mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
Removal of fields from new detections
This commit is contained in:
@@ -18,8 +18,6 @@ tags:
|
||||
analytic_story:
|
||||
- AWS IAM Privilege Escalation
|
||||
asset_type: AWS Account
|
||||
confidence: 90
|
||||
impact: 70
|
||||
mitre_attack_id:
|
||||
- T1136.003
|
||||
- T1136
|
||||
@@ -27,14 +25,6 @@ tags:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- api.operation
|
||||
- actor.user.uid
|
||||
- actor.user.account.uid
|
||||
- http_request.user_agent
|
||||
- src_endpoint.ip
|
||||
- src_endpoint.domain
|
||||
- cloud.region
|
||||
security_domain: network
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
|
||||
@@ -34,29 +34,13 @@ tags:
|
||||
analytic_story:
|
||||
- AWS IAM Privilege Escalation
|
||||
asset_type: AWS Account
|
||||
confidence: 70
|
||||
impact: 70
|
||||
mitre_attack_id:
|
||||
- T1078.004
|
||||
- T1078
|
||||
observable:
|
||||
- name: user
|
||||
type: User
|
||||
role:
|
||||
- Victim
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- api.operation
|
||||
- actor.user.account.uid
|
||||
- api.request.data
|
||||
- actor.user.uid
|
||||
- http_request.user_agent
|
||||
- src_endpoint.ip
|
||||
- src_endpoint.domain
|
||||
- cloud.region
|
||||
security_domain: network
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
|
||||
@@ -28,6 +28,7 @@ rba:
|
||||
risk_objects:
|
||||
- field: user
|
||||
type: user
|
||||
score: 49
|
||||
threat_objects:
|
||||
- field: src_ip
|
||||
type: ip_address
|
||||
@@ -35,35 +36,15 @@ tags:
|
||||
analytic_story:
|
||||
- AWS Identity and Access Management Account Takeover
|
||||
asset_type: AWS Account
|
||||
confidence: 70
|
||||
impact: 70
|
||||
mitre_attack_id:
|
||||
- T1586
|
||||
- T1586.003
|
||||
- T1110
|
||||
- T1110.001
|
||||
observable:
|
||||
- name: src_ip
|
||||
type: IP Address
|
||||
role:
|
||||
- Attacker
|
||||
- name: user
|
||||
type: User
|
||||
role:
|
||||
- Victim
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- api.operation
|
||||
- actor.user.uid
|
||||
- actor.user.account.uid
|
||||
- http_request.user_agent
|
||||
- src_endpoint.ip
|
||||
- src_endpoint.domain
|
||||
- cloud.region
|
||||
risk_score: 49
|
||||
security_domain: threat
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
|
||||
@@ -35,8 +35,6 @@ tags:
|
||||
analytic_story:
|
||||
- AWS Identity and Access Management Account Takeover
|
||||
asset_type: AWS Account
|
||||
confidence: 70
|
||||
impact: 70
|
||||
mitre_attack_id:
|
||||
- T1586
|
||||
- T1586.003
|
||||
@@ -45,15 +43,6 @@ tags:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- api.operation
|
||||
- api.request.data
|
||||
- actor.user.uid
|
||||
- actor.user.account.uid
|
||||
- http_request.user_agent
|
||||
- src_endpoint.ip
|
||||
- src_endpoint.domain
|
||||
- cloud.region
|
||||
security_domain: threat
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
|
||||
@@ -13,21 +13,10 @@ how_to_implement: The detection is based on Amazon Security Lake events from Ama
|
||||
known_false_positives: While this search has no known false positives, it is possible that it is a legitimate admin activity. Please consider filtering out these noisy events using userAgent, user_arn field names.
|
||||
references:
|
||||
- https://stratus-red-team.cloud/attack-techniques/AWS/aws.defense-evasion.cloudtrail-lifecycle-rule/
|
||||
rba:
|
||||
message: User $user$ has created a new rule to on an S3 bucket $bucketName$ with short expiration days
|
||||
risk_objects:
|
||||
- field: user
|
||||
type: user
|
||||
score: 20
|
||||
threat_objects:
|
||||
- field: src_ip
|
||||
type: ip_address
|
||||
tags:
|
||||
analytic_story:
|
||||
- AWS Defense Evasion
|
||||
asset_type: AWS Account
|
||||
confidence: 40
|
||||
impact: 50
|
||||
mitre_attack_id:
|
||||
- T1562.008
|
||||
- T1562
|
||||
@@ -37,15 +26,6 @@ tags:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- api.operation
|
||||
- api.request.data
|
||||
- actor.user.uid
|
||||
- actor.user.account.uid
|
||||
- http_request.user_agent
|
||||
- src_endpoint.ip
|
||||
- src_endpoint.domain
|
||||
- cloud.region
|
||||
security_domain: threat
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
|
||||
-12
@@ -48,24 +48,12 @@ tags:
|
||||
analytic_story:
|
||||
- Ransomware Cloud
|
||||
asset_type: AWS Account
|
||||
confidence: 50
|
||||
impact: 50
|
||||
message: AWS account is potentially compromised and user $user$ is trying to compromise other accounts.
|
||||
mitre_attack_id:
|
||||
- T1486
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- api.operation
|
||||
- actor.user.uid
|
||||
- actor.user.account.uid
|
||||
- api.request.data
|
||||
- http_request.user_agent
|
||||
- src_endpoint.ip
|
||||
- src_endpoint.domain
|
||||
- cloud.region
|
||||
security_domain: threat
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
|
||||
@@ -44,23 +44,12 @@ tags:
|
||||
- Suspicious AWS S3 Activities
|
||||
- Data Exfiltration
|
||||
asset_type: AWS Account
|
||||
confidence: 80
|
||||
impact: 80
|
||||
mitre_attack_id:
|
||||
- T1490
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- api.operation
|
||||
- actor.user.uid
|
||||
- actor.user.account.uid
|
||||
- api.request.data
|
||||
- http_request.user_agent
|
||||
- src_endpoint.ip
|
||||
- src_endpoint.domain
|
||||
- cloud.region
|
||||
security_domain: threat
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
|
||||
@@ -44,23 +44,12 @@ tags:
|
||||
- Suspicious Cloud Instance Activities
|
||||
- Data Exfiltration
|
||||
asset_type: EC2 Snapshot
|
||||
confidence: 80
|
||||
impact: 60
|
||||
mitre_attack_id:
|
||||
- T1537
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- api.operation
|
||||
- actor.user.uid
|
||||
- actor.user.account.uid
|
||||
- api.request.data
|
||||
- http_request.user_agent
|
||||
- src_endpoint.ip
|
||||
- src_endpoint.domain
|
||||
- cloud.region
|
||||
security_domain: threat
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
|
||||
@@ -41,19 +41,12 @@ tags:
|
||||
analytic_story:
|
||||
- Suspicious Cloud User Activities
|
||||
asset_type: AWS Account
|
||||
confidence: 50
|
||||
impact: 20
|
||||
mitre_attack_id:
|
||||
- T1580
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- api.operation
|
||||
- actor.user.uid
|
||||
- src_endpoint.ip
|
||||
- cloud.region
|
||||
security_domain: access
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
|
||||
@@ -42,8 +42,6 @@ tags:
|
||||
analytic_story:
|
||||
- AWS IAM Privilege Escalation
|
||||
asset_type: AWS Account
|
||||
confidence: 70
|
||||
impact: 40
|
||||
mitre_attack_id:
|
||||
- T1580
|
||||
- T1110
|
||||
@@ -51,12 +49,6 @@ tags:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- _time
|
||||
- api.operation
|
||||
- actor.user.uid
|
||||
- src_endpoint.ip
|
||||
- cloud.region
|
||||
security_domain: access
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
|
||||
@@ -44,8 +44,6 @@ tags:
|
||||
analytic_story:
|
||||
- AWS Network ACL Activity
|
||||
asset_type: AWS Instance
|
||||
confidence: 80
|
||||
impact: 60
|
||||
mitre_attack_id:
|
||||
- T1562.007
|
||||
- T1562
|
||||
@@ -53,14 +51,6 @@ tags:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- api.operation
|
||||
- api.request.data
|
||||
- actor.user.uid
|
||||
- actor.user.account.uid
|
||||
- http_request.user_agent
|
||||
- src_endpoint.ip
|
||||
- cloud.region
|
||||
security_domain: network
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
|
||||
@@ -41,8 +41,6 @@ tags:
|
||||
analytic_story:
|
||||
- AWS Network ACL Activity
|
||||
asset_type: AWS Instance
|
||||
confidence: 50
|
||||
impact: 10
|
||||
mitre_attack_id:
|
||||
- T1562.007
|
||||
- T1562
|
||||
@@ -50,14 +48,6 @@ tags:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- api.operation
|
||||
- api.request.data
|
||||
- actor.user.uid
|
||||
- actor.user.account.uid
|
||||
- http_request.user_agent
|
||||
- src_endpoint.ip
|
||||
- cloud.region
|
||||
security_domain: network
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
|
||||
@@ -42,22 +42,12 @@ tags:
|
||||
analytic_story:
|
||||
- Cloud Federated Credential Abuse
|
||||
asset_type: AWS Federated Account
|
||||
confidence: 80
|
||||
impact: 80
|
||||
message: User $user$ from IP address $src_ip$ updated the SAML provider
|
||||
mitre_attack_id:
|
||||
- T1078
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- api.operation
|
||||
- actor.user.uid
|
||||
- actor.user.account.uid
|
||||
- http_request.user_agent
|
||||
- src_endpoint.ip
|
||||
- cloud.region
|
||||
security_domain: threat
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
|
||||
@@ -40,8 +40,6 @@ tags:
|
||||
analytic_story:
|
||||
- AWS IAM Privilege Escalation
|
||||
asset_type: AWS Account
|
||||
confidence: 60
|
||||
impact: 50
|
||||
mitre_attack_id:
|
||||
- T1136.003
|
||||
- T1136
|
||||
@@ -49,13 +47,6 @@ tags:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- api.operation
|
||||
- actor.user.uid
|
||||
- actor.user.account.uid
|
||||
- http_request.user_agent
|
||||
- src_endpoint.ip
|
||||
- cloud.region
|
||||
security_domain: threat
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
|
||||
@@ -3,7 +3,7 @@ id: d62852db-a1f1-40db-a7fc-c3d56fa8bda3
|
||||
version: 1
|
||||
date: '2025-01-06'
|
||||
author: Dean Luxton
|
||||
data_sources:
|
||||
data_source:
|
||||
- Azure Active Directory NonInteractiveUserSignInLogs
|
||||
- Azure Active Directory MicrosoftGraphActivityLogs
|
||||
type: TTP
|
||||
@@ -35,7 +35,7 @@ rba:
|
||||
message: AzureHound UserAgent String $user_agent$ Detected on Tenant $tenantId$
|
||||
risk_objects:
|
||||
- field: tenantId
|
||||
type: Other
|
||||
type: other
|
||||
score: 80
|
||||
threat_objects:
|
||||
- field: src
|
||||
@@ -47,9 +47,6 @@ tags:
|
||||
- Azure Active Directory Privilege Escalation
|
||||
- Compromised User Account
|
||||
asset_type: Azure Tenant
|
||||
confidence: 100
|
||||
impact: 80
|
||||
message: AzureHound UserAgent String $user_agent$ Detected on Tenant $tenantId$
|
||||
mitre_attack_id:
|
||||
- T1087.004
|
||||
- T1526
|
||||
@@ -57,11 +54,6 @@ tags:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- src
|
||||
- category
|
||||
- properties.userAgent
|
||||
- tenantId
|
||||
security_domain: identity
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
|
||||
@@ -39,7 +39,7 @@ rba:
|
||||
message: $spn_count$ Service Principals have been enumerated by $user$ from IP $src$
|
||||
risk_objects:
|
||||
- field: tenantId
|
||||
type: Other
|
||||
type: other
|
||||
score: 80
|
||||
threat_objects:
|
||||
- field: src
|
||||
@@ -51,8 +51,6 @@ tags:
|
||||
- Azure Active Directory Privilege Escalation
|
||||
- Compromised User Account
|
||||
asset_type: Azure Tenant
|
||||
confidence: 100
|
||||
impact: 80
|
||||
mitre_attack_id:
|
||||
- T1087.004
|
||||
- T1526
|
||||
@@ -60,11 +58,6 @@ tags:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- category
|
||||
- properties.requestUri
|
||||
- src
|
||||
- user
|
||||
security_domain: identity
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
|
||||
@@ -3,7 +3,7 @@ id: 29eb39d3-2bc8-49cc-99b3-35593191a588
|
||||
version: 1
|
||||
date: '2025-01-06'
|
||||
author: Dean Luxton
|
||||
data_sources:
|
||||
data_source:
|
||||
- Azure Active Directory Add app role assignment to service principal
|
||||
type: TTP
|
||||
status: production
|
||||
@@ -48,8 +48,6 @@ tags:
|
||||
analytic_story:
|
||||
- Azure Active Directory Privilege Escalation
|
||||
asset_type: Azure Tenant
|
||||
confidence: 100
|
||||
impact: 100
|
||||
mitre_attack_id:
|
||||
- T1098.003
|
||||
- T1098
|
||||
@@ -57,18 +55,6 @@ tags:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- user_agent
|
||||
- identity
|
||||
- properties.initiatedBy.app.servicePrincipalId
|
||||
- operationName
|
||||
- tenantId
|
||||
- correlationId
|
||||
- category
|
||||
- properties.initiatedBy.app.displayName
|
||||
- properties.result
|
||||
- properties{}.targetResources{}.modifiedProperties{}
|
||||
- properties.targetResources{}.displayName
|
||||
security_domain: identity
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
|
||||
@@ -3,7 +3,7 @@ id: 6fe42e07-15b1-4caa-b547-7885666cb1bd
|
||||
version: 1
|
||||
date: '2025-01-06'
|
||||
author: Dean Luxton
|
||||
data_sources:
|
||||
data_source:
|
||||
- Azure Monitor Activity
|
||||
type: Hunting
|
||||
status: production
|
||||
@@ -29,8 +29,6 @@ tags:
|
||||
analytic_story:
|
||||
- Azure Active Directory Account Takeover
|
||||
asset_type: Azure Tenant
|
||||
confidence: 40
|
||||
impact: 100
|
||||
mitre_attack_id:
|
||||
- T1072
|
||||
- T1021.007
|
||||
@@ -40,10 +38,6 @@ tags:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- operationName
|
||||
- identity
|
||||
- properties.TargetObjectIds{}
|
||||
security_domain: audit
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
|
||||
@@ -3,7 +3,7 @@ id: 3c49e5ed-625c-408c-a2c7-8e2b524efb2c
|
||||
version: 1
|
||||
date: '2025-01-07'
|
||||
author: Dean Luxton
|
||||
data_sources:
|
||||
data_source:
|
||||
- Azure Monitor Activity
|
||||
type: Hunting
|
||||
status: production
|
||||
@@ -31,8 +31,6 @@ tags:
|
||||
analytic_story:
|
||||
- Azure Active Directory Account Takeover
|
||||
asset_type: Azure Tenant
|
||||
confidence: 40
|
||||
impact: 100
|
||||
mitre_attack_id:
|
||||
- T1072
|
||||
- T1484
|
||||
@@ -43,10 +41,6 @@ tags:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- operationName
|
||||
- identity
|
||||
- properties.TargetObjectIds{}
|
||||
security_domain: audit
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
|
||||
@@ -3,7 +3,7 @@ id: 5ca7ebee-4ee7-4cf2-b3be-0ea26a00d822
|
||||
version: 1
|
||||
date: '2025-01-07'
|
||||
author: Dean Luxton
|
||||
data_sources:
|
||||
data_source:
|
||||
- Azure Monitor Activity
|
||||
type: Hunting
|
||||
status: production
|
||||
@@ -31,8 +31,6 @@ tags:
|
||||
analytic_story:
|
||||
- Azure Active Directory Account Takeover
|
||||
asset_type: Azure Tenant
|
||||
confidence: 70
|
||||
impact: 20
|
||||
mitre_attack_id:
|
||||
- T1021.007
|
||||
- T1072
|
||||
@@ -41,10 +39,6 @@ tags:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- operationName
|
||||
- identity
|
||||
- properties.TargetObjectIds{}
|
||||
security_domain: audit
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
|
||||
@@ -3,7 +3,7 @@ id: 98e6b389-2806-4426-a580-8a92cb0d9710
|
||||
version: 1
|
||||
date: '2025-01-07'
|
||||
author: Dean Luxton
|
||||
data_sources:
|
||||
data_source:
|
||||
- Azure Monitor Activity
|
||||
type: Hunting
|
||||
status: experimental
|
||||
@@ -29,8 +29,6 @@ tags:
|
||||
analytic_story:
|
||||
- Azure Active Directory Account Takeover
|
||||
asset_type: Azure Tenant
|
||||
confidence: 40
|
||||
impact: 100
|
||||
mitre_attack_id:
|
||||
- T1072
|
||||
- T1021.007
|
||||
@@ -40,10 +38,6 @@ tags:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- operationName
|
||||
- identity
|
||||
- properties.TargetObjectIds{}
|
||||
security_domain: audit
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
|
||||
@@ -3,7 +3,7 @@ id: b686d0bd-cca7-44ca-ae07-87f6465131d9
|
||||
version: 1
|
||||
date: '2025-01-06'
|
||||
author: Dean Luxton
|
||||
data_sources:
|
||||
data_source:
|
||||
- O365 Add app role assignment grant to user
|
||||
type: TTP
|
||||
status: production
|
||||
@@ -47,8 +47,6 @@ tags:
|
||||
- Azure Active Directory Privilege Escalation
|
||||
- Office 365 Account Takeover
|
||||
asset_type: Azure Tenant
|
||||
confidence: 100
|
||||
impact: 100
|
||||
mitre_attack_id:
|
||||
- T1098.003
|
||||
- T1098
|
||||
@@ -56,15 +54,6 @@ tags:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
required_fields:
|
||||
- user_agent
|
||||
- Actor{}.ID
|
||||
- ResultStatus
|
||||
- Operation
|
||||
- ModifiedProperties{}
|
||||
- user
|
||||
- InterSystemsId
|
||||
- tenant_id
|
||||
security_domain: identity
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
|
||||
Reference in New Issue
Block a user