mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
Branch was auto-updated.
This commit is contained in:
@@ -46,7 +46,27 @@ tags:
|
||||
- ActorIpAddress
|
||||
- dest
|
||||
- ResultStatus
|
||||
risk_object: dest
|
||||
risk_object_type: system
|
||||
risk_score: 20
|
||||
security_domain: threat
|
||||
impact: 30
|
||||
confidence: 60
|
||||
# (impact * confidence)/100
|
||||
risk_score: 18
|
||||
context:
|
||||
- Source:Cloud Data
|
||||
- Scope:External
|
||||
- Outcome:Allowed
|
||||
- Stage:Execution
|
||||
message: User $Actor.ID$ has created a new federation setting on $dest$ from IP Address $ActorIpAddress$
|
||||
observable:
|
||||
- name: ActorIpAddress
|
||||
type: IP Address
|
||||
role:
|
||||
- Attacker
|
||||
- name: Actor.ID
|
||||
type: User
|
||||
role:
|
||||
- Attacker
|
||||
- name: dest
|
||||
type: Endpoint
|
||||
role:
|
||||
- Victim
|
||||
security_domain: threat
|
||||
@@ -49,7 +49,23 @@ tags:
|
||||
- ModifiedProperties{}.NewValue
|
||||
- Target{}.ID
|
||||
- ActorIpAddress
|
||||
risk_object: ActorIpAddress
|
||||
risk_object_type: system
|
||||
risk_score: 20
|
||||
security_domain: threat
|
||||
impact: 70
|
||||
confidence: 60
|
||||
# (impact * confidence)/100
|
||||
risk_score: 42
|
||||
context:
|
||||
- Source:Cloud Data
|
||||
- Scope:External
|
||||
- Outcome:Allowed
|
||||
- Stage:Execution
|
||||
message: User $Actor.ID$ created a new federation setting on $Target.ID$ and added service principal credentials from IP Address $ActorIpAddress$
|
||||
observable:
|
||||
- name: ActorIpAddress
|
||||
type: IP Address
|
||||
role:
|
||||
- Attacker
|
||||
- name: Target.ID
|
||||
type: Endpoint
|
||||
role:
|
||||
- Victim
|
||||
security_domain: threat
|
||||
@@ -52,7 +52,24 @@ tags:
|
||||
- status
|
||||
- user_id
|
||||
- action
|
||||
risk_object: user
|
||||
risk_object_type: user
|
||||
risk_score: 20
|
||||
security_domain: threat
|
||||
impact: 70
|
||||
confidence: 60
|
||||
# (impact * confidence)/100
|
||||
risk_score: 42
|
||||
context:
|
||||
- Source:Cloud Data
|
||||
- Scope:External
|
||||
- Outcome:Allowed
|
||||
- Stage:Execution
|
||||
- Stage:Defense Evasion
|
||||
message: User $user_id$ has added new IP addresses $ip_addresses_new_added$ to a list of trusted IPs to bypass MFA
|
||||
observable:
|
||||
- name: ip_addresses_new_added
|
||||
type: IP Address
|
||||
role:
|
||||
- Attacker
|
||||
- name: user_id
|
||||
type: User
|
||||
role:
|
||||
- Attacker
|
||||
security_domain: threat
|
||||
@@ -42,7 +42,24 @@ tags:
|
||||
- signature
|
||||
- dest
|
||||
- ResultStatus
|
||||
risk_object: dest
|
||||
risk_object_type: system
|
||||
risk_score: 20
|
||||
security_domain: threat
|
||||
impact: 80
|
||||
confidence: 80
|
||||
# (impact * confidence)/100
|
||||
risk_score: 64
|
||||
context:
|
||||
- Source:Cloud Data
|
||||
- Scope:External
|
||||
- Outcome:Allowed
|
||||
- Stage:Execution
|
||||
- Stage:Defense Evasion
|
||||
message: User $user$ has executed an operation $Operation$ for this destination $dest$
|
||||
observable:
|
||||
- name: dest
|
||||
type: Endpoint
|
||||
role:
|
||||
- Victim
|
||||
- name: user
|
||||
type: User
|
||||
role:
|
||||
- Attacker
|
||||
security_domain: threat
|
||||
@@ -42,7 +42,24 @@ tags:
|
||||
- UserAgent
|
||||
- src_ip
|
||||
- user
|
||||
risk_object: user
|
||||
risk_object_type: user
|
||||
risk_score: 20
|
||||
security_domain: threat
|
||||
impact: 80
|
||||
confidence: 80
|
||||
# (impact * confidence)/100
|
||||
risk_score: 64
|
||||
context:
|
||||
- Source:Cloud Data
|
||||
- Scope:External
|
||||
- Outcome:Allowed
|
||||
- Stage:Execution
|
||||
- Stage:Initial Access
|
||||
message: User $user$ has caused excessive number of authentication failures from $src_ip$ using UserAgent $UserAgent$.
|
||||
observable:
|
||||
- name: src_ip
|
||||
type: IP Address
|
||||
role:
|
||||
- Attacker
|
||||
- name: user
|
||||
type: User
|
||||
role:
|
||||
- Victim
|
||||
security_domain: threat
|
||||
@@ -42,7 +42,24 @@ tags:
|
||||
- ActorIpAddress
|
||||
- UserAgent
|
||||
- UserId
|
||||
risk_object: user
|
||||
risk_object_type: user
|
||||
risk_score: 20
|
||||
security_domain: threat
|
||||
impact: 80
|
||||
confidence: 80
|
||||
# (impact * confidence)/100
|
||||
risk_score: 64
|
||||
context:
|
||||
- Source:Cloud Data
|
||||
- Scope:External
|
||||
- Outcome:Allowed
|
||||
- Stage:Execution
|
||||
- Stage:Initial Access
|
||||
message: User $UserId$ has caused excessive number of SSO logon errors from $ActorIpAddress$ using UserAgent $UserAgent$.
|
||||
observable:
|
||||
- name: ActorIpAddress
|
||||
type: IP Address
|
||||
role:
|
||||
- Attacker
|
||||
- name: UserId
|
||||
type: User
|
||||
role:
|
||||
- Victim
|
||||
security_domain: threat
|
||||
@@ -49,7 +49,24 @@ tags:
|
||||
- OriginatingServer
|
||||
- UserId
|
||||
- UserKey
|
||||
risk_object: UserId
|
||||
risk_object_type: user
|
||||
risk_score: 20
|
||||
security_domain: threat
|
||||
impact: 80
|
||||
confidence: 80
|
||||
# (impact * confidence)/100
|
||||
risk_score: 64
|
||||
context:
|
||||
- Source:Cloud Data
|
||||
- Scope:External
|
||||
- Outcome:Allowed
|
||||
- Stage:Execution
|
||||
- Stage:Defense Evasion
|
||||
message: User $UserId$ has added a new federated domaain $Parameters.Value$ for $OrganizationName$
|
||||
observable:
|
||||
- name: OrganizationName
|
||||
type: Other
|
||||
role:
|
||||
- Victim
|
||||
- name: UserId
|
||||
type: User
|
||||
role:
|
||||
- Victim
|
||||
security_domain: threat
|
||||
@@ -43,7 +43,19 @@ tags:
|
||||
- Severity
|
||||
- AlertEntityId
|
||||
- Operation
|
||||
risk_object: Source
|
||||
risk_object_type: system
|
||||
risk_score: 20
|
||||
security_domain: threat
|
||||
impact: 80
|
||||
confidence: 60
|
||||
# (impact * confidence)/100
|
||||
risk_score: 48
|
||||
context:
|
||||
- Source:Cloud Data
|
||||
- Scope:External
|
||||
- Outcome:Allowed
|
||||
- Stage:Exfiltration
|
||||
message: User $Source$ has exported a PST file from the search using this operation- $Operation$ with a severity of $Severity$
|
||||
observable:
|
||||
- name: Source
|
||||
type: User
|
||||
role:
|
||||
- Attacker
|
||||
security_domain: threat
|
||||
@@ -42,7 +42,19 @@ tags:
|
||||
- _time
|
||||
- Operation
|
||||
- Parameters
|
||||
risk_object: src_user
|
||||
risk_object_type: system
|
||||
risk_score: 20
|
||||
security_domain: threat
|
||||
impact: 80
|
||||
confidence: 60
|
||||
# (impact * confidence)/100
|
||||
risk_score: 48
|
||||
context:
|
||||
- Source:Cloud Data
|
||||
- Scope:External
|
||||
- Outcome:Allowed
|
||||
- Stage:Exfiltration
|
||||
message: User $user$ has configured a forwarding rule for multiple mailboxes to the same destination $ForwardingAddress$
|
||||
observable:
|
||||
- name: user
|
||||
type: User
|
||||
role:
|
||||
- Attacker
|
||||
security_domain: threat
|
||||
@@ -41,7 +41,19 @@ tags:
|
||||
- _time
|
||||
- Operation
|
||||
- Parameters
|
||||
risk_object: user
|
||||
risk_object_type: user
|
||||
risk_score: 20
|
||||
security_domain: threat
|
||||
impact: 80
|
||||
confidence: 60
|
||||
# (impact * confidence)/100
|
||||
risk_score: 48
|
||||
context:
|
||||
- Source:Cloud Data
|
||||
- Scope:External
|
||||
- Stage:Exfiltration
|
||||
- Stage:Execution
|
||||
message: User $user$ has delegated suspicious rights $AccessRights$ to user $dest_user$ that allow access to sensitive
|
||||
observable:
|
||||
- name: user
|
||||
type: User
|
||||
role:
|
||||
- Attacker
|
||||
security_domain: threat
|
||||
@@ -42,7 +42,23 @@ tags:
|
||||
- _time
|
||||
- Operation
|
||||
- Parameters
|
||||
risk_object: ForwardingSmtpAddress
|
||||
risk_object_type: system
|
||||
risk_score: 20
|
||||
security_domain: threat
|
||||
impact: 80
|
||||
confidence: 60
|
||||
# (impact * confidence)/100
|
||||
risk_score: 48
|
||||
context:
|
||||
- Source:Cloud Data
|
||||
- Scope:External
|
||||
- Stage:Exfiltration
|
||||
- Stage:Execution
|
||||
message: User $user$ configured multiple users $src_user$ with a count of $count_src_user$, a forwarding rule to same destination $ForwardingSmtpAddress$
|
||||
observable:
|
||||
- name: user
|
||||
type: User
|
||||
role:
|
||||
- Attacker
|
||||
- name: ForwardingSmtpAddress
|
||||
type: Email Address
|
||||
role:
|
||||
- Other
|
||||
security_domain: threat
|
||||
Reference in New Issue
Block a user