Branch was auto-updated.

This commit is contained in:
pyth0n1c
2022-07-19 10:04:14 -07:00
committed by GitHub
2 changed files with 0 additions and 96 deletions
@@ -1,49 +0,0 @@
name: GCP GCR container uploaded
id: 4f00ca88-e766-4605-ac65-ae51c9fd185b
version: 1
date: '2020-02-20'
author: Rod Soto, Rico Valdez, Splunk
type: Hunting
datamodel: []
description: This search show information on uploaded containers including source
user, account, action, bucket name event name, http user agent, message and destination
path.
search: '|tstats count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Cloud_Infrastructure.Storage
where Storage.event_name=storage.objects.create by Storage.src_user Storage.account
Storage.action Storage.bucket_name Storage.event_name Storage.http_user_agent Storage.msg
Storage.object_path | `drop_dm_object_name("Storage")` | `gcp_gcr_container_uploaded_filter` '
how_to_implement: You must install the GCP App for Splunk (version 2.0.0 or later),
then configure stackdriver and set a subpub subscription to be imported to Splunk.
You must also install Cloud Infrastructure data model. Please also customize the
`container_implant_gcp_detection_filter` macro to filter out the false positives.
known_false_positives: Uploading container is a normal behavior from developers or
users with access to container registry. GCP GCR registers container upload as a
Storage event, this search must be considered under the context of CONTAINER upload
creation which automatically generates a bucket entry for destination path.
references: []
tags:
analytic_story:
- Container Implantation Monitoring and Investigation
asset_type: GCP GCR Container
mitre_attack_id:
- T1525
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
security_domain: threat
kill_chain_phases:
- Exploitation
confidence: 50
impact: 50
risk_score: 25
context:
- Unknown
message: tbd
observable:
- name: field
type: Unknown
role:
- Unknown
@@ -1,47 +0,0 @@
name: New container uploaded to AWS ECR
id: f0f70b40-f7ad-489d-9905-23d149da8099
version: 1
date: '2020-02-20'
author: Rod Soto, Rico Valdez, Splunk
type: Hunting
datamodel: []
description: This searches show information on uploaded containers including source
user, image id, source IP user type, http user agent, region, first time, last time
of operation (PutImage). These searches are based on Cloud Infrastructure Data Model.
search: '| tstats count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Cloud_Infrastructure.Compute
where Compute.user_type!="AssumeRole" AND Compute.http_user_agent="AWS Internal"
AND Compute.event_name="PutImage" by Compute.image_id Compute.src_user Compute.src
Compute.region Compute.msg Compute.user_type | `drop_dm_object_name("Compute")`
| `new_container_uploaded_to_aws_ecr_filter` '
how_to_implement: You must install the AWS App for Splunk (version 5.1.0 or later)
and Splunk Add-on for AWS (version 4.4.0 or later), then configure your AWS CloudTrail
inputs. You must also install Cloud Infrastructure data model. Please also customize
the `container_implant_aws_detection_filter` macro to filter out the false positives.
known_false_positives: Uploading container is a normal behavior from developers or
users with access to container registry.
references: []
tags:
analytic_story:
- Container Implantation Monitoring and Investigation
asset_type: AWS ECR container
mitre_attack_id:
- T1525
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
security_domain: threat
confidence: 50
impact: 50
risk_score: 25
context: []
observable:
- name: user
type: User
role:
- Victim
message: tbd
kill_chain_phases:
- Exploitation