detectuserencryptings3

This commit is contained in:
Rod Soto
2020-10-27 18:01:40 -04:00
parent a599d1ac21
commit be32b7bf01
2 changed files with 23 additions and 1 deletions
@@ -3,7 +3,7 @@ date: "2020-10-27"
description: "This search provides detection of accounts creating KMS with encrypt policy and without using MFA."
how_to_implement: "You must install splunk AWS add on and Splunk App for AWS. This search works with clodtrail logs"
id: c79c164f-4b21-4847-98f9-cf6a9f49179e
known_false_positives: "Not all KMS key creations are malicious. Particulary look for kms:Encryp only policy. It is very unusual to create a key to encrypt only and not to decrypt."
known_false_positives: "Not all KMS key creations are malicious. Particulary look for kms:Encrypt only policy. It is very unusual to create a key to encrypt only and not to decrypt."
name: "aws detect users creating keys with encrypt policy without mfa"
references:
- https://rhinosecuritylabs.com/aws/s3-ransomware-part-1-attack-vector/
@@ -0,0 +1,22 @@
author: "Rod Soto, Splunk"
date: "2020-10-27"
description: "This search provides detection of users with KMS keys performing encryption specifically against S3 buckets."
how_to_implement: "You must install splunk AWS add on and Splunk App for AWS. This search works with clodtrail logs"
id: 884a5f59-eec7-4f4a-948b-dbde18225fdc
known_false_positives: "Not all operations with KMS keys are malicious. It is very unusual to create a key to encrypt only and not to decrypt. This search compliments the creation of KMS keys with encrypt policy. It is recommended to change * for specific keys found in the KMS policy search"
name: "aws detect users with kms keys performing encryption"
references:
- https://rhinosecuritylabs.com/aws/s3-ransomware-part-1-attack-vector/
- https://github.com/d1vious/git-wild-hunt
- https://www.youtube.com/watch?v=PgzNib37g0M
search: 'sourcetype:aws:cloudtrail requestParameters.x-amz-server-side-encryption-aws-kms-key-id=* | table event_name errorCode region requestParameters.bucketName user object_path responseElements.x-amz-server-side-encryption sourceIPAddress
|`aws_detect_users_with_kms_keys_performing_encryption_s3_filter`'
tags:
analytics_story:
- "Ransomware Cloud"
asset_type: "AWS Account"
mitre_attack_id:
- T1486
security_domain: threat
type: ESCU
version: 1