mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
Merge branch 'develop' into sunnyside
This commit is contained in:
@@ -114,3 +114,9 @@ example_log:
|
||||
"Type": 4}], "TargetContextId": "0e8108b1-18e9-41a4-961b-dfcddf92ef08", "UserId":
|
||||
"rodsoto@rodsoto.onmicrosoft.com", "UserKey": "10037FFEA938FB92@rodsoto.onmicrosoft.com",
|
||||
"UserType": 0, "Version": 1, "Workload": "AzureActiveDirectory"}'
|
||||
output_fields:
|
||||
- dest
|
||||
- user
|
||||
- src
|
||||
- vendor_account
|
||||
- vendor_product
|
||||
|
||||
@@ -120,3 +120,9 @@ example_log:
|
||||
"Type": 2}, {"ID": "Office 365 Exchange Online", "Type": 1}, {"ID": "00000002-0000-0ff1-ce00-000000000000",
|
||||
"Type": 2}, {"ID": "https://outlook.office.com;Microsoft.Exchange;00000002-0000-0ff1-ce00-000000000000;00000002-0000-0ff1-ce00-000000000000/*.outlook.com;00000002-0000-0ff1-ce00-000000000000/outlook.com;00000002-0000-0ff1-ce00-000000000000/mail.office365.com;00000002-0000-0ff1-ce00-000000000000/outlook.office365.com;https://webmail.apps.mil/;https://ps.protection.outlook.com/;https://outlook-dod.office365.us/;https://outlook.com/;https://outlook.office365.com/;https://outlook.office.com/;https://outlook.office365.com:443/;https://outlook-sdf.office365.com/;https://outlook-sdf.office.com/;https://outlook.office365.us/;https://autodiscover-s.office365.us/;https://ps.compliance.protection.outlook.com;https://manage.protection.apps.mil;https://outlook-tdf.office.com/;https://outlook-tdf-2.office.com/;https://ps.outlook.com",
|
||||
"Type": 4}], "TargetContextId": "75243ab2-44f8-435c-a7a6-b479385df6d4"}'
|
||||
output_fields:
|
||||
- dest
|
||||
- user
|
||||
- src
|
||||
- vendor_account
|
||||
- vendor_product
|
||||
@@ -90,3 +90,9 @@ example_log:
|
||||
{"Name": "InheritanceType", "Value": "All"}], "RecordType": 1, "ResultStatus": "True",
|
||||
"SessionId": "2be46662-a743-4a05-8744-c2f75f886512", "UserId": "pbareiss@rodsoto.onmicrosoft.com",
|
||||
"UserKey": "10032001020A3408", "UserType": 2, "Version": 1, "Workload": "Exchange"}'
|
||||
output_fields:
|
||||
- dest
|
||||
- user
|
||||
- src
|
||||
- vendor_account
|
||||
- vendor_product
|
||||
@@ -112,3 +112,9 @@ example_log:
|
||||
"Type": 2}, {"ID": "57e4bd36-9722-4a4a-9729-7203d8e00b72", "Type": 2}, {"ID": "User",
|
||||
"Type": 2}, {"ID": "lowpriv@splunkresearch.onmicrosoft.com", "Type": 5}, {"ID":
|
||||
"10032002CC029AE9", "Type": 3}], "TargetContextId": "d8211c86-3244-409b-8c4f-ae27ed34b4a5"}'
|
||||
output_fields:
|
||||
- dest
|
||||
- user
|
||||
- src
|
||||
- vendor_account
|
||||
- vendor_product
|
||||
@@ -114,3 +114,9 @@ example_log:
|
||||
"Type": 2}, {"ID": "57e4bd36-9722-4a4a-9729-7203d8e00b72", "Type": 2}, {"ID": "User",
|
||||
"Type": 2}, {"ID": "user2@contoso.onmicrosoft.com", "Type": 5}, {"ID": "10032002CC029AE9",
|
||||
"Type": 3}], "TargetContextId": "48203edf-5d2c-45f2-8123-a368cc8b0e51"}'
|
||||
output_fields:
|
||||
- dest
|
||||
- user
|
||||
- src
|
||||
- vendor_account
|
||||
- vendor_product
|
||||
@@ -122,3 +122,9 @@ example_log:
|
||||
"Type": 2}, {"ID": "Malicious11", "Type": 1}, {"ID": "e06366ca-8489-4748-b6a2-d7e4332f45c1",
|
||||
"Type": 2}, {"ID": "e06366ca-8489-4748-b6a2-d7e4332f45c1", "Type": 4}], "TargetContextId":
|
||||
"75243ab2-44f8-435c-a7a6-b479385df6d4"}'
|
||||
output_fields:
|
||||
- dest
|
||||
- user
|
||||
- src
|
||||
- vendor_account
|
||||
- vendor_product
|
||||
@@ -106,3 +106,9 @@ example_log:
|
||||
"Type": 2}, {"ID": "57e4bd36-9722-4a4a-9729-7203d8e00b72", "Type": 2}, {"ID": "User",
|
||||
"Type": 2}, {"ID": "victimUser@splunkresearch.onmicrosoft.com", "Type": 5}, {"ID":
|
||||
"10032002CC029AE9", "Type": 3}], "TargetContextId": "bbad9541-eb53-4533-bcef-2b76182c3b75"}'
|
||||
output_fields:
|
||||
- dest
|
||||
- user
|
||||
- src
|
||||
- vendor_account
|
||||
- vendor_product
|
||||
@@ -114,3 +114,9 @@ example_log:
|
||||
"Type": 2}, {"ID": "TestApp2", "Type": 1}, {"ID": "95106c0e-3519-450e-8e38-7f326d873454",
|
||||
"Type": 2}, {"ID": "95106c0e-3519-450e-8e38-7f326d873454", "Type": 4}], "TargetContextId":
|
||||
"9c00a473-1b2c-4bc2-9215-84df3f57aee5"}'
|
||||
output_fields:
|
||||
- dest
|
||||
- user
|
||||
- src
|
||||
- vendor_account
|
||||
- vendor_product
|
||||
@@ -106,3 +106,9 @@ example_log:
|
||||
"Type": 5}, {"ID": "10037FFEA938FB92", "Type": 3}], "TargetContextId": "0e8108b1-18e9-41a4-961b-dfcddf92ef08",
|
||||
"UserId": "rodsoto@rodsoto.onmicrosoft.com", "UserKey": "10037FFEA938FB92@rodsoto.onmicrosoft.com",
|
||||
"UserType": 0, "Version": 1, "Workload": "AzureActiveDirectory"}'
|
||||
output_fields:
|
||||
- dest
|
||||
- user
|
||||
- src
|
||||
- vendor_account
|
||||
- vendor_product
|
||||
@@ -100,3 +100,9 @@ example_log:
|
||||
"SizeInBytes": 44572}, {"InternetMessageId": "<CH0PR18MB5530506D1B68B05A99A1109FF185A@CH0PR18MB5530.namprd18.prod.outlook.com>",
|
||||
"SizeInBytes": 245068}], "Id": "LgAAAAC0AxwgOj/BRq9Bs1bhMPw/AQDh+UNSDzeHSLWfq+fr83BDAAAAAAEMAAAB",
|
||||
"Path": "\\Inbox"}], "OperationCount": 4}'
|
||||
output_fields:
|
||||
- dest
|
||||
- user
|
||||
- src
|
||||
- vendor_account
|
||||
- vendor_product
|
||||
@@ -114,3 +114,9 @@ example_log:
|
||||
"ParentFolder": {"Id": "LgAAAABKe+NY5HVjRYWDqaJ5IKKFAQBQ11dzmT6LS6bQbkNDtISsAAAAAAEMAAAB",
|
||||
"MemberRights": "FreeBusySimple", "MemberSid": "S-1-1-0", "MemberUpn": "Everyone",
|
||||
"Name": "Inbox", "Path": "\\Inbox"}}}'
|
||||
output_fields:
|
||||
- dest
|
||||
- user
|
||||
- src
|
||||
- vendor_account
|
||||
- vendor_product
|
||||
@@ -121,3 +121,9 @@ example_log:
|
||||
Services LLC", "Type": 1}], "TargetContextId": "0e8108b1-18e9-41a4-961b-dfcddf92ef08",
|
||||
"UserId": "bpatel@rodsoto.onmicrosoft.com", "UserKey": "100320010208B5DC@rodsoto.onmicrosoft.com",
|
||||
"UserType": 0, "Version": 1, "Workload": "AzureActiveDirectory"}'
|
||||
output_fields:
|
||||
- dest
|
||||
- user
|
||||
- src
|
||||
- vendor_account
|
||||
- vendor_product
|
||||
@@ -98,3 +98,9 @@ example_log:
|
||||
"Identity", "Value": "bpatel@rodsoto.onmicrosoft.com"}], "RecordType": 1, "ResultStatus":
|
||||
"True", "SessionId": "86a7cd7c-3f42-4b68-b670-4024b5461a80", "UserId": "pbareiss@rodsoto.onmicrosoft.com",
|
||||
"UserKey": "10032001020A3408", "UserType": 2, "Version": 1, "Workload": "Exchange"}'
|
||||
output_fields:
|
||||
- dest
|
||||
- user
|
||||
- src
|
||||
- vendor_account
|
||||
- vendor_product
|
||||
@@ -122,3 +122,9 @@ example_log:
|
||||
{"ID": "a2d68f8b-ab9f-47ac-934f-b966c3ac134f", "Type": 2}, {"ID": "Application",
|
||||
"Type": 2}, {"ID": "TestApp2", "Type": 1}, {"ID": "95106c0e-3519-450e-8e38-7f326d873454",
|
||||
"Type": 2}], "TargetContextId": "58aee3b9-7433-46a0-b54e-2429487992a0"}'
|
||||
output_fields:
|
||||
- dest
|
||||
- user
|
||||
- src
|
||||
- vendor_account
|
||||
- vendor_product
|
||||
@@ -105,3 +105,9 @@ example_log:
|
||||
"Target": [{"ID": "AuthorizationPolicy_24484114-1daa-4700-aaf7-44ee5cbe5678", "Type":
|
||||
2}, {"ID": "24484114-1daa-4700-aaf7-44ee5cbe5678", "Type": 2}, {"ID": "Other", "Type":
|
||||
2}, {"ID": "Authorization Policy", "Type": 1}], "TargetContextId": "a417c578-c7ee-480d-a225-d48057e74df5"}'
|
||||
output_fields:
|
||||
- dest
|
||||
- user
|
||||
- src
|
||||
- vendor_account
|
||||
- vendor_product
|
||||
@@ -119,3 +119,9 @@ example_log:
|
||||
"57e4bd36-9722-4a4a-9729-7203d8e00b72", "Type": 2}, {"ID": "User", "Type": 2}, {"ID":
|
||||
"victim@splunkresearch1.onmicrosoft.com", "Type": 5}, {"ID": "10032002CC029AE9",
|
||||
"Type": 3}], "TargetContextId": "99825d50-9544-4061-8e46-68923805cbf2"}'
|
||||
output_fields:
|
||||
- dest
|
||||
- user
|
||||
- src
|
||||
- vendor_account
|
||||
- vendor_product
|
||||
@@ -109,3 +109,9 @@ example_log:
|
||||
"00000002-0000-0ff1-ce00-000000000000", "DeviceProperties": [{"Name": "OS", "Value":
|
||||
"Windows10"}, {"Name": "BrowserType", "Value": "Firefox"}, {"Name": "SessionId",
|
||||
"Value": "15e27956-79a0-45b2-9d02-60f48349f692"}], "ErrorNumber": "0"}'
|
||||
output_fields:
|
||||
- dest
|
||||
- user
|
||||
- src
|
||||
- vendor_account
|
||||
- vendor_product
|
||||
@@ -119,3 +119,9 @@ example_log:
|
||||
"OS", "Value": "Windows10"}, {"Name": "BrowserType", "Value": "Chrome"}, {"Name":
|
||||
"IsCompliantAndManaged", "Value": "False"}], "ErrorNumber": "50126", "LogonError":
|
||||
"InvalidUserNameOrPassword"}'
|
||||
output_fields:
|
||||
- dest
|
||||
- user
|
||||
- src
|
||||
- vendor_account
|
||||
- vendor_product
|
||||
+2
-2
@@ -1,4 +1,4 @@
|
||||
name: Splunk CIM
|
||||
name: Splunk Common Information Model (CIM)
|
||||
id: d3dd8270-7e1c-4bcd-8f3a-e5ec4a0e740a
|
||||
version: 1
|
||||
date: '2025-01-14'
|
||||
@@ -7,6 +7,6 @@ description: Data source object for Splunk CIM
|
||||
source: not_applicable
|
||||
sourcetype: not_applicable
|
||||
supported_TA:
|
||||
- name: Splunk_SA_CIM
|
||||
- name: Splunk Common Information Model (CIM)
|
||||
url: https://splunkbase.splunk.com/app/1621
|
||||
version: 6.0.3
|
||||
@@ -16,7 +16,7 @@ sourcetype: stream:http
|
||||
supported_TA:
|
||||
- name: Splunk Stream
|
||||
url: https://splunkbase.splunk.com/app/1809
|
||||
version: 8.1.3
|
||||
version: 8.1.5
|
||||
fields:
|
||||
- _time
|
||||
- bytes
|
||||
|
||||
@@ -16,7 +16,7 @@ sourcetype: stream:ip
|
||||
supported_TA:
|
||||
- name: Splunk Stream
|
||||
url: https://splunkbase.splunk.com/app/1809
|
||||
version: 8.1.3
|
||||
version: 8.1.5
|
||||
fields:
|
||||
- _time
|
||||
- action
|
||||
|
||||
@@ -16,4 +16,4 @@ sourcetype: stream:tcp
|
||||
supported_TA:
|
||||
- name: Splunk Stream
|
||||
url: https://splunkbase.splunk.com/app/1809
|
||||
version: 8.1.3
|
||||
version: 8.1.5
|
||||
|
||||
@@ -1,9 +1,9 @@
|
||||
name: Cisco AI Defense Security Alerts by Application Name
|
||||
id: 105e4a69-ec55-49fc-be1f-902467435ea8
|
||||
version: 1
|
||||
date: '2025-02-14'
|
||||
version: 2
|
||||
date: '2025-03-21'
|
||||
author: Bhavin Patel, Splunk
|
||||
status: experimental
|
||||
status: production
|
||||
type: Anomaly
|
||||
description: The search surfaces alerts from the Cisco AI Defense product for potential attacks against the AI models running in your environment. This analytic identifies security events within Cisco AI Defense by examining event messages, actions, and policy names. It focuses on connections and applications associated with specific guardrail entities and ruleset types. By aggregating and analyzing these elements, the search helps detect potential policy violations and security threats, enabling proactive defense measures and ensuring network integrity.
|
||||
data_source:
|
||||
@@ -36,15 +36,19 @@ search: |-
|
||||
severity="low", 25
|
||||
)
|
||||
| table model.model_name, user_id, event_action, application_id, application_name, severity, risk_score, policy_name, connection_name, guardrail_ruleset_type, guardrail_entity_name
|
||||
|`cisco_ai_defense_security_alerts_by_application_name_filter`'
|
||||
| `cisco_ai_defense_security_alerts_by_application_name_filter`
|
||||
how_to_implement: To enable this detection, you need to ingest alerts from the Cisco AI Defense product. This can be done by using this app from splunkbase - Cisco Security Cloud and ingest alerts into the cisco:ai:defense sourcetype.
|
||||
known_false_positives: False positives may vary based on Cisco AI Defense configuration; monitor and filter out the alerts that are not relevant to your environment.
|
||||
references:
|
||||
- https://www.robustintelligence.com/blog-posts/prompt-injection-attack-on-gpt-4
|
||||
- https://docs.aws.amazon.com/prescriptive-guidance/latest/llm-prompt-engineering-best-practices/common-attacks.html
|
||||
drilldown_searches:
|
||||
- name: View risk events for the last 7 days for - "$application_id$"
|
||||
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$application_id$" ) starthoursago=168 | stats count min(_time)
|
||||
- name: View the detection results for - "$application_name$"
|
||||
search: '%original_detection_search% | search application_name = "$application_name$"'
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
- name: View risk events for the last 7 days for - "$application_name$"
|
||||
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$application_name$") starthoursago=168 | stats count min(_time)
|
||||
as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message)
|
||||
as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all)
|
||||
as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics"
|
||||
@@ -67,9 +71,10 @@ tags:
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
security_domain: endpoint
|
||||
manual_test: We are dynamically creating the risk_score field based on the severity of the alert in the SPL and that supersedes the risk score set in the detection.
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/cisco_ai_defense_alerts/cisco_ai_defense.log
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/cisco_ai_defense_alerts/cisco_ai_defense_alerts.json
|
||||
source: cisco_ai_defense
|
||||
sourcetype: cisco:ai:defense
|
||||
@@ -1,6 +1,6 @@
|
||||
name: High Number of Login Failures from a single source
|
||||
id: 7f398cfb-918d-41f4-8db8-2e2474e02222
|
||||
version: 6
|
||||
version: 7
|
||||
date: '2025-02-10'
|
||||
author: Bhavin Patel, Mauricio Velazco, Splunk
|
||||
status: production
|
||||
@@ -16,10 +16,13 @@ description: The following analytic detects multiple failed login attempts in Of
|
||||
data_source:
|
||||
- O365 UserLoginFailed
|
||||
search: '`o365_management_activity` Workload=AzureActiveDirectory Operation=UserLoginFailed
|
||||
record_type=AzureActiveDirectoryStsLogon | bucket span=5m _time | stats dc(_raw)
|
||||
AS failed_attempts values(user) as user values(LogonError) as LogonError values(signature)
|
||||
as signature values(UserAgent) as UserAgent by _time, src_ip | where failed_attempts
|
||||
> 10 | `high_number_of_login_failures_from_a_single_source_filter`'
|
||||
record_type=AzureActiveDirectoryStsLogon
|
||||
| bucket span=5m _time
|
||||
| stats dc(_raw) AS failed_attempts values(user) as user values(LogonError) as LogonError values(signature)
|
||||
as signature values(UserAgent) as UserAgent values(dest) as dest values(vendor_account) as vendor_account values(vendor_product) as vendor_product
|
||||
by _time, src_ip
|
||||
| where failed_attempts > 10
|
||||
| `high_number_of_login_failures_from_a_single_source_filter`'
|
||||
how_to_implement: You must install the Splunk Microsoft Office 365 Add-on and ingest
|
||||
Office 365 management activity events. Adjust the threshold value to suit the specific
|
||||
environment, as environments with naturally higher login failures might generate
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: O365 Add App Role Assignment Grant User
|
||||
id: b2c81cc6-6040-11eb-ae93-0242ac130002
|
||||
version: 6
|
||||
version: 7
|
||||
date: '2025-02-10'
|
||||
author: Rod Soto, Splunk
|
||||
status: production
|
||||
@@ -14,11 +14,10 @@ description: The following analytic detects the addition of an application role
|
||||
access to critical resources and data within the Office 365 environment.
|
||||
data_source:
|
||||
- O365 Add app role assignment grant to user.
|
||||
search: '`o365_management_activity` Workload=AzureActiveDirectory Operation="Add app
|
||||
role assignment grant to user." | stats count min(_time) as firstTime max(_time)
|
||||
as lastTime values(Actor{}.ID) as Actor.ID values(Actor{}.Type) as Actor.Type values(ModifiedProperties{}.Name)
|
||||
as modified_properties_name by user dest ResultStatus Operation | `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)` | `o365_add_app_role_assignment_grant_user_filter`'
|
||||
search: '`o365_management_activity` Workload=AzureActiveDirectory Operation="Add app role assignment grant to user."
|
||||
| fillnull
|
||||
| stats count min(_time) as firstTime max(_time) as lastTime by signature dest user src vendor_account vendor_product
|
||||
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `o365_add_app_role_assignment_grant_user_filter`'
|
||||
how_to_implement: You must install splunk Microsoft Office 365 add-on. This search
|
||||
works with o365:management:activity
|
||||
known_false_positives: The creation of a new Federation is not necessarily malicious,
|
||||
@@ -42,8 +41,7 @@ drilldown_searches:
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
rba:
|
||||
message: User $user$ has created a new federation setting $modified_properties_name$
|
||||
on $dest$
|
||||
message: User $user$ added a new app role assignment
|
||||
risk_objects:
|
||||
- field: user
|
||||
type: user
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: O365 Added Service Principal
|
||||
id: 1668812a-6047-11eb-ae93-0242ac130002
|
||||
version: 7
|
||||
version: 8
|
||||
date: '2025-02-10'
|
||||
author: Rod Soto, Splunk
|
||||
status: production
|
||||
@@ -15,11 +15,12 @@ description: The following analytic detects the addition of new service principa
|
||||
leading to data breaches or further compromise.
|
||||
data_source:
|
||||
- O365
|
||||
search: '`o365_management_activity` Workload=AzureActiveDirectory Operation="*Add
|
||||
service principal*" OR (Operation = "*principal*" AND action = "created") | stats
|
||||
count values(ModifiedProperties{}.NewValue) as new_value by src_user src_user_type
|
||||
action Operation authentication_service Workload | `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)` | `o365_added_service_principal_filter`'
|
||||
search: '`o365_management_activity` Workload=AzureActiveDirectory Operation="*Add service principal*" OR (Operation = "*principal*" AND action = "created")
|
||||
| fillnull
|
||||
| stats count min(_time) as firstTime max(_time) as lastTime by signature dest user src vendor_account vendor_product
|
||||
| `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)`
|
||||
| `o365_added_service_principal_filter`'
|
||||
how_to_implement: You must install splunk Microsoft Office 365 add-on. This search
|
||||
works with o365:management:activity
|
||||
known_false_positives: The creation of a new Federation is not necessarily malicious,
|
||||
@@ -31,12 +32,12 @@ references:
|
||||
- https://www.splunk.com/en_us/blog/security/a-golden-saml-journey-solarwinds-continued.html
|
||||
- https://blog.sygnia.co/detection-and-hunting-of-golden-saml-attack?hsLang=en
|
||||
drilldown_searches:
|
||||
- name: View the detection results for - "$src_user$"
|
||||
search: '%original_detection_search% | search src_user = "$src_user$"'
|
||||
- name: View the detection results for - "$user$"
|
||||
search: '%original_detection_search% | search user = "$user$"'
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
- name: View risk events for the last 7 days for - "$src_user$"
|
||||
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$src_user$")
|
||||
- name: View risk events for the last 7 days for - "$user$"
|
||||
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$")
|
||||
starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime
|
||||
values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories)
|
||||
as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic)
|
||||
@@ -45,9 +46,9 @@ drilldown_searches:
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
rba:
|
||||
message: User $src_user$ has created new service principal $new_value$ in AzureActiveDirectory
|
||||
message: User $user$ has created new service principal in AzureActiveDirectory
|
||||
risk_objects:
|
||||
- field: src_user
|
||||
- field: user
|
||||
type: user
|
||||
score: 42
|
||||
threat_objects: []
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: O365 Admin Consent Bypassed by Service Principal
|
||||
id: 8a1b22eb-50ce-4e26-a691-97ff52349569
|
||||
version: 4
|
||||
version: 5
|
||||
date: '2024-11-14'
|
||||
author: Mauricio Velazco, Splunk
|
||||
data_source:
|
||||
@@ -15,15 +15,20 @@ description: The following analytic identifies instances where a service princip
|
||||
leading to unauthorized access or privilege escalation. If confirmed malicious,
|
||||
this could allow an attacker to misuse automated processes to assign sensitive permissions,
|
||||
compromising the security of the environment.
|
||||
search: "`o365_management_activity` Workload=AzureActiveDirectory Operation=\"Add
|
||||
app role assignment to service principal.\" | eval len=mvcount('Actor{}.ID') | eval
|
||||
userType = mvindex('Actor{}.ID',len-1) | eval roleId = mvindex('ModifiedProperties{}.NewValue',
|
||||
0) | eval roleValue = mvindex('ModifiedProperties{}.NewValue', 1) | eval roleDescription
|
||||
= mvindex('ModifiedProperties{}.NewValue', 2) | eval dest_user = mvindex('Target{}.ID',
|
||||
0) | search userType = \"ServicePrincipal\" | eval src_user = user | stats count
|
||||
earliest(_time) as firstTime latest(_time) as lastTime by src_user dest_user roleId
|
||||
roleValue roleDescription | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`\
|
||||
\ | `o365_admin_consent_bypassed_by_service_principal_filter`"
|
||||
search: "`o365_management_activity` Workload=AzureActiveDirectory Operation=\"Add app role assignment to service principal.\"
|
||||
| eval len=mvcount('Actor{}.ID')
|
||||
| eval userType = mvindex('Actor{}.ID',len-1)
|
||||
| eval roleId = mvindex('ModifiedProperties{}.NewValue', 0)
|
||||
| eval roleValue = mvindex('ModifiedProperties{}.NewValue', 1)
|
||||
| eval roleDescription = mvindex('ModifiedProperties{}.NewValue', 2)
|
||||
| eval dest_user = mvindex('Target{}.ID', 0)
|
||||
| search userType = \"ServicePrincipal\"
|
||||
| eval src_user = user
|
||||
| fillnull
|
||||
| stats count min(_time) as firstTime max(_time) as lastTime by signature dest user src vendor_account vendor_product dest_user roleId roleValue roleDescription
|
||||
| `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)`
|
||||
| `o365_admin_consent_bypassed_by_service_principal_filter`"
|
||||
how_to_implement: You must install the Splunk Microsoft Office 365 Add-on and ingest
|
||||
Office 365 management activity events.
|
||||
known_false_positives: Service Principals are sometimes configured to legitimately
|
||||
@@ -50,8 +55,7 @@ drilldown_searches:
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
rba:
|
||||
message: Service principal $src_user$ bypassed the admin consent process and granted
|
||||
permissions to $dest_user$
|
||||
message: Service principal $user$ bypassed the admin consent process and granted permissions to $dest_user$
|
||||
risk_objects:
|
||||
- field: dest_user
|
||||
type: user
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: O365 Advanced Audit Disabled
|
||||
id: 49862dd4-9cb2-4c48-a542-8c8a588d9361
|
||||
version: 5
|
||||
version: 6
|
||||
date: '2025-02-10'
|
||||
author: Mauricio Velazco, Michael Haag, Splunk
|
||||
status: production
|
||||
@@ -15,14 +15,19 @@ description: The following analytic detects instances where the O365 advanced au
|
||||
it can blind security teams to potential malicious actions. If confirmed malicious,
|
||||
attackers could operate within the user's mailbox or account with reduced risk of
|
||||
detection, leading to unauthorized data access, data exfiltration, or account compromise.
|
||||
search: "`o365_management_activity` Operation=\"Change user license.\" | eval property_name
|
||||
= mvindex ('ExtendedProperties{}.Name', 1) | search property_name = \"extendedAuditEventCategory\"\
|
||||
\ | eval additionalDetails = mvindex('ExtendedProperties{}.Value',0) | eval split_value=split(additionalDetails,
|
||||
\"NewValue\") | eval possible_plan=mvindex(split_value, 1) | rex field=\"possible_plan\"\
|
||||
\ \"DisabledPlans=\\[(?P<DisabledPlans>[^\\]]+)\\]\" | search DisabledPlans IN (\"\
|
||||
*M365_ADVANCED_AUDITING*\") | stats min(_time) as firstTime max(_time) as lastTime
|
||||
by Operation user object DisabledPlans | `security_content_ctime(firstTime)` |
|
||||
`security_content_ctime(lastTime)` | `o365_advanced_audit_disabled_filter`"
|
||||
search: "`o365_management_activity` Operation=\"Change user license.\"
|
||||
| eval property_name = mvindex ('ExtendedProperties{}.Name', 1)
|
||||
| search property_name = \"extendedAuditEventCategory\"
|
||||
| eval additionalDetails = mvindex('ExtendedProperties{}.Value',0)
|
||||
| eval split_value=split(additionalDetails,\"NewValue\")
|
||||
| eval possible_plan=mvindex(split_value, 1)
|
||||
| rex field=\"possible_plan\" \"DisabledPlans=\\[(?P<DisabledPlans>[^\\]]+)\\]\"
|
||||
| search DisabledPlans IN (\"*M365_ADVANCED_AUDITING*\")
|
||||
| fillnull
|
||||
| stats count min(_time) as firstTime max(_time) as lastTime by signature dest user src vendor_account vendor_product DisabledPlans object
|
||||
| `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)`
|
||||
| `o365_advanced_audit_disabled_filter`"
|
||||
how_to_implement: You must install the Splunk Microsoft Office 365 Add-on and ingest
|
||||
Office 365 management activity events.
|
||||
known_false_positives: Administrators might temporarily disable the advanced audit
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: O365 Application Available To Other Tenants
|
||||
id: 942548a3-0273-47a4-8dbd-e5202437395c
|
||||
version: 5
|
||||
version: 6
|
||||
date: '2025-02-10'
|
||||
author: Steven Dick
|
||||
status: production
|
||||
@@ -12,16 +12,18 @@ description: The following analytic identifies the configuration of Azure Active
|
||||
the O365 Universal Audit Log data source.
|
||||
data_source:
|
||||
- Office 365 Universal Audit Log
|
||||
search: "`o365_management_activity` Workload=AzureActiveDirectory Operation IN (\"\
|
||||
Add application.\",\"Update application.\") ModifiedProperties{}.Name=AvailableToOtherTenants
|
||||
search: "`o365_management_activity` Workload=AzureActiveDirectory Operation IN (\"Add application.\",\"Update application.\") ModifiedProperties{}.Name=AvailableToOtherTenants
|
||||
| eval result = case(match(mvindex('ModifiedProperties{}.NewValue',mvfind('ModifiedProperties{}.Name',\"\
|
||||
AvailableToOtherTenants\")),\"false\"),\"removed\",true(),\"added\"), object_name=mvindex('Target{}.ID',
|
||||
3), signature=Operation, object_attrs = \"AvailableToOtherTenants\", user = case(match(mvindex('Actor{}.ID',-1),\"\
|
||||
User\"),mvindex('Actor{}.ID',0),match(mvindex('Actor{}.ID',-1),\"ServicePrincipal\"\
|
||||
),mvindex('Actor{}.ID',3),true(),mvindex('Actor{}.ID',0)) | search result = \"added\"\
|
||||
\ | stats values(ActorIpAddress) as src, count, min(_time) as firstTime, max(_time)
|
||||
as lastTime by signature, user, object, object_name, object_attrs, result | `security_content_ctime(firstTime)`\
|
||||
\ | `security_content_ctime(lastTime)` | `o365_application_available_to_other_tenants_filter`"
|
||||
AvailableToOtherTenants\")),\"false\"),\"removed\",true(),\"added\"), object_name=mvindex('Target{}.ID',
|
||||
3), signature=Operation, object_attrs = \"AvailableToOtherTenants\", user = case(match(mvindex('Actor{}.ID',-1),\"\
|
||||
User\"),mvindex('Actor{}.ID',0),match(mvindex('Actor{}.ID',-1),\"ServicePrincipal\"\
|
||||
),mvindex('Actor{}.ID',3),true(),mvindex('Actor{}.ID',0))
|
||||
| search result = \"added\"
|
||||
| fillnull
|
||||
| stats count min(_time) as firstTime max(_time) as lastTime by signature dest user src vendor_account vendor_product object_attrs object_name
|
||||
| `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)`
|
||||
| `o365_application_available_to_other_tenants_filter`"
|
||||
how_to_implement: You must install the Splunk Microsoft Office 365 Add-on and ingest
|
||||
Office 365 management activity events.
|
||||
known_false_positives: Business approved changes by known administrators.
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: O365 Application Registration Owner Added
|
||||
id: c068d53f-6aaa-4558-8011-3734df878266
|
||||
version: 4
|
||||
version: 5
|
||||
date: '2024-11-14'
|
||||
author: Mauricio Velazco, Splunk
|
||||
status: production
|
||||
@@ -16,11 +16,14 @@ description: The following analytic identifies instances where a new owner is as
|
||||
an attacker could modify the application's settings, permissions, and behavior,
|
||||
leading to unauthorized data access, privilege escalation, or the introduction of
|
||||
malicious behavior within the application's operations.
|
||||
search: "`o365_management_activity` Workload=AzureActiveDirectory Operation=\"Add
|
||||
owner to application.\" | eval app_id=mvindex('ModifiedProperties{}.NewValue', 0)
|
||||
| eval app_displayName=mvindex('ModifiedProperties{}.NewValue', 1) | stats max(_time)
|
||||
as lastTime values(ModifiedProperties{}.NewValue) by Operation, user, app_displayName,
|
||||
object | `security_content_ctime(lastTime)` | `o365_application_registration_owner_added_filter`"
|
||||
search: "`o365_management_activity` Workload=AzureActiveDirectory Operation=\"Add owner to application.\"
|
||||
| eval app_id=mvindex('ModifiedProperties{}.NewValue', 0)
|
||||
| eval app_displayName=mvindex('ModifiedProperties{}.NewValue', 1)
|
||||
| fillnull
|
||||
| stats count min(_time) as firstTime max(_time) as lastTime by signature dest user src vendor_account vendor_product app_id app_displayName object
|
||||
| `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)`
|
||||
| `o365_application_registration_owner_added_filter`"
|
||||
how_to_implement: You must install the Splunk Microsoft Office 365 Add-on and ingest
|
||||
Office 365 management activity events.
|
||||
known_false_positives: Application owners may be added for legitimate reasons, filter
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: O365 ApplicationImpersonation Role Assigned
|
||||
id: 49cdce75-f814-4d56-a7a4-c64ec3a481f2
|
||||
version: 5
|
||||
version: 6
|
||||
date: '2025-02-10'
|
||||
author: Mauricio Velazco, Splunk
|
||||
status: production
|
||||
@@ -15,9 +15,12 @@ description: The following analytic detects the assignment of the ApplicationImp
|
||||
malicious, an attacker could gain unauthorized access to sensitive information,
|
||||
manipulate mailbox data, and perform actions as a legitimate user, posing a severe
|
||||
security risk to the organization.
|
||||
search: '`o365_management_activity` Workload=Exchange Operation="New-ManagementRoleAssignment" Role=ApplicationImpersonation
|
||||
| rename User as target_user | stats max(_time) as lastTime by Operation, user,
|
||||
object, ObjectId, Role, target_user | `security_content_ctime(lastTime)` | `o365_applicationimpersonation_role_assigned_filter`'
|
||||
search: '`o365_management_activity` Workload=Exchange Operation="New-ManagementRoleAssignment" Role=ApplicationImpersonation
|
||||
| rename User as target_user
|
||||
| fillnull
|
||||
| stats count min(_time) as firstTime max(_time) as lastTime by signature dest user src vendor_account vendor_product target_user
|
||||
| `security_content_ctime(lastTime)`
|
||||
| `o365_applicationimpersonation_role_assigned_filter`'
|
||||
how_to_implement: You must install the Splunk Microsoft Office 365 Add-on and ingest
|
||||
Office 365 management activity events.
|
||||
known_false_positives: While infrequent, the ApplicationImpersonation role may be
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: O365 Block User Consent For Risky Apps Disabled
|
||||
id: 12a23592-e3da-4344-8545-205d3290647c
|
||||
version: 4
|
||||
version: 5
|
||||
date: '2024-11-14'
|
||||
author: Mauricio Velazco, Splunk
|
||||
status: production
|
||||
@@ -15,13 +15,15 @@ description: The following analytic detects when the "risk-based step-up consent
|
||||
to grant consent to malicious applications. If confirmed malicious, attackers could
|
||||
gain unauthorized access to user data and sensitive information, leading to data
|
||||
breaches and further compromise within the organization.
|
||||
search: "`o365_management_activity` Workload=AzureActiveDirectory Operation=\"Update
|
||||
authorization policy.\" | eval index_number = if(mvfind('ModifiedProperties{}.Name',
|
||||
\"AllowUserConsentForRiskyApps\") >= 0, mvfind('ModifiedProperties{}.Name', \"AllowUserConsentForRiskyApps\"\
|
||||
), -1) | search index_number >= 0 | eval AllowUserConsentForRiskyApps = mvindex('ModifiedProperties{}.NewValue',index_number)
|
||||
| where AllowUserConsentForRiskyApps like \"%true%\" | stats count min(_time) as
|
||||
firstTime max(_time) as lastTime by user, Operation, AllowUserConsentForRiskyApps,
|
||||
user_agent | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
|
||||
search: "`o365_management_activity` Workload=AzureActiveDirectory Operation=\"Update authorization policy.\"
|
||||
| eval index_number = if(mvfind('ModifiedProperties{}.Name',\"AllowUserConsentForRiskyApps\") >= 0, mvfind('ModifiedProperties{}.Name',\"AllowUserConsentForRiskyApps\"), -1)
|
||||
| search index_number >= 0
|
||||
| eval AllowUserConsentForRiskyApps = mvindex('ModifiedProperties{}.NewValue',index_number)
|
||||
| where AllowUserConsentForRiskyApps like \"%true%\"
|
||||
| fillnull
|
||||
| stats count min(_time) as firstTime max(_time) as lastTime by signature dest user src vendor_account vendor_product AllowUserConsentForRiskyApps
|
||||
| `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)`
|
||||
| `o365_block_user_consent_for_risky_apps_disabled_filter`"
|
||||
how_to_implement: You must install the Splunk Microsoft Office 365 Add-on and ingest
|
||||
Office 365 management activity events.
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: O365 Bypass MFA via Trusted IP
|
||||
id: c783dd98-c703-4252-9e8a-f19d9f66949e
|
||||
version: 7
|
||||
version: 8
|
||||
date: '2025-02-10'
|
||||
author: Bhavin Patel, Mauricio Velazco, Splunk
|
||||
status: production
|
||||
@@ -16,15 +16,17 @@ description: The following analytic identifies instances where new IP addresses
|
||||
of the IP addition.
|
||||
data_source:
|
||||
- O365 Set Company Information.
|
||||
search: '`o365_management_activity` Operation="Set Company Information." ModifiedProperties{}.Name=StrongAuthenticationPolicy
|
||||
| rex max_match=100 field=ModifiedProperties{}.NewValue "(?<ip_addresses_new_added>\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3}\/\d{1,2})"
|
||||
| rex max_match=100 field=ModifiedProperties{}.OldValue "(?<ip_addresses_old>\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3}\/\d{1,2})"
|
||||
| eval ip_addresses_old=if(isnotnull(ip_addresses_old),ip_addresses_old,"0") | mvexpand
|
||||
ip_addresses_new_added | where isnull(mvfind(ip_addresses_old,ip_addresses_new_added))
|
||||
|stats count min(_time) as firstTime max(_time) as lastTime values(ip_addresses_old)
|
||||
as ip_addresses_old by user ip_addresses_new_added Operation Workload vendor_account
|
||||
status user_id action | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)`|
|
||||
`o365_bypass_mfa_via_trusted_ip_filter`'
|
||||
search: '`o365_management_activity` Operation="Set Company Information." ModifiedProperties{}.Name=StrongAuthenticationPolicy
|
||||
| rex max_match=100 field=ModifiedProperties{}.NewValue "(?<ip_addresses_new_added>\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3}\/\d{1,2})"
|
||||
| rex max_match=100 field=ModifiedProperties{}.OldValue "(?<ip_addresses_old>\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3}\/\d{1,2})"
|
||||
| eval ip_addresses_old=if(isnotnull(ip_addresses_old),ip_addresses_old,"0")
|
||||
| mvexpand ip_addresses_new_added
|
||||
| where isnull(mvfind(ip_addresses_old,ip_addresses_new_added))
|
||||
| fillnull
|
||||
| stats count min(_time) as firstTime max(_time) as lastTime values(ip_addresses_old) as ip_addresses_old by signature dest user src vendor_account vendor_product ip_addresses_new_added
|
||||
| `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)`
|
||||
| `o365_bypass_mfa_via_trusted_ip_filter`'
|
||||
how_to_implement: You must install Splunk Microsoft Office 365 add-on. This search
|
||||
works with o365:management:activity
|
||||
known_false_positives: Unless it is a special case, it is uncommon to continually
|
||||
@@ -34,12 +36,12 @@ references:
|
||||
- https://attack.mitre.org/techniques/T1562/007/
|
||||
- https://learn.microsoft.com/en-us/azure/active-directory/authentication/howto-mfa-mfasettings
|
||||
drilldown_searches:
|
||||
- name: View the detection results for - "$user_id$"
|
||||
search: '%original_detection_search% | search user_id = "$user_id$"'
|
||||
- name: View the detection results for - "$user$"
|
||||
search: '%original_detection_search% | search user = "$user$"'
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
- name: View risk events for the last 7 days for - "$user_id$"
|
||||
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user_id$")
|
||||
- name: View risk events for the last 7 days for - "$user$"
|
||||
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$")
|
||||
starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime
|
||||
values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories)
|
||||
as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic)
|
||||
@@ -48,15 +50,13 @@ drilldown_searches:
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
rba:
|
||||
message: User $user_id$ has added new IP addresses $ip_addresses_new_added$ to a
|
||||
message: User $user$ has added new IP addresses $ip_addresses_new_added$ to a
|
||||
list of trusted IPs to bypass MFA
|
||||
risk_objects:
|
||||
- field: user_id
|
||||
- field: user
|
||||
type: user
|
||||
score: 42
|
||||
threat_objects:
|
||||
- field: ip_addresses_new_added
|
||||
type: ip_address
|
||||
threat_objects: []
|
||||
tags:
|
||||
analytic_story:
|
||||
- Office 365 Persistence Mechanisms
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: O365 Compliance Content Search Exported
|
||||
id: 2ce9f31d-ab4f-4179-b2b7-c77a9652e1d8
|
||||
version: 6
|
||||
version: 7
|
||||
date: '2025-02-10'
|
||||
author: Mauricio Velazco, Splunk
|
||||
data_source: []
|
||||
@@ -14,10 +14,13 @@ description: The following analytic identifies when the results of a content sea
|
||||
If confirmed malicious, an attacker could gain access to and exfiltrate sensitive
|
||||
information, posing a severe risk to the organization's data security and compliance
|
||||
posture.
|
||||
search: '`o365_management_activity` Workload=SecurityComplianceCenter Operation="SearchExported"
|
||||
| rename user_id as user | stats count earliest(_time) as firstTime latest(_time)
|
||||
as lastTime by Operation, ObjectId, ExchangeLocations, user, Query |`security_content_ctime(firstTime)`
|
||||
|`security_content_ctime(lastTime)` | `o365_compliance_content_search_exported_filter`'
|
||||
search: '`o365_management_activity` Workload=SecurityComplianceCenter Operation="SearchExported"
|
||||
| rename user_id as user
|
||||
| fillnull
|
||||
| stats count min(_time) as firstTime max(_time) as lastTime by signature dest user src vendor_account vendor_product ExchangeLocations Query
|
||||
| `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)`
|
||||
| `o365_compliance_content_search_exported_filter`'
|
||||
how_to_implement: You must install the Splunk Microsoft Office 365 Add-on and ingest
|
||||
Office 365 management activity events.
|
||||
known_false_positives: Compliance content searche exports may be executed for legitimate
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: O365 Compliance Content Search Started
|
||||
id: f4cabbc7-c19a-4e41-8be5-98daeaccbb50
|
||||
version: 6
|
||||
version: 7
|
||||
date: '2025-02-10'
|
||||
author: Mauricio Velazco, Splunk
|
||||
data_source: []
|
||||
@@ -14,10 +14,13 @@ description: The following analytic detects when a content search is initiated w
|
||||
unauthorized data access, potential data exfiltration, and compliance violations.
|
||||
Monitoring this behavior helps ensure the integrity and security of organizational
|
||||
data.
|
||||
search: '`o365_management_activity` Workload=SecurityComplianceCenter Operation=SearchCreated
|
||||
| rename user_id as user | stats count earliest(_time) as firstTime latest(_time)
|
||||
as lastTime by Operation, ObjectId, ExchangeLocations, user, Query |`security_content_ctime(firstTime)`
|
||||
|`security_content_ctime(lastTime)` | `o365_compliance_content_search_started_filter`'
|
||||
search: '`o365_management_activity` Workload=SecurityComplianceCenter Operation=SearchCreated
|
||||
| rename user_id as user
|
||||
| fillnull
|
||||
| stats count min(_time) as firstTime max(_time) as lastTime by signature dest user src vendor_account vendor_product ExchangeLocations Query
|
||||
| `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)`
|
||||
| `o365_compliance_content_search_started_filter`'
|
||||
how_to_implement: You must install the Splunk Microsoft Office 365 Add-on and ingest
|
||||
Office 365 management activity events.
|
||||
known_false_positives: Compliance content searches may be executed for legitimate
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: O365 Concurrent Sessions From Different Ips
|
||||
id: 58e034de-1f87-4812-9dc3-a4f68c7db930
|
||||
version: 5
|
||||
version: 6
|
||||
date: '2024-11-14'
|
||||
author: Mauricio Velazco, Splunk
|
||||
status: production
|
||||
@@ -15,10 +15,13 @@ description: The following analytic identifies user sessions in Office 365 acces
|
||||
posing severe risks to organizational security.
|
||||
data_source:
|
||||
- O365 UserLoggedIn
|
||||
search: '`o365_management_activity` Workload=AzureActiveDirectory Operation=UserLoggedIn
|
||||
| stats min(_time) as firstTime max(_time) as lastTime values(src_ip) as ips values(user_agent)
|
||||
as user_agents by Operation, user, SessionId | where mvcount(ips) > 1 | `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)` | `o365_concurrent_sessions_from_different_ips_filter`'
|
||||
search: '`o365_management_activity` Workload=AzureActiveDirectory Operation=UserLoggedIn
|
||||
| fillnull
|
||||
| stats count min(_time) as firstTime max(_time) as lastTime values(src) as src by signature dest user vendor_account vendor_product
|
||||
| where mvcount(src) > 1
|
||||
| `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)`
|
||||
| `o365_concurrent_sessions_from_different_ips_filter`'
|
||||
how_to_implement: You must install splunk Microsoft Office 365 add-on. This search
|
||||
works with o365:management:activity
|
||||
known_false_positives: Unknown
|
||||
@@ -47,9 +50,7 @@ rba:
|
||||
- field: user
|
||||
type: user
|
||||
score: 42
|
||||
threat_objects:
|
||||
- field: ips
|
||||
type: ip_address
|
||||
threat_objects: []
|
||||
tags:
|
||||
analytic_story:
|
||||
- Office 365 Account Takeover
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: O365 Cross-Tenant Access Change
|
||||
id: 7c0fa490-12b0-4d0b-b9f5-e101d1e0e06f
|
||||
version: 4
|
||||
version: 5
|
||||
date: '2024-11-14'
|
||||
author: Steven Dick
|
||||
status: production
|
||||
@@ -13,13 +13,14 @@ description: The following analytic identifies when cross-tenant access/synchron
|
||||
data_source:
|
||||
- Office 365 Universal Audit Log
|
||||
search: "`o365_management_activity` Workload=AzureActiveDirectory Operation IN (\"\
|
||||
Add a partner to cross-tenant access setting.\",\"Delete partner specific cross-tenant
|
||||
access setting.\") | eval user = case(match(mvindex('Actor{}.ID',-1),\"User\"),mvindex('Actor{}.ID',0),match(mvindex('Actor{}.ID',-1),\"\
|
||||
ServicePrincipal\"),mvindex('Actor{}.ID',3),true(),mvindex('Actor{}.ID',0)) | stats
|
||||
values(Workload) as category, values(ClientIP) as src, values(ModifiedProperties{}.Name)
|
||||
as object_name, values(ModifiedProperties{}.NewValue) as object_attrs, count, min(_time)
|
||||
as firstTime, max(_time) as lastTime by Id,user,Operation | rename Operation as
|
||||
signature, Id as signature_id | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
|
||||
Add a partner to cross-tenant access setting.\",\"Delete partner specific cross-tenant
|
||||
access setting.\")
|
||||
| eval user = case(match(mvindex('Actor{}.ID',-1),\"User\"),mvindex('Actor{}.ID',0),match(mvindex('Actor{}.ID',-1),\"\
|
||||
ServicePrincipal\"),mvindex('Actor{}.ID',3),true(),mvindex('Actor{}.ID',0))
|
||||
| fillnull
|
||||
| stats count min(_time) as firstTime max(_time) as lastTime by dest user src vendor_account vendor_product signature signature_id
|
||||
| `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)`
|
||||
| `o365_cross_tenant_access_change_filter`"
|
||||
how_to_implement: You must install the Splunk Microsoft Office 365 Add-on and ingest
|
||||
Office 365 management activity events.
|
||||
@@ -44,8 +45,7 @@ drilldown_searches:
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
rba:
|
||||
message: The user [$user$] changed the Azure cross-tenant access settings for $object_name$
|
||||
$object_attrs$ [$signature$]
|
||||
message: The user [$user$] changed the Azure cross-tenant access settings
|
||||
risk_objects:
|
||||
- field: user
|
||||
type: user
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: O365 Disable MFA
|
||||
id: c783dd98-c703-4252-9e8a-f19d9f5c949e
|
||||
version: 5
|
||||
version: 6
|
||||
date: '2024-11-14'
|
||||
author: Rod Soto, Splunk
|
||||
status: production
|
||||
@@ -16,11 +16,13 @@ description: The following analytic identifies instances where Multi-Factor Auth
|
||||
related to the affected account.
|
||||
data_source:
|
||||
- O365 Disable Strong Authentication.
|
||||
search: '`o365_management_activity` Operation="Disable Strong Authentication." | stats
|
||||
count earliest(_time) as firstTime latest(_time) as lastTime by UserType Operation
|
||||
UserId ResultStatus object | rename UserType AS user_type, Operation AS action,
|
||||
UserId AS src_user, object AS user, ResultStatus AS result | `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)` | `o365_disable_mfa_filter`'
|
||||
search: '`o365_management_activity` Operation="Disable Strong Authentication."
|
||||
| rename UserId as user object as src_user
|
||||
| fillnull
|
||||
| stats count min(_time) as firstTime max(_time) as lastTime by signature dest user src vendor_account vendor_product src_user
|
||||
| `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)`
|
||||
| `o365_disable_mfa_filter`'
|
||||
how_to_implement: You must install the Splunk Microsoft Office 365 add-on. This search
|
||||
works with o365:management:activity
|
||||
known_false_positives: Unless it is a special case, it is uncommon to disable MFA
|
||||
@@ -42,7 +44,7 @@ drilldown_searches:
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
rba:
|
||||
message: User $src_user$ has executed an operation $action$ for user $user$
|
||||
message: User $src_user$ has executed an operation $signature$ for user $user$
|
||||
risk_objects:
|
||||
- field: user
|
||||
type: user
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: O365 DLP Rule Triggered
|
||||
id: 63a8a537-36fd-4aac-a3ea-1a96afd2c871
|
||||
version: 5
|
||||
date: '2024-11-14'
|
||||
version: 6
|
||||
date: '2025-03-25'
|
||||
author: Steven Dick
|
||||
status: production
|
||||
type: Anomaly
|
||||
@@ -9,22 +9,20 @@ description: The following analytic detects when Microsoft Office 365 Data Loss
|
||||
(DLP) rules have been triggered. DLP rules can be configured for any number of security,
|
||||
regulatory, or business compliance reasons, as such this analytic will only be as
|
||||
accurate as the upstream DLP configuration. Detections from this analytic should
|
||||
be evaluated thoroughly to determine what, if any, security relevance the underlying
|
||||
be evaluated thoroughly to de termine what, if any, security relevance the underlying
|
||||
DLP events contain.
|
||||
data_source:
|
||||
- Office 365 Universal Audit Log
|
||||
search: "`o365_management_activity` Operation=DLPRuleMatch | eval recipient = 'ExchangeMetaData.To{}',
|
||||
signature_id = 'ExchangeMetaData.UniqueID', signature = 'PolicyDetails{}.Rules{}.RuleName'
|
||||
, src_user = UserId, reason ='PolicyDetails{}.Rules{}.ConditionsMatched.SensitiveInformation{}.SensitiveInformationTypeName',
|
||||
result='PolicyDetails{}.Rules{}.Actions{}', file_name=case(NOT match('PolicyDetails{}.Rules{}.ConditionsMatched.SensitiveInformation{}.Location',\"\
|
||||
Message Body\"),'PolicyDetails{}.Rules{}.ConditionsMatched.SensitiveInformation{}.Location')
|
||||
| stats min(_time) as firstTime max(_time) as lastTime values(signature) as signature
|
||||
values(file_name) as file_name values(ExchangeMetaData.Subject) AS subject values(Workload)
|
||||
as app values(result) as result by src_user,recipient,signature_id,reason | `o365_dlp_rule_triggered_filter`
|
||||
| stats count min(firstTime) as firstTime max(lastTime) as lastTime values(*) AS
|
||||
* by src_user,signature_id | eval action = CASE(match(result,\"Halt\"),\"blocked\"\
|
||||
,isnotnull(result),\"alert\",true(),\"allow\") |`security_content_ctime(firstTime)`\
|
||||
\ |`security_content_ctime(lastTime)`"
|
||||
search: '`o365_management_activity` Operation=DLPRuleMatch | eval recipient = ''ExchangeMetaData.To{}'',
|
||||
signature_id = ''ExchangeMetaData.UniqueID'', signature = ''PolicyDetails{}.Rules{}.RuleName''
|
||||
, src_user = UserId, reason =''PolicyDetails{}.Rules{}.ConditionsMatched.SensitiveInformation{}.SensitiveInformationTypeName'',
|
||||
result=''PolicyDetails{}.Rules{}.Actions{}'', file_name=case(NOT match(''PolicyDetails{}.Rules{}.ConditionsMatched.SensitiveInformation{}.Location'',"Message
|
||||
Body"),''PolicyDetails{}.Rules{}.ConditionsMatched.SensitiveInformation{}.Location'')
|
||||
| fillnull | stats count min(_time) as firstTime max(_time) as lastTime values(signature)
|
||||
as signature values(file_name) as file_name values(ExchangeMetaData.Subject) AS
|
||||
subject values(Workload) as app values(result) as result by action dest user src
|
||||
vendor_account vendor_product src_user recipient signature_id reason | `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)` | `o365_dlp_rule_triggered_filter` '
|
||||
how_to_implement: You must install the Splunk Microsoft Office 365 Add-on and ingest
|
||||
Office 365 management activity events. You must deploy DLP rules through O365 security
|
||||
and compliance functions.
|
||||
@@ -33,12 +31,12 @@ known_false_positives: WIll depending on accuracy of DLP rules, these can be noi
|
||||
references:
|
||||
- https://learn.microsoft.com/en-us/purview/dlp-learn-about-dlp
|
||||
drilldown_searches:
|
||||
- name: View the detection results for - "$src_user$"
|
||||
search: '%original_detection_search% | search src_user = "$src_user$"'
|
||||
- name: View the detection results for - "$user$"
|
||||
search: '%original_detection_search% | search user = "$user$"'
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
- name: View risk events for the last 7 days for - "$src_user$"
|
||||
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$src_user$")
|
||||
- name: View risk events for the last 7 days for - "$user$"
|
||||
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$")
|
||||
starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime
|
||||
values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories)
|
||||
as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic)
|
||||
@@ -47,14 +45,12 @@ drilldown_searches:
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
rba:
|
||||
message: User $src_user$ triggered a Microsoft Office DLP rule.
|
||||
message: User $user$ triggered a Microsoft Office DLP rule.
|
||||
risk_objects:
|
||||
- field: src_user
|
||||
- field: user
|
||||
type: user
|
||||
score: 20
|
||||
threat_objects:
|
||||
- field: recipient
|
||||
type: email_address
|
||||
threat_objects: []
|
||||
tags:
|
||||
analytic_story:
|
||||
- Data Exfiltration
|
||||
@@ -70,7 +66,6 @@ tags:
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- data:
|
||||
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566/o365_various_alerts/o365_various_alerts.log
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566/o365_various_alerts/o365_various_alerts.log
|
||||
sourcetype: o365:management:activity
|
||||
source: o365
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: O365 Elevated Mailbox Permission Assigned
|
||||
id: 2246c142-a678-45f8-8546-aaed7e0efd30
|
||||
version: 6
|
||||
version: 7
|
||||
date: '2025-02-10'
|
||||
author: Patrick Bareiss, Mauricio Velazco, Splunk
|
||||
data_source: []
|
||||
@@ -14,11 +14,13 @@ description: The following analytic identifies the assignment of elevated mailbo
|
||||
over mailboxes, which could lead to data exfiltration or privilege escalation. If
|
||||
confirmed malicious, attackers could gain extensive access to sensitive email data
|
||||
and potentially manipulate mailbox settings, posing a severe security risk.
|
||||
search: '`o365_management_activity` Workload=Exchange Operation=Add-MailboxPermission
|
||||
| search (AccessRights=FullAccess OR AccessRights=ChangePermission OR AccessRights=ChangeOwner)
|
||||
| rename Identity AS dest_user | stats count earliest(_time) as firstTime latest(_time)
|
||||
as lastTime by user dest_user Operation AccessRights |`security_content_ctime(firstTime)`
|
||||
|`security_content_ctime(lastTime)` | `o365_elevated_mailbox_permission_assigned_filter`'
|
||||
search: '`o365_management_activity` Workload=Exchange Operation=Add-MailboxPermission (AccessRights=FullAccess OR AccessRights=ChangePermission OR AccessRights=ChangeOwner)
|
||||
| rename Identity AS dest_user
|
||||
| fillnull
|
||||
| stats count min(_time) as firstTime max(_time) as lastTime by signature dest user src vendor_account vendor_product dest_user
|
||||
| `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)`
|
||||
| `o365_elevated_mailbox_permission_assigned_filter`'
|
||||
how_to_implement: You must install the Splunk Microsoft Office 365 Add-on and ingest
|
||||
Office 365 management activity events.
|
||||
known_false_positives: FullAccess mailbox delegation may be assigned for legitimate
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: O365 Email Access By Security Administrator
|
||||
id: c6998a30-fef4-4e89-97ac-3bb0123719b4
|
||||
version: 5
|
||||
date: '2025-02-10'
|
||||
version: 6
|
||||
date: '2025-03-25'
|
||||
author: Steven Dick
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -12,9 +12,9 @@ description: The following analytic identifies when a user with sufficient acces
|
||||
data_source:
|
||||
- Office 365 Universal Audit Log
|
||||
search: '`o365_management_activity` Workload=SecurityComplianceCenter Operation=AdminMailAccess
|
||||
| stats values(Workload) as category, values(MailboxId) as user, values(Operation)
|
||||
as signature, count, min(_time) as firstTime, max(_time) as lastTime by InternetMessageId,
|
||||
UserId | rename InternetMessageId as signature_id, UserId as src_user | `security_content_ctime(firstTime)`
|
||||
| rename InternetMessageId as signature_id, UserId as src_user | fillnull | stats
|
||||
count min(_time) as firstTime max(_time) as lastTime by signature dest user src
|
||||
vendor_account vendor_product src_user signature_id | `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)` | `o365_email_access_by_security_administrator_filter`'
|
||||
how_to_implement: You must install the Splunk Microsoft Office 365 Add-on and ingest
|
||||
Office 365 management activity events. Threat Explorer is a premium feature with
|
||||
@@ -64,7 +64,6 @@ tags:
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- data:
|
||||
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566/o365_various_alerts/o365_various_alerts.log
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566/o365_various_alerts/o365_various_alerts.log
|
||||
sourcetype: o365:management:activity
|
||||
source: o365
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: O365 Email Reported By Admin Found Malicious
|
||||
id: 94396c3e-7728-422a-9956-e4b77b53dbdf
|
||||
version: 5
|
||||
date: '2025-02-10'
|
||||
version: 6
|
||||
date: '2025-03-25'
|
||||
author: Steven Dick
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -13,12 +13,11 @@ description: The following analytic detects when an email manually submitted to
|
||||
data_source:
|
||||
- Office 365 Universal Audit Log
|
||||
search: '`o365_management_activity` Workload=SecurityComplianceCenter Operation=AdminSubmission
|
||||
| search RescanVerdict IN (Phish,Malware) | stats values(Subject) as subject, values(RescanVerdict)
|
||||
as result, values(SenderIP) as src, values(P2Sender) as sender, values(P1Sender)
|
||||
as src_user, values(Recipients{}) as user, count min(_time) as firstTime, max(_time)
|
||||
as lastTime, by Id,Operation,UserId | rename Name as signature, Id as signature_id,
|
||||
UserId as o365_adminuser | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
|
||||
| `o365_email_reported_by_admin_found_malicious_filter`'
|
||||
| search RescanVerdict IN (Phish,Malware) | rename Id as signature_id, SenderIP
|
||||
as src, Recipients{} as dest_user, P1Sender as src_user | fillnull | stats count
|
||||
min(_time) as firstTime max(_time) as lastTime by dest user src vendor_account vendor_product
|
||||
signature signature_id dest_user src_user Subject SubmissionContent | `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)` | `o365_email_reported_by_admin_found_malicious_filter`'
|
||||
how_to_implement: You must install splunk Microsoft Office 365 add-on. This search
|
||||
works with o365:management:activity
|
||||
known_false_positives: Administrators that submit known phishing training exercises.
|
||||
@@ -39,8 +38,7 @@ drilldown_searches:
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
rba:
|
||||
message: O365 security admin $o365_adminuser$ manually reported a suspicious email
|
||||
from $src_user$
|
||||
message: O365 security admin $user$ manually reported a suspicious email from $src_user$
|
||||
risk_objects:
|
||||
- field: src_user
|
||||
type: user
|
||||
@@ -49,7 +47,7 @@ rba:
|
||||
type: user
|
||||
score: 50
|
||||
threat_objects:
|
||||
- field: subject
|
||||
- field: Subject
|
||||
type: email_subject
|
||||
tags:
|
||||
analytic_story:
|
||||
@@ -67,7 +65,6 @@ tags:
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- data:
|
||||
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566/o365_various_alerts/o365_various_alerts.log
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566/o365_various_alerts/o365_various_alerts.log
|
||||
sourcetype: o365:management:activity
|
||||
source: o365
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: O365 Email Reported By User Found Malicious
|
||||
id: 7698b945-238e-4bb9-b172-81f5ca1685a1
|
||||
version: 5
|
||||
date: '2025-02-10'
|
||||
version: 6
|
||||
date: '2025-03-25'
|
||||
author: Steven Dick
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -12,14 +12,14 @@ description: The following analytic detects when an email submitted to Microsoft
|
||||
that returns a Phish or Malware verdict upon submission.
|
||||
data_source:
|
||||
- Office 365 Universal Audit Log
|
||||
search: '`o365_management_activity` Workload=SecurityComplianceCenter Operation=AlertEntityGenerated
|
||||
search: '`o365_management_activity` Workload=SecurityComplianceCenter Operation=AlertEntityGenerated
|
||||
Name="Email reported by user as*" | fromjson Data | rename _raw AS temp etps AS
|
||||
_raw | extract pairdelim=";" kvdelim=":" | rename _raw AS etps temp AS _raw | search
|
||||
RescanVerdict IN (Phish,Malware) | rex field=tsd "\<(?<src_user>.+)\>" | eval src_user
|
||||
= case(isnull(src_user),tsd,true(),src_user) | stats count min(_time) as firstTime
|
||||
max(_time) as lastTime values(ms) as subject values(RescanVerdict) as result values(tsd)
|
||||
as sender values(src_user) as src_user by AlertId,AlertEntityId,Operation,Name |
|
||||
rename Name as signature, AlertId as signature_id, AlertEntityId as user | `security_content_ctime(firstTime)`
|
||||
= case(isnull(src_user),tsd,true(),src_user) | rename Name as signature, AlertId
|
||||
as signature_id, AlertEntityId as user, tsd as sender, ms as subject | fillnull
|
||||
| stats count min(_time) as firstTime max(_time) as lastTime by dest user src vendor_account
|
||||
vendor_product signature signature_id src_user sender subject | `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)` | `o365_email_reported_by_user_found_malicious_filter`'
|
||||
how_to_implement: You must install the Splunk Microsoft Office 365 Add-on and ingest
|
||||
Office 365 management activity events. You must deploy/allow the usage of the Microsoft
|
||||
@@ -42,7 +42,7 @@ drilldown_searches:
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
rba:
|
||||
message: The user $user$ reported an email classified as $result$ from $src_user$
|
||||
message: The user $user$ reported an email classified from $src_user$
|
||||
risk_objects:
|
||||
- field: src_user
|
||||
type: user
|
||||
@@ -69,7 +69,6 @@ tags:
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- data:
|
||||
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566/o365_various_alerts/o365_various_alerts.log
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566/o365_various_alerts/o365_various_alerts.log
|
||||
sourcetype: o365:management:activity
|
||||
source: o365
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: O365 Email Security Feature Changed
|
||||
id: 4d28013d-3a0f-4d65-a33f-4e8009fee0ae
|
||||
version: 5
|
||||
date: '2025-02-10'
|
||||
version: 6
|
||||
date: '2025-03-25'
|
||||
author: Steven Dick
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -13,10 +13,11 @@ description: The following analytic identifies when specific O365 advanced secur
|
||||
data_source:
|
||||
- Office 365 Universal Audit Log
|
||||
search: '`o365_management_activity` Workload=Exchange AND Operation IN ("Set-*","Disable-*","New-*","Remove-*")
|
||||
Operation IN ("*AntiPhish*","*SafeLink*","*SafeAttachment*","*Malware*") | stats
|
||||
values(ObjectId) as object, min(_time) as firstTime, max(_time) as lastTime, count by
|
||||
Id, UserId, Operation | rename Id as object_id, UserId as user, Operation as signature
|
||||
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `o365_email_security_feature_changed_filter`'
|
||||
Operation IN ("*AntiPhish*","*SafeLink*","*SafeAttachment*","*Malware*") | rename
|
||||
Id as object_id, UserId as user, Operation as signature, ObjectId as object | fillnull
|
||||
| stats count min(_time) as firstTime max(_time) as lastTime by dest user src vendor_account
|
||||
vendor_product signature object_id object | `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)` | `o365_email_security_feature_changed_filter`'
|
||||
how_to_implement: You must install the Splunk Microsoft Office 365 Add-on and ingest
|
||||
Office 365 management activity events.
|
||||
known_false_positives: Administrators might alter features for troubleshooting, performance
|
||||
@@ -61,7 +62,6 @@ tags:
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- data:
|
||||
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566/o365_various_alerts/o365_various_alerts.log
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566/o365_various_alerts/o365_various_alerts.log
|
||||
sourcetype: o365:management:activity
|
||||
source: o365
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: O365 Email Suspicious Behavior Alert
|
||||
id: 85c7555a-05af-4322-81aa-76b4ddf52baa
|
||||
version: 5
|
||||
date: '2025-02-10'
|
||||
version: 6
|
||||
date: '2025-03-25'
|
||||
author: Steven Dick
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -16,8 +16,9 @@ data_source:
|
||||
search: '`o365_management_activity` Workload=SecurityComplianceCenter Operation=AlertEntityGenerated
|
||||
Name IN ("Suspicious email sending patterns detected","User restricted from sending
|
||||
email","Suspicious Email Forwarding Activity","Email sending limit exceeded") |
|
||||
fromjson Data | stats count min(_time) as firstTime max(_time) as lastTime by AlertId,ObjectId,Operation,Name
|
||||
| rename Name as signature, AlertId as signature_id, ObjectId as user | `security_content_ctime(firstTime)`
|
||||
fromjson Data | rename Name as signature, AlertId as signature_id, ObjectId as user
|
||||
| fillnull | stats count min(_time) as firstTime max(_time) as lastTime by dest
|
||||
user src vendor_account vendor_product signature signature_id | `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)` | `o365_email_suspicious_behavior_alert_filter`'
|
||||
how_to_implement: You must install the Splunk Microsoft Office 365 Add-on and ingest
|
||||
Office 365 management activity events. The alerts must be enabled in the o365 security
|
||||
@@ -63,7 +64,6 @@ tags:
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- data:
|
||||
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566/o365_various_alerts/o365_various_alerts.log
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566/o365_various_alerts/o365_various_alerts.log
|
||||
sourcetype: o365:management:activity
|
||||
source: o365
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: O365 Email Transport Rule Changed
|
||||
id: 11ebb7c2-46bd-41c9-81e1-d0b4b34583a2
|
||||
version: 1
|
||||
version: 2
|
||||
date: '2025-01-15'
|
||||
author: Steven Dick
|
||||
status: production
|
||||
@@ -11,8 +11,8 @@ data_source:
|
||||
search: |-
|
||||
`o365_management_activity` Workload=Exchange AND Operation IN ("Set-*","Disable-*","New-*","Remove-*") AND Operation="*TransportRule"
|
||||
| eval object_name = case('Parameters{}.Name'=="Name",mvindex('Parameters{}.Value',mvfind('Parameters{}.Name',"^Name$")),true(),ObjectId), object_id = case('Parameters{}.Name'=="Identity",mvindex('Parameters{}.Value',mvfind('Parameters{}.Name',"^Identity$")),true(),Id)
|
||||
| stats values(object_name) as object_name, min(_time) as firstTime, max(_time) as lastTime, count by object_id, UserId, Operation
|
||||
| rename UserId as user, Operation as signature
|
||||
| stats values(object_name) as object_name, min(_time) as firstTime, max(_time) as lastTime, count by object_id, UserId, Operation, signature
|
||||
| rename UserId as user
|
||||
| `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)`
|
||||
| `o365_email_transport_rule_changed_filter`
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: O365 Excessive Authentication Failures Alert
|
||||
id: d441364c-349c-453b-b55f-12eccab67cf9
|
||||
version: 5
|
||||
version: 6
|
||||
date: '2024-11-14'
|
||||
author: Rod Soto, Splunk
|
||||
status: production
|
||||
@@ -13,11 +13,12 @@ description: The following analytic identifies an excessive number of authentica
|
||||
this activity could lead to unauthorized access, data breaches, or further exploitation
|
||||
within the environment.
|
||||
data_source: []
|
||||
search: '`o365_management_activity` Workload=AzureActiveDirectory UserAuthenticationMethod=*
|
||||
status=failure | stats count earliest(_time) AS firstTime latest(_time) AS lastTime
|
||||
values(UserAuthenticationMethod) AS UserAuthenticationMethod values(UserAgent) AS
|
||||
UserAgent values(status) AS status values(src_ip) AS src_ip by user | where count
|
||||
> 10 | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
|
||||
search: '`o365_management_activity` Workload=AzureActiveDirectory UserAuthenticationMethod=* status=failure
|
||||
| stats count earliest(_time) AS firstTime latest(_time) AS lastTime values(UserAuthenticationMethod) AS UserAuthenticationMethod values(UserAgent) AS
|
||||
user_agent values(status) AS status values(src_ip) AS src values(signature) as signature by user vendor_account vendor_product dest
|
||||
| where count > 10
|
||||
| `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)`
|
||||
| `o365_excessive_authentication_failures_alert_filter`'
|
||||
how_to_implement: You must install splunk Microsoft Office 365 add-on. This search
|
||||
works with o365:management:activity
|
||||
@@ -41,13 +42,13 @@ drilldown_searches:
|
||||
latest_offset: $info_max_time$
|
||||
rba:
|
||||
message: User $user$ has caused excessive number of authentication failures from
|
||||
$src_ip$ using UserAgent $UserAgent$.
|
||||
$src$ using UserAgent $user_agent$.
|
||||
risk_objects:
|
||||
- field: user
|
||||
type: user
|
||||
score: 64
|
||||
threat_objects:
|
||||
- field: src_ip
|
||||
- field: src
|
||||
type: ip_address
|
||||
tags:
|
||||
analytic_story:
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: O365 Excessive SSO logon errors
|
||||
id: 8158ccc4-6038-11eb-ae93-0242ac130002
|
||||
version: 6
|
||||
version: 7
|
||||
date: '2024-11-14'
|
||||
author: Rod Soto, Splunk
|
||||
status: production
|
||||
@@ -14,10 +14,11 @@ description: The following analytic detects accounts experiencing a high number
|
||||
movement within the organization.
|
||||
data_source:
|
||||
- O365 UserLoginFailed
|
||||
search: '`o365_management_activity` Workload=AzureActiveDirectory LogonError=*Sso*
|
||||
Operation=UserLoginFailed | stats count min(_time) as firstTime max(_time) as lastTime
|
||||
values(user) as user by src_ip signature user_agent authentication_service action|
|
||||
where count >= 5 | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
|
||||
search: '`o365_management_activity` Workload=AzureActiveDirectory LogonError=*Sso* Operation=UserLoginFailed
|
||||
| stats count min(_time) as firstTime max(_time) as lastTime values(user) as user by src vendor_account vendor_product dest signature user_agent
|
||||
| where count >= 5
|
||||
| `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)`
|
||||
| `o365_excessive_sso_logon_errors_filter`'
|
||||
how_to_implement: You must install splunk Microsoft Office 365 add-on. This search
|
||||
works with o365:management:activity
|
||||
@@ -40,13 +41,13 @@ drilldown_searches:
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
rba:
|
||||
message: Excessive number of SSO logon errors from $src_ip$ using UserAgent $user_agent$.
|
||||
message: Excessive number of SSO logon errors from $src$ using UserAgent $user_agent$.
|
||||
risk_objects:
|
||||
- field: user
|
||||
type: user
|
||||
score: 64
|
||||
threat_objects:
|
||||
- field: src_ip
|
||||
- field: src
|
||||
type: ip_address
|
||||
tags:
|
||||
analytic_story:
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: O365 External Guest User Invited
|
||||
id: 8c6d52ec-d5f2-4b2f-8ba1-f32c047a71fa
|
||||
version: 4
|
||||
version: 5
|
||||
date: '2024-11-14'
|
||||
author: Steven Dick
|
||||
status: production
|
||||
@@ -16,15 +16,19 @@ description: The following analytic identifies the invitation of an external gue
|
||||
source.
|
||||
data_source:
|
||||
- Office 365 Universal Audit Log
|
||||
search: "`o365_management_activity` Workload=AzureActiveDirectory AND Operation=\"\
|
||||
Add user*\" AND ModifiedProperties{}.NewValue=\"[*Guest*]\" AND ModifiedProperties{}.NewValue=\"\
|
||||
[*Invitation*]\" | eval user = (mvindex('ModifiedProperties{}.NewValue',5)), src_user
|
||||
= case(match(mvindex('Actor{}.ID',-1),\"User\"),mvindex('Actor{}.ID',0),match(mvindex('Actor{}.ID',-1),\"\
|
||||
ServicePrincipal\"),mvindex('Actor{}.ID',3),true(),mvindex('Actor{}.ID',0)) | rex
|
||||
field=user \"(?<user>[\\\\w\\\\.-]+@[\\\\w-]+\\\\.[\\\\w-]{2,4})\" | stats values(user)
|
||||
as user, min(_time) as firstTime, max(_time) as lastTime, count by Operation,Id,src_user
|
||||
| rename Operation as signature, Id as signature_id | `security_content_ctime(firstTime)`\
|
||||
\ | `security_content_ctime(lastTime)` | `o365_external_guest_user_invited_filter`"
|
||||
search: "`o365_management_activity` Workload=AzureActiveDirectory AND Operation=\"Add user*\" AND ModifiedProperties{}.NewValue=\"[*Guest*]\" AND ModifiedProperties{}.NewValue=\"[*Invitation*]\"
|
||||
| eval user = (mvindex('ModifiedProperties{}.NewValue',5)), src_user = case(match(mvindex('Actor{}.ID',-1),\"User\"),mvindex('Actor{}.ID',0),match(mvindex('Actor{}.ID',-1),\"ServicePrincipal\"),mvindex('Actor{}.ID',3),true(),mvindex('Actor{}.ID',0))
|
||||
| rex
|
||||
field=user \"(?<user>
|
||||
[ \\w\\.-]+@
|
||||
[ \\w-]+\\.
|
||||
[ \\w-]{2,4})\"
|
||||
| rename Operation as signature, Id as signature_id
|
||||
| fillnull
|
||||
| stats count min(_time) as firstTime max(_time) as lastTime by dest user src vendor_account vendor_product signature signature_id src_user
|
||||
| `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)`
|
||||
| `o365_external_guest_user_invited_filter`"
|
||||
how_to_implement: You must install the Splunk Microsoft Office 365 Add-on and ingest
|
||||
Office 365 management activity events.
|
||||
known_false_positives: Administrator may legitimately invite external guest users.
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: O365 External Identity Policy Changed
|
||||
id: 29af1725-7a72-4d2d-8a18-e697e79a62d3
|
||||
version: 4
|
||||
version: 5
|
||||
date: '2024-11-14'
|
||||
author: Steven Dick
|
||||
status: production
|
||||
@@ -15,23 +15,27 @@ description: The following analytic identifies when changes are made to the exte
|
||||
by Abusing External Identities`.
|
||||
data_source:
|
||||
- Office 365 Universal Audit Log
|
||||
search: "`o365_management_activity` Workload=AzureActiveDirectory Operation=\"Update
|
||||
policy.\" Target{}.ID=\"B2BManagementPolicy\" | eval object_attrs = mvindex('ModifiedProperties{}.NewValue',0),
|
||||
object_attrs_old = mvindex('ModifiedProperties{}.OldValue',0), object_name = mvindex('Target{}.ID',3),
|
||||
signature=Operation, user = case(match(mvindex('Actor{}.ID',-1),\"User\"),mvindex('Actor{}.ID',0),match(mvindex('Actor{}.ID',-1),\"\
|
||||
ServicePrincipal\"),mvindex('Actor{}.ID',3),true(),mvindex('Actor{}.ID',0)) | spath
|
||||
input=object_attrs_old output=B2BOld path={} | spath input=B2BOld | rename B2BManagementPolicy.*
|
||||
as B2BManagementPolicyOld.* | spath input=object_attrs output=B2BNew path={} | spath
|
||||
input=B2BNew | eval object_attrs = 'B2BManagementPolicy.InvitationsAllowedAndBlockedDomainsPolicy.AllowedDomains{}'
|
||||
, object_attrs_old = 'B2BManagementPolicyOld.InvitationsAllowedAndBlockedDomainsPolicy.AllowedDomains{}'
|
||||
| eval diff_add=mvmap(object_attrs,if(isnull(mvfind(object_attrs_old,object_attrs)),object_attrs,null))
|
||||
| eval diff_remove=mvmap(object_attrs_old,if(isnull(mvfind(object_attrs,object_attrs_old)),object_attrs_old,null))
|
||||
| eval result = case(isnotnull(diff_add),\"Added \".mvjoin(diff_add,\",\"),isnotnull(diff_remove),\"\
|
||||
Removed \".mvjoin(diff_remove,\",\")), action = case(isnotnull(diff_add),\"created\"\
|
||||
,isnotnull(diff_remove),\"deleted\") | stats values(object_attrs) as object_attrs,
|
||||
values(action) as action, values(result) as result, values(B2BManagementPolicy*)
|
||||
as B2BManagementPolicy*, count, min(_time) as firstTime, max(_time) as lastTime
|
||||
by user,signature,object_name | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
|
||||
search: "`o365_management_activity` Workload=AzureActiveDirectory Operation=\"Update policy.\" Target{}.ID=\"B2BManagementPolicy\"
|
||||
| eval object_attrs = mvindex('ModifiedProperties{}.NewValue',0),
|
||||
object_attrs_old = mvindex('ModifiedProperties{}.OldValue',0), object_name = mvindex('Target{}.ID',3),
|
||||
signature=Operation, user = case(match(mvindex('Actor{}.ID',-1),\"User\"),mvindex('Actor{}.ID',0),match(mvindex('Actor{}.ID',-1),\"ServicePrincipal\"),
|
||||
mvindex('Actor{}.ID',3),true(),mvindex('Actor{}.ID',0))
|
||||
| spath input=object_attrs_old output=B2BOld path={}
|
||||
| spath input=B2BOld
|
||||
| rename B2BManagementPolicy.* as B2BManagementPolicyOld.*
|
||||
| spath input=object_attrs output=B2BNew path={}
|
||||
| spath input=B2BNew
|
||||
| eval object_attrs = 'B2BManagementPolicy.InvitationsAllowedAndBlockedDomainsPolicy.AllowedDomains{}'
|
||||
, object_attrs_old = 'B2BManagementPolicyOld.InvitationsAllowedAndBlockedDomainsPolicy.AllowedDomains{}'
|
||||
| eval diff_add=mvmap(object_attrs,if(isnull(mvfind(object_attrs_old,object_attrs)),object_attrs,null))
|
||||
| eval diff_remove=mvmap(object_attrs_old,if(isnull(mvfind(object_attrs,object_attrs_old)),object_attrs_old,null))
|
||||
| eval result = case(isnotnull(diff_add),\"Added \".mvjoin(diff_add,\",\"),isnotnull(diff_remove),\"Removed \".mvjoin(diff_remove,\",\")), action = case(isnotnull(diff_add),\"created\",isnotnull(diff_remove),\"deleted\")
|
||||
| stats values(object_attrs) as object_attrs,
|
||||
values(action) as action, values(result) as result, values(B2BManagementPolicy*)
|
||||
as B2BManagementPolicy*, count, min(_time) as firstTime, max(_time) as lastTime
|
||||
by user signature object_name dest vendor_account vendor_product
|
||||
| `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)`
|
||||
| `o365_external_identity_policy_changed_filter`"
|
||||
how_to_implement: You must install the Splunk Microsoft Office 365 Add-on and ingest
|
||||
Office 365 management activity events.
|
||||
@@ -54,7 +58,7 @@ drilldown_searches:
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
rba:
|
||||
message: User $user$ changed the external identity [$object_name$] policy - $result$
|
||||
message: User $user$ changed the external identity [$object_name$] policy
|
||||
risk_objects:
|
||||
- field: user
|
||||
type: user
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: O365 File Permissioned Application Consent Granted by User
|
||||
id: 6c382336-22b8-4023-9b80-1689e799f21f
|
||||
version: 4
|
||||
version: 5
|
||||
date: '2024-11-14'
|
||||
author: Mauricio Velazco, Splunk
|
||||
status: production
|
||||
@@ -15,13 +15,17 @@ description: The following analytic identifies instances where a user in the Off
|
||||
is malicious or overly permissive. If confirmed malicious, this could lead to data
|
||||
breaches, data loss, or unauthorized data manipulation, necessitating immediate
|
||||
investigation to validate the application's legitimacy and assess potential risks.
|
||||
search: "`o365_management_activity` Workload=AzureActiveDirectory Operation=\"Consent
|
||||
to application.\" ResultStatus=Success | eval admin_consent =mvindex('ModifiedProperties{}.NewValue',
|
||||
0) | search admin_consent=False | eval permissions =mvindex('ModifiedProperties{}.NewValue',
|
||||
4) | rex field=permissions \"Scope: (?<Scope>[^,]+)\" | makemv delim=\" \" Scope
|
||||
| search Scope IN (\"Files.Read\", \"Files.Read.All\", \"Files.ReadWrite\", \"Files.ReadWrite.All\"\
|
||||
, \"Files.ReadWrite.AppFolder\") | stats max(_time) as lastTime values(Scope) by
|
||||
Operation, user, object, ObjectId | `security_content_ctime(lastTime)` | `o365_file_permissioned_application_consent_granted_by_user_filter`"
|
||||
search: "`o365_management_activity` Workload=AzureActiveDirectory Operation=\"Consent to application.\" ResultStatus=Success
|
||||
| eval admin_consent =mvindex('ModifiedProperties{}.NewValue',0)
|
||||
| search admin_consent=False
|
||||
| eval permissions =mvindex('ModifiedProperties{}.NewValue',4)
|
||||
| rex field=permissions \"Scope:(?<Scope>[^,]+)\"
|
||||
| makemv delim=\" \" Scope
|
||||
| search Scope IN (\"Files.Read\", \"Files.Read.All\", \"Files.ReadWrite\", \"Files.ReadWrite.All\", \"Files.ReadWrite.AppFolder\")
|
||||
| fillnull
|
||||
| stats count min(_time) as firstTime max(_time) as lastTime values(Scope) as Scope by signature dest user src vendor_account vendor_product object ObjectId
|
||||
| `security_content_ctime(lastTime)`
|
||||
| `o365_file_permissioned_application_consent_granted_by_user_filter`"
|
||||
how_to_implement: You must install the Splunk Microsoft Office 365 Add-on and ingest
|
||||
Office 365 management activity events.
|
||||
known_false_positives: OAuth applications that require file permissions may be legitimate,
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: O365 FullAccessAsApp Permission Assigned
|
||||
id: 01a510b3-a6ac-4d50-8812-7e8a3cde3d79
|
||||
version: 4
|
||||
version: 5
|
||||
date: '2024-11-14'
|
||||
author: Mauricio Velazco, Splunk
|
||||
status: production
|
||||
@@ -15,13 +15,15 @@ description: The following analytic detects the assignment of the 'full_access_a
|
||||
Office 365 operations, including access to all mailboxes and the ability to send
|
||||
mail as any user. If confirmed malicious, this could lead to unauthorized data access,
|
||||
exfiltration, or account compromise. Immediate investigation is required.
|
||||
search: "`o365_management_activity` Workload=AzureActiveDirectory Operation=\"Update
|
||||
application.\" | eval newvalue = mvindex('ModifiedProperties{}.NewValue',0) | spath
|
||||
input=newvalue | search \"{}.ResourceAppId\"=\"00000002-0000-0ff1-ce00-000000000000\"\
|
||||
\ \"{}.RequiredAppPermissions{}.EntitlementId\"=\"dc890d15-9560-4a4c-9b7f-a736ec74ec40\"\
|
||||
\ | eval Permissions = '{}.RequiredAppPermissions{}.EntitlementId' | stats count
|
||||
earliest(_time) as firstTime latest(_time) as lastTime values(Permissions) by user,
|
||||
object, user_agent, Operation | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
|
||||
search: "`o365_management_activity` Workload=AzureActiveDirectory Operation=\"Update application.\"
|
||||
| eval newvalue = mvindex('ModifiedProperties{}.NewValue',0)
|
||||
| spath input=newvalue
|
||||
| search \"{}.ResourceAppId\"=\"00000002-0000-0ff1-ce00-000000000000\"\"{}.RequiredAppPermissions{}.EntitlementId\"=\"dc890d15-9560-4a4c-9b7f-a736ec74ec40\"
|
||||
| eval Permissions = '{}.RequiredAppPermissions{}.EntitlementId'
|
||||
| fillnull
|
||||
| stats count min(_time) as firstTime max(_time) as lastTime values(Scope) as Scope by signature dest user src vendor_account vendor_product object user_agent
|
||||
| `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)`
|
||||
| `o365_fullaccessasapp_permission_assigned_filter`"
|
||||
how_to_implement: You must install the Splunk Microsoft Office 365 Add-on and ingest
|
||||
Office 365 management activity events.
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: O365 High Number Of Failed Authentications for User
|
||||
id: 31641378-2fa9-42b1-948e-25e281cb98f7
|
||||
version: 6
|
||||
version: 7
|
||||
date: '2025-02-10'
|
||||
author: Mauricio Velazco, Splunk
|
||||
status: production
|
||||
@@ -15,9 +15,12 @@ description: The following analytic identifies an O365 account experiencing more
|
||||
access to the O365 environment, potentially compromising sensitive emails, documents,
|
||||
and other data. Prompt investigation and action are crucial to prevent unauthorized
|
||||
access and data breaches.
|
||||
search: '`o365_management_activity` Operation=UserLoginFailed record_type=AzureActiveDirectoryStsLogon
|
||||
Workload=AzureActiveDirectory | bucket span=5m _time | stats dc(_raw) AS failed_attempts values(src_ip)
|
||||
as src_ip by user, _time | where failed_attempts > 10 | `o365_high_number_of_failed_authentications_for_user_filter`'
|
||||
search: '`o365_management_activity` Operation=UserLoginFailed record_type=AzureActiveDirectoryStsLogon Workload=AzureActiveDirectory
|
||||
| bucket span=5m _time
|
||||
| fillnull
|
||||
| stats dc(_raw) AS failed_attempts values(src_ip) as src by signature user _time dest vendor_account vendor_product
|
||||
| where failed_attempts > 10
|
||||
| `o365_high_number_of_failed_authentications_for_user_filter`'
|
||||
how_to_implement: You must install the Splunk Microsoft Office 365 Add-on and ingest
|
||||
Office 365 management activity events.
|
||||
known_false_positives: Although unusual, users who have lost their passwords may trigger
|
||||
@@ -47,7 +50,7 @@ rba:
|
||||
type: user
|
||||
score: 35
|
||||
threat_objects:
|
||||
- field: src_ip
|
||||
- field: src
|
||||
type: ip_address
|
||||
tags:
|
||||
analytic_story:
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: O365 High Privilege Role Granted
|
||||
id: e78a1037-4548-4072-bb1b-ad99ae416426
|
||||
version: 5
|
||||
version: 6
|
||||
date: '2025-02-10'
|
||||
author: Mauricio Velazco, Splunk
|
||||
status: production
|
||||
@@ -15,12 +15,15 @@ description: The following analytic detects when high-privilege roles such as "E
|
||||
over critical resources and data. If confirmed malicious, this could enable attackers
|
||||
to gain significant control over O365 resources, access, modify, or delete critical
|
||||
data, and compromise the overall security and functionality of the O365 environment.
|
||||
search: "`o365_management_activity` Operation=\"Add member to role.\" Workload=AzureActiveDirectory
|
||||
| eval role_id = mvindex('ModifiedProperties{}.NewValue',2) | eval role_name = mvindex('ModifiedProperties{}.NewValue',1)
|
||||
| where role_id IN (\"29232cdf-9323-42fd-ade2-1d097af3e4de\", \"f28a1f50-f6e7-4571-818b-6a12f2af6b6c\"\
|
||||
, \"62e90394-69f5-4237-9190-012177145e10\") | stats earliest(_time) as firstTime
|
||||
latest(_time) as lastTime by user Operation ObjectId role_name | `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)` | `o365_high_privilege_role_granted_filter`"
|
||||
search: "`o365_management_activity` Operation=\"Add member to role.\" Workload=AzureActiveDirectory
|
||||
| eval role_id = mvindex('ModifiedProperties{}.NewValue',2)
|
||||
| eval role_name = mvindex('ModifiedProperties{}.NewValue',1)
|
||||
| where role_id IN (\"29232cdf-9323-42fd-ade2-1d097af3e4de\", \"f28a1f50-f6e7-4571-818b-6a12f2af6b6c\", \"62e90394-69f5-4237-9190-012177145e10\")
|
||||
| fillnull
|
||||
| stats count min(_time) as firstTime max(_time) as lastTime by signature dest user src vendor_account vendor_product ObjectId role_name role_id
|
||||
| `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)`
|
||||
| `o365_high_privilege_role_granted_filter`"
|
||||
how_to_implement: You must install the Splunk Microsoft Office 365 Add-on and ingest
|
||||
Office 365 management activity events.
|
||||
known_false_positives: Privilege roles may be assigned for legitimate purposes, filter
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: O365 Mail Permissioned Application Consent Granted by User
|
||||
id: fddad083-cdf5-419d-83c6-baa85e329595
|
||||
version: 4
|
||||
version: 5
|
||||
date: '2024-11-14'
|
||||
author: Mauricio Velazco, Splunk
|
||||
status: production
|
||||
@@ -16,13 +16,16 @@ description: The following analytic identifies instances where a user grants con
|
||||
data access, email forwarding, or sending malicious emails from the compromised
|
||||
account. Validating the legitimacy of the application and consent context is crucial
|
||||
to prevent data breaches.
|
||||
search: "`o365_management_activity` Workload=AzureActiveDirectory Operation=\"Consent
|
||||
to application.\" ResultStatus=Success | eval admin_consent =mvindex('ModifiedProperties{}.NewValue',
|
||||
0) | search admin_consent=False | eval permissions =mvindex('ModifiedProperties{}.NewValue',
|
||||
4) | rex field=permissions \"Scope: (?<Scope>[^,]+)\" | makemv delim=\" \" Scope
|
||||
| search Scope IN (\"Mail.Read\", \"Mail.ReadBasic\", \"Mail.ReadWrite\", \"Mail.Read.Shared\"\
|
||||
, \"Mail.ReadWrite.Shared\", \"Mail.Send\", \"Mail.Send.Shared\") | stats max(_time)
|
||||
as lastTime values(Scope) by Operation, user, object, ObjectId | `security_content_ctime(lastTime)`
|
||||
search: "`o365_management_activity` Workload=AzureActiveDirectory Operation=\"Consent to application.\" ResultStatus=Success
|
||||
| eval admin_consent =mvindex('ModifiedProperties{}.NewValue',0)
|
||||
| search admin_consent=False
|
||||
| eval permissions =mvindex('ModifiedProperties{}.NewValue',4)
|
||||
| rex field=permissions \"Scope:(?<Scope>[^,]+)\"
|
||||
| makemv delim=\" \" Scope
|
||||
| search Scope IN (\"Mail.Read\", \"Mail.ReadBasic\", \"Mail.ReadWrite\", \"Mail.Read.Shared\", \"Mail.ReadWrite.Shared\", \"Mail.Send\", \"Mail.Send.Shared\")
|
||||
| fillnull
|
||||
| stats count min(_time) as firstTime max(_time) as lastTime values(Scope) as Scope by signature dest user src vendor_account vendor_product object ObjectId
|
||||
| `security_content_ctime(lastTime)`
|
||||
| `o365_mail_permissioned_application_consent_granted_by_user_filter`"
|
||||
how_to_implement: You must install the Splunk Microsoft Office 365 Add-on and ingest
|
||||
Office 365 management activity events.
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: O365 Mailbox Email Forwarding Enabled
|
||||
id: 0b6bc75c-05d1-4101-9fc3-97e706168f24
|
||||
version: 5
|
||||
version: 6
|
||||
date: '2025-02-10'
|
||||
author: Patrick Bareiss, Mauricio Velazco, Splunk
|
||||
data_source: []
|
||||
@@ -14,12 +14,16 @@ description: The following analytic identifies instances where email forwarding
|
||||
to data exfiltration and unauthorized access to sensitive information. If confirmed
|
||||
malicious, attackers could intercept and redirect emails, potentially compromising
|
||||
confidential communications and leading to data breaches.
|
||||
search: "`o365_management_activity` Operation=Set-Mailbox | eval match1=mvfind('Parameters{}.Name',
|
||||
\"ForwardingAddress\") | eval match2=mvfind('Parameters{}.Name', \"ForwardingSmtpAddress\"\
|
||||
) | where match1>= 0 OR match2>= 0 | eval ForwardTo=coalesce(ForwardingAddress,
|
||||
ForwardingSmtpAddress) | search ForwardTo!=\"\" | rename user_id as user | stats
|
||||
count earliest(_time) as firstTime latest(_time) as lastTime values(ForwardTo) as
|
||||
ForwardTo by user ObjectId |`security_content_ctime(firstTime)` |`security_content_ctime(lastTime)`
|
||||
search: "`o365_management_activity` Operation=Set-Mailbox
|
||||
| eval match1=mvfind('Parameters{}.Name',\"ForwardingAddress\")
|
||||
| eval match2=mvfind('Parameters{}.Name', \"ForwardingSmtpAddress\")
|
||||
| where match1>= 0 OR match2>= 0
|
||||
| eval ForwardTo=coalesce(ForwardingAddress,ForwardingSmtpAddress)
|
||||
| search ForwardTo!=\"\"
|
||||
| rename user_id as user
|
||||
| stats count earliest(_time) as firstTime latest(_time) as lastTime values(ForwardTo) as ForwardTo by signature dest user src vendor_account vendor_product object ObjectId
|
||||
| `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)`
|
||||
| `o365_mailbox_email_forwarding_enabled_filter`"
|
||||
how_to_implement: You must install the Splunk Microsoft Office 365 Add-on and ingest
|
||||
Office 365 management activity events.
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: O365 Mailbox Folder Read Permission Assigned
|
||||
id: 1435475e-2128-4417-a34f-59770733b0d5
|
||||
version: 5
|
||||
version: 6
|
||||
date: '2025-02-10'
|
||||
author: Mauricio Velazco, Splunk
|
||||
data_source: []
|
||||
@@ -14,12 +14,12 @@ description: The following analytic identifies instances where read permissions
|
||||
and potential information leakage. If confirmed malicious, an attacker could gain
|
||||
unauthorized access to sensitive emails, leading to data breaches and compromising
|
||||
the confidentiality of organizational communications.
|
||||
search: "`o365_management_activity` Workload=Exchange (Operation=ModifyFolderPermissions
|
||||
OR Operation=AddFolderPermissions) Workload=Exchange object!=Calendar object!=Contacts
|
||||
object!=PersonMetadata | eval isReadRole=if(match('Item.ParentFolder.MemberRights',
|
||||
\"(ReadAny)\"), \"true\", \"false\") | rename UserId as user | stats count earliest(_time)
|
||||
as firstTime latest(_time) as lastTime by Operation, user, object, Item.ParentFolder.MemberUpn,
|
||||
Item.ParentFolder.MemberRights | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
|
||||
search: "`o365_management_activity` Workload=Exchange (Operation=ModifyFolderPermissions OR Operation=AddFolderPermissions) Workload=Exchange object!=Calendar object!=Contacts object!=PersonMetadata
|
||||
| eval isReadRole=if(match('Item.ParentFolder.MemberRights',\"(ReadAny)\"), \"true\", \"false\")
|
||||
| rename UserId as user
|
||||
| stats count earliest(_time) as firstTime latest(_time) as lastTime by signature user object dest Item.ParentFolder.MemberUpn Item.ParentFolder.MemberRights src vendor_account vendor_product
|
||||
| `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)`
|
||||
| `o365_mailbox_folder_read_permission_assigned_filter`"
|
||||
how_to_implement: You must install the Splunk Microsoft Office 365 Add-on and ingest
|
||||
Office 365 management activity events.
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: O365 Mailbox Folder Read Permission Granted
|
||||
id: cd15c0a8-470e-4b12-9517-046e4927db30
|
||||
version: 6
|
||||
version: 7
|
||||
date: '2025-02-10'
|
||||
author: Mauricio Velazco, Splunk
|
||||
data_source: []
|
||||
@@ -14,12 +14,15 @@ description: The following analytic identifies instances where read permissions
|
||||
exposing sensitive email content. If confirmed malicious, an attacker could gain
|
||||
unauthorized access to read email communications, leading to data breaches or information
|
||||
leakage.
|
||||
search: '`o365_management_activity` Workload=Exchange (Operation="Set-MailboxFolderPermission"
|
||||
OR Operation="Add-MailboxFolderPermission" ) | eval isReadRole=if(match(AccessRights,
|
||||
"^(ReadItems|Author|NonEditingAuthor|Owner|PublishingAuthor|Reviewer)$"), "true",
|
||||
"false") | search isReadRole="true" | rename UserId as user | stats count earliest(_time)
|
||||
as firstTime latest(_time) as lastTime by Operation, user, Identity, AccessRights
|
||||
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `o365_mailbox_folder_read_permission_granted_filter`'
|
||||
search: '`o365_management_activity` Workload=Exchange (Operation="Set-MailboxFolderPermission" OR Operation="Add-MailboxFolderPermission" )
|
||||
| eval isReadRole=if(match(AccessRights,"^(ReadItems|Author|NonEditingAuthor|Owner|PublishingAuthor|Reviewer)$"), "true", "false")
|
||||
| search isReadRole="true"
|
||||
| rename UserId as user
|
||||
| fillnull
|
||||
| stats count min(_time) as firstTime max(_time) as lastTime by signature dest user src vendor_account vendor_product Identity AccessRights
|
||||
| `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)`
|
||||
| `o365_mailbox_folder_read_permission_granted_filter`'
|
||||
how_to_implement: You must install the Splunk Microsoft Office 365 Add-on and ingest
|
||||
Office 365 management activity events.
|
||||
known_false_positives: Mailbox folder permissions may be configured for legitimate
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: O365 Mailbox Inbox Folder Shared with All Users
|
||||
id: 21421896-a692-4594-9888-5faeb8a53106
|
||||
version: 5
|
||||
version: 6
|
||||
date: '2025-02-10'
|
||||
author: Mauricio Velazco, Splunk
|
||||
status: production
|
||||
@@ -15,12 +15,15 @@ description: The following analytic detects instances where the inbox folder of
|
||||
emails. If confirmed malicious, this could lead to data breaches, exfiltration of
|
||||
confidential information, and further compromise through spear-phishing or other
|
||||
malicious activities based on the accessed email content.
|
||||
search: "`o365_management_activity` Operation=ModifyFolderPermissions Workload=Exchange
|
||||
object=Inbox Item.ParentFolder.MemberUpn=Everyone | eval isReadRole=if(match('Item.ParentFolder.MemberRights',
|
||||
\"(ReadAny)\"), \"true\", \"false\") | search isReadRole = \"true\" | stats count
|
||||
earliest(_time) as firstTime latest(_time) as lastTime by Operation, UserId, object,
|
||||
MailboxOwnerUPN, Item.ParentFolder.MemberUpn, Item.ParentFolder.MemberRights | `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)` | `o365_mailbox_inbox_folder_shared_with_all_users_filter`"
|
||||
search: "`o365_management_activity` Operation=ModifyFolderPermissions Workload=Exchange object=Inbox Item.ParentFolder.MemberUpn=Everyone
|
||||
| eval isReadRole=if(match('Item.ParentFolder.MemberRights',\"(ReadAny)\"), \"true\", \"false\")
|
||||
| search isReadRole = \"true\"
|
||||
| rename UserId as user
|
||||
| fillnull
|
||||
| stats count earliest(_time) as firstTime latest(_time) as lastTime by signature, user, dest, vendor_account, vendor_product, object, MailboxOwnerUPN, Item.ParentFolder.MemberUpn, Item.ParentFolder.MemberRights, src
|
||||
| `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)`
|
||||
| `o365_mailbox_inbox_folder_shared_with_all_users_filter`"
|
||||
how_to_implement: You must install the Splunk Microsoft Office 365 Add-on and ingest
|
||||
Office 365 management activity events.
|
||||
known_false_positives: Administrators might temporarily share a mailbox with all users
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: O365 Mailbox Read Access Granted to Application
|
||||
id: 27ab61c5-f08a-438a-b4d3-325e666490b3
|
||||
version: 5
|
||||
version: 6
|
||||
date: '2025-02-10'
|
||||
author: Mauricio Velazco, Splunk
|
||||
status: production
|
||||
@@ -15,12 +15,17 @@ description: The following analytic identifies instances where the Mail.Read Gra
|
||||
read all emails within a user's mailbox, which often contain sensitive or confidential
|
||||
information. If confirmed malicious, this could lead to data exfiltration, spear-phishing
|
||||
attacks, or further compromise based on the information gathered from the emails.
|
||||
search: "`o365_management_activity` Operation=\"Update application.\" | eval json_data=mvindex('ModifiedProperties{}.NewValue',
|
||||
0) | eval json_data=replace(json_data, \"^\\[\\s*\", \"\") | eval json_data=replace(json_data,
|
||||
\"\\s*\\]$\", \"\") | spath input=json_data path=RequiredAppPermissions{}.EntitlementId
|
||||
output=EntitlementIds | eval match_found=mvfind(EntitlementIds, \"810c84a8-4a9e-49e6-bf7d-12d183f40d01\"\
|
||||
) | where isnotnull(match_found) | stats max(_time) as lastTime values(EntitlementIds)
|
||||
as EntitlementIds by Operation, user, object | `security_content_ctime(lastTime)`
|
||||
search: "`o365_management_activity` Operation=\"Update application.\"
|
||||
| eval json_data=mvindex('ModifiedProperties{}.NewValue',0)
|
||||
| eval json_data=replace(json_data,\"^\\[\\s*\",\"\")
|
||||
| eval json_data=replace(json_data,\"\\s*\\]$\",\"\")
|
||||
| spath input=json_data path=RequiredAppPermissions{}.EntitlementId output=EntitlementIds
|
||||
| eval match_found=mvfind(EntitlementIds, \"810c84a8-4a9e-49e6-bf7d-12d183f40d01\")
|
||||
| where isnotnull(match_found)
|
||||
| fillnull
|
||||
| stats count earliest(_time) as firstTime max(_time) as lastTime values(EntitlementIds) as EntitlementIds by signature, user, dest, vendor_account, vendor_product, object, src
|
||||
| `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)`
|
||||
| `o365_mailbox_read_access_granted_to_application_filter`"
|
||||
how_to_implement: You must install the Splunk Microsoft Office 365 Add-on and ingest
|
||||
Office 365 management activity events.
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: O365 Multi-Source Failed Authentications Spike
|
||||
id: ea4e2c41-dbfb-4f5f-a7b6-9ac1b7f104aa
|
||||
version: 6
|
||||
version: 7
|
||||
date: '2025-02-10'
|
||||
author: Mauricio Velazco, Splunk
|
||||
status: production
|
||||
@@ -15,12 +15,15 @@ description: The following analytic identifies a spike in failed authentication
|
||||
If confirmed malicious, this activity could lead to unauthorized access, data breaches,
|
||||
privilege escalation, and lateral movement within the organization. Early detection
|
||||
is crucial to prevent account takeovers and mitigate subsequent threats.
|
||||
search: '`o365_management_activity` Workload=AzureActiveDirectory Operation=UserLoginFailed
|
||||
ErrorNumber=50126 | bucket span=5m _time | eval uniqueIPUserCombo = src_ip . "-"
|
||||
. user | stats dc(uniqueIPUserCombo) as uniqueIpUserCombinations, dc(user) as uniqueUsers,
|
||||
dc(src_ip) as uniqueIPs, values(user) as user, values(src_ip) as ips, values(user_agent)
|
||||
as user_agents by _time | where uniqueIpUserCombinations > 20 AND uniqueUsers >
|
||||
20 AND uniqueIPs > 20 | `o365_multi_source_failed_authentications_spike_filter`'
|
||||
search: '`o365_management_activity` Workload=AzureActiveDirectory Operation=UserLoginFailed ErrorNumber=50126
|
||||
| bucket span=5m _time
|
||||
| eval uniqueIPUserCombo = src_ip . "-" . user
|
||||
| fillnull
|
||||
| stats earliest(_time) as firstTime max(_time) as lastTime dc(uniqueIPUserCombo) as uniqueIpUserCombinations, dc(user) as uniqueUsers, dc(src_ip) as uniqueIPs, values(user) as user, values(src_ip) as ips, values(user_agent) as user_agents values(signature) as signature values(src) as src values(dest) as dest by _time vendor_account vendor_product
|
||||
| where uniqueIpUserCombinations > 20 AND uniqueUsers > 20 AND uniqueIPs > 20
|
||||
| `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)`
|
||||
| `o365_multi_source_failed_authentications_spike_filter`'
|
||||
how_to_implement: You must install the Splunk Microsoft Office 365 Add-on and ingest
|
||||
Office 365 management activity events. The thresholds set within the analytic (such
|
||||
as unique IPs, unique users, etc.) are initial guidelines and should be customized
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: O365 Multiple AppIDs and UserAgents Authentication Spike
|
||||
id: 66adc486-224d-45c1-8e4d-9e7eeaba988f
|
||||
version: 5
|
||||
version: 6
|
||||
date: '2024-11-14'
|
||||
author: Mauricio Velazco, Splunk
|
||||
status: production
|
||||
@@ -17,11 +17,11 @@ description: The following analytic identifies unusual authentication activity i
|
||||
it suggests a compromised account, potentially leading to unauthorized access, privilege
|
||||
escalation, and data exfiltration. Early detection is crucial to prevent further
|
||||
exploitation.
|
||||
search: '`o365_management_activity` Workload=AzureActiveDirectory (Operation=UserLoggedIn
|
||||
OR Operation=UserLoginFailed) | bucket span=5m _time | stats dc(_raw) as failed_attempts
|
||||
dc(ApplicationId) as unique_app_ids dc(UserAgent) as unique_user_agents values(ApplicationId)
|
||||
values(OS) by _time user src_ip | where failed_attempts > 5 and unique_user_agents
|
||||
> 5 and unique_app_ids > 2 | `o365_multiple_appids_and_useragents_authentication_spike_filter`'
|
||||
search: '`o365_management_activity` Workload=AzureActiveDirectory (Operation=UserLoggedIn OR Operation=UserLoginFailed)
|
||||
| bucket span=5m _time
|
||||
| stats dc(_raw) as failed_attempts dc(ApplicationId) as unique_app_ids dc(UserAgent) as unique_user_agents values(ApplicationId) values(OS) values(signature) as signature by _time user src vendor_account vendor_product dest
|
||||
| where failed_attempts > 5 and unique_user_agents > 5 and unique_app_ids > 2
|
||||
| `o365_multiple_appids_and_useragents_authentication_spike_filter`'
|
||||
how_to_implement: You must install the Splunk Microsoft Office 365 Add-on and ingest
|
||||
Office 365 management activity events.
|
||||
known_false_positives: Rapid authentication from the same user using more than 5 different
|
||||
@@ -54,7 +54,7 @@ rba:
|
||||
type: user
|
||||
score: 48
|
||||
threat_objects:
|
||||
- field: src_ip
|
||||
- field: src
|
||||
type: ip_address
|
||||
tags:
|
||||
analytic_story:
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: O365 Multiple Failed MFA Requests For User
|
||||
id: fd22124e-dbac-4744-a8ce-be10d8ec3e26
|
||||
version: 5
|
||||
version: 6
|
||||
date: '2024-11-14'
|
||||
author: Mauricio Velazco, Splunk
|
||||
status: production
|
||||
@@ -16,10 +16,11 @@ description: The following analytic identifies potential "MFA fatigue" attacks t
|
||||
requests. If confirmed malicious, this could lead to data breaches, unauthorized
|
||||
data access, or further compromise within the O365 environment. Immediate investigation
|
||||
is crucial.
|
||||
search: '`o365_management_activity` Workload=AzureActiveDirectory Operation=UserLoginFailed
|
||||
ResultStatus=Success ErrorNumber=500121 | bucket span=10m _time | stats dc(_raw)
|
||||
as mfa_prompts values(LogonError) as LogonError values(signature) as signature by
|
||||
user, _time | where mfa_prompts > 9 | `o365_multiple_failed_mfa_requests_for_user_filter`'
|
||||
search: '`o365_management_activity` Workload=AzureActiveDirectory Operation=UserLoginFailed ResultStatus=Success ErrorNumber=500121
|
||||
| bucket span=10m _time
|
||||
| stats dc(_raw) as mfa_prompts values(LogonError) as LogonError values(signature) as signature values(action) as action values(src) as src by user _time vendor_account vendor_product dest
|
||||
| where mfa_prompts > 9
|
||||
| `o365_multiple_failed_mfa_requests_for_user_filter`'
|
||||
how_to_implement: You must install the Splunk Microsoft Office 365 Add-on and ingest
|
||||
Office 365 management activity events.
|
||||
known_false_positives: Multiple Failed MFA requests may also be a sign of authentication
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: O365 Multiple Mailboxes Accessed via API
|
||||
id: 7cd853e9-d370-412f-965d-a2bcff2a2908
|
||||
version: 5
|
||||
version: 6
|
||||
date: '2024-11-14'
|
||||
author: Mauricio Velazco, Splunk
|
||||
data_source:
|
||||
@@ -16,12 +16,14 @@ description: The following analytic detects when a high number of Office 365 Exc
|
||||
information, leading to data breaches and further exploitation of compromised accounts.
|
||||
The threshold is set to flag over five unique mailboxes accessed within 10 minutes,
|
||||
but should be tailored to your environment.
|
||||
search: '`o365_management_activity` Workload=Exchange Operation=MailItemsAccessed
|
||||
AppId=* ClientAppId=* | bucket span=10m _time | eval matchRegex=if(match(ClientInfoString,
|
||||
"^Client=WebServices;ExchangeWebServices"), 1, 0) | search (AppId="00000003-0000-0000-c000-000000000000"
|
||||
OR matchRegex=1) | stats values(ClientIPAddress) as src_ip dc(user) as unique_mailboxes
|
||||
values(user) as user by _time ClientAppId ClientInfoString | where unique_mailboxes
|
||||
> 5 | `o365_multiple_mailboxes_accessed_via_api_filter`'
|
||||
search: '`o365_management_activity` Workload=Exchange Operation=MailItemsAccessed AppId=* ClientAppId=*
|
||||
| bucket span=10m _time
|
||||
| eval matchRegex=if(match(ClientInfoString,"^Client=WebServices;ExchangeWebServices"), 1, 0)
|
||||
| search (AppId="00000003-0000-0000-c000-000000000000" OR matchRegex=1)
|
||||
| fillnull
|
||||
| stats values(ClientIPAddress) as src dc(user) as unique_mailboxes values(user) as user by _time ClientAppId ClientInfoString vendor_account vendor_product dest signature
|
||||
| where unique_mailboxes > 5
|
||||
| `o365_multiple_mailboxes_accessed_via_api_filter`'
|
||||
how_to_implement: You must install the Splunk Microsoft Office 365 Add-on and ingest
|
||||
Office 365 management activity events.
|
||||
known_false_positives: Legitimate applications may access multiple mailboxes via an
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: O365 Multiple OS Vendors Authenticating From User
|
||||
id: 3451e58a-9457-4985-a600-b616b0cbfda1
|
||||
version: 1
|
||||
version: 2
|
||||
date: '2024-12-19'
|
||||
author: Steven Dick
|
||||
status: production
|
||||
@@ -9,14 +9,15 @@ description: The following analytic identifies when multiple operating systems a
|
||||
data_source:
|
||||
- Office 365 Universal Audit Log
|
||||
search: |-
|
||||
`o365_management_activity` Operation IN (UserLoginFailed,UserLoggedIn)
|
||||
| eval -time = _time
|
||||
| bin _time span=15m
|
||||
| stats values(Operation) as signature, values(ErrorNumber) as signature_id, values(OS) as os_name, dc(OS) as os_count, count, min(-time) as firstTime, max(-time) as lastTime by ClientIP, UserId, _time
|
||||
| where os_count >= 4
|
||||
| eval src = ClientIP, user = UserId
|
||||
`o365_management_activity` Operation IN (UserLoginFailed,UserLoggedIn)
|
||||
| eval -time = _time
|
||||
| bin _time span=15m
|
||||
| fillnull
|
||||
| stats values(Operation) as signature, values(ErrorNumber) as signature_id, values(OS) as os_name, dc(OS) as os_count, count, min(-time) as firstTime, max(-time) as lastTime by ClientIP, UserId, _time, dest, vendor_account, vendor_product
|
||||
| where os_count >= 4
|
||||
| eval src = ClientIP, user = UserId
|
||||
| `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)`
|
||||
| `security_content_ctime(lastTime)`
|
||||
| `o365_multiple_os_vendors_authenticating_from_user_filter`
|
||||
how_to_implement: You must install the Splunk Microsoft Office 365 Add-on and ingest Office 365 management activity events. The thresholds set within the analytic (such as unique OS) are initial guidelines and should be customized based on the organization's user behavior and risk profile. Security teams are encouraged to adjust these thresholds to optimize the balance between detecting genuine threats and minimizing false positives, ensuring the detection is tailored to their specific environment.
|
||||
known_false_positives: IP or users where the usage of multiple Operating systems is expected, filter accordingly.
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: O365 Multiple Service Principals Created by SP
|
||||
id: ef4c3f20-d1ad-4ad1-a3f4-d5f391c005fe
|
||||
version: 4
|
||||
version: 5
|
||||
date: '2024-11-14'
|
||||
author: Mauricio Velazco, Splunk
|
||||
data_source:
|
||||
@@ -15,12 +15,18 @@ description: The following analytic identifies instances where a single service
|
||||
attempting to expand control or access within the network. If confirmed malicious,
|
||||
this could lead to unauthorized access and potential lateral movement within the
|
||||
environment, posing a significant security risk.
|
||||
search: "`o365_management_activity` Workload=AzureActiveDirectory Operation=\"Add
|
||||
service principal.\" | bucket span=10m _time | eval len=mvcount('Actor{}.ID') |
|
||||
eval userType = mvindex('Actor{}.ID',len-1) | search userType = \"ServicePrincipal\"\
|
||||
\ | eval displayName = object | stats count earliest(_time) as firstTime latest(_time)
|
||||
as lastTime values(displayName) as displayName dc(displayName) as unique_apps by
|
||||
src_user | where unique_apps > 3 | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
|
||||
search: "`o365_management_activity` Workload=AzureActiveDirectory Operation=\"Add service principal.\"
|
||||
| bucket span=10m _time
|
||||
| eval len=mvcount('Actor{}.ID')
|
||||
| eval userType = mvindex('Actor{}.ID',len-1)
|
||||
| search userType = \"ServicePrincipal\"
|
||||
| eval displayName = object
|
||||
| fillnull
|
||||
| stats count earliest(_time) as firstTime latest(_time) as lastTime values(displayName) as displayName dc(displayName) as unique_apps values(user) as user values(src) as src
|
||||
by src_user vendor_account vendor_product dest signature
|
||||
| where unique_apps > 3
|
||||
| `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)`
|
||||
| `o365_multiple_service_principals_created_by_sp_filter`"
|
||||
how_to_implement: You must install the Splunk Microsoft Office 365 Add-on and ingest
|
||||
Office 365 management activity events.
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: O365 Multiple Service Principals Created by User
|
||||
id: a34e65d0-54de-4b02-9db8-5a04522067f6
|
||||
version: 4
|
||||
version: 5
|
||||
date: '2024-11-14'
|
||||
author: Mauricio Velazco, Splunk
|
||||
data_source:
|
||||
@@ -15,12 +15,17 @@ description: The following analytic identifies instances where a single user cre
|
||||
potentially leading to broader network infiltration or privilege escalation. If
|
||||
confirmed malicious, this behavior could allow attackers to gain persistent access,
|
||||
escalate privileges, or exfiltrate sensitive information.
|
||||
search: "`o365_management_activity` Workload=AzureActiveDirectory Operation=\"Add
|
||||
service principal.\" | bucket span=10m _time | eval len=mvcount('Actor{}.ID') |
|
||||
eval userType = mvindex('Actor{}.ID',len-1) | search userType = \"User\" | eval
|
||||
displayName = object | stats count earliest(_time) as firstTime latest(_time) as
|
||||
lastTime values(displayName) as displayName dc(displayName) as unique_apps by src_user
|
||||
| where unique_apps > 3 | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
|
||||
search: "`o365_management_activity` Workload=AzureActiveDirectory Operation=\"Add service principal.\"
|
||||
| bucket span=10m _time
|
||||
| eval len=mvcount('Actor{}.ID')
|
||||
| eval userType = mvindex('Actor{}.ID',len-1)
|
||||
| search userType = \"User\"
|
||||
| eval displayName = object
|
||||
| stats count earliest(_time) as firstTime latest(_time) as lastTime values(displayName) as displayName dc(displayName) as unique_apps values(user) as user values(src) as src
|
||||
by src_user vendor_account vendor_product dest signature
|
||||
| where unique_apps > 3
|
||||
| `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)`
|
||||
| `o365_multiple_service_principals_created_by_user_filter`"
|
||||
how_to_implement: You must install the Splunk Microsoft Office 365 Add-on and ingest
|
||||
Office 365 management activity events.
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: O365 Multiple Users Failing To Authenticate From Ip
|
||||
id: 8d486e2e-3235-4cfe-ac35-0d042e24ecb4
|
||||
version: 7
|
||||
version: 8
|
||||
date: '2025-02-10'
|
||||
author: Mauricio Velazco, Splunk
|
||||
status: production
|
||||
@@ -16,10 +16,12 @@ description: The following analytic identifies instances where more than 10 uniq
|
||||
multiple accounts, potentially leading to unauthorized access. Immediate action
|
||||
is required to block or monitor the suspicious IP and notify affected users to enhance
|
||||
their security measures.
|
||||
search: '`o365_management_activity` Workload=AzureActiveDirectory Operation=UserLoginFailed
|
||||
ErrorNumber=50126 | bucket span=5m _time | stats dc(user) as unique_accounts values(user)
|
||||
as user values(LogonError) as LogonError values(signature) as signature values(UserAgent)
|
||||
as UserAgent by _time, src_ip | where unique_accounts > 10 | `o365_multiple_users_failing_to_authenticate_from_ip_filter`'
|
||||
search: '`o365_management_activity` Workload=AzureActiveDirectory Operation=UserLoginFailed ErrorNumber=50126
|
||||
| bucket span=5m _time
|
||||
| fillnull
|
||||
| stats dc(user) as unique_accounts values(user) as user values(LogonError) as LogonError values(signature) as signature values(UserAgent) as user_agent values(dest) as dest by _time src vendor_account vendor_product
|
||||
| where unique_accounts > 10
|
||||
| `o365_multiple_users_failing_to_authenticate_from_ip_filter`'
|
||||
how_to_implement: You must install the Splunk Microsoft Office 365 Add-on and ingest
|
||||
Office 365 management activity events.
|
||||
known_false_positives: A source Ip failing to authenticate with multiple users in
|
||||
@@ -44,13 +46,13 @@ drilldown_searches:
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
rba:
|
||||
message: Source Ip $src_ip$ failed to authenticate with 20 users within 5 minutes.
|
||||
message: Source Ip $src$ failed to authenticate with 20 users within 5 minutes.
|
||||
risk_objects:
|
||||
- field: user
|
||||
type: user
|
||||
score: 63
|
||||
threat_objects:
|
||||
- field: src_ip
|
||||
- field: src
|
||||
type: ip_address
|
||||
tags:
|
||||
analytic_story:
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: O365 New Email Forwarding Rule Created
|
||||
id: 68469fd0-1315-44ba-b7e4-e92847bb76d6
|
||||
version: 5
|
||||
version: 6
|
||||
date: '2025-02-10'
|
||||
author: Mauricio Velazco, Splunk
|
||||
data_source: []
|
||||
@@ -14,13 +14,17 @@ description: The following analytic identifies the creation of new email forward
|
||||
unauthorized access to sensitive information. If confirmed malicious, attackers
|
||||
could intercept and redirect emails, potentially compromising confidential communications
|
||||
and leading to data breaches.
|
||||
search: "`o365_management_activity` (Operation=New-InboxRule OR Operation=set-InboxRule)
|
||||
| eval match1=mvfind('Parameters{}.Name', \"ForwardTo\") | eval match2=mvfind('Parameters{}.Name',
|
||||
\"ForwardAsAttachmentTo\") | eval match3=mvfind('Parameters{}.Name', \"RedirectTo\"\
|
||||
) | where match1>= 0 OR match2>= 0 OR match3>= 0 | eval ForwardTo=coalesce(ForwardTo,
|
||||
ForwardAsAttachmentTo, RedirectTo) | stats count min(_time) as firstTime max(_time)
|
||||
as lastTime values(Name) as Name by user Operation ForwardTo | `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)` | `o365_new_email_forwarding_rule_created_filter`"
|
||||
search: "`o365_management_activity` (Operation=New-InboxRule OR Operation=set-InboxRule)
|
||||
| eval match1=mvfind('Parameters{}.Name', \"ForwardTo\")
|
||||
| eval match2=mvfind('Parameters{}.Name', \"ForwardAsAttachmentTo\")
|
||||
| eval match3=mvfind('Parameters{}.Name', \"RedirectTo\")
|
||||
| where match1>= 0 OR match2>= 0 OR match3>= 0
|
||||
| eval ForwardTo=coalesce(ForwardTo, ForwardAsAttachmentTo, RedirectTo)
|
||||
| fillnull
|
||||
| stats count min(_time) as firstTime max(_time) as lastTime values(Name) as Name by signature dest user src vendor_account vendor_product ForwardTo
|
||||
| `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)`
|
||||
| `o365_new_email_forwarding_rule_created_filter`"
|
||||
how_to_implement: You must install the Splunk Microsoft Office 365 Add-on and ingest
|
||||
Office 365 management activity events.
|
||||
known_false_positives: Users may create email forwarding rules for legitimate purposes.
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: O365 New Email Forwarding Rule Enabled
|
||||
id: ac7c4d0a-06a3-4278-aa59-88a5e537f981
|
||||
version: 5
|
||||
version: 6
|
||||
date: '2025-02-10'
|
||||
author: Mauricio Velazco, Splunk
|
||||
data_source: []
|
||||
@@ -13,17 +13,23 @@ description: The following analytic identifies the creation of new email forward
|
||||
This activity is significant as it may indicate unauthorized email redirection,
|
||||
potentially leading to data exfiltration. If confirmed malicious, attackers could
|
||||
intercept sensitive communications, leading to data breaches and information leakage.
|
||||
search: "`o365_management_activity` Workload=Exchange Operation=UpdateInboxRules \
|
||||
\ | eval match1=mvfind('OperationProperties{}.Value', \"ForwardToRecipientsAction\"\
|
||||
) | eval match2=mvfind('OperationProperties{}.Value', \"ForwardAsAttachmentToRecipientsAction\"\
|
||||
) | eval match3=mvfind('OperationProperties{}.Value', \"RedirectToRecipientsAction\"\
|
||||
) | eval index = mvfind('OperationProperties{}.Name', \"ServerRule\") | where match1>=
|
||||
0 OR match2>= 0 OR match3>= 0 | eval ServerRule = mvindex('OperationProperties{}.Value',
|
||||
index-1) | spath input=ServerRule path=Actions{}.Recipients{}.Values{}.Value output=valueExtracted
|
||||
| mvexpand valueExtracted | search valueExtracted=\"*@*.*\" | eval ForwardTo=if(match(valueExtracted,
|
||||
\"^[^@]+@[^@]+\\\\.[^@]+$\"), valueExtracted, null) | dedup ForwardTo | where isnotnull(ForwardTo)
|
||||
| stats count min(_time) as firstTime max(_time) as lastTime values(Name) as Name
|
||||
by user Operation ForwardTo | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
|
||||
search: "`o365_management_activity` Workload=Exchange Operation=UpdateInboxRules
|
||||
| eval match1=mvfind('OperationProperties{}.Value', \"ForwardToRecipientsAction\")
|
||||
| eval match2=mvfind('OperationProperties{}.Value', \"ForwardAsAttachmentToRecipientsAction\")
|
||||
| eval match3=mvfind('OperationProperties{}.Value', \"RedirectToRecipientsAction\")
|
||||
| eval index = mvfind('OperationProperties{}.Name', \"ServerRule\")
|
||||
| where match1>=0 OR match2>= 0 OR match3>= 0
|
||||
| eval ServerRule = mvindex('OperationProperties{}.Value',index-1)
|
||||
| spath input=ServerRule path=Actions{}.Recipients{}.Values{}.Value output=valueExtracted
|
||||
| mvexpand valueExtracted
|
||||
| search valueExtracted=\"*@*.*\"
|
||||
| eval ForwardTo=if(match(valueExtracted,\"^[^@]+@[^@]+\\\\.[^@]+$\"), valueExtracted, null)
|
||||
| dedup ForwardTo
|
||||
| where isnotnull(ForwardTo)
|
||||
| fillnull
|
||||
| stats count min(_time) as firstTime max(_time) as lastTime values(Name) as Name by signature dest user src vendor_account vendor_product ForwardTo
|
||||
| `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)`
|
||||
| `o365_new_email_forwarding_rule_enabled_filter`"
|
||||
how_to_implement: You must install the Splunk Microsoft Office 365 Add-on and ingest
|
||||
Office 365 management activity events.
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: O365 New Federated Domain Added
|
||||
id: e155876a-6048-11eb-ae93-0242ac130002
|
||||
version: 7
|
||||
version: 8
|
||||
date: '2025-02-10'
|
||||
author: Rod Soto, Mauricio Velazco Splunk
|
||||
status: production
|
||||
@@ -15,10 +15,13 @@ description: The following analytic identifies the addition of a new federated d
|
||||
to review the details of the added domain and any concurrent suspicious activities.
|
||||
data_source:
|
||||
- O365
|
||||
search: '`o365_management_activity` Operation IN ("*add*", "*new*") AND Operation="*domain*"
|
||||
| stats count values(ModifiedProperties{}.NewValue) as new_value by user user_agent
|
||||
authentication_service action Workload Operation | `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)` | `o365_new_federated_domain_added_filter`'
|
||||
search: '`o365_management_activity` Operation IN ("*add*", "*new*") AND Operation="*domain*"
|
||||
| eval src="NA"
|
||||
| fillnull
|
||||
| stats count values(ModifiedProperties{}.NewValue) as new_value by user user_agent authentication_service signature Workload src vendor_account vendor_product dest
|
||||
| `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)`
|
||||
| `o365_new_federated_domain_added_filter`'
|
||||
how_to_implement: You must install splunk Microsoft Office 365 add-on. This search
|
||||
works with o365:management:activity.
|
||||
known_false_positives: The creation of a new Federated domain is not necessarily malicious,
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: O365 New Forwarding Mailflow Rule Created
|
||||
id: 289ed0a1-4c78-4a43-9321-44ea2e089c14
|
||||
version: 4
|
||||
version: 5
|
||||
date: '2024-11-14'
|
||||
author: Mauricio Velazco, Splunk
|
||||
data_source: []
|
||||
@@ -13,14 +13,19 @@ description: The following analytic detects the creation of new mail flow rules
|
||||
This activity is significant as it can indicate potential data exfiltration or unauthorized
|
||||
access to sensitive information. If confirmed malicious, attackers could intercept
|
||||
or redirect email communications, leading to data breaches or information leakage.
|
||||
search: "`o365_management_activity` Workload=Exchange Operation=\"New-TransportRule\"\
|
||||
\ | eval match1=mvfind('Parameters{}.Name', \"BlindCopyTo\") | eval match2=mvfind('Parameters{}.Name',
|
||||
\"CopyTo\") | eval match3=mvfind('Parameters{}.Name', \"RedirectMessageTo\") | where
|
||||
match1>= 0 OR match2>= 0 OR match3>=0 | eval ForwardTo=coalesce(BlindCopyTo, CopyTo,
|
||||
RedirectMessageTo) | search ForwardTo!=\"\" | rename UserId as user | stats count
|
||||
earliest(_time) as firstTime latest(_time) as lastTime by Operation, user, Name,
|
||||
ForwardTo | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`\
|
||||
\ | `o365_new_forwarding_mailflow_rule_created_filter`"
|
||||
search: "`o365_management_activity` Workload=Exchange Operation=\"New-TransportRule\"
|
||||
| eval match1=mvfind('Parameters{}.Name',\"BlindCopyTo\")
|
||||
| eval match2=mvfind('Parameters{}.Name',\"CopyTo\")
|
||||
| eval match3=mvfind('Parameters{}.Name', \"RedirectMessageTo\")
|
||||
| where match1>= 0 OR match2>= 0 OR match3>=0
|
||||
| eval ForwardTo=coalesce(BlindCopyTo, CopyTo, RedirectMessageTo)
|
||||
| search ForwardTo!=\"\"
|
||||
| rename UserId as user
|
||||
| fillnull
|
||||
| stats count earliest(_time) as firstTime latest(_time) as lastTime by user, Name, ForwardTo, vendor_account, vendor_product, dest, signature
|
||||
| `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)`
|
||||
| `o365_new_forwarding_mailflow_rule_created_filter`"
|
||||
how_to_implement: You must install the Splunk Microsoft Office 365 Add-on and ingest
|
||||
Office 365 management activity events.
|
||||
known_false_positives: Forwarding mail flow rules may be created for legitimate reasons,
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: O365 New MFA Method Registered
|
||||
id: 4e12db1f-f7c7-486d-8152-a221cad6ac2b
|
||||
version: 5
|
||||
version: 6
|
||||
date: '2025-02-10'
|
||||
author: Mauricio Velazco, Splunk
|
||||
status: production
|
||||
@@ -14,16 +14,21 @@ description: The following analytic detects the registration of a new Multi-Fact
|
||||
account. If confirmed malicious, the attacker could bypass existing security measures,
|
||||
solidify their access, and potentially escalate privileges or access sensitive data.
|
||||
Immediate verification and remediation are required to secure the affected account.
|
||||
search: "`o365_management_activity` Workload=AzureActiveDirectory Operation=\"Update
|
||||
user.\" | eval propertyName = mvindex('ModifiedProperties{}.Name', 0) | search
|
||||
propertyName = StrongAuthenticationMethod | eval oldvalue = mvindex('ModifiedProperties{}.OldValue',0)
|
||||
| eval newvalue = mvindex('ModifiedProperties{}.NewValue',0) | rex field=newvalue
|
||||
max_match=0 \"(?i)(?<new_method_type>\\\"MethodType\\\")\" | rex field=oldvalue
|
||||
max_match=0 \"(?i)(?<old_method_type>\\\"MethodType\\\")\" | eval count_new_method_type
|
||||
= coalesce(mvcount(new_method_type), 0) | eval count_old_method_type = coalesce(mvcount(old_method_type),
|
||||
0) | where count_new_method_type > count_old_method_type | stats earliest(_time)
|
||||
as firstTime latest(_time) as lastTime values(propertyName) by user newvalue oldvalue
|
||||
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `o365_new_mfa_method_registered_filter`"
|
||||
search: "`o365_management_activity` Workload=AzureActiveDirectory Operation=\"Update user.\"
|
||||
| eval propertyName = mvindex('ModifiedProperties{}.Name', 0)
|
||||
| search propertyName = StrongAuthenticationMethod
|
||||
| eval oldvalue = mvindex('ModifiedProperties{}.OldValue',0)
|
||||
| eval newvalue = mvindex('ModifiedProperties{}.NewValue',0)
|
||||
| rex field=newvalue max_match=0 \"(?i)(?<new_method_type>\\\"MethodType\\\")\"
|
||||
| rex field=oldvalue max_match=0 \"(?i)(?<old_method_type>\\\"MethodType\\\")\"
|
||||
| eval count_new_method_type = coalesce(mvcount(new_method_type), 0)
|
||||
| eval count_old_method_type = coalesce(mvcount(old_method_type), 0)
|
||||
| where count_new_method_type > count_old_method_type
|
||||
| fillnull
|
||||
| stats earliest(_time) as firstTime latest(_time) as lastTime values(propertyName) by user newvalue oldvalue vendor_account vendor_product dest signature src
|
||||
| `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)`
|
||||
| `o365_new_mfa_method_registered_filter`"
|
||||
how_to_implement: You must install the Splunk Microsoft Office 365 Add-on and ingest
|
||||
Office 365 management activity events.
|
||||
known_false_positives: Users may register MFA methods legitimally, investigate and
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: O365 OAuth App Mailbox Access via EWS
|
||||
id: e600cf1a-0bef-4426-b42e-00176d610a4d
|
||||
version: 5
|
||||
version: 6
|
||||
date: '2024-11-14'
|
||||
author: Mauricio Velazco, Splunk
|
||||
status: production
|
||||
@@ -15,11 +15,13 @@ description: The following analytic detects when emails are accessed in Office 3
|
||||
emails through EWS is crucial for identifying potential abuse or unauthorized data
|
||||
access. If confirmed malicious, this activity could lead to unauthorized email access,
|
||||
data exfiltration, or further compromise of sensitive information.
|
||||
search: '`o365_management_activity` Workload=Exchange Operation=MailItemsAccessed
|
||||
AppId=* ClientAppId=* | regex ClientInfoString="^Client=WebServices;ExchangeWebServices"
|
||||
| stats count earliest(_time) as firstTime latest(_time) as lastTime values(ClientIPAddress)
|
||||
as src_ip by user ClientAppId OperationCount AppId ClientInfoString | `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)` | `o365_oauth_app_mailbox_access_via_ews_filter`'
|
||||
search: '`o365_management_activity` Workload=Exchange Operation=MailItemsAccessed AppId=* ClientAppId=*
|
||||
| regex ClientInfoString="^Client=WebServices;ExchangeWebServices"
|
||||
| fillnull
|
||||
| stats count earliest(_time) as firstTime latest(_time) as lastTime values(ClientIPAddress) as src by user ClientAppId OperationCount AppId vendor_account vendor_product dest signature ClientInfoString
|
||||
| `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)`
|
||||
| `o365_oauth_app_mailbox_access_via_ews_filter`'
|
||||
how_to_implement: You must install the Splunk Microsoft Office 365 Add-on and ingest
|
||||
Office 365 management activity events.
|
||||
known_false_positives: OAuth applications may access mailboxes for legitimate purposes,
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: O365 OAuth App Mailbox Access via Graph API
|
||||
id: 9db0d5b0-4058-4cb7-baaf-77d8143539a2
|
||||
version: 5
|
||||
version: 6
|
||||
date: '2024-11-14'
|
||||
author: Mauricio Velazco, Splunk
|
||||
status: production
|
||||
@@ -13,11 +13,12 @@ description: The following analytic detects when emails are accessed in Office 3
|
||||
on OAuth-authenticated applications. This activity is significant as unauthorized
|
||||
access to emails can lead to data breaches and information theft. If confirmed malicious,
|
||||
attackers could exfiltrate sensitive information, compromise user accounts, and
|
||||
further infiltrate the organization’s network.
|
||||
search: '`o365_management_activity` Workload=Exchange Operation=MailItemsAccessed
|
||||
AppId=* AppId=00000003-0000-0000-c000-000000000000 | stats count earliest(_time)
|
||||
as firstTime latest(_time) as lastTime values(ClientIPAddress) by user ClientAppId
|
||||
OperationCount AppId | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
|
||||
further infiltrate the organization's network.
|
||||
search: '`o365_management_activity` Workload=Exchange Operation=MailItemsAccessed AppId=* AppId=00000003-0000-0000-c000-000000000000
|
||||
| fillnull
|
||||
| stats count earliest(_time) as firstTime latest(_time) as lastTime values(ClientIPAddress) as src by user ClientAppId OperationCount AppId vendor_account vendor_product dest signature
|
||||
| `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)`
|
||||
| `o365_oauth_app_mailbox_access_via_graph_api_filter`'
|
||||
how_to_implement: You must install the Splunk Microsoft Office 365 Add-on and ingest
|
||||
Office 365 management activity events.
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: O365 Privileged Graph API Permission Assigned
|
||||
id: 868f3131-d5e1-4bf1-af5b-9b0fbaaaedbb
|
||||
version: 4
|
||||
version: 5
|
||||
date: '2024-11-14'
|
||||
author: Mauricio Velazco, Splunk
|
||||
status: production
|
||||
@@ -15,14 +15,15 @@ description: The following analytic detects the assignment of critical Graph API
|
||||
provide extensive control over Azure AD settings, posing a high risk if misused.
|
||||
If confirmed malicious, this could allow unauthorized modifications, leading to
|
||||
potential data breaches or privilege escalation. Immediate investigation is crucial.
|
||||
search: "`o365_management_activity` Workload=AzureActiveDirectory Operation=\"Update
|
||||
application.\" | eval newvalue = mvindex('ModifiedProperties{}.NewValue',0) | spath
|
||||
input=newvalue | search \"{}.RequiredAppPermissions{}.EntitlementId\"=\"1bfefb4e-e0b5-418b-a88f-73c46d2cc8e9\"\
|
||||
\ OR \"{}.RequiredAppPermissions{}.EntitlementId\"=\"06b708a9-e830-4db3-a914-8e69da51d44f\"\
|
||||
\ OR \"{}.RequiredAppPermissions{}.EntitlementId\"=\"9e3f62cf-ca93-4989-b6ce-bf83c28f9fe8\"\
|
||||
\ | eval Permissions = '{}.RequiredAppPermissions{}.EntitlementId' | stats count
|
||||
earliest(_time) as firstTime latest(_time) as lastTime values(Permissions) by user,
|
||||
object, user_agent, Operation | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
|
||||
search: "`o365_management_activity` Workload=AzureActiveDirectory Operation=\"Update application.\"
|
||||
| eval newvalue = mvindex('ModifiedProperties{}.NewValue',0)
|
||||
| spath input=newvalue
|
||||
| search \"{}.RequiredAppPermissions{}.EntitlementId\"=\"1bfefb4e-e0b5-418b-a88f-73c46d2cc8e9\" OR \"{}.RequiredAppPermissions{}.EntitlementId\"=\"06b708a9-e830-4db3-a914-8e69da51d44f\" OR \"{}.RequiredAppPermissions{}.EntitlementId\"=\"9e3f62cf-ca93-4989-b6ce-bf83c28f9fe8\"
|
||||
| eval Permissions = '{}.RequiredAppPermissions{}.EntitlementId'
|
||||
| fillnull
|
||||
| stats count earliest(_time) as firstTime latest(_time) as lastTime values(Permissions) by user src object user_agent signature vendor_account vendor_product dest
|
||||
| `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)`
|
||||
| `o365_privileged_graph_api_permission_assigned_filter`"
|
||||
how_to_implement: You must install the Splunk Microsoft Office 365 Add-on and ingest
|
||||
Office 365 management activity events.
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: O365 Privileged Role Assigned
|
||||
id: db435700-4ddc-4c23-892e-49e7525d7d39
|
||||
version: 5
|
||||
version: 6
|
||||
date: '2025-02-10'
|
||||
author: Steven Dick
|
||||
status: production
|
||||
@@ -11,18 +11,15 @@ description: The following analytic identifies the assignment of sensitive and p
|
||||
AD environment. This detection leverages the O365 Universal Audit Log data source.
|
||||
data_source:
|
||||
- Office 365 Universal Audit Log
|
||||
search: "`o365_management_activity` Workload=AzureActiveDirectory Operation IN (\"\
|
||||
Add member to role.\",\"Add eligible member to role.\") | eval user = ObjectId,
|
||||
src_user = case(match(mvindex('Actor{}.ID',-1),\"User\"),mvindex('Actor{}.ID',0),match(mvindex('Actor{}.ID',-1),\"\
|
||||
ServicePrincipal\"),mvindex('Actor{}.ID',3),true(),mvindex('Actor{}.ID',0)), object_name
|
||||
= mvindex('ModifiedProperties{}.NewValue', mvfind('ModifiedProperties{}.Name',\"\
|
||||
Role\\.DisplayName\")), object_id = mvindex('ModifiedProperties{}.NewValue', mvfind('ModifiedProperties{}.Name',\"\
|
||||
Role\\.TemplateId\")), signature = Operation, result = ResultStatus, category =
|
||||
mvindex('Target{}.ID',2) | stats count, min(_time) as firstTime, max(_time) as lastTime
|
||||
by src_user, user, category, result, object_name, object_id, signature | lookup
|
||||
privileged_azure_ad_roles azuretemplateid as object_id OUTPUT isprvilegedadrole
|
||||
| search isprvilegedadrole=\"TRUE\" category=\"User\" | `security_content_ctime(firstTime)`\
|
||||
\ | `security_content_ctime(lastTime)` | `o365_privileged_role_assigned_filter`"
|
||||
search: "`o365_management_activity` Workload=AzureActiveDirectory Operation IN (\"Add member to role.\",\"Add eligible member to role.\")
|
||||
| eval user = ObjectId, src_user = case(match(mvindex('Actor{}.ID',-1),\"User\"),mvindex('Actor{}.ID',0),match(mvindex('Actor{}.ID',-1),\"ServicePrincipal\"),mvindex('Actor{}.ID',3),true(),mvindex('Actor{}.ID',0)), object_name = mvindex('ModifiedProperties{}.NewValue', mvfind('ModifiedProperties{}.Name',\"Role\\.DisplayName\")), object_id = mvindex('ModifiedProperties{}.NewValue', mvfind('ModifiedProperties{}.Name',\"Role\\.TemplateId\")), signature = Operation, result = ResultStatus, category = mvindex('Target{}.ID',2)
|
||||
| fillnull
|
||||
| stats count, min(_time) as firstTime, max(_time) as lastTime by src_user, src, user, category, result, object_name, object_id, signature, vendor_account, vendor_product, dest
|
||||
| lookup privileged_azure_ad_roles azuretemplateid as object_id OUTPUT isprvilegedadrole
|
||||
| search isprvilegedadrole=\"TRUE\" category=\"User\"
|
||||
| `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)`
|
||||
| `o365_privileged_role_assigned_filter`"
|
||||
how_to_implement: You must install the Splunk Microsoft Office 365 Add-on and ingest
|
||||
Office 365 management activity events.
|
||||
known_false_positives: Administrators will legitimately assign the privileged roles
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: O365 Privileged Role Assigned To Service Principal
|
||||
id: 80f3fc1b-705f-4080-bf08-f61bf013b900
|
||||
version: 5
|
||||
version: 6
|
||||
date: '2025-02-10'
|
||||
author: Steven Dick
|
||||
status: production
|
||||
@@ -15,18 +15,15 @@ description: The following analytic detects potential privilege escalation threa
|
||||
source.
|
||||
data_source:
|
||||
- Office 365 Universal Audit Log
|
||||
search: "`o365_management_activity` Workload=AzureActiveDirectory Operation IN (\"\
|
||||
Add member to role.\",\"Add eligible member to role.\") | eval user = ObjectId,
|
||||
src_user = case(match(mvindex('Actor{}.ID',-1),\"User\"),mvindex('Actor{}.ID',0),match(mvindex('Actor{}.ID',-1),\"\
|
||||
ServicePrincipal\"),mvindex('Actor{}.ID',3),true(),mvindex('Actor{}.ID',0)), object_name
|
||||
= mvindex('ModifiedProperties{}.NewValue', mvfind('ModifiedProperties{}.Name',\"\
|
||||
Role\\.DisplayName\")), object_id = mvindex('ModifiedProperties{}.NewValue', mvfind('ModifiedProperties{}.Name',\"\
|
||||
Role\\.TemplateId\")), signature = Operation, result = ResultStatus, category =
|
||||
mvindex('Target{}.ID',2) | stats count, min(_time) as firstTime, max(_time) as lastTime
|
||||
by src_user, user, category, result, object_name, object_id, signature | lookup
|
||||
privileged_azure_ad_roles azuretemplateid as object_id OUTPUT isprvilegedadrole
|
||||
| search isprvilegedadrole=\"TRUE\" category!=\"User\" | `security_content_ctime(firstTime)`\
|
||||
\ | `security_content_ctime(lastTime)` | `o365_privileged_role_assigned_to_service_principal_filter`"
|
||||
search: "`o365_management_activity` Workload=AzureActiveDirectory Operation IN (\"Add member to role.\",\"Add eligible member to role.\")
|
||||
| eval user = ObjectId, src_user = case(match(mvindex('Actor{}.ID',-1),\"User\"),mvindex('Actor{}.ID',0),match(mvindex('Actor{}.ID',-1),\"ServicePrincipal\"),mvindex('Actor{}.ID',3),true(),mvindex('Actor{}.ID',0)), object_name = mvindex('ModifiedProperties{}.NewValue', mvfind('ModifiedProperties{}.Name',\"Role\\.DisplayName\")), object_id = mvindex('ModifiedProperties{}.NewValue', mvfind('ModifiedProperties{}.Name',\"Role\\.TemplateId\")), signature = Operation, result = ResultStatus, category = mvindex('Target{}.ID',2)
|
||||
| fillnull
|
||||
| stats count, min(_time) as firstTime, max(_time) as lastTime by src_user, src, user, category, result, object_name, object_id, signature,vendor_account, vendor_product, dest
|
||||
| lookup privileged_azure_ad_roles azuretemplateid as object_id OUTPUT isprvilegedadrole
|
||||
| search isprvilegedadrole=\"TRUE\" category!=\"User\"
|
||||
| `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)`
|
||||
| `o365_privileged_role_assigned_to_service_principal_filter`"
|
||||
how_to_implement: You must install the Splunk Microsoft Office 365 Add-on and ingest
|
||||
Office 365 management activity events.
|
||||
known_false_positives: Administrators may legitimately assign the privileged roles
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: O365 PST export alert
|
||||
id: 5f694cc4-a678-4a60-9410-bffca1b647dc
|
||||
version: 5
|
||||
version: 6
|
||||
date: '2024-11-14'
|
||||
author: Rod Soto, Splunk
|
||||
status: production
|
||||
@@ -16,10 +16,12 @@ description: The following analytic detects instances where a user has initiated
|
||||
Immediate investigation is required.
|
||||
data_source:
|
||||
- O365
|
||||
search: '`o365_management_activity` Category=ThreatManagement Name="eDiscovery search
|
||||
started or exported" | stats count earliest(_time) as firstTime latest(_time) as
|
||||
lastTime by Source Severity AlertEntityId Operation Name |`security_content_ctime(firstTime)`
|
||||
|`security_content_ctime(lastTime)` | `o365_pst_export_alert_filter`'
|
||||
search: '`o365_management_activity` Category=ThreatManagement Name="eDiscovery search started or exported"
|
||||
| fillnull
|
||||
| stats count earliest(_time) as firstTime latest(_time) as lastTime by Source Severity AlertEntityId Name user src vendor_account vendor_product dest signature
|
||||
| `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)`
|
||||
| `o365_pst_export_alert_filter`'
|
||||
how_to_implement: You must install splunk Microsoft Office 365 add-on. This search
|
||||
works with o365:management:activity
|
||||
known_false_positives: PST export can be done for legitimate purposes but due to the
|
||||
@@ -27,12 +29,12 @@ known_false_positives: PST export can be done for legitimate purposes but due to
|
||||
references:
|
||||
- https://attack.mitre.org/techniques/T1114/
|
||||
drilldown_searches:
|
||||
- name: View the detection results for - "$Source$"
|
||||
search: '%original_detection_search% | search Source = "$Source$"'
|
||||
- name: View the detection results for - "$user$"
|
||||
search: '%original_detection_search% | search user = "$user$"'
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
- name: View risk events for the last 7 days for - "$Source$"
|
||||
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$Source$")
|
||||
- name: View risk events for the last 7 days for - "$user$"
|
||||
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$")
|
||||
starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime
|
||||
values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories)
|
||||
as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic)
|
||||
@@ -41,10 +43,10 @@ drilldown_searches:
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
rba:
|
||||
message: User $Source$ has exported a PST file from the search using this operation-
|
||||
$Operation$ with a severity of $Severity$
|
||||
message: User $user$ has exported a PST file from the search using this operation-
|
||||
$signature$ with a severity of $Severity$
|
||||
risk_objects:
|
||||
- field: Source
|
||||
- field: user
|
||||
type: user
|
||||
score: 48
|
||||
threat_objects: []
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: O365 Safe Links Detection
|
||||
id: 711d9e8c-2cb0-45cf-8813-5f191ecb9b26
|
||||
version: 5
|
||||
date: '2025-02-10'
|
||||
version: 6
|
||||
date: '2025-03-25'
|
||||
author: Steven Dick
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -11,11 +11,12 @@ description: The following analytic detects when any Microsoft Safe Links alerti
|
||||
data_source:
|
||||
- Office 365 Universal Audit Log
|
||||
search: '`o365_management_activity` Name="*a potentially malicious URL*" Operation=AlertEntityGenerated
|
||||
| fromjson Data | stats count min(_time) as firstTime max(_time) as lastTime values(ObjectId)
|
||||
as url values(od) as desc by AlertId,trc,Operation,Name,ot | rename Name as signature,
|
||||
AlertId as signature_id, trc as user,ot as action | eval action = CASE(action ==
|
||||
"Allowed", "allowed", action=="BlockPageOverride", "allowed", true(),"blocked")
|
||||
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `o365_safe_links_detection_filter`'
|
||||
| fromjson Data | fillnull | stats count min(_time) as firstTime max(_time) as lastTime
|
||||
values(ObjectId) as url values(od) as desc by AlertId, trc, Name, ot, dest, vendor_account,
|
||||
vendor_product, src | rename Name as signature, AlertId as signature_id, trc as
|
||||
user, ot as action | eval action = CASE(action == "Allowed", "allowed", action=="BlockPageOverride",
|
||||
"allowed", true(),"blocked") | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
|
||||
| `o365_safe_links_detection_filter`'
|
||||
how_to_implement: You must install the Splunk Microsoft Office 365 Add-on and ingest
|
||||
Office 365 management activity events. The Safe Links capability must be configured
|
||||
and is typically only available to E3/E5 level customers.
|
||||
@@ -43,9 +44,7 @@ rba:
|
||||
- field: user
|
||||
type: user
|
||||
score: 40
|
||||
threat_objects:
|
||||
- field: url
|
||||
type: url
|
||||
threat_objects: []
|
||||
tags:
|
||||
analytic_story:
|
||||
- Office 365 Account Takeover
|
||||
@@ -61,7 +60,6 @@ tags:
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- data:
|
||||
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566/o365_various_alerts/o365_various_alerts.log
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566/o365_various_alerts/o365_various_alerts.log
|
||||
sourcetype: o365:management:activity
|
||||
source: o365
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: O365 Security And Compliance Alert Triggered
|
||||
id: 5b367cdd-8dfc-49ac-a9b7-6406cf27f33e
|
||||
version: 6
|
||||
version: 7
|
||||
date: '2025-02-10'
|
||||
author: Mauricio Velazco, Splunk
|
||||
data_source: []
|
||||
@@ -15,14 +15,19 @@ description: The following analytic identifies alerts triggered by the Office 36
|
||||
If confirmed malicious, these alerts could indicate attempts to breach security
|
||||
policies, leading to unauthorized access, data exfiltration, or other malicious
|
||||
activities.
|
||||
search: '`o365_management_activity` Workload=SecurityComplianceCenter Category=ThreatManagement
|
||||
Operation=AlertTriggered | spath input=Data path=f3u output=user | spath input=Data
|
||||
path=op output=operation | spath input=_raw path=wl | spath input=Data path=rid
|
||||
output=rule_id | spath input=Data path=ad output=alert_description | spath input=Data
|
||||
path=lon output=operation_name | spath input=Data path=an output=alert_name | spath
|
||||
input=Data path=sev output=severity | stats count earliest(_time) as firstTime
|
||||
latest(_time) as lastTime by user, Name, operation, rule_id, alert_description,
|
||||
alert_name, severity | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
|
||||
search: '`o365_management_activity` Workload=SecurityComplianceCenter Category=ThreatManagement Operation=AlertTriggered
|
||||
| spath input=Data path=f3u output=user
|
||||
| spath input=Data path=op output=operation
|
||||
| spath input=_raw path=wl
|
||||
| spath input=Data path=rid output=rule_id
|
||||
| spath input=Data path=ad output=alert_description
|
||||
| spath input=Data path=lon output=operation_name
|
||||
| spath input=Data path=an output=alert_name
|
||||
| spath input=Data path=sev output=severity
|
||||
| fillnull
|
||||
| stats count earliest(_time) as firstTime latest(_time) as lastTime by user, Name, rule_id, alert_description, alert_name, severity, dest, src, vendor_account, vendor_product, signature
|
||||
| `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)`
|
||||
| `o365_security_and_compliance_alert_triggered_filter`'
|
||||
how_to_implement: You must install the Splunk Microsoft Office 365 Add-on and ingest
|
||||
Office 365 management activity events.
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: O365 Service Principal New Client Credentials
|
||||
id: a1b229e9-d962-4222-8c62-905a8a010453
|
||||
version: 7
|
||||
version: 8
|
||||
date: '2025-02-10'
|
||||
author: Mauricio Velazco, Splunk
|
||||
status: production
|
||||
@@ -15,10 +15,12 @@ description: The following analytic detects the addition of new credentials for
|
||||
operations under the application's identity.
|
||||
data_source:
|
||||
- O365
|
||||
search: '`o365_management_activity` Workload=AzureActiveDirectory Operation="Update
|
||||
application*Certificates and secrets management " | stats earliest(_time) as firstTime
|
||||
latest(_time) as lastTime by user ModifiedProperties{}.NewValue object ObjectId
|
||||
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `o365_service_principal_new_client_credentials_filter`'
|
||||
search: '`o365_management_activity` Workload=AzureActiveDirectory Operation="Update application*Certificates and secrets management "
|
||||
| fillnull
|
||||
| stats earliest(_time) as firstTime latest(_time) as lastTime by user ModifiedProperties{}.NewValue object ObjectId dest signature src vendor_account vendor_product
|
||||
| `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)`
|
||||
| `o365_service_principal_new_client_credentials_filter`'
|
||||
how_to_implement: You must install the Splunk Microsoft Office 365 Add-on and ingest
|
||||
Office 365 management activity events.
|
||||
known_false_positives: Service Principal client credential modifications may be part
|
||||
|
||||
@@ -1,28 +1,25 @@
|
||||
name: O365 Service Principal Privilege Escalation
|
||||
id: b686d0bd-cca7-44ca-ae07-87f6465131d9
|
||||
version: 2
|
||||
version: 3
|
||||
date: '2025-02-10'
|
||||
author: Dean Luxton
|
||||
data_source:
|
||||
- O365 Add app role assignment grant to user.
|
||||
type: TTP
|
||||
status: production
|
||||
description: This detection identifies when an Azure Service Principal elevates privileges
|
||||
by adding themself to a new app role assignment.
|
||||
search: >-
|
||||
`o365_management_activity` Operation="Add app role assignment to service principal."
|
||||
"Actor{}.ID"=ServicePrincipal ResultStatus=Success
|
||||
| spath path=ModifiedProperties{} output=targetResources
|
||||
| stats min(_time) as _time values(eval(mvfilter(match(targetResources, "AppRole.Value"))))
|
||||
as appRole, values(eval(mvfilter(match(targetResources, "ServicePrincipal.DisplayName"))))
|
||||
as targetServicePrincipal values(object) as targetAppContext values(user_agent)
|
||||
as user_agent values(user) as servicePrincipal values(UserId) as servicePrincipalId by
|
||||
Operation InterSystemsId tenant_id
|
||||
| spath input=appRole path=NewValue output=appRole
|
||||
| spath input=targetServicePrincipal path=NewValue output=targetServicePrincipal
|
||||
| where servicePrincipal=targetServicePrincipal
|
||||
| table _time Operation servicePrincipal servicePrincipalId appRole targetAppContext
|
||||
user_agent tenant_id InterSystemsId
|
||||
description: This detection identifies when an Azure Service Principal elevates privileges by adding themself to a new app role assignment.
|
||||
search: >-
|
||||
`o365_management_activity` Operation="Add app role assignment to service principal." "Actor{}.ID"=ServicePrincipal ResultStatus=Success
|
||||
| spath path=ModifiedProperties{} output=targetResources
|
||||
| eval src="NA"
|
||||
| stats min(_time) as _time values(eval(mvfilter(match(targetResources, "AppRole.Value")))) as appRole, values(eval(mvfilter(match(targetResources, "ServicePrincipal.DisplayName")))) as targetServicePrincipal values(object) as targetAppContext values(user_agent) as user_agent values(user) as servicePrincipal values(UserId) as servicePrincipalId by Operation InterSystemsId tenant_id user dest src vendor_account vendor_product signature
|
||||
| spath input=appRole path=NewValue output=appRole
|
||||
| spath input=targetServicePrincipal path=NewValue output=targetServicePrincipal
|
||||
| where servicePrincipal=targetServicePrincipal
|
||||
| fillnull
|
||||
| stats earliest(_time) as firstTime latest(_time) as lastTime by servicePrincipal servicePrincipalId appRole targetAppContext user_agent tenant_id InterSystemsId user dest src vendor_account vendor_product signature
|
||||
| `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)`
|
||||
| `o365_service_principal_privilege_escalation_filter`
|
||||
how_to_implement: The Splunk Add-on for Microsoft Office 365 add-on is required to
|
||||
ingest EntraID audit logs via the 365 API. See references for links for further
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: O365 SharePoint Allowed Domains Policy Changed
|
||||
id: b0cc6fa8-39b1-49ac-a4fe-f2f2a668e06c
|
||||
version: 6
|
||||
date: '2024-11-14'
|
||||
version: 7
|
||||
date: '2025-03-25'
|
||||
author: Steven Dick
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -13,19 +13,19 @@ description: The following analytic identifies when the allowed domain settings
|
||||
access.
|
||||
data_source:
|
||||
- Office 365 Universal Audit Log
|
||||
search: "`o365_management_activity` Workload=SharePoint Operation=SharingPolicyChanged
|
||||
\"ModifiedProperties{}.Name\"=AllowDomainList | eval signature_id = CorrelationId,
|
||||
signature=Operation, src = ClientIP, user = UserId, object_name='ModifiedProperties{}.Name',
|
||||
object_attrs_new = split(replace('ModifiedProperties{}.NewValue',\"\\.\\.\\.\",\"\
|
||||
\"),\",\"), object_attrs_old = split(replace('ModifiedProperties{}.OldValue',\"\\\
|
||||
.\\.\\.\",\"\"),\",\") | stats values(object_attrs_new) as object_attrs_new, values(object_attrs_old)
|
||||
search: '`o365_management_activity` Workload=SharePoint Operation=SharingPolicyChanged
|
||||
"ModifiedProperties{}.Name"=AllowDomainList | eval signature_id = CorrelationId,
|
||||
signature=Operation, src = ClientIP, user = UserId, object_name=''ModifiedProperties{}.Name'',
|
||||
object_attrs_new = split(replace(''ModifiedProperties{}.NewValue'',"\.\.\.",""),","),
|
||||
object_attrs_old = split(replace(''ModifiedProperties{}.OldValue'',"\.\.\.",""),",")
|
||||
| fillnull | stats values(object_attrs_new) as object_attrs_new, values(object_attrs_old)
|
||||
as object_attrs_old, values(src) as src, count, min(_time) as firstTime, max(_time)
|
||||
as lastTime by user,signature,signature_id,object_name | eval diff_add=mvmap(object_attrs_new,if(isnull(mvfind(object_attrs_old,object_attrs_new)),object_attrs_new,null))
|
||||
as lastTime by user,signature,signature_id,object_name,dest,action,vendor_account,vendor_product
|
||||
| eval diff_add=mvmap(object_attrs_new,if(isnull(mvfind(object_attrs_old,object_attrs_new)),object_attrs_new,null))
|
||||
| eval diff_remove=mvmap(object_attrs_old,if(isnull(mvfind(object_attrs_new,object_attrs_old)),object_attrs_old,null))
|
||||
| eval result = case(isnotnull(diff_add),\"Added \".mvjoin(diff_add,\",\"),isnotnull(diff_remove),\"\
|
||||
Removed \".mvjoin(diff_remove,\",\")), action = case(isnotnull(diff_add),\"created\"\
|
||||
,isnotnull(diff_remove),\"deleted\") | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
|
||||
| `o365_sharepoint_allowed_domains_policy_changed_filter`"
|
||||
| eval result = case(isnotnull(diff_add),"Added ".mvjoin(diff_add,","),isnotnull(diff_remove),"Removed
|
||||
".mvjoin(diff_remove,",")), action = case(isnotnull(diff_add),"created",isnotnull(diff_remove),"deleted")
|
||||
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `o365_sharepoint_allowed_domains_policy_changed_filter`'
|
||||
how_to_implement: You must install the Splunk Microsoft Office 365 Add-on and ingest
|
||||
Office 365 management activity events.
|
||||
known_false_positives: Business approved changes by known administrators.
|
||||
@@ -66,7 +66,6 @@ tags:
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- data:
|
||||
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566/o365_various_alerts/o365_various_alerts.log
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566/o365_various_alerts/o365_various_alerts.log
|
||||
sourcetype: o365:management:activity
|
||||
source: o365
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: O365 SharePoint Malware Detection
|
||||
id: 583c5de3-7709-44cb-abfc-0e828d301b59
|
||||
version: 5
|
||||
date: '2025-02-10'
|
||||
version: 6
|
||||
date: '2025-03-25'
|
||||
author: Steven Dick
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -12,11 +12,12 @@ description: The following analytic identifies when a malicious file is detected
|
||||
Office 365 capabilities further enhance these detection and response functions.
|
||||
data_source:
|
||||
- Office 365 Universal Audit Log
|
||||
search: '`o365_management_activity` Operation=FileMalwareDetected | stats values(Workload)
|
||||
as category, values(SourceFileName) as file_name values(ObjectId) as file_path,
|
||||
values(VirusInfo) as signature, count, min(_time) as firstTime, max(_time) as lastTime
|
||||
by Id, UserId | rename Id as signature_id, UserId as user | `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)` | `o365_sharepoint_malware_detection_filter`'
|
||||
search: '`o365_management_activity` Operation=FileMalwareDetected | rename UserId
|
||||
as user, Id as signature_id | stats values(Workload) as category, values(SourceFileName)
|
||||
as file_name values(ObjectId) as file_path, values(VirusInfo) as signature, count,
|
||||
min(_time) as firstTime, max(_time) as lastTime by signature_id, user, dest, src,
|
||||
vendor_account, vendor_product | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
|
||||
| `o365_sharepoint_malware_detection_filter`'
|
||||
how_to_implement: You must install the Splunk Microsoft Office 365 Add-on and ingest
|
||||
Office 365 management activity events.
|
||||
known_false_positives: unknown
|
||||
@@ -61,7 +62,6 @@ tags:
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- data:
|
||||
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566/o365_various_alerts/o365_various_alerts.log
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566/o365_various_alerts/o365_various_alerts.log
|
||||
sourcetype: o365:management:activity
|
||||
source: o365
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: O365 Tenant Wide Admin Consent Granted
|
||||
id: 50eaabf8-5180-4e86-bfb2-011472c359fc
|
||||
version: 5
|
||||
version: 6
|
||||
date: '2025-02-10'
|
||||
author: Mauricio Velazco, Splunk
|
||||
status: production
|
||||
@@ -15,12 +15,16 @@ description: The following analytic identifies instances where admin consent is
|
||||
data. If confirmed malicious, an attacker could gain extensive and persistent access
|
||||
to organizational data, leading to data exfiltration, espionage, further malicious
|
||||
activities, and potential compliance violations.
|
||||
search: "`o365_management_activity` Operation=\"Consent to application.\" | eval
|
||||
new_field=mvindex('ModifiedProperties{}.NewValue', 4) | rex field=new_field \"ConsentType:
|
||||
(?<ConsentType>[^\\,]+)\" | rex field=new_field \"Scope: (?<Scope>[^\\,]+)\" |
|
||||
search ConsentType = \"AllPrincipals\" | stats count min(_time) as firstTime max(_time)
|
||||
as lastTime by Operation, user, object, ObjectId, ConsentType, Scope | `security_content_ctime(firstTime)`\
|
||||
\ | `security_content_ctime(lastTime)` | `o365_tenant_wide_admin_consent_granted_filter`"
|
||||
search: "`o365_management_activity` Operation=\"Consent to application.\"
|
||||
| eval new_field=mvindex('ModifiedProperties{}.NewValue', 4)
|
||||
| rex field=new_field \"ConsentType: (?<ConsentType>[^\\,]+)\"
|
||||
| rex field=new_field \"Scope: (?<Scope>[^\\,]+)\"
|
||||
| search ConsentType = \"AllPrincipals\"
|
||||
| fillnull
|
||||
| stats count min(_time) as firstTime max(_time) as lastTime by user, object, ObjectId, ConsentType, Scope, dest, vendor_account, vendor_product, signature, src
|
||||
| `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)`
|
||||
| `o365_tenant_wide_admin_consent_granted_filter`"
|
||||
how_to_implement: You must install the Splunk Microsoft Office 365 Add-on and ingest
|
||||
Office 365 management activity events.
|
||||
known_false_positives: Legitimate applications may be granted tenant wide consent,
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: O365 Threat Intelligence Suspicious Email Delivered
|
||||
id: 605cc93a-70e4-4ee3-9a3d-1a62e8c9b6c2
|
||||
version: 5
|
||||
date: '2025-02-10'
|
||||
version: 6
|
||||
date: '2025-03-25'
|
||||
author: Steven Dick
|
||||
status: production
|
||||
type: Anomaly
|
||||
@@ -21,8 +21,8 @@ search: '`o365_management_activity` Workload=ThreatIntelligence Operation=TIMail
|
||||
values(ThreatsAndDetectionTech{}) as category, values(AttachmentData{}.FileName)
|
||||
as file_name, values(AttachmentData{}.FileType) as file_type, values(AttachmentData{}.SHA256)
|
||||
as file_hash values(DetectionMethod) as signature, min(_time) as firstTime max(_time)
|
||||
as lastTime, count by src_user,sender | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
|
||||
| `o365_threat_intelligence_suspicious_email_delivered_filter`'
|
||||
as lastTime, count by src_user,sender,dest,vendor_account,vendor_product | `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)` | `o365_threat_intelligence_suspicious_email_delivered_filter`'
|
||||
how_to_implement: You must install the Splunk Microsoft Office 365 Add-on and ingest
|
||||
Office 365 management activity events. The threat intelligence workload is typically
|
||||
only visible to E3/E5 level customers.
|
||||
@@ -73,7 +73,6 @@ tags:
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- data:
|
||||
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566/o365_various_alerts/o365_various_alerts.log
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566/o365_various_alerts/o365_various_alerts.log
|
||||
sourcetype: o365:management:activity
|
||||
source: o365
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: O365 Threat Intelligence Suspicious File Detected
|
||||
id: 00958c7b-35db-4e7a-ad13-31550a7a7c64
|
||||
version: 5
|
||||
date: '2025-02-10'
|
||||
version: 6
|
||||
date: '2025-03-25'
|
||||
author: Steven Dick
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -14,9 +14,10 @@ description: The following analytic identifies when a malicious file is detected
|
||||
data_source:
|
||||
- Office 365 Universal Audit Log
|
||||
search: '`o365_management_activity` Workload=ThreatIntelligence Operation=AtpDetection
|
||||
| stats values(DetectionMethod) as category values(FileData.FileName) as file_name
|
||||
values(FileData.FilePath) as file_path values(FileData.FileSize) as file_size values(FileData.MalwareFamily)
|
||||
as signature count, min(_time) as firstTime, max(_time) as lastTime by Id, UserId
|
||||
| eval dest="NA" | eval src="NA" | stats values(DetectionMethod) as category values(FileData.FileName)
|
||||
as file_name values(FileData.FilePath) as file_path values(FileData.FileSize) as
|
||||
file_size values(FileData.MalwareFamily) as signature count, min(_time) as firstTime,
|
||||
max(_time) as lastTime by Id, UserId, dest, src, vendor_account, vendor_product
|
||||
| rename Id as signature_id, UserId as user | `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)` | `o365_threat_intelligence_suspicious_file_detected_filter`'
|
||||
how_to_implement: You must install the Splunk Microsoft Office 365 Add-on and ingest
|
||||
@@ -66,7 +67,6 @@ tags:
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- data:
|
||||
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566/o365_various_alerts/o365_various_alerts.log
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566/o365_various_alerts/o365_various_alerts.log
|
||||
sourcetype: o365:management:activity
|
||||
source: o365
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: O365 User Consent Blocked for Risky Application
|
||||
id: 242e4d30-cb59-4051-b0cf-58895e218f40
|
||||
version: 4
|
||||
version: 5
|
||||
date: '2024-11-14'
|
||||
author: Mauricio Velazco, Splunk
|
||||
status: production
|
||||
@@ -16,11 +16,14 @@ description: The following analytic identifies instances where Office 365 has bl
|
||||
the organization. If confirmed malicious, this activity suggests that O365's security
|
||||
measures successfully prevented a harmful application from accessing organizational
|
||||
data, warranting immediate investigation.
|
||||
search: "`o365_management_activity` Workload=AzureActiveDirectory Operation=\"Consent
|
||||
to application.\" ResultStatus=Failure | eval permissions =mvindex('ModifiedProperties{}.NewValue',
|
||||
4) | eval reason =mvindex('ModifiedProperties{}.NewValue', 5) | search reason =
|
||||
\"Risky application detected\" | rex field=permissions \"Scope: (?<Scope>[^,]+)\"\
|
||||
\ | stats max(_time) as lastTime by Operation, user, reason, object, Scope | `security_content_ctime(lastTime)`
|
||||
search: "`o365_management_activity` Workload=AzureActiveDirectory Operation=\"Consent to application.\" ResultStatus=Failure
|
||||
| eval permissions =mvindex('ModifiedProperties{}.NewValue', 4)
|
||||
| eval reason =mvindex('ModifiedProperties{}.NewValue', 5)
|
||||
| search reason = \"Risky application detected\"
|
||||
| rex field=permissions \"Scope: (?<Scope>[^,]+)\"
|
||||
| fillnull
|
||||
| stats max(_time) as lastTime by user, reason, object, Scope, dest, src, vendor_account, vendor_product, signature
|
||||
| `security_content_ctime(lastTime)`
|
||||
| `o365_user_consent_blocked_for_risky_application_filter`"
|
||||
how_to_implement: You must install the Splunk Microsoft Office 365 Add-on and ingest
|
||||
Office 365 management activity events.
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: O365 User Consent Denied for OAuth Application
|
||||
id: 2d8679ef-b075-46be-8059-c25116cb1072
|
||||
version: 5
|
||||
version: 6
|
||||
date: '2024-11-14'
|
||||
author: Mauricio Velazco, Splunk
|
||||
status: production
|
||||
@@ -16,9 +16,11 @@ description: The following analytic identifies instances where a user has denied
|
||||
or unfamiliar applications. If confirmed malicious, it suggests an attempt by a
|
||||
potentially harmful application to gain unauthorized access, which was proactively
|
||||
blocked by the user.
|
||||
search: '`o365_graph` status.errorCode=65004 | rename userPrincipalName as user |
|
||||
rename ipAddress as src_ip | stats max(_time) as lastTime by user src_ip appDisplayName
|
||||
status.failureReason | `security_content_ctime(lastTime)` | `o365_user_consent_denied_for_oauth_application_filter`'
|
||||
search: '`o365_graph` status.errorCode=65004
|
||||
| rename userPrincipalName as user
|
||||
| rename ipAddress as src_ip
|
||||
| stats min(_time) as firstTime max(_time) as lastTime by user src_ip appDisplayName status.failureReason
|
||||
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `o365_user_consent_denied_for_oauth_application_filter`'
|
||||
how_to_implement: You must install the Splunk Microsoft Office 365 Add-on and ingest
|
||||
Office 365 events.
|
||||
known_false_positives: OAuth applications that require mail permissions may be legitimate,
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: O365 ZAP Activity Detection
|
||||
id: 4df275fd-a0e5-4246-8b92-d3201edaef7a
|
||||
version: 5
|
||||
date: '2025-02-10'
|
||||
version: 6
|
||||
date: '2025-03-25'
|
||||
author: Steven Dick
|
||||
status: production
|
||||
type: Anomaly
|
||||
@@ -13,12 +13,13 @@ description: The following analytic detects when the Microsoft Zero-hour Automat
|
||||
data_source:
|
||||
- Office 365 Universal Audit Log
|
||||
search: '`o365_management_activity` Workload=SecurityComplianceCenter Operation=AlertEntityGenerated
|
||||
Name="*messages containing malicious*" | fromjson Data | stats count min(_time)
|
||||
as firstTime max(_time) as lastTime values(zu) as url values(zfn) as file_name values(ms)
|
||||
as subject values(ttr) as result values(tsd) as src_user by AlertId,trc,Operation,Name
|
||||
| rename Name as signature, AlertId as signature_id, trc as user | eval action =
|
||||
CASE(match(result,"Success"), "blocked", true(),"allowed"), url = split(url,";")
|
||||
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `o365_zap_activity_detection_filter`'
|
||||
Name="*messages containing malicious*" | fromjson Data | fillnull | stats count
|
||||
min(_time) as firstTime max(_time) as lastTime values(zu) as url values(zfn) as
|
||||
file_name values(ms) as subject values(ttr) as result values(tsd) as src_user by
|
||||
AlertId,trc,signature,Name,dest,src,vendor_account,vendor_product | rename Name
|
||||
as signature, AlertId as signature_id, trc as user | eval action = CASE(match(result,"Success"),
|
||||
"blocked", true(),"allowed"), url = split(url,";") | `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)` | `o365_zap_activity_detection_filter`'
|
||||
how_to_implement: You must install the Splunk Microsoft Office 365 Add-on and ingest
|
||||
Office 365 management activity events. Some features of Zero-hour purge are only
|
||||
offered within E3/E5 license level tenants, events may not be available otherwise.
|
||||
@@ -68,7 +69,6 @@ tags:
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- data:
|
||||
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566/o365_various_alerts/o365_various_alerts.log
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1566/o365_various_alerts/o365_various_alerts.log
|
||||
sourcetype: o365:management:activity
|
||||
source: o365
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Common Ransomware Extensions
|
||||
id: a9e5c5db-db11-43ca-86a8-c852d1b2c0ec
|
||||
version: '12'
|
||||
date: '2025-03-03'
|
||||
version: '13'
|
||||
date: '2025-03-25'
|
||||
author: David Dorsey, Michael Haag, Splunk, Steven Dick
|
||||
status: production
|
||||
type: TTP
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Delete ShadowCopy With PowerShell
|
||||
id: 5ee2bcd0-b2ff-11eb-bb34-acde48001122
|
||||
version: 5
|
||||
date: '2024-11-13'
|
||||
version: 6
|
||||
date: '2025-03-25'
|
||||
author: Teoderick Contreras, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -57,6 +57,7 @@ tags:
|
||||
- Ransomware
|
||||
- Revil Ransomware
|
||||
- DarkGate Malware
|
||||
- VanHelsing Ransomware
|
||||
asset_type: Endpoint
|
||||
mitre_attack_id:
|
||||
- T1490
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Deleting Shadow Copies
|
||||
id: b89919ed-ee5f-492c-b139-95dbb162039e
|
||||
version: '11'
|
||||
date: '2025-03-03'
|
||||
version: '12'
|
||||
date: '2025-03-25'
|
||||
author: David Dorsey, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -81,6 +81,7 @@ tags:
|
||||
- Windows Log Manipulation
|
||||
- Compromised Windows Host
|
||||
- Clop Ransomware
|
||||
- VanHelsing Ransomware
|
||||
asset_type: Endpoint
|
||||
mitre_attack_id:
|
||||
- T1490
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Detect Copy of ShadowCopy with Script Block Logging
|
||||
id: 9251299c-ea5b-11eb-a8de-acde48001122
|
||||
version: 6
|
||||
date: '2025-02-10'
|
||||
version: 7
|
||||
date: '2025-03-25'
|
||||
author: Michael Haag, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -56,6 +56,7 @@ rba:
|
||||
tags:
|
||||
analytic_story:
|
||||
- Credential Dumping
|
||||
- VanHelsing Ransomware
|
||||
asset_type: Endpoint
|
||||
cve:
|
||||
- CVE-2021-36934
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Detect PsExec With accepteula Flag
|
||||
id: 27c3a83d-cada-47c6-9042-67baf19d2574
|
||||
version: 10
|
||||
date: '2025-02-10'
|
||||
version: 11
|
||||
date: '2025-03-25'
|
||||
author: Bhavin Patel, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -81,6 +81,7 @@ tags:
|
||||
- BlackByte Ransomware
|
||||
- DarkGate Malware
|
||||
- Rhysida Ransomware
|
||||
- VanHelsing Ransomware
|
||||
asset_type: Endpoint
|
||||
mitre_attack_id:
|
||||
- T1021.002
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Detect Renamed PSExec
|
||||
id: 683e6196-b8e8-11eb-9a79-acde48001122
|
||||
version: '12'
|
||||
date: '2025-02-24'
|
||||
version: '13'
|
||||
date: '2025-03-25'
|
||||
author: Michael Haag, Splunk, Alex Oberkircher, Github Community
|
||||
status: production
|
||||
type: Hunting
|
||||
@@ -51,6 +51,7 @@ tags:
|
||||
- Rhysida Ransomware
|
||||
- Earth Estries
|
||||
- SamSam Ransomware
|
||||
- VanHelsing Ransomware
|
||||
asset_type: Endpoint
|
||||
mitre_attack_id:
|
||||
- T1569.002
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Executable File Written in Administrative SMB Share
|
||||
id: f63c34fe-a435-11eb-935a-acde48001122
|
||||
version: 8
|
||||
date: '2025-02-10'
|
||||
version: 9
|
||||
date: '2025-03-25'
|
||||
author: Teoderick Contreras, Mauricio Velazco, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -66,6 +66,7 @@ tags:
|
||||
- Compromised Windows Host
|
||||
- Hermetic Wiper
|
||||
- Trickbot
|
||||
- VanHelsing Ransomware
|
||||
asset_type: Endpoint
|
||||
mitre_attack_id:
|
||||
- T1021.002
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Living Off The Land Detection
|
||||
id: 1be30d80-3a39-4df9-9102-64a467b24abc
|
||||
version: 5
|
||||
date: '2024-11-13'
|
||||
version: 6
|
||||
date: '2025-03-26'
|
||||
author: Michael Haag, Splunk
|
||||
status: production
|
||||
type: Correlation
|
||||
@@ -70,6 +70,6 @@ tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- data:
|
||||
https://raw.githubusercontent.com/splunk/attack_data/master/datasets/attack_techniques/T1218/living_off_the_land/lolbinrisk.log
|
||||
https://media.githubusercontent.com/media/splunk/attack_data/refs/heads/master/datasets/attack_techniques/T1218/living_off_the_land/lolbinrisk.log
|
||||
source: lotl
|
||||
sourcetype: stash
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Resize ShadowStorage volume
|
||||
id: bc760ca6-8336-11eb-bcbb-acde48001122
|
||||
version: 5
|
||||
date: '2024-12-10'
|
||||
version: 6
|
||||
date: '2025-03-25'
|
||||
author: Teoderick Contreras
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -73,6 +73,7 @@ tags:
|
||||
- Compromised Windows Host
|
||||
- Clop Ransomware
|
||||
- BlackByte Ransomware
|
||||
- VanHelsing Ransomware
|
||||
asset_type: Endpoint
|
||||
mitre_attack_id:
|
||||
- T1490
|
||||
|
||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user