mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
Improved how_to_implement
This commit is contained in:
@@ -26,6 +26,8 @@ how_to_implement: The detection is based on data that originates from Kubernetes
|
||||
Kubernetes audit logs provide a record of the requests made to the Kubernetes API server, which is crucial for monitoring and detecting suspicious activities.
|
||||
Configure the audit policy in Kubernetes to determine what kind of activities are logged. This is done by creating an Audit Policy and providing it to the API server.
|
||||
Use the Splunk OpenTelemetry Collector for Kubernetes to collect the logs. This doc will describe how to collect the audit log file https://github.com/signalfx/splunk-otel-collector-chart/blob/main/docs/migration-from-sck.md.
|
||||
When you want to use this detection with AWS EKS, you need to enable EKS control plane logging https://docs.aws.amazon.com/eks/latest/userguide/control-plane-logs.html. Then
|
||||
you can collect the logs from Cloudwatch using the AWS TA https://splunk.github.io/splunk-add-on-for-amazon-web-services/CloudWatchLogs/.
|
||||
known_false_positives: unknown
|
||||
references:
|
||||
- https://kubernetes.io/docs/tasks/debug/debug-cluster/audit/
|
||||
|
||||
@@ -25,6 +25,8 @@ how_to_implement: The detection is based on data that originates from Kubernetes
|
||||
Kubernetes audit logs provide a record of the requests made to the Kubernetes API server, which is crucial for monitoring and detecting suspicious activities.
|
||||
Configure the audit policy in Kubernetes to determine what kind of activities are logged. This is done by creating an Audit Policy and providing it to the API server.
|
||||
Use the Splunk OpenTelemetry Collector for Kubernetes to collect the logs. This doc will describe how to collect the audit log file https://github.com/signalfx/splunk-otel-collector-chart/blob/main/docs/migration-from-sck.md.
|
||||
When you want to use this detection with AWS EKS, you need to enable EKS control plane logging https://docs.aws.amazon.com/eks/latest/userguide/control-plane-logs.html. Then
|
||||
you can collect the logs from Cloudwatch using the AWS TA https://splunk.github.io/splunk-add-on-for-amazon-web-services/CloudWatchLogs/.
|
||||
known_false_positives: unknown
|
||||
references:
|
||||
- https://kubernetes.io/docs/tasks/debug/debug-cluster/audit/
|
||||
|
||||
@@ -24,6 +24,8 @@ how_to_implement: The detection is based on data that originates from Kubernetes
|
||||
Kubernetes audit logs provide a record of the requests made to the Kubernetes API server, which is crucial for monitoring and detecting suspicious activities.
|
||||
Configure the audit policy in Kubernetes to determine what kind of activities are logged. This is done by creating an Audit Policy and providing it to the API server.
|
||||
Use the Splunk OpenTelemetry Collector for Kubernetes to collect the logs. This doc will describe how to collect the audit log file https://github.com/signalfx/splunk-otel-collector-chart/blob/main/docs/migration-from-sck.md.
|
||||
When you want to use this detection with AWS EKS, you need to enable EKS control plane logging https://docs.aws.amazon.com/eks/latest/userguide/control-plane-logs.html. Then
|
||||
you can collect the logs from Cloudwatch using the AWS TA https://splunk.github.io/splunk-add-on-for-amazon-web-services/CloudWatchLogs/.
|
||||
known_false_positives: unknown
|
||||
references:
|
||||
- https://kubernetes.io/docs/tasks/debug/debug-cluster/audit/
|
||||
|
||||
@@ -25,6 +25,8 @@ how_to_implement: The detection is based on data that originates from Kubernetes
|
||||
Kubernetes audit logs provide a record of the requests made to the Kubernetes API server, which is crucial for monitoring and detecting suspicious activities.
|
||||
Configure the audit policy in Kubernetes to determine what kind of activities are logged. This is done by creating an Audit Policy and providing it to the API server.
|
||||
Use the Splunk OpenTelemetry Collector for Kubernetes to collect the logs. This doc will describe how to collect the audit log file https://github.com/signalfx/splunk-otel-collector-chart/blob/main/docs/migration-from-sck.md.
|
||||
When you want to use this detection with AWS EKS, you need to enable EKS control plane logging https://docs.aws.amazon.com/eks/latest/userguide/control-plane-logs.html. Then
|
||||
you can collect the logs from Cloudwatch using the AWS TA https://splunk.github.io/splunk-add-on-for-amazon-web-services/CloudWatchLogs/.
|
||||
known_false_positives: unknown
|
||||
references:
|
||||
- https://kubernetes.io/docs/tasks/debug/debug-cluster/audit/
|
||||
|
||||
@@ -26,6 +26,8 @@ how_to_implement: The detection is based on data that originates from Kubernetes
|
||||
Kubernetes audit logs provide a record of the requests made to the Kubernetes API server, which is crucial for monitoring and detecting suspicious activities.
|
||||
Configure the audit policy in Kubernetes to determine what kind of activities are logged. This is done by creating an Audit Policy and providing it to the API server.
|
||||
Use the Splunk OpenTelemetry Collector for Kubernetes to collect the logs. This doc will describe how to collect the audit log file https://github.com/signalfx/splunk-otel-collector-chart/blob/main/docs/migration-from-sck.md.
|
||||
When you want to use this detection with AWS EKS, you need to enable EKS control plane logging https://docs.aws.amazon.com/eks/latest/userguide/control-plane-logs.html. Then
|
||||
you can collect the logs from Cloudwatch using the AWS TA https://splunk.github.io/splunk-add-on-for-amazon-web-services/CloudWatchLogs/.
|
||||
known_false_positives: unknown
|
||||
references:
|
||||
- https://kubernetes.io/docs/tasks/debug/debug-cluster/audit/
|
||||
|
||||
@@ -19,8 +19,12 @@ search: '`kube_audit` user.username="system:anonymous" user.groups{} IN ("system
|
||||
requestReceivedTimestamp requestURI responseStatus.code sourceIPs{} stage user.groups{}
|
||||
user.uid user.username userAgent verb | rename sourceIPs{} as src_ip, user.username
|
||||
as user |`kubernetes_aws_detect_suspicious_kubectl_calls_filter`'
|
||||
how_to_implement: You must install splunk AWS add on and Splunk App for AWS. This
|
||||
search works with cloudwatch logs.
|
||||
how_to_implement: The detection is based on data that originates from Kubernetes Audit logs. Ensure that audit logging is enabled in your Kubernetes cluster.
|
||||
Kubernetes audit logs provide a record of the requests made to the Kubernetes API server, which is crucial for monitoring and detecting suspicious activities.
|
||||
Configure the audit policy in Kubernetes to determine what kind of activities are logged. This is done by creating an Audit Policy and providing it to the API server.
|
||||
Use the Splunk OpenTelemetry Collector for Kubernetes to collect the logs. This doc will describe how to collect the audit log file https://github.com/signalfx/splunk-otel-collector-chart/blob/main/docs/migration-from-sck.md.
|
||||
When you want to use this detection with AWS EKS, you need to enable EKS control plane logging https://docs.aws.amazon.com/eks/latest/userguide/control-plane-logs.html. Then
|
||||
you can collect the logs from Cloudwatch using the AWS TA https://splunk.github.io/splunk-add-on-for-amazon-web-services/CloudWatchLogs/.
|
||||
known_false_positives: Kubectl calls are not malicious by nature. However source IP,
|
||||
verb and Object can reveal potential malicious activity, specially anonymous suspicious
|
||||
IPs and sensitive objects such as configmaps or secrets
|
||||
|
||||
@@ -24,6 +24,8 @@ how_to_implement: The detection is based on data that originates from Kubernetes
|
||||
Kubernetes audit logs provide a record of the requests made to the Kubernetes API server, which is crucial for monitoring and detecting suspicious activities.
|
||||
Configure the audit policy in Kubernetes to determine what kind of activities are logged. This is done by creating an Audit Policy and providing it to the API server.
|
||||
Use the Splunk OpenTelemetry Collector for Kubernetes to collect the logs. This doc will describe how to collect the audit log file https://github.com/signalfx/splunk-otel-collector-chart/blob/main/docs/migration-from-sck.md.
|
||||
When you want to use this detection with AWS EKS, you need to enable EKS control plane logging https://docs.aws.amazon.com/eks/latest/userguide/control-plane-logs.html. Then
|
||||
you can collect the logs from Cloudwatch using the AWS TA https://splunk.github.io/splunk-add-on-for-amazon-web-services/CloudWatchLogs/.
|
||||
known_false_positives: unknown
|
||||
references:
|
||||
- https://kubernetes.io/docs/tasks/debug/debug-cluster/audit/
|
||||
|
||||
@@ -24,6 +24,8 @@ how_to_implement: The detection is based on data that originates from Kubernetes
|
||||
Kubernetes audit logs provide a record of the requests made to the Kubernetes API server, which is crucial for monitoring and detecting suspicious activities.
|
||||
Configure the audit policy in Kubernetes to determine what kind of activities are logged. This is done by creating an Audit Policy and providing it to the API server.
|
||||
Use the Splunk OpenTelemetry Collector for Kubernetes to collect the logs. This doc will describe how to collect the audit log file https://github.com/signalfx/splunk-otel-collector-chart/blob/main/docs/migration-from-sck.md.
|
||||
When you want to use this detection with AWS EKS, you need to enable EKS control plane logging https://docs.aws.amazon.com/eks/latest/userguide/control-plane-logs.html. Then
|
||||
you can collect the logs from Cloudwatch using the AWS TA https://splunk.github.io/splunk-add-on-for-amazon-web-services/CloudWatchLogs/.
|
||||
known_false_positives: unknown
|
||||
references:
|
||||
- https://kubernetes.io/docs/tasks/debug/debug-cluster/audit/
|
||||
|
||||
@@ -24,6 +24,8 @@ how_to_implement: The detection is based on data that originates from Kubernetes
|
||||
Kubernetes audit logs provide a record of the requests made to the Kubernetes API server, which is crucial for monitoring and detecting suspicious activities.
|
||||
Configure the audit policy in Kubernetes to determine what kind of activities are logged. This is done by creating an Audit Policy and providing it to the API server.
|
||||
Use the Splunk OpenTelemetry Collector for Kubernetes to collect the logs. This doc will describe how to collect the audit log file https://github.com/signalfx/splunk-otel-collector-chart/blob/main/docs/migration-from-sck.md.
|
||||
When you want to use this detection with AWS EKS, you need to enable EKS control plane logging https://docs.aws.amazon.com/eks/latest/userguide/control-plane-logs.html. Then
|
||||
you can collect the logs from Cloudwatch using the AWS TA https://splunk.github.io/splunk-add-on-for-amazon-web-services/CloudWatchLogs/.
|
||||
known_false_positives: unknown
|
||||
references:
|
||||
- https://kubernetes.io/docs/tasks/debug/debug-cluster/audit/
|
||||
|
||||
@@ -19,11 +19,12 @@ search: '`kube_container_falco` "A shell was spawned in a container"
|
||||
| fillnull
|
||||
| stats count by container_image container_image_tag container_name parent proc_exepath process user
|
||||
| `kubernetes_falco_shell_spawned_filter`'
|
||||
how_to_implement: The detection is based on data that originates from Falco, a cloud native runtime security tool.
|
||||
Falco is designed to detect anomalous activity in your applications and is a crucial component of this detection rule.
|
||||
To implement this detection rule, you need to install and configure Falco in your Kubernetes environment.
|
||||
Once Falco is set up, it will monitor the system calls in your Kubernetes infrastructure and generate logs for any suspicious activity.
|
||||
These logs are then ingested by Splunk for analysis. Use the Splunk OpenTelemetry Collector for Kubernetes to collect the logs.
|
||||
how_to_implement: The detection is based on data that originates from Kubernetes Audit logs. Ensure that audit logging is enabled in your Kubernetes cluster.
|
||||
Kubernetes audit logs provide a record of the requests made to the Kubernetes API server, which is crucial for monitoring and detecting suspicious activities.
|
||||
Configure the audit policy in Kubernetes to determine what kind of activities are logged. This is done by creating an Audit Policy and providing it to the API server.
|
||||
Use the Splunk OpenTelemetry Collector for Kubernetes to collect the logs. This doc will describe how to collect the audit log file https://github.com/signalfx/splunk-otel-collector-chart/blob/main/docs/migration-from-sck.md.
|
||||
When you want to use this detection with AWS EKS, you need to enable EKS control plane logging https://docs.aws.amazon.com/eks/latest/userguide/control-plane-logs.html. Then
|
||||
you can collect the logs from Cloudwatch using the AWS TA https://splunk.github.io/splunk-add-on-for-amazon-web-services/CloudWatchLogs/.
|
||||
known_false_positives: unknown
|
||||
references:
|
||||
- https://kubernetes.io/docs/tasks/debug/debug-cluster/audit/
|
||||
|
||||
@@ -24,6 +24,8 @@ how_to_implement: The detection is based on data that originates from Kubernetes
|
||||
Kubernetes audit logs provide a record of the requests made to the Kubernetes API server, which is crucial for monitoring and detecting suspicious activities.
|
||||
Configure the audit policy in Kubernetes to determine what kind of activities are logged. This is done by creating an Audit Policy and providing it to the API server.
|
||||
Use the Splunk OpenTelemetry Collector for Kubernetes to collect the logs. This doc will describe how to collect the audit log file https://github.com/signalfx/splunk-otel-collector-chart/blob/main/docs/migration-from-sck.md.
|
||||
When you want to use this detection with AWS EKS, you need to enable EKS control plane logging https://docs.aws.amazon.com/eks/latest/userguide/control-plane-logs.html. Then
|
||||
you can collect the logs from Cloudwatch using the AWS TA https://splunk.github.io/splunk-add-on-for-amazon-web-services/CloudWatchLogs/.
|
||||
known_false_positives: unknown
|
||||
references:
|
||||
- https://kubernetes.io/docs/tasks/debug/debug-cluster/audit/
|
||||
|
||||
@@ -23,6 +23,8 @@ how_to_implement: The detection is based on data that originates from Kubernetes
|
||||
Kubernetes audit logs provide a record of the requests made to the Kubernetes API server, which is crucial for monitoring and detecting suspicious activities.
|
||||
Configure the audit policy in Kubernetes to determine what kind of activities are logged. This is done by creating an Audit Policy and providing it to the API server.
|
||||
Use the Splunk OpenTelemetry Collector for Kubernetes to collect the logs. This doc will describe how to collect the audit log file https://github.com/signalfx/splunk-otel-collector-chart/blob/main/docs/migration-from-sck.md.
|
||||
When you want to use this detection with AWS EKS, you need to enable EKS control plane logging https://docs.aws.amazon.com/eks/latest/userguide/control-plane-logs.html. Then
|
||||
you can collect the logs from Cloudwatch using the AWS TA https://splunk.github.io/splunk-add-on-for-amazon-web-services/CloudWatchLogs/.
|
||||
known_false_positives: unknown
|
||||
references:
|
||||
- https://kubernetes.io/docs/tasks/debug/debug-cluster/audit/
|
||||
|
||||
@@ -24,6 +24,8 @@ how_to_implement: The detection is based on data that originates from Kubernetes
|
||||
Kubernetes audit logs provide a record of the requests made to the Kubernetes API server, which is crucial for monitoring and detecting suspicious activities.
|
||||
Configure the audit policy in Kubernetes to determine what kind of activities are logged. This is done by creating an Audit Policy and providing it to the API server.
|
||||
Use the Splunk OpenTelemetry Collector for Kubernetes to collect the logs. This doc will describe how to collect the audit log file https://github.com/signalfx/splunk-otel-collector-chart/blob/main/docs/migration-from-sck.md.
|
||||
When you want to use this detection with AWS EKS, you need to enable EKS control plane logging https://docs.aws.amazon.com/eks/latest/userguide/control-plane-logs.html. Then
|
||||
you can collect the logs from Cloudwatch using the AWS TA https://splunk.github.io/splunk-add-on-for-amazon-web-services/CloudWatchLogs/.
|
||||
known_false_positives: unknown
|
||||
references:
|
||||
- https://kubernetes.io/docs/tasks/debug/debug-cluster/audit/
|
||||
|
||||
@@ -22,7 +22,12 @@ search: '`kube_audit` "user.groups{}"="system:unauthenticated" "responseStatus.c
|
||||
| where count > 5
|
||||
| rename sourceIPs{} as src_ip, user.username as user
|
||||
| `kubernetes_scanning_by_unauthenticated_ip_address_filter`'
|
||||
how_to_implement: You must ingest Kubernetes audit logs.
|
||||
how_to_implement: The detection is based on data that originates from Kubernetes Audit logs. Ensure that audit logging is enabled in your Kubernetes cluster.
|
||||
Kubernetes audit logs provide a record of the requests made to the Kubernetes API server, which is crucial for monitoring and detecting suspicious activities.
|
||||
Configure the audit policy in Kubernetes to determine what kind of activities are logged. This is done by creating an Audit Policy and providing it to the API server.
|
||||
Use the Splunk OpenTelemetry Collector for Kubernetes to collect the logs. This doc will describe how to collect the audit log file https://github.com/signalfx/splunk-otel-collector-chart/blob/main/docs/migration-from-sck.md.
|
||||
When you want to use this detection with AWS EKS, you need to enable EKS control plane logging https://docs.aws.amazon.com/eks/latest/userguide/control-plane-logs.html. Then
|
||||
you can collect the logs from Cloudwatch using the AWS TA https://splunk.github.io/splunk-add-on-for-amazon-web-services/CloudWatchLogs/.
|
||||
known_false_positives: unknown
|
||||
references:
|
||||
- https://kubernetes.io/docs/tasks/debug/debug-cluster/audit/
|
||||
|
||||
@@ -25,6 +25,8 @@ how_to_implement: The detection is based on data that originates from Kubernetes
|
||||
Kubernetes audit logs provide a record of the requests made to the Kubernetes API server, which is crucial for monitoring and detecting suspicious activities.
|
||||
Configure the audit policy in Kubernetes to determine what kind of activities are logged. This is done by creating an Audit Policy and providing it to the API server.
|
||||
Use the Splunk OpenTelemetry Collector for Kubernetes to collect the logs. This doc will describe how to collect the audit log file https://github.com/signalfx/splunk-otel-collector-chart/blob/main/docs/migration-from-sck.md.
|
||||
When you want to use this detection with AWS EKS, you need to enable EKS control plane logging https://docs.aws.amazon.com/eks/latest/userguide/control-plane-logs.html. Then
|
||||
you can collect the logs from Cloudwatch using the AWS TA https://splunk.github.io/splunk-add-on-for-amazon-web-services/CloudWatchLogs/.
|
||||
known_false_positives: unknown
|
||||
references:
|
||||
- https://kubernetes.io/docs/tasks/debug/debug-cluster/audit/
|
||||
|
||||
@@ -24,6 +24,8 @@ how_to_implement: The detection is based on data that originates from Kubernetes
|
||||
Kubernetes audit logs provide a record of the requests made to the Kubernetes API server, which is crucial for monitoring and detecting suspicious activities.
|
||||
Configure the audit policy in Kubernetes to determine what kind of activities are logged. This is done by creating an Audit Policy and providing it to the API server.
|
||||
Use the Splunk OpenTelemetry Collector for Kubernetes to collect the logs. This doc will describe how to collect the audit log file https://github.com/signalfx/splunk-otel-collector-chart/blob/main/docs/migration-from-sck.md.
|
||||
When you want to use this detection with AWS EKS, you need to enable EKS control plane logging https://docs.aws.amazon.com/eks/latest/userguide/control-plane-logs.html. Then
|
||||
you can collect the logs from Cloudwatch using the AWS TA https://splunk.github.io/splunk-add-on-for-amazon-web-services/CloudWatchLogs/.
|
||||
known_false_positives: unknown
|
||||
references:
|
||||
- https://kubernetes.io/docs/tasks/debug/debug-cluster/audit/
|
||||
|
||||
Reference in New Issue
Block a user