updating docs and package bits [ci skip]

This commit is contained in:
research bot
2021-07-29 21:15:45 +00:00
parent a3237b801b
commit df85ff33ad
19 changed files with 408 additions and 1617 deletions
@@ -34,7 +34,7 @@ tags:
dataset:
- https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/security_hub_ec2_spike/security_hub_ec2_spike.json
impact: 30
message: Spike in AWS security Hub alerts with title $Title$ for EC2 instance $dest$
message: Spike in AWS security Hub alerts with title $Title$ for EC2 instance $dest$
nist:
- DE.DP
observable:
+1 -1
View File
@@ -1,6 +1,6 @@
#############
# Automatically generated by generator.py in splunk/security_content
# On Date: 2021-07-28T20:05:49 UTC
# On Date: 2021-07-29T20:53:17 UTC
# Author: Splunk Security Research
# Contact: research@splunk.com
#############
+2 -2
View File
@@ -1,6 +1,6 @@
#############
# Automatically generated by generator.py in splunk/security_content
# On Date: 2021-07-28T20:05:49 UTC
# On Date: 2021-07-29T20:53:17 UTC
# Author: Splunk Security Research
# Contact: research@splunk.com
#############
@@ -2950,7 +2950,7 @@ asset_type = AWS Instance
confidence = medium
explanation = This search looks for a spike in number of of AWS security Hub alerts for an EC2 instance in 4 hours intervals
how_to_implement = You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add-on for AWS (version 4.4.0 or later), then configure your Security Hub inputs. The threshold_value should be tuned to your environment and schedule these searches according to the bucket span interval.
annotations = {"cis20": ["CIS 13"], "nist": ["DE.DP", "DE.AE"]}
annotations = {"cis20": ["CIS 13"], "nist": ["DE.DP"]}
known_false_positives = None
providing_technologies = []
+1 -1
View File
@@ -4,7 +4,7 @@
is_configured = false
state = enabled
state_change_requires_restart = false
build = 35181
build = 35236
[triggers]
reload.analytic_stories = simple
+1 -1
View File
@@ -1,6 +1,6 @@
#############
# Automatically generated by generator.py in splunk/security_content
# On Date: 2021-07-28T20:05:49 UTC
# On Date: 2021-07-29T20:53:17 UTC
# Author: Splunk Security Research
# Contact: research@splunk.com
#############
+1 -1
View File
@@ -1,6 +1,6 @@
#############
# Automatically generated by generator.py in splunk/security_content
# On Date: 2021-07-28T20:05:49 UTC
# On Date: 2021-07-29T20:53:17 UTC
# Author: Splunk Security Research
# Contact: research@splunk.com
#############
+333 -1389
View File
File diff suppressed because it is too large Load Diff
+1 -1
View File
@@ -1,6 +1,6 @@
#############
# Automatically generated by generator.py in splunk/security_content
# On Date: 2021-07-28T20:05:49 UTC
# On Date: 2021-07-29T20:53:17 UTC
# Author: Splunk Security Research
# Contact: research@splunk.com
#############
+2 -2
View File
@@ -1,6 +1,6 @@
#############
# Automatically generated by generator.py in splunk/security_content
# On Date: 2021-07-28T20:05:49 UTC
# On Date: 2021-07-29T20:53:17 UTC
# Author: Splunk Security Research
# Contact: research@splunk.com
#############
@@ -2950,7 +2950,7 @@ asset_type = AWS Instance
confidence = medium
explanation = This search looks for a spike in number of of AWS security Hub alerts for an EC2 instance in 4 hours intervals
how_to_implement = You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add-on for AWS (version 4.4.0 or later), then configure your Security Hub inputs. The threshold_value should be tuned to your environment and schedule these searches according to the bucket span interval.
annotations = {"cis20": ["CIS 13"], "nist": ["DE.DP", "DE.AE"]}
annotations = {"cis20": ["CIS 13"], "nist": ["DE.DP"]}
known_false_positives = None
providing_technologies = []
+2 -2
View File
@@ -1,6 +1,6 @@
#############
# Automatically generated by generator.py in splunk/security_content
# On Date: 2021-07-28T20:06:09 UTC
# On Date: 2021-07-29T20:53:37 UTC
# Author: Splunk Security Research
# Contact: research@splunk.com
#############
@@ -50,7 +50,7 @@ id = 2f2f610a-d64d-48c2-b57c-96722b49ab5a
version = 1
reference = ["https://aws.amazon.com/security-hub/features/"]
detection_searches = ["ESCU - Detect Spike in AWS Security Hub Alerts for EC2 Instance - Rule"]
mappings = {"cis20": ["CIS 13"], "nist": ["DE.AE", "DE.DP"]}
mappings = {"cis20": ["CIS 13"], "nist": ["DE.DP"]}
investigative_searches = ["ESCU - AWS Investigate User Activities By ARN - Response Task", "ESCU - Get EC2 Instance Details by instanceId - Response Task", "ESCU - Get EC2 Launch Details - Response Task"]
support_searches = []
data_models = []
+2 -2
View File
@@ -1,6 +1,6 @@
#############
# Automatically generated by generator.py in splunk/security_content
# On Date: 2021-07-28T20:06:09 UTC
# On Date: 2021-07-29T20:53:37 UTC
# Author: Splunk Security Research
# Contact: research@splunk.com
#############
@@ -553,7 +553,7 @@ asset_type = AWS Instance
confidence = medium
explanation = This search looks for a spike in number of of AWS security Hub alerts for an EC2 instance in 4 hours intervals
how_to_implement = You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add-on for AWS (version 4.4.0 or later), then configure your Security Hub inputs. The threshold_value should be tuned to your environment and schedule these searches according to the bucket span interval.
annotations = {"cis20": ["CIS 13"], "nist": ["DE.DP", "DE.AE"]}
annotations = {"cis20": ["CIS 13"], "nist": ["DE.DP"]}
known_false_positives = None
providing_technologies = []
+1 -1
View File
@@ -4,7 +4,7 @@
is_configured = false
state = enabled
state_change_requires_restart = false
build = 35181
build = 35236
[triggers]
reload.analytic_stories = simple
+1 -1
View File
@@ -1,6 +1,6 @@
#############
# Automatically generated by generator.py in splunk/security_content
# On Date: 2021-07-28T20:06:09 UTC
# On Date: 2021-07-29T20:53:37 UTC
# Author: Splunk Security Research
# Contact: research@splunk.com
#############
+1 -1
View File
@@ -1,6 +1,6 @@
#############
# Automatically generated by generator.py in splunk/security_content
# On Date: 2021-07-28T20:06:09 UTC
# On Date: 2021-07-29T20:53:37 UTC
# Author: Splunk Security Research
# Contact: research@splunk.com
#############
+53 -206
View File
@@ -1,6 +1,6 @@
#############
# Automatically generated by generator.py in splunk/security_content
# On Date: 2021-07-28T20:06:09 UTC
# On Date: 2021-07-29T20:53:37 UTC
# Author: Splunk Security Research
# Contact: research@splunk.com
#############
@@ -25,11 +25,8 @@ action.escu.product = ["Splunk Security Analytics for AWS", "Splunk Enterprise",
action.escu.providing_technologies = []
action.escu.analytic_story = ["AWS IAM Privilege Escalation"]
action.risk = 1
action.risk.param._risk_object = user
action.risk.param._risk_object_type = user
action.risk.param._risk_score = 49
action.risk.param._risk_message = User $user$ created a policy version that allows them to access any resource in their account
action.risk.param._risk = [{"risk_object_field": "user", "risk_object_type": "user", "risk_score": 49, "threat_object_field": "user", "threat_object_type": "user"}, {"risk_object_field": "user", "risk_object_type": "user", "risk_score": 49, "threat_object_field": "user", "threat_object_type": "user"}]
action.risk.param._risk = [{"risk_object_field": "user", "risk_object_type": "user", "risk_score": 49}]
action.risk.param.verbose = 0
cron_schedule = 0 * * * *
dispatch.earliest_time = -70m@m
@@ -67,11 +64,8 @@ action.escu.product = ["Splunk Security Analytics for AWS", "Splunk Enterprise",
action.escu.providing_technologies = []
action.escu.analytic_story = ["AWS IAM Privilege Escalation"]
action.risk = 1
action.risk.param._risk_object = user_arn
action.risk.param._risk_object_type = user
action.risk.param._risk_score = 63
action.risk.param._risk_message = User $user_arn$ is attempting to create access keys for $requestParameters.userName$ from this IP $src$
action.risk.param._risk = [{"risk_object_field": "src", "risk_object_type": "system", "risk_score": 63, "threat_object_field": "src", "threat_object_type": "ip address"}, {"risk_object_field": "src", "risk_object_type": "system", "risk_score": 63, "threat_object_field": "src", "threat_object_type": "ip address"}, {"risk_object_field": "user_arn", "risk_object_type": "user", "risk_score": 63, "threat_object_field": "user_arn", "threat_object_type": "user"}, {"risk_object_field": "user_arn", "risk_object_type": "user", "risk_score": 63, "threat_object_field": "user_arn", "threat_object_type": "user"}]
action.risk.param._risk = [{"risk_object_field": "src", "risk_object_type": "system", "risk_score": 63}, {"risk_object_field": "user_arn", "risk_object_type": "user", "risk_score": 63}]
action.risk.param.verbose = 0
cron_schedule = 0 * * * *
dispatch.earliest_time = -70m@m
@@ -109,11 +103,8 @@ action.escu.product = ["Splunk Security Analytics for AWS", "Splunk Enterprise",
action.escu.providing_technologies = []
action.escu.analytic_story = ["AWS IAM Privilege Escalation"]
action.risk = 1
action.risk.param._risk_object = user_arn
action.risk.param._risk_object_type = user
action.risk.param._risk_score = 72
action.risk.param._risk_message = User $user_arn$ is attempting to create a login profile for $requestParameters.userName$ and did a console login from this IP $src_ip$
action.risk.param._risk = [{"risk_object_field": "src_ip", "risk_object_type": "system", "risk_score": 72, "threat_object_field": "src_ip", "threat_object_type": "ip address"}, {"risk_object_field": "src_ip", "risk_object_type": "system", "risk_score": 72, "threat_object_field": "src_ip", "threat_object_type": "ip address"}, {"risk_object_field": "user_arn", "risk_object_type": "user", "risk_score": 72, "threat_object_field": "user_arn", "threat_object_type": "user"}, {"risk_object_field": "user_arn", "risk_object_type": "user", "risk_score": 72, "threat_object_field": "user_arn", "threat_object_type": "user"}]
action.risk.param._risk = [{"risk_object_field": "src_ip", "risk_object_type": "system", "risk_score": 72}, {"risk_object_field": "user_arn", "risk_object_type": "user", "risk_score": 72}]
action.risk.param.verbose = 0
cron_schedule = 0 * * * *
dispatch.earliest_time = -70m@m
@@ -151,9 +142,6 @@ action.escu.product = ["Splunk Security Analytics for AWS", "Splunk Enterprise",
action.escu.providing_technologies = []
action.escu.analytic_story = ["Suspicious Cloud Authentication Activities"]
action.risk = 1
action.risk.param._risk_object =
action.risk.param._risk_object_type =
action.risk.param._risk_score = 15
action.risk.param._risk_message = AWS account $requestingAccountId$ is trying to access resource from some other account $requestedAccountId$, for the first time.
action.risk.param._risk = [{"threat_object_field": "requestingAccountId", "threat_object_type": "other"}, {"threat_object_field": "requestedAccountId", "threat_object_type": "other"}]
action.risk.param.verbose = 0
@@ -193,11 +181,8 @@ action.escu.product = ["Splunk Security Analytics for AWS", "Splunk Enterprise",
action.escu.providing_technologies = []
action.escu.analytic_story = ["Ransomware Cloud"]
action.risk = 1
action.risk.param._risk_object = userIdentity.principalId
action.risk.param._risk_object_type = user
action.risk.param._risk_score = 25
action.risk.param._risk_message = AWS account is potentially compromised and user $userIdentity.principalId$ is trying to compromise other accounts.
action.risk.param._risk = [{"risk_object_field": "userIdentity.principalId", "risk_object_type": "user", "risk_score": 25, "threat_object_field": "userIdentity.principalId", "threat_object_type": "user"}, {"risk_object_field": "userIdentity.principalId", "risk_object_type": "user", "risk_score": 25, "threat_object_field": "userIdentity.principalId", "threat_object_type": "user"}]
action.risk.param._risk = [{"risk_object_field": "userIdentity.principalId", "risk_object_type": "user", "risk_score": 25}]
action.risk.param.verbose = 0
cron_schedule = 0 * * * *
dispatch.earliest_time = -70m@m
@@ -235,11 +220,8 @@ action.escu.product = ["Splunk Security Analytics for AWS", "Splunk Enterprise",
action.escu.providing_technologies = []
action.escu.analytic_story = ["Ransomware Cloud"]
action.risk = 1
action.risk.param._risk_object = user
action.risk.param._risk_object_type = user
action.risk.param._risk_score = 15
action.risk.param._risk_message = User $user$ with KMS keys is performing encryption, against S3 buckets on these files $dest_file$
action.risk.param._risk = [{"risk_object_field": "user", "risk_object_type": "user", "risk_score": 15, "threat_object_field": "user", "threat_object_type": "user"}, {"risk_object_field": "user", "risk_object_type": "user", "risk_score": 15, "threat_object_field": "user", "threat_object_type": "user"}, {"threat_object_field": "dest_file", "threat_object_type": "file"}]
action.risk.param._risk = [{"risk_object_field": "user", "risk_object_type": "user", "risk_score": 15}, {"threat_object_field": "dest_file", "threat_object_type": "file"}]
action.risk.param.verbose = 0
cron_schedule = 0 * * * *
dispatch.earliest_time = -70m@m
@@ -277,11 +259,8 @@ action.escu.product = ["Splunk Security Analytics for AWS", "Splunk Enterprise",
action.escu.providing_technologies = []
action.escu.analytic_story = ["AWS User Monitoring"]
action.risk = 1
action.risk.param._risk_object = user
action.risk.param._risk_object_type = user
action.risk.param._risk_score = 18
action.risk.param._risk_message = user $user$ has excessive number of api calls $dc_events$ from these IP addresses $src$, violating the threshold of 50, using the following commands $command$.
action.risk.param._risk = [{"risk_object_field": "src", "risk_object_type": "system", "risk_score": 18, "threat_object_field": "src", "threat_object_type": "ip address"}, {"risk_object_field": "src", "risk_object_type": "system", "risk_score": 18, "threat_object_field": "src", "threat_object_type": "ip address"}, {"risk_object_field": "user", "risk_object_type": "user", "risk_score": 18, "threat_object_field": "user", "threat_object_type": "user"}, {"risk_object_field": "user", "risk_object_type": "user", "risk_score": 18, "threat_object_field": "user", "threat_object_type": "user"}]
action.risk.param._risk = [{"risk_object_field": "src", "risk_object_type": "system", "risk_score": 18}, {"risk_object_field": "user", "risk_object_type": "user", "risk_score": 18}]
action.risk.param.verbose = 0
cron_schedule = 0 * * * *
dispatch.earliest_time = -70m@m
@@ -319,11 +298,8 @@ action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splun
action.escu.providing_technologies = []
action.escu.analytic_story = ["Suspicious Cloud User Activities"]
action.risk = 1
action.risk.param._risk_object = userIdentity.arn
action.risk.param._risk_object_type = user
action.risk.param._risk_score = 10
action.risk.param._risk_message = User $userIdentity.arn$ is seen to perform excessive number of discovery related api calls- $failures$, within an hour where the access was denied.
action.risk.param._risk = [{"risk_object_field": "src_ip", "risk_object_type": "system", "risk_score": 10, "threat_object_field": "src_ip", "threat_object_type": "ip address"}, {"risk_object_field": "src_ip", "risk_object_type": "system", "risk_score": 10, "threat_object_field": "src_ip", "threat_object_type": "ip address"}, {"risk_object_field": "userIdentity.arn", "risk_object_type": "user", "risk_score": 10, "threat_object_field": "userIdentity.arn", "threat_object_type": "user"}, {"risk_object_field": "userIdentity.arn", "risk_object_type": "user", "risk_score": 10, "threat_object_field": "userIdentity.arn", "threat_object_type": "user"}]
action.risk.param._risk = [{"risk_object_field": "src_ip", "risk_object_type": "system", "risk_score": 10}, {"risk_object_field": "userIdentity.arn", "risk_object_type": "user", "risk_score": 10}]
action.risk.param.verbose = 0
cron_schedule = 0 * * * *
dispatch.earliest_time = -70m@m
@@ -361,11 +337,8 @@ action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splun
action.escu.providing_technologies = []
action.escu.analytic_story = ["AWS IAM Privilege Escalation"]
action.risk = 1
action.risk.param._risk_object = user_arn
action.risk.param._risk_object_type = user
action.risk.param._risk_score = 28
action.risk.param._risk_message = User $user_arn$ has caused multiple failures with errorCode $errorCode$, which potentially means adversary is attempting to identify a role name.
action.risk.param._risk = [{"risk_object_field": "src", "risk_object_type": "system", "risk_score": 28, "threat_object_field": "src", "threat_object_type": "ip address"}, {"risk_object_field": "src", "risk_object_type": "system", "risk_score": 28, "threat_object_field": "src", "threat_object_type": "ip address"}, {"risk_object_field": "user_arn", "risk_object_type": "user", "risk_score": 28}]
action.risk.param._risk = [{"risk_object_field": "src", "risk_object_type": "system", "risk_score": 28}]
action.risk.param.verbose = 0
cron_schedule = 0 * * * *
dispatch.earliest_time = -70m@m
@@ -403,11 +376,8 @@ action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splun
action.escu.providing_technologies = []
action.escu.analytic_story = ["AWS IAM Privilege Escalation"]
action.risk = 1
action.risk.param._risk_object = user_arn
action.risk.param._risk_object_type = user
action.risk.param._risk_score = 10
action.risk.param._risk_message = User $user_arn$ has deleted AWS Policies from IP address $src$ by executing the following command $eventName$
action.risk.param._risk = [{"risk_object_field": "src", "risk_object_type": "system", "risk_score": 10, "threat_object_field": "src", "threat_object_type": "ip address"}, {"risk_object_field": "src", "risk_object_type": "system", "risk_score": 10, "threat_object_field": "src", "threat_object_type": "ip address"}, {"risk_object_field": "user_arn", "risk_object_type": "user", "risk_score": 10}]
action.risk.param._risk = [{"risk_object_field": "src", "risk_object_type": "system", "risk_score": 10}]
action.risk.param.verbose = 0
cron_schedule = 0 * * * *
dispatch.earliest_time = -70m@m
@@ -445,11 +415,8 @@ action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splun
action.escu.providing_technologies = []
action.escu.analytic_story = ["AWS IAM Privilege Escalation"]
action.risk = 1
action.risk.param._risk_object = group_name
action.risk.param._risk_object_type = user
action.risk.param._risk_score = 5
action.risk.param._risk_message = User $user_arn$ has had mulitple failures while attempting to delete groups from $src$
action.risk.param._risk = [{"risk_object_field": "src", "risk_object_type": "system", "risk_score": 5, "threat_object_field": "src", "threat_object_type": "ip address"}, {"risk_object_field": "src", "risk_object_type": "system", "risk_score": 5, "threat_object_field": "src", "threat_object_type": "ip address"}, {"risk_object_field": "user_arn", "risk_object_type": "user", "risk_score": 5}, {"risk_object_field": "group_name", "risk_object_type": "user", "risk_score": 5}]
action.risk.param._risk = [{"risk_object_field": "src", "risk_object_type": "system", "risk_score": 5}]
action.risk.param.verbose = 0
cron_schedule = 0 * * * *
dispatch.earliest_time = -70m@m
@@ -487,11 +454,8 @@ action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splun
action.escu.providing_technologies = []
action.escu.analytic_story = ["AWS IAM Privilege Escalation"]
action.risk = 1
action.risk.param._risk_object = group_deleted
action.risk.param._risk_object_type = user
action.risk.param._risk_score = 5
action.risk.param._risk_message = User $user_arn$ has sucessfully deleted mulitple groups $group_deleted$ from $src$
action.risk.param._risk = [{"risk_object_field": "src", "risk_object_type": "system", "risk_score": 5, "threat_object_field": "src", "threat_object_type": "ip address"}, {"risk_object_field": "src", "risk_object_type": "system", "risk_score": 5, "threat_object_field": "src", "threat_object_type": "ip address"}, {"risk_object_field": "user_arn", "risk_object_type": "user", "risk_score": 5}, {"risk_object_field": "group_deleted", "risk_object_type": "user", "risk_score": 5}]
action.risk.param._risk = [{"risk_object_field": "src", "risk_object_type": "system", "risk_score": 5}]
action.risk.param.verbose = 0
cron_schedule = 0 * * * *
dispatch.earliest_time = -70m@m
@@ -529,11 +493,8 @@ action.escu.product = ["Splunk Security Analytics for AWS", "Splunk Enterprise",
action.escu.providing_technologies = []
action.escu.analytic_story = ["AWS Network ACL Activity"]
action.risk = 1
action.risk.param._risk_object = requestParameters.cidrBlock
action.risk.param._risk_object_type = system
action.risk.param._risk_score = 48
action.risk.param._risk_message = User $user_arn$ has created network ACLs with all the ports open to a specified CIDR $requestParameters.cidrBlock$
action.risk.param._risk = [{"risk_object_field": "src", "risk_object_type": "system", "risk_score": 48, "threat_object_field": "src", "threat_object_type": "ip address"}, {"risk_object_field": "src", "risk_object_type": "system", "risk_score": 48, "threat_object_field": "src", "threat_object_type": "ip address"}, {"risk_object_field": "userName", "risk_object_type": "user", "risk_score": 48}, {"risk_object_field": "requestParameters.cidrBlock", "risk_object_type": "system", "risk_score": 48}]
action.risk.param._risk = [{"risk_object_field": "src", "risk_object_type": "system", "risk_score": 48}]
action.risk.param.verbose = 0
cron_schedule = 0 * * * *
dispatch.earliest_time = -70m@m
@@ -571,11 +532,8 @@ action.escu.product = ["Splunk Security Analytics for AWS", "Splunk Enterprise",
action.escu.providing_technologies = []
action.escu.analytic_story = ["AWS Network ACL Activity"]
action.risk = 1
action.risk.param._risk_object = user_arn
action.risk.param._risk_object_type = user
action.risk.param._risk_score = 5
action.risk.param._risk_message = User $user_arn$ from $src$ has sucessfully deleted network ACLs entry (eventName= $eventName$), such that the instance is accessible from anywhere
action.risk.param._risk = [{"risk_object_field": "src", "risk_object_type": "system", "risk_score": 5, "threat_object_field": "src", "threat_object_type": "ip address"}, {"risk_object_field": "src", "risk_object_type": "system", "risk_score": 5, "threat_object_field": "src", "threat_object_type": "ip address"}, {"risk_object_field": "user_arn", "risk_object_type": "user", "risk_score": 5}]
action.risk.param._risk = [{"risk_object_field": "src", "risk_object_type": "system", "risk_score": 5}]
action.risk.param.verbose = 0
cron_schedule = 0 * * * *
dispatch.earliest_time = -70m@m
@@ -613,11 +571,8 @@ action.escu.product = ["Splunk Security Analytics for AWS", "Splunk Enterprise",
action.escu.providing_technologies = []
action.escu.analytic_story = ["Cloud Federated Credential Abuse"]
action.risk = 1
action.risk.param._risk_object = sourceIPAddress
action.risk.param._risk_object_type = system
action.risk.param._risk_score = 64
action.risk.param._risk_message = From IP address $sourceIPAddress$, user agent $userAgent$ has trigged an event $eventName$ for account ID $recipientAccountId$
action.risk.param._risk = [{"risk_object_field": "sourceIPAddress", "risk_object_type": "system", "risk_score": 64, "threat_object_field": "sourceIPAddress", "threat_object_type": "ip address"}, {"risk_object_field": "sourceIPAddress", "risk_object_type": "system", "risk_score": 64, "threat_object_field": "sourceIPAddress", "threat_object_type": "ip address"}, {"threat_object_field": "recipientAccountId", "threat_object_type": "other"}]
action.risk.param._risk = [{"risk_object_field": "sourceIPAddress", "risk_object_type": "system", "risk_score": 64}, {"threat_object_field": "recipientAccountId", "threat_object_type": "other"}]
action.risk.param.verbose = 0
cron_schedule = 0 * * * *
dispatch.earliest_time = -70m@m
@@ -655,11 +610,8 @@ action.escu.product = ["Splunk Security Analytics for AWS", "Splunk Enterprise",
action.escu.providing_technologies = []
action.escu.analytic_story = ["Cloud Federated Credential Abuse"]
action.risk = 1
action.risk.param._risk_object = userIdentity.principalId
action.risk.param._risk_object_type = user
action.risk.param._risk_score = 64
action.risk.param._risk_message = User $userIdentity.principalId$ from IP address $sourceIPAddress$ has trigged an event $eventName$ to update the SAML provider to $requestParameters.sAMLProviderArn$
action.risk.param._risk = [{"risk_object_field": "sourceIPAddress", "risk_object_type": "system", "risk_score": 64, "threat_object_field": "sourceIPAddress", "threat_object_type": "ip address"}, {"risk_object_field": "sourceIPAddress", "risk_object_type": "system", "risk_score": 64, "threat_object_field": "sourceIPAddress", "threat_object_type": "ip address"}, {"risk_object_field": "userIdentity.principalId", "risk_object_type": "user", "risk_score": 64}]
action.risk.param._risk = [{"risk_object_field": "sourceIPAddress", "risk_object_type": "system", "risk_score": 64}]
action.risk.param.verbose = 0
cron_schedule = 0 * * * *
dispatch.earliest_time = -70m@m
@@ -697,11 +649,8 @@ action.escu.product = ["Splunk Security Analytics for AWS", "Splunk Enterprise",
action.escu.providing_technologies = []
action.escu.analytic_story = ["AWS IAM Privilege Escalation"]
action.risk = 1
action.risk.param._risk_object = user_arn
action.risk.param._risk_object_type = user
action.risk.param._risk_score = 30
action.risk.param._risk_message = From IP address $sourceIPAddress$, user agent $userAgent$ has trigged an event $eventName$ for updating the the default policy version
action.risk.param._risk = [{"risk_object_field": "src", "risk_object_type": "system", "risk_score": 30, "threat_object_field": "src", "threat_object_type": "ip address"}, {"risk_object_field": "src", "risk_object_type": "system", "risk_score": 30, "threat_object_field": "src", "threat_object_type": "ip address"}, {"risk_object_field": "user_arn", "risk_object_type": "user", "risk_score": 30}]
action.risk.param._risk = [{"risk_object_field": "src", "risk_object_type": "system", "risk_score": 30}]
action.risk.param.verbose = 0
cron_schedule = 0 * * * *
dispatch.earliest_time = -70m@m
@@ -739,11 +688,8 @@ action.escu.product = ["Splunk Security Analytics for AWS", "Splunk Enterprise",
action.escu.providing_technologies = []
action.escu.analytic_story = ["AWS IAM Privilege Escalation"]
action.risk = 1
action.risk.param._risk_object = user_arn
action.risk.param._risk_object_type = user
action.risk.param._risk_score = 30
action.risk.param._risk_message = From IP address $sourceIPAddress$, user agent $userAgent$ has trigged an event $eventName$ for updating the existing login profile, potentially giving user $user_arn$ more access privilleges
action.risk.param._risk = [{"risk_object_field": "src", "risk_object_type": "system", "risk_score": 30, "threat_object_field": "src", "threat_object_type": "ip address"}, {"risk_object_field": "src", "risk_object_type": "system", "risk_score": 30, "threat_object_field": "src", "threat_object_type": "ip address"}, {"risk_object_field": "user_arn", "risk_object_type": "user", "risk_score": 30}]
action.risk.param._risk = [{"risk_object_field": "src", "risk_object_type": "system", "risk_score": 30}]
action.risk.param.verbose = 0
cron_schedule = 0 * * * *
dispatch.earliest_time = -70m@m
@@ -781,11 +727,8 @@ action.escu.product = ["Splunk Security Analytics for AWS", "Splunk Enterprise",
action.escu.providing_technologies = []
action.escu.analytic_story = ["Suspicious Cloud User Activities"]
action.risk = 1
action.risk.param._risk_object = user
action.risk.param._risk_object_type = user
action.risk.param._risk_score = 15
action.risk.param._risk_message = user $user$ has made $api_calls$ api calls, violating the dynamic threshold of $expected_upper_threshold$ with the following command $command$.
action.risk.param._risk = [{"risk_object_field": "user", "risk_object_type": "user", "risk_score": 15, "threat_object_field": "user", "threat_object_type": "user"}, {"risk_object_field": "user", "risk_object_type": "user", "risk_score": 15, "threat_object_field": "user", "threat_object_type": "user"}]
action.risk.param._risk = [{"risk_object_field": "user", "risk_object_type": "user", "risk_score": 15}]
action.risk.param.verbose = 0
cron_schedule = 0 * * * *
dispatch.earliest_time = -70m@m
@@ -823,9 +766,6 @@ action.escu.product = ["Splunk Security Analytics for AWS", "Splunk Enterprise",
action.escu.providing_technologies = []
action.escu.analytic_story = ["Suspicious Cloud Instance Activities"]
action.risk = 1
action.risk.param._risk_object =
action.risk.param._risk_object_type =
action.risk.param._risk_score = 10
action.risk.param._risk_message =
action.risk.param._risk = []
action.risk.param.verbose = 0
@@ -865,9 +805,6 @@ action.escu.product = ["Splunk Security Analytics for AWS", "Splunk Enterprise",
action.escu.providing_technologies = []
action.escu.analytic_story = ["Cloud Cryptomining", "Suspicious Cloud Instance Activities"]
action.risk = 1
action.risk.param._risk_object =
action.risk.param._risk_object_type =
action.risk.param._risk_score = 40
action.risk.param._risk_message =
action.risk.param._risk = []
action.risk.param.verbose = 0
@@ -907,11 +844,8 @@ action.escu.product = ["Splunk Security Analytics for AWS", "Splunk Enterprise",
action.escu.providing_technologies = []
action.escu.analytic_story = ["Suspicious Cloud User Activities"]
action.risk = 1
action.risk.param._risk_object = user
action.risk.param._risk_object_type = user
action.risk.param._risk_score = 15
action.risk.param._risk_message = user $user$ has made $api_calls$ api calls related to security groups, violating the dynamic threshold of $expected_upper_threshold$ with the following command $command$.
action.risk.param._risk = [{"risk_object_field": "user", "risk_object_type": "user", "risk_score": 15, "threat_object_field": "user", "threat_object_type": "user"}, {"risk_object_field": "user", "risk_object_type": "user", "risk_score": 15, "threat_object_field": "user", "threat_object_type": "user"}]
action.risk.param._risk = [{"risk_object_field": "user", "risk_object_type": "user", "risk_score": 15}]
action.risk.param.verbose = 0
cron_schedule = 0 * * * *
dispatch.earliest_time = -70m@m
@@ -949,18 +883,15 @@ action.escu.product = ["Splunk Security Analytics for AWS", "Splunk Enterprise",
action.escu.providing_technologies = []
action.escu.analytic_story = ["Suspicious Cloud User Activities"]
action.risk = 1
action.risk.param._risk_object = user
action.risk.param._risk_object_type = user
action.risk.param._risk_score = 36
action.risk.param._risk_message = User $user$ of type AssumedRole attempting to execute new API calls $command$ that have not been seen before
action.risk.param._risk = [{"risk_object_field": "user", "risk_object_type": "user", "risk_score": 36, "threat_object_field": "user", "threat_object_type": "user"}, {"risk_object_field": "user", "risk_object_type": "user", "risk_score": 36, "threat_object_field": "user", "threat_object_type": "user"}]
action.risk.param._risk = [{"risk_object_field": "user", "risk_object_type": "user", "risk_score": 36}]
action.risk.param.verbose = 0
cron_schedule = 0 * * * *
dispatch.earliest_time = -70m@m
dispatch.latest_time = -10m@m
action.correlationsearch.enabled = 1
action.correlationsearch.label = ESCU - Cloud API Calls From Previously Unseen User Roles - Rule
action.correlationsearch.annotations = {"analytic_story": ["Suspicious Cloud User Activities"], "cis20": ["CIS 1"], "confidence": 60, "context": ["Source:Cloud Data", "Scope:External", "Outcome:Allowed", "Stage:Recon", "Stage:Execution"], "impact": 60, "mitre_attack": ["T1078"], "nist": ["ID.AM"], "observable": [{"name": "user", "role": ["Attacker"], "type": "user"}]}
action.correlationsearch.annotations = {"analytic_story": ["Suspicious Cloud User Activities"], "cis20": ["CIS 1"], "confidence": 60, "context": ["Source:Cloud Data", "Scope:External", "Outcome:Allowed", "Stage:Recon", "Stage:Execution"], "impact": 60, "mitre_attack": ["T1078"], "nist": ["ID.AM"], "observable": [{"name": "user", "role": ["Attacker"], "type": "User"}]}
schedule_window = auto
alert.digest_mode = 1
disabled = false
@@ -991,11 +922,8 @@ action.escu.product = ["Splunk Security Analytics for AWS", "Splunk Enterprise",
action.escu.providing_technologies = []
action.escu.analytic_story = ["Cloud Cryptomining"]
action.risk = 1
action.risk.param._risk_object = dest
action.risk.param._risk_object_type = system
action.risk.param._risk_score = 18
action.risk.param._risk_message = User $user$ is creating a new instance $dest$ for the first time
action.risk.param._risk = [{"risk_object_field": "user", "risk_object_type": "user", "risk_score": 18, "threat_object_field": "user", "threat_object_type": "user"}, {"risk_object_field": "user", "risk_object_type": "user", "risk_score": 18, "threat_object_field": "user", "threat_object_type": "user"}, {"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 18}]
action.risk.param._risk = [{"risk_object_field": "user", "risk_object_type": "user", "risk_score": 18}]
action.risk.param.verbose = 0
cron_schedule = 0 * * * *
dispatch.earliest_time = -70m@m
@@ -1033,11 +961,8 @@ action.escu.product = ["Splunk Security Analytics for AWS", "Splunk Enterprise",
action.escu.providing_technologies = []
action.escu.analytic_story = ["Cloud Cryptomining"]
action.risk = 1
action.risk.param._risk_object = dest
action.risk.param._risk_object_type = system
action.risk.param._risk_score = 42
action.risk.param._risk_message = User $user$ is creating an instance $dest$ in a new region for the first time
action.risk.param._risk = [{"risk_object_field": "user", "risk_object_type": "user", "risk_score": 42, "threat_object_field": "user", "threat_object_type": "user"}, {"risk_object_field": "user", "risk_object_type": "user", "risk_score": 42, "threat_object_field": "user", "threat_object_type": "user"}, {"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 42}]
action.risk.param._risk = [{"risk_object_field": "user", "risk_object_type": "user", "risk_score": 42}]
action.risk.param.verbose = 0
cron_schedule = 0 * * * *
dispatch.earliest_time = -70m@m
@@ -1075,11 +1000,8 @@ action.escu.product = ["Splunk Security Analytics for AWS", "Splunk Enterprise",
action.escu.providing_technologies = []
action.escu.analytic_story = ["Cloud Cryptomining"]
action.risk = 1
action.risk.param._risk_object = dest
action.risk.param._risk_object_type = system
action.risk.param._risk_score = 36
action.risk.param._risk_message = User $user$ is creating an instance $dest$ with an image that has not been previously seen.
action.risk.param._risk = [{"risk_object_field": "user", "risk_object_type": "user", "risk_score": 36, "threat_object_field": "user", "threat_object_type": "user"}, {"risk_object_field": "user", "risk_object_type": "user", "risk_score": 36, "threat_object_field": "user", "threat_object_type": "user"}, {"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 36}]
action.risk.param._risk = [{"risk_object_field": "user", "risk_object_type": "user", "risk_score": 36}]
action.risk.param.verbose = 0
cron_schedule = 0 * * * *
dispatch.earliest_time = -70m@m
@@ -1117,18 +1039,15 @@ action.escu.product = ["Splunk Security Analytics for AWS", "Splunk Enterprise",
action.escu.providing_technologies = []
action.escu.analytic_story = ["Cloud Cryptomining"]
action.risk = 1
action.risk.param._risk_object = dest
action.risk.param._risk_object_type = system
action.risk.param._risk_score = 30
action.risk.param._risk_message = User $user$ is creating an instance $dest$ with an instance type $instance_type$ that has not been previously seen.
action.risk.param._risk = [{"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 30}]
action.risk.param._risk = [{"risk_object_field": "user", "risk_object_type": "user", "risk_score": 30}]
action.risk.param.verbose = 0
cron_schedule = 0 * * * *
dispatch.earliest_time = -70m@m
dispatch.latest_time = -10m@m
action.correlationsearch.enabled = 1
action.correlationsearch.label = ESCU - Cloud Compute Instance Created With Previously Unseen Instance Type - Rule
action.correlationsearch.annotations = {"analytic_story": ["Cloud Cryptomining"], "cis20": ["CIS 1"], "confidence": 60, "context": ["Source:Cloud Data", "Scope:External", "Outcome:Allowed", "Stage:Execution"], "impact": 50, "nist": ["ID.AM"], "observable": [{"name": "dest", "role": ["Victim"], "type": "Endpoint"}]}
action.correlationsearch.annotations = {"analytic_story": ["Cloud Cryptomining"], "cis20": ["CIS 1"], "confidence": 60, "context": ["Source:Cloud Data", "Scope:External", "Outcome:Allowed", "Stage:Execution"], "impact": 50, "nist": ["ID.AM"], "observable": [{"name": "user", "role": ["Attacker"], "type": "User"}, {"name": "dest", "role": ["Victim"], "type": "Endpoint"}]}
schedule_window = auto
alert.digest_mode = 1
disabled = false
@@ -1159,11 +1078,8 @@ action.escu.product = ["Splunk Security Analytics for AWS", "Splunk Enterprise",
action.escu.providing_technologies = []
action.escu.analytic_story = ["Suspicious Cloud Instance Activities"]
action.risk = 1
action.risk.param._risk_object = dest
action.risk.param._risk_object_type = system
action.risk.param._risk_score = 42
action.risk.param._risk_message = User $user$ is modifying an instance $dest$ for the first time.
action.risk.param._risk = [{"risk_object_field": "user", "risk_object_type": "user", "risk_score": 42, "threat_object_field": "user", "threat_object_type": "user"}, {"risk_object_field": "user", "risk_object_type": "user", "risk_score": 42, "threat_object_field": "user", "threat_object_type": "user"}, {"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 42}]
action.risk.param._risk = [{"risk_object_field": "user", "risk_object_type": "user", "risk_score": 42}]
action.risk.param.verbose = 0
cron_schedule = 0 * * * *
dispatch.earliest_time = -70m@m
@@ -1202,11 +1118,8 @@ action.escu.product = ["Splunk Security Analytics for AWS", "Splunk Enterprise",
action.escu.providing_technologies = []
action.escu.analytic_story = ["Suspicious Cloud Provisioning Activities"]
action.risk = 1
action.risk.param._risk_object = dest
action.risk.param._risk_object_type = system
action.risk.param._risk_score = 18
action.risk.param._risk_message = User $user$ is starting or creating an instance $dest$ for the first time in City $City$ from IP address $src$
action.risk.param._risk = [{"risk_object_field": "user", "risk_object_type": "user", "risk_score": 18, "threat_object_field": "user", "threat_object_type": "user"}, {"risk_object_field": "user", "risk_object_type": "user", "risk_score": 18, "threat_object_field": "user", "threat_object_type": "user"}, {"risk_object_field": "src", "risk_object_type": "system", "risk_score": 18, "threat_object_field": "src", "threat_object_type": "ip address"}, {"risk_object_field": "src", "risk_object_type": "system", "risk_score": 18, "threat_object_field": "src", "threat_object_type": "ip address"}, {"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 18}]
action.risk.param._risk = [{"risk_object_field": "user", "risk_object_type": "user", "risk_score": 18}, {"risk_object_field": "src", "risk_object_type": "system", "risk_score": 18}]
action.risk.param.verbose = 0
cron_schedule = 0 * * * *
dispatch.earliest_time = -70m@m
@@ -1245,11 +1158,8 @@ action.escu.product = ["Splunk Security Analytics for AWS", "Splunk Enterprise",
action.escu.providing_technologies = []
action.escu.analytic_story = ["Suspicious Cloud Provisioning Activities"]
action.risk = 1
action.risk.param._risk_object = object
action.risk.param._risk_object_type = system
action.risk.param._risk_score = 42
action.risk.param._risk_message = User $user$ is starting or creating an instance $object$ for the first time in Country $Country$ from IP address $src$
action.risk.param._risk = [{"risk_object_field": "user", "risk_object_type": "user", "risk_score": 42, "threat_object_field": "user", "threat_object_type": "user"}, {"risk_object_field": "user", "risk_object_type": "user", "risk_score": 42, "threat_object_field": "user", "threat_object_type": "user"}, {"risk_object_field": "src", "risk_object_type": "system", "risk_score": 42, "threat_object_field": "src", "threat_object_type": "ip address"}, {"risk_object_field": "src", "risk_object_type": "system", "risk_score": 42, "threat_object_field": "src", "threat_object_type": "ip address"}, {"risk_object_field": "object", "risk_object_type": "system", "risk_score": 42}]
action.risk.param._risk = [{"risk_object_field": "user", "risk_object_type": "user", "risk_score": 42}, {"risk_object_field": "src", "risk_object_type": "system", "risk_score": 42}]
action.risk.param.verbose = 0
cron_schedule = 0 * * * *
dispatch.earliest_time = -70m@m
@@ -1288,11 +1198,8 @@ action.escu.product = ["Splunk Security Analytics for AWS", "Splunk Enterprise",
action.escu.providing_technologies = []
action.escu.analytic_story = ["Suspicious Cloud Provisioning Activities"]
action.risk = 1
action.risk.param._risk_object = object_id
action.risk.param._risk_object_type = system
action.risk.param._risk_score = 42
action.risk.param._risk_message = User $user$ is starting or creating an instance $object_id$ for the first time from IP address $src$
action.risk.param._risk = [{"risk_object_field": "user", "risk_object_type": "user", "risk_score": 42, "threat_object_field": "user", "threat_object_type": "user"}, {"risk_object_field": "user", "risk_object_type": "user", "risk_score": 42, "threat_object_field": "user", "threat_object_type": "user"}, {"risk_object_field": "src", "risk_object_type": "system", "risk_score": 42, "threat_object_field": "src", "threat_object_type": "ip address"}, {"risk_object_field": "src", "risk_object_type": "system", "risk_score": 42, "threat_object_field": "src", "threat_object_type": "ip address"}, {"risk_object_field": "object_id", "risk_object_type": "system", "risk_score": 42}]
action.risk.param._risk = [{"risk_object_field": "user", "risk_object_type": "user", "risk_score": 42}, {"risk_object_field": "src", "risk_object_type": "system", "risk_score": 42}]
action.risk.param.verbose = 0
cron_schedule = 0 * * * *
dispatch.earliest_time = -70m@m
@@ -1331,11 +1238,8 @@ action.escu.product = ["Splunk Security Analytics for AWS", "Splunk Enterprise",
action.escu.providing_technologies = []
action.escu.analytic_story = ["Suspicious Cloud Provisioning Activities"]
action.risk = 1
action.risk.param._risk_object = object
action.risk.param._risk_object_type = system
action.risk.param._risk_score = 42
action.risk.param._risk_message = User $user$ is starting or creating an instance $object$ for the first time in region $Region$ from IP address $src$
action.risk.param._risk = [{"risk_object_field": "user", "risk_object_type": "user", "risk_score": 42, "threat_object_field": "user", "threat_object_type": "user"}, {"risk_object_field": "user", "risk_object_type": "user", "risk_score": 42, "threat_object_field": "user", "threat_object_type": "user"}, {"risk_object_field": "src", "risk_object_type": "system", "risk_score": 42, "threat_object_field": "src", "threat_object_type": "ip address"}, {"risk_object_field": "src", "risk_object_type": "system", "risk_score": 42, "threat_object_field": "src", "threat_object_type": "ip address"}, {"risk_object_field": "object", "risk_object_type": "system", "risk_score": 42}]
action.risk.param._risk = [{"risk_object_field": "user", "risk_object_type": "user", "risk_score": 42}, {"risk_object_field": "src", "risk_object_type": "system", "risk_score": 42}]
action.risk.param.verbose = 0
cron_schedule = 0 * * * *
dispatch.earliest_time = -70m@m
@@ -1373,11 +1277,8 @@ action.escu.product = ["Splunk Security Analytics for AWS", "Splunk Enterprise",
action.escu.providing_technologies = []
action.escu.analytic_story = ["Suspicious Cloud Authentication Activities"]
action.risk = 1
action.risk.param._risk_object = user
action.risk.param._risk_object_type = user
action.risk.param._risk_score = 30
action.risk.param._risk_message = User $user$ is logging into the AWS console for the first time
action.risk.param._risk = [{"risk_object_field": "user", "risk_object_type": "user", "risk_score": 30, "threat_object_field": "user", "threat_object_type": "user"}, {"risk_object_field": "user", "risk_object_type": "user", "risk_score": 30, "threat_object_field": "user", "threat_object_type": "user"}]
action.risk.param._risk = [{"risk_object_field": "user", "risk_object_type": "user", "risk_score": 30}]
action.risk.param.verbose = 0
cron_schedule = 0 * * * *
dispatch.earliest_time = -70m@m
@@ -1415,11 +1316,8 @@ action.escu.product = ["Splunk Security Analytics for AWS", "Splunk Enterprise",
action.escu.providing_technologies = []
action.escu.analytic_story = ["Suspicious AWS Login Activities", "Suspicious Cloud Authentication Activities"]
action.risk = 1
action.risk.param._risk_object = user
action.risk.param._risk_object_type = user
action.risk.param._risk_score = 18
action.risk.param._risk_message = User $user$ is logging into the AWS console from City $City$ for the first time
action.risk.param._risk = [{"risk_object_field": "user", "risk_object_type": "user", "risk_score": 18, "threat_object_field": "user", "threat_object_type": "user"}, {"risk_object_field": "user", "risk_object_type": "user", "risk_score": 18, "threat_object_field": "user", "threat_object_type": "user"}]
action.risk.param._risk = [{"risk_object_field": "user", "risk_object_type": "user", "risk_score": 18}]
action.risk.param.verbose = 0
cron_schedule = 0 * * * *
dispatch.earliest_time = -70m@m
@@ -1457,11 +1355,8 @@ action.escu.product = ["Splunk Security Analytics for AWS", "Splunk Enterprise",
action.escu.providing_technologies = []
action.escu.analytic_story = ["Suspicious AWS Login Activities", "Suspicious Cloud Authentication Activities"]
action.risk = 1
action.risk.param._risk_object = user
action.risk.param._risk_object_type = user
action.risk.param._risk_score = 42
action.risk.param._risk_message = User $user$ is logging into the AWS console from Country $Country$ for the first time
action.risk.param._risk = [{"risk_object_field": "user", "risk_object_type": "user", "risk_score": 42, "threat_object_field": "user", "threat_object_type": "user"}, {"risk_object_field": "user", "risk_object_type": "user", "risk_score": 42, "threat_object_field": "user", "threat_object_type": "user"}]
action.risk.param._risk = [{"risk_object_field": "user", "risk_object_type": "user", "risk_score": 42}]
action.risk.param.verbose = 0
cron_schedule = 0 * * * *
dispatch.earliest_time = -70m@m
@@ -1499,11 +1394,8 @@ action.escu.product = ["Splunk Security Analytics for AWS", "Splunk Enterprise",
action.escu.providing_technologies = []
action.escu.analytic_story = ["Suspicious AWS Login Activities", "Suspicious Cloud Authentication Activities"]
action.risk = 1
action.risk.param._risk_object = user
action.risk.param._risk_object_type = user
action.risk.param._risk_score = 36
action.risk.param._risk_message = User $user$ is logging into the AWS console from Region $Region$ for the first time
action.risk.param._risk = [{"risk_object_field": "user", "risk_object_type": "user", "risk_score": 36, "threat_object_field": "user", "threat_object_type": "user"}, {"risk_object_field": "user", "risk_object_type": "user", "risk_score": 36, "threat_object_field": "user", "threat_object_type": "user"}]
action.risk.param._risk = [{"risk_object_field": "user", "risk_object_type": "user", "risk_score": 36}]
action.risk.param.verbose = 0
cron_schedule = 0 * * * *
dispatch.earliest_time = -70m@m
@@ -1541,11 +1433,8 @@ action.escu.product = ["Splunk Security Analytics for AWS", "Splunk Enterprise",
action.escu.providing_technologies = []
action.escu.analytic_story = ["Suspicious AWS S3 Activities"]
action.risk = 1
action.risk.param._risk_object = userIdentity.userName
action.risk.param._risk_object_type = user
action.risk.param._risk_score = 48
action.risk.param._risk_message = User $userIdentity.userName$ has created an open/public bucket $bucketName$ using AWS CLI with the following permissions - $requestParameters.accessControlList.x-amz-grant-read$ $requestParameters.accessControlList.x-amz-grant-read-acp$ $requestParameters.accessControlList.x-amz-grant-write$ $requestParameters.accessControlList.x-amz-grant-write-acp$ $requestParameters.accessControlList.x-amz-grant-full-control$
action.risk.param._risk = [{"risk_object_field": "userIdentity.userName", "risk_object_type": "user", "risk_score": 48, "threat_object_field": "userIdentity.userName", "threat_object_type": "user"}, {"risk_object_field": "userIdentity.userName", "risk_object_type": "user", "risk_score": 48, "threat_object_field": "userIdentity.userName", "threat_object_type": "user"}, {"threat_object_field": "bucketName", "threat_object_type": "other"}]
action.risk.param._risk = [{"risk_object_field": "userIdentity.userName", "risk_object_type": "user", "risk_score": 48}, {"threat_object_field": "bucketName", "threat_object_type": "other"}]
action.risk.param.verbose = 0
cron_schedule = 0 * * * *
dispatch.earliest_time = -70m@m
@@ -1583,11 +1472,8 @@ action.escu.product = ["Splunk Security Analytics for AWS", "Splunk Enterprise",
action.escu.providing_technologies = []
action.escu.analytic_story = ["Suspicious AWS S3 Activities"]
action.risk = 1
action.risk.param._risk_object = user_arn
action.risk.param._risk_object_type = user
action.risk.param._risk_score = 48
action.risk.param._risk_message = User $user_arn$ has created an open/public bucket $bucketName$ with the following permissions $permission$
action.risk.param._risk = [{"risk_object_field": "user_arn", "risk_object_type": "user", "risk_score": 48, "threat_object_field": "user_arn", "threat_object_type": "user"}, {"risk_object_field": "user_arn", "risk_object_type": "user", "risk_score": 48, "threat_object_field": "user_arn", "threat_object_type": "user"}, {"threat_object_field": "bucketName", "threat_object_type": "other"}]
action.risk.param._risk = [{"risk_object_field": "user_arn", "risk_object_type": "user", "risk_score": 48}, {"threat_object_field": "bucketName", "threat_object_type": "other"}]
action.risk.param.verbose = 0
cron_schedule = 0 * * * *
dispatch.earliest_time = -70m@m
@@ -1611,7 +1497,7 @@ search = `cloudtrail` eventSource=s3.amazonaws.com eventName=PutBucketAcl | rex
action.escu = 0
action.escu.enabled = 1
description = This search looks for a spike in number of of AWS security Hub alerts for an EC2 instance in 4 hours intervals
action.escu.mappings = {"cis20": ["CIS 13"], "nist": ["DE.DP", "DE.AE"]}
action.escu.mappings = {"cis20": ["CIS 13"], "nist": ["DE.DP"]}
action.escu.data_models = []
action.escu.eli5 = This search looks for a spike in number of of AWS security Hub alerts for an EC2 instance in 4 hours intervals
action.escu.how_to_implement = You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add-on for AWS (version 4.4.0 or later), then configure your Security Hub inputs. The threshold_value should be tuned to your environment and schedule these searches according to the bucket span interval.
@@ -1625,10 +1511,7 @@ action.escu.product = ["Splunk Security Analytics for AWS", "Splunk Enterprise",
action.escu.providing_technologies = []
action.escu.analytic_story = ["AWS Security Hub Alerts"]
action.risk = 1
action.risk.param._risk_object =
action.risk.param._risk_object_type =
action.risk.param._risk_score = 20
action.risk.param._risk_message =
action.risk.param._risk_message = Spike in AWS security Hub alerts with title $Title$ for EC2 instance $dest$
action.risk.param._risk = []
action.risk.param.verbose = 0
cron_schedule = 0 * * * *
@@ -1636,7 +1519,7 @@ dispatch.earliest_time = -70m@m
dispatch.latest_time = -10m@m
action.correlationsearch.enabled = 1
action.correlationsearch.label = ESCU - Detect Spike in AWS Security Hub Alerts for EC2 Instance - Rule
action.correlationsearch.annotations = {"analytic_story": ["AWS Security Hub Alerts"], "cis20": ["CIS 13"], "nist": ["DE.DP", "DE.AE"]}
action.correlationsearch.annotations = {"analytic_story": ["AWS Security Hub Alerts"], "cis20": ["CIS 13"], "confidence": 50, "context": ["Source:Cloud Data", "Stage:Execution"], "impact": 30, "nist": ["DE.DP"], "observable": [{"name": "dest", "role": ["Victim"], "type": "Endpoint"}]}
schedule_window = auto
alert.digest_mode = 1
disabled = false
@@ -1667,11 +1550,8 @@ action.escu.product = ["Splunk Security Analytics for AWS", "Splunk Enterprise",
action.escu.providing_technologies = []
action.escu.analytic_story = ["Suspicious Cloud Instance Activities", "Data Exfiltration"]
action.risk = 1
action.risk.param._risk_object = src_ip
action.risk.param._risk_object_type = system
action.risk.param._risk_score = 48
action.risk.param._risk_message = AWS EC2 snapshot from account $aws_account_id$ is shared with $requested_account_id$ by user $user_arn$ from $src_ip$
action.risk.param._risk = [{"risk_object_field": "user_arn", "risk_object_type": "user", "risk_score": 48, "threat_object_field": "user_arn", "threat_object_type": "user"}, {"risk_object_field": "user_arn", "risk_object_type": "user", "risk_score": 48, "threat_object_field": "user_arn", "threat_object_type": "user"}, {"risk_object_field": "src_ip", "risk_object_type": "system", "risk_score": 48, "threat_object_field": "src_ip", "threat_object_type": "ip address"}, {"risk_object_field": "src_ip", "risk_object_type": "system", "risk_score": 48, "threat_object_field": "src_ip", "threat_object_type": "ip address"}]
action.risk.param._risk = [{"risk_object_field": "user_arn", "risk_object_type": "user", "risk_score": 48}, {"risk_object_field": "src_ip", "risk_object_type": "system", "risk_score": 48}]
action.risk.param.verbose = 0
cron_schedule = 0 * * * *
dispatch.earliest_time = -70m@m
@@ -1709,11 +1589,8 @@ action.escu.product = ["Splunk Security Analytics for AWS", "Splunk Enterprise",
action.escu.providing_technologies = []
action.escu.analytic_story = ["Office 365 Detections", "Cloud Federated Credential Abuse"]
action.risk = 1
action.risk.param._risk_object = dest
action.risk.param._risk_object_type = system
action.risk.param._risk_score = 18
action.risk.param._risk_message = User $Actor.ID$ has created a new federation setting on $dest$ from IP Address $ActorIpAddress$
action.risk.param._risk = [{"risk_object_field": "ActorIpAddress", "risk_object_type": "system", "risk_score": 18, "threat_object_field": "ActorIpAddress", "threat_object_type": "ip address"}, {"risk_object_field": "ActorIpAddress", "risk_object_type": "system", "risk_score": 18, "threat_object_field": "ActorIpAddress", "threat_object_type": "ip address"}, {"risk_object_field": "Actor.ID", "risk_object_type": "user", "risk_score": 18, "threat_object_field": "Actor.ID", "threat_object_type": "user"}, {"risk_object_field": "Actor.ID", "risk_object_type": "user", "risk_score": 18, "threat_object_field": "Actor.ID", "threat_object_type": "user"}, {"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 18}]
action.risk.param._risk = [{"risk_object_field": "ActorIpAddress", "risk_object_type": "system", "risk_score": 18}, {"risk_object_field": "Actor.ID", "risk_object_type": "user", "risk_score": 18}]
action.risk.param.verbose = 0
cron_schedule = 0 * * * *
dispatch.earliest_time = -70m@m
@@ -1751,11 +1628,8 @@ action.escu.product = ["Splunk Security Analytics for AWS", "Splunk Enterprise",
action.escu.providing_technologies = []
action.escu.analytic_story = ["Office 365 Detections", "Cloud Federated Credential Abuse"]
action.risk = 1
action.risk.param._risk_object = Target.ID
action.risk.param._risk_object_type = system
action.risk.param._risk_score = 42
action.risk.param._risk_message = User $Actor.ID$ created a new federation setting on $Target.ID$ and added service principal credentials from IP Address $ActorIpAddress$
action.risk.param._risk = [{"risk_object_field": "ActorIpAddress", "risk_object_type": "system", "risk_score": 42, "threat_object_field": "ActorIpAddress", "threat_object_type": "ip address"}, {"risk_object_field": "ActorIpAddress", "risk_object_type": "system", "risk_score": 42, "threat_object_field": "ActorIpAddress", "threat_object_type": "ip address"}, {"risk_object_field": "Target.ID", "risk_object_type": "system", "risk_score": 42}]
action.risk.param._risk = [{"risk_object_field": "ActorIpAddress", "risk_object_type": "system", "risk_score": 42}]
action.risk.param.verbose = 0
cron_schedule = 0 * * * *
dispatch.earliest_time = -70m@m
@@ -1793,11 +1667,8 @@ action.escu.product = ["Splunk Security Analytics for AWS", "Splunk Enterprise",
action.escu.providing_technologies = []
action.escu.analytic_story = ["Office 365 Detections"]
action.risk = 1
action.risk.param._risk_object = user_id
action.risk.param._risk_object_type = user
action.risk.param._risk_score = 42
action.risk.param._risk_message = User $user_id$ has added new IP addresses $ip_addresses_new_added$ to a list of trusted IPs to bypass MFA
action.risk.param._risk = [{"risk_object_field": "ip_addresses_new_added", "risk_object_type": "system", "risk_score": 42, "threat_object_field": "ip_addresses_new_added", "threat_object_type": "ip address"}, {"risk_object_field": "ip_addresses_new_added", "risk_object_type": "system", "risk_score": 42, "threat_object_field": "ip_addresses_new_added", "threat_object_type": "ip address"}, {"risk_object_field": "user_id", "risk_object_type": "user", "risk_score": 42, "threat_object_field": "user_id", "threat_object_type": "user"}, {"risk_object_field": "user_id", "risk_object_type": "user", "risk_score": 42, "threat_object_field": "user_id", "threat_object_type": "user"}]
action.risk.param._risk = [{"risk_object_field": "ip_addresses_new_added", "risk_object_type": "system", "risk_score": 42}, {"risk_object_field": "user_id", "risk_object_type": "user", "risk_score": 42}]
action.risk.param.verbose = 0
cron_schedule = 0 * * * *
dispatch.earliest_time = -70m@m
@@ -1835,11 +1706,8 @@ action.escu.product = ["Splunk Security Analytics for AWS", "Splunk Enterprise",
action.escu.providing_technologies = []
action.escu.analytic_story = ["Office 365 Detections"]
action.risk = 1
action.risk.param._risk_object = user
action.risk.param._risk_object_type = user
action.risk.param._risk_score = 64
action.risk.param._risk_message = User $user$ has executed an operation $Operation$ for this destination $dest$
action.risk.param._risk = [{"risk_object_field": "dest", "risk_object_type": "system", "risk_score": 64}, {"risk_object_field": "user", "risk_object_type": "user", "risk_score": 64, "threat_object_field": "user", "threat_object_type": "user"}, {"risk_object_field": "user", "risk_object_type": "user", "risk_score": 64, "threat_object_field": "user", "threat_object_type": "user"}]
action.risk.param._risk = [{"risk_object_field": "user", "risk_object_type": "user", "risk_score": 64}]
action.risk.param.verbose = 0
cron_schedule = 0 * * * *
dispatch.earliest_time = -70m@m
@@ -1877,11 +1745,8 @@ action.escu.product = ["Splunk Security Analytics for AWS", "Splunk Enterprise",
action.escu.providing_technologies = []
action.escu.analytic_story = ["Office 365 Detections"]
action.risk = 1
action.risk.param._risk_object = user
action.risk.param._risk_object_type = user
action.risk.param._risk_score = 64
action.risk.param._risk_message = User $user$ has caused excessive number of authentication failures from $src_ip$ using UserAgent $UserAgent$.
action.risk.param._risk = [{"risk_object_field": "src_ip", "risk_object_type": "system", "risk_score": 64, "threat_object_field": "src_ip", "threat_object_type": "ip address"}, {"risk_object_field": "src_ip", "risk_object_type": "system", "risk_score": 64, "threat_object_field": "src_ip", "threat_object_type": "ip address"}, {"risk_object_field": "user", "risk_object_type": "user", "risk_score": 64}]
action.risk.param._risk = [{"risk_object_field": "src_ip", "risk_object_type": "system", "risk_score": 64}]
action.risk.param.verbose = 0
cron_schedule = 0 * * * *
dispatch.earliest_time = -70m@m
@@ -1919,11 +1784,8 @@ action.escu.product = ["Splunk Security Analytics for AWS", "Splunk Enterprise",
action.escu.providing_technologies = []
action.escu.analytic_story = ["Office 365 Detections", "Cloud Federated Credential Abuse"]
action.risk = 1
action.risk.param._risk_object = UserId
action.risk.param._risk_object_type = user
action.risk.param._risk_score = 64
action.risk.param._risk_message = User $UserId$ has caused excessive number of SSO logon errors from $ActorIpAddress$ using UserAgent $UserAgent$.
action.risk.param._risk = [{"risk_object_field": "ActorIpAddress", "risk_object_type": "system", "risk_score": 64, "threat_object_field": "ActorIpAddress", "threat_object_type": "ip address"}, {"risk_object_field": "ActorIpAddress", "risk_object_type": "system", "risk_score": 64, "threat_object_field": "ActorIpAddress", "threat_object_type": "ip address"}, {"risk_object_field": "UserId", "risk_object_type": "user", "risk_score": 64}]
action.risk.param._risk = [{"risk_object_field": "ActorIpAddress", "risk_object_type": "system", "risk_score": 64}]
action.risk.param.verbose = 0
cron_schedule = 0 * * * *
dispatch.earliest_time = -70m@m
@@ -1961,11 +1823,8 @@ action.escu.product = ["Splunk Security Analytics for AWS", "Splunk Enterprise",
action.escu.providing_technologies = []
action.escu.analytic_story = ["Office 365 Detections", "Cloud Federated Credential Abuse"]
action.risk = 1
action.risk.param._risk_object = UserId
action.risk.param._risk_object_type = user
action.risk.param._risk_score = 64
action.risk.param._risk_message = User $UserId$ has added a new federated domaain $Parameters.Value$ for $OrganizationName$
action.risk.param._risk = [{"threat_object_field": "OrganizationName", "threat_object_type": "other"}, {"risk_object_field": "UserId", "risk_object_type": "user", "risk_score": 64}]
action.risk.param._risk = [{"threat_object_field": "OrganizationName", "threat_object_type": "other"}]
action.risk.param.verbose = 0
cron_schedule = 0 * * * *
dispatch.earliest_time = -70m@m
@@ -2003,11 +1862,8 @@ action.escu.product = ["Splunk Security Analytics for AWS", "Splunk Enterprise",
action.escu.providing_technologies = []
action.escu.analytic_story = ["Office 365 Detections", "Data Exfiltration"]
action.risk = 1
action.risk.param._risk_object = Source
action.risk.param._risk_object_type = user
action.risk.param._risk_score = 48
action.risk.param._risk_message = User $Source$ has exported a PST file from the search using this operation- $Operation$ with a severity of $Severity$
action.risk.param._risk = [{"risk_object_field": "Source", "risk_object_type": "user", "risk_score": 48, "threat_object_field": "Source", "threat_object_type": "user"}, {"risk_object_field": "Source", "risk_object_type": "user", "risk_score": 48, "threat_object_field": "Source", "threat_object_type": "user"}]
action.risk.param._risk = [{"risk_object_field": "Source", "risk_object_type": "user", "risk_score": 48}]
action.risk.param.verbose = 0
cron_schedule = 0 * * * *
dispatch.earliest_time = -70m@m
@@ -2045,11 +1901,8 @@ action.escu.product = ["Splunk Security Analytics for AWS", "Splunk Enterprise",
action.escu.providing_technologies = []
action.escu.analytic_story = ["Office 365 Detections", "Data Exfiltration"]
action.risk = 1
action.risk.param._risk_object = user
action.risk.param._risk_object_type = user
action.risk.param._risk_score = 48
action.risk.param._risk_message = User $user$ has configured a forwarding rule for multiple mailboxes to the same destination $ForwardingAddress$
action.risk.param._risk = [{"risk_object_field": "user", "risk_object_type": "user", "risk_score": 48, "threat_object_field": "user", "threat_object_type": "user"}, {"risk_object_field": "user", "risk_object_type": "user", "risk_score": 48, "threat_object_field": "user", "threat_object_type": "user"}]
action.risk.param._risk = [{"risk_object_field": "user", "risk_object_type": "user", "risk_score": 48}]
action.risk.param.verbose = 0
cron_schedule = 0 * * * *
dispatch.earliest_time = -70m@m
@@ -2087,11 +1940,8 @@ action.escu.product = ["Splunk Security Analytics for AWS", "Splunk Enterprise",
action.escu.providing_technologies = []
action.escu.analytic_story = ["Office 365 Detections"]
action.risk = 1
action.risk.param._risk_object = user
action.risk.param._risk_object_type = user
action.risk.param._risk_score = 48
action.risk.param._risk_message = User $user$ has delegated suspicious rights $AccessRights$ to user $dest_user$ that allow access to sensitive
action.risk.param._risk = [{"risk_object_field": "user", "risk_object_type": "user", "risk_score": 48, "threat_object_field": "user", "threat_object_type": "user"}, {"risk_object_field": "user", "risk_object_type": "user", "risk_score": 48, "threat_object_field": "user", "threat_object_type": "user"}]
action.risk.param._risk = [{"risk_object_field": "user", "risk_object_type": "user", "risk_score": 48}]
action.risk.param.verbose = 0
cron_schedule = 0 * * * *
dispatch.earliest_time = -70m@m
@@ -2129,11 +1979,8 @@ action.escu.product = ["Splunk Security Analytics for AWS", "Splunk Enterprise",
action.escu.providing_technologies = []
action.escu.analytic_story = ["Office 365 Detections", "Data Exfiltration"]
action.risk = 1
action.risk.param._risk_object = ForwardingSmtpAddress
action.risk.param._risk_object_type = user
action.risk.param._risk_score = 48
action.risk.param._risk_message = User $user$ configured multiple users $src_user$ with a count of $count_src_user$, a forwarding rule to same destination $ForwardingSmtpAddress$
action.risk.param._risk = [{"risk_object_field": "user", "risk_object_type": "user", "risk_score": 48, "threat_object_field": "user", "threat_object_type": "user"}, {"risk_object_field": "user", "risk_object_type": "user", "risk_score": 48, "threat_object_field": "user", "threat_object_type": "user"}, {"risk_object_field": "ForwardingSmtpAddress", "risk_object_type": "user", "risk_score": 48}]
action.risk.param._risk = [{"risk_object_field": "user", "risk_object_type": "user", "risk_score": 48}]
action.risk.param.verbose = 0
cron_schedule = 0 * * * *
dispatch.earliest_time = -70m@m
+1 -1
View File
@@ -1,6 +1,6 @@
#############
# Automatically generated by generator.py in splunk/security_content
# On Date: 2021-07-28T20:06:09 UTC
# On Date: 2021-07-29T20:53:37 UTC
# Author: Splunk Security Research
# Contact: research@splunk.com
#############
+2 -2
View File
@@ -1,6 +1,6 @@
#############
# Automatically generated by generator.py in splunk/security_content
# On Date: 2021-07-28T20:06:09 UTC
# On Date: 2021-07-29T20:53:37 UTC
# Author: Splunk Security Research
# Contact: research@splunk.com
#############
@@ -553,7 +553,7 @@ asset_type = AWS Instance
confidence = medium
explanation = This search looks for a spike in number of of AWS security Hub alerts for an EC2 instance in 4 hours intervals
how_to_implement = You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add-on for AWS (version 4.4.0 or later), then configure your Security Hub inputs. The threshold_value should be tuned to your environment and schedule these searches according to the bucket span interval.
annotations = {"cis20": ["CIS 13"], "nist": ["DE.DP", "DE.AE"]}
annotations = {"cis20": ["CIS 13"], "nist": ["DE.DP"]}
known_false_positives = None
providing_technologies = []
+1 -1
View File
@@ -42288,7 +42288,7 @@ There might be false positives associted with this detection since items like ar
<pre>
#############
# Automatically generated by doc_gen.py in https://github.com/splunk/security_content''
# On Date: 2021-07-28 20:19:18.091984 UTC''
# On Date: 2021-07-29 21:06:56.901053 UTC''
# Author: Splunk Security Research''
# Contact: research@splunk.com''
#############
+1 -1
View File
@@ -7831,7 +7831,7 @@ In March of 2016, adversaries were seen using JexBoss--an open-source utility us
<pre>
#############
# Automatically generated by doc_gen.py in https://github.com/splunk/security_content
# On Date: 2021-07-28 20:19:18.414652 UTC
# On Date: 2021-07-29 21:06:57.254832 UTC
# Author: Splunk Security Research
# Contact: research@splunk.com
#############