From 6ea36044817ca79deb740645c42e8f88882a90d3 Mon Sep 17 00:00:00 2001 From: Rod Soto Date: Thu, 25 Jun 2020 14:36:18 -0400 Subject: [PATCH 1/2] fixedaddedcondition --- detections/kubernetes_azure_detect_sensitive_object_access.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/detections/kubernetes_azure_detect_sensitive_object_access.yml b/detections/kubernetes_azure_detect_sensitive_object_access.yml index b24ed7a2b2..95b86696f1 100644 --- a/detections/kubernetes_azure_detect_sensitive_object_access.yml +++ b/detections/kubernetes_azure_detect_sensitive_object_access.yml @@ -6,7 +6,7 @@ id: 1bba382b-07fd-4ffa-b390-8002739b76e8 known_false_positives: "Sensitive object access is not necessarily malicious but user and object context can provide guidance for detection." name: "Azure AKS Kubernetes cluster sensitive object access detection" references: [] -search: "sourcetype=mscs:storage:blob:json index=azure_test category=kube-audit | spath input=properties.log| search objectRef.resource=secrets OR configmaps |table user.username user.groups{} objectRef.resource objectRef.namespace objectRef.name annotations.authorization.k8s.io/reason |dedup user.username user.groups{} |`kubernetes_azure_detect_sensitive_object_access`" +search: "sourcetype=mscs:storage:blob:json category=kube-audit | spath input=properties.log| search objectRef.resource=secrets OR configmaps user.username=system.anonymous OR annotations.authorization.k8s.io/decision=allow |table user.username user.groups{} objectRef.resource objectRef.namespace objectRef.name annotations.authorization.k8s.io/reason |dedup user.username user.groups{} |`kubernetes_azure_detect_sensitive_object_access`" tags: analytics_story: - "Kubernetes Sensitive Object Access Activity" From e432a4ab5010b6100e48b00d74a4a9f5a8408b74 Mon Sep 17 00:00:00 2001 From: Rod Soto Date: Thu, 25 Jun 2020 14:52:41 -0400 Subject: [PATCH 2/2] fixedservaccounatct --- ...ure_detect_most_active_service_accounts_by_pod_namespace.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/detections/kubernetes_azure_detect_most_active_service_accounts_by_pod_namespace.yml b/detections/kubernetes_azure_detect_most_active_service_accounts_by_pod_namespace.yml index 5354724a71..c750867252 100644 --- a/detections/kubernetes_azure_detect_most_active_service_accounts_by_pod_namespace.yml +++ b/detections/kubernetes_azure_detect_most_active_service_accounts_by_pod_namespace.yml @@ -6,7 +6,7 @@ id: 55a2264a-b7f0-45e5-addd-1e5ab3415c72 known_false_positives: "Not all service accounts interactions are malicious. Analyst must consider IP and verb context when trying to detect maliciousness." name: "Azure AKS Kubernetes detect most active service accounts by pod and namespaces" references: [] -search: "sourcetype:mscs:storage:blob:json category=kube-audit | spath input=properties.log | search user.groups{}=system:serviceaccounts* | table sourceIPs{} user.username userAgent verb responseStatus.reason responseStatus.status properties.pod objectRef.namespace | top sourceIPs{} user.username verb responseStatus.status properties.pod objectRef.namespace |`kubernetes_azure_detect_most_active_service_accounts_by_pod_namespace`" +search: "sourcetype:mscs:storage:blob:json category=kube-audit | spath input=properties.log | search user.groups{}=system:serviceaccounts* OR user.username=system.anonymous OR annotations.authorization.k8s.io/decision=allow | table sourceIPs{} user.username userAgent verb responseStatus.reason responseStatus.status properties.pod objectRef.namespace | top sourceIPs{} user.username verb responseStatus.status properties.pod objectRef.namespace |`kubernetes_azure_detect_most_active_service_accounts_by_pod_namespace`" tags: analytics_story: - "Kubernetes Sensitive Role Activity"