mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
Fixing story mappings
This commit is contained in:
@@ -27,7 +27,7 @@ search: '`cloudtrail` eventName=RunInstances errorCode=success `ec2_excessive_ru
|
||||
fit DensityFunction instances_launched threshold=0.0005 into ec2_excessive_runinstances_v1'
|
||||
tags:
|
||||
analytics_story:
|
||||
- Cloud Cryptomining
|
||||
- AWS Cryptomining
|
||||
- Suspicious AWS EC2 Activities
|
||||
detections:
|
||||
- Abnormally High AWS Instances Launched by User - MLTK
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
name: Previously Seen Cloud Compute Images
|
||||
name: Previously Seen Cloud Compute Images - Initial
|
||||
id: 7744597f-d07a-4cea-94a7-e0f8aaebc410
|
||||
version: 1
|
||||
date: '2018-03-12'
|
||||
|
||||
@@ -20,7 +20,7 @@ known_false_positives: Many service accounts configured within an AWS infrastruc
|
||||
human user.
|
||||
tags:
|
||||
analytics_story:
|
||||
- Cloud Cryptomining
|
||||
- AWS Cryptomining
|
||||
- Suspicious AWS EC2 Activities
|
||||
kill_chain_phases:
|
||||
- Actions on Objectives
|
||||
|
||||
@@ -31,7 +31,7 @@ known_false_positives: Many service accounts configured within an AWS infrastruc
|
||||
tags:
|
||||
analytics_story:
|
||||
- Cloud Cryptomining
|
||||
- Suspicious AWS EC2 Activities
|
||||
- Suspicious Cloud Instance Activities
|
||||
kill_chain_phases:
|
||||
- Actions on Objectives
|
||||
mitre_attack_id:
|
||||
|
||||
@@ -29,7 +29,8 @@ known_false_positives: It's possible that a new user will start to modify EC2 in
|
||||
modifying instances that this is the intended behavior.
|
||||
tags:
|
||||
analytics_story:
|
||||
- Suspicious Cloud Change Activity
|
||||
- Suspicious Cloud Change Activity
|
||||
- Suspicious Cloud Instance Activities
|
||||
mitre_attack_id:
|
||||
- T1078.004
|
||||
cis20:
|
||||
|
||||
Reference in New Issue
Block a user