From 248986168afc132f5abde666dd7dab154d2ddca9 Mon Sep 17 00:00:00 2001 From: patel-bhavin Date: Tue, 13 Jul 2021 16:00:17 -0500 Subject: [PATCH 1/4] tags --- ...alls_from_previously_unseen_user_roles.yml | 21 +++++++++++--- ...ance_created_by_previously_unseen_user.yml | 29 +++++++++++++++---- ...ce_created_in_previously_unused_region.yml | 24 ++++++++++++--- ...e_created_with_previously_unseen_image.yml | 24 ++++++++++++--- ...d_with_previously_unseen_instance_type.yml | 25 +++++++++++++--- ...e_modified_with_previously_unseen_user.yml | 24 ++++++++++++--- 6 files changed, 121 insertions(+), 26 deletions(-) diff --git a/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml b/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml index 6e4aee9e77..7a452f7eee 100644 --- a/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml +++ b/detections/cloud/cloud_api_calls_from_previously_unseen_user_roles.yml @@ -51,7 +51,20 @@ tags: - All_Changes.status - All_Changes.command - All_Changes.object - risk_object: user - risk_object_type: user - risk_score: 25 - security_domain: endpoint + impact: 60 + confidence: 60 + # (impact * confidence)/100 + risk_score: 36 + context: + - Source:Cloud Data + - Scope:External + - Outcome:Allowed + - Stage:Recon + - Stage:Execution + message: User $user$ of type AssumedRole attempting to execute new API calls $command$ that have not been seen before + observable: + - name: user + type: user + role: + - Attacker + security_domain: threat diff --git a/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml b/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml index 6d8f20e18d..70990ec77f 100644 --- a/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml +++ b/detections/cloud/cloud_compute_instance_created_by_previously_unseen_user.yml @@ -1,7 +1,7 @@ name: Cloud Compute Instance Created By Previously Unseen User id: 37a0ec8d-827e-4d6d-8025-cedf31f3a149 -version: 1 -date: '2020-08-21' +version: 2 +date: '2021-07-13' author: Rico Valdez, Splunk type: batch datamodel: @@ -48,7 +48,24 @@ tags: - All_Changes.action - All_Changes.user - All_Changes.vendor_region - risk_object: user - risk_object_type: user - risk_score: 20 - security_domain: endpoint + impact: 30 + confidence: 60 + # (impact * confidence)/100 + risk_score: 18 + context: + - Source:Cloud Data + - Scope:External + - Outcome:Allowed + - Stage:Recon + - Stage:Execution + message: User $user$ is creating a new instance $dest$ for the first time + observable: + - name: user + type: User + role: + - Attacker + - name: dest + type: Endpoint + role: + - Victim + security_domain: threat \ No newline at end of file diff --git a/detections/cloud/cloud_compute_instance_created_in_previously_unused_region.yml b/detections/cloud/cloud_compute_instance_created_in_previously_unused_region.yml index 5181900d57..670addb3b1 100644 --- a/detections/cloud/cloud_compute_instance_created_in_previously_unused_region.yml +++ b/detections/cloud/cloud_compute_instance_created_in_previously_unused_region.yml @@ -54,7 +54,23 @@ tags: - All_Changes.action - All_Changes.vendor_region - All_Changes.user - risk_object: user - risk_object_type: user - risk_score: 20 - security_domain: network + impact: 70 + confidence: 60 + # (impact * confidence)/100 + risk_score: 42 + context: + - Source:Cloud Data + - Scope:External + - Outcome:Allowed + - Stage:Execution + message: User $user$ is creating an instance $dest$ in a new region for the first time + observable: + - name: user + type: user + role: + - Attacker + - name: dest + type: Endpoint + role: + - Victim + security_domain: threat \ No newline at end of file diff --git a/detections/cloud/cloud_compute_instance_created_with_previously_unseen_image.yml b/detections/cloud/cloud_compute_instance_created_with_previously_unseen_image.yml index 068b7651d9..fc0f43dbe5 100644 --- a/detections/cloud/cloud_compute_instance_created_with_previously_unseen_image.yml +++ b/detections/cloud/cloud_compute_instance_created_with_previously_unseen_image.yml @@ -49,7 +49,23 @@ tags: - All_Changes.action - All_Changes.Instance_Changes.image_id - All_Changes.user - risk_object: user - risk_object_type: user - risk_score: 20 - security_domain: endpoint + impact: 30 + confidence: 60 + # (impact * confidence)/100 + risk_score: 18 + context: + - Source:Cloud Data + - Scope:External + - Outcome:Allowed + - Stage:Execution + message: User $user$ is creating an instance $dest$ with an image that has not been previously seen. + observable: + - name: user + type: User + role: + - Attacker + - name: dest + type: Endpoint + role: + - Victim + security_domain: threat \ No newline at end of file diff --git a/detections/cloud/cloud_compute_instance_created_with_previously_unseen_instance_type.yml b/detections/cloud/cloud_compute_instance_created_with_previously_unseen_instance_type.yml index 30e8096950..86e66346fc 100644 --- a/detections/cloud/cloud_compute_instance_created_with_previously_unseen_instance_type.yml +++ b/detections/cloud/cloud_compute_instance_created_with_previously_unseen_instance_type.yml @@ -49,7 +49,24 @@ tags: - All_Changes.action - All_Changes.Instance_Changes.instance_type - All_Changes.user - risk_object: user - risk_object_type: user - risk_score: 20 - security_domain: endpoint + impact: 30 + confidence: 60 + # (impact * confidence)/100 + risk_score: 18 + context: + - Source:Cloud Data + - Scope:External + - Outcome:Allowed + - Stage:Execution + message: User $user$ is creating an instance $dest$ with an instance type $instance_type$ that has not been previously seen. + observable: + - name: user + type: User + role: + - Attacker + observable: + - name: dest + type: Endpoint + role: + - Victim + security_domain: threat \ No newline at end of file diff --git a/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml b/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml index 810320d61c..a23043e266 100644 --- a/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml +++ b/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml @@ -51,7 +51,23 @@ tags: - All_Changes.change_type - All_Changes.status - All_Changes.user - risk_object: user - risk_object_type: user - risk_score: 10 - security_domain: endpoint + impact: 30 + confidence: 60 + # (impact * confidence)/100 + risk_score: 18 + context: + - Source:Cloud Data + - Scope:External + - Outcome:Allowed + - Stage:Execution + message: User $user$ is modifying an instance $dest$ for the first time. + observable: + - name: user + type: User + role: + - Attacker + - name: dest + type: Endpoint + role: + - Victim + security_domain: threat \ No newline at end of file From 286e3a79ad9960858b8d6c34999733eef63f38de Mon Sep 17 00:00:00 2001 From: patel-bhavin Date: Tue, 13 Jul 2021 16:31:37 -0500 Subject: [PATCH 2/4] next 6 --- ...e_created_with_previously_unseen_image.yml | 4 +-- ...d_with_previously_unseen_instance_type.yml | 4 +-- ...e_modified_with_previously_unseen_user.yml | 4 +-- ...ovisioning_from_previously_unseen_city.yml | 28 ++++++++++++++++--- ...sioning_from_previously_unseen_country.yml | 28 ++++++++++++++++--- ...ning_from_previously_unseen_ip_address.yml | 28 ++++++++++++++++--- ...isioning_from_previously_unseen_region.yml | 28 ++++++++++++++++--- 7 files changed, 102 insertions(+), 22 deletions(-) diff --git a/detections/cloud/cloud_compute_instance_created_with_previously_unseen_image.yml b/detections/cloud/cloud_compute_instance_created_with_previously_unseen_image.yml index fc0f43dbe5..30b44ec8c6 100644 --- a/detections/cloud/cloud_compute_instance_created_with_previously_unseen_image.yml +++ b/detections/cloud/cloud_compute_instance_created_with_previously_unseen_image.yml @@ -49,10 +49,10 @@ tags: - All_Changes.action - All_Changes.Instance_Changes.image_id - All_Changes.user - impact: 30 + impact: 60 confidence: 60 # (impact * confidence)/100 - risk_score: 18 + risk_score: 36 context: - Source:Cloud Data - Scope:External diff --git a/detections/cloud/cloud_compute_instance_created_with_previously_unseen_instance_type.yml b/detections/cloud/cloud_compute_instance_created_with_previously_unseen_instance_type.yml index 86e66346fc..cd39c63f5f 100644 --- a/detections/cloud/cloud_compute_instance_created_with_previously_unseen_instance_type.yml +++ b/detections/cloud/cloud_compute_instance_created_with_previously_unseen_instance_type.yml @@ -49,10 +49,10 @@ tags: - All_Changes.action - All_Changes.Instance_Changes.instance_type - All_Changes.user - impact: 30 + impact: 50 confidence: 60 # (impact * confidence)/100 - risk_score: 18 + risk_score: 36 context: - Source:Cloud Data - Scope:External diff --git a/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml b/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml index a23043e266..5f8c0e7590 100644 --- a/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml +++ b/detections/cloud/cloud_instance_modified_with_previously_unseen_user.yml @@ -51,10 +51,10 @@ tags: - All_Changes.change_type - All_Changes.status - All_Changes.user - impact: 30 + impact: 70 confidence: 60 # (impact * confidence)/100 - risk_score: 18 + risk_score: 42 context: - Source:Cloud Data - Scope:External diff --git a/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml b/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml index aa1b0b25d6..ad2c97f674 100644 --- a/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml +++ b/detections/cloud/cloud_provisioning_from_previously_unseen_city.yml @@ -66,7 +66,27 @@ tags: - All_Changes.user - All_Changes.object - All_Changes.command - risk_object: user - risk_object_type: user - risk_score: 10 - security_domain: endpoint + impact: 30 + confidence: 60 + # (impact * confidence)/100 + risk_score: 18 + context: + - Source:Cloud Data + - Scope:External + - Outcome:Allowed + - Stage:Execution + message: User $user$ is starting or creating an instance $dest$ for the first time in City $City$ from IP address $src$ + observable: + - name: user + type: User + role: + - Attacker + - name: src + type: IP Address + role: + - Attacker + - name: dest + type: Endpoint + role: + - Victim + security_domain: threat \ No newline at end of file diff --git a/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml b/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml index daa8caf0d3..d9c3c6cca8 100644 --- a/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml +++ b/detections/cloud/cloud_provisioning_from_previously_unseen_country.yml @@ -66,7 +66,27 @@ tags: - All_Changes.user - All_Changes.object - All_Changes.command - risk_object: user - risk_object_type: user - risk_score: 5 - security_domain: endpoint + impact: 70 + confidence: 60 + # (impact * confidence)/100 + risk_score: 42 + context: + - Source:Cloud Data + - Scope:External + - Outcome:Allowed + - Stage:Execution + message: User $user$ is starting or creating an instance $object$ for the first time in Country $Country$ from IP address $src$ + observable: + - name: user + type: User + role: + - Attacker + - name: src + type: IP Address + role: + - Attacker + - name: object + type: Endpoint + role: + - Victim + security_domain: threat \ No newline at end of file diff --git a/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml b/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml index b96889ae17..5290034a63 100644 --- a/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml +++ b/detections/cloud/cloud_provisioning_from_previously_unseen_ip_address.yml @@ -65,7 +65,27 @@ tags: - All_Changes.src - All_Changes.user - All_Changes.command - risk_object: user - risk_object_type: user - risk_score: 5 - security_domain: endpoint + impact: 70 + confidence: 60 + # (impact * confidence)/100 + risk_score: 42 + context: + - Source:Cloud Data + - Scope:External + - Outcome:Allowed + - Stage:Execution + message: User $user$ is starting or creating an instance $object_id$ for the first time from IP address $src$ + observable: + - name: user + type: User + role: + - Attacker + - name: src + type: IP Address + role: + - Attacker + - name: object_id + type: Endpoint + role: + - Victim + security_domain: threat \ No newline at end of file diff --git a/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml b/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml index 41446e109c..13c115d37e 100644 --- a/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml +++ b/detections/cloud/cloud_provisioning_from_previously_unseen_region.yml @@ -66,7 +66,27 @@ tags: - All_Changes.user - All_Changes.object - All_Changes.command - risk_object: user - risk_object_type: user - risk_score: 5 - security_domain: endpoint + impact: 70 + confidence: 60 + # (impact * confidence)/100 + risk_score: 42 + context: + - Source:Cloud Data + - Scope:External + - Outcome:Allowed + - Stage:Execution + message: User $user$ is starting or creating an instance $object$ for the first time in region $Region$ from IP address $src$ + observable: + - name: user + type: User + role: + - Attacker + - name: src + type: IP Address + role: + - Attacker + - name: object + type: Endpoint + role: + - Victim + security_domain: threat \ No newline at end of file From 903e42875b8d023f15f4b4ea901048e7c8936db4 Mon Sep 17 00:00:00 2001 From: patel-bhavin Date: Wed, 14 Jul 2021 15:43:04 -0500 Subject: [PATCH 3/4] next 6 --- .../detect_aws_console_login_by_new_user.yml | 18 ++++++++++--- ...ws_console_login_by_user_from_new_city.yml | 20 +++++++++++--- ...console_login_by_user_from_new_country.yml | 20 +++++++++++--- ..._console_login_by_user_from_new_region.yml | 20 +++++++++++--- .../cloud/detect_new_open_s3_buckets.yml | 24 ++++++++++++++--- ...etect_new_open_s3_buckets_over_aws_cli.yml | 26 ++++++++++++++++--- 6 files changed, 105 insertions(+), 23 deletions(-) diff --git a/detections/cloud/detect_aws_console_login_by_new_user.yml b/detections/cloud/detect_aws_console_login_by_new_user.yml index f983c9e690..c2cc21e7db 100644 --- a/detections/cloud/detect_aws_console_login_by_new_user.yml +++ b/detections/cloud/detect_aws_console_login_by_new_user.yml @@ -52,7 +52,19 @@ tags: - _time - Authentication.signature - Authentication.user - risk_object: user - risk_object_type: user + impact: 50 + confidence: 60 + # (impact * confidence)/100 risk_score: 30 - security_domain: network + context: + - Source:Cloud Data + - Scope:External + - Outcome:Allowed + - Stage:Execution + message: User $user$ is logging into the AWS console for the first time + observable: + - name: user + type: User + role: + - Attacker + security_domain: threat \ No newline at end of file diff --git a/detections/cloud/detect_aws_console_login_by_user_from_new_city.yml b/detections/cloud/detect_aws_console_login_by_user_from_new_city.yml index 4d97c2485f..defd5cdf87 100644 --- a/detections/cloud/detect_aws_console_login_by_user_from_new_city.yml +++ b/detections/cloud/detect_aws_console_login_by_user_from_new_city.yml @@ -61,7 +61,19 @@ tags: - Authentication.signature - Authentication.user - Authentication.src - risk_object: user - risk_object_type: user - risk_score: 5 - security_domain: network + impact: 30 + confidence: 60 + # (impact * confidence)/100 + risk_score: 18 + context: + - Source:Cloud Data + - Scope:External + - Outcome:Allowed + - Stage:Execution + message: User $user$ is logging into the AWS console from City $City$ for the first time + observable: + - name: user + type: User + role: + - Attacker + security_domain: threat \ No newline at end of file diff --git a/detections/cloud/detect_aws_console_login_by_user_from_new_country.yml b/detections/cloud/detect_aws_console_login_by_user_from_new_country.yml index 8aa8cc5f65..8484eb13b3 100644 --- a/detections/cloud/detect_aws_console_login_by_user_from_new_country.yml +++ b/detections/cloud/detect_aws_console_login_by_user_from_new_country.yml @@ -61,7 +61,19 @@ tags: - Authentication.signature - Authentication.user - Authentication.src - risk_object: user - risk_object_type: user - risk_score: 5 - security_domain: network + impact: 70 + confidence: 60 + # (impact * confidence)/100 + risk_score: 42 + context: + - Source:Cloud Data + - Scope:External + - Outcome:Allowed + - Stage:Execution + message: User $user$ is logging into the AWS console from Country $Country$ for the first time + observable: + - name: user + type: User + role: + - Attacker + security_domain: threat \ No newline at end of file diff --git a/detections/cloud/detect_aws_console_login_by_user_from_new_region.yml b/detections/cloud/detect_aws_console_login_by_user_from_new_region.yml index e638c488d5..e5b5690b26 100644 --- a/detections/cloud/detect_aws_console_login_by_user_from_new_region.yml +++ b/detections/cloud/detect_aws_console_login_by_user_from_new_region.yml @@ -61,7 +61,19 @@ tags: - Authentication.signature - Authentication.user - Authentication.src - risk_object: user - risk_object_type: user - risk_score: 5 - security_domain: network + impact: 60 + confidence: 60 + # (impact * confidence)/100 + risk_score: 36 + context: + - Source:Cloud Data + - Scope:External + - Outcome:Allowed + - Stage:Execution + message: User $user$ is logging into the AWS console from Region $Region$ for the first time + observable: + - name: user + type: User + role: + - Attacker + security_domain: threat \ No newline at end of file diff --git a/detections/cloud/detect_new_open_s3_buckets.yml b/detections/cloud/detect_new_open_s3_buckets.yml index c27a34643c..071f2448b1 100644 --- a/detections/cloud/detect_new_open_s3_buckets.yml +++ b/detections/cloud/detect_new_open_s3_buckets.yml @@ -54,7 +54,23 @@ tags: - userAgent - uri - permission - risk_object: src - risk_object_type: system - risk_score: 20 - security_domain: network + impact: 60 + confidence: 80 + # (impact * confidence)/100 + risk_score: 48 + context: + - Source:Cloud Data + - Scope:External + - Outcome:Allowed + - Stage:Execution + message: User $user$ has created an open/public bucket $bucketName$ with the following permissions $permission$ + observable: + - name: userName + type: User + role: + - Attacker + - name: bucketName + type: Other + role: + - Victim + security_domain: threat \ No newline at end of file diff --git a/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml b/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml index d84e766b66..517e5197b1 100644 --- a/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml +++ b/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml @@ -58,7 +58,25 @@ tags: - userIdentity.principalId - userAgent - bucketName - risk_object: src - risk_object_type: system - risk_score: 20 - security_domain: network + impact: 60 + confidence: 80 + # (impact * confidence)/100 + risk_score: 48 + context: + - Source:Cloud Data + - Scope:External + - Outcome:Allowed + - Stage:Execution + message: User $user$ has created an open/public bucket $bucketName$ using AWS CLI with the following permissions- $requestParameters.accessControlList.x-amz-grant-read$ + $requestParameters.accessControlList.x-amz-grant-read-acp$ $requestParameters.accessControlList.x-amz-grant-write$ + $requestParameters.accessControlList.x-amz-grant-write-acp$ $requestParameters.accessControlList.x-amz-grant-full-control$ + observable: + - name: userName + type: User + role: + - Attacker + - name: bucketName + type: Other + role: + - Victim + security_domain: threat \ No newline at end of file From ae79918ffdb38b485127c465e6b3f0c74e4ad655 Mon Sep 17 00:00:00 2001 From: patel-bhavin Date: Wed, 14 Jul 2021 16:04:17 -0500 Subject: [PATCH 4/4] error fix: --- bin/validate.py | 3 ++- ..._instance_created_with_previously_unseen_instance_type.yml | 2 +- detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml | 4 +--- 3 files changed, 4 insertions(+), 5 deletions(-) diff --git a/bin/validate.py b/bin/validate.py index 404859e497..4fed76d211 100644 --- a/bin/validate.py +++ b/bin/validate.py @@ -176,7 +176,8 @@ def validate_standard_fields(object, uuids): if 'impact' in object['tags'] and 'confidence' in object['tags']: calculated_risk_score = int(((object['tags']['impact'])*(object['tags']['confidence']))/100) if calculated_risk_score != object['tags']['risk_score']: - errors.append("ERROR: risk_score not calulated correctly and it should be set as: %s" % calculated_risk_score) + + errors.append('ERROR: risk_score not calulated correctly in {0} and it should be set as:: {1}'.format(object['name'], calculated_risk_score)) return errors, uuids diff --git a/detections/cloud/cloud_compute_instance_created_with_previously_unseen_instance_type.yml b/detections/cloud/cloud_compute_instance_created_with_previously_unseen_instance_type.yml index cd39c63f5f..fbfe98862e 100644 --- a/detections/cloud/cloud_compute_instance_created_with_previously_unseen_instance_type.yml +++ b/detections/cloud/cloud_compute_instance_created_with_previously_unseen_instance_type.yml @@ -52,7 +52,7 @@ tags: impact: 50 confidence: 60 # (impact * confidence)/100 - risk_score: 36 + risk_score: 30 context: - Source:Cloud Data - Scope:External diff --git a/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml b/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml index 517e5197b1..c10bcf027f 100644 --- a/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml +++ b/detections/cloud/detect_new_open_s3_buckets_over_aws_cli.yml @@ -67,9 +67,7 @@ tags: - Scope:External - Outcome:Allowed - Stage:Execution - message: User $user$ has created an open/public bucket $bucketName$ using AWS CLI with the following permissions- $requestParameters.accessControlList.x-amz-grant-read$ - $requestParameters.accessControlList.x-amz-grant-read-acp$ $requestParameters.accessControlList.x-amz-grant-write$ - $requestParameters.accessControlList.x-amz-grant-write-acp$ $requestParameters.accessControlList.x-amz-grant-full-control$ + message: User $user$ has created an open/public bucket $bucketName$ using AWS CLI with the following permissions - $requestParameters.accessControlList.x-amz-grant-read$ $requestParameters.accessControlList.x-amz-grant-read-acp$ $requestParameters.accessControlList.x-amz-grant-write$ $requestParameters.accessControlList.x-amz-grant-write-acp$ $requestParameters.accessControlList.x-amz-grant-full-control$ observable: - name: userName type: User