Branch was auto-updated.

This commit is contained in:
srv-rr-gh-researchbt
2023-06-12 11:29:03 -07:00
committed by GitHub
11 changed files with 696 additions and 0 deletions
@@ -0,0 +1,68 @@
name: ASL AWS Concurrent Sessions From Different Ips
id: b3424bbe-3204-4469-887b-ec144483a336
version: 1
date: '2023-05-23'
author: Patrick Bareiss, Splunk
status: experimental
type: Anomaly
description: The following analytic identifies an AWS IAM account with concurrent
sessions coming from more than one unique IP address within the span of 5 minutes.
This behavior could represent a session hijacking attack whereby an adversary has
extracted cookies from a victims browser and is using them from a different location
to access corporate online resources. When a user navigates the AWS Console after
authentication, the API call with the event name `DescribeEventAggregates` is registered
in the AWS CloudTrail logs. The Splunk Threat Research team leveraged this event
name to identify 2 concurrent sessions. The presence of this event occurring from
two different IP addresses is highly unlikely. As users may behave differently across
organizations, security teams should test and customize this detection to fit their
environments.
data_source: []
search: ' `amazon_security_lake` api.operation=DescribeEventAggregates src_endpoint.domain!="AWS Internal"
| bin span=5m _time
| stats values(src_endpoint.ip) as src_endpoint.ip dc(src_endpoint.ip) as distinct_ip_count
by _time identity.user.credential_uid identity.user.name
| where distinct_ip_count > 1
| `aws_concurrent_sessions_from_different_ips_filter`'
how_to_implement: You must install Splunk AWS Add on and Splunk App for AWS. This
search works with Amazon Security Lake logs.
known_false_positives: A user with concurrent sessions from different Ips may also
represent the legitimate use of more than one device. Filter as needed and/or customize
the threshold to fit your environment.
references:
- https://attack.mitre.org/techniques/T1185/
- https://breakdev.org/evilginx-2-next-generation-of-phishing-2fa-tokens/
- https://github.com/kgretzky/evilginx2
tags:
analytic_story:
- Compromised User Account
- AWS Identity and Access Management Account
asset_type: AWS Account
confidence: 60
impact: 70
message: User $identity.user.name$ has concurrent sessions from more than one unique IP address
$src_endpoint.ip$ in the span of 5 minutes.
mitre_attack_id:
- T1185
observable:
- name: identity.user.credential_uid
type: User
role:
- Victim
- name: src_endpoint.ip
type: IP Address
role:
- Attacker
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- api.operation
- src_endpoint.domain
- src_endpoint.ip
- identity.user.credential_uid
- identity.user.name
risk_score: 42
security_domain: threat
@@ -0,0 +1,81 @@
name: ASL AWS CreateAccessKey
id: ccb3e4af-23d6-407f-9842-a26212816c9e
version: 1
date: '2022-05-23'
author: Patrick Bareiss, Splunk
status: experimental
type: Hunting
description: This search looks for AWS CloudTrail events where a user A who has already
permission to create access keys, makes an API call to create access keys for another
user B. Attackers have been know to use this technique for Privilege Escalation
in case new victim(user B) has more permissions than old victim(user B)
data_source: []
search: '`amazon_security_lake` api.operation=CreateAccessKey http_request.user_agent!=console.amazonaws.com api.response.error=null
| rename unmapped{}.key as unmapped_key , unmapped{}.value as unmapped_value
| eval keyjoin=mvzip(unmapped_key,unmapped_value)
| mvexpand keyjoin
| rex field=keyjoin "^(?<key>[^,]+),(?<value>.*)$"
| eval {key} = value
| search responseElements.accessKey.userName = *
| rename identity.user.name as identity_user_name, responseElements.accessKey.userName as responseElements_accessKey_userName
| eval match=if(identity_user_name=responseElements_accessKey_userName,1,0)
| search match=0
| rename identity_user_name as identity.user.name , responseElements_accessKey_userName as responseElements.accessKey.userName
| stats count min(_time) as firstTime max(_time) as lastTime by responseElements.accessKey.userName
api.operation api.service.name identity.user.account_uid identity.user.credential_uid identity.user.name
identity.user.type identity.user.uid identity.user.uuid http_request.user_agent src_endpoint.ip
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
|`asl_aws_createaccesskey_filter`'
how_to_implement: You must install splunk AWS add on and Splunk App for AWS. This
search works with Amazon Security Lake logs.
known_false_positives: While this search has no known false positives, it is possible
that an AWS admin has legitimately created keys for another user.
references:
- https://bishopfox.com/blog/privilege-escalation-in-aws
- https://rhinosecuritylabs.com/aws/aws-privilege-escalation-methods-mitigation-part-2/
tags:
analytic_story:
- AWS IAM Privilege Escalation
asset_type: AWS Account
confidence: 90
impact: 70
message: User $responseElements.accessKey.userName$ is attempting to create access keys for $responseElements.accessKey.userName$
from this IP $src_endpoint.ip$
mitre_attack_id:
- T1078
observable:
- name: src_endpoint.ip
type: IP Address
role:
- Attacker
- name: identity.user.name
type: User
role:
- Attacker
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- api.service.name
- api.operation
- identity.user.account_uid
- identity.user.credential_uid
- identity.user.name
- identity.user.type
- identity.user.uid
- identity.user.uuid
- http_request.user_agent
- src_endpoint.ip
- unmapped{}.key
- unmapped{}.value
risk_score: 63
security_domain: threat
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078/amazon_security_lake.json
sourcetype: aws:asl
source: aws_asl
update_timestamp: true
@@ -0,0 +1,65 @@
name: ASL AWS Defense Evasion Delete Cloudtrail
id: 1f0b47e5-0134-43eb-851c-e3258638945e
version: 1
date: '2023-05-31'
author: Patrick Bareiss, Splunk
status: experimental
type: TTP
description: This analytic identifies AWS `DeleteTrail` events within CloudTrail logs.
Adversaries often try to impair their target's defenses by stopping their malicious
activity from being logged, so that they may operate with stealth and avoid detection.
When the adversary has the right type of permissions in the compromised AWS environment,
they may delete the the entire cloudtrail that is logging activities in the environment.
data_source: []
search: '`amazon_security_lake` api.operation=DeleteTrail
| stats count min(_time) as firstTime max(_time) as lastTime by identity.user.account_uid identity.user.credential_uid identity.user.name
identity.user.type identity.user.uid identity.user.uuid http_request.user_agent src_endpoint.ip cloud.region | `security_content_ctime(firstTime)`|
`security_content_ctime(lastTime)`| `asl_aws_defense_evasion_delete_cloudtrail_filter`'
how_to_implement: You must install Splunk AWS Add on and enable Amazon Security Lake logs in
your AWS Environment.
known_false_positives: While this search has no known false positives, it is possible
that an AWS admin has stopped cloudTrail logging. Please investigate this activity.
references:
- https://attack.mitre.org/techniques/T1562/008/
tags:
analytic_story:
- AWS Defense Evasion
asset_type: AWS Account
confidence: 90
impact: 100
message: User $identity.user.name$ has delete a CloudTrail logging for account id $identity.user.account_uid$
mitre_attack_id:
- T1562.008
- T1562
observable:
- name: src_endpoint.ip
type: IP Address
role:
- Attacker
- name: identity.user.name
type: User
role:
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- api.service.name
- api.operation
- identity.user.account_uid
- identity.user.credential_uid
- identity.user.name
- identity.user.type
- identity.user.uid
- identity.user.uuid
- http_request.user_agent
- src_endpoint.ip
risk_score: 90
security_domain: threat
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.008/stop_delete_cloudtrail/amazon_security_lake.json
sourcetype: aws:asl
source: aws_asl
@@ -0,0 +1,66 @@
name: ASL AWS Defense Evasion Delete CloudWatch Log Group
id: 0f701b38-a0fb-43fd-a83d-d12265f71f33
version: 1
date: '2023-05-31'
author: Patrick Bareiss, Splunk
status: experimental
type: TTP
description: This analytic identifies AWS `DeleteLogGroup` events in CloudTrail logs.
Attackers may evade the logging capability by deleting the log group in CloudWatch.
This will stop sending the logs and metrics to CloudWatch. When the adversary has
the right type of permissions within the compromised AWS environment, they may delete
the CloudWatch log group that is logging activities in the environment.
data_source: []
search: '`amazon_security_lake` api.operation=DeleteLogGroup
| stats count min(_time) as firstTime max(_time) as lastTime by identity.user.account_uid identity.user.credential_uid identity.user.name
identity.user.type identity.user.uid identity.user.uuid http_request.user_agent src_endpoint.ip cloud.region | `security_content_ctime(firstTime)`|
`security_content_ctime(lastTime)`| `asl_aws_defense_evasion_delete_cloudwatch_log_group_filter`'
how_to_implement: You must install Splunk AWS Add on and enable Amazon Security Lake logs in
your AWS Environment.
known_false_positives: While this search has no known false positives, it is possible
that an AWS admin has deleted CloudWatch logging. Please investigate this activity.
references:
- https://attack.mitre.org/techniques/T1562/008/
tags:
analytic_story:
- AWS Defense Evasion
asset_type: AWS Account
confidence: 90
impact: 100
message: User $identity.user.name$ has deleted a CloudWatch logging group for account id $identity.user.account_uid$
mitre_attack_id:
- T1562
- T1562.008
observable:
- name: src_endpoint.ip
type: IP Address
role:
- Attacker
- name: identity.user.name
type: User
role:
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- api.service.name
- api.operation
- identity.user.account_uid
- identity.user.credential_uid
- identity.user.name
- identity.user.type
- identity.user.uid
- identity.user.uuid
- http_request.user_agent
- src_endpoint.ip
risk_score: 90
security_domain: threat
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.008/delete_cloudwatch_log_group/amazon_security_lake.json
source: aws_asl
sourcetype: aws:asl
update_timestamp: true
@@ -0,0 +1,72 @@
name: ASL AWS Defense Evasion Impair Security Services
id: 5029b681-0462-47b7-82e7-f7e3d37f5a2d
version: 1
date: '2023-06-01'
author: Patrick Bareiss, Bhavin Patel, Gowthamaraj Rajendran, Splunk
status: experimental
type: Hunting
description: This analytic looks for several delete specific API calls made to AWS
Security Services like CloudWatch, GuardDuty and Web Application Firewalls. These
API calls are often leveraged by adversaries to weaken existing security defenses
by deleting logging configurations in the CloudWatch alarm, delete a set of detectors
from your Guardduty environment or simply delete a bunch of CloudWatch alarms to
remain stealthy and avoid detection.
data_source: []
search: '`amazon_security_lake` api.operation IN ("DeleteLogStream","DeleteDetector","DeleteIPSet","DeleteWebACL","DeleteRule","DeleteRuleGroup","DeleteLoggingConfiguration","DeleteAlarms")
| stats count min(_time) as firstTime max(_time) as lastTime by api.operation identity.user.account_uid identity.user.credential_uid identity.user.name
identity.user.type identity.user.uid identity.user.uuid http_request.user_agent src_endpoint.ip cloud.region
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`| `asl_aws_defense_evasion_impair_security_services_filter`'
how_to_implement: You must install Splunk AWS Add on and enable Amazon Security Lake logs in
your AWS Environment.
known_false_positives: While this search has no known false positives, it is possible
that it is a legitimate admin activity. Please consider filtering out these noisy
events using userAgent, user_arn field names.
references:
- https://docs.aws.amazon.com/cli/latest/reference/guardduty/index.html
- https://docs.aws.amazon.com/cli/latest/reference/waf/index.html
- https://www.elastic.co/guide/en/security/current/prebuilt-rules.html
tags:
analytic_story:
- AWS Defense Evasion
asset_type: AWS Account
confidence: 60
impact: 70
message: User $identity.user.name$ has made potentially risky api calls $api.operation$ that could
impair AWS security services for account id $identity.user.account_uid$
mitre_attack_id:
- T1562.008
- T1562
observable:
- name: src_endpoint.ip
type: IP Address
role:
- Attacker
- name: identity.user.name
type: User
role:
- Attacker
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- api.service.name
- api.operation
- identity.user.account_uid
- identity.user.credential_uid
- identity.user.name
- identity.user.type
- identity.user.uid
- identity.user.uuid
- http_request.user_agent
- src_endpoint.ip
risk_score: 42
security_domain: threat
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.008/aws_delete_security_services/amazon_security_lake.json
sourcetype: aws:asl
source: aws_asl
update_timestamp: true
@@ -0,0 +1,51 @@
name: ASL AWS Excessive Security Scanning
id: ff2bfdbc-65b7-4434-8f08-d55761d1d446
version: 1
date: '2023-06-01'
author: Patrick Bareiss, Splunk
status: experimental
type: Anomaly
description: This search looks for AWS CloudTrail events and analyse the amount of
eventNames which starts with Describe by a single user. This indicates that this
user scans the configuration of your AWS cloud environment.
data_source: []
search: '`amazon_security_lake` api.operation=Describe* OR api.operation=List* OR api.operation=Get*
| stats dc(api.operation) as dc_api_operations min(_time) as firstTime max(_time) as lastTime values(http_request.user_agent) as http_request.user_agent
values(src_endpoint.ip) as src_endpoint.ip values(cloud.region) as cloud.region values(identity.user.account_uid) as identity.user.account_uid by identity.user.name
| where dc_api_operations > 50 | `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`|`asl_aws_excessive_security_scanning_filter`'
how_to_implement: You must install splunk AWS add on and Splunk App for AWS. This
search works with Amazon Security Lake logs.
known_false_positives: While this search has no known false positives.
references:
- https://github.com/aquasecurity/cloudsploit
tags:
analytic_story:
- AWS User Monitoring
asset_type: AWS Account
confidence: 60
impact: 30
message: user $identity.user.name$ has excessive number of api calls.
mitre_attack_id:
- T1526
observable:
- name: src_endpoint.ip
type: IP Address
role:
- Attacker
- name: identity.user.name
type: User
role:
- Attacker
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- api.operation
- identity.user.account_uid
- identity.user.name
- http_request.user_agent
- src_endpoint.ip
risk_score: 18
security_domain: network
@@ -0,0 +1,70 @@
name: ASL AWS IAM Delete Policy
id: 609ced68-d420-4ff7-8164-ae98b4b4018c
version: 1
date: '2023-06-02'
author: Patrick Bareiss, Splunk
status: experimental
type: Hunting
description: The following detection identifes when a policy is deleted on AWS. This
does not identify whether successful or failed, but the error messages tell a story
of suspicious attempts. There is a specific process to follow when deleting a policy.
First, detach the policy from all users, groups, and roles that the policy is attached
to, using DetachUserPolicy , DetachGroupPolicy , or DetachRolePolicy.
data_source: []
search: '`amazon_security_lake` api.operation=DeletePolicy | stats count min(_time) as firstTime max(_time) as lastTime by api.operation
api.service.name identity.user.account_uid identity.user.credential_uid identity.user.name identity.user.type identity.user.uid identity.user.uuid
http_request.user_agent src_endpoint.ip cloud.region | `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)` | `asl_aws_iam_delete_policy_filter`'
how_to_implement: The Splunk AWS Add-on and Splunk App for AWS is required to utilize
this data. The search requires Amazon Security Lake logs.
known_false_positives: This detection will require tuning to provide high fidelity
detection capabilties. Tune based on src addresses (corporate offices, VPN terminations)
or by groups of users. Not every user with AWS access should have permission to
delete policies (least privilege). In addition, this may be saved seperately and
tuned for failed or success attempts only.
references:
- https://docs.aws.amazon.com/IAM/latest/APIReference/API_DeletePolicy.html
- https://docs.aws.amazon.com/cli/latest/reference/iam/delete-policy.html
tags:
analytic_story:
- AWS IAM Privilege Escalation
asset_type: AWS Account
confidence: 50
impact: 20
message: User $user_arn$ has deleted AWS Policies from IP address $src$ by executing
the following command $eventName$
mitre_attack_id:
- T1098
observable:
- name: src_endpoint.ip
type: IP Address
role:
- Attacker
- name: identity.user.name
type: User
role:
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- api.service.name
- api.operation
- identity.user.account_uid
- identity.user.credential_uid
- identity.user.name
- identity.user.type
- identity.user.uid
- identity.user.uuid
- http_request.user_agent
- src_endpoint.ip
risk_score: 10
security_domain: access
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1098/aws_iam_delete_policy/amazon_security_lake.json
sourcetype: aws:asl
source: aws_asl
update_timestamp: true
@@ -0,0 +1,79 @@
name: ASL AWS Multi-Factor Authentication Disabled
id: 4d2df5e0-1092-4817-88a8-79c7fa054668
version: 1
date: '2023-06-02'
author: Patrick Bareiss, Splunk
status: experimental
type: TTP
description: The following analytic identifies an attempt to disable multi-factor
authentication for an AWS IAM user. An adversary who has obtained access to an AWS
tenant may disable multi-factor authentication as a way to plant a backdoor and
maintain persistence using a valid account. This way the attackers can keep persistance
in the environment without adding new users.
data_source: []
search: '`amazon_security_lake` (api.operation=DeleteVirtualMFADevice OR api.operation=DeactivateMFADevice)
| stats count min(_time) as firstTime max(_time) as lastTime by api.operation
api.service.name identity.user.account_uid identity.user.credential_uid identity.user.name identity.user.type
identity.user.uid identity.user.uuid
http_request.user_agent src_endpoint.ip cloud.region
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `asl_aws_multi_factor_authentication_disabled_filter`'
how_to_implement: The Splunk AWS Add-on is required to utilize this data. The search
requires Amazon Security Lake logs.
known_false_positives: AWS Administrators may disable MFA but it is highly unlikely
for this event to occur without prior notice to the company
references:
- https://attack.mitre.org/techniques/T1621/
- https://aws.amazon.com/what-is/mfa/
tags:
analytic_story:
- AWS Identity and Access Management Account Takeover
asset_type: AWS Account
confidence: 80
impact: 80
message: User $user_name$ has disabled Multi-Factor authentication for AWS account
$aws_account_id$
mitre_attack_id:
- T1586
- T1586.003
- T1621
- T1556
- T1556.006
observable:
- name: identity.user.account_uid
type: Other
role:
- Victim
- name: identity.user.name
type: User
role:
- Victim
- name: src_endpoint.ip
type: IP Address
role:
- Attacker
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- api.service.name
- api.operation
- identity.user.account_uid
- identity.user.credential_uid
- identity.user.name
- identity.user.type
- identity.user.uid
- identity.user.uuid
- http_request.user_agent
- src_endpoint.ip
risk_score: 64
security_domain: threat
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1621/aws_mfa_disabled/amazon_security_lake.json
sourcetype: aws:asl
source: aws_asl
update_timestamp: true
@@ -0,0 +1,70 @@
name: ASL AWS New MFA Method Registered For User
id: 33ae0931-2a03-456b-b1d7-b016c5557fbd
version: 1
date: '2023-05-22'
author: Patrick Bareiss, Splunk
status: production
type: TTP
description: The following analytic identifies the registration of a new Multi Factor
authentication method for an AWS account logged through Amazon Secruity Lake (ASL). Adversaries who have obtained unauthorized
access to an AWS account may register a new MFA method to maintain persistence.
data_source: []
search: ' `amazon_security_lake` api.operation=CreateVirtualMFADevice | stats count min(_time) as firstTime max(_time) as lastTime by api.operation
api.service.name identity.user.account_uid identity.user.credential_uid identity.user.name identity.user.type identity.user.uid identity.user.uuid
http_request.user_agent src_endpoint.ip cloud.region
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `asl_aws_new_mfa_method_registered_for_user_filter`'
how_to_implement: You must install Splunk AWS add on and Splunk App for AWS. This
search works with Amazon Security Lake logs.
known_false_positives: Newly onboarded users who are registering an MFA method for
the first time will also trigger this detection.
references:
- https://aws.amazon.com/blogs/security/you-can-now-assign-multiple-mfa-devices-in-iam/
- https://attack.mitre.org/techniques/T1556/
- https://attack.mitre.org/techniques/T1556/006/
- https://twitter.com/jhencinski/status/1618660062352007174
tags:
analytic_story:
- Compromised User Account
- Azure Active Directory Account Takeover
asset_type: Azure Active Directory
confidence: 80
impact: 80
message: A new virtual device is added to user $identity.user.name$
mitre_attack_id:
- T1556
- T1556.006
observable:
- name: identity.user.name
type: User
role:
- Victim
- name: src_endpoint.ip
type: IP Address
role:
- Attacker
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- api.service.name
- api.operation
- identity.user.account_uid
- identity.user.credential_uid
- identity.user.name
- identity.user.type
- identity.user.uid
- identity.user.uuid
- http_request.user_agent
- src_endpoint.ip
risk_score: 64
security_domain: identity
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1556.006/aws_new_mfa_method_registered_for_user/amazon_security_lake.json
sourcetype: aws:asl
source: aws_asl
update_timestamp: true
@@ -0,0 +1,70 @@
name: ASL AWS Password Policy Changes
id: 5ade5937-11a2-4363-ba6b-39a3ee8d5b1a
version: 1
date: '2023-05-22'
author: Patrick Bareiss, Splunk
status: production
type: Hunting
description: This search looks for AWS CloudTrail events from Amazon Security Lake where a user is making successful
API calls to view/update/delete the existing password policy in an AWS organization.
It is unlikely for a regular user to conduct this operation. These events may potentially
be malicious, adversaries often use this information to gain more understanding
of the password defenses in place and exploit them to increase their attack surface
when a user account is compromised.
data_source: []
search: '`amazon_security_lake` "api.service.name"="iam.amazonaws.com" "api.operation" IN ("UpdateAccountPasswordPolicy","GetAccountPasswordPolicy","DeleteAccountPasswordPolicy") "api.response.error"=null
| stats count min(_time) as firstTime max(_time) as lastTime by identity.user.account_uid identity.user.credential_uid identity.user.name
identity.user.type identity.user.uid identity.user.uuid http_request.user_agent src_endpoint.ip cloud.region
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `asl_aws_password_policy_changes_filter`'
how_to_implement: You must install Splunk AWS Add on and Splunk App for AWS. This
search works with Amazon Security Lake logs.
known_false_positives: While this search has no known false positives, it is possible
that an AWS admin has legitimately triggered an AWS audit tool activity which may
trigger this event.
references:
- https://www.trendmicro.com/cloudoneconformity/knowledge-base/aws/IAM/password-policy.html
tags:
analytic_story:
- AWS IAM Privilege Escalation
- Compromised User Account
asset_type: AWS Account
confidence: 80
impact: 90
message: User $identity.user.name$ is attempting to $api.operation$ the password policy for accounts
mitre_attack_id:
- T1201
observable:
- name: src_endpoint.ip
type: IP Address
role:
- Attacker
- name: identity.user.name
type: User
role:
- Attacker
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- api.service.name
- api.operation
- identity.user.account_uid
- identity.user.credential_uid
- identity.user.name
- identity.user.type
- identity.user.uid
- identity.user.uuid
- http_request.user_agent
- src_endpoint.ip
risk_score: 72
security_domain: threat
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1201/aws_password_policy/amazon_security_lake.json
sourcetype: aws:asl
source: aws_asl
update_timestamp: true
+4
View File
@@ -0,0 +1,4 @@
definition: sourcetype=aws:asl
description: customer specific splunk configurations(eg- index, source, sourcetype).
Replace the macro definition with configurations for your Splunk Environmnent.
name: amazon_security_lake