Removal of fields from new detections

This commit is contained in:
ljstella
2025-01-15 15:17:50 -06:00
parent 9ee2e1de7d
commit ef2ac2a45f
22 changed files with 10 additions and 238 deletions
@@ -18,8 +18,6 @@ tags:
analytic_story:
- AWS IAM Privilege Escalation
asset_type: AWS Account
confidence: 90
impact: 70
mitre_attack_id:
- T1136.003
- T1136
@@ -27,14 +25,6 @@ tags:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- api.operation
- actor.user.uid
- actor.user.account.uid
- http_request.user_agent
- src_endpoint.ip
- src_endpoint.domain
- cloud.region
security_domain: network
tests:
- name: True Positive Test
@@ -34,29 +34,13 @@ tags:
analytic_story:
- AWS IAM Privilege Escalation
asset_type: AWS Account
confidence: 70
impact: 70
mitre_attack_id:
- T1078.004
- T1078
observable:
- name: user
type: User
role:
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- api.operation
- actor.user.account.uid
- api.request.data
- actor.user.uid
- http_request.user_agent
- src_endpoint.ip
- src_endpoint.domain
- cloud.region
security_domain: network
tests:
- name: True Positive Test
@@ -28,6 +28,7 @@ rba:
risk_objects:
- field: user
type: user
score: 49
threat_objects:
- field: src_ip
type: ip_address
@@ -35,35 +36,15 @@ tags:
analytic_story:
- AWS Identity and Access Management Account Takeover
asset_type: AWS Account
confidence: 70
impact: 70
mitre_attack_id:
- T1586
- T1586.003
- T1110
- T1110.001
observable:
- name: src_ip
type: IP Address
role:
- Attacker
- name: user
type: User
role:
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- api.operation
- actor.user.uid
- actor.user.account.uid
- http_request.user_agent
- src_endpoint.ip
- src_endpoint.domain
- cloud.region
risk_score: 49
security_domain: threat
tests:
- name: True Positive Test
@@ -35,8 +35,6 @@ tags:
analytic_story:
- AWS Identity and Access Management Account Takeover
asset_type: AWS Account
confidence: 70
impact: 70
mitre_attack_id:
- T1586
- T1586.003
@@ -45,15 +43,6 @@ tags:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- api.operation
- api.request.data
- actor.user.uid
- actor.user.account.uid
- http_request.user_agent
- src_endpoint.ip
- src_endpoint.domain
- cloud.region
security_domain: threat
tests:
- name: True Positive Test
@@ -13,21 +13,10 @@ how_to_implement: The detection is based on Amazon Security Lake events from Ama
known_false_positives: While this search has no known false positives, it is possible that it is a legitimate admin activity. Please consider filtering out these noisy events using userAgent, user_arn field names.
references:
- https://stratus-red-team.cloud/attack-techniques/AWS/aws.defense-evasion.cloudtrail-lifecycle-rule/
rba:
message: User $user$ has created a new rule to on an S3 bucket $bucketName$ with short expiration days
risk_objects:
- field: user
type: user
score: 20
threat_objects:
- field: src_ip
type: ip_address
tags:
analytic_story:
- AWS Defense Evasion
asset_type: AWS Account
confidence: 40
impact: 50
mitre_attack_id:
- T1562.008
- T1562
@@ -37,15 +26,6 @@ tags:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- api.operation
- api.request.data
- actor.user.uid
- actor.user.account.uid
- http_request.user_agent
- src_endpoint.ip
- src_endpoint.domain
- cloud.region
security_domain: threat
tests:
- name: True Positive Test
@@ -48,24 +48,12 @@ tags:
analytic_story:
- Ransomware Cloud
asset_type: AWS Account
confidence: 50
impact: 50
message: AWS account is potentially compromised and user $user$ is trying to compromise other accounts.
mitre_attack_id:
- T1486
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- api.operation
- actor.user.uid
- actor.user.account.uid
- api.request.data
- http_request.user_agent
- src_endpoint.ip
- src_endpoint.domain
- cloud.region
security_domain: threat
tests:
- name: True Positive Test
@@ -44,23 +44,12 @@ tags:
- Suspicious AWS S3 Activities
- Data Exfiltration
asset_type: AWS Account
confidence: 80
impact: 80
mitre_attack_id:
- T1490
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- api.operation
- actor.user.uid
- actor.user.account.uid
- api.request.data
- http_request.user_agent
- src_endpoint.ip
- src_endpoint.domain
- cloud.region
security_domain: threat
tests:
- name: True Positive Test
@@ -44,23 +44,12 @@ tags:
- Suspicious Cloud Instance Activities
- Data Exfiltration
asset_type: EC2 Snapshot
confidence: 80
impact: 60
mitre_attack_id:
- T1537
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- api.operation
- actor.user.uid
- actor.user.account.uid
- api.request.data
- http_request.user_agent
- src_endpoint.ip
- src_endpoint.domain
- cloud.region
security_domain: threat
tests:
- name: True Positive Test
@@ -41,19 +41,12 @@ tags:
analytic_story:
- Suspicious Cloud User Activities
asset_type: AWS Account
confidence: 50
impact: 20
mitre_attack_id:
- T1580
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- api.operation
- actor.user.uid
- src_endpoint.ip
- cloud.region
security_domain: access
tests:
- name: True Positive Test
@@ -42,8 +42,6 @@ tags:
analytic_story:
- AWS IAM Privilege Escalation
asset_type: AWS Account
confidence: 70
impact: 40
mitre_attack_id:
- T1580
- T1110
@@ -51,12 +49,6 @@ tags:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- api.operation
- actor.user.uid
- src_endpoint.ip
- cloud.region
security_domain: access
tests:
- name: True Positive Test
@@ -44,8 +44,6 @@ tags:
analytic_story:
- AWS Network ACL Activity
asset_type: AWS Instance
confidence: 80
impact: 60
mitre_attack_id:
- T1562.007
- T1562
@@ -53,14 +51,6 @@ tags:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- api.operation
- api.request.data
- actor.user.uid
- actor.user.account.uid
- http_request.user_agent
- src_endpoint.ip
- cloud.region
security_domain: network
tests:
- name: True Positive Test
@@ -41,8 +41,6 @@ tags:
analytic_story:
- AWS Network ACL Activity
asset_type: AWS Instance
confidence: 50
impact: 10
mitre_attack_id:
- T1562.007
- T1562
@@ -50,14 +48,6 @@ tags:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- api.operation
- api.request.data
- actor.user.uid
- actor.user.account.uid
- http_request.user_agent
- src_endpoint.ip
- cloud.region
security_domain: network
tests:
- name: True Positive Test
@@ -42,22 +42,12 @@ tags:
analytic_story:
- Cloud Federated Credential Abuse
asset_type: AWS Federated Account
confidence: 80
impact: 80
message: User $user$ from IP address $src_ip$ updated the SAML provider
mitre_attack_id:
- T1078
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- api.operation
- actor.user.uid
- actor.user.account.uid
- http_request.user_agent
- src_endpoint.ip
- cloud.region
security_domain: threat
tests:
- name: True Positive Test
@@ -40,8 +40,6 @@ tags:
analytic_story:
- AWS IAM Privilege Escalation
asset_type: AWS Account
confidence: 60
impact: 50
mitre_attack_id:
- T1136.003
- T1136
@@ -49,13 +47,6 @@ tags:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- api.operation
- actor.user.uid
- actor.user.account.uid
- http_request.user_agent
- src_endpoint.ip
- cloud.region
security_domain: threat
tests:
- name: True Positive Test
@@ -3,7 +3,7 @@ id: d62852db-a1f1-40db-a7fc-c3d56fa8bda3
version: 1
date: '2025-01-06'
author: Dean Luxton
data_sources:
data_source:
- Azure Active Directory NonInteractiveUserSignInLogs
- Azure Active Directory MicrosoftGraphActivityLogs
type: TTP
@@ -35,7 +35,7 @@ rba:
message: AzureHound UserAgent String $user_agent$ Detected on Tenant $tenantId$
risk_objects:
- field: tenantId
type: Other
type: other
score: 80
threat_objects:
- field: src
@@ -47,9 +47,6 @@ tags:
- Azure Active Directory Privilege Escalation
- Compromised User Account
asset_type: Azure Tenant
confidence: 100
impact: 80
message: AzureHound UserAgent String $user_agent$ Detected on Tenant $tenantId$
mitre_attack_id:
- T1087.004
- T1526
@@ -57,11 +54,6 @@ tags:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- src
- category
- properties.userAgent
- tenantId
security_domain: identity
tests:
- name: True Positive Test
@@ -39,7 +39,7 @@ rba:
message: $spn_count$ Service Principals have been enumerated by $user$ from IP $src$
risk_objects:
- field: tenantId
type: Other
type: other
score: 80
threat_objects:
- field: src
@@ -51,8 +51,6 @@ tags:
- Azure Active Directory Privilege Escalation
- Compromised User Account
asset_type: Azure Tenant
confidence: 100
impact: 80
mitre_attack_id:
- T1087.004
- T1526
@@ -60,11 +58,6 @@ tags:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- category
- properties.requestUri
- src
- user
security_domain: identity
tests:
- name: True Positive Test
@@ -3,7 +3,7 @@ id: 29eb39d3-2bc8-49cc-99b3-35593191a588
version: 1
date: '2025-01-06'
author: Dean Luxton
data_sources:
data_source:
- Azure Active Directory Add app role assignment to service principal
type: TTP
status: production
@@ -48,8 +48,6 @@ tags:
analytic_story:
- Azure Active Directory Privilege Escalation
asset_type: Azure Tenant
confidence: 100
impact: 100
mitre_attack_id:
- T1098.003
- T1098
@@ -57,18 +55,6 @@ tags:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- user_agent
- identity
- properties.initiatedBy.app.servicePrincipalId
- operationName
- tenantId
- correlationId
- category
- properties.initiatedBy.app.displayName
- properties.result
- properties{}.targetResources{}.modifiedProperties{}
- properties.targetResources{}.displayName
security_domain: identity
tests:
- name: True Positive Test
@@ -3,7 +3,7 @@ id: 6fe42e07-15b1-4caa-b547-7885666cb1bd
version: 1
date: '2025-01-06'
author: Dean Luxton
data_sources:
data_source:
- Azure Monitor Activity
type: Hunting
status: production
@@ -29,8 +29,6 @@ tags:
analytic_story:
- Azure Active Directory Account Takeover
asset_type: Azure Tenant
confidence: 40
impact: 100
mitre_attack_id:
- T1072
- T1021.007
@@ -40,10 +38,6 @@ tags:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- operationName
- identity
- properties.TargetObjectIds{}
security_domain: audit
tests:
- name: True Positive Test
@@ -3,7 +3,7 @@ id: 3c49e5ed-625c-408c-a2c7-8e2b524efb2c
version: 1
date: '2025-01-07'
author: Dean Luxton
data_sources:
data_source:
- Azure Monitor Activity
type: Hunting
status: production
@@ -31,8 +31,6 @@ tags:
analytic_story:
- Azure Active Directory Account Takeover
asset_type: Azure Tenant
confidence: 40
impact: 100
mitre_attack_id:
- T1072
- T1484
@@ -43,10 +41,6 @@ tags:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- operationName
- identity
- properties.TargetObjectIds{}
security_domain: audit
tests:
- name: True Positive Test
@@ -3,7 +3,7 @@ id: 5ca7ebee-4ee7-4cf2-b3be-0ea26a00d822
version: 1
date: '2025-01-07'
author: Dean Luxton
data_sources:
data_source:
- Azure Monitor Activity
type: Hunting
status: production
@@ -31,8 +31,6 @@ tags:
analytic_story:
- Azure Active Directory Account Takeover
asset_type: Azure Tenant
confidence: 70
impact: 20
mitre_attack_id:
- T1021.007
- T1072
@@ -41,10 +39,6 @@ tags:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- operationName
- identity
- properties.TargetObjectIds{}
security_domain: audit
tests:
- name: True Positive Test
@@ -3,7 +3,7 @@ id: 98e6b389-2806-4426-a580-8a92cb0d9710
version: 1
date: '2025-01-07'
author: Dean Luxton
data_sources:
data_source:
- Azure Monitor Activity
type: Hunting
status: experimental
@@ -29,8 +29,6 @@ tags:
analytic_story:
- Azure Active Directory Account Takeover
asset_type: Azure Tenant
confidence: 40
impact: 100
mitre_attack_id:
- T1072
- T1021.007
@@ -40,10 +38,6 @@ tags:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- operationName
- identity
- properties.TargetObjectIds{}
security_domain: audit
tests:
- name: True Positive Test
@@ -3,7 +3,7 @@ id: b686d0bd-cca7-44ca-ae07-87f6465131d9
version: 1
date: '2025-01-06'
author: Dean Luxton
data_sources:
data_source:
- O365 Add app role assignment grant to user
type: TTP
status: production
@@ -47,8 +47,6 @@ tags:
- Azure Active Directory Privilege Escalation
- Office 365 Account Takeover
asset_type: Azure Tenant
confidence: 100
impact: 100
mitre_attack_id:
- T1098.003
- T1098
@@ -56,15 +54,6 @@ tags:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- user_agent
- Actor{}.ID
- ResultStatus
- Operation
- ModifiedProperties{}
- user
- InterSystemsId
- tenant_id
security_domain: identity
tests:
- name: True Positive Test