||||
- user_type
|
||||
- vendor
|
||||
- vendor_account
|
||||
- vendor_product
|
||||
- vendor_region
|
||||
example_log: '{"eventVersion": "1.09", "userIdentity": {"type": "IAMUser", "principalId":
|
||||
"AIDAAAAAAAAAAAAAAAAAA", "arn": "arn:aws:iam::111111111111:user/daftpunk_cli", "accountId":
|
||||
"111111111111", "accessKeyId": "AKIAAAAAAAAAAAAAAAAA", "userName": "daftpunk_cli"},
|
||||
"eventTime": "2024-02-21T19:19:40Z", "eventSource": "ec2.amazonaws.com", "eventName":
|
||||
"AuthorizeSecurityGroupIngress", "awsRegion": "us-west-2", "sourceIPAddress": "2.2.2.2",
|
||||
"userAgent": "aws-cli/2.13.22 Python/3.11.5 Darwin/22.5.0 source/arm64 prompt/off
|
||||
command/ec2.authorize-security-group-ingress", "requestParameters": {"groupId":
|
||||
"sg-07ffb1896dcd3713e", "ipPermissions": {"items": [{"ipProtocol": "-1", "fromPort":
|
||||
-1, "toPort": -1, "groups": {}, "ipRanges": {"items": [{"cidrIp": "0.0.0.0/0"}]},
|
||||
"ipv6Ranges": {}, "prefixListIds": {}}]}}, "responseElements": {"requestId": "4950930b-2129-423c-95b0-1b87c8fa115a",
|
||||
"_return": true, "securityGroupRuleSet": {"items": [{"groupOwnerId": "111111111111",
|
||||
"groupId": "sg-07ffb1896dcd3713e", "securityGroupRuleId": "sgr-0217c1b508cc6b76c",
|
||||
"isEgress": false, "ipProtocol": "-1", "fromPort": -1, "toPort": -1, "cidrIpv4":
|
||||
"0.0.0.0/0"}]}}, "requestID": "4950930b-2129-423c-95b0-1b87c8fa115a", "eventID":
|
||||
"bdade96f-6272-468a-b084-413b9711e92f", "readOnly": false, "eventType": "AwsApiCall",
|
||||
"managementEvent": true, "recipientAccountId": "111111111111", "eventCategory":
|
||||
"Management", "tlsDetails": {"tlsVersion": "TLSv1.3", "cipherSuite": "TLS_AES_128_GCM_SHA256",
|
||||
"clientProvidedHostHeader": "ec2.us-west-2.amazonaws.com"}}'
|
||||
@@ -1,66 +0,0 @@
|
||||
name: AWS CloudWatchLogs VPCflow
|
||||
id: 38a34fc4-e128-4478-a8f4-7835d51d5135
|
||||
author: Bhavin Patel, Splunk
|
||||
source: aws_cloudwatchlogs_vpcflow
|
||||
sourcetype: aws:cloudwatchlogs:vpcflow
|
||||
separator: eventName
|
||||
supported_TA:
|
||||
name: Splunk Add-on for Amazon Web Services (AWS)
|
||||
version: 7.4.1
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
event_names: []
|
||||
fields:
|
||||
- _raw
|
||||
- _time
|
||||
- account_id
|
||||
- action
|
||||
- app
|
||||
- aws_account_id
|
||||
- bytes
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- dest
|
||||
- dest_ip
|
||||
- dest_port
|
||||
- duration
|
||||
- dvc
|
||||
- end_time
|
||||
- eventtype
|
||||
- host
|
||||
- index
|
||||
- interface_id
|
||||
- linecount
|
||||
- log_status
|
||||
- packets
|
||||
- protocol
|
||||
- protocol_code
|
||||
- protocol_full_name
|
||||
- protocol_version
|
||||
- punct
|
||||
- region
|
||||
- source
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- splunk_server_group
|
||||
- src
|
||||
- src_ip
|
||||
- src_port
|
||||
- start_time
|
||||
- tag
|
||||
- tag::action
|
||||
- tag::eventtype
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
- transport
|
||||
- user_id
|
||||
- vendor_account
|
||||
- vendor_product
|
||||
- version
|
||||
- vpcflow_action
|
||||
example_log: '2 123397614277 eni-0b0f9f261f45e6489 10.0.1.30 10.0.1.1 47254 22 17 2 98 1697608042 1697608070 ACCEPT OK'
|
||||
@@ -1,180 +0,0 @@
|
||||
name: Azure Active Directory
|
||||
id: 7c12d2b2-2679-4806-b258-c17eaffbc66d
|
||||
author: Patrick Bareiss, Splunk
|
||||
source: Azure AD
|
||||
sourcetype: azure:monitor:aad
|
||||
separator: operationName
|
||||
supported_TA:
|
||||
name: Splunk Add-on for Microsoft Cloud Services
|
||||
version: 5.2.2
|
||||
url: https://splunkbase.splunk.com/app/3110
|
||||
event_names:
|
||||
- event_name: Azure Active Directory
|
||||
data_source: data_sources/cloud/event_sources/Azure_Active_Directory.yml
|
||||
- event_name: Azure Active Directory Add app role assignment to service principal
|
||||
data_source: data_sources/cloud/event_sources/Azure_Active_Directory_Add_app_role_assignment_to_service_principal.yml
|
||||
- event_name: Azure Active Directory Add member to role
|
||||
data_source: data_sources/cloud/event_sources/Azure_Active_Directory_Add_member_to_role.yml
|
||||
- event_name: Azure Active Directory Add owner to application
|
||||
data_source: data_sources/cloud/event_sources/Azure_Active_Directory_Add_owner_to_application.yml
|
||||
- event_name: Azure Active Directory Add service principal
|
||||
data_source: data_sources/cloud/event_sources/Azure_Active_Directory_Add_service_principal.yml
|
||||
- event_name: Azure Active Directory Add unverified domain
|
||||
data_source: data_sources/cloud/event_sources/Azure_Active_Directory_Add_unverified_domain.yml
|
||||
- event_name: Azure Active Directory Consent to application
|
||||
data_source: data_sources/cloud/event_sources/Azure_Active_Directory_Consent_to_application.yml
|
||||
- event_name: Azure Active Directory Disable Strong Authentication
|
||||
data_source: data_sources/cloud/event_sources/Azure_Active_Directory_Disable_Strong_Authentication.yml
|
||||
- event_name: Azure Active Directory Enable account
|
||||
data_source: data_sources/cloud/event_sources/Azure_Active_Directory_Enable_account.yml
|
||||
- event_name: Azure Active Directory Invite external user
|
||||
data_source: data_sources/cloud/event_sources/Azure_Active_Directory_Invite_external_user.yml
|
||||
- event_name: Azure Active Directory Reset password (by admin)
|
||||
data_source: data_sources/cloud/event_sources/Azure_Active_Directory_Reset_password_(by_admin).yml
|
||||
- event_name: Azure Active Directory Set domain authentication
|
||||
data_source: data_sources/cloud/event_sources/Azure_Active_Directory_Set_domain_authentication.yml
|
||||
- event_name: Azure Active Directory Sign-in activity
|
||||
data_source: data_sources/cloud/event_sources/Azure_Active_Directory_Sign-in_activity.yml
|
||||
- event_name: Azure Active Directory Update application
|
||||
data_source: data_sources/cloud/event_sources/Azure_Active_Directory_Update_application.yml
|
||||
- event_name: Azure Active Directory Update authorization policy
|
||||
data_source: data_sources/cloud/event_sources/Azure_Active_Directory_Update_authorization_policy.yml
|
||||
- event_name: Azure Active Directory Update user
|
||||
data_source: data_sources/cloud/event_sources/Azure_Active_Directory_Update_user.yml
|
||||
- event_name: Azure Active Directory User registered security info
|
||||
data_source: data_sources/cloud/event_sources/Azure_Active_Directory_User_registered_security_info.yml
|
||||
fields:
|
||||
- _time
|
||||
- Level
|
||||
- callerIpAddress
|
||||
- category
|
||||
- correlationId
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- durationMs
|
||||
- host
|
||||
- identity
|
||||
- index
|
||||
- linecount
|
||||
- location
|
||||
- operationName
|
||||
- operationVersion
|
||||
- properties.alternateSignInName
|
||||
- properties.appDisplayName
|
||||
- properties.appId
|
||||
- properties.appServicePrincipalId
|
||||
- properties.authenticationDetails{}.RequestSequence
|
||||
- properties.authenticationDetails{}.StatusSequence
|
||||
- properties.authenticationDetails{}.authenticationMethod
|
||||
- properties.authenticationDetails{}.authenticationMethodDetail
|
||||
- properties.authenticationDetails{}.authenticationStepDateTime
|
||||
- properties.authenticationDetails{}.authenticationStepRequirement
|
||||
- properties.authenticationDetails{}.authenticationStepResultDetail
|
||||
- properties.authenticationDetails{}.succeeded
|
||||
- properties.authenticationProcessingDetails{}.key
|
||||
- properties.authenticationProcessingDetails{}.value
|
||||
- properties.authenticationProtocol
|
||||
- properties.authenticationRequirement
|
||||
- properties.autonomousSystemNumber
|
||||
- properties.clientAppUsed
|
||||
- properties.clientCredentialType
|
||||
- properties.conditionalAccessStatus
|
||||
- properties.correlationId
|
||||
- properties.createdDateTime
|
||||
- properties.crossTenantAccessType
|
||||
- properties.deviceDetail.deviceId
|
||||
- properties.deviceDetail.operatingSystem
|
||||
- properties.flaggedForReview
|
||||
- properties.homeTenantId
|
||||
- properties.id
|
||||
- properties.incomingTokenType
|
||||
- properties.ipAddress
|
||||
- properties.isInteractive
|
||||
- properties.isTenantRestricted
|
||||
- properties.location.city
|
||||
- properties.location.countryOrRegion
|
||||
- properties.location.geoCoordinates.latitude
|
||||
- properties.location.geoCoordinates.longitude
|
||||
- properties.location.state
|
||||
- properties.originalRequestId
|
||||
- properties.processingTimeInMilliseconds
|
||||
- properties.resourceDisplayName
|
||||
- properties.resourceId
|
||||
- properties.resourceServicePrincipalId
|
||||
- properties.resourceTenantId
|
||||
- properties.riskDetail
|
||||
- properties.riskLevelAggregated
|
||||
- properties.riskLevelDuringSignIn
|
||||
- properties.riskState
|
||||
- properties.rngcStatus
|
||||
- properties.servicePrincipalId
|
||||
- properties.signInIdentifier
|
||||
- properties.ssoExtensionVersion
|
||||
- properties.status.errorCode
|
||||
- properties.status.failureReason
|
||||
- properties.tokenIssuerName
|
||||
- properties.tokenIssuerType
|
||||
- properties.uniqueTokenIdentifier
|
||||
- properties.userAgent
|
||||
- properties.userDisplayName
|
||||
- properties.userId
|
||||
- properties.userPrincipalName
|
||||
- properties.userType
|
||||
- punct
|
||||
- resourceId
|
||||
- resultDescription
|
||||
- resultSignature
|
||||
- resultType
|
||||
- source
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- tenantId
|
||||
- time
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
example_log: '{"time": "2023-01-23T21:29:14.1490728Z", "resourceId": "/tenants/fc69e276-e9e8-4af9-9002-1e410d77244e/providers/Microsoft.aadiam",
|
||||
"operationName": "Sign-in activity", "operationVersion": "1.0", "category": "SignInLogs",
|
||||
"tenantId": "fc69e276-e9e8-4af9-9002-1e410d77244e", "resultType": "50126", "resultSignature":
|
||||
"None", "resultDescription": "Invalid username or password or Invalid on-premise
|
||||
username or password.", "durationMs": 0, "callerIpAddress": "35.80.10.10", "correlationId":
|
||||
"1634ad3a-1f98-4964-add5-92fc58621944", "identity": "User30", "Level": 4, "location":
|
||||
"US", "properties": {"id": "13148568-d61e-45eb-b38b-1fa63c106d00", "createdDateTime":
|
||||
"2023-01-23T21:29:14.1490728+00:00", "userDisplayName": "User30", "userPrincipalName":
|
||||
"user30@splunkresearch.com", "userId": "40b61050-e814-4ae5-8ffe-66b6f0c53998", "appId":
|
||||
"1b730954-1685-4b74-9bfd-dac224a7b894", "appDisplayName": "Azure Active Directory
|
||||
PowerShell", "ipAddress": "35.80.10.10", "status": {"errorCode": 50126, "failureReason":
|
||||
"Invalid username or password or Invalid on-premise username or password."}, "clientAppUsed":
|
||||
"Mobile Apps and Desktop clients", "userAgent": "Mozilla/5.0 (Windows NT; Windows
|
||||
NT 10.0; en-US) WindowsPowerShell/5.1.14393.5127", "deviceDetail": {"deviceId":
|
||||
"", "operatingSystem": "Windows 10"}, "location": {"city": "Boardman", "state":
|
||||
"Oregon", "countryOrRegion": "US", "geoCoordinates": {"latitude": 45.83599853515625,
|
||||
"longitude": -119.6989974975586}}, "correlationId": "1634ad3a-1f98-4964-add5-92fc58621944",
|
||||
"conditionalAccessStatus": "notApplied", "appliedConditionalAccessPolicies": [],
|
||||
"authenticationContextClassReferences": [], "originalRequestId": "13148568-d61e-45eb-b38b-1fa63c106d00",
|
||||
"isInteractive": true, "tokenIssuerName": "", "tokenIssuerType": "AzureAD", "authenticationProcessingDetails":
|
||||
[{"key": "Legacy TLS (TLS 1.0, 1.1, 3DES)", "value": "False"}, {"key": "Is CAE Token",
|
||||
"value": "False"}], "networkLocationDetails": [], "clientCredentialType": "none",
|
||||
"processingTimeInMilliseconds": 47, "riskDetail": "none", "riskLevelAggregated":
|
||||
"none", "riskLevelDuringSignIn": "none", "riskState": "none", "riskEventTypes":
|
||||
[], "riskEventTypes_v2": [], "resourceDisplayName": "Windows Azure Active Directory",
|
||||
"resourceId": "00000002-0000-0000-c000-000000000000", "resourceTenantId": "fc69e276-e9e8-4af9-9002-1e410d77244e",
|
||||
"homeTenantId": "fc69e276-e9e8-4af9-9002-1e410d77244e", "authenticationDetails":
|
||||
[{"authenticationStepDateTime": "2023-01-23T21:29:14.1490728+00:00", "authenticationMethod":
|
||||
"Password", "authenticationMethodDetail": "Password in the cloud", "succeeded":
|
||||
false, "authenticationStepResultDetail": "Invalid username or password or Invalid
|
||||
on-premise username or password.", "authenticationStepRequirement": "Primary authentication",
|
||||
"StatusSequence": 0, "RequestSequence": 1}], "authenticationRequirementPolicies":
|
||||
[], "authenticationRequirement": "singleFactorAuthentication", "alternateSignInName":
|
||||
"user30@splunkresearch.com", "signInIdentifier": "user30@splunkresearch.com", "servicePrincipalId":
|
||||
"", "userType": "Member", "flaggedForReview": false, "isTenantRestricted": false,
|
||||
"autonomousSystemNumber": 16509, "crossTenantAccessType": "none", "privateLinkDetails":
|
||||
{}, "ssoExtensionVersion": "", "uniqueTokenIdentifier": "aIUUEx7W60Wzix-mPBBtAA",
|
||||
"authenticationStrengths": [], "incomingTokenType": "none", "authenticationProtocol":
|
||||
"none", "appServicePrincipalId": null, "resourceServicePrincipalId": "4d6bd7de-c9bc-45cc-b8ec-ae315f66bf77",
|
||||
"rngcStatus": 0}}'
|
||||
@@ -1,17 +0,0 @@
|
||||
name: Azure Audit
|
||||
id: 62e2f93e-4e9c-4d38-bb2c-6d59c4565318
|
||||
author: Patrick Bareiss, Splunk
|
||||
source: mscs:azure:audit
|
||||
sourcetype: mscs:azure:audit
|
||||
separator: operationName.localizedValue
|
||||
supported_TA:
|
||||
name: Splunk Add-on for Microsoft Cloud Services
|
||||
version: 5.2.2
|
||||
url: https://splunkbase.splunk.com/app/3110
|
||||
event_names:
|
||||
- event_name: Azure Audit Create or Update an Azure Automation Runbook
|
||||
data_source: data_sources/cloud/event_sources/Azure_Audit_Create_or_Update_an_Azure_Automation_Runbook.yml
|
||||
- event_name: Azure Audit Create or Update an Azure Automation account
|
||||
data_source: data_sources/cloud/event_sources/Azure_Audit_Create_or_Update_an_Azure_Automation_account.yml
|
||||
- event_name: Azure Audit Create or Update an Azure Automation webhook
|
||||
data_source: data_sources/cloud/event_sources/Azure_Audit_Create_or_Update_an_Azure_Automation_webhook.yml
|
||||
@@ -1,205 +0,0 @@
|
||||
name: GitHub
|
||||
id: 88aa4632-3c3e-43f6-a00a-998d71f558e3
|
||||
author: Patrick Bareiss, Splunk
|
||||
source: github
|
||||
sourcetype: aws:firehose:json
|
||||
supported_TA:
|
||||
name: Splunk Add-on for Github
|
||||
version: 2.2.1
|
||||
url: https://splunkbase.splunk.com/app/6254
|
||||
event_names: []
|
||||
fields:
|
||||
- _time
|
||||
- action
|
||||
- host
|
||||
- index
|
||||
- linecount
|
||||
- meta
|
||||
- punct
|
||||
- source
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- timestamp
|
||||
- workflow_run.actor.avatar_url
|
||||
- workflow_run.actor.events_url
|
||||
- workflow_run.actor.followers_url
|
||||
- workflow_run.actor.following_url
|
||||
- workflow_run.actor.gists_url
|
||||
- workflow_run.actor.gravatar_id
|
||||
- workflow_run.actor.html_url
|
||||
- workflow_run.actor.id
|
||||
- workflow_run.actor.login
|
||||
- workflow_run.actor.node_id
|
||||
- workflow_run.actor.organizations_url
|
||||
- workflow_run.actor.received_events_url
|
||||
- workflow_run.actor.repos_url
|
||||
- workflow_run.actor.site_admin
|
||||
- workflow_run.actor.starred_url
|
||||
- workflow_run.actor.subscriptions_url
|
||||
- workflow_run.actor.type
|
||||
- workflow_run.actor.url
|
||||
- workflow_run.artifacts_url
|
||||
- workflow_run.cancel_url
|
||||
- workflow_run.check_suite_id
|
||||
- workflow_run.check_suite_node_id
|
||||
- workflow_run.check_suite_url
|
||||
- workflow_run.conclusion
|
||||
- workflow_run.created_at
|
||||
- workflow_run.event
|
||||
- workflow_run.head_branch
|
||||
- workflow_run.head_commit.author.email
|
||||
- workflow_run.head_commit.author.name
|
||||
- workflow_run.head_commit.committer.email
|
||||
- workflow_run.head_commit.committer.name
|
||||
- workflow_run.head_commit.id
|
||||
- workflow_run.head_commit.message
|
||||
- workflow_run.head_commit.timestamp
|
||||
- workflow_run.head_commit.tree_id
|
||||
- workflow_run.head_repository.collaborators_url
|
||||
- workflow_run.head_repository.description
|
||||
- workflow_run.head_repository.fork
|
||||
- workflow_run.head_repository.forks_url
|
||||
- workflow_run.head_repository.full_name
|
||||
- workflow_run.head_repository.hooks_url
|
||||
- workflow_run.head_repository.html_url
|
||||
- workflow_run.head_repository.id
|
||||
- workflow_run.head_repository.keys_url
|
||||
- workflow_run.head_repository.name
|
||||
- workflow_run.head_repository.node_id
|
||||
- workflow_run.head_repository.owner.avatar_url
|
||||
- workflow_run.head_repository.owner.events_url
|
||||
- workflow_run.head_repository.owner.followers_url
|
||||
- workflow_run.head_repository.owner.following_url
|
||||
- workflow_run.head_repository.owner.gists_url
|
||||
- workflow_run.head_repository.owner.gravatar_id
|
||||
- workflow_run.head_repository.owner.html_url
|
||||
- workflow_run.head_repository.owner.id
|
||||
- workflow_run.head_repository.owner.login
|
||||
- workflow_run.head_repository.owner.node_id
|
||||
- workflow_run.head_repository.owner.organizations_url
|
||||
- workflow_run.head_repository.owner.received_events_url
|
||||
- workflow_run.head_repository.owner.repos_url
|
||||
- workflow_run.head_repository.owner.site_admin
|
||||
- workflow_run.head_repository.owner.starred_url
|
||||
- workflow_run.head_repository.owner.subscriptions_url
|
||||
- workflow_run.head_repository.owner.type
|
||||
- workflow_run.head_repository.owner.url
|
||||
- workflow_run.head_repository.private
|
||||
- workflow_run.head_repository.teams_url
|
||||
- workflow_run.head_repository.url
|
||||
- workflow_run.head_sha
|
||||
- workflow_run.html_url
|
||||
- workflow_run.id
|
||||
- workflow_run.jobs_url
|
||||
- workflow_run.logs_url
|
||||
- workflow_run.name
|
||||
- workflow_run.node_id
|
||||
- workflow_run.previous_attempt_url
|
||||
- workflow_run.pull_requests{}.base.ref
|
||||
- workflow_run.pull_requests{}.base.repo.id
|
||||
- workflow_run.pull_requests{}.base.repo.name
|
||||
- workflow_run.pull_requests{}.base.repo.url
|
||||
- workflow_run.pull_requests{}.base.sha
|
||||
- workflow_run.pull_requests{}.head.ref
|
||||
- workflow_run.pull_requests{}.head.repo.id
|
||||
- workflow_run.pull_requests{}.head.repo.name
|
||||
- workflow_run.pull_requests{}.head.repo.url
|
||||
- workflow_run.pull_requests{}.head.sha
|
||||
- workflow_run.pull_requests{}.id
|
||||
- workflow_run.pull_requests{}.number
|
||||
- workflow_run.pull_requests{}.url
|
||||
- workflow_run.repository.archive_url
|
||||
- workflow_run.repository.assignees_url
|
||||
- workflow_run.repository.blobs_url
|
||||
- workflow_run.repository.branches_url
|
||||
- workflow_run.repository.collaborators_url
|
||||
- workflow_run.repository.comments_url
|
||||
- workflow_run.repository.commits_url
|
||||
- workflow_run.repository.compare_url
|
||||
- workflow_run.repository.contents_url
|
||||
- workflow_run.repository.contributors_url
|
||||
- workflow_run.repository.deployments_url
|
||||
- workflow_run.repository.description
|
||||
- workflow_run.repository.downloads_url
|
||||
- workflow_run.repository.events_url
|
||||
- workflow_run.repository.fork
|
||||
- workflow_run.repository.forks_url
|
||||
- workflow_run.repository.full_name
|
||||
- workflow_run.repository.git_commits_url
|
||||
- workflow_run.repository.git_refs_url
|
||||
- workflow_run.repository.git_tags_url
|
||||
- workflow_run.repository.hooks_url
|
||||
- workflow_run.repository.html_url
|
||||
- workflow_run.repository.id
|
||||
- workflow_run.repository.issue_comment_url
|
||||
- workflow_run.repository.issue_events_url
|
||||
- workflow_run.repository.issues_url
|
||||
- workflow_run.repository.keys_url
|
||||
- workflow_run.repository.labels_url
|
||||
- workflow_run.repository.languages_url
|
||||
- workflow_run.repository.merges_url
|
||||
- workflow_run.repository.milestones_url
|
||||
- workflow_run.repository.name
|
||||
- workflow_run.repository.node_id
|
||||
- workflow_run.repository.notifications_url
|
||||
- workflow_run.repository.owner.avatar_url
|
||||
- workflow_run.repository.owner.events_url
|
||||
- workflow_run.repository.owner.followers_url
|
||||
- workflow_run.repository.owner.following_url
|
||||
- workflow_run.repository.owner.gists_url
|
||||
- workflow_run.repository.owner.gravatar_id
|
||||
- workflow_run.repository.owner.html_url
|
||||
- workflow_run.repository.owner.id
|
||||
- workflow_run.repository.owner.login
|
||||
- workflow_run.repository.owner.node_id
|
||||
- workflow_run.repository.owner.organizations_url
|
||||
- workflow_run.repository.owner.received_events_url
|
||||
- workflow_run.repository.owner.repos_url
|
||||
- workflow_run.repository.owner.site_admin
|
||||
- workflow_run.repository.owner.starred_url
|
||||
- workflow_run.repository.owner.subscriptions_url
|
||||
- workflow_run.repository.owner.type
|
||||
- workflow_run.repository.owner.url
|
||||
- workflow_run.repository.private
|
||||
- workflow_run.repository.pulls_url
|
||||
- workflow_run.repository.releases_url
|
||||
- workflow_run.repository.stargazers_url
|
||||
- workflow_run.repository.statuses_url
|
||||
- workflow_run.repository.subscribers_url
|
||||
- workflow_run.repository.subscription_url
|
||||
- workflow_run.repository.tags_url
|
||||
- workflow_run.repository.teams_url
|
||||
- workflow_run.repository.trees_url
|
||||
- workflow_run.repository.url
|
||||
- workflow_run.rerun_url
|
||||
- workflow_run.run_attempt
|
||||
- workflow_run.run_number
|
||||
- workflow_run.run_started_at
|
||||
- workflow_run.status
|
||||
- workflow_run.triggering_actor.avatar_url
|
||||
- workflow_run.triggering_actor.events_url
|
||||
- workflow_run.triggering_actor.followers_url
|
||||
- workflow_run.triggering_actor.following_url
|
||||
- workflow_run.triggering_actor.gists_url
|
||||
- workflow_run.triggering_actor.gravatar_id
|
||||
- workflow_run.triggering_actor.html_url
|
||||
- workflow_run.triggering_actor.id
|
||||
- workflow_run.triggering_actor.login
|
||||
- workflow_run.triggering_actor.node_id
|
||||
- workflow_run.triggering_actor.organizations_url
|
||||
- workflow_run.triggering_actor.received_events_url
|
||||
- workflow_run.triggering_actor.repos_url
|
||||
- workflow_run.triggering_actor.site_admin
|
||||
- workflow_run.triggering_actor.starred_url
|
||||
- workflow_run.triggering_actor.subscriptions_url
|
||||
- workflow_run.triggering_actor.type
|
||||
- workflow_run.triggering_actor.url
|
||||
- workflow_run.updated_at
|
||||
- workflow_run.url
|
||||
- workflow_run.workflow_id
|
||||
- workflow_run.workflow_url
|
||||
example_log:
|
||||
'{"action":"requested","workflow_run":{"id":2088708615,"name":"auto-update","node_id":"WFR_kwLOCa00Ec58fyoH","head_branch":"mac_os_detections","head_sha":"4049334910ea3d52a917ca35aed66d11c80ed966","run_number":9504,"event":"push","status":"queued","conclusion":null,"workflow_id":4692335,"check_suite_id":5918781611,"check_suite_node_id":"CS_kwDOCa00Ec8AAAABYMlwqw","url":"https://api.github.com/repos/splunk/security_content/actions/runs/2088708615","html_url":"https://github.com/splunk/security_content/actions/runs/2088708615","pull_requests":[{"url":"https://api.github.com/repos/splunk/security_content/pulls/2131","id":893091277,"number":2131,"head":{"ref":"mac_os_detections","sha":"4049334910ea3d52a917ca35aed66d11c80ed966","repo":{"id":162346001,"url":"https://api.github.com/repos/splunk/security_content","name":"security_content"}},"base":{"ref":"develop","sha":"a7d3d1dc57f9bf36fe22e470bcf518fcc2c89283","repo":{"id":162346001,"url":"https://api.github.com/repos/splunk/security_content","name":"security_content"}}}],"created_at":"2022-04-04T08:43:15Z","updated_at":"2022-04-04T08:43:15Z","actor":{"login":"jsmith","id":8362376,"node_id":"MDQ6VXNlcjgzNjIzNzY=","avatar_url":"https://avatars.githubusercontent.com/u/8362376?v=4","gravatar_id":"","url":"https://api.github.com/users/jsmith","html_url":"https://github.com/jsmith","followers_url":"https://api.github.com/users/jsmith/followers","following_url":"https://api.github.com/users/jsmith/following{/other_user}","gists_url":"https://api.github.com/users/jsmith/gists{/gist_id}","starred_url":"https://api.github.com/users/jsmith/starred{/owner}{/repo}","subscriptions_url":"https://api.github.com/users/jsmith/subscriptions","organizations_url":"https://api.github.com/users/jsmith/orgs","repos_url":"https://api.github.com/users/jsmith/repos","events_url":"https://api.github.com/users/jsmith/events{/privacy}","received_events_url":"https://api.github.com/users/jsmith/received_events","type":"User","site_admin":false},"run_attempt":1,"run_started_at":"2022-04-04T08:43:15Z","triggering_actor":{"login":"jsmith","id":8362376,"node_id":"MDQ6VXNlcjgzNjIzNzY=","avatar_url":"https://avatars.githubusercontent.com/u/8362376?v=4","gravatar_id":"","url":"https://api.github.com/users/jsmith","html_url":"https://github.com/jsmith","followers_url":"https://api.github.com/users/jsmith/followers","following_url":"https://api.github.com/users/jsmith/following{/other_user}","gists_url":"https://api.github.com/users/jsmith/gists{/gist_id}","starred_url":"https://api.github.com/users/jsmith/starred{/owner}{/repo}","subscriptions_url":"https://api.github.com/users/jsmith/subscriptions","organizations_url":"https://api.github.com/users/jsmith/orgs","repos_url":"https://api.github.com/users/jsmith/repos","events_url":"https://api.github.com/users/jsmith/events{/privacy}","received_events_url":"https://api.github.com/users/jsmith/received_events","type":"User","site_admin":false},"jobs_url":"https://api.github.com/repos/splunk/security_content/actions/runs/2088708615/jobs","logs_url":"https://api.github.com/repos/splunk/security_content/actions/runs/2088708615/logs","check_suite_url":"https://api.github.com/repos/splunk/security_content/check-suites/5918781611","artifacts_url":"https://api.github.com/repos/splunk/security_content/actions/runs/2088708615/artifacts","cancel_url":"https://api.github.com/repos/splunk/security_content/actions/runs/2088708615/cancel","rerun_url":"https://api.github.com/repos/splunk/security_content/actions/runs/2088708615/rerun","previous_attempt_url":null,"workflow_url":"https://api.github.com/repos/splunk/security_content/actions/workflows/4692335","head_commit":{"id":"4049334910ea3d52a917ca35aed66d11c80ed966","tree_id":"df4ddc1359be3b19f093b7a27dbf5708187743a0","message":"small
|
||||
change","timestamp":"2022-04-04T08:43:01Z","author":{"name":"jsmith","email":"jsmith@evilcorp.com"},"committer":{"name":"jsmith","email":"jsmith@evilcorp.com"}},"repository":{"id":162346001,"node_id":"MDEwOlJlcG9zaXRvcnkxNjIzNDYwMDE=","name":"security_content","full_name":"splunk/security_content","private":false,"owner":{"login":"splunk","id":651467,"node_id":"MDEyOk9yZ2FuaXphdGlvbjY1MTQ2Nw==","avatar_url":"https://avatars.githubusercontent.com/u/651467?v=4","gravatar_id":"","url":"https://api.github.com/users/splunk","html_url":"https://github.com/splunk","followers_url":"https://api.github.com/users/splunk/followers","following_url":"https://api.github.com/users/splunk/following{/other_user}","gists_url":"https://api.github.com/users/splunk/gists{/gist_id}","starred_url":"https://api.github.com/users/splunk/starred{/owner}{/repo}","subscriptions_url":"https://api.github.com/users/splunk/subscriptions","organizations_url":"https://api.github.com/users/splunk/orgs","repos_url":"https://api.github.com/users/splunk/repos","events_url":"https://api.github.com/users/splunk/events{/privacy}","received_events_url":"https://api.github.com/users/splunk/received_events","type":"Organization","site_admin":false},"html_url":"https://github.com/splunk/security_content","description":"Splunk
|
||||
Security Content","fork":false,"url":"https://api.github.com/repos/splunk/security_content","forks_url":"https://api.github.com/repos/splunk/security_content/forks","keys_url":"https://api.github.com/repos/splunk/security_content/keys{/key_id}","collaborators_url":"https://api.github.com/repos/splunk/security_content/collaborators{/collaborator}","teams_url":"https://api.github.com/repos/splunk/security_content/teams","hooks_url":"https://api.github.com/repos/splunk/security_content/hooks","issue_events_url":"https://api.github.com/repos/splunk/security_content/issues/events{/number}","events_url":"https://api.github.com/repos/splunk/security_content/events","assignees_url":"https://api.github.com/repos/splunk/security_content/assignees{/user}","branches_url":"https://api.github.com/repos/splunk/security_content/branches{/branch}","tags_url":"https://api.github.com/repos/splunk/security_content/tags","blobs_url":"https://api.github.com/repos/splunk/security_content/git/blobs{/sha}","git_tags_url":"https://api.github.com/repos/splunk/security_content/git/tags{/sha}","git_refs_url":"https://api.github.com/repos/splunk/security_content/git/refs{/sha}","trees_url":"https://api.github.com/repos/splunk/security_content/git/trees{/sha}","statuses_url":"https://api.github.com/repos/splunk/security_content/statuses/{sha}","languages_url":"https://api.github.com/repos/splunk/security_content/languages","stargazers_url":"https://api.github.com/repos/splunk/security_content/stargazers","contributors_url":"https://api.github.com/repos/splunk/security_content/contributors","subscribers_url":"https://api.github.com/repos/splunk/security_content/subscribers","subscription_url":"https://api.github.com/repos/splunk/security_content/subscription","commits_url":"https://api.github.com/repos/splunk/security_content/commits{/sha}","git_commits_url":"https://api.github.com/repos/splunk/security_content/git/commits{/sha}","comments_url":"https://api.github.com/repos/splunk/security_content/comments{/number}","issue_comment_url":"https://api.github.com/repos/splunk/security_content/issues/comments{/number}","contents_url":"https://api.github.com/repos/splunk/security_content/contents/{+path}","compare_url":"https://api.github.com/repos/splunk/security_content/compare/{base}...{head}","merges_url":"https://api.github.com/repos/splunk/security_content/merges","archive_url":"https://api.github.com/repos/splunk/security_content/{archive_format}{/ref}","downloads_url":"https://api.github.com/repos/splunk/security_content/downloads","issues_url":"https://api.github.com/repos/splunk/security_content/issues{/number}","pulls_url":"https://api.github.com/repos/splunk/security_content/pulls{/number}","milestones_url":"https://api.github.com/repos/splunk/security_content/milestones{/number}","notifications_url":"https://api.github.com/repos/splunk/security_content/notifications{?since,all,participating}","labels_url":"https://api.github.com/repos/splunk/security_content/labels{/name}","releases_url":"https://api.github.com/repos/splunk/security_content/releases{/id}","deployments_url":"https://api.github.com/repos/splunk/security_content/deployments"},"head_repository":{"id":162346001,"node_id":"MDEwOlJlcG9zaXRvcnkxNjIzNDYwMDE=","name":"security_content","full_name":"splunk/security_content","private":false,"owner":{"login":"splunk","id":651467,"node_id":"MDEyOk9yZ2FuaXphdGlvbjY1MTQ2Nw==","avatar_url":"https://avatars.githubusercontent.com/u/651467?v=4","gravatar_id":"","url":"https://api.github.com/users/splunk","html_url":"https://github.com/splunk","followers_url":"https://api.github.com/users/splunk/followers","following_url":"https://api.github.com/users/splunk/following{/other_user}","gists_url":"https://api.github.com/users/splunk/gists{/gist_id}","starred_url":"https://api.github.com/users/splunk/starred{/owner}{/repo}","subscriptions_url":"https://api.github.com/users/splunk/subscriptions","organizations_url":"https://api.github.com/users/splunk/orgs","repos_url":"https://api.github.com/users/splunk/repos","events_url":"https://api.github.com/users/splunk/events{/privacy}","received_events_url":"https://api.github.com/users/splunk/received_events","type":"Organization","site_admin":false},"html_url":"https://github.com/splunk/security_content","description":"Splunk
|
||||
Security Content","fork":false,"url":"https://api.github.com/repos/splunk/security_content","forks_url":"https://api.github.com/repos/splunk/security_content/forks","keys_url":"https://api.github.com/repos/splunk/security_content/keys{/key_id}","collaborators_url":"https://api.github.com/repos/splunk/security_content/collaborators{/collaborator}","teams_url":"https://api.github.com/repos/splunk/security_content/teams","hooks_url":"https://api.github.com/repos/splunk/security_content/hooks","issue_events_url":"https://api.github.com/repos/splunk/security_content/issues/events{/num'
|
||||
@@ -1,17 +0,0 @@
|
||||
name: Google Workspace
|
||||
id: 9ef3a321-c641-4798-8a92-9c10c714a004
|
||||
author: Patrick Bareiss, Splunk
|
||||
source: gws:reports:admin
|
||||
sourcetype: gws:reports:admin
|
||||
separator: event.name
|
||||
supported_TA:
|
||||
name: Splunk Add-on for Google Workspace
|
||||
version: 2.6.3
|
||||
url: https://splunkbase.splunk.com/app/5556
|
||||
event_names:
|
||||
- event_name: Google Workspace
|
||||
data_source: data_sources/cloud/event_sources/Google_Workspace.yml
|
||||
- event_name: Google Workspace login_failure
|
||||
data_source: data_sources/cloud/event_sources/Google_Workspace_login_failure.yml
|
||||
- event_name: Google Workspace login_success
|
||||
data_source: data_sources/cloud/event_sources/Google_Workspace_login_success.yml
|
||||
@@ -1,61 +0,0 @@
|
||||
name: Kubernetes Audit
|
||||
id: 6c25181a-0c07-4aaf-90e6-77ab1f0e6699
|
||||
author: Patrick Bareiss, Splunk
|
||||
source: kubernetes
|
||||
sourcetype: _json
|
||||
supported_TA: {}
|
||||
event_names: []
|
||||
fields:
|
||||
- _time
|
||||
- annotations.authorization.k8s.io/decision
|
||||
- annotations.authorization.k8s.io/reason
|
||||
- apiVersion
|
||||
- auditID
|
||||
- eventtype
|
||||
- host
|
||||
- index
|
||||
- kind
|
||||
- level
|
||||
- linecount
|
||||
- objectRef.apiGroup
|
||||
- objectRef.apiVersion
|
||||
- objectRef.namespace
|
||||
- objectRef.resource
|
||||
- punct
|
||||
- requestReceivedTimestamp
|
||||
- requestURI
|
||||
- responseObject.apiVersion
|
||||
- responseObject.code
|
||||
- responseObject.details.group
|
||||
- responseObject.details.kind
|
||||
- responseObject.kind
|
||||
- responseObject.message
|
||||
- responseObject.reason
|
||||
- responseObject.status
|
||||
- responseStatus.code
|
||||
- responseStatus.details.group
|
||||
- responseStatus.details.kind
|
||||
- responseStatus.message
|
||||
- responseStatus.reason
|
||||
- responseStatus.status
|
||||
- source
|
||||
- sourceIPs{}
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- stage
|
||||
- stageTimestamp
|
||||
- tag
|
||||
- tag::eventtype
|
||||
- timestamp
|
||||
- user.groups{}
|
||||
- user.uid
|
||||
- user.username
|
||||
- userAgent
|
||||
- verb
|
||||
example_log:
|
||||
'{"kind":"Event","apiVersion":"audit.k8s.io/v1","level":"RequestResponse","auditID":"582c31ab-4906-49bb-9ff9-872f980ccb84","stage":"ResponseComplete","requestURI":"/apis/batch/v1/namespaces/test2/jobs?fieldManager=kubectl-create\u0026fieldValidation=Strict","verb":"create","user":{"username":"k8s-test-user","uid":"aws-iam-authenticator:591511147606:AROAYTOGP2RLFHNBOTP5J","groups":["system:authenticated"]},"sourceIPs":["176.95.188.101"],"userAgent":"kubectl/v1.27.2
|
||||
(darwin/arm64) kubernetes/7f6f68f","objectRef":{"resource":"jobs","namespace":"test2","apiGroup":"batch","apiVersion":"v1"},"responseStatus":{"metadata":{},"status":"Failure","message":"jobs.batch
|
||||
is forbidden: User \"k8s-test-user\" cannot create resource \"jobs\" in API group
|
||||
\"batch\" in the namespace \"test2\"","reason":"Forbidden","details":{"group":"batch","kind":"jobs"},"code":403},"responseObject":{"kind":"Status","apiVersion":"v1","metadata":{},"status":"Failure","message":"jobs.batch
|
||||
is forbidden: User \"k8s-test-user\" cannot create resource \"jobs\" in API group
|
||||
\"batch\" in the namespace \"test2\"","reason":"Forbidden","details":{"group":"batch","kind":"jobs"},"code":403},"requestReceivedTimestamp":"2023-12-07T14:44:53.358394Z","stageTimestamp":"2023-12-07T14:44:53.375985Z","annotations":{"authorization.k8s.io/decision":"forbid","authorization.k8s.io/reason":""}}'
|
||||
@@ -1,48 +0,0 @@
|
||||
name: Kubernetes Falco
|
||||
id: 23c0eeed-840a-4711-a41b-6819c1ffbba5
|
||||
author: Patrick Bareiss, Splunk
|
||||
source: kubernetes
|
||||
sourcetype: kube:container:falco
|
||||
supported_TA: {}
|
||||
event_names: []
|
||||
fields:
|
||||
- _time
|
||||
- command
|
||||
- container_id
|
||||
- container_image
|
||||
- container_image_tag
|
||||
- container_name
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- evt_type
|
||||
- exe_flags
|
||||
- host
|
||||
- index
|
||||
- k8s_ns
|
||||
- k8s_pod_name
|
||||
- linecount
|
||||
- parent
|
||||
- proc_exepath
|
||||
- process
|
||||
- punct
|
||||
- source
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- terminal
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
- user
|
||||
- user_loginuid
|
||||
- user_uid
|
||||
example_log:
|
||||
"12:18:18.691725165: Notice A shell was spawned in a container with an
|
||||
attached terminal (evt_type=execve user=root user_uid=0 user_loginuid=-1 process=bash
|
||||
proc_exepath=/usr/lib/splunk-otel-collector/agent-bundle/bin/bash parent=runc command=bash
|
||||
-il terminal=34816 exe_flags=EXE_WRITABLE container_id=7a2566e8e462 container_image=quay.io/signalfx/splunk-otel-collector
|
||||
container_image_tag=0.88.0 container_name=otel-collector k8s_ns=default k8s_pod_name=my-splunk-otel-collector-agent-9sdhr)"
|
||||
@@ -1,123 +0,0 @@
|
||||
name: O365
|
||||
id: 11c0eed5-3f3f-42e4-bf72-30f11295a686
|
||||
author: Patrick Bareiss, Splunk
|
||||
source: o365
|
||||
sourcetype: o365:management:activity
|
||||
separator: Operation
|
||||
supported_TA:
|
||||
name: Splunk Add-on for Microsoft Office 365
|
||||
version: 4.5.1
|
||||
url: https://splunkbase.splunk.com/app/4055
|
||||
event_names:
|
||||
- event_name: O365
|
||||
data_source: data_sources/cloud/event_sources/O365.yml
|
||||
- event_name: O365 Add app role assignment grant to user.
|
||||
data_source: data_sources/cloud/event_sources/O365_Add_app_role_assignment_grant_to_user..yml
|
||||
- event_name: O365 Add app role assignment to service principal.
|
||||
data_source: data_sources/cloud/event_sources/O365_Add_app_role_assignment_to_service_principal..yml
|
||||
- event_name: O365 Add member to role.
|
||||
data_source: data_sources/cloud/event_sources/O365_Add_member_to_role..yml
|
||||
- event_name: O365 Add owner to application.
|
||||
data_source: data_sources/cloud/event_sources/O365_Add_owner_to_application..yml
|
||||
- event_name: O365 Add service principal.
|
||||
data_source: data_sources/cloud/event_sources/O365_Add_service_principal..yml
|
||||
- event_name: O365 Add-MailboxPermission
|
||||
data_source: data_sources/cloud/event_sources/O365_Add-MailboxPermission.yml
|
||||
- event_name: O365 Change user license.
|
||||
data_source: data_sources/cloud/event_sources/O365_Change_user_license..yml
|
||||
- event_name: O365 Consent to application.
|
||||
data_source: data_sources/cloud/event_sources/O365_Consent_to_application..yml
|
||||
- event_name: O365 Disable Strong Authentication.
|
||||
data_source: data_sources/cloud/event_sources/O365_Disable_Strong_Authentication..yml
|
||||
- event_name: O365 MailItemsAccessed
|
||||
data_source: data_sources/cloud/event_sources/O365_MailItemsAccessed.yml
|
||||
- event_name: O365 ModifyFolderPermissions
|
||||
data_source: data_sources/cloud/event_sources/O365_ModifyFolderPermissions.yml
|
||||
- event_name: O365 Set Company Information.
|
||||
data_source: data_sources/cloud/event_sources/O365_Set_Company_Information..yml
|
||||
- event_name: O365 Set-Mailbox
|
||||
data_source: data_sources/cloud/event_sources/O365_Set-Mailbox.yml
|
||||
- event_name: O365 Update application.
|
||||
data_source: data_sources/cloud/event_sources/O365_Update_application..yml
|
||||
- event_name: O365 Update authorization policy.
|
||||
data_source: data_sources/cloud/event_sources/O365_Update_authorization_policy..yml
|
||||
- event_name: O365 Update user.
|
||||
data_source: data_sources/cloud/event_sources/O365_Update_user..yml
|
||||
- event_name: O365 UserLoggedIn
|
||||
data_source: data_sources/cloud/event_sources/O365_UserLoggedIn.yml
|
||||
- event_name: O365 UserLoginFailed
|
||||
data_source: data_sources/cloud/event_sources/O365_UserLoginFailed.yml
|
||||
fields:
|
||||
- _time
|
||||
- AppAccessContext.IssuedAtTime
|
||||
- AppAccessContext.UniqueTokenId
|
||||
- AppId
|
||||
- ClientAppId
|
||||
- ClientIP
|
||||
- CreationTime
|
||||
- ExternalAccess
|
||||
- Id
|
||||
- Name
|
||||
- ObjectId
|
||||
- Operation
|
||||
- OrganizationId
|
||||
- OrganizationName
|
||||
- OriginatingServer
|
||||
- Parameters{}.Name
|
||||
- Parameters{}.Value
|
||||
- RecordType
|
||||
- RequestId
|
||||
- ResultStatus
|
||||
- Role
|
||||
- SessionId
|
||||
- User
|
||||
- UserId
|
||||
- UserKey
|
||||
- UserType
|
||||
- Version
|
||||
- Workload
|
||||
- app
|
||||
- authentication_service
|
||||
- command
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- dest
|
||||
- dest_name
|
||||
- dvc
|
||||
- host
|
||||
- index
|
||||
- linecount
|
||||
- object
|
||||
- punct
|
||||
- record_type
|
||||
- signature
|
||||
- source
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- src
|
||||
- src_ip
|
||||
- status
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
- user
|
||||
- user_id
|
||||
- user_type
|
||||
- vendor_account
|
||||
- vendor_product
|
||||
example_log: '{"AppAccessContext": {"IssuedAtTime": "2023-10-17T19:13:05", "UniqueTokenId":
|
||||
"g7oAmNhLoU-8qJVeWeAwAA"}, "CreationTime": "2023-10-17T19:19:59", "Id": "3d26a8cd-d8f4-42f9-1898-08dbcf460e5a",
|
||||
"Operation": "New-ManagementRoleAssignment", "OrganizationId": "aeb12f6b-1ff3-4a18-9ea2-29aa57e2ae08",
|
||||
"RecordType": 1, "ResultStatus": "True", "UserKey": "1003BFFD98415B4E", "UserType":
|
||||
2, "Version": 1, "Workload": "Exchange", "ClientIP": "71.1.1.1:61528", "ObjectId":
|
||||
"splunkresearch.onmicrosoft.com\\attack-test", "UserId": "compromisedAdmin@splunkresearch.onmicrosoft.com",
|
||||
"AppId": "fb78d390-0c51-40cd-8e17-fdbfab77341b", "ClientAppId": "", "ExternalAccess":
|
||||
false, "OrganizationName": "splunkresearch.onmicrosoft.com", "OriginatingServer":
|
||||
"BYAPR18MB2408 (15.20.6863.047)", "Parameters": [{"Name": "User", "Value": "lowpriv@splunkresearch.onmicrosoft.com"},
|
||||
{"Name": "Name", "Value": "attack-test"}, {"Name": "Role", "Value": "ApplicationImpersonation"}],
|
||||
"RequestId": "53a50583-e429-63a4-c9f7-8fbb14437e8a", "SessionId": "e2a028f1-d0e1-4ddb-a5a7-ec57343457ad"}'
|
||||
@@ -1,92 +0,0 @@
|
||||
event_name: AWS CloudTrail AssumeRoleWithSAML
|
||||
fields:
|
||||
- _time
|
||||
- action
|
||||
- app
|
||||
- awsRegion
|
||||
- change_type
|
||||
- command
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- dest
|
||||
- dvc
|
||||
- errorCode
|
||||
- eventCategory
|
||||
- eventID
|
||||
- eventName
|
||||
- eventSource
|
||||
- eventTime
|
||||
- eventType
|
||||
- eventVersion
|
||||
- eventtype
|
||||
- host
|
||||
- index
|
||||
- linecount
|
||||
- managementEvent
|
||||
- msg
|
||||
- object_category
|
||||
- product
|
||||
- punct
|
||||
- readOnly
|
||||
- recipientAccountId
|
||||
- region
|
||||
- requestID
|
||||
- requestParameters.durationSeconds
|
||||
- requestParameters.principalArn
|
||||
- requestParameters.roleArn
|
||||
- requestParameters.roleSessionName
|
||||
- requestParameters.sAMLAssertionID
|
||||
- resources{}.ARN
|
||||
- resources{}.accountId
|
||||
- resources{}.type
|
||||
- responseElements.assumedRoleUser.arn
|
||||
- responseElements.assumedRoleUser.assumedRoleId
|
||||
- responseElements.audience
|
||||
- responseElements.credentials.accessKeyId
|
||||
- responseElements.credentials.expiration
|
||||
- responseElements.credentials.sessionToken
|
||||
- responseElements.issuer
|
||||
- responseElements.nameQualifier
|
||||
- responseElements.subject
|
||||
- responseElements.subjectType
|
||||
- signature
|
||||
- source
|
||||
- sourceIPAddress
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- src
|
||||
- src_ip
|
||||
- src_user
|
||||
- src_user_id
|
||||
- src_user_type
|
||||
- start_time
|
||||
- status
|
||||
- tag
|
||||
- tag::action
|
||||
- tag::eventtype
|
||||
- temp_access_key
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
- user
|
||||
- userAgent
|
||||
- userIdentity.identityProvider
|
||||
- userIdentity.principalId
|
||||
- userIdentity.type
|
||||
- userIdentity.userName
|
||||
- user_agent
|
||||
- user_arn
|
||||
- user_id
|
||||
- user_name
|
||||
- user_role
|
||||
- user_type
|
||||
- vendor
|
||||
- vendor_account
|
||||
- vendor_product
|
||||
- vendor_region
|
||||
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "SAMLUser", "principalId": "ZRu9MRAjiG9tvi1QBNfdI664G5A=:rodsoto@rodsoto.onmicrosoft.com", "userName": "rodsoto@rodsoto.onmicrosoft.com", "identityProvider": "ZRu9MRAjiG9tvi1QBNfdI664G5A="}, "eventTime": "2021-01-22T03:44:16Z", "eventSource": "sts.amazonaws.com", "eventName": "AssumeRoleWithSAML", "awsRegion": "us-east-1", "sourceIPAddress": "72.21.217.152", "userAgent": "AWS Signin, aws-internal/3 aws-sdk-java/1.11.898 Linux/4.9.230-0.1.ac.223.84.332.metal1.x86_64 OpenJDK_64-Bit_Server_VM/25.275-b01 java/1.8.0_275 kotlin/1.3.72 vendor/Oracle_Corporation", "requestParameters": {"sAMLAssertionID": "_d33ba0ad-0c88-4b83-80a6-27c08027d000", "roleSessionName": "rodsoto@rodsoto.onmicrosoft.com", "durationSeconds": 3600, "roleArn": "arn:aws:iam::111111111111:role/rodonmicrotestrole", "principalArn": "arn:aws:iam::111111111111:saml-provider/rodsotoonmicrosoft"}, "responseElements": {"subjectType": "urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress", "issuer": "https://sts.windows.net/0e8108b1-18e9-41a4-961b-dfcddf92ef08/", "credentials": {"accessKeyId": "ASIAYTOGP2RLKJXOV7VR", "expiration": "Jan 22, 2021 3:59:16 AM", "sessionToken": "IQoJb3JpZ2luX2VjENz//////////wEaCXVzLWVhc3QtMSJGMEQCIHl/WQdLq53ULYl10fPtpeV3H7da9mOXGuIStvhdDA6kAiAdO/7rocOXAtyDV+0MJhSj/piqlqEI/BcAKm8zqBhOgiqgAwi1//////////8BEAIaDDU5MTUxMTE0NzYwNiIMAFP8GfyI/x1fKCHYKvQCznxxgKnEdcuvrr/fBLmHxEDjQ9vQxjasA8gZF8GawZ5SFH9ViKqoZh93bYkOwKqZD8cdqJIo9SYL17RGhVqxzvsjU4+QsRXTN5eGgh+LyF9EZqeCl6oCkaTJqNrXHuenzTi0yiL510LKsSckrAm8+SuwI/jQu3oE1BEcJQieAc4RjYx3II+1cUvyfRlFvR2NDfZhdWcQvAivV06KJg9c2zfCF0Agzn/YZSNvsRL5UhnKhJ2wktSvT8lR0mS3n9xR1j3iYNxVDHab180cnfkP3G6tAmxj5U29diNQrusJxKWWhr/Q9wHRdDj5dO2QUZzSymKKU/UiRJ8nyYPINaJ8XWVAPiT4QgzpMxotkvSkDLEG/brB9yEr2p7W8Y3xMGZ37qSGkuU4z9x40RU9G1XPhv27NO9aaGs/VXYTMCzWRNxnsLfNkk/DihrcaR0SclRcvs+zmfe1ZUoGnfjNYm+AIyJi4D7OrXF5/Mt46Z2y76DnULlAMJCUqYAGOpsBw4fyafV8OizX7Lebh2JRXFZsWBY1GTpyGvO5otrw++4axud44vYVi5iU5rbJxtTBm4vtJartxgXoPJFnQuat9gLrIlXhjmg+m50a5xs1Ut2UWEsWY2Duu4jA9ap7P7dYv9kIK9P2uyhsjKQhCjTpfe4I/llcupbDotYBJuvlB5n85a5kgiSriFk5zetoXQIweuYEWQZsD/AN+LE="}, "nameQualifier": "ZRu9MRAjiG9tvi1QBNfdI664G5A=", "assumedRoleUser": {"assumedRoleId": "AROAYTOGP2RLKFUVAQAIJ:rodsoto@rodsoto.onmicrosoft.com", "arn": "arn:aws:sts::111111111111:assumed-role/rodonmicrotestrole/rodsoto@rodsoto.onmicrosoft.com"}, "subject": "rodsoto@rodsoto.onmicrosoft.com", "audience": "https://signin.aws.amazon.com/saml"}, "requestID": "e19c7a7f-cd96-4642-9ee6-2360a7b01b12", "eventID": "b25b825d-9c9b-49d3-9ecd-290dbe8f2c29", "readOnly": true, "resources": [{"accountId": "111111111111", "type": "AWS::IAM::Role", "ARN": "arn:aws:iam::111111111111:role/rodonmicrotestrole"}, {"accountId": "111111111111", "type": "AWS::IAM::SAMLProvider", "ARN": "arn:aws:iam::111111111111:saml-provider/rodsotoonmicrosoft"}], "eventType": "AwsApiCall", "managementEvent": true, "eventCategory": "Management", "recipientAccountId": "111111111111"}'
|
||||
@@ -1,80 +0,0 @@
|
||||
event_name: AWS CloudTrail ConsoleLogin
|
||||
fields:
|
||||
- _time
|
||||
- action
|
||||
- additionalEventData.LoginTo
|
||||
- additionalEventData.MFAUsed
|
||||
- additionalEventData.MobileVersion
|
||||
- app
|
||||
- authentication_method
|
||||
- awsRegion
|
||||
- aws_account_id
|
||||
- command
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- desc
|
||||
- dest
|
||||
- dvc
|
||||
- errorCode
|
||||
- errorMessage
|
||||
- eventCategory
|
||||
- eventID
|
||||
- eventName
|
||||
- eventSource
|
||||
- eventTime
|
||||
- eventType
|
||||
- eventVersion
|
||||
- eventtype
|
||||
- host
|
||||
- index
|
||||
- linecount
|
||||
- managementEvent
|
||||
- msg
|
||||
- object_category
|
||||
- product
|
||||
- punct
|
||||
- readOnly
|
||||
- reason
|
||||
- recipientAccountId
|
||||
- region
|
||||
- requestParameters
|
||||
- responseElements.ConsoleLogin
|
||||
- result
|
||||
- signature
|
||||
- source
|
||||
- sourceIPAddress
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- src
|
||||
- src_ip
|
||||
- start_time
|
||||
- status
|
||||
- tag
|
||||
- tag::action
|
||||
- tag::eventtype
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
- tlsDetails.cipherSuite
|
||||
- tlsDetails.clientProvidedHostHeader
|
||||
- tlsDetails.tlsVersion
|
||||
- userAgent
|
||||
- userIdentity.accessKeyId
|
||||
- userIdentity.accountId
|
||||
- userIdentity.type
|
||||
- userIdentity.userName
|
||||
- user_access_key
|
||||
- user_agent
|
||||
- user_group_id
|
||||
- user_name
|
||||
- user_type
|
||||
- vendor
|
||||
- vendor_account
|
||||
- vendor_product
|
||||
- vendor_region
|
||||
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "accountId": "140429656527", "accessKeyId": "", "userName": "HIDDEN_DUE_TO_SECURITY_REASONS"}, "eventTime": "2022-10-19T20:33:38Z", "eventSource": "signin.amazonaws.com", "eventName": "ConsoleLogin", "awsRegion": "us-east-1", "sourceIPAddress": "142.254.89.27", "userAgent": "Go-http-client/1.1", "errorMessage": "No username found in supplied account", "requestParameters": null, "responseElements": {"ConsoleLogin": "Failure"}, "additionalEventData": {"LoginTo": "https://console.aws.amazon.com", "MobileVersion": "No", "MFAUsed": "No"}, "eventID": "9fcfb8c3-3fca-48db-85d2-7b107f9d95d0", "readOnly": false, "eventType": "AwsConsoleSignIn", "managementEvent": true, "recipientAccountId": "140429656527", "eventCategory": "Management", "tlsDetails": {"tlsVersion": "TLSv1.2", "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256", "clientProvidedHostHeader": "signin.aws.amazon.com"}}'
|
||||
@@ -1,86 +0,0 @@
|
||||
event_name: AWS CloudTrail CopyObject
|
||||
fields:
|
||||
- _time
|
||||
- additionalEventData.AuthenticationMethod
|
||||
- additionalEventData.CipherSuite
|
||||
- additionalEventData.SSEApplied
|
||||
- additionalEventData.SignatureVersion
|
||||
- additionalEventData.bytesTransferredIn
|
||||
- additionalEventData.bytesTransferredOut
|
||||
- additionalEventData.x-amz-id-2
|
||||
- app
|
||||
- awsRegion
|
||||
- aws_account_id
|
||||
- command
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- dest
|
||||
- dvc
|
||||
- errorCode
|
||||
- eventCategory
|
||||
- eventID
|
||||
- eventName
|
||||
- eventSource
|
||||
- eventTime
|
||||
- eventType
|
||||
- eventVersion
|
||||
- host
|
||||
- index
|
||||
- linecount
|
||||
- managementEvent
|
||||
- msg
|
||||
- object_category
|
||||
- product
|
||||
- punct
|
||||
- readOnly
|
||||
- recipientAccountId
|
||||
- region
|
||||
- requestID
|
||||
- requestParameters.Host
|
||||
- requestParameters.bucketName
|
||||
- requestParameters.key
|
||||
- requestParameters.x-amz-copy-source
|
||||
- requestParameters.x-amz-server-side-encryption
|
||||
- requestParameters.x-amz-server-side-encryption-aws-kms-key-id
|
||||
- resources{}.ARN
|
||||
- resources{}.accountId
|
||||
- resources{}.type
|
||||
- responseElements.x-amz-server-side-encryption
|
||||
- responseElements.x-amz-server-side-encryption-aws-kms-key-id
|
||||
- signature
|
||||
- source
|
||||
- sourceIPAddress
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- src
|
||||
- src_ip
|
||||
- start_time
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
- user
|
||||
- userAgent
|
||||
- userIdentity.accessKeyId
|
||||
- userIdentity.accountId
|
||||
- userIdentity.arn
|
||||
- userIdentity.principalId
|
||||
- userIdentity.type
|
||||
- userIdentity.userName
|
||||
- userName
|
||||
- user_access_key
|
||||
- user_agent
|
||||
- user_arn
|
||||
- user_group_id
|
||||
- user_id
|
||||
- user_name
|
||||
- user_type
|
||||
- vendor
|
||||
- vendor_account
|
||||
- vendor_product
|
||||
- vendor_region
|
||||
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId": "AIDAYTOGP2RLNALZHZ6KX", "arn": "arn:aws:iam::111111111111:user/patrick_cli", "accountId": "111111111111", "accessKeyId": "AKIAYTOGP2RLJ2OYSF6E", "userName": "patrick_cli"}, "eventTime": "2021-01-11T12:40:47Z", "eventSource": "s3.amazonaws.com", "eventName": "CopyObject", "awsRegion": "us-west-2", "sourceIPAddress": "95.90.199.65", "userAgent": "[aws-cli/2.0.45 Python/3.7.4 Darwin/20.2.0 exe/x86_64 command/s3.cp]", "requestParameters": {"bucketName": "patricktestbucketencrypt", "x-amz-server-side-encryption-aws-kms-key-id": "arn:aws:kms:us-west-2:111111111111:key/f2a82583-a7d3-4c92-8787-fe2baab1cee1", "Host": "patricktestbucketencrypt.s3.us-west-2.amazonaws.com", "x-amz-server-side-encryption": "aws:kms", "x-amz-copy-source": "patricktestbucketencrypt/kms_aws_events.json", "key": "kms_aws_events_encrypted.json"}, "responseElements": {"x-amz-server-side-encryption": "aws:kms", "x-amz-server-side-encryption-aws-kms-key-id": "arn:aws:kms:us-west-2:111111111111:key/f2a82583-a7d3-4c92-8787-fe2baab1cee1"}, "additionalEventData": {"SignatureVersion": "SigV4", "CipherSuite": "ECDHE-RSA-AES128-GCM-SHA256", "bytesTransferredIn": 0.0, "SSEApplied": "SSE_KMS", "AuthenticationMethod": "AuthHeader", "x-amz-id-2": "fqzX1iZV6ImDtkFxbGvziOE6fUwryRa+PhnLckfVAkLNHdbCAHNq4l/yckUd1a2HNJPL6NAS01U=", "bytesTransferredOut": 234.0}, "requestID": "6A7359F7A9414B02", "eventID": "b20d43de-175d-4443-acd7-f5f3e587ae00", "readOnly": false, "resources": [{"type": "AWS::S3::Object", "ARN": "arn:aws:s3:::patricktestbucketencrypt/kms_aws_events_encrypted.json"}, {"accountId": "111111111111", "type": "AWS::S3::Bucket", "ARN": "arn:aws:s3:::patricktestbucketencrypt"}, {"accountId": "111111111111", "type": "AWS::S3::Bucket", "ARN": "arn:aws:s3:::patricktestbucketencrypt"}, {"type": "AWS::S3::Object", "ARN": "arn:aws:s3:::patricktestbucketencrypt/kms_aws_events.json"}], "eventType": "AwsApiCall", "managementEvent": false, "recipientAccountId": "111111111111", "eventCategory": "Data"}'
|
||||
@@ -1,80 +0,0 @@
|
||||
event_name: AWS CloudTrail CreateAccessKey
|
||||
fields:
|
||||
- _time
|
||||
- action
|
||||
- app
|
||||
- awsRegion
|
||||
- aws_account_id
|
||||
- change_type
|
||||
- command
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- dest
|
||||
- dvc
|
||||
- errorCode
|
||||
- eventCategory
|
||||
- eventID
|
||||
- eventName
|
||||
- eventSource
|
||||
- eventTime
|
||||
- eventType
|
||||
- eventVersion
|
||||
- eventtype
|
||||
- host
|
||||
- index
|
||||
- linecount
|
||||
- managementEvent
|
||||
- msg
|
||||
- object_category
|
||||
- product
|
||||
- punct
|
||||
- readOnly
|
||||
- recipientAccountId
|
||||
- region
|
||||
- requestID
|
||||
- requestParameters.userName
|
||||
- responseElements.accessKey.accessKeyId
|
||||
- responseElements.accessKey.createDate
|
||||
- responseElements.accessKey.status
|
||||
- responseElements.accessKey.userName
|
||||
- signature
|
||||
- source
|
||||
- sourceIPAddress
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- src
|
||||
- src_ip
|
||||
- src_user_name
|
||||
- start_time
|
||||
- status
|
||||
- tag
|
||||
- tag::eventtype
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
- user
|
||||
- userAgent
|
||||
- userIdentity.accessKeyId
|
||||
- userIdentity.accountId
|
||||
- userIdentity.arn
|
||||
- userIdentity.principalId
|
||||
- userIdentity.type
|
||||
- userIdentity.userName
|
||||
- userName
|
||||
- user_access_key
|
||||
- user_agent
|
||||
- user_arn
|
||||
- user_group_id
|
||||
- user_id
|
||||
- user_name
|
||||
- user_type
|
||||
- vendor
|
||||
- vendor_account
|
||||
- vendor_product
|
||||
- vendor_region
|
||||
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId": "AIDAYTOGP2RLEHRX5YWNV", "arn": "arn:aws:iam::121521347698:user/bhavin_cli", "accountId": "121521347698", "accessKeyId": "AKIAYTOGP2RLLAA6NJUM", "userName": "bhavin_cli"}, "eventTime": "2021-03-02T21:18:24Z", "eventSource": "iam.amazonaws.com", "eventName": "CreateAccessKey", "awsRegion": "us-east-1", "sourceIPAddress": "12.25.72.12", "userAgent": "aws-cli/2.0.62 Python/3.9.0 Darwin/19.6.0 source/x86_64 command/iam.create-access-key", "requestParameters": {"userName": "AtomicRedTeam"}, "responseElements": {"accessKey": {"userName": "AtomicRedTeam", "accessKeyId": "AKIAYTOGP2RLOQ4ULYGT", "status": "Active", "createDate": "Mar 2, 2021 9:18:24 PM"}}, "requestID": "12c8773d-6c78-46bf-a8e4-f841adc8f70d", "eventID": "5772e8d5-cccc-470d-81ef-acacfe85a804", "readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "eventCategory": "Management", "recipientAccountId": "121521347698"}'
|
||||
@@ -1,98 +0,0 @@
|
||||
event_name: AWS CloudTrail CreateKey
|
||||
fields:
|
||||
- _time
|
||||
- app
|
||||
- awsRegion
|
||||
- aws_account_id
|
||||
- command
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- dest
|
||||
- dvc
|
||||
- errorCode
|
||||
- eventCategory
|
||||
- eventID
|
||||
- eventName
|
||||
- eventSource
|
||||
- eventTime
|
||||
- eventType
|
||||
- eventVersion
|
||||
- eventtype
|
||||
- host
|
||||
- index
|
||||
- linecount
|
||||
- managementEvent
|
||||
- msg
|
||||
- object_category
|
||||
- product
|
||||
- punct
|
||||
- readOnly
|
||||
- recipientAccountId
|
||||
- region
|
||||
- requestID
|
||||
- requestParameters.bypassPolicyLockoutSafetyCheck
|
||||
- requestParameters.customerMasterKeySpec
|
||||
- requestParameters.description
|
||||
- requestParameters.keyUsage
|
||||
- requestParameters.origin
|
||||
- requestParameters.policy
|
||||
- resources{}.ARN
|
||||
- resources{}.accountId
|
||||
- resources{}.type
|
||||
- responseElements.keyMetadata.aWSAccountId
|
||||
- responseElements.keyMetadata.arn
|
||||
- responseElements.keyMetadata.creationDate
|
||||
- responseElements.keyMetadata.customerMasterKeySpec
|
||||
- responseElements.keyMetadata.description
|
||||
- responseElements.keyMetadata.enabled
|
||||
- responseElements.keyMetadata.encryptionAlgorithms{}
|
||||
- responseElements.keyMetadata.keyId
|
||||
- responseElements.keyMetadata.keyManager
|
||||
- responseElements.keyMetadata.keyState
|
||||
- responseElements.keyMetadata.keyUsage
|
||||
- responseElements.keyMetadata.origin
|
||||
- signature
|
||||
- source
|
||||
- sourceIPAddress
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- src
|
||||
- src_ip
|
||||
- start_time
|
||||
- tag
|
||||
- tag::eventtype
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
- user
|
||||
- userAgent
|
||||
- userIdentity.accessKeyId
|
||||
- userIdentity.accountId
|
||||
- userIdentity.arn
|
||||
- userIdentity.principalId
|
||||
- userIdentity.sessionContext.attributes.creationDate
|
||||
- userIdentity.sessionContext.attributes.mfaAuthenticated
|
||||
- userIdentity.sessionContext.sessionIssuer.accountId
|
||||
- userIdentity.sessionContext.sessionIssuer.arn
|
||||
- userIdentity.sessionContext.sessionIssuer.principalId
|
||||
- userIdentity.sessionContext.sessionIssuer.type
|
||||
- userIdentity.sessionContext.sessionIssuer.userName
|
||||
- userIdentity.type
|
||||
- userName
|
||||
- user_access_key
|
||||
- user_agent
|
||||
- user_arn
|
||||
- user_group_id
|
||||
- user_id
|
||||
- user_name
|
||||
- user_type
|
||||
- vendor
|
||||
- vendor_account
|
||||
- vendor_product
|
||||
- vendor_region
|
||||
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "principalId": "AROAIJIESMXKGCJRCTPR6:pbareiss@splunk.local", "arn": "arn:aws:sts::111111111111:assumed-role/okta_adm_role/pbareiss@splunk.local", "accountId": "111111111111", "accessKeyId": "ASIAYTOGP2RLK74OPBDR", "sessionContext": {"sessionIssuer": {"type": "Role", "principalId": "AROAIJIESMXKGCJRCTPR6", "arn": "arn:aws:iam::111111111111:role/okta_adm_role", "accountId": "111111111111", "userName": "okta_adm_role"}, "webIdFederationData": {}, "attributes": {"mfaAuthenticated": "false", "creationDate": "2021-01-11T09:03:18Z"}}}, "eventTime": "2021-01-11T09:56:31Z", "eventSource": "kms.amazonaws.com", "eventName": "CreateKey", "awsRegion": "us-west-2", "sourceIPAddress": "95.90.199.65", "userAgent": "aws-internal/3 aws-sdk-java/1.11.893 Linux/4.9.230-0.1.ac.223.84.332.metal1.x86_64 OpenJDK_64-Bit_Server_VM/25.272-b10 java/1.8.0_272 vendor/Oracle_Corporation", "requestParameters": {"origin": "AWS_KMS", "policy": "{\n \"Id\": \"key-consolepolicy-3\",\n \"Version\": \"2012-10-17\",\n \"Statement\": [\n {\n \"Sid\": \"Enable IAM User Permissions\",\n \"Effect\": \"Allow\",\n \"Principal\": {\n \"AWS\": \"arn:aws:iam::111111111111:root\"\n },\n \"Action\": \"kms:*\",\n \"Resource\": \"*\"\n },\n {\n \"Sid\": \"Allow access for Key Administrators\",\n \"Effect\": \"Allow\",\n \"Principal\": {\n \"AWS\": \"arn:aws:iam::111111111111:user/patrick_cli\"\n },\n \"Action\": [\n \"kms:Create*\",\n \"kms:Describe*\",\n \"kms:Enable*\",\n \"kms:List*\",\n \"kms:Put*\",\n \"kms:Update*\",\n \"kms:Revoke*\",\n \"kms:Disable*\",\n \"kms:Get*\",\n \"kms:Delete*\",\n \"kms:TagResource\",\n \"kms:UntagResource\",\n \"kms:ScheduleKeyDeletion\",\n \"kms:CancelKeyDeletion\"\n ],\n \"Resource\": \"*\"\n },\n {\n \"Sid\": \"Allow use of the key\",\n \"Effect\": \"Allow\",\n \"Principal\": {\n \"AWS\": \"arn:aws:iam::111111111111:user/patrick_cli\"\n },\n \"Action\": [\n \"kms:Encrypt\",\n \"kms:Decrypt\",\n \"kms:ReEncrypt*\",\n \"kms:GenerateDataKey*\",\n \"kms:DescribeKey\"\n ],\n \"Resource\": \"*\"\n },\n {\n \"Sid\": \"Allow attachment of persistent resources\",\n \"Effect\": \"Allow\",\n \"Principal\": {\n \"AWS\": \"arn:aws:iam::111111111111:user/patrick_cli\"\n },\n \"Action\": [\n \"kms:CreateGrant\",\n \"kms:ListGrants\",\n \"kms:RevokeGrant\"\n ],\n \"Resource\": \"*\",\n \"Condition\": {\n \"Bool\": {\n \"kms:GrantIsForAWSResource\": \"true\"\n }\n }\n },\n {\n \"Sid\": \"Allow use of the key\",\n \"Effect\": \"Allow\",\n \"Principal\": {\n \"AWS\": \"*\"\n },\n \"Action\": [\n \"kms:Encrypt\"\n ],\n \"Resource\": \"*\"\n }\n ]\n}", "description": "", "customerMasterKeySpec": "SYMMETRIC_DEFAULT", "bypassPolicyLockoutSafetyCheck": false, "tags": [], "keyUsage": "ENCRYPT_DECRYPT"}, "responseElements": {"keyMetadata": {"aWSAccountId": "111111111111", "keyId": "f2a82583-a7d3-4c92-8787-fe2baab1cee1", "arn": "arn:aws:kms:us-west-2:111111111111:key/f2a82583-a7d3-4c92-8787-fe2baab1cee1", "creationDate": "Jan 11, 2021, 9:56:30 AM", "enabled": true, "description": "", "keyUsage": "ENCRYPT_DECRYPT", "keyState": "Enabled", "origin": "AWS_KMS", "keyManager": "CUSTOMER", "customerMasterKeySpec": "SYMMETRIC_DEFAULT", "encryptionAlgorithms": ["SYMMETRIC_DEFAULT"]}}, "requestID": "3356af25-a237-471f-ba5e-abb37d4a256f", "eventID": "f09518ac-5ae5-4214-80ee-4f23ccdedd4c", "readOnly": false, "resources": [{"accountId": "111111111111", "type": "AWS::KMS::Key", "ARN": "arn:aws:kms:us-west-2:111111111111:key/f2a82583-a7d3-4c92-8787-fe2baab1cee1"}], "eventType": "AwsApiCall", "managementEvent": true, "eventCategory": "Management", "recipientAccountId": "111111111111"}'
|
||||
@@ -1,79 +0,0 @@
|
||||
event_name: AWS CloudTrail CreateLoginProfile
|
||||
fields:
|
||||
- _time
|
||||
- action
|
||||
- app
|
||||
- awsRegion
|
||||
- aws_account_id
|
||||
- change_type
|
||||
- command
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- dest
|
||||
- dvc
|
||||
- errorCode
|
||||
- eventCategory
|
||||
- eventID
|
||||
- eventName
|
||||
- eventSource
|
||||
- eventTime
|
||||
- eventType
|
||||
- eventVersion
|
||||
- eventtype
|
||||
- host
|
||||
- index
|
||||
- linecount
|
||||
- managementEvent
|
||||
- msg
|
||||
- object_category
|
||||
- product
|
||||
- punct
|
||||
- readOnly
|
||||
- recipientAccountId
|
||||
- region
|
||||
- requestID
|
||||
- requestParameters.passwordResetRequired
|
||||
- requestParameters.userName
|
||||
- responseElements.loginProfile.createDate
|
||||
- responseElements.loginProfile.passwordResetRequired
|
||||
- responseElements.loginProfile.userName
|
||||
- signature
|
||||
- source
|
||||
- sourceIPAddress
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- src
|
||||
- src_ip
|
||||
- start_time
|
||||
- status
|
||||
- tag
|
||||
- tag::eventtype
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
- user
|
||||
- userAgent
|
||||
- userIdentity.accessKeyId
|
||||
- userIdentity.accountId
|
||||
- userIdentity.arn
|
||||
- userIdentity.principalId
|
||||
- userIdentity.type
|
||||
- userIdentity.userName
|
||||
- userName
|
||||
- user_access_key
|
||||
- user_agent
|
||||
- user_arn
|
||||
- user_group_id
|
||||
- user_id
|
||||
- user_name
|
||||
- user_type
|
||||
- vendor
|
||||
- vendor_account
|
||||
- vendor_product
|
||||
- vendor_region
|
||||
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId": "AIDAYTOGP2RLEHRX5YWNV", "arn": "arn:aws:iam::111111111111:user/bhavin_cli", "accountId": "111111111111", "accessKeyId": "AKIAYTOGP2RLLAA6NJUM", "userName": "bhavin_cli"}, "eventTime": "2021-03-05T01:02:38Z", "eventSource": "iam.amazonaws.com", "eventName": "CreateLoginProfile", "awsRegion": "us-east-1", "sourceIPAddress": "73.15.72.101", "userAgent": "aws-cli/2.0.62 Python/3.9.2 Darwin/19.6.0 source/x86_64 command/iam.create-login-profile", "requestParameters": {"userName": "AtomicRedTeam", "passwordResetRequired": false}, "responseElements": {"loginProfile": {"userName": "AtomicRedTeam", "createDate": "Mar 5, 2021 1:02:38 AM", "passwordResetRequired": false}}, "requestID": "f1b90364-8aed-4559-96cf-f5f2009bb7cb", "eventID": "ffb76906-6dd1-4219-adfe-e26b92036a1e", "readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "eventCategory": "Management", "recipientAccountId": "111111111111"}'
|
||||
@@ -1,95 +0,0 @@
|
||||
event_name: AWS CloudTrail CreateNetworkAclEntry
|
||||
fields:
|
||||
- _time
|
||||
- action
|
||||
- app
|
||||
- awsRegion
|
||||
- aws_account_id
|
||||
- change_type
|
||||
- command
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- dest
|
||||
- direction
|
||||
- dvc
|
||||
- errorCode
|
||||
- eventCategory
|
||||
- eventID
|
||||
- eventName
|
||||
- eventSource
|
||||
- eventTime
|
||||
- eventType
|
||||
- eventVersion
|
||||
- eventtype
|
||||
- host
|
||||
- index
|
||||
- linecount
|
||||
- managementEvent
|
||||
- msg
|
||||
- object
|
||||
- object_category
|
||||
- object_id
|
||||
- product
|
||||
- protocol
|
||||
- protocol_code
|
||||
- punct
|
||||
- readOnly
|
||||
- recipientAccountId
|
||||
- region
|
||||
- requestID
|
||||
- requestParameters.aclProtocol
|
||||
- requestParameters.cidrBlock
|
||||
- requestParameters.egress
|
||||
- requestParameters.networkAclId
|
||||
- requestParameters.ruleAction
|
||||
- requestParameters.ruleNumber
|
||||
- responseElements._return
|
||||
- responseElements.requestId
|
||||
- rule_action
|
||||
- signature
|
||||
- source
|
||||
- sourceIPAddress
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- src
|
||||
- src_ip
|
||||
- src_ip_range
|
||||
- start_time
|
||||
- status
|
||||
- tag
|
||||
- tag::eventtype
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
- user
|
||||
- userAgent
|
||||
- userIdentity.accessKeyId
|
||||
- userIdentity.accountId
|
||||
- userIdentity.arn
|
||||
- userIdentity.principalId
|
||||
- userIdentity.sessionContext.attributes.creationDate
|
||||
- userIdentity.sessionContext.attributes.mfaAuthenticated
|
||||
- userIdentity.sessionContext.sessionIssuer.accountId
|
||||
- userIdentity.sessionContext.sessionIssuer.arn
|
||||
- userIdentity.sessionContext.sessionIssuer.principalId
|
||||
- userIdentity.sessionContext.sessionIssuer.type
|
||||
- userIdentity.sessionContext.sessionIssuer.userName
|
||||
- userIdentity.type
|
||||
- userName
|
||||
- user_access_key
|
||||
- user_agent
|
||||
- user_arn
|
||||
- user_group_id
|
||||
- user_id
|
||||
- user_name
|
||||
- user_type
|
||||
- vendor
|
||||
- vendor_account
|
||||
- vendor_product
|
||||
- vendor_region
|
||||
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "principalId": "AROAIJIESMXKGCJRCTPR6:pbareiss@splunk.local", "arn": "arn:aws:sts::111111111111:assumed-role/okta_adm_role/pbareiss@splunk.local", "accountId": "111111111111", "accessKeyId": "ASIAYTOGP2RLF3F7BXZK", "sessionContext": {"sessionIssuer": {"type": "Role", "principalId": "AROAIJIESMXKGCJRCTPR6", "arn": "arn:aws:iam::111111111111:role/okta_adm_role", "accountId": "111111111111", "userName": "okta_adm_role"}, "webIdFederationData": {}, "attributes": {"mfaAuthenticated": "false", "creationDate": "2021-01-12T08:36:15Z"}}}, "eventTime": "2021-01-12T08:38:39Z", "eventSource": "ec2.amazonaws.com", "eventName": "CreateNetworkAclEntry", "awsRegion": "eu-central-1", "sourceIPAddress": "95.90.199.65", "userAgent": "console.ec2.amazonaws.com", "requestParameters": {"networkAclId": "acl-078ccebebcbabe175", "ruleNumber": 10, "egress": false, "ruleAction": "allow", "icmpTypeCode": {}, "portRange": {}, "aclProtocol": "-1", "cidrBlock": "0.0.0.0/0"}, "responseElements": {"requestId": "d29c9c32-3a72-48d3-b612-6ba795e9ec64", "_return": true}, "requestID": "d29c9c32-3a72-48d3-b612-6ba795e9ec64", "eventID": "6d1ce00e-4099-463c-8a4d-2af2fb2178ba", "readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "eventCategory": "Management", "recipientAccountId": "111111111111"}'
|
||||
@@ -1,80 +0,0 @@
|
||||
event_name: AWS CloudTrail CreatePolicyVersion
|
||||
fields:
|
||||
- _time
|
||||
- action
|
||||
- app
|
||||
- awsRegion
|
||||
- aws_account_id
|
||||
- change_type
|
||||
- command
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- dest
|
||||
- dvc
|
||||
- errorCode
|
||||
- eventCategory
|
||||
- eventID
|
||||
- eventName
|
||||
- eventSource
|
||||
- eventTime
|
||||
- eventType
|
||||
- eventVersion
|
||||
- eventtype
|
||||
- host
|
||||
- index
|
||||
- linecount
|
||||
- managementEvent
|
||||
- msg
|
||||
- object_category
|
||||
- product
|
||||
- punct
|
||||
- readOnly
|
||||
- recipientAccountId
|
||||
- region
|
||||
- requestID
|
||||
- requestParameters.policyArn
|
||||
- requestParameters.policyDocument
|
||||
- requestParameters.setAsDefault
|
||||
- responseElements.policyVersion.createDate
|
||||
- responseElements.policyVersion.isDefaultVersion
|
||||
- responseElements.policyVersion.versionId
|
||||
- signature
|
||||
- source
|
||||
- sourceIPAddress
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- src
|
||||
- src_ip
|
||||
- start_time
|
||||
- status
|
||||
- tag
|
||||
- tag::eventtype
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
- user
|
||||
- userAgent
|
||||
- userIdentity.accessKeyId
|
||||
- userIdentity.accountId
|
||||
- userIdentity.arn
|
||||
- userIdentity.principalId
|
||||
- userIdentity.type
|
||||
- userIdentity.userName
|
||||
- userName
|
||||
- user_access_key
|
||||
- user_agent
|
||||
- user_arn
|
||||
- user_group_id
|
||||
- user_id
|
||||
- user_name
|
||||
- user_type
|
||||
- vendor
|
||||
- vendor_account
|
||||
- vendor_product
|
||||
- vendor_region
|
||||
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId": "AIDAYTOGP2RLNMCDVJZAY", "arn": "arn:aws:iam::111111111111:user/rhino_escalate", "accountId": "111111111111", "accessKeyId": "AKIAYTOGP2RLHSQZPZFZ", "userName": "rhino_escalate"}, "eventTime": "2021-02-23T00:02:30Z", "eventSource": "iam.amazonaws.com", "eventName": "CreatePolicyVersion", "awsRegion": "us-east-1", "sourceIPAddress": "73.15.72.101", "userAgent": "aws-cli/2.0.62 Python/3.9.0 Darwin/19.6.0 source/x86_64 command/iam.create-policy-version", "requestParameters": {"policyArn": "arn:aws:iam::111111111111:policy/rhino_escalate", "policyDocument": "{\n \"Version\": \"2012-10-17\",\n \"Statement\": [\n {\n \"Sid\": \"AllowEverything\",\n \"Effect\": \"Allow\",\n \"Action\": \"iam:*\",\n \"Resource\": \"*\"\n }\n ]\n }", "setAsDefault": true}, "responseElements": {"policyVersion": {"versionId": "v2", "isDefaultVersion": true, "createDate": "Feb 23, 2021 12:02:30 AM"}}, "requestID": "fa42b4b2-f34a-4673-8f9f-b25cf1f5005a", "eventID": "33149175-90fd-4cff-a43b-408e4f848c1c", "readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "eventCategory": "Management", "recipientAccountId": "111111111111"}'
|
||||
@@ -1,89 +0,0 @@
|
||||
event_name: AWS CloudTrail CreateSnapshot
|
||||
fields:
|
||||
- _time
|
||||
- app
|
||||
- awsRegion
|
||||
- aws_account_id
|
||||
- change_type
|
||||
- command
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- dest
|
||||
- dvc
|
||||
- errorCode
|
||||
- eventCategory
|
||||
- eventID
|
||||
- eventName
|
||||
- eventSource
|
||||
- eventTime
|
||||
- eventType
|
||||
- eventVersion
|
||||
- eventtype
|
||||
- host
|
||||
- index
|
||||
- linecount
|
||||
- managementEvent
|
||||
- msg
|
||||
- object_category
|
||||
- product
|
||||
- punct
|
||||
- readOnly
|
||||
- recipientAccountId
|
||||
- region
|
||||
- requestID
|
||||
- requestParameters.tagSpecificationSet.items{}.resourceType
|
||||
- requestParameters.tagSpecificationSet.items{}.tags{}.key
|
||||
- requestParameters.tagSpecificationSet.items{}.tags{}.value
|
||||
- requestParameters.volumeId
|
||||
- responseElements.encrypted
|
||||
- responseElements.ownerId
|
||||
- responseElements.requestId
|
||||
- responseElements.snapshotId
|
||||
- responseElements.startTime
|
||||
- responseElements.status
|
||||
- responseElements.tagSet.items{}.key
|
||||
- responseElements.tagSet.items{}.value
|
||||
- responseElements.volumeId
|
||||
- responseElements.volumeSize
|
||||
- signature
|
||||
- source
|
||||
- sourceIPAddress
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- src
|
||||
- src_ip
|
||||
- start_time
|
||||
- tag
|
||||
- tag::eventtype
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
- tlsDetails.cipherSuite
|
||||
- tlsDetails.clientProvidedHostHeader
|
||||
- tlsDetails.tlsVersion
|
||||
- user
|
||||
- userAgent
|
||||
- userIdentity.accessKeyId
|
||||
- userIdentity.accountId
|
||||
- userIdentity.arn
|
||||
- userIdentity.principalId
|
||||
- userIdentity.type
|
||||
- userIdentity.userName
|
||||
- userName
|
||||
- user_access_key
|
||||
- user_agent
|
||||
- user_arn
|
||||
- user_group_id
|
||||
- user_id
|
||||
- user_name
|
||||
- user_type
|
||||
- vendor
|
||||
- vendor_account
|
||||
- vendor_product
|
||||
- vendor_region
|
||||
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "principalId": "AIDAYTOGP2RLCNEAQXWZV", "arn": "arn:aws:iam::111111111111:user/bhavin_console", "accountId": "111111111111", "accessKeyId": "AKIAYTOGP2RLF5EAXXXX", "userName": "bhavin_console"}, "eventTime": "2023-03-20T22:31:18Z", "eventSource": "ec2.amazonaws.com", "eventName": "CreateSnapshot", "awsRegion": "us-west-2", "sourceIPAddress": "72.135.1.1", "userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.157 (go1.19.3; darwin; amd64) stratus-red-team_46665bb8-dc15-4aba-a5ad-a362772b3f0d HashiCorp-terraform-exec/0.17.3", "requestParameters": {"volumeId": "vol-0363e53e12f67c9b7", "tagSpecificationSet": {"items": [{"resourceType": "snapshot", "tags": [{"key": "StratusRedTeam", "value": "true"}]}]}}, "responseElements": {"requestId": "fefed928-d461-45f0-802f-a99d94c833a8", "snapshotId": "snap-02effb3bb62786b18", "volumeId": "vol-0363e53e12f67c9b7", "status": "pending", "startTime": 1679351478226, "ownerId": "111111111111", "volumeSize": "1", "encrypted": false, "tagSet": {"items": [{"key": "StratusRedTeam", "value": "true"}]}}, "requestID": "fefed928-d461-45f0-802f-a99d94c833a8", "eventID": "2d52d141-d1e6-4d1f-a380-1461c1bf9f83", "readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId": "111111111111", "eventCategory": "Management", "tlsDetails": {"tlsVersion": "TLSv1.2", "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256", "clientProvidedHostHeader": "ec2.us-west-2.amazonaws.com"}}'
|
||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user