Merge branch 'develop' into medusa_ransomware

This commit is contained in:
Br3akp0int
2025-03-19 10:20:24 +01:00
committed by GitHub
552 changed files with 4122 additions and 1367 deletions
View File
@@ -4,7 +4,7 @@ version: 1
date: '2020-08-15'
author: Rico Valdez, Splunk
type: Baseline
status: production
status: deprecated
description: This search looks for **AssumeRole** events where the requesting account
differs from the requested account, then writes these relationships to a lookup
file.
@@ -4,7 +4,7 @@ version: 1
date: '2020-08-15'
author: Rico Valdez, Splunk
type: Baseline
status: production
status: deprecated
description: This search looks for **AssumeRole** events where the requesting account
differs from the requested account, then writes these relationships to a lookup
file.
+4 -4
View File
@@ -3,7 +3,7 @@ app:
uid: 3449
title: ES Content Updates
appid: DA-ESS-ContentUpdate
version: 5.1.1
version: 5.2.0
description: Explore the Analytic Stories included with ES Content Updates.
prefix: ESCU
label: ESCU
@@ -218,11 +218,11 @@ apps:
version: 3.1.0
description: description of app
hardcoded_path: https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/splunk-add-on-for-github_310.tgz
- uid: 2882
- uid: 3471
title: Splunk Add-on for AppDynamics
appid: Splunk_TA_AppDynamics
version: 3.1.0
version: 3.0.0
description: The Splunk Add-on for AppDynamics enables you to easily configure data
inputs to pull data from AppDynamics' REST APIs
hardcoded_path: https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/cisco-splunk-add-on-for-appdynamics_310.tgz
hardcoded_path: https://attack-range-appbinaries.s3.us-west-2.amazonaws.com/cisco-splunk-add-on-for-appdynamics_300.tgz
githash: d6fac80e6d50ae06b40f91519a98489d4ce3a3fd
+16 -5
View File
@@ -1,9 +1,22 @@
name: ASL AWS CloudTrail
id: 1dcf9cfb-0e91-44c6-81b3-61b2574ec898
version: 1
date: '2025-01-14'
version: 2
date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Data source object for ASL AWS CloudTrail
description: Represents AWS API dataset data collection from Amazon Security Lake.
mitre_components:
- Cloud Service Metadata
- Cloud Service Modification
- Cloud Storage Access
- Instance Creation
- Instance Deletion
- Instance Start
- Instance Stop
- Instance Modification
- Cloud Storage Creation
- Cloud Storage Deletion
- Cloud Service Enumeration
- Cloud Storage Enumeration
source: aws_asl
sourcetype: aws:asl
separator: api.operation
@@ -12,11 +25,9 @@ supported_TA:
url: https://splunkbase.splunk.com/app/1876
version: 7.9.1
output_fields:
- action
- dest
- user
- user_agent
- status
- src
- vendor_account
- vendor_region
+11 -3
View File
@@ -1,9 +1,17 @@
name: AWS Cloudfront
id: 780086dc-2384-45b6-ade7-56cb00105464
version: 1
date: '2024-07-18'
version: 2
date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Data source object for AWS Cloudfront
description: Logs requests made to AWS CloudFront distributions, including details
on client access, response data, and performance metrics.
mitre_components:
- Network Traffic Content
- Network Traffic Flow
- Response Metadata
- Response Content
- Logon Session Metadata
- Cloud Service Metadata
source: aws
sourcetype: aws:cloudfront:accesslogs
supported_TA:
+1 -10
View File
@@ -3,7 +3,7 @@ id: e8ace6db-1dbd-4c72-a1fb-334684619a38
version: 1
date: '2024-07-24'
author: Patrick Bareiss, Splunk
description: Data source object for AWS CloudTrail
description: All AWS CloudTrail events
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
@@ -11,12 +11,3 @@ supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
version: 7.9.1
output_fields:
- action
- dest
- user
- user_agent
- src
- vendor_account
- vendor_region
- vendor_product
@@ -1,12 +1,20 @@
name: AWS CloudTrail AssumeRoleWithSAML
id: 1e28f2a6-2db9-405f-b298-18734a293f77
version: 1
date: '2024-07-18'
version: 2
date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Data source object for AWS CloudTrail AssumeRoleWithSAML
description: Logs attempts to assume roles via SAML authentication in AWS, including
details of identity provider and role mapping.
mitre_components:
- User Account Authentication
- Logon Session Creation
- User Account Metadata
- Cloud Service Metadata
- Instance Modification
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: AssumeRoleWithSAML
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
@@ -125,7 +133,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "SAMLUser", "pri
"eventType": "AwsApiCall", "managementEvent": true, "eventCategory": "Management",
"recipientAccountId": "111111111111"}'
output_fields:
- action
- dest
- user
- user_agent
+11 -4
View File
@@ -1,12 +1,20 @@
name: AWS CloudTrail ConsoleLogin
id: b68b3f26-bd21-4fa8-b593-616fe75ac0ae
version: 1
date: '2024-07-18'
version: 2
date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Data source object for AWS CloudTrail ConsoleLogin
description: Logs attempts to sign in to the AWS Management Console, including successful
and failed login events.
mitre_components:
- User Account Authentication
- Logon Session Creation
- User Account Metadata
- Logon Session Metadata
- Cloud Service Metadata
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: ConsoleLogin
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
@@ -101,7 +109,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "acco
"Management", "tlsDetails": {"tlsVersion": "TLSv1.2", "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "signin.aws.amazon.com"}}'
output_fields:
- action
- dest
- user
- user_agent
+10 -4
View File
@@ -1,12 +1,19 @@
name: AWS CloudTrail CopyObject
id: 965083f4-64a8-403f-99cc-252e1a6bd3b6
version: 1
date: '2024-07-18'
version: 2
date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Data source object for AWS CloudTrail CopyObject
description: Logs operations that copy objects within or between AWS S3 buckets, including
details of source and destination.
mitre_components:
- Cloud Storage Access
- Cloud Storage Modification
- Cloud Storage Metadata
- Instance Modification
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: CopyObject
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
@@ -118,7 +125,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "prin
"eventType": "AwsApiCall", "managementEvent": false, "recipientAccountId": "111111111111",
"eventCategory": "Data"}'
output_fields:
- action
- dest
- user
- user_agent
@@ -1,12 +1,19 @@
name: AWS CloudTrail CreateAccessKey
id: 0460f7da-3254-4d90-b8c0-2ca657d0cea0
version: 1
date: '2024-07-18'
version: 2
date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Data source object for AWS CloudTrail CreateAccessKey
description: Logs the creation of new AWS access keys, including details of the associated
user and permissions.
mitre_components:
- User Account Creation
- User Account Metadata
- Cloud Service Modification
- Cloud Service Metadata
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: CreateAccessKey
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
@@ -102,7 +109,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "prin
"AwsApiCall", "managementEvent": true, "eventCategory": "Management", "recipientAccountId":
"121521347698"}'
output_fields:
- action
- dest
- user
- user_agent
+10 -4
View File
@@ -1,12 +1,19 @@
name: AWS CloudTrail CreateKey
id: fcfc1593-b6b5-4a0f-91c5-3c395116a8b9
version: 1
date: '2024-07-18'
version: 2
date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Data source object for AWS CloudTrail CreateKey
description: Logs the creation of new AWS KMS keys, including details of key properties
and associated metadata.
mitre_components:
- Cloud Service Creation
- Cloud Service Metadata
- Instance Creation
- Volume Metadata
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: CreateKey
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
@@ -149,7 +156,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "
"eventType": "AwsApiCall", "managementEvent": true, "eventCategory": "Management",
"recipientAccountId": "111111111111"}'
output_fields:
- action
- dest
- user
- user_agent
@@ -1,12 +1,19 @@
name: AWS CloudTrail CreateLoginProfile
id: 0024fdb1-0d62-4449-970a-746952cf80b6
version: 1
date: '2024-07-18'
version: 2
date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Data source object for AWS CloudTrail CreateLoginProfile
description: Logs the creation of login profiles for IAM users, including associated
metadata and authentication settings.
mitre_components:
- User Account Creation
- User Account Metadata
- Logon Session Metadata
- Cloud Service Metadata
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: CreateLoginProfile
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
@@ -101,7 +108,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "prin
"AwsApiCall", "managementEvent": true, "eventCategory": "Management", "recipientAccountId":
"111111111111"}'
output_fields:
- action
- dest
- user
- user_agent
@@ -1,12 +1,19 @@
name: AWS CloudTrail CreateNetworkAclEntry
id: 45934028-10ec-4ab5-a7b1-a6349b833e67
version: 1
date: '2024-07-18'
version: 2
date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Data source object for AWS CloudTrail CreateNetworkAclEntry
description: Logs the creation of new entries in a network ACL, including rules to
allow or deny specific network traffic.
mitre_components:
- Firewall Rule Modification
- Network Connection Creation
- Cloud Service Modification
- Cloud Service Metadata
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: CreateNetworkAclEntry
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
@@ -120,7 +127,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "
"6d1ce00e-4099-463c-8a4d-2af2fb2178ba", "readOnly": false, "eventType": "AwsApiCall",
"managementEvent": true, "eventCategory": "Management", "recipientAccountId": "111111111111"}'
output_fields:
- action
- dest
- user
- user_agent
@@ -1,12 +1,19 @@
name: AWS CloudTrail CreatePolicyVersion
id: f9f0f3da-37ec-4164-9ea0-0ae46645a86b
version: 1
date: '2024-07-18'
version: 2
date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Data source object for AWS CloudTrail CreatePolicyVersion
description: Logs the creation of new versions of IAM policies, including changes
to permissions and attached roles or resources.
mitre_components:
- Cloud Service Modification
- Cloud Service Metadata
- User Account Metadata
- Group Modification
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: CreatePolicyVersion
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
@@ -105,7 +112,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "prin
"AwsApiCall", "managementEvent": true, "eventCategory": "Management", "recipientAccountId":
"111111111111"}'
output_fields:
- action
- dest
- user
- user_agent
+10 -4
View File
@@ -1,12 +1,19 @@
name: AWS CloudTrail CreateSnapshot
id: 514135a2-f4b2-4d32-8f31-d87824887f9f
version: 1
date: '2024-07-18'
version: 2
date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Data source object for AWS CloudTrail CreateSnapshot
description: Logs the creation of a new snapshot of a cloud resource, such as an Amazon
EBS volume, including details about the snapshot ID and resource type.
mitre_components:
- Snapshot Creation
- Snapshot Metadata
- Volume Metadata
- Cloud Service Metadata
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: CreateSnapshot
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
@@ -117,7 +124,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "prin
"111111111111", "eventCategory": "Management", "tlsDetails": {"tlsVersion": "TLSv1.2",
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256", "clientProvidedHostHeader": "ec2.us-west-2.amazonaws.com"}}'
output_fields:
- action
- dest
- user
- user_agent
+10 -4
View File
@@ -1,12 +1,19 @@
name: AWS CloudTrail CreateTask
id: 6501e4fe-05b2-45f1-bd51-9e06a94fa7d9
version: 1
date: '2024-07-18'
version: 2
date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Data source object for AWS CloudTrail CreateTask
description: Logs the creation of a new task in AWS services, such as ECS, including
details about the task definition and resource allocation.
mitre_components:
- Scheduled Job Creation
- Scheduled Job Metadata
- Cloud Service Metadata
- Instance Creation
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: CreateTask
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
@@ -120,7 +127,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256", "clientProvidedHostHeader": "datasync.us-west-2.amazonaws.com"},
"sessionCredentialFromConsole": "true"}'
output_fields:
- action
- dest
- user
- user_agent
@@ -1,12 +1,19 @@
name: AWS CloudTrail CreateVirtualMFADevice
id: 13e6e952-0dad-4190-865c-fb5911725f7a
version: 1
date: '2024-07-18'
version: 2
date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Data source object for AWS CloudTrail CreateVirtualMFADevice
description: Logs the creation of a new virtual multi-factor authentication (MFA)
device, including details about the associated user and configuration.
mitre_components:
- User Account Creation
- User Account Metadata
- Cloud Service Creation
- Cloud Service Metadata
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: CreateVirtualMFADevice
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
@@ -99,7 +106,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "Root", "princip
"readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId":
"140429656527", "eventCategory": "Management", "sessionCredentialFromConsole": "true"}'
output_fields:
- action
- dest
- user
- user_agent
@@ -1,12 +1,19 @@
name: AWS CloudTrail DeactivateMFADevice
id: 7397a10b-1150-4de9-8062-a96454ae53b2
version: 1
date: '2024-07-18'
version: 2
date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Data source object for AWS CloudTrail DeactivateMFADevice
description: Logs the deactivation of a multi-factor authentication (MFA) device,
including details about the associated user and the device.
mitre_components:
- User Account Modification
- User Account Metadata
- Cloud Service Modification
- Cloud Service Metadata
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: DeactivateMFADevice
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
@@ -99,7 +106,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "Root", "princip
"readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId":
"111111111111", "eventCategory": "Management"}'
output_fields:
- action
- dest
- user
- user_agent
@@ -1,12 +1,17 @@
name: AWS CloudTrail DeleteAccountPasswordPolicy
id: b0730ac8-0992-4de8-b000-2c7d0fc7a67f
version: 1
date: '2024-07-18'
version: 2
date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Data source object for AWS CloudTrail DeleteAccountPasswordPolicy
description: Logs the deletion of an account-level password policy in AWS, including
details about the account and policy being removed.
mitre_components:
- Cloud Service Modification
- Cloud Service Metadata
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: DeleteAccountPasswordPolicy
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
@@ -99,7 +104,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "Root", "princip
"readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId":
"111111111111", "eventCategory": "Management", "sessionCredentialFromConsole": "true"}'
output_fields:
- action
- dest
- user
- user_agent
+10 -4
View File
@@ -1,12 +1,19 @@
name: AWS CloudTrail DeleteAlarms
id: b0730ac8-0992-4de8-b000-2c7d0fc7a61f
version: 1
date: '2024-07-18'
version: 2
date: '2025-01-23'
author: Bhavin Patel, Splunk
description: Data source object for AWS CloudTrail DeleteAlarms
description: Logs the deletion of CloudWatch alarms, including details about the alarm
names and associated monitoring configurations.
mitre_components:
- Cloud Service Modification
- Cloud Service Metadata
- Application Log Content
- Host Status
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: DeleteAlarms
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
@@ -140,7 +147,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "
"managementEvent": true, "recipientAccountId": "111111111111", "eventCategory":
"Management"}'
output_fields:
- action
- dest
- user
- user_agent
+10 -4
View File
@@ -1,12 +1,19 @@
name: AWS CloudTrail DeleteDetector
id: 5d8bd475-c8bc-4447-b27f-efa508728b90
version: 1
date: '2024-07-18'
version: 2
date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Data source object for AWS CloudTrail DeleteDetector
description: Logs the deletion of an Amazon GuardDuty detector, including details
about the detector ID and associated configurations.
mitre_components:
- Cloud Service Modification
- Cloud Service Metadata
- Host Status
- Application Log Content
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: DeleteDetector
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
@@ -97,7 +104,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "prin
"readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId":
"111111111111", "eventCategory": "Management"}'
output_fields:
- action
- dest
- user
- user_agent
+10 -4
View File
@@ -1,12 +1,19 @@
name: AWS CloudTrail DeleteGroup
id: c95308a4-a943-42ca-b112-f90a05c21bd3
version: 1
date: '2024-07-18'
version: 2
date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Data source object for AWS CloudTrail DeleteGroup
description: Logs the deletion of an IAM group in AWS, including details about the
group name and its associated policies or members.
mitre_components:
- Group Modification
- Group Metadata
- User Account Metadata
- Cloud Service Modification
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: DeleteGroup
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
@@ -101,7 +108,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "prin
"readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "eventCategory":
"Management", "recipientAccountId": "121522247101"}'
output_fields:
- action
- dest
- user
- user_agent
+9 -4
View File
@@ -1,12 +1,18 @@
name: AWS CloudTrail DeleteIPSet
id: ebdeeb63-77a0-4808-a6fe-549956731377
version: 1
date: '2024-07-18'
version: 2
date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Data source object for AWS CloudTrail DeleteIPSet
description: Logs the deletion of an IP set in AWS WAF or GuardDuty, including details
about the IP set ID and its associated configurations.
mitre_components:
- Cloud Service Modification
- Cloud Service Metadata
- Firewall Rule Modification
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: DeleteIPSet
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
@@ -98,7 +104,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "prin
"readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId":
"111111111111", "eventCategory": "Management"}'
output_fields:
- action
- dest
- user
- user_agent
+10 -4
View File
@@ -1,12 +1,19 @@
name: AWS CloudTrail DeleteLogGroup
id: 60cf6a69-fa43-4a6c-8808-e9fb46bf387f
version: 1
date: '2024-07-18'
version: 2
date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Data source object for AWS CloudTrail DeleteLogGroup
description: Logs the deletion of a CloudWatch log group, including details about
the log group name and associated resources.
mitre_components:
- Cloud Service Modification
- Cloud Service Metadata
- Application Log Content
- Host Status
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: DeleteLogGroup
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
@@ -99,7 +106,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "prin
"eventCategory": "Management", "tlsDetails": {"tlsVersion": "TLSv1.2", "cipherSuite":
"ECDHE-RSA-AES128-GCM-SHA256", "clientProvidedHostHeader": "logs.us-west-2.amazonaws.com"}}'
output_fields:
- action
- dest
- user
- user_agent
@@ -1,12 +1,19 @@
name: AWS CloudTrail DeleteLogStream
id: 6f8bb808-89f8-465e-a34d-229df2f46402
version: 1
date: '2024-07-18'
version: 2
date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Data source object for AWS CloudTrail DeleteLogStream
description: Logs the deletion of a log stream within a CloudWatch log group, including
details about the stream name and associated log group.
mitre_components:
- Cloud Service Modification
- Cloud Service Metadata
- Application Log Content
- Host Status
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: DeleteLogStream
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
@@ -100,7 +107,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "prin
"111111111111", "eventCategory": "Management", "tlsDetails": {"tlsVersion": "TLSv1.2",
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256", "clientProvidedHostHeader": "logs.us-west-2.amazonaws.com"}}'
output_fields:
- action
- dest
- user
- user_agent
@@ -1,12 +1,18 @@
name: AWS CloudTrail DeleteNetworkAclEntry
id: a0dd0f10-cc03-425d-bd5a-e1e0d954b856
version: 1
date: '2024-07-18'
version: 2
date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Data source object for AWS CloudTrail DeleteNetworkAclEntry
description: Logs the deletion of a network ACL entry in AWS, including details about
the rule number and associated network ACL.
mitre_components:
- Firewall Rule Modification
- Cloud Service Modification
- Cloud Service Metadata
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: DeleteNetworkAclEntry
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
@@ -109,7 +115,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "
"b9e05770-e9b0-4ba1-91e8-6537097e06e7", "readOnly": false, "eventType": "AwsApiCall",
"managementEvent": true, "eventCategory": "Management", "recipientAccountId": "111111111111"}'
output_fields:
- action
- dest
- user
- user_agent
+8 -4
View File
@@ -1,12 +1,17 @@
name: AWS CloudTrail DeletePolicy
id: d190d23a-2c59-4a0e-9c55-a53ebef28ee5
version: 1
date: '2024-07-18'
version: 2
date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Data source object for AWS CloudTrail DeletePolicy
description: Logs the deletion of an IAM policy in AWS, including details about the
policy name and its associated roles or users.
mitre_components:
- Cloud Service Modification
- Cloud Service Metadata
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: DeletePolicy
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
@@ -101,7 +106,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "prin
"abd071bf-0a38-4fab-af4a-5eee55f0935e", "readOnly": false, "eventType": "AwsApiCall",
"managementEvent": true, "eventCategory": "Management", "recipientAccountId": "151521547504"}'
output_fields:
- action
- dest
- user
- user_agent
+10 -4
View File
@@ -1,12 +1,19 @@
name: AWS CloudTrail DeleteRule
id: b5760623-f3ca-492d-a372-d5c2b3567dfc
version: 1
date: '2024-07-18'
version: 2
date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Data source object for AWS CloudTrail DeleteRule
description: Logs the deletion of an event rule in AWS EventBridge, including details
about the rule name and its associated targets or schedules.
mitre_components:
- Cloud Service Modification
- Cloud Service Metadata
- Scheduled Job Modification
- Application Log Content
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: DeleteRule
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
@@ -101,7 +108,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "prin
"111111111111", "eventCategory": "Management", "tlsDetails": {"tlsVersion": "TLSv1.2",
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256", "clientProvidedHostHeader": "waf.amazonaws.com"}}'
output_fields:
- action
- dest
- user
- user_agent
+10 -4
View File
@@ -1,12 +1,19 @@
name: AWS CloudTrail DeleteSnapshot
id: b0731ac8-0992-4de8-b000-2c7d0fc2a61f
version: 1
date: '2024-07-18'
version: 2
date: '2025-01-23'
author: Bhavin Patel, Splunk
description: Data source object for AWS CloudTrail DeleteSnapshot
description: Logs the deletion of a cloud resource snapshot, such as an Amazon EBS
snapshot, including details about the snapshot ID and associated resource.
mitre_components:
- Snapshot Deletion
- Snapshot Metadata
- Cloud Service Modification
- Cloud Service Metadata
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: DeleteSnapshot
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
@@ -144,7 +151,6 @@ example_log: '{"eventVersion": "1.09", "userIdentity": {"type": "AssumedRole", "
"managementEvent": true, "recipientAccountId": "11111111111111", "eventCategory":
"Management", "sessionCredentialFromConsole": "true"}'
output_fields:
- action
- dest
- user
- user_agent
+10 -4
View File
@@ -1,12 +1,19 @@
name: AWS CloudTrail DeleteTrail
id: a5af09ff-07b6-4df6-92a0-2146bfe402c8
version: 1
date: '2024-07-18'
version: 2
date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Data source object for AWS CloudTrail DeleteTrail
description: Logs the deletion of an AWS CloudTrail trail, including details about
the trail name and its associated logging configurations.
mitre_components:
- Cloud Service Modification
- Cloud Service Metadata
- Application Log Content
- Host Status
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: DeleteTrail
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
@@ -97,7 +104,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "prin
"111111111111", "eventCategory": "Management", "tlsDetails": {"tlsVersion": "TLSv1.2",
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256", "clientProvidedHostHeader": "cloudtrail.us-west-2.amazonaws.com"}}'
output_fields:
- action
- dest
- user
- user_agent
@@ -1,12 +1,17 @@
name: AWS CloudTrail DeleteVirtualMFADevice
id: 84a08d6b-3d59-4260-8cab-84278ada262f
version: 1
date: '2024-07-18'
version: 2
date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Data source object for AWS CloudTrail DeleteVirtualMFADevice
description: Logs an event when a virtual Multi-Factor Authentication (MFA) device
is deleted in AWS CloudTrail.
mitre_components:
- User Account Authentication
- User Account Deletion
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: DeleteVirtualMFADevice
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
@@ -99,7 +104,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "Root", "princip
"managementEvent": true, "recipientAccountId": "111111111111", "eventCategory":
"Management", "sessionCredentialFromConsole": "true"}'
output_fields:
- action
- dest
- user
- user_agent
+8 -4
View File
@@ -1,12 +1,17 @@
name: AWS CloudTrail DeleteWebACL
id: 90da5f08-7961-4c29-8de8-01364982aadf
version: 1
date: '2024-07-18'
version: 2
date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Data source object for AWS CloudTrail DeleteWebACL
description: Logs an event when a Web Access Control List (WebACL) is deleted in AWS
CloudTrail.
mitre_components:
- Cloud Service Modification
- Cloud Service Metadata
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: DeleteWebACL
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
@@ -101,7 +106,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "prin
"111111111111", "eventCategory": "Management", "tlsDetails": {"tlsVersion": "TLSv1.2",
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256", "clientProvidedHostHeader": "waf.amazonaws.com"}}'
output_fields:
- action
- dest
- user
- user_agent
@@ -1,12 +1,17 @@
name: AWS CloudTrail DescribeEventAggregates
id: 7efe4afe-62ae-4f96-81d1-76598ea37fc2
version: 1
date: '2024-07-18'
version: 2
date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Data source object for AWS CloudTrail DescribeEventAggregates
description: Logs an event when aggregate details about AWS events are queried, often
for analysis.
mitre_components:
- Cloud Service Enumeration
- Cloud Service Metadata
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: DescribeEventAggregates
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
@@ -96,7 +101,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "Root", "princip
"AwsApiCall", "managementEvent": true, "recipientAccountId": "1111111111111111", "eventCategory":
"Management", "sessionCredentialFromConsole": "true"}'
output_fields:
- action
- dest
- user
- user_agent
@@ -1,12 +1,18 @@
name: AWS CloudTrail DescribeImageScanFindings
id: 688ea789-9ba2-4970-90a2-17e541e273c9
version: 1
date: '2024-07-18'
version: 2
date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Data source object for AWS CloudTrail DescribeImageScanFindings
description: Logs an event when findings from an image vulnerability scan are described
using the DescribeImageScanFindings operation in AWS CloudTrail.
mitre_components:
- Image Metadata
- Image Modification
- Malware Metadata
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: DescribeImageScanFindings
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
@@ -112,15 +118,15 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "
"accountId": "111111111111", "accessKeyId": "AKIAIOSFODNN7EXAMPLE", "sessionContext":
{"sessionIssuer": {"type": "Role", "principalId": "AKIAIOSFODNN7EXAMPLE", "arn":
"arn:aws:iam::111111111111:role/aws-reserved/test/region/group", "accountId": "111111111111",
"userName": "test"}, "webIdFederationData": {}, "attributes": {"creationDate": "2021-08-11T09:42:53Z",
"mfaAuthenticated": "false"}}}, "eventTime": "2021-08-11T11:52:27Z", "eventSource":
"ecr.amazonaws.com", "eventName": "DescribeImageScanFindings", "awsRegion": "eu-central-1",
"sourceIPAddress": "154.16.165.133", "userAgent": "aws-internal/3 aws-sdk-java/1.11.1030
Linux/4.9.273-0.1.ac.226.84.332.metal1.x86_64 OpenJDK_64-Bit_Server_VM/25.302-b08
"userName": "test"}, "webIdFederationData" : {}, "attributes": {"creationDate":
"2021-08-11T09:42:53Z", "mfaAuthenticated": "false"}}}, "eventTime": "2021-08-11T11:52:27Z",
"eventSource": "ecr.amazonaws.com", "eventName": "DescribeImageScanFindings", "awsRegion":
"eu-central-1" , "sourceIPAddress": "154.16.165.133", "userAgent": "aws-internal/3
aws-sdk-java/1.11.1030 Linux/4.9.273-0.1.ac.226.84.332.metal1.x86_64 OpenJDK_64-Bit_Server_VM/25.302-b08
java/1.8.0_302 vendor/Oracle_Corporation cfg/retry-mode/legacy", "requestParameters":
{"repositoryName": "devsecops/cat_dog_client", "imageId": {"imageDigest": "sha256:a27d73188718a511a1ec1ec788826674b21e097f29873dde734a4dedfbfab1c6"},
"maxResults": 1000}, "responseElements": {"registryId": "111111111111", "repositoryName":
"devsecops/cat_dog_client", "imageId": {"imageDigest": "sha256:a27d73188718a511a1ec1ec788826674b21e097f29873dde734a4dedfbfab1c6"},
"devsecops/cat_dog_client", "imageId": {"imageDigest" : "sha256:a27d73188718a511a1ec1ec788826674b21e097f29873dde734a4dedfbfab1c6"},
"imageScanStatus": {"status": "COMPLETE", "description": "The scan was completed
successfully."}, "imageScanFindings": {"imageScanCompletedAt": "Aug 11, 2021, 11:30:16
AM", "vulnerabilitySourceUpdatedAt": "Aug 11, 2021, 1:17:52 AM", "findings": [{"name":
@@ -376,7 +382,7 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "
able to disclose sensitive information or cause a denial of service condition on
the client system when a user connects to the server.", "uri": "https://security-tracker.debian.org/tracker/CVE-2019-17498",
"severity": "LOW", "attributes": [{"key": "package_version", "value": "1.8.0-2.1"},
{"key": "package_name", "value": "libssh2"}, {"key": "CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:P/I:N/A:P"},
{"key": "package_name", "value": "libssh2"}, {"key" : "CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:P/I:N/A:P"},
{"key": "CVSS2_SCORE", "value": "5.8"}]}, {"name": "CVE-2019-17543", "description":
"LZ4 before 1.9.2 has a heap-based buffer overflow in LZ4_write32 (related to LZ4_compress_destSize),
affecting applications that call LZ4_compress_fast with a large input. (This issue
@@ -409,7 +415,7 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "
"AV:N/AC:L/Au:N/C:P/I:P/A:P"}, {"key": "CVSS2_SCORE", "value": "7.5"}]}, {"name":
"CVE-2011-3374", "description": "It was found that apt-key in apt, all versions,
do not correctly validate gpg keys with the master keyring, leading to a potential
man-in-the-middle attack.", "uri": "https://security-tracker.debian.org/tracker/CVE-2011-3374",
man-in-the-middle attack.", "uri" : "https://security-tracker.debian.org/tracker/CVE-2011-3374",
"severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
"1.8.2.3"}, {"key": "package_name", "value": "apt"}, {"key": "CVSS2_VECTOR", "value":
"AV:N/AC:M/Au:N/C:N/I:P/A:N"}, {"key": "CVSS2_SCORE", "value": "4.3"}]}, {"name":
@@ -564,7 +570,7 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "
other artifacts of the database as we know that a Kerberos database dump file contains
trusted data.", "uri": "https://security-tracker.debian.org/tracker/CVE-2018-5709",
"severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
"1.17-3+deb10u1"}, {"key": "package_name", "value": "krb5"}, {"key": "CVSS2_VECTOR",
"1.17-3+deb10u1"}, {"key": "package_name", "value": "krb5"}, {"key" : "CVSS2_VECTOR",
"value": "AV:N/AC:L/Au:N/C:N/I:P/A:N"}, {"key": "CVSS2_SCORE", "value": "5"}]},
{"name": "CVE-2021-36222", "description": "ec_verify in kdc/kdc_preauth_ec.c in
the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.18.4 and
@@ -651,7 +657,7 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "
"severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
"1.1.32-2.2~deb10u1"}, {"key": "package_name", "value": "libxslt"}, {"key": "CVSS2_VECTOR",
"value": "AV:N/AC:L/Au:N/C:P/I:N/A:N"}, {"key": "CVSS2_SCORE", "value": "5"}]},
{"name": "CVE-2009-4487", "description": "nginx 0.7.64 writes data to a log file
{"name": "CVE-2009-4487" , "description": "nginx 0.7.64 writes data to a log file
without sanitizing non-printable characters, which might allow remote attackers
to modify a window''s title, or possibly execute arbitrary commands or overwrite
files, via an HTTP request containing an escape sequence for a terminal emulator.",
@@ -666,7 +672,7 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "
"severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
"2.4.47+dfsg-3+deb10u6"}, {"key": "package_name", "value": "openldap"}, {"key":
"CVSS2_VECTOR", "value": "AV:N/AC:H/Au:N/C:P/I:P/A:N"}, {"key": "CVSS2_SCORE", "value":
"4"}]}, {"name": "CVE-2015-3276", "description": "The nss_parse_ciphers function
"4"}]}, {"name": "CVE-2015-3276" , "description": "The nss_parse_ciphers function
in libraries/libldap/tls_m.c in OpenLDAP does not properly parse OpenSSL-style multi-keyword
mode cipher strings, which might cause a weaker than intended cipher to be used
and allow remote attackers to have unspecified impact via unknown vectors.", "uri":
@@ -689,7 +695,7 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "
"severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
"2.4.47+dfsg-3+deb10u6"}, {"key": "package_name", "value": "openldap"}, {"key":
"CVSS2_VECTOR", "value": "AV:N/AC:L/Au:N/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value":
"5"}]}, {"name": "CVE-2010-0928", "description": "OpenSSL 0.9.8i on the Gaisler
"5"}]}, {"name": "CVE-2010-0928" , "description": "OpenSSL 0.9.8i on the Gaisler
Research LEON3 SoC on the Xilinx Virtex-II Pro FPGA uses a Fixed Width Exponentiation
(FWE) algorithm for certain signature calculations, and does not verify the signature
before providing it to a caller, which makes it easier for physically proximate
@@ -744,10 +750,10 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "
"2:8.39-12"}, {"key": "package_name", "value": "pcre3"}, {"key": "CVSS2_VECTOR",
"value": "AV:N/AC:L/Au:N/C:N/I:N/A:C"}, {"key": "CVSS2_SCORE", "value": "7.8"}]},
{"name": "CVE-2011-4116", "description": "_is_safe in the File::Temp module for
Perl does not properly handle symlinks.", "uri": "https://security-tracker.debian.org/tracker/CVE-2011-4116",
Perl does not properly handle symlinks.", "uri" : "https://security-tracker.debian.org/tracker/CVE-2011-4116",
"severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
"5.28.1-6+deb10u1"}, {"key": "package_name", "value": "perl"}, {"key": "CVSS2_VECTOR",
"value": "AV:N/AC:L/Au:N/C:N/I:P/A:N"}, {"key": "CVSS2_SCORE", "value": "5"}]},
"5.28.1-6+deb10u1"}, {"key": "package_name", "value": "perl"}, {"key": "CVSS2_VECTOR"
, "value": "AV:N/AC:L/Au:N/C:N/I:P/A:N"}, {"key": "CVSS2_SCORE", "value": "5"}]},
{"name": "CVE-2019-19882", "description": "shadow 4.8, in certain circumstances
affecting at least Gentoo, Arch Linux, and Void Linux, allows local users to obtain
root access because setuid programs are misconfigured. Specifically, this affects
@@ -771,8 +777,8 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "
"1:4.5-1.1"}, {"key": "package_name", "value": "shadow"}, {"key": "CVSS2_VECTOR",
"value": "AV:L/AC:L/Au:N/C:C/I:N/A:N"}, {"key": "CVSS2_SCORE", "value": "4.9"}]},
{"name": "CVE-2013-4235", "description": "shadow: TOCTOU (time-of-check time-of-use)
race condition when copying and removing directory trees", "uri": "https://security-tracker.debian.org/tracker/CVE-2013-4235",
"severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
race condition when copying and removing directory trees", "uri": "https://security-tracker.debian.org/tracker/CVE-2013-4235"
, "severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
"1:4.5-1.1"}, {"key": "package_name", "value": "shadow"}, {"key": "CVSS2_VECTOR",
"value": "AV:L/AC:M/Au:N/C:N/I:P/A:P"}, {"key": "CVSS2_SCORE", "value": "3.3"}]},
{"name": "CVE-2020-13529", "description": "An exploitable denial-of-service vulnerability
@@ -817,7 +823,7 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "
{"name": "CVE-2021-20193", "description": "A flaw was found in the src/list.c of
tar 1.33 and earlier. This flaw allows an attacker who can submit a crafted input
file to tar to cause uncontrolled consumption of memory. The highest threat from
this vulnerability is to system availability.", "uri": "https://security-tracker.debian.org/tracker/CVE-2021-20193",
this vulnerability is to system availability." , "uri": "https://security-tracker.debian.org/tracker/CVE-2021-20193",
"severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
"1.30+dfsg-6"}, {"key": "package_name", "value": "tar"}, {"key": "CVSS2_VECTOR",
"value": "AV:N/AC:M/Au:N/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value": "4.3"}]},
@@ -839,19 +845,19 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "
crafted TIFF image that is mishandled by the TIFFWriteScanline function in tif_write.c,
as demonstrated by tiffdither.", "uri": "https://security-tracker.debian.org/tracker/CVE-2014-8130",
"severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
"4.1.0+git191117-2~deb10u2"}, {"key": "package_name", "value": "tiff"}, {"key":
"4.1.0+git191117-2~deb10u2"}, {"key": "package_name", "value": "tiff" }, {"key":
"CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value":
"4.3"}]}, {"name": "CVE-2017-5563", "description": "LibTIFF version 4.0.7 is vulnerable
to a heap-based buffer over-read in tif_lzw.c resulting in DoS or code execution
via a crafted bmp image to tools/bmp2tiff.", "uri": "https://security-tracker.debian.org/tracker/CVE-2017-5563",
via a crafted bmp image to tools/bmp2tiff." , "uri": "https://security-tracker.debian.org/tracker/CVE-2017-5563",
"severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
"4.1.0+git191117-2~deb10u2"}, {"key": "package_name", "value": "tiff"}, {"key":
"4.1.0+git191117-2~deb10u2"}, {"key": "package_name", "value": "tiff" }, {"key":
"CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:P/I:P/A:P"}, {"key": "CVSS2_SCORE", "value":
"6.8"}]}, {"name": "CVE-2020-35522", "description": "In LibTIFF, there is a memory
malloc failure in tif_pixarlog.c. A crafted TIFF document can lead to an abort,
resulting in a remote denial of service attack.", "uri": "https://security-tracker.debian.org/tracker/CVE-2020-35522",
"severity": "INFORMATIONAL", "attributes": [{"key": "package_version", "value":
"4.1.0+git191117-2~deb10u2"}, {"key": "package_name", "value": "tiff"}, {"key":
"4.1.0+git191117-2~deb10u2"}, {"key": "package_name", "value": "tiff" }, {"key":
"CVSS2_VECTOR", "value": "AV:N/AC:M/Au:N/C:N/I:N/A:P"}, {"key": "CVSS2_SCORE", "value":
"4.3"}]}, {"name": "CVE-2017-9117", "description": "In LibTIFF 4.0.7, the program
processes BMP images without verifying that biWidth and biHeight in the bitmap-information
@@ -881,7 +887,7 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "
comparison also didn''t include the ''issuer cert'' which a transfer can setto qualify
how to verify the server certificate.", "uri": "https://security-tracker.debian.org/tracker/CVE-2021-22924",
"severity": "UNDEFINED", "attributes": [{"key": "package_version", "value": "7.64.0-4+deb10u2"},
{"key": "package_name", "value": "curl"}]}, {"name": "CVE-2021-38115", "description":
{"key": "package_name", "value": "curl" }]}, {"name": "CVE-2021-38115", "description":
"read_header_tga in gd_tga.c in the GD Graphics Library (aka LibGD) through 2.3.2
allows remote attackers to cause a denial of service (out-of-bounds read) via a
crafted TGA file.", "uri": "https://security-tracker.debian.org/tracker/CVE-2021-38115",
@@ -894,7 +900,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "
"readOnly": true, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId":
"111111111111", "eventCategory": "Management"}'
output_fields:
- action
- dest
- user
- user_agent
@@ -1,12 +1,17 @@
name: AWS CloudTrail GetAccountPasswordPolicy
id: 439bdc53-6e4b-4cd7-b326-86c7317fd396
version: 1
date: '2024-07-18'
version: 2
date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Data source object for AWS CloudTrail GetAccountPasswordPolicy
description: Logs an event when a request is made to get the account password policy
in AWS CloudTrail.
mitre_components:
- User Account Authentication
- User Account Metadata
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: GetAccountPasswordPolicy
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
@@ -98,7 +103,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "prin
"111111111111", "eventCategory": "Management", "tlsDetails": {"tlsVersion": "TLSv1.2",
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256", "clientProvidedHostHeader": "iam.amazonaws.com"}}'
output_fields:
- action
- dest
- user
- user_agent
+9 -4
View File
@@ -1,12 +1,18 @@
name: AWS CloudTrail GetObject
id: 5063cb10-84c0-44af-ade4-ab9ecad11dfe
version: 1
date: '2024-07-18'
version: 2
date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Data source object for AWS CloudTrail GetObject
description: Logs an event when a request is made to access an object stored in an
AWS S3 bucket.
mitre_components:
- Cloud Storage Access
- Cloud Storage Metadata
- Cloud Storage Enumeration
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: GetObject
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
@@ -112,7 +118,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "prin
"eventCategory": "Data", "tlsDetails": {"tlsVersion": "TLSv1.2", "cipherSuite":
"ECDHE-RSA-AES128-GCM-SHA256", "clientProvidedHostHeader": "security-content.s3.us-west-2.amazonaws.com"}}'
output_fields:
- action
- dest
- user
- user_agent
@@ -1,12 +1,17 @@
name: AWS CloudTrail GetPasswordData
id: 6ff2ce99-85b1-4c17-888a-56dbc3570671
version: 1
date: '2024-07-18'
version: 2
date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Data source object for AWS CloudTrail GetPasswordData
description: Logs an event when a request is made to retrieve the administrator password
of an EC2 instance.
mitre_components:
- Instance Metadata
- User Account Authentication
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: GetPasswordData
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
@@ -114,7 +119,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "
"111111111111", "eventCategory": "Management", "tlsDetails": {"tlsVersion": "TLSv1.2",
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256", "clientProvidedHostHeader": "ec2.us-west-2.amazonaws.com"}}'
output_fields:
- action
- dest
- user
- user_agent
+7 -4
View File
@@ -1,12 +1,16 @@
name: AWS CloudTrail JobCreated
id: 6473289b-d097-4c86-a837-3cc5ae408155
version: 1
date: '2024-07-18'
version: 2
date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Data source object for AWS CloudTrail JobCreated
description: Logs an event when a new job is created in AWS CloudTrail.
mitre_components:
- Scheduled Job Creation
- Cloud Service Metadata
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: JobCreated
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
@@ -83,7 +87,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"accountId": "1111111111
"status": "New", "jobEventId": "4e70d2f1053c07a79d9be9a14e486020", "failureCodes":
[], "statusChangeReason": []}, "eventCategory": "Management"}'
output_fields:
- action
- dest
- user
- user_agent
@@ -1,12 +1,18 @@
name: AWS CloudTrail ModifyDBInstance
id: bfa2912d-1a33-4b05-be46-543874d68241
version: 1
date: '2024-07-18'
version: 2
date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Data source object for AWS CloudTrail ModifyDBInstance
description: Logs an event when a modification is made to an AWS database instance,
such as parameters or configurations.
mitre_components:
- Instance Modification
- Cloud Service Modification
- Instance Metadata
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: ModifyDBInstance
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
@@ -192,7 +198,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "
"AwsApiCall", "managementEvent": true, "recipientAccountId": "111111111111", "eventCategory":
"Management", "sessionCredentialFromConsole": "true"}'
output_fields:
- action
- dest
- user
- user_agent
@@ -1,12 +1,17 @@
name: AWS CloudTrail ModifyImageAttribute
id: 667c2115-8082-419e-b541-8150066bda4d
version: 1
date: '2024-07-18'
version: 2
date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Data source object for AWS CloudTrail ModifyImageAttribute
description: Logs an event when the attributes of an Amazon Machine Image (AMI) are
modified.
mitre_components:
- Image Modification
- Image Metadata
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: ModifyImageAttribute
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
@@ -107,7 +112,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "
"AwsApiCall", "managementEvent": true, "recipientAccountId": "111111111111", "eventCategory":
"Management", "sessionCredentialFromConsole": "true"}'
output_fields:
- action
- dest
- user
- user_agent
@@ -1,12 +1,16 @@
name: AWS CloudTrail ModifySnapshotAttribute
id: 7e5aa947-3a0d-4ee5-b800-0c10b555da05
version: 1
date: '2024-07-18'
version: 2
date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Data source object for AWS CloudTrail ModifySnapshotAttribute
description: Logs an event when modifications are made to the attributes of a snapshot
in AWS CloudTrail.
mitre_components:
- Snapshot Modification
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: ModifySnapshotAttribute
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
@@ -100,7 +104,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "prin
"111111111111", "eventCategory": "Management", "tlsDetails": {"tlsVersion": "TLSv1.2",
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256", "clientProvidedHostHeader": "ec2.us-west-2.amazonaws.com"}}'
output_fields:
- action
- dest
- user
- user_agent
+8 -4
View File
@@ -1,12 +1,17 @@
name: AWS CloudTrail PutBucketAcl
id: 28fffbfd-d98d-4a42-990b-b04ab47422eb
version: 1
date: '2024-07-18'
version: 2
date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Data source object for AWS CloudTrail PutBucketAcl
description: Logs an event when an ACL is set or modified for an S3 bucket in AWS
CloudTrail.
mitre_components:
- Cloud Storage Modification
- Cloud Storage Metadata
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: PutBucketAcl
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
@@ -115,7 +120,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "prin
"ARN": "arn:aws:s3:::patricktestbucket19"}], "eventType": "AwsApiCall", "managementEvent":
true, "eventCategory": "Management", "recipientAccountId": "111111111111"}'
output_fields:
- action
- dest
- user
- user_agent
@@ -1,12 +1,17 @@
name: AWS CloudTrail PutBucketLifecycle
id: 1c73e954-87b6-4bd7-ac6a-5db7c4082b22
version: 1
date: '2024-07-18'
version: 2
date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Data source object for AWS CloudTrail PutBucketLifecycle
description: Logs an event when a lifecycle configuration is added to an S3 bucket
in AWS CloudTrail.
mitre_components:
- Cloud Storage Modification
- Cloud Storage Metadata
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: PutBucketLifecycle
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
@@ -119,7 +124,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "prin
"Management", "tlsDetails": {"tlsVersion": "TLSv1.2", "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "my-cloudtrail-bucket-alfsujjpnbpguqrh.s3.us-west-2.amazonaws.com"}}'
output_fields:
- action
- dest
- user
- user_agent
@@ -1,12 +1,16 @@
name: AWS CloudTrail PutBucketReplication
id: 0e1362eb-e592-419f-8fa5-556d3a122417
version: 1
date: '2024-07-18'
version: 2
date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Data source object for AWS CloudTrail PutBucketReplication
description: Logs an event when replication configurations are added or modified for
an S3 bucket.
mitre_components:
- Cloud Storage Modification
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: PutBucketReplication
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
@@ -140,7 +144,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "
"Management", "tlsDetails": {"tlsVersion": "TLSv1.2", "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "s3.us-west-2.amazonaws.com"}}'
output_fields:
- action
- dest
- user
- user_agent
@@ -1,12 +1,16 @@
name: AWS CloudTrail PutBucketVersioning
id: 17b2fc7d-c8ce-487c-8815-f9a65a09e980
version: 1
date: '2024-07-18'
version: 2
date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Data source object for AWS CloudTrail PutBucketVersioning
description: Logs an event when the bucket versioning state is modified in an AWS
S3 bucket.
mitre_components:
- Cloud Storage Modification
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: PutBucketVersioning
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
@@ -128,7 +132,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "
"Management", "tlsDetails": {"tlsVersion": "TLSv1.2", "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "s3.us-west-2.amazonaws.com"}}'
output_fields:
- action
- dest
- user
- user_agent
+8 -5
View File
@@ -1,12 +1,17 @@
name: AWS CloudTrail PutImage
id: bb13f10d-0d8c-4fde-9136-b7cfd930e87c
version: 1
date: '2024-07-18'
version: 2
date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Data source object for AWS CloudTrail PutImage
description: Logs an event when a container image is uploaded to a repository in AWS
CloudTrail.
mitre_components:
- Image Creation
- Image Metadata
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: PutImage
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
@@ -150,8 +155,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "prin
"eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId": "111111111111",
"eventCategory": "Management"}'
output_fields:
- action
- dest
- user
- user_agent
- src
+6 -4
View File
@@ -1,9 +1,10 @@
name: AWS CloudTrail PutKeyPolicy
id: 9c54c86b-43b9-4bb8-915d-6838beb7f07c
version: 1
date: '2024-07-18'
version: 2
date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Data source object for AWS CloudTrail PutKeyPolicy
description: Logs changes made to AWS Key Management Service (KMS) key policies, including
updates and permission assignments.
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
@@ -94,6 +95,8 @@ fields:
- vendor_account
- vendor_product
- vendor_region
mitre_components:
- Cloud Service Modification
example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "principalId":
"AROAIJIESMXKGCJRCTPR6:pbareiss@splunk.local", "arn": "arn:aws:sts::111111111111:assumed-role/okta_adm_role/pbareiss@splunk.local",
"accountId": "111111111111", "accessKeyId": "ASIAYTOGP2RLK74OPBDR", "sessionContext":
@@ -131,7 +134,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "
"eventType": "AwsApiCall", "managementEvent": true, "eventCategory": "Management",
"recipientAccountId": "111111111111"}'
output_fields:
- action
- dest
- user
- user_agent
@@ -1,12 +1,16 @@
name: AWS CloudTrail ReplaceNetworkAclEntry
id: db0c240e-3754-40e4-86ef-cde018ee9f65
version: 1
date: '2024-07-18'
version: 2
date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Data source object for AWS CloudTrail ReplaceNetworkAclEntry
description: Logs an event when a network ACL entry is replaced within the AWS CloudTrail.
mitre_components:
- Firewall Rule Modification
- Cloud Service Modification
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: ReplaceNetworkAclEntry
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
@@ -117,7 +121,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "
"46fe04b8-d007-4933-8bb8-c8b65c1121fa", "readOnly": false, "eventType": "AwsApiCall",
"managementEvent": true, "eventCategory": "Management", "recipientAccountId": "111111111111"}'
output_fields:
- action
- dest
- user
- user_agent
@@ -1,12 +1,17 @@
name: AWS CloudTrail SetDefaultPolicyVersion
id: 06e0b5a0-8d36-485e-befc-4ae79d77ef6c
version: 1
date: '2024-07-18'
version: 2
date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Data source object for AWS CloudTrail SetDefaultPolicyVersion
description: Logs an event when the default version of a resource policy in AWS is
set or changed.
mitre_components:
- Cloud Service Modification
- Cloud Service Metadata
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: SetDefaultPolicyVersion
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
@@ -98,7 +103,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "prin
"AwsApiCall", "managementEvent": true, "eventCategory": "Management", "recipientAccountId":
"111111111111"}'
output_fields:
- action
- dest
- user
- user_agent
+7 -4
View File
@@ -1,12 +1,16 @@
name: AWS CloudTrail StopLogging
id: c5de7c54-4809-4659-bf9f-3bacf8bdfd35
version: 1
date: '2024-07-18'
version: 2
date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Data source object for AWS CloudTrail StopLogging
description: Logs an event when a cloud service in AWS, such as CloudTrail, is deactivated
or stopped.
mitre_components:
- Cloud Service Disable
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: StopLogging
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
@@ -94,7 +98,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "prin
"Management", "tlsDetails": {"tlsVersion": "TLSv1.2", "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "cloudtrail.us-west-2.amazonaws.com"}}'
output_fields:
- action
- dest
- user
- user_agent
@@ -1,12 +1,16 @@
name: AWS CloudTrail UpdateAccountPasswordPolicy
id: 35a8cc97-3600-40e1-a5d1-1c2ad5060be0
version: 1
date: '2024-07-18'
version: 2
date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Data source object for AWS CloudTrail UpdateAccountPasswordPolicy
description: Logs an event when an AWS account's password policy is updated.
mitre_components:
- User Account Modification
- Cloud Service Modification
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: UpdateAccountPasswordPolicy
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
@@ -106,7 +110,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "Root", "princip
"readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId":
"111111111111", "eventCategory": "Management", "sessionCredentialFromConsole": "true"}'
output_fields:
- action
- dest
- user
- user_agent
@@ -1,12 +1,16 @@
name: AWS CloudTrail UpdateLoginProfile
id: 1db79158-e5d3-4d35-9d3c-586e44e09f1c
version: 1
date: '2024-07-18'
version: 2
date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Data source object for AWS CloudTrail UpdateLoginProfile
description: Logs an event when an IAM user's login profile is updated.
mitre_components:
- User Account Modification
- User Account Authentication
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: UpdateLoginProfile
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
@@ -96,7 +100,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "prin
"readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "eventCategory":
"Management", "recipientAccountId": "111111111111"}'
output_fields:
- action
- dest
- user
- user_agent
@@ -1,12 +1,17 @@
name: AWS CloudTrail UpdateSAMLProvider
id: e5eb628d-711e-499c-87d9-8fa5dee419ec
version: 1
date: '2024-07-18'
version: 2
date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Data source object for AWS CloudTrail UpdateSAMLProvider
description: Logs an event when a SAML provider is updated in AWS.
mitre_components:
- Cloud Service Modification
- User Account Modification
- Cloud Service Metadata
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: UpdateSAMLProvider
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
@@ -96,7 +101,7 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "
"AROAYTOGP2RLKFUVAQAIJ:rodsoto@rodsoto.onmicrosoft.com", "arn": "arn:aws:sts::111111111111:assumed-role/rodonmicrotestrole/rodsoto@rodsoto.onmicrosoft.com",
"accountId": "111111111111", "accessKeyId": "ASIAYTOGP2RLMZGPIW6C", "sessionContext":
{"sessionIssuer": {"type": "Role", "principalId": "AROAYTOGP2RLKFUVAQAIJ", "arn":
"arn:aws:iam::111111111111:role/rodonmicrotestrole", "accountId": "111111111111",
"arn:aws:iam::111111111111:role/rodonmicrotestrole", "accountId" : "111111111111",
"userName": "rodonmicrotestrole"}, "webIdFederationData": {}, "attributes": {"mfaAuthenticated":
"false", "creationDate": "2021-01-20T03:10:32Z"}}}, "eventTime": "2021-01-20T03:12:39Z",
"eventSource": "iam.amazonaws.com", "eventName": "UpdateSAMLProvider", "awsRegion":
@@ -186,7 +191,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "AssumedRole", "
"readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "eventCategory":
"Management", "recipientAccountId": "111111111111"}'
output_fields:
- action
- dest
- user
- user_agent
+8 -4
View File
@@ -1,12 +1,17 @@
name: AWS CloudTrail UpdateTrail
id: d5b7a1eb-711a-4c96-aa93-235fe3c8a939
version: 1
date: '2024-07-18'
version: 2
date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Data source object for AWS CloudTrail UpdateTrail
description: Logs an event when an AWS CloudTrail trail is updated, typically involving
changes to settings or configuration.
mitre_components:
- Cloud Service Modification
- Cloud Service Metadata
source: aws_cloudtrail
sourcetype: aws:cloudtrail
separator: eventName
separator_value: UpdateTrail
supported_TA:
- name: Splunk Add-on for AWS
url: https://splunkbase.splunk.com/app/1876
@@ -106,7 +111,6 @@ example_log: '{"eventVersion": "1.08", "userIdentity": {"type": "IAMUser", "prin
"Management", "tlsDetails": {"tlsVersion": "TLSv1.2", "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "cloudtrail.us-west-2.amazonaws.com"}}'
output_fields:
- action
- dest
- user
- user_agent
+8 -4
View File
@@ -1,12 +1,16 @@
name: AWS CloudWatchLogs VPCflow
id: 38a34fc4-e128-4478-a8f4-7835d51d5135
version: 1
version: 2
author: Bhavin Patel, Splunk
date: '2024-07-18'
description: Data source object for AWS CloudWatchLogs VPCflow
date: '2025-01-23'
description: Logs an event when network traffic flow information such as source and
destination IPs, ports, protocol, and action (allow/deny) is captured for VPC in
AWS.
mitre_components:
- Network Traffic Flow
- Network Connection Creation
source: aws_cloudwatchlogs_vpcflow
sourcetype: aws:cloudwatchlogs:vpcflow
separator: eventName
supported_TA:
- name: Splunk Add-on for AWS
version: 7.9.1
+9 -3
View File
@@ -1,9 +1,15 @@
name: AWS Security Hub
id: b02bfbf3-294f-478e-99a1-e24b8c692d7e
version: 1
date: '2024-07-18'
version: 2
date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Data source object for AWS Security Hub
description: Logs an event when AWS Security Hub identifies potential security risks
or deviations from configured best practices across AWS accounts.
mitre_components:
- Cloud Service Metadata
- Cloud Service Enumeration
- Cloud Service Modification
- Cloud Service Disable
source: aws_securityhub_finding
sourcetype: aws:securityhub:finding
supported_TA:
+1 -1
View File
@@ -3,7 +3,7 @@ id: 51ca21e5-bda2-4652-bb29-27c7bc18a81c
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
description: Data source object for Azure Active Directory
description: All Azure Active Directory events
source: Azure AD
sourcetype: azure:monitor:aad
separator: operationName
@@ -1,13 +1,20 @@
name: Azure Active Directory Add app role assignment to service principal
id: 8b2e84cd-6db0-47e9-badc-75c17df1995f
version: 1
date: '2024-07-18'
version: 2
date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Data source object for Azure Active Directory Add app role assignment
to service principal
description: Logs the addition of an application role assignment to a service principal
in Azure Active Directory, including details about the role, service principal,
and the user or process performing the action.
mitre_components:
- User Account Modification
- Group Modification
- Cloud Service Modification
- Cloud Service Metadata
source: Azure AD
sourcetype: azure:monitor:aad
separator: operationName
separator_value: Add app role assignment to service principal
supported_TA:
- name: Splunk Add-on for Microsoft Cloud Services
url: https://splunkbase.splunk.com/app/3110
@@ -1,12 +1,20 @@
name: Azure Active Directory Add member to role
id: 1660d196-127f-4678-81b2-472d51711b07
version: 1
date: "2024-07-18"
version: 2
date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Data source object for Azure Active Directory Add member to role
description: Logs the addition of a member to a directory role in Azure Active Directory,
including details about the role, the member added, and the user or process performing
the action.
mitre_components:
- Group Modification
- Group Metadata
- User Account Metadata
- Cloud Service Modification
source: Azure AD
sourcetype: azure:monitor:aad
separator: operationName
separator_value: Add member to role
supported_TA:
- name: Splunk Add-on for Microsoft Cloud Services
url: https://splunkbase.splunk.com/app/3110
@@ -1,12 +1,20 @@
name: Azure Active Directory Add owner to application
id: e895ed56-7be4-4b3a-b782-ecd0f594ec4c
version: 1
date: "2024-07-18"
version: 2
date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Data source object for Azure Active Directory Add owner to application
description: Logs the addition of an owner to an application in Azure Active Directory,
including details about the application, the owner added, and the user or process
performing the action.
mitre_components:
- User Account Modification
- Group Modification
- Cloud Service Modification
- Cloud Service Metadata
source: Azure AD
sourcetype: azure:monitor:aad
separator: operationName
separator_value: Add owner to application
supported_TA:
- name: Splunk Add-on for Microsoft Cloud Services
url: https://splunkbase.splunk.com/app/3110
@@ -1,12 +1,20 @@
name: Azure Active Directory Add service principal
id: fd89d337-e4c0-4162-ad13-bca36f096fe6
version: 1
date: "2024-07-18"
version: 2
date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Data source object for Azure Active Directory Add service principal
description: Logs the creation of a new service principal in Azure Active Directory,
including details about the service principal, associated application, and the user
or process performing the action.
mitre_components:
- Cloud Service Creation
- Cloud Service Metadata
- User Account Metadata
- Active Directory Object Creation
source: Azure AD
sourcetype: azure:monitor:aad
separator: operationName
separator_value: Add service principal
supported_TA:
- name: Splunk Add-on for Microsoft Cloud Services
url: https://splunkbase.splunk.com/app/3110
@@ -1,12 +1,19 @@
name: Azure Active Directory Add unverified domain
id: d4c01fb1-3b88-46d3-bd12-9b9e256450f7
version: 1
date: "2024-07-18"
version: 2
date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Data source object for Azure Active Directory Add unverified domain
description: Logs the addition of an unverified domain to Azure Active Directory,
including details about the domain name and the user or process performing the action.
mitre_components:
- Domain Registration
- Cloud Service Modification
- Cloud Service Metadata
- Configuration Modification
source: Azure AD
sourcetype: azure:monitor:aad
separator: operationName
separator_value: Add unverified domain
supported_TA:
- name: Splunk Add-on for Microsoft Cloud Services
url: https://splunkbase.splunk.com/app/3110
@@ -1,12 +1,20 @@
name: Azure Active Directory Consent to application
id: 4c5d6c49-53e3-4980-a4de-c63e26291ed0
version: 1
date: "2024-07-18"
version: 2
date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Data source object for Azure Active Directory Consent to application
description: Logs user or admin consent to an application's permissions in Azure Active
Directory, including details about the application, granted permissions, and the
consenting user or process.
mitre_components:
- User Account Modification
- Cloud Service Modification
- Cloud Service Metadata
- Configuration Modification
source: Azure AD
sourcetype: azure:monitor:aad
separator: operationName
separator_value: Consent to application
supported_TA:
- name: Splunk Add-on for Microsoft Cloud Services
url: https://splunkbase.splunk.com/app/3110
@@ -1,12 +1,18 @@
name: Azure Active Directory Disable Strong Authentication
id: 8f31966d-c496-496d-8837-f7fd11f31255
version: 1
date: "2024-07-18"
version: 2
date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Data source object for Azure Active Directory Disable Strong Authentication
description: Logs an event when strong authentication methods are disabled in Azure
Active Directory.
mitre_components:
- User Account Authentication
- User Account Modification
- Cloud Service Modification
source: Azure AD
sourcetype: azure:monitor:aad
separator: operationName
separator_value: Disable Strong Authentication
supported_TA:
- name: Splunk Add-on for Microsoft Cloud Services
url: https://splunkbase.splunk.com/app/3110
@@ -1,12 +1,17 @@
name: Azure Active Directory Enable account
id: cb49f3cd-04ad-415c-a5ed-9b27b2829fa7
version: 1
date: "2024-07-18"
version: 2
date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Data source object for Azure Active Directory Enable account
description: Logs an event when an Azure Active Directory account is enabled.
mitre_components:
- User Account Modification
- User Account Authentication
- User Account Metadata
source: Azure AD
sourcetype: azure:monitor:aad
separator: operationName
separator_value: Enable account
supported_TA:
- name: Splunk Add-on for Microsoft Cloud Services
url: https://splunkbase.splunk.com/app/3110
@@ -1,12 +1,18 @@
name: Azure Active Directory Invite external user
id: d3818bd5-f283-4518-8b67-df19240c3e40
version: 1
date: "2024-07-18"
version: 2
date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Data source object for Azure Active Directory Invite external user
description: Logs an event when an external user is invited to join an Azure Active
Directory tenant.
mitre_components:
- Active Directory Object Creation
- User Account Creation
- User Account Authentication
source: Azure AD
sourcetype: azure:monitor:aad
separator: operationName
separator_value: Invite external user
supported_TA:
- name: Splunk Add-on for Microsoft Cloud Services
url: https://splunkbase.splunk.com/app/3110
@@ -1,12 +1,18 @@
name: Azure Active Directory Reset password (by admin)
id: dcd0e4dc-68f8-4b77-a66f-89c57b3afa6b
version: 1
date: "2024-07-18"
version: 2
date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Data source object for Azure Active Directory Reset password (by admin)
description: Logs an event when an admin resets a user's password in Azure Active
Directory.
mitre_components:
- User Account Authentication
- User Account Modification
- Active Directory Object Modification
source: Azure AD
sourcetype: azure:monitor:aad
separator: operationName
separator_value: Reset password (by admin)
supported_TA:
- name: Splunk Add-on for Microsoft Cloud Services
url: https://splunkbase.splunk.com/app/3110
@@ -1,12 +1,18 @@
name: Azure Active Directory Set domain authentication
id: e7bcdab9-908c-40ab-ba38-5db54fa87750
version: 1
date: "2024-07-18"
version: 2
date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Data source object for Azure Active Directory Set domain authentication
description: Logs an event when the authentication method for a domain in Azure Active
Directory is set or modified.
mitre_components:
- Active Directory Object Modification
- User Account Authentication
- Cloud Service Modification
source: Azure AD
sourcetype: azure:monitor:aad
separator: operationName
separator_value: Set domain authentication
supported_TA:
- name: Splunk Add-on for Microsoft Cloud Services
url: https://splunkbase.splunk.com/app/3110
@@ -1,12 +1,18 @@
name: Azure Active Directory Sign-in activity
id: f9ed0a3a-9e20-4198-a035-d0a29593fbe0
version: 1
date: "2024-07-18"
version: 2
date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Data source object for Azure Active Directory Sign-in activity
description: Logs an event when a user attempts to sign into Azure Active Directory,
capturing authentication details and outcomes.
mitre_components:
- User Account Authentication
- Logon Session Creation
- User Account Metadata
source: Azure AD
sourcetype: azure:monitor:aad
separator: operationName
separator_value: Sign-in activity
supported_TA:
- name: Splunk Add-on for Microsoft Cloud Services
url: https://splunkbase.splunk.com/app/3110
@@ -1,12 +1,18 @@
name: Azure Active Directory Update application
id: 2c08188a-ba25-496e-87c7-803cf28b6c90
version: 1
date: "2024-07-18"
version: 2
date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Data source object for Azure Active Directory Update application
description: Logs an event when an application in Azure Active Directory is updated,
such as changes to its settings or permissions.
mitre_components:
- Service Modification
- User Account Modification
- Cloud Service Modification
source: Azure AD
sourcetype: azure:monitor:aad
separator: operationName
separator_value: Update application
supported_TA:
- name: Splunk Add-on for Microsoft Cloud Services
url: https://splunkbase.splunk.com/app/3110
@@ -1,12 +1,18 @@
name: Azure Active Directory Update authorization policy
id: c5b7ffcd-73d8-4fe5-afd8-b1218d715c0c
version: 1
date: "2024-07-18"
version: 2
date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Data source object for Azure Active Directory Update authorization policy
description: Logs an event when an authorization policy is updated in Azure Active
Directory.
mitre_components:
- User Account Modification
- Group Modification
- Active Directory Object Modification
source: Azure AD
sourcetype: azure:monitor:aad
separator: operationName
separator_value: Update authorization policy
supported_TA:
- name: Splunk Add-on for Microsoft Cloud Services
url: https://splunkbase.splunk.com/app/3110
@@ -1,12 +1,16 @@
name: Azure Active Directory Update user
id: 5495c90a-047c-4b8e-b2fe-1db6282d3872
version: 1
date: "2024-07-18"
version: 2
date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Data source object for Azure Active Directory Update user
description: Logs an event when a user account is updated in Azure Active Directory.
mitre_components:
- User Account Modification
- User Account Metadata
source: Azure AD
sourcetype: azure:monitor:aad
separator: operationName
separator_value: Update user
supported_TA:
- name: Splunk Add-on for Microsoft Cloud Services
url: https://splunkbase.splunk.com/app/3110
@@ -1,14 +1,17 @@
name: Azure Active Directory User registered security info
id: b63240de-8a01-4ba8-8987-89d18d4b375d
version: 1
date: "2024-07-18"
version: 2
date: '2025-01-23'
author: Patrick Bareiss, Splunk
description:
Data source object for Azure Active Directory User registered security
info
description: Logs an event when a user registers or updates their security information
in Azure Active Directory.
mitre_components:
- User Account Modification
- User Account Metadata
source: Azure AD
sourcetype: azure:monitor:aad
separator: operationName
separator_value: User registered security info
supported_TA:
- name: Splunk Add-on for Microsoft Cloud Services
url: https://splunkbase.splunk.com/app/3110
@@ -1,14 +1,17 @@
name: Azure Audit Create or Update an Azure Automation account
id: 2ab182e7-feda-4249-9418-32710b55a885
version: 1
date: "2024-07-18"
version: 2
date: '2025-01-23'
author: Patrick Bareiss, Splunk
description:
Data source object for Azure Audit Create or Update an Azure Automation
account
description: Logs an event when an Azure Automation account is created or updated.
mitre_components:
- Cloud Service Creation
- Cloud Service Modification
- Cloud Service Metadata
source: mscs:azure:audit
sourcetype: mscs:azure:audit
separator: operationName.localizedValue
separator_value: Create or Update an Azure Automation account
supported_TA:
- name: Splunk Add-on for Microsoft Cloud Services
url: https://splunkbase.splunk.com/app/3110
@@ -1,14 +1,17 @@
name: Azure Audit Create or Update an Azure Automation Runbook
id: 2bd83221-7a8b-436f-9b2b-efa1d44d009e
version: 1
date: "2024-07-18"
version: 2
date: '2025-01-23'
author: Patrick Bareiss, Splunk
description:
Data source object for Azure Audit Create or Update an Azure Automation
Runbook
description: Logs an event when a new Azure Automation Runbook is created or an existing
one is updated.
mitre_components:
- Scheduled Job Modification
- Scheduled Job Creation
source: mscs:azure:audit
sourcetype: mscs:azure:audit
separator: operationName.localizedValue
separator_value: Create or Update an Azure Automation Runbook
supported_TA:
- name: Splunk Add-on for Microsoft Cloud Services
url: https://splunkbase.splunk.com/app/3110
@@ -1,14 +1,17 @@
name: Azure Audit Create or Update an Azure Automation webhook
id: 575faeb2-09d0-4849-b1f6-eae241f26ff2
version: 1
date: "2024-07-18"
version: 2
date: '2025-01-23'
author: Patrick Bareiss, Splunk
description:
Data source object for Azure Audit Create or Update an Azure Automation
webhook
description: Logs an event when a webhook is created or updated in Azure Automation.
mitre_components:
- Scheduled Job Modification
- Cloud Service Modification
- Scheduled Job Metadata
source: mscs:azure:audit
sourcetype: mscs:azure:audit
separator: operationName.localizedValue
separator_value: Create or Update an Azure Automation webhook
supported_TA:
- name: Splunk Add-on for Microsoft Cloud Services
url: https://splunkbase.splunk.com/app/3110
+1 -1
View File
@@ -1,7 +1,7 @@
name: Azure Monitor Activity
id: 1997a515-a61a-4f78-ada9-54af34c764f2
version: 1
date: "2025-01-13"
date: '2025-01-13'
author: Bhavin Patel, Splunk
description:
Data source object for Azure Monitor Activity. The Splunk Add-on for
-9
View File
@@ -1,9 +0,0 @@
name: Bro
id: c5d9612b-0ffd-44d3-8247-3cf3486ec5e2
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
description: Data source object for Bro
source: bro:http:json
sourcetype: bro:http:json
supported_TA: []
+18
View File
@@ -0,0 +1,18 @@
name: Bro conn
id: c5a7e93b-2172-45a7-a7e9-3b217255a7f5
version: 2
date: '2025-01-23'
author: Jacob Delgado, SnapAttack
description: Logs network connection metadata captured by Zeek (formerly Bro), including
details such as source and destination IPs, ports, connection state, and protocol.
mitre_components:
- Network Connection Creation
- Network Traffic Flow
- Response Metadata
- Application Log Content
source: bro:conn:json
sourcetype: bro:conn:json
supported_TA:
- name: TA for Zeek
url: https://splunkbase.splunk.com/app/5466
version: 1.0.8
+20
View File
@@ -0,0 +1,20 @@
name: Bro dns
id: a4576cbf-06cc-4ed0-976c-bf06ccaed011
version: 2
date: '2025-01-23'
author: Jacob Delgado, SnapAttack
description: Logs DNS queries and responses captured by Zeek (formerly Bro), including
details such as queried domains, resolved IPs, query types, and response codes.
mitre_components:
- Active DNS
- Passive DNS
- Network Traffic Content
- Network Traffic Flow
- Response Metadata
source: bro:dns:json
sourcetype: bro:dns:json
supported_TA:
- name: TA for Zeek
url: https://splunkbase.splunk.com/app/5466
version: 1.0.8
+20
View File
@@ -0,0 +1,20 @@
name: Bro files
id: f72d34d0-3495-4826-ad34-d03495782633
version: 2
date: '2025-01-23'
author: Jacob Delgado, SnapAttack
description: Logs metadata about files transferred over the network captured by Zeek
(formerly Bro), including details such as file names, hashes, MIME types, and transfer
protocols.
mitre_components:
- File Metadata
- Network Traffic Content
- Network Traffic Flow
- Response Metadata
- Application Log Content
source: bro:files:json
sourcetype: bro:files:json
supported_TA:
- name: TA for Zeek
url: https://splunkbase.splunk.com/app/5466
version: 1.0.8
+19
View File
@@ -0,0 +1,19 @@
name: Bro http
id: c5d9612b-0ffd-44d3-8247-3cf3486ec5e2
version: 3
date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Logs HTTP traffic analyzed by Zeek (formerly Bro), including details
such as request methods, URLs, user agents, response codes, and headers.
mitre_components:
- Network Traffic Content
- Network Traffic Flow
- Response Content
- Response Metadata
- Application Log Content
source: bro:http:json
sourcetype: bro:http:json
supported_TA:
- name: TA for Zeek
url: https://splunkbase.splunk.com/app/5466
version: 1.0.8
+18
View File
@@ -0,0 +1,18 @@
name: Bro loaded_scripts
id: 81e08a21-a735-42b1-a08a-21a73582b1bf
version: 2
date: '2025-01-23'
author: Jacob Delgado, SnapAttack
description: Logs details about the scripts loaded by Zeek (formerly Bro) during initialization,
including script names and paths.
mitre_components:
- Application Log Content
- Configuration Modification
- Script Execution
- OS API Execution
source: bro:loaded_scripts:json
sourcetype: bro:loaded_scripts:json
supported_TA:
- name: TA for Zeek
url: https://splunkbase.splunk.com/app/5466
version: 1.0.8
+18
View File
@@ -0,0 +1,18 @@
name: Bro ntp
id: 3f64a544-47a4-4958-a4a5-4447a47958df
version: 2
date: '2025-01-23'
author: Jacob Delgado, SnapAttack
description: Logs Network Time Protocol (NTP) activity captured by Zeek (formerly
Bro), including details such as NTP requests, responses, and server metadata.
mitre_components:
- Network Traffic Flow
- Network Traffic Content
- Response Metadata
- Application Log Content
source: bro:ntp:json
sourcetype: bro:ntp:json
supported_TA:
- name: TA for Zeek
url: https://splunkbase.splunk.com/app/5466
version: 1.0.8
+19
View File
@@ -0,0 +1,19 @@
name: Bro ocsp
id: d20909ab-70be-409a-8909-ab70be609af1
version: 2
date: '2025-01-23'
author: Jacob Delgado, SnapAttack
description: Logs Online Certificate Status Protocol (OCSP) activity captured by Zeek
(formerly Bro), including details such as certificate validation requests and responses.
mitre_components:
- Certificate Registration
- Network Traffic Flow
- Network Traffic Content
- Response Metadata
- Application Log Content
source: bro:ocsp:json
sourcetype: bro:ocsp:json
supported_TA:
- name: TA for Zeek
url: https://splunkbase.splunk.com/app/5466
version: 1.0.8
+19
View File
@@ -0,0 +1,19 @@
name: Bro ssl
id: 22c637eb-f62e-41f0-8637-ebf62e11f0a8
version: 2
date: '2025-01-23'
author: Jacob Delgado, SnapAttack
description: Logs SSL/TLS handshake and session details captured by Zeek (formerly
Bro), including certificates, cipher suites, and session information.
mitre_components:
- Certificate Registration
- Network Traffic Flow
- Network Traffic Content
- Response Metadata
- Application Log Content
source: bro:ssl:json
sourcetype: bro:ssl:json
supported_TA:
- name: TA for Zeek
url: https://splunkbase.splunk.com/app/5466
version: 1.0.8
+19
View File
@@ -0,0 +1,19 @@
name: Bro weird
id: e03762c5-c4b8-44e3-b762-c5c4b8e4e3b6
version: 2
date: '2025-01-23'
author: Jacob Delgado, SnapAttack
description: Logs anomalous or unexpected network behaviors identified by Zeek (formerly
Bro), including protocol violations and unusual traffic patterns.
mitre_components:
- Network Traffic Flow
- Network Traffic Content
- Response Metadata
- Application Log Content
- Host Status
source: bro:weird:json
sourcetype: bro:weird:json
supported_TA:
- name: TA for Zeek
url: https://splunkbase.splunk.com/app/5466
version: 1.0.8
+19
View File
@@ -0,0 +1,19 @@
name: Bro x509
id: e8792367-64b0-47e9-b923-6764b0f7e936
version: 2
date: '2025-01-23'
author: Jacob Delgado, SnapAttack
description: Logs details about X.509 certificates observed in network traffic captured
by Zeek (formerly Bro), including certificate fields, validity periods, and issuers.
mitre_components:
- Certificate Registration
- Network Traffic Content
- Response Metadata
- Application Log Content
- Host Status
source: bro:x509:json
sourcetype: bro:x509:json
supported_TA:
- name: TA for Zeek
url: https://splunkbase.splunk.com/app/5466
version: 1.0.8
+10 -3
View File
@@ -1,9 +1,16 @@
name: CircleCI
id: 34ad06fc-a296-4ab5-8315-2f07714948e3
version: 1
date: '2024-07-18'
version: 2
date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Data source object for CircleCI
description: Logs activities related to CI/CD pipelines executed in CircleCI, including
job execution, workflow progress, and configuration changes.
mitre_components:
- Scheduled Job Execution
- Scheduled Job Metadata
- Application Log Content
- Configuration Modification
- Host Status
source: circleci
sourcetype: circleci
supported_TA:
File diff suppressed because one or more lines are too long
+12 -3
View File
@@ -1,12 +1,21 @@
name: CrowdStrike ProcessRollup2
id: cbb06880-9dd9-4542-ac60-bd6e5d3c3e4e
version: 1
date: '2024-07-18'
version: 2
date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Data source object for CrowdStrike ProcessRollup2
description: Logs process-related activities captured by CrowdStrike, including process
creation, termination, and metadata such as hashes, parent processes, and command-line
arguments.
mitre_components:
- Process Creation
- Process Termination
- Process Metadata
- Command Execution
- OS API Execution
source: crowdstrike
sourcetype: crowdstrike:events:sensor
separator: event_simpleName
separator_value: ProcessRollup2
supported_TA:
- name: Splunk Add-on for CrowdStrike FDR
url: https://splunkbase.splunk.com/app/5579
+10 -3
View File
@@ -1,9 +1,16 @@
name: CrushFTP
id: 8a42ace5-e4c8-4653-80cf-1b8e7e6024ef
version: 1
date: '2024-07-18'
version: 2
date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Data source object for CrushFTP
description: Logs activities related to file transfers and user interactions in CrushFTP,
including file uploads, downloads, user authentication, and session details.
mitre_components:
- File Access
- File Metadata
- User Account Authentication
- Logon Session Metadata
- Network Traffic Content
source: crushftp
sourcetype: crushftp:sessionlogs
supported_TA: []
+10 -3
View File
@@ -1,9 +1,16 @@
name: G Suite Drive
id: 5f79120f-a235-4468-bd0d-55203758ac22
version: 1
date: "2024-07-18"
version: 2
date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Data source object for G Suite Drive
description: Logs activities related to Google Drive in G Suite, including file creation,
modification, sharing, and access details.
mitre_components:
- File Access
- File Creation
- File Modification
- Cloud Storage Access
- Cloud Storage Metadata
source: http:gsuite
sourcetype: gsuite:drive:json
supported_TA:
+9 -3
View File
@@ -1,9 +1,15 @@
name: G Suite Gmail
id: 706c3978-41de-406b-b6e0-75bd01e12a5d
version: 1
date: "2024-07-18"
version: 2
date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Data source object for G Suite Gmail
description: Logs Gmail activities in G Suite, including email sending, receiving,
and access details, as well as potential security-related events.
mitre_components:
- Application Log Content
- User Account Metadata
- Email Metadata
- Cloud Service Metadata
source: http:gsuite
sourcetype: gsuite:gmail:bigquery
supported_TA:
+9 -3
View File
@@ -1,9 +1,15 @@
name: GitHub Webhooks
id: 88aa4632-3c3e-43f6-a00a-998d71f558e3
version: 1
date: '2024-07-18'
version: 2
date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Data source object for GitHub Webooks
description: Data source object for GitHub Webooks
mitre_components:
- User Account Authentication
- Configuration Modification
- Application Log Content
- User Account Metadata
- Scheduled Job Metadata
source: github
sourcetype: aws:firehose:json
supported_TA: []
+1 -1
View File
@@ -1,7 +1,7 @@
name: Google Workspace
id: f1a044e3-113a-4e4d-84f2-b153ade83087
version: 1
date: "2025-02-21"
date: '2025-02-21'
author: Bhavin Patel, Splunk
description: Data source object for Google Workspace
source: google_workspace
@@ -1,12 +1,19 @@
name: Google Workspace login_failure
id: cabec7cf-4008-4899-b47e-39c34a9a1255
version: 1
date: "2024-07-18"
version: 2
date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Data source object for Google Workspace login_failure
description: Logs failed login attempts to Google Workspace accounts, including details
about the user, IP address, and reason for failure.
mitre_components:
- User Account Authentication
- Logon Session Metadata
- User Account Metadata
- Application Log Content
source: gws:reports:admin
sourcetype: gws:reports:admin
separator: event.name
separator_value: login_failure
supported_TA:
- name: Splunk Add-on for Google Workspace
url: https://splunkbase.splunk.com/app/5556
@@ -1,12 +1,19 @@
name: Google Workspace login_success
id: bffe8013-9cdf-4fe6-9c1b-6784391a4951
version: 1
date: "2024-07-18"
version: 2
date: '2025-01-23'
author: Patrick Bareiss, Splunk
description: Data source object for Google Workspace login_success
description: Logs successful login attempts to Google Workspace accounts, including
details about the user, IP address, and session metadata.
mitre_components:
- User Account Authentication
- Logon Session Creation
- User Account Metadata
- Logon Session Metadata
source: gws:reports:admin
sourcetype: gws:reports:admin
separator: event.name
separator_value: login_success
supported_TA:
- name: Splunk Add-on for Google Workspace
url: https://splunkbase.splunk.com/app/5556
+12 -4
View File
@@ -1,9 +1,16 @@
name: Ivanti VTM Audit
id: b04be6e5-2002-4a49-8722-52285635b8f5
version: 1
date: '2024-08-19'
version: 2
date: '2025-01-23'
author: Michael Haag, Splunk
description: Data source object for Ivanti Virtual Traffic Manager (vTM)
description: Logs administrative and operational activities in Ivanti Virtual Traffic
Manager (VTM), including configuration changes, user actions, and system events.
mitre_components:
- Configuration Modification
- Application Log Content
- User Account Metadata
- Host Status
- Service Modification
source: ivanti_vtm
sourcetype: ivanti_vtm_audit
supported_TA: []
@@ -16,4 +23,5 @@ fields:
- AUTH
- USER
- GROUP
example_log: '[19/Aug/2024:19:41:22 +0000] USER=!!ABSENT!! GROUP=!!ABSENT!! AUTH=!!ABSENT!! IP=!!ABSENT!! OPERATION=adduser MODUSER=newadmin MODGROUP=admin'
example_log: '[19/Aug/2024:19:41:22 +0000] USER=!!ABSENT!! GROUP=!!ABSENT!! AUTH=!!ABSENT!!
IP=!!ABSENT!! OPERATION=adduser MODUSER=newadmin MODGROUP=admin'

Some files were not shown because too many files have changed in this diff Show More