mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
Merge branch 'develop' into medusa_ransomware
This commit is contained in:
+1
-1
@@ -4,7 +4,7 @@ version: 1
|
||||
date: '2020-08-15'
|
||||
author: Rico Valdez, Splunk
|
||||
type: Baseline
|
||||
status: production
|
||||
status: deprecated
|
||||
description: This search looks for **AssumeRole** events where the requesting account
|
||||
differs from the requested account, then writes these relationships to a lookup
|
||||
file.
|
||||
+1
-1
@@ -4,7 +4,7 @@ version: 1
|
||||
date: '2020-08-15'
|
||||
author: Rico Valdez, Splunk
|
||||
type: Baseline
|
||||
status: production
|
||||
status: deprecated
|
||||
description: This search looks for **AssumeRole** events where the requesting account
|
||||
differs from the requested account, then writes these relationships to a lookup
|
||||
file.
|
||||
+4
-4
@@ -3,7 +3,7 @@ app:
|
||||
uid: 3449
|
||||
title: ES Content Updates
|
||||
appid: DA-ESS-ContentUpdate
|
||||
version: 5.1.1
|
||||
version: 5.2.0
|
||||
description: Explore the Analytic Stories included with ES Content Updates.
|
||||
prefix: ESCU
|
||||
label: ESCU
|
||||
@@ -218,11 +218,11 @@ apps:
|
||||
version: 3.1.0
|
||||
description: description of app
|
||||
hardcoded_path: https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/splunk-add-on-for-github_310.tgz
|
||||
- uid: 2882
|
||||
- uid: 3471
|
||||
title: Splunk Add-on for AppDynamics
|
||||
appid: Splunk_TA_AppDynamics
|
||||
version: 3.1.0
|
||||
version: 3.0.0
|
||||
description: The Splunk Add-on for AppDynamics enables you to easily configure data
|
||||
inputs to pull data from AppDynamics' REST APIs
|
||||
hardcoded_path: https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/cisco-splunk-add-on-for-appdynamics_310.tgz
|
||||
hardcoded_path: https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/cisco-splunk-add-on-for-appdynamics_300.tgz
|
||||
githash: d6fac80e6d50ae06b40f91519a98489d4ce3a3fd
|
||||
|
||||
@@ -1,9 +1,22 @@
|
||||
name: ASL AWS CloudTrail
|
||||
id: 1dcf9cfb-0e91-44c6-81b3-61b2574ec898
|
||||
version: 1
|
||||
date: '2025-01-14'
|
||||
version: 2
|
||||
date: '2025-01-23'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for ASL AWS CloudTrail
|
||||
description: Represents AWS API dataset data collection from Amazon Security Lake.
|
||||
mitre_components:
|
||||
- Cloud Service Metadata
|
||||
- Cloud Service Modification
|
||||
- Cloud Storage Access
|
||||
- Instance Creation
|
||||
- Instance Deletion
|
||||
- Instance Start
|
||||
- Instance Stop
|
||||
- Instance Modification
|
||||
- Cloud Storage Creation
|
||||
- Cloud Storage Deletion
|
||||
- Cloud Service Enumeration
|
||||
- Cloud Storage Enumeration
|
||||
source: aws_asl
|
||||
sourcetype: aws:asl
|
||||
separator: api.operation
|
||||
@@ -12,11 +25,9 @@ supported_TA:
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.9.1
|
||||
output_fields:
|
||||
- action
|
||||
- dest
|
||||
- user
|
||||
- user_agent
|
||||
- status
|
||||
- src
|
||||
- vendor_account
|
||||
- vendor_region
|
||||
|
||||
@@ -1,9 +1,17 @@
|
||||
name: AWS Cloudfront
|
||||
id: 780086dc-2384-45b6-ade7-56cb00105464
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
version: 2
|
||||
date: '2025-01-23'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for AWS Cloudfront
|
||||
description: Logs requests made to AWS CloudFront distributions, including details
|
||||
on client access, response data, and performance metrics.
|
||||
mitre_components:
|
||||
- Network Traffic Content
|
||||
- Network Traffic Flow
|
||||
- Response Metadata
|
||||
- Response Content
|
||||
- Logon Session Metadata
|
||||
- Cloud Service Metadata
|
||||
source: aws
|
||||
sourcetype: aws:cloudfront:accesslogs
|
||||
supported_TA:
|
||||
|
||||
@@ -3,7 +3,7 @@ id: e8ace6db-1dbd-4c72-a1fb-334684619a38
|
||||
version: 1
|
||||
date: '2024-07-24'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for AWS CloudTrail
|
||||
description: All AWS CloudTrail events
|
||||
source: aws_cloudtrail
|
||||
sourcetype: aws:cloudtrail
|
||||
separator: eventName
|
||||
@@ -11,12 +11,3 @@ supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
version: 7.9.1
|
||||
output_fields:
|
||||
- action
|
||||
- dest
|
||||
- user
|
||||
- user_agent
|
||||
- src
|
||||
- vendor_account
|
||||
- vendor_region
|
||||
- vendor_product
|
||||
|
||||
@@ -1,12 +1,20 @@
|
||||
name: AWS CloudTrail AssumeRoleWithSAML
|
||||
id: 1e28f2a6-2db9-405f-b298-18734a293f77
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
version: 2
|
||||
date: '2025-01-23'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for AWS CloudTrail AssumeRoleWithSAML
|
||||
description: Logs attempts to assume roles via SAML authentication in AWS, including
|
||||
details of identity provider and role mapping.
|
||||
mitre_components:
|
||||
- User Account Authentication
|
||||
- Logon Session Creation
|
||||
- User Account Metadata
|
||||
- Cloud Service Metadata
|
||||
- Instance Modification
|
||||
source: aws_cloudtrail
|
||||
sourcetype: aws:cloudtrail
|
||||
separator: eventName
|
||||
separator_value: AssumeRoleWithSAML
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
@@ -125,7 +133,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "SAMLUser", "pri
|
||||
"eventType": "AwsApiCall", "managementEvent": true, "eventCategory": "Management",
|
||||
"recipientAccountId": "111111111111"}'
|
||||
output_fields:
|
||||
- action
|
||||
- dest
|
||||
- user
|
||||
- user_agent
|
||||
|
||||
@@ -1,12 +1,20 @@
|
||||
name: AWS CloudTrail ConsoleLogin
|
||||
id: b68b3f26-bd21-4fa8-b593-616fe75ac0ae
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
version: 2
|
||||
date: '2025-01-23'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for AWS CloudTrail ConsoleLogin
|
||||
description: Logs attempts to sign in to the AWS Management Console, including successful
|
||||
and failed login events.
|
||||
mitre_components:
|
||||
- User Account Authentication
|
||||
- Logon Session Creation
|
||||
- User Account Metadata
|
||||
- Logon Session Metadata
|
||||
- Cloud Service Metadata
|
||||
source: aws_cloudtrail
|
||||
sourcetype: aws:cloudtrail
|
||||
separator: eventName
|
||||
separator_value: ConsoleLogin
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
@@ -101,7 +109,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "acco
|
||||
"Management", "tlsDetails": {"tlsVersion": "TLSv1.2", "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
|
||||
"clientProvidedHostHeader": "signin.aws.amazon.com"}}'
|
||||
output_fields:
|
||||
- action
|
||||
- dest
|
||||
- user
|
||||
- user_agent
|
||||
|
||||
@@ -1,12 +1,19 @@
|
||||
name: AWS CloudTrail CopyObject
|
||||
id: 965083f4-64a8-403f-99cc-252e1a6bd3b6
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
version: 2
|
||||
date: '2025-01-23'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for AWS CloudTrail CopyObject
|
||||
description: Logs operations that copy objects within or between AWS S3 buckets, including
|
||||
details of source and destination.
|
||||
mitre_components:
|
||||
- Cloud Storage Access
|
||||
- Cloud Storage Modification
|
||||
- Cloud Storage Metadata
|
||||
- Instance Modification
|
||||
source: aws_cloudtrail
|
||||
sourcetype: aws:cloudtrail
|
||||
separator: eventName
|
||||
separator_value: CopyObject
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
@@ -118,7 +125,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "prin
|
||||
"eventType": "AwsApiCall", "managementEvent": false, "recipientAccountId": "111111111111",
|
||||
"eventCategory": "Data"}'
|
||||
output_fields:
|
||||
- action
|
||||
- dest
|
||||
- user
|
||||
- user_agent
|
||||
|
||||
@@ -1,12 +1,19 @@
|
||||
name: AWS CloudTrail CreateAccessKey
|
||||
id: 0460f7da-3254-4d90-b8c0-2ca657d0cea0
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
version: 2
|
||||
date: '2025-01-23'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for AWS CloudTrail CreateAccessKey
|
||||
description: Logs the creation of new AWS access keys, including details of the associated
|
||||
user and permissions.
|
||||
mitre_components:
|
||||
- User Account Creation
|
||||
- User Account Metadata
|
||||
- Cloud Service Modification
|
||||
- Cloud Service Metadata
|
||||
source: aws_cloudtrail
|
||||
sourcetype: aws:cloudtrail
|
||||
separator: eventName
|
||||
separator_value: CreateAccessKey
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
@@ -102,7 +109,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "prin
|
||||
"AwsApiCall", "managementEvent": true, "eventCategory": "Management", "recipientAccountId":
|
||||
"121521347698"}'
|
||||
output_fields:
|
||||
- action
|
||||
- dest
|
||||
- user
|
||||
- user_agent
|
||||
|
||||
@@ -1,12 +1,19 @@
|
||||
name: AWS CloudTrail CreateKey
|
||||
id: fcfc1593-b6b5-4a0f-91c5-3c395116a8b9
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
version: 2
|
||||
date: '2025-01-23'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for AWS CloudTrail CreateKey
|
||||
description: Logs the creation of new AWS KMS keys, including details of key properties
|
||||
and associated metadata.
|
||||
mitre_components:
|
||||
- Cloud Service Creation
|
||||
- Cloud Service Metadata
|
||||
- Instance Creation
|
||||
- Volume Metadata
|
||||
source: aws_cloudtrail
|
||||
sourcetype: aws:cloudtrail
|
||||
separator: eventName
|
||||
separator_value: CreateKey
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
@@ -149,7 +156,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "
|
||||
"eventType": "AwsApiCall", "managementEvent": true, "eventCategory": "Management",
|
||||
"recipientAccountId": "111111111111"}'
|
||||
output_fields:
|
||||
- action
|
||||
- dest
|
||||
- user
|
||||
- user_agent
|
||||
|
||||
@@ -1,12 +1,19 @@
|
||||
name: AWS CloudTrail CreateLoginProfile
|
||||
id: 0024fdb1-0d62-4449-970a-746952cf80b6
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
version: 2
|
||||
date: '2025-01-23'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for AWS CloudTrail CreateLoginProfile
|
||||
description: Logs the creation of login profiles for IAM users, including associated
|
||||
metadata and authentication settings.
|
||||
mitre_components:
|
||||
- User Account Creation
|
||||
- User Account Metadata
|
||||
- Logon Session Metadata
|
||||
- Cloud Service Metadata
|
||||
source: aws_cloudtrail
|
||||
sourcetype: aws:cloudtrail
|
||||
separator: eventName
|
||||
separator_value: CreateLoginProfile
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
@@ -101,7 +108,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "prin
|
||||
"AwsApiCall", "managementEvent": true, "eventCategory": "Management", "recipientAccountId":
|
||||
"111111111111"}'
|
||||
output_fields:
|
||||
- action
|
||||
- dest
|
||||
- user
|
||||
- user_agent
|
||||
|
||||
@@ -1,12 +1,19 @@
|
||||
name: AWS CloudTrail CreateNetworkAclEntry
|
||||
id: 45934028-10ec-4ab5-a7b1-a6349b833e67
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
version: 2
|
||||
date: '2025-01-23'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for AWS CloudTrail CreateNetworkAclEntry
|
||||
description: Logs the creation of new entries in a network ACL, including rules to
|
||||
allow or deny specific network traffic.
|
||||
mitre_components:
|
||||
- Firewall Rule Modification
|
||||
- Network Connection Creation
|
||||
- Cloud Service Modification
|
||||
- Cloud Service Metadata
|
||||
source: aws_cloudtrail
|
||||
sourcetype: aws:cloudtrail
|
||||
separator: eventName
|
||||
separator_value: CreateNetworkAclEntry
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
@@ -120,7 +127,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "
|
||||
"6d1ce00e-4099-463c-8a4d-2af2fb2178ba", "readOnly": false, "eventType": "AwsApiCall",
|
||||
"managementEvent": true, "eventCategory": "Management", "recipientAccountId": "111111111111"}'
|
||||
output_fields:
|
||||
- action
|
||||
- dest
|
||||
- user
|
||||
- user_agent
|
||||
|
||||
@@ -1,12 +1,19 @@
|
||||
name: AWS CloudTrail CreatePolicyVersion
|
||||
id: f9f0f3da-37ec-4164-9ea0-0ae46645a86b
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
version: 2
|
||||
date: '2025-01-23'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for AWS CloudTrail CreatePolicyVersion
|
||||
description: Logs the creation of new versions of IAM policies, including changes
|
||||
to permissions and attached roles or resources.
|
||||
mitre_components:
|
||||
- Cloud Service Modification
|
||||
- Cloud Service Metadata
|
||||
- User Account Metadata
|
||||
- Group Modification
|
||||
source: aws_cloudtrail
|
||||
sourcetype: aws:cloudtrail
|
||||
separator: eventName
|
||||
separator_value: CreatePolicyVersion
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
@@ -105,7 +112,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "prin
|
||||
"AwsApiCall", "managementEvent": true, "eventCategory": "Management", "recipientAccountId":
|
||||
"111111111111"}'
|
||||
output_fields:
|
||||
- action
|
||||
- dest
|
||||
- user
|
||||
- user_agent
|
||||
|
||||
@@ -1,12 +1,19 @@
|
||||
name: AWS CloudTrail CreateSnapshot
|
||||
id: 514135a2-f4b2-4d32-8f31-d87824887f9f
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
version: 2
|
||||
date: '2025-01-23'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for AWS CloudTrail CreateSnapshot
|
||||
description: Logs the creation of a new snapshot of a cloud resource, such as an Amazon
|
||||
EBS volume, including details about the snapshot ID and resource type.
|
||||
mitre_components:
|
||||
- Snapshot Creation
|
||||
- Snapshot Metadata
|
||||
- Volume Metadata
|
||||
- Cloud Service Metadata
|
||||
source: aws_cloudtrail
|
||||
sourcetype: aws:cloudtrail
|
||||
separator: eventName
|
||||
separator_value: CreateSnapshot
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
@@ -117,7 +124,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "prin
|
||||
"111111111111", "eventCategory": "Management", "tlsDetails": {"tlsVersion": "TLSv1.2",
|
||||
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256", "clientProvidedHostHeader": "ec2.us-west-2.amazonaws.com"}}'
|
||||
output_fields:
|
||||
- action
|
||||
- dest
|
||||
- user
|
||||
- user_agent
|
||||
|
||||
@@ -1,12 +1,19 @@
|
||||
name: AWS CloudTrail CreateTask
|
||||
id: 6501e4fe-05b2-45f1-bd51-9e06a94fa7d9
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
version: 2
|
||||
date: '2025-01-23'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for AWS CloudTrail CreateTask
|
||||
description: Logs the creation of a new task in AWS services, such as ECS, including
|
||||
details about the task definition and resource allocation.
|
||||
mitre_components:
|
||||
- Scheduled Job Creation
|
||||
- Scheduled Job Metadata
|
||||
- Cloud Service Metadata
|
||||
- Instance Creation
|
||||
source: aws_cloudtrail
|
||||
sourcetype: aws:cloudtrail
|
||||
separator: eventName
|
||||
separator_value: CreateTask
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
@@ -120,7 +127,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "
|
||||
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256", "clientProvidedHostHeader": "datasync.us-west-2.amazonaws.com"},
|
||||
"sessionCredentialFromConsole": "true"}'
|
||||
output_fields:
|
||||
- action
|
||||
- dest
|
||||
- user
|
||||
- user_agent
|
||||
|
||||
@@ -1,12 +1,19 @@
|
||||
name: AWS CloudTrail CreateVirtualMFADevice
|
||||
id: 13e6e952-0dad-4190-865c-fb5911725f7a
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
version: 2
|
||||
date: '2025-01-23'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for AWS CloudTrail CreateVirtualMFADevice
|
||||
description: Logs the creation of a new virtual multi-factor authentication (MFA)
|
||||
device, including details about the associated user and configuration.
|
||||
mitre_components:
|
||||
- User Account Creation
|
||||
- User Account Metadata
|
||||
- Cloud Service Creation
|
||||
- Cloud Service Metadata
|
||||
source: aws_cloudtrail
|
||||
sourcetype: aws:cloudtrail
|
||||
separator: eventName
|
||||
separator_value: CreateVirtualMFADevice
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
@@ -99,7 +106,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "Root", "princip
|
||||
"readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId":
|
||||
"140429656527", "eventCategory": "Management", "sessionCredentialFromConsole": "true"}'
|
||||
output_fields:
|
||||
- action
|
||||
- dest
|
||||
- user
|
||||
- user_agent
|
||||
|
||||
@@ -1,12 +1,19 @@
|
||||
name: AWS CloudTrail DeactivateMFADevice
|
||||
id: 7397a10b-1150-4de9-8062-a96454ae53b2
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
version: 2
|
||||
date: '2025-01-23'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for AWS CloudTrail DeactivateMFADevice
|
||||
description: Logs the deactivation of a multi-factor authentication (MFA) device,
|
||||
including details about the associated user and the device.
|
||||
mitre_components:
|
||||
- User Account Modification
|
||||
- User Account Metadata
|
||||
- Cloud Service Modification
|
||||
- Cloud Service Metadata
|
||||
source: aws_cloudtrail
|
||||
sourcetype: aws:cloudtrail
|
||||
separator: eventName
|
||||
separator_value: DeactivateMFADevice
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
@@ -99,7 +106,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "Root", "princip
|
||||
"readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId":
|
||||
"111111111111", "eventCategory": "Management"}'
|
||||
output_fields:
|
||||
- action
|
||||
- dest
|
||||
- user
|
||||
- user_agent
|
||||
|
||||
@@ -1,12 +1,17 @@
|
||||
name: AWS CloudTrail DeleteAccountPasswordPolicy
|
||||
id: b0730ac8-0992-4de8-b000-2c7d0fc7a67f
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
version: 2
|
||||
date: '2025-01-23'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for AWS CloudTrail DeleteAccountPasswordPolicy
|
||||
description: Logs the deletion of an account-level password policy in AWS, including
|
||||
details about the account and policy being removed.
|
||||
mitre_components:
|
||||
- Cloud Service Modification
|
||||
- Cloud Service Metadata
|
||||
source: aws_cloudtrail
|
||||
sourcetype: aws:cloudtrail
|
||||
separator: eventName
|
||||
separator_value: DeleteAccountPasswordPolicy
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
@@ -99,7 +104,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "Root", "princip
|
||||
"readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId":
|
||||
"111111111111", "eventCategory": "Management", "sessionCredentialFromConsole": "true"}'
|
||||
output_fields:
|
||||
- action
|
||||
- dest
|
||||
- user
|
||||
- user_agent
|
||||
|
||||
@@ -1,12 +1,19 @@
|
||||
name: AWS CloudTrail DeleteAlarms
|
||||
id: b0730ac8-0992-4de8-b000-2c7d0fc7a61f
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
version: 2
|
||||
date: '2025-01-23'
|
||||
author: Bhavin Patel, Splunk
|
||||
description: Data source object for AWS CloudTrail DeleteAlarms
|
||||
description: Logs the deletion of CloudWatch alarms, including details about the alarm
|
||||
names and associated monitoring configurations.
|
||||
mitre_components:
|
||||
- Cloud Service Modification
|
||||
- Cloud Service Metadata
|
||||
- Application Log Content
|
||||
- Host Status
|
||||
source: aws_cloudtrail
|
||||
sourcetype: aws:cloudtrail
|
||||
separator: eventName
|
||||
separator_value: DeleteAlarms
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
@@ -140,7 +147,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "
|
||||
"managementEvent": true, "recipientAccountId": "111111111111", "eventCategory":
|
||||
"Management"}'
|
||||
output_fields:
|
||||
- action
|
||||
- dest
|
||||
- user
|
||||
- user_agent
|
||||
|
||||
@@ -1,12 +1,19 @@
|
||||
name: AWS CloudTrail DeleteDetector
|
||||
id: 5d8bd475-c8bc-4447-b27f-efa508728b90
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
version: 2
|
||||
date: '2025-01-23'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for AWS CloudTrail DeleteDetector
|
||||
description: Logs the deletion of an Amazon GuardDuty detector, including details
|
||||
about the detector ID and associated configurations.
|
||||
mitre_components:
|
||||
- Cloud Service Modification
|
||||
- Cloud Service Metadata
|
||||
- Host Status
|
||||
- Application Log Content
|
||||
source: aws_cloudtrail
|
||||
sourcetype: aws:cloudtrail
|
||||
separator: eventName
|
||||
separator_value: DeleteDetector
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
@@ -97,7 +104,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "prin
|
||||
"readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId":
|
||||
"111111111111", "eventCategory": "Management"}'
|
||||
output_fields:
|
||||
- action
|
||||
- dest
|
||||
- user
|
||||
- user_agent
|
||||
|
||||
@@ -1,12 +1,19 @@
|
||||
name: AWS CloudTrail DeleteGroup
|
||||
id: c95308a4-a943-42ca-b112-f90a05c21bd3
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
version: 2
|
||||
date: '2025-01-23'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for AWS CloudTrail DeleteGroup
|
||||
description: Logs the deletion of an IAM group in AWS, including details about the
|
||||
group name and its associated policies or members.
|
||||
mitre_components:
|
||||
- Group Modification
|
||||
- Group Metadata
|
||||
- User Account Metadata
|
||||
- Cloud Service Modification
|
||||
source: aws_cloudtrail
|
||||
sourcetype: aws:cloudtrail
|
||||
separator: eventName
|
||||
separator_value: DeleteGroup
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
@@ -101,7 +108,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "prin
|
||||
"readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "eventCategory":
|
||||
"Management", "recipientAccountId": "121522247101"}'
|
||||
output_fields:
|
||||
- action
|
||||
- dest
|
||||
- user
|
||||
- user_agent
|
||||
|
||||
@@ -1,12 +1,18 @@
|
||||
name: AWS CloudTrail DeleteIPSet
|
||||
id: ebdeeb63-77a0-4808-a6fe-549956731377
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
version: 2
|
||||
date: '2025-01-23'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for AWS CloudTrail DeleteIPSet
|
||||
description: Logs the deletion of an IP set in AWS WAF or GuardDuty, including details
|
||||
about the IP set ID and its associated configurations.
|
||||
mitre_components:
|
||||
- Cloud Service Modification
|
||||
- Cloud Service Metadata
|
||||
- Firewall Rule Modification
|
||||
source: aws_cloudtrail
|
||||
sourcetype: aws:cloudtrail
|
||||
separator: eventName
|
||||
separator_value: DeleteIPSet
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
@@ -98,7 +104,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "prin
|
||||
"readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId":
|
||||
"111111111111", "eventCategory": "Management"}'
|
||||
output_fields:
|
||||
- action
|
||||
- dest
|
||||
- user
|
||||
- user_agent
|
||||
|
||||
@@ -1,12 +1,19 @@
|
||||
name: AWS CloudTrail DeleteLogGroup
|
||||
id: 60cf6a69-fa43-4a6c-8808-e9fb46bf387f
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
version: 2
|
||||
date: '2025-01-23'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for AWS CloudTrail DeleteLogGroup
|
||||
description: Logs the deletion of a CloudWatch log group, including details about
|
||||
the log group name and associated resources.
|
||||
mitre_components:
|
||||
- Cloud Service Modification
|
||||
- Cloud Service Metadata
|
||||
- Application Log Content
|
||||
- Host Status
|
||||
source: aws_cloudtrail
|
||||
sourcetype: aws:cloudtrail
|
||||
separator: eventName
|
||||
separator_value: DeleteLogGroup
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
@@ -99,7 +106,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "prin
|
||||
"eventCategory": "Management", "tlsDetails": {"tlsVersion": "TLSv1.2", "cipherSuite":
|
||||
"ECDHE-RSA-AES128-GCM-SHA256", "clientProvidedHostHeader": "logs.us-west-2.amazonaws.com"}}'
|
||||
output_fields:
|
||||
- action
|
||||
- dest
|
||||
- user
|
||||
- user_agent
|
||||
|
||||
@@ -1,12 +1,19 @@
|
||||
name: AWS CloudTrail DeleteLogStream
|
||||
id: 6f8bb808-89f8-465e-a34d-229df2f46402
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
version: 2
|
||||
date: '2025-01-23'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for AWS CloudTrail DeleteLogStream
|
||||
description: Logs the deletion of a log stream within a CloudWatch log group, including
|
||||
details about the stream name and associated log group.
|
||||
mitre_components:
|
||||
- Cloud Service Modification
|
||||
- Cloud Service Metadata
|
||||
- Application Log Content
|
||||
- Host Status
|
||||
source: aws_cloudtrail
|
||||
sourcetype: aws:cloudtrail
|
||||
separator: eventName
|
||||
separator_value: DeleteLogStream
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
@@ -100,7 +107,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "prin
|
||||
"111111111111", "eventCategory": "Management", "tlsDetails": {"tlsVersion": "TLSv1.2",
|
||||
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256", "clientProvidedHostHeader": "logs.us-west-2.amazonaws.com"}}'
|
||||
output_fields:
|
||||
- action
|
||||
- dest
|
||||
- user
|
||||
- user_agent
|
||||
|
||||
@@ -1,12 +1,18 @@
|
||||
name: AWS CloudTrail DeleteNetworkAclEntry
|
||||
id: a0dd0f10-cc03-425d-bd5a-e1e0d954b856
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
version: 2
|
||||
date: '2025-01-23'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for AWS CloudTrail DeleteNetworkAclEntry
|
||||
description: Logs the deletion of a network ACL entry in AWS, including details about
|
||||
the rule number and associated network ACL.
|
||||
mitre_components:
|
||||
- Firewall Rule Modification
|
||||
- Cloud Service Modification
|
||||
- Cloud Service Metadata
|
||||
source: aws_cloudtrail
|
||||
sourcetype: aws:cloudtrail
|
||||
separator: eventName
|
||||
separator_value: DeleteNetworkAclEntry
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
@@ -109,7 +115,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "
|
||||
"b9e05770-e9b0-4ba1-91e8-6537097e06e7", "readOnly": false, "eventType": "AwsApiCall",
|
||||
"managementEvent": true, "eventCategory": "Management", "recipientAccountId": "111111111111"}'
|
||||
output_fields:
|
||||
- action
|
||||
- dest
|
||||
- user
|
||||
- user_agent
|
||||
|
||||
@@ -1,12 +1,17 @@
|
||||
name: AWS CloudTrail DeletePolicy
|
||||
id: d190d23a-2c59-4a0e-9c55-a53ebef28ee5
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
version: 2
|
||||
date: '2025-01-23'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for AWS CloudTrail DeletePolicy
|
||||
description: Logs the deletion of an IAM policy in AWS, including details about the
|
||||
policy name and its associated roles or users.
|
||||
mitre_components:
|
||||
- Cloud Service Modification
|
||||
- Cloud Service Metadata
|
||||
source: aws_cloudtrail
|
||||
sourcetype: aws:cloudtrail
|
||||
separator: eventName
|
||||
separator_value: DeletePolicy
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
@@ -101,7 +106,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "prin
|
||||
"abd071bf-0a38-4fab-af4a-5eee55f0935e", "readOnly": false, "eventType": "AwsApiCall",
|
||||
"managementEvent": true, "eventCategory": "Management", "recipientAccountId": "151521547504"}'
|
||||
output_fields:
|
||||
- action
|
||||
- dest
|
||||
- user
|
||||
- user_agent
|
||||
|
||||
@@ -1,12 +1,19 @@
|
||||
name: AWS CloudTrail DeleteRule
|
||||
id: b5760623-f3ca-492d-a372-d5c2b3567dfc
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
version: 2
|
||||
date: '2025-01-23'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for AWS CloudTrail DeleteRule
|
||||
description: Logs the deletion of an event rule in AWS EventBridge, including details
|
||||
about the rule name and its associated targets or schedules.
|
||||
mitre_components:
|
||||
- Cloud Service Modification
|
||||
- Cloud Service Metadata
|
||||
- Scheduled Job Modification
|
||||
- Application Log Content
|
||||
source: aws_cloudtrail
|
||||
sourcetype: aws:cloudtrail
|
||||
separator: eventName
|
||||
separator_value: DeleteRule
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
@@ -101,7 +108,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "prin
|
||||
"111111111111", "eventCategory": "Management", "tlsDetails": {"tlsVersion": "TLSv1.2",
|
||||
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256", "clientProvidedHostHeader": "waf.amazonaws.com"}}'
|
||||
output_fields:
|
||||
- action
|
||||
- dest
|
||||
- user
|
||||
- user_agent
|
||||
|
||||
@@ -1,12 +1,19 @@
|
||||
name: AWS CloudTrail DeleteSnapshot
|
||||
id: b0731ac8-0992-4de8-b000-2c7d0fc2a61f
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
version: 2
|
||||
date: '2025-01-23'
|
||||
author: Bhavin Patel, Splunk
|
||||
description: Data source object for AWS CloudTrail DeleteSnapshot
|
||||
description: Logs the deletion of a cloud resource snapshot, such as an Amazon EBS
|
||||
snapshot, including details about the snapshot ID and associated resource.
|
||||
mitre_components:
|
||||
- Snapshot Deletion
|
||||
- Snapshot Metadata
|
||||
- Cloud Service Modification
|
||||
- Cloud Service Metadata
|
||||
source: aws_cloudtrail
|
||||
sourcetype: aws:cloudtrail
|
||||
separator: eventName
|
||||
separator_value: DeleteSnapshot
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
@@ -144,7 +151,6 @@ example_log: '{"eventVersion": "1.09", "userIdentity": {"type": "AssumedRole", "
|
||||
"managementEvent": true, "recipientAccountId": "11111111111111", "eventCategory":
|
||||
"Management", "sessionCredentialFromConsole": "true"}'
|
||||
output_fields:
|
||||
- action
|
||||
- dest
|
||||
- user
|
||||
- user_agent
|
||||
|
||||
@@ -1,12 +1,19 @@
|
||||
name: AWS CloudTrail DeleteTrail
|
||||
id: a5af09ff-07b6-4df6-92a0-2146bfe402c8
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
version: 2
|
||||
date: '2025-01-23'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for AWS CloudTrail DeleteTrail
|
||||
description: Logs the deletion of an AWS CloudTrail trail, including details about
|
||||
the trail name and its associated logging configurations.
|
||||
mitre_components:
|
||||
- Cloud Service Modification
|
||||
- Cloud Service Metadata
|
||||
- Application Log Content
|
||||
- Host Status
|
||||
source: aws_cloudtrail
|
||||
sourcetype: aws:cloudtrail
|
||||
separator: eventName
|
||||
separator_value: DeleteTrail
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
@@ -97,7 +104,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "prin
|
||||
"111111111111", "eventCategory": "Management", "tlsDetails": {"tlsVersion": "TLSv1.2",
|
||||
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256", "clientProvidedHostHeader": "cloudtrail.us-west-2.amazonaws.com"}}'
|
||||
output_fields:
|
||||
- action
|
||||
- dest
|
||||
- user
|
||||
- user_agent
|
||||
|
||||
@@ -1,12 +1,17 @@
|
||||
name: AWS CloudTrail DeleteVirtualMFADevice
|
||||
id: 84a08d6b-3d59-4260-8cab-84278ada262f
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
version: 2
|
||||
date: '2025-01-23'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for AWS CloudTrail DeleteVirtualMFADevice
|
||||
description: Logs an event when a virtual Multi-Factor Authentication (MFA) device
|
||||
is deleted in AWS CloudTrail.
|
||||
mitre_components:
|
||||
- User Account Authentication
|
||||
- User Account Deletion
|
||||
source: aws_cloudtrail
|
||||
sourcetype: aws:cloudtrail
|
||||
separator: eventName
|
||||
separator_value: DeleteVirtualMFADevice
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
@@ -99,7 +104,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "Root", "princip
|
||||
"managementEvent": true, "recipientAccountId": "111111111111", "eventCategory":
|
||||
"Management", "sessionCredentialFromConsole": "true"}'
|
||||
output_fields:
|
||||
- action
|
||||
- dest
|
||||
- user
|
||||
- user_agent
|
||||
|
||||
@@ -1,12 +1,17 @@
|
||||
name: AWS CloudTrail DeleteWebACL
|
||||
id: 90da5f08-7961-4c29-8de8-01364982aadf
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
version: 2
|
||||
date: '2025-01-23'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for AWS CloudTrail DeleteWebACL
|
||||
description: Logs an event when a Web Access Control List (WebACL) is deleted in AWS
|
||||
CloudTrail.
|
||||
mitre_components:
|
||||
- Cloud Service Modification
|
||||
- Cloud Service Metadata
|
||||
source: aws_cloudtrail
|
||||
sourcetype: aws:cloudtrail
|
||||
separator: eventName
|
||||
separator_value: DeleteWebACL
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
@@ -101,7 +106,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "prin
|
||||
"111111111111", "eventCategory": "Management", "tlsDetails": {"tlsVersion": "TLSv1.2",
|
||||
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256", "clientProvidedHostHeader": "waf.amazonaws.com"}}'
|
||||
output_fields:
|
||||
- action
|
||||
- dest
|
||||
- user
|
||||
- user_agent
|
||||
|
||||
@@ -1,12 +1,17 @@
|
||||
name: AWS CloudTrail DescribeEventAggregates
|
||||
id: 7efe4afe-62ae-4f96-81d1-76598ea37fc2
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
version: 2
|
||||
date: '2025-01-23'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for AWS CloudTrail DescribeEventAggregates
|
||||
description: Logs an event when aggregate details about AWS events are queried, often
|
||||
for analysis.
|
||||
mitre_components:
|
||||
- Cloud Service Enumeration
|
||||
- Cloud Service Metadata
|
||||
source: aws_cloudtrail
|
||||
sourcetype: aws:cloudtrail
|
||||
separator: eventName
|
||||
separator_value: DescribeEventAggregates
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
@@ -96,7 +101,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "Root", "princip
|
||||
"AwsApiCall", "managementEvent": true, "recipientAccountId": "1111111111111111", "eventCategory":
|
||||
"Management", "sessionCredentialFromConsole": "true"}'
|
||||
output_fields:
|
||||
- action
|
||||
- dest
|
||||
- user
|
||||
- user_agent
|
||||
|
||||
@@ -1,12 +1,18 @@
|
||||
name: AWS CloudTrail DescribeImageScanFindings
|
||||
id: 688ea789-9ba2-4970-90a2-17e541e273c9
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
version: 2
|
||||
date: '2025-01-23'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for AWS CloudTrail DescribeImageScanFindings
|
||||
description: Logs an event when findings from an image vulnerability scan are described
|
||||
using the DescribeImageScanFindings operation in AWS CloudTrail.
|
||||
mitre_components:
|
||||
- Image Metadata
|
||||
- Image Modification
|
||||
- Malware Metadata
|
||||
source: aws_cloudtrail
|
||||
sourcetype: aws:cloudtrail
|
||||
separator: eventName
|
||||
separator_value: DescribeImageScanFindings
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
@@ -112,15 +118,15 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "
|
||||
"accountId": "111111111111", "accessKeyId": "AKIAIOSFODNN7EXAMPLE", "sessionContext":
|
||||
{"sessionIssuer": {"type": "Role", "principalId": "AKIAIOSFODNN7EXAMPLE", "arn":
|
||||
"arn:aws:iam::111111111111:role/aws-reserved/test/region/group", "accountId": "111111111111",
|
||||
"userName": "test"}, "webIdFederationData": {}, "attributes": {"creationDate": "2021-08-11T09:42:53Z",
|
||||
"mfaAuthenticated": "false"}}}, "eventTime": "2021-08-11T11:52:27Z", "eventSource":
|
||||
"ecr.amazonaws.com", "eventName": "DescribeImageScanFindings", "awsRegion": "eu-central-1",
|
||||
"sourceIPAddress": "154.16.165.133", "userAgent": "aws-internal/3 aws-sdk-java/1.11.1030
|
||||
Linux/4.9.273-0.1.ac.226.84.332.metal1.x86_64 OpenJDK_64-Bit_Server_VM/25.302-b08
|
||||
"userName": "test"}, "webIdFederationData" : {}, "attributes": {"creationDate":
|
||||
"2021-08-11T09:42:53Z", "mfaAuthenticated": "false"}}}, "eventTime": "2021-08-11T11:52:27Z",
|
||||
"eventSource": "ecr.amazonaws.com", "eventName": "DescribeImageScanFindings", "awsRegion":
|
||||
"eu-central-1" , "sourceIPAddress": "154.16.165.133", "userAgent": "aws-internal/3
|
||||
aws-sdk-java/1.11.1030 Linux/4.9.273-0.1.ac.226.84.332.metal1.x86_64 OpenJDK_64-Bit_Server_VM/25.302-b08
|
||||
java/1.8.0_302 vendor/Oracle_Corporation cfg/retry-mode/legacy", "requestParameters":
|
||||
{"repositoryName": "devsecops/cat_dog_client", "imageId": {"imageDigest": "sha256:a27d73188718a511a1ec1ec788826674b21e097f29873dde734a4dedfbfab1c6"},
|
||||
"maxResults": 1000}, "responseElements": {"registryId": "111111111111", "repositoryName":
|
||||
"devsecops/cat_dog_client", "imageId": {"imageDigest": "sha256:a27d73188718a511a1ec1ec788826674b21e097f29873dde734a4dedfbfab1c6"},
|
||||
"devsecops/cat_dog_client", "imageId": {"imageDigest" : "sha256:a27d73188718a511a1ec1ec788826674b21e097f29873dde734a4dedfbfab1c6"},
|
||||
"imageScanStatus": {"status": "COMPLETE", "description": "The scan was completed
|
||||
successfully."}, "imageScanFindings": {"imageScanCompletedAt": "Aug 11, 2021, 11:30:16
|
||||
AM", "vulnerabilitySourceUpdatedAt": "Aug 11, 2021, 1:17:52 AM", "findings": [{"name":
|
||||
@@ -376,7 +382,7 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "
|
||||
able to disclose sensitive information or cause a denial of service condition on
|
||||
the client system when a user connects to the server.", "uri": "https://security-tracker.debian.org/tracker/CVE-2019-17498",
|
||||
"severity": "LOW", "attributes": [{"key": "package_version", "value": "1.8.0-2.1"},
|
||||
{"key": "package_name", "value": "libssh2"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:P/I:N/A:P"},
|
||||
{"key": "package_name", "value": "libssh2"}, {"key" : "CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:P/I:N/A:P"},
|
||||
{"key": "CVSS2_SCORE", "value": "5.8"}]}, {"name": "CVE-2019-17543", "description":
|
||||
"LZ4 before 1.9.2 has a heap-based buffer overflow in LZ4_write32 (related to LZ4_compress_destSize),
|
||||
affecting applications that call LZ4_compress_fast with a large input. (This issue
|
||||
@@ -409,7 +415,7 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "
|
||||
"AV:N/AC:L/Au:N/C:P/I:P/A:P"}, {"key": "CVSS2_SCORE", "value": "7.5"}]}, {"name":
|
||||
"CVE-2011-3374", "description": "It was found that apt-key in apt, all versions,
|
||||
do not correctly validate gpg keys with the master keyring, leading to a potential
|
||||
man-in-the-middle attack.", "uri": "https://security-tracker.debian.org/tracker/CVE-2011-3374",
|
||||
man-in-the-middle attack.", "uri" : "https://security-tracker.debian.org/tracker/CVE-2011-3374",
|
||||
"severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
|
||||
"1.8.2.3"}, {"key": "package_name", "value": "apt"}, {"key": "CVSS2_VECTOR", "value":
|
||||
"AV:N/AC:M/Au:N/C:N/I:P/A:N"}, {"key": "CVSS2_SCORE", "value": "4.3"}]}, {"name":
|
||||
@@ -564,7 +570,7 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "
|
||||
other artifacts of the database as we know that a Kerberos database dump file contains
|
||||
trusted data.", "uri": "https://security-tracker.debian.org/tracker/CVE-2018-5709",
|
||||
"severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
|
||||
"1.17-3+deb10u1"}, {"key": "package_name", "value": "krb5"}, {"key": "CVSS2_VECTOR",
|
||||
"1.17-3+deb10u1"}, {"key": "package_name", "value": "krb5"}, {"key" : "CVSS2_VECTOR",
|
||||
"value": "AV:N/AC:L/Au:N/C:N/I:P/A:N"}, {"key": "CVSS2_SCORE", "value": "5"}]},
|
||||
{"name": "CVE-2021-36222", "description": "ec_verify in kdc/kdc_preauth_ec.c in
|
||||
the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.18.4 and
|
||||
@@ -651,7 +657,7 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "
|
||||
"severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
|
||||
"1.1.32-2.2~deb10u1"}, {"key": "package_name", "value": "libxslt"}, {"key": "CVSS2_VECTOR",
|
||||
"value": "AV:N/AC:L/Au:N/C:P/I:N/A:N"}, {"key": "CVSS2_SCORE", "value": "5"}]},
|
||||
{"name": "CVE-2009-4487", "description": "nginx 0.7.64 writes data to a log file
|
||||
{"name": "CVE-2009-4487" , "description": "nginx 0.7.64 writes data to a log file
|
||||
without sanitizing non-printable characters, which might allow remote attackers
|
||||
to modify a window''s title, or possibly execute arbitrary commands or overwrite
|
||||
files, via an HTTP request containing an escape sequence for a terminal emulator.",
|
||||
@@ -666,7 +672,7 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "
|
||||
"severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
|
||||
"2.4.47+dfsg-3+deb10u6"}, {"key": "package_name", "value": "openldap"}, {"key":
|
||||
"CVSS2_VECTOR", "value": "AV:N/AC:H/Au:N/C:P/I:P/A:N"}, {"key": "CVSS2_SCORE", "value":
|
||||
"4"}]}, {"name": "CVE-2015-3276", "description": "The nss_parse_ciphers function
|
||||
"4"}]}, {"name": "CVE-2015-3276" , "description": "The nss_parse_ciphers function
|
||||
in libraries/libldap/tls_m.c in OpenLDAP does not properly parse OpenSSL-style multi-keyword
|
||||
mode cipher strings, which might cause a weaker than intended cipher to be used
|
||||
and allow remote attackers to have unspecified impact via unknown vectors.", "uri":
|
||||
@@ -689,7 +695,7 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "
|
||||
"severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
|
||||
"2.4.47+dfsg-3+deb10u6"}, {"key": "package_name", "value": "openldap"}, {"key":
|
||||
"CVSS2_VECTOR", "value": "AV:N/AC:L/Au:N/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value":
|
||||
"5"}]}, {"name": "CVE-2010-0928", "description": "OpenSSL 0.9.8i on the Gaisler
|
||||
"5"}]}, {"name": "CVE-2010-0928" , "description": "OpenSSL 0.9.8i on the Gaisler
|
||||
Research LEON3 SoC on the Xilinx Virtex-II Pro FPGA uses a Fixed Width Exponentiation
|
||||
(FWE) algorithm for certain signature calculations, and does not verify the signature
|
||||
before providing it to a caller, which makes it easier for physically proximate
|
||||
@@ -744,10 +750,10 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "
|
||||
"2:8.39-12"}, {"key": "package_name", "value": "pcre3"}, {"key": "CVSS2_VECTOR",
|
||||
"value": "AV:N/AC:L/Au:N/C:N/I:N/A:C"}, {"key": "CVSS2_SCORE", "value": "7.8"}]},
|
||||
{"name": "CVE-2011-4116", "description": "_is_safe in the File::Temp module for
|
||||
Perl does not properly handle symlinks.", "uri": "https://security-tracker.debian.org/tracker/CVE-2011-4116",
|
||||
Perl does not properly handle symlinks.", "uri" : "https://security-tracker.debian.org/tracker/CVE-2011-4116",
|
||||
"severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
|
||||
"5.28.1-6+deb10u1"}, {"key": "package_name", "value": "perl"}, {"key": "CVSS2_VECTOR",
|
||||
"value": "AV:N/AC:L/Au:N/C:N/I:P/A:N"}, {"key": "CVSS2_SCORE", "value": "5"}]},
|
||||
"5.28.1-6+deb10u1"}, {"key": "package_name", "value": "perl"}, {"key": "CVSS2_VECTOR"
|
||||
, "value": "AV:N/AC:L/Au:N/C:N/I:P/A:N"}, {"key": "CVSS2_SCORE", "value": "5"}]},
|
||||
{"name": "CVE-2019-19882", "description": "shadow 4.8, in certain circumstances
|
||||
affecting at least Gentoo, Arch Linux, and Void Linux, allows local users to obtain
|
||||
root access because setuid programs are misconfigured. Specifically, this affects
|
||||
@@ -771,8 +777,8 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "
|
||||
"1:4.5-1.1"}, {"key": "package_name", "value": "shadow"}, {"key": "CVSS2_VECTOR",
|
||||
"value": "AV:L/AC:L/Au:N/C:C/I:N/A:N"}, {"key": "CVSS2_SCORE", "value": "4.9"}]},
|
||||
{"name": "CVE-2013-4235", "description": "shadow: TOCTOU (time-of-check time-of-use)
|
||||
race condition when copying and removing directory trees", "uri": "https://security-tracker.debian.org/tracker/CVE-2013-4235",
|
||||
"severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
|
||||
race condition when copying and removing directory trees", "uri": "https://security-tracker.debian.org/tracker/CVE-2013-4235"
|
||||
, "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
|
||||
"1:4.5-1.1"}, {"key": "package_name", "value": "shadow"}, {"key": "CVSS2_VECTOR",
|
||||
"value": "AV:L/AC:M/Au:N/C:N/I:P/A:P"}, {"key": "CVSS2_SCORE", "value": "3.3"}]},
|
||||
{"name": "CVE-2020-13529", "description": "An exploitable denial-of-service vulnerability
|
||||
@@ -817,7 +823,7 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "
|
||||
{"name": "CVE-2021-20193", "description": "A flaw was found in the src/list.c of
|
||||
tar 1.33 and earlier. This flaw allows an attacker who can submit a crafted input
|
||||
file to tar to cause uncontrolled consumption of memory. The highest threat from
|
||||
this vulnerability is to system availability.", "uri": "https://security-tracker.debian.org/tracker/CVE-2021-20193",
|
||||
this vulnerability is to system availability." , "uri": "https://security-tracker.debian.org/tracker/CVE-2021-20193",
|
||||
"severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
|
||||
"1.30+dfsg-6"}, {"key": "package_name", "value": "tar"}, {"key": "CVSS2_VECTOR",
|
||||
"value": "AV:N/AC:M/Au:N/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value": "4.3"}]},
|
||||
@@ -839,19 +845,19 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "
|
||||
crafted TIFF image that is mishandled by the TIFFWriteScanline function in tif_write.c,
|
||||
as demonstrated by tiffdither.", "uri": "https://security-tracker.debian.org/tracker/CVE-2014-8130",
|
||||
"severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
|
||||
"4.1.0+git191117-2~deb10u2"}, {"key": "package_name", "value": "tiff"}, {"key":
|
||||
"4.1.0+git191117-2~deb10u2"}, {"key": "package_name", "value": "tiff" }, {"key":
|
||||
"CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value":
|
||||
"4.3"}]}, {"name": "CVE-2017-5563", "description": "LibTIFF version 4.0.7 is vulnerable
|
||||
to a heap-based buffer over-read in tif_lzw.c resulting in DoS or code execution
|
||||
via a crafted bmp image to tools/bmp2tiff.", "uri": "https://security-tracker.debian.org/tracker/CVE-2017-5563",
|
||||
via a crafted bmp image to tools/bmp2tiff." , "uri": "https://security-tracker.debian.org/tracker/CVE-2017-5563",
|
||||
"severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
|
||||
"4.1.0+git191117-2~deb10u2"}, {"key": "package_name", "value": "tiff"}, {"key":
|
||||
"4.1.0+git191117-2~deb10u2"}, {"key": "package_name", "value": "tiff" }, {"key":
|
||||
"CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:P/I:P/A:P"}, {"key": "CVSS2_SCORE", "value":
|
||||
"6.8"}]}, {"name": "CVE-2020-35522", "description": "In LibTIFF, there is a memory
|
||||
malloc failure in tif_pixarlog.c. A crafted TIFF document can lead to an abort,
|
||||
resulting in a remote denial of service attack.", "uri": "https://security-tracker.debian.org/tracker/CVE-2020-35522",
|
||||
"severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
|
||||
"4.1.0+git191117-2~deb10u2"}, {"key": "package_name", "value": "tiff"}, {"key":
|
||||
"4.1.0+git191117-2~deb10u2"}, {"key": "package_name", "value": "tiff" }, {"key":
|
||||
"CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value":
|
||||
"4.3"}]}, {"name": "CVE-2017-9117", "description": "In LibTIFF 4.0.7, the program
|
||||
processes BMP images without verifying that biWidth and biHeight in the bitmap-information
|
||||
@@ -881,7 +887,7 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "
|
||||
comparison also didn''t include the ''issuer cert'' which a transfer can setto qualify
|
||||
how to verify the server certificate.", "uri": "https://security-tracker.debian.org/tracker/CVE-2021-22924",
|
||||
"severity": "UNDEFINED", "attributes": [{"key": "package_version", "value": "7.64.0-4+deb10u2"},
|
||||
{"key": "package_name", "value": "curl"}]}, {"name": "CVE-2021-38115", "description":
|
||||
{"key": "package_name", "value": "curl" }]}, {"name": "CVE-2021-38115", "description":
|
||||
"read_header_tga in gd_tga.c in the GD Graphics Library (aka LibGD) through 2.3.2
|
||||
allows remote attackers to cause a denial of service (out-of-bounds read) via a
|
||||
crafted TGA file.", "uri": "https://security-tracker.debian.org/tracker/CVE-2021-38115",
|
||||
@@ -894,7 +900,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "
|
||||
"readOnly": true, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId":
|
||||
"111111111111", "eventCategory": "Management"}'
|
||||
output_fields:
|
||||
- action
|
||||
- dest
|
||||
- user
|
||||
- user_agent
|
||||
|
||||
@@ -1,12 +1,17 @@
|
||||
name: AWS CloudTrail GetAccountPasswordPolicy
|
||||
id: 439bdc53-6e4b-4cd7-b326-86c7317fd396
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
version: 2
|
||||
date: '2025-01-23'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for AWS CloudTrail GetAccountPasswordPolicy
|
||||
description: Logs an event when a request is made to get the account password policy
|
||||
in AWS CloudTrail.
|
||||
mitre_components:
|
||||
- User Account Authentication
|
||||
- User Account Metadata
|
||||
source: aws_cloudtrail
|
||||
sourcetype: aws:cloudtrail
|
||||
separator: eventName
|
||||
separator_value: GetAccountPasswordPolicy
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
@@ -98,7 +103,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "prin
|
||||
"111111111111", "eventCategory": "Management", "tlsDetails": {"tlsVersion": "TLSv1.2",
|
||||
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256", "clientProvidedHostHeader": "iam.amazonaws.com"}}'
|
||||
output_fields:
|
||||
- action
|
||||
- dest
|
||||
- user
|
||||
- user_agent
|
||||
|
||||
@@ -1,12 +1,18 @@
|
||||
name: AWS CloudTrail GetObject
|
||||
id: 5063cb10-84c0-44af-ade4-ab9ecad11dfe
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
version: 2
|
||||
date: '2025-01-23'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for AWS CloudTrail GetObject
|
||||
description: Logs an event when a request is made to access an object stored in an
|
||||
AWS S3 bucket.
|
||||
mitre_components:
|
||||
- Cloud Storage Access
|
||||
- Cloud Storage Metadata
|
||||
- Cloud Storage Enumeration
|
||||
source: aws_cloudtrail
|
||||
sourcetype: aws:cloudtrail
|
||||
separator: eventName
|
||||
separator_value: GetObject
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
@@ -112,7 +118,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "prin
|
||||
"eventCategory": "Data", "tlsDetails": {"tlsVersion": "TLSv1.2", "cipherSuite":
|
||||
"ECDHE-RSA-AES128-GCM-SHA256", "clientProvidedHostHeader": "security-content.s3.us-west-2.amazonaws.com"}}'
|
||||
output_fields:
|
||||
- action
|
||||
- dest
|
||||
- user
|
||||
- user_agent
|
||||
|
||||
@@ -1,12 +1,17 @@
|
||||
name: AWS CloudTrail GetPasswordData
|
||||
id: 6ff2ce99-85b1-4c17-888a-56dbc3570671
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
version: 2
|
||||
date: '2025-01-23'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for AWS CloudTrail GetPasswordData
|
||||
description: Logs an event when a request is made to retrieve the administrator password
|
||||
of an EC2 instance.
|
||||
mitre_components:
|
||||
- Instance Metadata
|
||||
- User Account Authentication
|
||||
source: aws_cloudtrail
|
||||
sourcetype: aws:cloudtrail
|
||||
separator: eventName
|
||||
separator_value: GetPasswordData
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
@@ -114,7 +119,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "
|
||||
"111111111111", "eventCategory": "Management", "tlsDetails": {"tlsVersion": "TLSv1.2",
|
||||
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256", "clientProvidedHostHeader": "ec2.us-west-2.amazonaws.com"}}'
|
||||
output_fields:
|
||||
- action
|
||||
- dest
|
||||
- user
|
||||
- user_agent
|
||||
|
||||
@@ -1,12 +1,16 @@
|
||||
name: AWS CloudTrail JobCreated
|
||||
id: 6473289b-d097-4c86-a837-3cc5ae408155
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
version: 2
|
||||
date: '2025-01-23'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for AWS CloudTrail JobCreated
|
||||
description: Logs an event when a new job is created in AWS CloudTrail.
|
||||
mitre_components:
|
||||
- Scheduled Job Creation
|
||||
- Cloud Service Metadata
|
||||
source: aws_cloudtrail
|
||||
sourcetype: aws:cloudtrail
|
||||
separator: eventName
|
||||
separator_value: JobCreated
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
@@ -83,7 +87,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"accountId": "1111111111
|
||||
"status": "New", "jobEventId": "4e70d2f1053c07a79d9be9a14e486020", "failureCodes":
|
||||
[], "statusChangeReason": []}, "eventCategory": "Management"}'
|
||||
output_fields:
|
||||
- action
|
||||
- dest
|
||||
- user
|
||||
- user_agent
|
||||
|
||||
@@ -1,12 +1,18 @@
|
||||
name: AWS CloudTrail ModifyDBInstance
|
||||
id: bfa2912d-1a33-4b05-be46-543874d68241
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
version: 2
|
||||
date: '2025-01-23'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for AWS CloudTrail ModifyDBInstance
|
||||
description: Logs an event when a modification is made to an AWS database instance,
|
||||
such as parameters or configurations.
|
||||
mitre_components:
|
||||
- Instance Modification
|
||||
- Cloud Service Modification
|
||||
- Instance Metadata
|
||||
source: aws_cloudtrail
|
||||
sourcetype: aws:cloudtrail
|
||||
separator: eventName
|
||||
separator_value: ModifyDBInstance
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
@@ -192,7 +198,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "
|
||||
"AwsApiCall", "managementEvent": true, "recipientAccountId": "111111111111", "eventCategory":
|
||||
"Management", "sessionCredentialFromConsole": "true"}'
|
||||
output_fields:
|
||||
- action
|
||||
- dest
|
||||
- user
|
||||
- user_agent
|
||||
|
||||
@@ -1,12 +1,17 @@
|
||||
name: AWS CloudTrail ModifyImageAttribute
|
||||
id: 667c2115-8082-419e-b541-8150066bda4d
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
version: 2
|
||||
date: '2025-01-23'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for AWS CloudTrail ModifyImageAttribute
|
||||
description: Logs an event when the attributes of an Amazon Machine Image (AMI) are
|
||||
modified.
|
||||
mitre_components:
|
||||
- Image Modification
|
||||
- Image Metadata
|
||||
source: aws_cloudtrail
|
||||
sourcetype: aws:cloudtrail
|
||||
separator: eventName
|
||||
separator_value: ModifyImageAttribute
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
@@ -107,7 +112,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "
|
||||
"AwsApiCall", "managementEvent": true, "recipientAccountId": "111111111111", "eventCategory":
|
||||
"Management", "sessionCredentialFromConsole": "true"}'
|
||||
output_fields:
|
||||
- action
|
||||
- dest
|
||||
- user
|
||||
- user_agent
|
||||
|
||||
@@ -1,12 +1,16 @@
|
||||
name: AWS CloudTrail ModifySnapshotAttribute
|
||||
id: 7e5aa947-3a0d-4ee5-b800-0c10b555da05
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
version: 2
|
||||
date: '2025-01-23'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for AWS CloudTrail ModifySnapshotAttribute
|
||||
description: Logs an event when modifications are made to the attributes of a snapshot
|
||||
in AWS CloudTrail.
|
||||
mitre_components:
|
||||
- Snapshot Modification
|
||||
source: aws_cloudtrail
|
||||
sourcetype: aws:cloudtrail
|
||||
separator: eventName
|
||||
separator_value: ModifySnapshotAttribute
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
@@ -100,7 +104,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "prin
|
||||
"111111111111", "eventCategory": "Management", "tlsDetails": {"tlsVersion": "TLSv1.2",
|
||||
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256", "clientProvidedHostHeader": "ec2.us-west-2.amazonaws.com"}}'
|
||||
output_fields:
|
||||
- action
|
||||
- dest
|
||||
- user
|
||||
- user_agent
|
||||
|
||||
@@ -1,12 +1,17 @@
|
||||
name: AWS CloudTrail PutBucketAcl
|
||||
id: 28fffbfd-d98d-4a42-990b-b04ab47422eb
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
version: 2
|
||||
date: '2025-01-23'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for AWS CloudTrail PutBucketAcl
|
||||
description: Logs an event when an ACL is set or modified for an S3 bucket in AWS
|
||||
CloudTrail.
|
||||
mitre_components:
|
||||
- Cloud Storage Modification
|
||||
- Cloud Storage Metadata
|
||||
source: aws_cloudtrail
|
||||
sourcetype: aws:cloudtrail
|
||||
separator: eventName
|
||||
separator_value: PutBucketAcl
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
@@ -115,7 +120,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "prin
|
||||
"ARN": "arn:aws:s3:::patricktestbucket19"}], "eventType": "AwsApiCall", "managementEvent":
|
||||
true, "eventCategory": "Management", "recipientAccountId": "111111111111"}'
|
||||
output_fields:
|
||||
- action
|
||||
- dest
|
||||
- user
|
||||
- user_agent
|
||||
|
||||
@@ -1,12 +1,17 @@
|
||||
name: AWS CloudTrail PutBucketLifecycle
|
||||
id: 1c73e954-87b6-4bd7-ac6a-5db7c4082b22
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
version: 2
|
||||
date: '2025-01-23'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for AWS CloudTrail PutBucketLifecycle
|
||||
description: Logs an event when a lifecycle configuration is added to an S3 bucket
|
||||
in AWS CloudTrail.
|
||||
mitre_components:
|
||||
- Cloud Storage Modification
|
||||
- Cloud Storage Metadata
|
||||
source: aws_cloudtrail
|
||||
sourcetype: aws:cloudtrail
|
||||
separator: eventName
|
||||
separator_value: PutBucketLifecycle
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
@@ -119,7 +124,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "prin
|
||||
"Management", "tlsDetails": {"tlsVersion": "TLSv1.2", "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
|
||||
"clientProvidedHostHeader": "my-cloudtrail-bucket-alfsujjpnbpguqrh.s3.us-west-2.amazonaws.com"}}'
|
||||
output_fields:
|
||||
- action
|
||||
- dest
|
||||
- user
|
||||
- user_agent
|
||||
|
||||
@@ -1,12 +1,16 @@
|
||||
name: AWS CloudTrail PutBucketReplication
|
||||
id: 0e1362eb-e592-419f-8fa5-556d3a122417
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
version: 2
|
||||
date: '2025-01-23'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for AWS CloudTrail PutBucketReplication
|
||||
description: Logs an event when replication configurations are added or modified for
|
||||
an S3 bucket.
|
||||
mitre_components:
|
||||
- Cloud Storage Modification
|
||||
source: aws_cloudtrail
|
||||
sourcetype: aws:cloudtrail
|
||||
separator: eventName
|
||||
separator_value: PutBucketReplication
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
@@ -140,7 +144,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "
|
||||
"Management", "tlsDetails": {"tlsVersion": "TLSv1.2", "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
|
||||
"clientProvidedHostHeader": "s3.us-west-2.amazonaws.com"}}'
|
||||
output_fields:
|
||||
- action
|
||||
- dest
|
||||
- user
|
||||
- user_agent
|
||||
|
||||
@@ -1,12 +1,16 @@
|
||||
name: AWS CloudTrail PutBucketVersioning
|
||||
id: 17b2fc7d-c8ce-487c-8815-f9a65a09e980
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
version: 2
|
||||
date: '2025-01-23'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for AWS CloudTrail PutBucketVersioning
|
||||
description: Logs an event when the bucket versioning state is modified in an AWS
|
||||
S3 bucket.
|
||||
mitre_components:
|
||||
- Cloud Storage Modification
|
||||
source: aws_cloudtrail
|
||||
sourcetype: aws:cloudtrail
|
||||
separator: eventName
|
||||
separator_value: PutBucketVersioning
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
@@ -128,7 +132,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "
|
||||
"Management", "tlsDetails": {"tlsVersion": "TLSv1.2", "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
|
||||
"clientProvidedHostHeader": "s3.us-west-2.amazonaws.com"}}'
|
||||
output_fields:
|
||||
- action
|
||||
- dest
|
||||
- user
|
||||
- user_agent
|
||||
|
||||
@@ -1,12 +1,17 @@
|
||||
name: AWS CloudTrail PutImage
|
||||
id: bb13f10d-0d8c-4fde-9136-b7cfd930e87c
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
version: 2
|
||||
date: '2025-01-23'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for AWS CloudTrail PutImage
|
||||
description: Logs an event when a container image is uploaded to a repository in AWS
|
||||
CloudTrail.
|
||||
mitre_components:
|
||||
- Image Creation
|
||||
- Image Metadata
|
||||
source: aws_cloudtrail
|
||||
sourcetype: aws:cloudtrail
|
||||
separator: eventName
|
||||
separator_value: PutImage
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
@@ -150,8 +155,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "prin
|
||||
"eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId": "111111111111",
|
||||
"eventCategory": "Management"}'
|
||||
output_fields:
|
||||
- action
|
||||
- dest
|
||||
- user
|
||||
- user_agent
|
||||
- src
|
||||
|
||||
@@ -1,9 +1,10 @@
|
||||
name: AWS CloudTrail PutKeyPolicy
|
||||
id: 9c54c86b-43b9-4bb8-915d-6838beb7f07c
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
version: 2
|
||||
date: '2025-01-23'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for AWS CloudTrail PutKeyPolicy
|
||||
description: Logs changes made to AWS Key Management Service (KMS) key policies, including
|
||||
updates and permission assignments.
|
||||
source: aws_cloudtrail
|
||||
sourcetype: aws:cloudtrail
|
||||
separator: eventName
|
||||
@@ -94,6 +95,8 @@ fields:
|
||||
- vendor_account
|
||||
- vendor_product
|
||||
- vendor_region
|
||||
mitre_components:
|
||||
- Cloud Service Modification
|
||||
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "principalId":
|
||||
"AROAIJIESMXKGCJRCTPR6:pbareiss@splunk.local", "arn": "arn:aws:sts::111111111111:assumed-role/okta_adm_role/pbareiss@splunk.local",
|
||||
"accountId": "111111111111", "accessKeyId": "ASIAYTOGP2RLK74OPBDR", "sessionContext":
|
||||
@@ -131,7 +134,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "
|
||||
"eventType": "AwsApiCall", "managementEvent": true, "eventCategory": "Management",
|
||||
"recipientAccountId": "111111111111"}'
|
||||
output_fields:
|
||||
- action
|
||||
- dest
|
||||
- user
|
||||
- user_agent
|
||||
|
||||
@@ -1,12 +1,16 @@
|
||||
name: AWS CloudTrail ReplaceNetworkAclEntry
|
||||
id: db0c240e-3754-40e4-86ef-cde018ee9f65
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
version: 2
|
||||
date: '2025-01-23'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for AWS CloudTrail ReplaceNetworkAclEntry
|
||||
description: Logs an event when a network ACL entry is replaced within the AWS CloudTrail.
|
||||
mitre_components:
|
||||
- Firewall Rule Modification
|
||||
- Cloud Service Modification
|
||||
source: aws_cloudtrail
|
||||
sourcetype: aws:cloudtrail
|
||||
separator: eventName
|
||||
separator_value: ReplaceNetworkAclEntry
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
@@ -117,7 +121,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "
|
||||
"46fe04b8-d007-4933-8bb8-c8b65c1121fa", "readOnly": false, "eventType": "AwsApiCall",
|
||||
"managementEvent": true, "eventCategory": "Management", "recipientAccountId": "111111111111"}'
|
||||
output_fields:
|
||||
- action
|
||||
- dest
|
||||
- user
|
||||
- user_agent
|
||||
|
||||
@@ -1,12 +1,17 @@
|
||||
name: AWS CloudTrail SetDefaultPolicyVersion
|
||||
id: 06e0b5a0-8d36-485e-befc-4ae79d77ef6c
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
version: 2
|
||||
date: '2025-01-23'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for AWS CloudTrail SetDefaultPolicyVersion
|
||||
description: Logs an event when the default version of a resource policy in AWS is
|
||||
set or changed.
|
||||
mitre_components:
|
||||
- Cloud Service Modification
|
||||
- Cloud Service Metadata
|
||||
source: aws_cloudtrail
|
||||
sourcetype: aws:cloudtrail
|
||||
separator: eventName
|
||||
separator_value: SetDefaultPolicyVersion
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
@@ -98,7 +103,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "prin
|
||||
"AwsApiCall", "managementEvent": true, "eventCategory": "Management", "recipientAccountId":
|
||||
"111111111111"}'
|
||||
output_fields:
|
||||
- action
|
||||
- dest
|
||||
- user
|
||||
- user_agent
|
||||
|
||||
@@ -1,12 +1,16 @@
|
||||
name: AWS CloudTrail StopLogging
|
||||
id: c5de7c54-4809-4659-bf9f-3bacf8bdfd35
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
version: 2
|
||||
date: '2025-01-23'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for AWS CloudTrail StopLogging
|
||||
description: Logs an event when a cloud service in AWS, such as CloudTrail, is deactivated
|
||||
or stopped.
|
||||
mitre_components:
|
||||
- Cloud Service Disable
|
||||
source: aws_cloudtrail
|
||||
sourcetype: aws:cloudtrail
|
||||
separator: eventName
|
||||
separator_value: StopLogging
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
@@ -94,7 +98,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "prin
|
||||
"Management", "tlsDetails": {"tlsVersion": "TLSv1.2", "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
|
||||
"clientProvidedHostHeader": "cloudtrail.us-west-2.amazonaws.com"}}'
|
||||
output_fields:
|
||||
- action
|
||||
- dest
|
||||
- user
|
||||
- user_agent
|
||||
|
||||
@@ -1,12 +1,16 @@
|
||||
name: AWS CloudTrail UpdateAccountPasswordPolicy
|
||||
id: 35a8cc97-3600-40e1-a5d1-1c2ad5060be0
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
version: 2
|
||||
date: '2025-01-23'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for AWS CloudTrail UpdateAccountPasswordPolicy
|
||||
description: Logs an event when an AWS account's password policy is updated.
|
||||
mitre_components:
|
||||
- User Account Modification
|
||||
- Cloud Service Modification
|
||||
source: aws_cloudtrail
|
||||
sourcetype: aws:cloudtrail
|
||||
separator: eventName
|
||||
separator_value: UpdateAccountPasswordPolicy
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
@@ -106,7 +110,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "Root", "princip
|
||||
"readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId":
|
||||
"111111111111", "eventCategory": "Management", "sessionCredentialFromConsole": "true"}'
|
||||
output_fields:
|
||||
- action
|
||||
- dest
|
||||
- user
|
||||
- user_agent
|
||||
|
||||
@@ -1,12 +1,16 @@
|
||||
name: AWS CloudTrail UpdateLoginProfile
|
||||
id: 1db79158-e5d3-4d35-9d3c-586e44e09f1c
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
version: 2
|
||||
date: '2025-01-23'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for AWS CloudTrail UpdateLoginProfile
|
||||
description: Logs an event when an IAM user's login profile is updated.
|
||||
mitre_components:
|
||||
- User Account Modification
|
||||
- User Account Authentication
|
||||
source: aws_cloudtrail
|
||||
sourcetype: aws:cloudtrail
|
||||
separator: eventName
|
||||
separator_value: UpdateLoginProfile
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
@@ -96,7 +100,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "prin
|
||||
"readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "eventCategory":
|
||||
"Management", "recipientAccountId": "111111111111"}'
|
||||
output_fields:
|
||||
- action
|
||||
- dest
|
||||
- user
|
||||
- user_agent
|
||||
|
||||
@@ -1,12 +1,17 @@
|
||||
name: AWS CloudTrail UpdateSAMLProvider
|
||||
id: e5eb628d-711e-499c-87d9-8fa5dee419ec
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
version: 2
|
||||
date: '2025-01-23'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for AWS CloudTrail UpdateSAMLProvider
|
||||
description: Logs an event when a SAML provider is updated in AWS.
|
||||
mitre_components:
|
||||
- Cloud Service Modification
|
||||
- User Account Modification
|
||||
- Cloud Service Metadata
|
||||
source: aws_cloudtrail
|
||||
sourcetype: aws:cloudtrail
|
||||
separator: eventName
|
||||
separator_value: UpdateSAMLProvider
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
@@ -96,7 +101,7 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "
|
||||
"AROAYTOGP2RLKFUVAQAIJ:rodsoto@rodsoto.onmicrosoft.com", "arn": "arn:aws:sts::111111111111:assumed-role/rodonmicrotestrole/rodsoto@rodsoto.onmicrosoft.com",
|
||||
"accountId": "111111111111", "accessKeyId": "ASIAYTOGP2RLMZGPIW6C", "sessionContext":
|
||||
{"sessionIssuer": {"type": "Role", "principalId": "AROAYTOGP2RLKFUVAQAIJ", "arn":
|
||||
"arn:aws:iam::111111111111:role/rodonmicrotestrole", "accountId": "111111111111",
|
||||
"arn:aws:iam::111111111111:role/rodonmicrotestrole", "accountId" : "111111111111",
|
||||
"userName": "rodonmicrotestrole"}, "webIdFederationData": {}, "attributes": {"mfaAuthenticated":
|
||||
"false", "creationDate": "2021-01-20T03:10:32Z"}}}, "eventTime": "2021-01-20T03:12:39Z",
|
||||
"eventSource": "iam.amazonaws.com", "eventName": "UpdateSAMLProvider", "awsRegion":
|
||||
@@ -186,7 +191,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "
|
||||
"readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "eventCategory":
|
||||
"Management", "recipientAccountId": "111111111111"}'
|
||||
output_fields:
|
||||
- action
|
||||
- dest
|
||||
- user
|
||||
- user_agent
|
||||
|
||||
@@ -1,12 +1,17 @@
|
||||
name: AWS CloudTrail UpdateTrail
|
||||
id: d5b7a1eb-711a-4c96-aa93-235fe3c8a939
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
version: 2
|
||||
date: '2025-01-23'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for AWS CloudTrail UpdateTrail
|
||||
description: Logs an event when an AWS CloudTrail trail is updated, typically involving
|
||||
changes to settings or configuration.
|
||||
mitre_components:
|
||||
- Cloud Service Modification
|
||||
- Cloud Service Metadata
|
||||
source: aws_cloudtrail
|
||||
sourcetype: aws:cloudtrail
|
||||
separator: eventName
|
||||
separator_value: UpdateTrail
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
@@ -106,7 +111,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "prin
|
||||
"Management", "tlsDetails": {"tlsVersion": "TLSv1.2", "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
|
||||
"clientProvidedHostHeader": "cloudtrail.us-west-2.amazonaws.com"}}'
|
||||
output_fields:
|
||||
- action
|
||||
- dest
|
||||
- user
|
||||
- user_agent
|
||||
|
||||
@@ -1,12 +1,16 @@
|
||||
name: AWS CloudWatchLogs VPCflow
|
||||
id: 38a34fc4-e128-4478-a8f4-7835d51d5135
|
||||
version: 1
|
||||
version: 2
|
||||
author: Bhavin Patel, Splunk
|
||||
date: '2024-07-18'
|
||||
description: Data source object for AWS CloudWatchLogs VPCflow
|
||||
date: '2025-01-23'
|
||||
description: Logs an event when network traffic flow information such as source and
|
||||
destination IPs, ports, protocol, and action (allow/deny) is captured for VPC in
|
||||
AWS.
|
||||
mitre_components:
|
||||
- Network Traffic Flow
|
||||
- Network Connection Creation
|
||||
source: aws_cloudwatchlogs_vpcflow
|
||||
sourcetype: aws:cloudwatchlogs:vpcflow
|
||||
separator: eventName
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for AWS
|
||||
version: 7.9.1
|
||||
|
||||
@@ -1,9 +1,15 @@
|
||||
name: AWS Security Hub
|
||||
id: b02bfbf3-294f-478e-99a1-e24b8c692d7e
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
version: 2
|
||||
date: '2025-01-23'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for AWS Security Hub
|
||||
description: Logs an event when AWS Security Hub identifies potential security risks
|
||||
or deviations from configured best practices across AWS accounts.
|
||||
mitre_components:
|
||||
- Cloud Service Metadata
|
||||
- Cloud Service Enumeration
|
||||
- Cloud Service Modification
|
||||
- Cloud Service Disable
|
||||
source: aws_securityhub_finding
|
||||
sourcetype: aws:securityhub:finding
|
||||
supported_TA:
|
||||
|
||||
@@ -3,7 +3,7 @@ id: 51ca21e5-bda2-4652-bb29-27c7bc18a81c
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for Azure Active Directory
|
||||
description: All Azure Active Directory events
|
||||
source: Azure AD
|
||||
sourcetype: azure:monitor:aad
|
||||
separator: operationName
|
||||
|
||||
+11
-4
@@ -1,13 +1,20 @@
|
||||
name: Azure Active Directory Add app role assignment to service principal
|
||||
id: 8b2e84cd-6db0-47e9-badc-75c17df1995f
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
version: 2
|
||||
date: '2025-01-23'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for Azure Active Directory Add app role assignment
|
||||
to service principal
|
||||
description: Logs the addition of an application role assignment to a service principal
|
||||
in Azure Active Directory, including details about the role, service principal,
|
||||
and the user or process performing the action.
|
||||
mitre_components:
|
||||
- User Account Modification
|
||||
- Group Modification
|
||||
- Cloud Service Modification
|
||||
- Cloud Service Metadata
|
||||
source: Azure AD
|
||||
sourcetype: azure:monitor:aad
|
||||
separator: operationName
|
||||
separator_value: Add app role assignment to service principal
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Cloud Services
|
||||
url: https://splunkbase.splunk.com/app/3110
|
||||
|
||||
@@ -1,12 +1,20 @@
|
||||
name: Azure Active Directory Add member to role
|
||||
id: 1660d196-127f-4678-81b2-472d51711b07
|
||||
version: 1
|
||||
date: "2024-07-18"
|
||||
version: 2
|
||||
date: '2025-01-23'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for Azure Active Directory Add member to role
|
||||
description: Logs the addition of a member to a directory role in Azure Active Directory,
|
||||
including details about the role, the member added, and the user or process performing
|
||||
the action.
|
||||
mitre_components:
|
||||
- Group Modification
|
||||
- Group Metadata
|
||||
- User Account Metadata
|
||||
- Cloud Service Modification
|
||||
source: Azure AD
|
||||
sourcetype: azure:monitor:aad
|
||||
separator: operationName
|
||||
separator_value: Add member to role
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Cloud Services
|
||||
url: https://splunkbase.splunk.com/app/3110
|
||||
|
||||
@@ -1,12 +1,20 @@
|
||||
name: Azure Active Directory Add owner to application
|
||||
id: e895ed56-7be4-4b3a-b782-ecd0f594ec4c
|
||||
version: 1
|
||||
date: "2024-07-18"
|
||||
version: 2
|
||||
date: '2025-01-23'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for Azure Active Directory Add owner to application
|
||||
description: Logs the addition of an owner to an application in Azure Active Directory,
|
||||
including details about the application, the owner added, and the user or process
|
||||
performing the action.
|
||||
mitre_components:
|
||||
- User Account Modification
|
||||
- Group Modification
|
||||
- Cloud Service Modification
|
||||
- Cloud Service Metadata
|
||||
source: Azure AD
|
||||
sourcetype: azure:monitor:aad
|
||||
separator: operationName
|
||||
separator_value: Add owner to application
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Cloud Services
|
||||
url: https://splunkbase.splunk.com/app/3110
|
||||
|
||||
@@ -1,12 +1,20 @@
|
||||
name: Azure Active Directory Add service principal
|
||||
id: fd89d337-e4c0-4162-ad13-bca36f096fe6
|
||||
version: 1
|
||||
date: "2024-07-18"
|
||||
version: 2
|
||||
date: '2025-01-23'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for Azure Active Directory Add service principal
|
||||
description: Logs the creation of a new service principal in Azure Active Directory,
|
||||
including details about the service principal, associated application, and the user
|
||||
or process performing the action.
|
||||
mitre_components:
|
||||
- Cloud Service Creation
|
||||
- Cloud Service Metadata
|
||||
- User Account Metadata
|
||||
- Active Directory Object Creation
|
||||
source: Azure AD
|
||||
sourcetype: azure:monitor:aad
|
||||
separator: operationName
|
||||
separator_value: Add service principal
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Cloud Services
|
||||
url: https://splunkbase.splunk.com/app/3110
|
||||
|
||||
@@ -1,12 +1,19 @@
|
||||
name: Azure Active Directory Add unverified domain
|
||||
id: d4c01fb1-3b88-46d3-bd12-9b9e256450f7
|
||||
version: 1
|
||||
date: "2024-07-18"
|
||||
version: 2
|
||||
date: '2025-01-23'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for Azure Active Directory Add unverified domain
|
||||
description: Logs the addition of an unverified domain to Azure Active Directory,
|
||||
including details about the domain name and the user or process performing the action.
|
||||
mitre_components:
|
||||
- Domain Registration
|
||||
- Cloud Service Modification
|
||||
- Cloud Service Metadata
|
||||
- Configuration Modification
|
||||
source: Azure AD
|
||||
sourcetype: azure:monitor:aad
|
||||
separator: operationName
|
||||
separator_value: Add unverified domain
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Cloud Services
|
||||
url: https://splunkbase.splunk.com/app/3110
|
||||
|
||||
@@ -1,12 +1,20 @@
|
||||
name: Azure Active Directory Consent to application
|
||||
id: 4c5d6c49-53e3-4980-a4de-c63e26291ed0
|
||||
version: 1
|
||||
date: "2024-07-18"
|
||||
version: 2
|
||||
date: '2025-01-23'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for Azure Active Directory Consent to application
|
||||
description: Logs user or admin consent to an application's permissions in Azure Active
|
||||
Directory, including details about the application, granted permissions, and the
|
||||
consenting user or process.
|
||||
mitre_components:
|
||||
- User Account Modification
|
||||
- Cloud Service Modification
|
||||
- Cloud Service Metadata
|
||||
- Configuration Modification
|
||||
source: Azure AD
|
||||
sourcetype: azure:monitor:aad
|
||||
separator: operationName
|
||||
separator_value: Consent to application
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Cloud Services
|
||||
url: https://splunkbase.splunk.com/app/3110
|
||||
|
||||
@@ -1,12 +1,18 @@
|
||||
name: Azure Active Directory Disable Strong Authentication
|
||||
id: 8f31966d-c496-496d-8837-f7fd11f31255
|
||||
version: 1
|
||||
date: "2024-07-18"
|
||||
version: 2
|
||||
date: '2025-01-23'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for Azure Active Directory Disable Strong Authentication
|
||||
description: Logs an event when strong authentication methods are disabled in Azure
|
||||
Active Directory.
|
||||
mitre_components:
|
||||
- User Account Authentication
|
||||
- User Account Modification
|
||||
- Cloud Service Modification
|
||||
source: Azure AD
|
||||
sourcetype: azure:monitor:aad
|
||||
separator: operationName
|
||||
separator_value: Disable Strong Authentication
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Cloud Services
|
||||
url: https://splunkbase.splunk.com/app/3110
|
||||
|
||||
@@ -1,12 +1,17 @@
|
||||
name: Azure Active Directory Enable account
|
||||
id: cb49f3cd-04ad-415c-a5ed-9b27b2829fa7
|
||||
version: 1
|
||||
date: "2024-07-18"
|
||||
version: 2
|
||||
date: '2025-01-23'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for Azure Active Directory Enable account
|
||||
description: Logs an event when an Azure Active Directory account is enabled.
|
||||
mitre_components:
|
||||
- User Account Modification
|
||||
- User Account Authentication
|
||||
- User Account Metadata
|
||||
source: Azure AD
|
||||
sourcetype: azure:monitor:aad
|
||||
separator: operationName
|
||||
separator_value: Enable account
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Cloud Services
|
||||
url: https://splunkbase.splunk.com/app/3110
|
||||
|
||||
@@ -1,12 +1,18 @@
|
||||
name: Azure Active Directory Invite external user
|
||||
id: d3818bd5-f283-4518-8b67-df19240c3e40
|
||||
version: 1
|
||||
date: "2024-07-18"
|
||||
version: 2
|
||||
date: '2025-01-23'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for Azure Active Directory Invite external user
|
||||
description: Logs an event when an external user is invited to join an Azure Active
|
||||
Directory tenant.
|
||||
mitre_components:
|
||||
- Active Directory Object Creation
|
||||
- User Account Creation
|
||||
- User Account Authentication
|
||||
source: Azure AD
|
||||
sourcetype: azure:monitor:aad
|
||||
separator: operationName
|
||||
separator_value: Invite external user
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Cloud Services
|
||||
url: https://splunkbase.splunk.com/app/3110
|
||||
|
||||
@@ -1,12 +1,18 @@
|
||||
name: Azure Active Directory Reset password (by admin)
|
||||
id: dcd0e4dc-68f8-4b77-a66f-89c57b3afa6b
|
||||
version: 1
|
||||
date: "2024-07-18"
|
||||
version: 2
|
||||
date: '2025-01-23'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for Azure Active Directory Reset password (by admin)
|
||||
description: Logs an event when an admin resets a user's password in Azure Active
|
||||
Directory.
|
||||
mitre_components:
|
||||
- User Account Authentication
|
||||
- User Account Modification
|
||||
- Active Directory Object Modification
|
||||
source: Azure AD
|
||||
sourcetype: azure:monitor:aad
|
||||
separator: operationName
|
||||
separator_value: Reset password (by admin)
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Cloud Services
|
||||
url: https://splunkbase.splunk.com/app/3110
|
||||
|
||||
@@ -1,12 +1,18 @@
|
||||
name: Azure Active Directory Set domain authentication
|
||||
id: e7bcdab9-908c-40ab-ba38-5db54fa87750
|
||||
version: 1
|
||||
date: "2024-07-18"
|
||||
version: 2
|
||||
date: '2025-01-23'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for Azure Active Directory Set domain authentication
|
||||
description: Logs an event when the authentication method for a domain in Azure Active
|
||||
Directory is set or modified.
|
||||
mitre_components:
|
||||
- Active Directory Object Modification
|
||||
- User Account Authentication
|
||||
- Cloud Service Modification
|
||||
source: Azure AD
|
||||
sourcetype: azure:monitor:aad
|
||||
separator: operationName
|
||||
separator_value: Set domain authentication
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Cloud Services
|
||||
url: https://splunkbase.splunk.com/app/3110
|
||||
|
||||
@@ -1,12 +1,18 @@
|
||||
name: Azure Active Directory Sign-in activity
|
||||
id: f9ed0a3a-9e20-4198-a035-d0a29593fbe0
|
||||
version: 1
|
||||
date: "2024-07-18"
|
||||
version: 2
|
||||
date: '2025-01-23'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for Azure Active Directory Sign-in activity
|
||||
description: Logs an event when a user attempts to sign into Azure Active Directory,
|
||||
capturing authentication details and outcomes.
|
||||
mitre_components:
|
||||
- User Account Authentication
|
||||
- Logon Session Creation
|
||||
- User Account Metadata
|
||||
source: Azure AD
|
||||
sourcetype: azure:monitor:aad
|
||||
separator: operationName
|
||||
separator_value: Sign-in activity
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Cloud Services
|
||||
url: https://splunkbase.splunk.com/app/3110
|
||||
|
||||
@@ -1,12 +1,18 @@
|
||||
name: Azure Active Directory Update application
|
||||
id: 2c08188a-ba25-496e-87c7-803cf28b6c90
|
||||
version: 1
|
||||
date: "2024-07-18"
|
||||
version: 2
|
||||
date: '2025-01-23'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for Azure Active Directory Update application
|
||||
description: Logs an event when an application in Azure Active Directory is updated,
|
||||
such as changes to its settings or permissions.
|
||||
mitre_components:
|
||||
- Service Modification
|
||||
- User Account Modification
|
||||
- Cloud Service Modification
|
||||
source: Azure AD
|
||||
sourcetype: azure:monitor:aad
|
||||
separator: operationName
|
||||
separator_value: Update application
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Cloud Services
|
||||
url: https://splunkbase.splunk.com/app/3110
|
||||
|
||||
@@ -1,12 +1,18 @@
|
||||
name: Azure Active Directory Update authorization policy
|
||||
id: c5b7ffcd-73d8-4fe5-afd8-b1218d715c0c
|
||||
version: 1
|
||||
date: "2024-07-18"
|
||||
version: 2
|
||||
date: '2025-01-23'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for Azure Active Directory Update authorization policy
|
||||
description: Logs an event when an authorization policy is updated in Azure Active
|
||||
Directory.
|
||||
mitre_components:
|
||||
- User Account Modification
|
||||
- Group Modification
|
||||
- Active Directory Object Modification
|
||||
source: Azure AD
|
||||
sourcetype: azure:monitor:aad
|
||||
separator: operationName
|
||||
separator_value: Update authorization policy
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Cloud Services
|
||||
url: https://splunkbase.splunk.com/app/3110
|
||||
|
||||
@@ -1,12 +1,16 @@
|
||||
name: Azure Active Directory Update user
|
||||
id: 5495c90a-047c-4b8e-b2fe-1db6282d3872
|
||||
version: 1
|
||||
date: "2024-07-18"
|
||||
version: 2
|
||||
date: '2025-01-23'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for Azure Active Directory Update user
|
||||
description: Logs an event when a user account is updated in Azure Active Directory.
|
||||
mitre_components:
|
||||
- User Account Modification
|
||||
- User Account Metadata
|
||||
source: Azure AD
|
||||
sourcetype: azure:monitor:aad
|
||||
separator: operationName
|
||||
separator_value: Update user
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Cloud Services
|
||||
url: https://splunkbase.splunk.com/app/3110
|
||||
|
||||
@@ -1,14 +1,17 @@
|
||||
name: Azure Active Directory User registered security info
|
||||
id: b63240de-8a01-4ba8-8987-89d18d4b375d
|
||||
version: 1
|
||||
date: "2024-07-18"
|
||||
version: 2
|
||||
date: '2025-01-23'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description:
|
||||
Data source object for Azure Active Directory User registered security
|
||||
info
|
||||
description: Logs an event when a user registers or updates their security information
|
||||
in Azure Active Directory.
|
||||
mitre_components:
|
||||
- User Account Modification
|
||||
- User Account Metadata
|
||||
source: Azure AD
|
||||
sourcetype: azure:monitor:aad
|
||||
separator: operationName
|
||||
separator_value: User registered security info
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Cloud Services
|
||||
url: https://splunkbase.splunk.com/app/3110
|
||||
|
||||
@@ -1,14 +1,17 @@
|
||||
name: Azure Audit Create or Update an Azure Automation account
|
||||
id: 2ab182e7-feda-4249-9418-32710b55a885
|
||||
version: 1
|
||||
date: "2024-07-18"
|
||||
version: 2
|
||||
date: '2025-01-23'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description:
|
||||
Data source object for Azure Audit Create or Update an Azure Automation
|
||||
account
|
||||
description: Logs an event when an Azure Automation account is created or updated.
|
||||
mitre_components:
|
||||
- Cloud Service Creation
|
||||
- Cloud Service Modification
|
||||
- Cloud Service Metadata
|
||||
source: mscs:azure:audit
|
||||
sourcetype: mscs:azure:audit
|
||||
separator: operationName.localizedValue
|
||||
separator_value: Create or Update an Azure Automation account
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Cloud Services
|
||||
url: https://splunkbase.splunk.com/app/3110
|
||||
|
||||
@@ -1,14 +1,17 @@
|
||||
name: Azure Audit Create or Update an Azure Automation Runbook
|
||||
id: 2bd83221-7a8b-436f-9b2b-efa1d44d009e
|
||||
version: 1
|
||||
date: "2024-07-18"
|
||||
version: 2
|
||||
date: '2025-01-23'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description:
|
||||
Data source object for Azure Audit Create or Update an Azure Automation
|
||||
Runbook
|
||||
description: Logs an event when a new Azure Automation Runbook is created or an existing
|
||||
one is updated.
|
||||
mitre_components:
|
||||
- Scheduled Job Modification
|
||||
- Scheduled Job Creation
|
||||
source: mscs:azure:audit
|
||||
sourcetype: mscs:azure:audit
|
||||
separator: operationName.localizedValue
|
||||
separator_value: Create or Update an Azure Automation Runbook
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Cloud Services
|
||||
url: https://splunkbase.splunk.com/app/3110
|
||||
|
||||
@@ -1,14 +1,17 @@
|
||||
name: Azure Audit Create or Update an Azure Automation webhook
|
||||
id: 575faeb2-09d0-4849-b1f6-eae241f26ff2
|
||||
version: 1
|
||||
date: "2024-07-18"
|
||||
version: 2
|
||||
date: '2025-01-23'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description:
|
||||
Data source object for Azure Audit Create or Update an Azure Automation
|
||||
webhook
|
||||
description: Logs an event when a webhook is created or updated in Azure Automation.
|
||||
mitre_components:
|
||||
- Scheduled Job Modification
|
||||
- Cloud Service Modification
|
||||
- Scheduled Job Metadata
|
||||
source: mscs:azure:audit
|
||||
sourcetype: mscs:azure:audit
|
||||
separator: operationName.localizedValue
|
||||
separator_value: Create or Update an Azure Automation webhook
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Microsoft Cloud Services
|
||||
url: https://splunkbase.splunk.com/app/3110
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Azure Monitor Activity
|
||||
id: 1997a515-a61a-4f78-ada9-54af34c764f2
|
||||
version: 1
|
||||
date: "2025-01-13"
|
||||
date: '2025-01-13'
|
||||
author: Bhavin Patel, Splunk
|
||||
description:
|
||||
Data source object for Azure Monitor Activity. The Splunk Add-on for
|
||||
|
||||
@@ -1,9 +0,0 @@
|
||||
name: Bro
|
||||
id: c5d9612b-0ffd-44d3-8247-3cf3486ec5e2
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for Bro
|
||||
source: bro:http:json
|
||||
sourcetype: bro:http:json
|
||||
supported_TA: []
|
||||
@@ -0,0 +1,18 @@
|
||||
name: Bro conn
|
||||
id: c5a7e93b-2172-45a7-a7e9-3b217255a7f5
|
||||
version: 2
|
||||
date: '2025-01-23'
|
||||
author: Jacob Delgado, SnapAttack
|
||||
description: Logs network connection metadata captured by Zeek (formerly Bro), including
|
||||
details such as source and destination IPs, ports, connection state, and protocol.
|
||||
mitre_components:
|
||||
- Network Connection Creation
|
||||
- Network Traffic Flow
|
||||
- Response Metadata
|
||||
- Application Log Content
|
||||
source: bro:conn:json
|
||||
sourcetype: bro:conn:json
|
||||
supported_TA:
|
||||
- name: TA for Zeek
|
||||
url: https://splunkbase.splunk.com/app/5466
|
||||
version: 1.0.8
|
||||
@@ -0,0 +1,20 @@
|
||||
name: Bro dns
|
||||
id: a4576cbf-06cc-4ed0-976c-bf06ccaed011
|
||||
version: 2
|
||||
date: '2025-01-23'
|
||||
author: Jacob Delgado, SnapAttack
|
||||
description: Logs DNS queries and responses captured by Zeek (formerly Bro), including
|
||||
details such as queried domains, resolved IPs, query types, and response codes.
|
||||
mitre_components:
|
||||
- Active DNS
|
||||
- Passive DNS
|
||||
- Network Traffic Content
|
||||
- Network Traffic Flow
|
||||
- Response Metadata
|
||||
source: bro:dns:json
|
||||
sourcetype: bro:dns:json
|
||||
supported_TA:
|
||||
- name: TA for Zeek
|
||||
url: https://splunkbase.splunk.com/app/5466
|
||||
version: 1.0.8
|
||||
|
||||
@@ -0,0 +1,20 @@
|
||||
name: Bro files
|
||||
id: f72d34d0-3495-4826-ad34-d03495782633
|
||||
version: 2
|
||||
date: '2025-01-23'
|
||||
author: Jacob Delgado, SnapAttack
|
||||
description: Logs metadata about files transferred over the network captured by Zeek
|
||||
(formerly Bro), including details such as file names, hashes, MIME types, and transfer
|
||||
protocols.
|
||||
mitre_components:
|
||||
- File Metadata
|
||||
- Network Traffic Content
|
||||
- Network Traffic Flow
|
||||
- Response Metadata
|
||||
- Application Log Content
|
||||
source: bro:files:json
|
||||
sourcetype: bro:files:json
|
||||
supported_TA:
|
||||
- name: TA for Zeek
|
||||
url: https://splunkbase.splunk.com/app/5466
|
||||
version: 1.0.8
|
||||
@@ -0,0 +1,19 @@
|
||||
name: Bro http
|
||||
id: c5d9612b-0ffd-44d3-8247-3cf3486ec5e2
|
||||
version: 3
|
||||
date: '2025-01-23'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Logs HTTP traffic analyzed by Zeek (formerly Bro), including details
|
||||
such as request methods, URLs, user agents, response codes, and headers.
|
||||
mitre_components:
|
||||
- Network Traffic Content
|
||||
- Network Traffic Flow
|
||||
- Response Content
|
||||
- Response Metadata
|
||||
- Application Log Content
|
||||
source: bro:http:json
|
||||
sourcetype: bro:http:json
|
||||
supported_TA:
|
||||
- name: TA for Zeek
|
||||
url: https://splunkbase.splunk.com/app/5466
|
||||
version: 1.0.8
|
||||
@@ -0,0 +1,18 @@
|
||||
name: Bro loaded_scripts
|
||||
id: 81e08a21-a735-42b1-a08a-21a73582b1bf
|
||||
version: 2
|
||||
date: '2025-01-23'
|
||||
author: Jacob Delgado, SnapAttack
|
||||
description: Logs details about the scripts loaded by Zeek (formerly Bro) during initialization,
|
||||
including script names and paths.
|
||||
mitre_components:
|
||||
- Application Log Content
|
||||
- Configuration Modification
|
||||
- Script Execution
|
||||
- OS API Execution
|
||||
source: bro:loaded_scripts:json
|
||||
sourcetype: bro:loaded_scripts:json
|
||||
supported_TA:
|
||||
- name: TA for Zeek
|
||||
url: https://splunkbase.splunk.com/app/5466
|
||||
version: 1.0.8
|
||||
@@ -0,0 +1,18 @@
|
||||
name: Bro ntp
|
||||
id: 3f64a544-47a4-4958-a4a5-4447a47958df
|
||||
version: 2
|
||||
date: '2025-01-23'
|
||||
author: Jacob Delgado, SnapAttack
|
||||
description: Logs Network Time Protocol (NTP) activity captured by Zeek (formerly
|
||||
Bro), including details such as NTP requests, responses, and server metadata.
|
||||
mitre_components:
|
||||
- Network Traffic Flow
|
||||
- Network Traffic Content
|
||||
- Response Metadata
|
||||
- Application Log Content
|
||||
source: bro:ntp:json
|
||||
sourcetype: bro:ntp:json
|
||||
supported_TA:
|
||||
- name: TA for Zeek
|
||||
url: https://splunkbase.splunk.com/app/5466
|
||||
version: 1.0.8
|
||||
@@ -0,0 +1,19 @@
|
||||
name: Bro ocsp
|
||||
id: d20909ab-70be-409a-8909-ab70be609af1
|
||||
version: 2
|
||||
date: '2025-01-23'
|
||||
author: Jacob Delgado, SnapAttack
|
||||
description: Logs Online Certificate Status Protocol (OCSP) activity captured by Zeek
|
||||
(formerly Bro), including details such as certificate validation requests and responses.
|
||||
mitre_components:
|
||||
- Certificate Registration
|
||||
- Network Traffic Flow
|
||||
- Network Traffic Content
|
||||
- Response Metadata
|
||||
- Application Log Content
|
||||
source: bro:ocsp:json
|
||||
sourcetype: bro:ocsp:json
|
||||
supported_TA:
|
||||
- name: TA for Zeek
|
||||
url: https://splunkbase.splunk.com/app/5466
|
||||
version: 1.0.8
|
||||
@@ -0,0 +1,19 @@
|
||||
name: Bro ssl
|
||||
id: 22c637eb-f62e-41f0-8637-ebf62e11f0a8
|
||||
version: 2
|
||||
date: '2025-01-23'
|
||||
author: Jacob Delgado, SnapAttack
|
||||
description: Logs SSL/TLS handshake and session details captured by Zeek (formerly
|
||||
Bro), including certificates, cipher suites, and session information.
|
||||
mitre_components:
|
||||
- Certificate Registration
|
||||
- Network Traffic Flow
|
||||
- Network Traffic Content
|
||||
- Response Metadata
|
||||
- Application Log Content
|
||||
source: bro:ssl:json
|
||||
sourcetype: bro:ssl:json
|
||||
supported_TA:
|
||||
- name: TA for Zeek
|
||||
url: https://splunkbase.splunk.com/app/5466
|
||||
version: 1.0.8
|
||||
@@ -0,0 +1,19 @@
|
||||
name: Bro weird
|
||||
id: e03762c5-c4b8-44e3-b762-c5c4b8e4e3b6
|
||||
version: 2
|
||||
date: '2025-01-23'
|
||||
author: Jacob Delgado, SnapAttack
|
||||
description: Logs anomalous or unexpected network behaviors identified by Zeek (formerly
|
||||
Bro), including protocol violations and unusual traffic patterns.
|
||||
mitre_components:
|
||||
- Network Traffic Flow
|
||||
- Network Traffic Content
|
||||
- Response Metadata
|
||||
- Application Log Content
|
||||
- Host Status
|
||||
source: bro:weird:json
|
||||
sourcetype: bro:weird:json
|
||||
supported_TA:
|
||||
- name: TA for Zeek
|
||||
url: https://splunkbase.splunk.com/app/5466
|
||||
version: 1.0.8
|
||||
@@ -0,0 +1,19 @@
|
||||
name: Bro x509
|
||||
id: e8792367-64b0-47e9-b923-6764b0f7e936
|
||||
version: 2
|
||||
date: '2025-01-23'
|
||||
author: Jacob Delgado, SnapAttack
|
||||
description: Logs details about X.509 certificates observed in network traffic captured
|
||||
by Zeek (formerly Bro), including certificate fields, validity periods, and issuers.
|
||||
mitre_components:
|
||||
- Certificate Registration
|
||||
- Network Traffic Content
|
||||
- Response Metadata
|
||||
- Application Log Content
|
||||
- Host Status
|
||||
source: bro:x509:json
|
||||
sourcetype: bro:x509:json
|
||||
supported_TA:
|
||||
- name: TA for Zeek
|
||||
url: https://splunkbase.splunk.com/app/5466
|
||||
version: 1.0.8
|
||||
@@ -1,9 +1,16 @@
|
||||
name: CircleCI
|
||||
id: 34ad06fc-a296-4ab5-8315-2f07714948e3
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
version: 2
|
||||
date: '2025-01-23'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for CircleCI
|
||||
description: Logs activities related to CI/CD pipelines executed in CircleCI, including
|
||||
job execution, workflow progress, and configuration changes.
|
||||
mitre_components:
|
||||
- Scheduled Job Execution
|
||||
- Scheduled Job Metadata
|
||||
- Application Log Content
|
||||
- Configuration Modification
|
||||
- Host Status
|
||||
source: circleci
|
||||
sourcetype: circleci
|
||||
supported_TA:
|
||||
|
||||
File diff suppressed because one or more lines are too long
@@ -1,12 +1,21 @@
|
||||
name: CrowdStrike ProcessRollup2
|
||||
id: cbb06880-9dd9-4542-ac60-bd6e5d3c3e4e
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
version: 2
|
||||
date: '2025-01-23'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for CrowdStrike ProcessRollup2
|
||||
description: Logs process-related activities captured by CrowdStrike, including process
|
||||
creation, termination, and metadata such as hashes, parent processes, and command-line
|
||||
arguments.
|
||||
mitre_components:
|
||||
- Process Creation
|
||||
- Process Termination
|
||||
- Process Metadata
|
||||
- Command Execution
|
||||
- OS API Execution
|
||||
source: crowdstrike
|
||||
sourcetype: crowdstrike:events:sensor
|
||||
separator: event_simpleName
|
||||
separator_value: ProcessRollup2
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for CrowdStrike FDR
|
||||
url: https://splunkbase.splunk.com/app/5579
|
||||
|
||||
@@ -1,9 +1,16 @@
|
||||
name: CrushFTP
|
||||
id: 8a42ace5-e4c8-4653-80cf-1b8e7e6024ef
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
version: 2
|
||||
date: '2025-01-23'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for CrushFTP
|
||||
description: Logs activities related to file transfers and user interactions in CrushFTP,
|
||||
including file uploads, downloads, user authentication, and session details.
|
||||
mitre_components:
|
||||
- File Access
|
||||
- File Metadata
|
||||
- User Account Authentication
|
||||
- Logon Session Metadata
|
||||
- Network Traffic Content
|
||||
source: crushftp
|
||||
sourcetype: crushftp:sessionlogs
|
||||
supported_TA: []
|
||||
|
||||
@@ -1,9 +1,16 @@
|
||||
name: G Suite Drive
|
||||
id: 5f79120f-a235-4468-bd0d-55203758ac22
|
||||
version: 1
|
||||
date: "2024-07-18"
|
||||
version: 2
|
||||
date: '2025-01-23'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for G Suite Drive
|
||||
description: Logs activities related to Google Drive in G Suite, including file creation,
|
||||
modification, sharing, and access details.
|
||||
mitre_components:
|
||||
- File Access
|
||||
- File Creation
|
||||
- File Modification
|
||||
- Cloud Storage Access
|
||||
- Cloud Storage Metadata
|
||||
source: http:gsuite
|
||||
sourcetype: gsuite:drive:json
|
||||
supported_TA:
|
||||
|
||||
@@ -1,9 +1,15 @@
|
||||
name: G Suite Gmail
|
||||
id: 706c3978-41de-406b-b6e0-75bd01e12a5d
|
||||
version: 1
|
||||
date: "2024-07-18"
|
||||
version: 2
|
||||
date: '2025-01-23'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for G Suite Gmail
|
||||
description: Logs Gmail activities in G Suite, including email sending, receiving,
|
||||
and access details, as well as potential security-related events.
|
||||
mitre_components:
|
||||
- Application Log Content
|
||||
- User Account Metadata
|
||||
- Email Metadata
|
||||
- Cloud Service Metadata
|
||||
source: http:gsuite
|
||||
sourcetype: gsuite:gmail:bigquery
|
||||
supported_TA:
|
||||
|
||||
@@ -1,9 +1,15 @@
|
||||
name: GitHub Webhooks
|
||||
id: 88aa4632-3c3e-43f6-a00a-998d71f558e3
|
||||
version: 1
|
||||
date: '2024-07-18'
|
||||
version: 2
|
||||
date: '2025-01-23'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for GitHub Webooks
|
||||
description: Data source object for GitHub Webooks
|
||||
mitre_components:
|
||||
- User Account Authentication
|
||||
- Configuration Modification
|
||||
- Application Log Content
|
||||
- User Account Metadata
|
||||
- Scheduled Job Metadata
|
||||
source: github
|
||||
sourcetype: aws:firehose:json
|
||||
supported_TA: []
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Google Workspace
|
||||
id: f1a044e3-113a-4e4d-84f2-b153ade83087
|
||||
version: 1
|
||||
date: "2025-02-21"
|
||||
date: '2025-02-21'
|
||||
author: Bhavin Patel, Splunk
|
||||
description: Data source object for Google Workspace
|
||||
source: google_workspace
|
||||
|
||||
@@ -1,12 +1,19 @@
|
||||
name: Google Workspace login_failure
|
||||
id: cabec7cf-4008-4899-b47e-39c34a9a1255
|
||||
version: 1
|
||||
date: "2024-07-18"
|
||||
version: 2
|
||||
date: '2025-01-23'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for Google Workspace login_failure
|
||||
description: Logs failed login attempts to Google Workspace accounts, including details
|
||||
about the user, IP address, and reason for failure.
|
||||
mitre_components:
|
||||
- User Account Authentication
|
||||
- Logon Session Metadata
|
||||
- User Account Metadata
|
||||
- Application Log Content
|
||||
source: gws:reports:admin
|
||||
sourcetype: gws:reports:admin
|
||||
separator: event.name
|
||||
separator_value: login_failure
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Google Workspace
|
||||
url: https://splunkbase.splunk.com/app/5556
|
||||
|
||||
@@ -1,12 +1,19 @@
|
||||
name: Google Workspace login_success
|
||||
id: bffe8013-9cdf-4fe6-9c1b-6784391a4951
|
||||
version: 1
|
||||
date: "2024-07-18"
|
||||
version: 2
|
||||
date: '2025-01-23'
|
||||
author: Patrick Bareiss, Splunk
|
||||
description: Data source object for Google Workspace login_success
|
||||
description: Logs successful login attempts to Google Workspace accounts, including
|
||||
details about the user, IP address, and session metadata.
|
||||
mitre_components:
|
||||
- User Account Authentication
|
||||
- Logon Session Creation
|
||||
- User Account Metadata
|
||||
- Logon Session Metadata
|
||||
source: gws:reports:admin
|
||||
sourcetype: gws:reports:admin
|
||||
separator: event.name
|
||||
separator_value: login_success
|
||||
supported_TA:
|
||||
- name: Splunk Add-on for Google Workspace
|
||||
url: https://splunkbase.splunk.com/app/5556
|
||||
|
||||
@@ -1,9 +1,16 @@
|
||||
name: Ivanti VTM Audit
|
||||
id: b04be6e5-2002-4a49-8722-52285635b8f5
|
||||
version: 1
|
||||
date: '2024-08-19'
|
||||
version: 2
|
||||
date: '2025-01-23'
|
||||
author: Michael Haag, Splunk
|
||||
description: Data source object for Ivanti Virtual Traffic Manager (vTM)
|
||||
description: Logs administrative and operational activities in Ivanti Virtual Traffic
|
||||
Manager (VTM), including configuration changes, user actions, and system events.
|
||||
mitre_components:
|
||||
- Configuration Modification
|
||||
- Application Log Content
|
||||
- User Account Metadata
|
||||
- Host Status
|
||||
- Service Modification
|
||||
source: ivanti_vtm
|
||||
sourcetype: ivanti_vtm_audit
|
||||
supported_TA: []
|
||||
@@ -16,4 +23,5 @@ fields:
|
||||
- AUTH
|
||||
- USER
|
||||
- GROUP
|
||||
example_log: '[19/Aug/2024:19:41:22 +0000] USER=!!ABSENT!! GROUP=!!ABSENT!! AUTH=!!ABSENT!! IP=!!ABSENT!! OPERATION=adduser MODUSER=newadmin MODGROUP=admin'
|
||||
example_log: '[19/Aug/2024:19:41:22 +0000] USER=!!ABSENT!! GROUP=!!ABSENT!! AUTH=!!ABSENT!!
|
||||
IP=!!ABSENT!! OPERATION=adduser MODUSER=newadmin MODGROUP=admin'
|
||||
|
||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user