This commit is contained in:
P4T12ICK
2021-03-10 14:44:44 +01:00
parent 34f64d972c
commit 7c134dbb5d
227 changed files with 1502 additions and 3 deletions
@@ -29,4 +29,10 @@ tags:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- displayMessage
- client.geographicalContext.country
- client.geographicalContext.state
- client.geographicalContext.city
security_domain: access
@@ -29,4 +29,11 @@ tags:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- displayMessage
- app
- user
- result
- src_ip
security_domain: access
@@ -35,4 +35,10 @@ tags:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- displayMessage
- client.geographicalContext.city
- client.geographicalContext.state
- user
security_domain: access
@@ -39,4 +39,11 @@ tags:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- Processes.dest_category
- Processes.process
- Processes.process_name
- Processes.dest
- Processes.user
security_domain: endpoint
@@ -47,6 +47,13 @@ tags:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- All_Changes.object_id
- All_Changes.action
- All_Changes.status
- All_Changes.object_category
- All_Changes.user
risk_object: user
risk_object_type: user
risk_score: 10
@@ -48,6 +48,13 @@ tags:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- All_Changes.object_id
- All_Changes.action
- All_Changes.status
- All_Changes.object_category
- All_Changes.user
risk_object: user
risk_object_type: user
risk_score: 40
@@ -46,6 +46,11 @@ tags:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- All_Changes.command
- All_Changes.user
- All_Changes.status
risk_object: user
risk_object_type: user
risk_score: 25
@@ -47,6 +47,12 @@ tags:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- All_Changes.command
- All_Changes.object_category
- All_Changes.status
- All_Changes.user
risk_object: user
risk_object_type: user
risk_score: 25
@@ -50,6 +50,13 @@ tags:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- Authentication.signature
- Authentication.vendor_account
- Authentication.user
- Authentication.user_role
- Authentication.src
risk_object: user
risk_object_type: user
risk_score: 15
@@ -38,4 +38,12 @@ tags:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- eventName
- eventSource
- eventID
- awsRegion
- requestParameters.policy
- userIdentity.principalId
security_domain: threat
@@ -33,4 +33,13 @@ tags:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- eventName
- requestParameters.x-amz-server-side-encryption
- requestParameters.bucketName
- requestParameters.x-amz-copy-source
- requestParameters.key
- userAgent
- region
security_domain: threat
@@ -44,6 +44,18 @@ tags:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- eventName
- requestParameters.ruleAction
- requestParameters.egress
- requestParameters.aclProtocol
- requestParameters.portRange.to
- requestParameters.portRange.from
- requestParameters.cidrBlock
- userName
- userIdentity.principalId
- userAgent
risk_object: userName
risk_object_type: user
risk_score: 10
@@ -40,6 +40,14 @@ tags:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- eventName
- requestParameters.egress
- userName
- userIdentity.principalId
- src
- userAgent
risk_object: userName
risk_object_type: user
risk_score: 5
@@ -40,4 +40,14 @@ tags:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- eventName
- requestParameters.principalArn
- requestParameters.roleArn
- requestParameters.roleSessionName
- recipientAccountId
- responseElements.issuer
- sourceIPAddress
- userAgent
security_domain: threat
@@ -36,4 +36,13 @@ tags:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- eventName
- eventType
- requestParameters.sAMLProviderArn
- userIdentity.sessionContext.sessionIssuer.arn
- sourceIPAddress
- userIdentity.accessKeyId
- userIdentity.principalId
security_domain: threat
@@ -44,6 +44,13 @@ tags:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- All_Changes.user
- All_Changes.user_type
- All_Changes.status
- All_Changes.command
- All_Changes.object
risk_object: user
risk_object_type: user
risk_score: 25
@@ -42,6 +42,12 @@ tags:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- All_Changes.object
- All_Changes.action
- All_Changes.user
- All_Changes.vendor_region
risk_object: user
risk_object_type: user
risk_score: 20
@@ -48,6 +48,12 @@ tags:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- All_Changes.object_id
- All_Changes.action
- All_Changes.vendor_region
- All_Changes.user
risk_object: user
risk_object_type: user
risk_score: 20
@@ -43,6 +43,12 @@ tags:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- All_Changes.object_id
- All_Changes.action
- All_Changes.Instance_Changes.image_id
- All_Changes.user
risk_object: user
risk_object_type: user
risk_score: 20
@@ -43,6 +43,12 @@ tags:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- All_Changes.object_id
- All_Changes.action
- All_Changes.Instance_Changes.instance_type
- All_Changes.user
risk_object: user
risk_object_type: user
risk_score: 20
@@ -43,6 +43,14 @@ tags:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- All_Changes.object_id
- All_Changes.command
- All_Changes.action
- All_Changes.change_type
- All_Changes.status
- All_Changes.user
risk_object: user
risk_object_type: user
risk_score: 10
@@ -58,6 +58,14 @@ tags:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- All_Changes.action
- All_Changes.status
- All_Changes.src
- All_Changes.user
- All_Changes.object
- All_Changes.command
risk_object: user
risk_object_type: user
risk_score: 10
@@ -58,6 +58,14 @@ tags:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- All_Changes.action
- All_Changes.status
- All_Changes.src
- All_Changes.user
- All_Changes.object
- All_Changes.command
risk_object: user
risk_object_type: user
risk_score: 5
@@ -57,6 +57,14 @@ tags:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- All_Changes.object_id
- All_Changes.action
- All_Changes.status
- All_Changes.src
- All_Changes.user
- All_Changes.command
risk_object: user
risk_object_type: user
risk_score: 5
@@ -58,6 +58,14 @@ tags:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- All_Changes.action
- All_Changes.status
- All_Changes.src
- All_Changes.user
- All_Changes.object
- All_Changes.command
risk_object: user
risk_object_type: user
risk_score: 5
@@ -48,6 +48,10 @@ tags:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- Authentication.signature
- Authentication.user
risk_object: user
risk_object_type: user
risk_score: 30
@@ -56,6 +56,11 @@ tags:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- Authentication.signature
- Authentication.user
- Authentication.src
risk_object: user
risk_object_type: user
risk_score: 5
@@ -56,6 +56,11 @@ tags:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- Authentication.signature
- Authentication.user
- Authentication.src
risk_object: user
risk_object_type: user
risk_score: 5
@@ -56,6 +56,11 @@ tags:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- Authentication.signature
- Authentication.user
- Authentication.src
risk_object: user
risk_object_type: user
risk_score: 5
@@ -54,4 +54,11 @@ tags:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- sc_status_
- cs_object_
- c_ip_
- cs_uri_
- cs_method_
security_domain: network
@@ -42,4 +42,15 @@ tags:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- data.resource.type
- data.protoPayload.methodName
- data.protoPayload.serviceData.policyDelta.bindingDeltas{}.action
- data.protoPayload.authenticationInfo.principalEmail
- data.protoPayload.resourceLocation.currentLocations{}
- data.protoPayload.requestMetadata.callerIp
- data.protoPayload.resourceName
- data.protoPayload.serviceData.policyDelta.bindingDeltas{}.role
- data.protoPayload.serviceData.policyDelta.bindingDeltas{}.member
security_domain: network
@@ -43,6 +43,16 @@ tags:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- eventSource
- eventName
- requestParameters.bucketName
- userName
- userIdentity.principalId
- userAgent
- uri
- permission
risk_object: src
risk_object_type: system
risk_score: 20
@@ -44,6 +44,19 @@ tags:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- eventSource
- eventName
- requestParameters.accessControlList.x-amz-grant-read-acp
- requestParameters.accessControlList.x-amz-grant-write
- requestParameters.accessControlList.x-amz-grant-write-acp
- requestParameters.accessControlList.x-amz-grant-full-control
- requestParameters.bucketName
- userName
- userIdentity.principalId
- userAgent
- bucketName
risk_object: src
risk_object_type: system
risk_score: 20
@@ -43,6 +43,11 @@ tags:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- http_status
- bucket_name
- remote_ip
risk_object: src_ip
risk_object_type: system
risk_score: 10
@@ -36,4 +36,13 @@ tags:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- Resources{}.Type
- Title
- Types{}
- vendor_account
- vendor_region
- severity
- dest
security_domain: network
@@ -31,4 +31,9 @@ tags:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- findings{}.Resources{}.Type
- indings{}.Resources{}.Id
- user
security_domain: network
@@ -59,6 +59,11 @@ tags:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- action
- src_ip
- dest_ip
risk_object: src_ip
risk_object_type: system
risk_score: 20
@@ -52,6 +52,10 @@ tags:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- eventName
- userIdentity.arn
risk_object: user
risk_object_type: user
risk_score: 10
@@ -33,4 +33,16 @@ tags:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- Operation
- record_type
- app
- user
- LogonError
- authentication_method
- signature
- UserAgent
- src_ip
- record_type
security_domain: threat
@@ -36,4 +36,13 @@ tags:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- Workload
- Operation
- Actor{}.ID
- Actor{}.Type
- ActorIpAddress
- dest
- ResultStatus
security_domain: threat
@@ -39,4 +39,13 @@ tags:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- Workload
- signature
- Actor{}.ID
- ModifiedProperties{}.Name
- ModifiedProperties{}.NewValue
- Target{}.ID
- ActorIpAddress
security_domain: threat
@@ -39,4 +39,16 @@ tags:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- signature
- ModifiedProperties{}.Name
- ModifiedProperties{}.NewValue
- ModifiedProperties{}.OldValue
- user
- vendor_product
- vendor_account
- status
- user_id
- action
security_domain: threat
+9
View File
@@ -32,4 +32,13 @@ tags:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- Operation
- UserType
- user
- status
- signature
- dest
- ResultStatus
security_domain: threat
@@ -33,4 +33,12 @@ tags:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- Workload
- UserAuthenticationMethod
- status
- UserAgent
- src_ip
- user
security_domain: threat
@@ -34,4 +34,11 @@ tags:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- Workload
- LogonError
- ActorIpAddress
- UserAgent
- UserId
security_domain: threat
@@ -38,4 +38,14 @@ tags:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- Workload
- Operation
- Parameters{}.Value
- ObjectId
- OrganizationName
- OriginatingServer
- UserId
- UserKey
security_domain: threat
@@ -33,4 +33,12 @@ tags:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- Category
- Name
- Source
- Severity
- AlertEntityId
- Operation
security_domain: threat
@@ -35,4 +35,8 @@ tags:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- Operation
- Parameters
security_domain: threat
@@ -35,4 +35,8 @@ tags:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- Operation
- Parameters
security_domain: threat
@@ -35,4 +35,8 @@ tags:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- Operation
- Parameters
security_domain: threat
@@ -57,4 +57,6 @@ tags:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
security_domain: network
@@ -30,4 +30,7 @@ tags:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
-
security_domain: threat
@@ -41,4 +41,6 @@ tags:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
security_domain: threat
@@ -40,4 +40,13 @@ tags:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- EventCode
- TargetImage
- CallTrace
- Computer
- TargetProcessId
- SourceImage
- SourceProcessId
security_domain: endpoint
@@ -45,4 +45,10 @@ tags:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- Processes.process
- Processes.process_name
- Processes.parent_process
- Processes.user
security_domain: endpoint
@@ -45,4 +45,10 @@ tags:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- Registry.registry_path
- Registry.registry_key_name
- Registry.registry_value_name
- Registry.dest
security_domain: endpoint
@@ -52,4 +52,10 @@ tags:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- Processes.process_name
- Processes.process
- Processes.dest
- Processes.user
security_domain: endpoint
@@ -42,4 +42,9 @@ tags:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- Processes.process_name
- Processes.process
- Processes.dest
security_domain: endpoint
@@ -46,4 +46,10 @@ tags:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- Filesystem.dest
- Filesystem.file_name
- Filesystem.user
- Filesystem.file_path
security_domain: endpoint
@@ -41,4 +41,11 @@ tags:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- Processes.process_name
- Processes.process
- Processes.parent_process_name
- Processes.dest
- Processes.user
security_domain: endpoint
@@ -33,4 +33,10 @@ tags:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- Processes.process
- Processes.process_name
- Processes.parent_process
- Processes.user
security_domain: endpoint
@@ -57,4 +57,10 @@ tags:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- Filesystem.user
- Filesystem.dest
- Filesystem.file_path
- Filesystem.file_name
security_domain: endpoint
@@ -43,4 +43,10 @@ tags:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- Filesystem.user
- Filesystem.dest
- Filesystem.file_path
- Filesystem.file_name
security_domain: endpoint
@@ -44,4 +44,11 @@ tags:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- Processes.user
- Processes.parent_process
- Processes.process_name
- Processes.process
- Processes.dest
security_domain: endpoint
@@ -43,4 +43,11 @@ tags:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- Processes.user
- Processes.parent_process
- Processs.process_name
- Processes.process
- Processes.dest
security_domain: endpoint
@@ -40,4 +40,12 @@ tags:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- EventID
- TargetImage
- Computer
- EventCode
- TargetImage
- TargetProcessId
security_domain: endpoint
@@ -46,4 +46,11 @@ tags:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- EventID
- process_name
- TargetFilename
- Computer
- object_category
security_domain: endpoint
@@ -43,4 +43,13 @@ tags:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- Processes.process_name
- Processes.process
- Processes.dest
- Processes.user
- Processes.parent_process
- Processes.process_id
- Processes.parent_process_id
security_domain: endpoint
@@ -39,4 +39,10 @@ tags:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- Processes.process_name
- Processes.process
- Processes.user
- Processes.dest
security_domain: endpoint
@@ -42,4 +42,13 @@ tags:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- Processes.process_name
- Processes.process
- Processes.dest
- Processes.user
- Processes.parent_process
- Processes.process_id
- Processes.parent_process_id
security_domain: endpoint
@@ -40,4 +40,13 @@ tags:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- Processes.process_name
- Processes.process
- Processes.dest
- Processes.user
- Processes.parent_process
- Processes.process_id
- Processes.parent_process_id
security_domain: endpoint
@@ -48,4 +48,12 @@ tags:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- Processes.process
- Processes.parent_process
- Processes.process_name
- Processes.user
- Processes.parent_process_name
- Processes.dest
security_domain: endpoint
@@ -41,4 +41,12 @@ tags:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- EventCode
- Logon_Type
- Logon_Process
- WorkstationName
- user
- dest
security_domain: access
@@ -37,4 +37,11 @@ tags:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- EventCode
- TargetUserName
- LogonType
- TargetDomainName
- user
security_domain: endpoint
@@ -47,4 +47,14 @@ tags:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- EventCode
- TargetImage
- GrantedAccess
- Computer
- SourceImage
- SourceProcessId
- TargetImage
- TargetProcessId
security_domain: endpoint
@@ -49,4 +49,10 @@ tags:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- All_Changes.user
- nodename
- All_Changes.result
- All_Changes.dest
security_domain: access

Some files were not shown because too many files have changed in this diff Show More