From ef2ac2a45fa9f901c68799e2bfed7edea6c95aae Mon Sep 17 00:00:00 2001 From: ljstella Date: Wed, 15 Jan 2025 15:17:50 -0600 Subject: [PATCH] Removal of fields from new detections --- .../cloud/asl_aws_create_access_key.yml | 10 --------- ..._policy_version_to_allow_all_resources.yml | 16 -------------- ..._aws_credential_access_getpassworddata.yml | 21 +------------------ ...s_credential_access_rds_password_reset.yml | 11 ---------- ...aws_defense_evasion_putbucketlifecycle.yml | 20 ------------------ ...g_keys_with_encrypt_policy_without_mfa.yml | 12 ----------- .../asl_aws_disable_bucket_versioning.yml | 11 ---------- ...asl_aws_ec2_snapshot_shared_externally.yml | 11 ---------- ..._aws_iam_accessdenied_discovery_events.yml | 7 ------- ...aws_iam_assume_role_policy_brute_force.yml | 8 ------- ...ntrol_list_created_with_all_open_ports.yml | 10 --------- ...ws_network_access_control_list_deleted.yml | 10 --------- .../asl_aws_saml_update_identity_provider.yml | 10 --------- .../cloud/asl_aws_updateloginprofile.yml | 9 -------- ...azure_ad_azurehound_useragent_detected.yml | 12 ++--------- ...azure_ad_service_principal_enumeration.yml | 9 +------- ...service_principal_privilege_escalation.yml | 16 +------------- ...microsoft_intune_device_health_scripts.yml | 8 +------ ..._devicemanagementconfigurationpolicies.yml | 8 +------ ...rosoft_intune_manual_device_management.yml | 8 +------ .../cloud/microsoft_intune_mobile_apps.yml | 8 +------ ...service_principal_privilege_escalation.yml | 13 +----------- 22 files changed, 10 insertions(+), 238 deletions(-) diff --git a/detections/cloud/asl_aws_create_access_key.yml b/detections/cloud/asl_aws_create_access_key.yml index 8360d06107..eeb433eaa8 100644 --- a/detections/cloud/asl_aws_create_access_key.yml +++ b/detections/cloud/asl_aws_create_access_key.yml @@ -18,8 +18,6 @@ tags: analytic_story: - AWS IAM Privilege Escalation asset_type: AWS Account - confidence: 90 - impact: 70 mitre_attack_id: - T1136.003 - T1136 @@ -27,14 +25,6 @@ tags: - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud - required_fields: - - api.operation - - actor.user.uid - - actor.user.account.uid - - http_request.user_agent - - src_endpoint.ip - - src_endpoint.domain - - cloud.region security_domain: network tests: - name: True Positive Test diff --git a/detections/cloud/asl_aws_create_policy_version_to_allow_all_resources.yml b/detections/cloud/asl_aws_create_policy_version_to_allow_all_resources.yml index b58aeffbba..d4620bd070 100644 --- a/detections/cloud/asl_aws_create_policy_version_to_allow_all_resources.yml +++ b/detections/cloud/asl_aws_create_policy_version_to_allow_all_resources.yml @@ -34,29 +34,13 @@ tags: analytic_story: - AWS IAM Privilege Escalation asset_type: AWS Account - confidence: 70 - impact: 70 mitre_attack_id: - T1078.004 - T1078 - observable: - - name: user - type: User - role: - - Victim product: - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud - required_fields: - - api.operation - - actor.user.account.uid - - api.request.data - - actor.user.uid - - http_request.user_agent - - src_endpoint.ip - - src_endpoint.domain - - cloud.region security_domain: network tests: - name: True Positive Test diff --git a/detections/cloud/asl_aws_credential_access_getpassworddata.yml b/detections/cloud/asl_aws_credential_access_getpassworddata.yml index e066738260..4c112af04c 100644 --- a/detections/cloud/asl_aws_credential_access_getpassworddata.yml +++ b/detections/cloud/asl_aws_credential_access_getpassworddata.yml @@ -28,6 +28,7 @@ rba: risk_objects: - field: user type: user + score: 49 threat_objects: - field: src_ip type: ip_address @@ -35,35 +36,15 @@ tags: analytic_story: - AWS Identity and Access Management Account Takeover asset_type: AWS Account - confidence: 70 - impact: 70 mitre_attack_id: - T1586 - T1586.003 - T1110 - T1110.001 - observable: - - name: src_ip - type: IP Address - role: - - Attacker - - name: user - type: User - role: - - Victim product: - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud - required_fields: - - api.operation - - actor.user.uid - - actor.user.account.uid - - http_request.user_agent - - src_endpoint.ip - - src_endpoint.domain - - cloud.region - risk_score: 49 security_domain: threat tests: - name: True Positive Test diff --git a/detections/cloud/asl_aws_credential_access_rds_password_reset.yml b/detections/cloud/asl_aws_credential_access_rds_password_reset.yml index 6b69e67e2c..300892fee9 100644 --- a/detections/cloud/asl_aws_credential_access_rds_password_reset.yml +++ b/detections/cloud/asl_aws_credential_access_rds_password_reset.yml @@ -35,8 +35,6 @@ tags: analytic_story: - AWS Identity and Access Management Account Takeover asset_type: AWS Account - confidence: 70 - impact: 70 mitre_attack_id: - T1586 - T1586.003 @@ -45,15 +43,6 @@ tags: - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud - required_fields: - - api.operation - - api.request.data - - actor.user.uid - - actor.user.account.uid - - http_request.user_agent - - src_endpoint.ip - - src_endpoint.domain - - cloud.region security_domain: threat tests: - name: True Positive Test diff --git a/detections/cloud/asl_aws_defense_evasion_putbucketlifecycle.yml b/detections/cloud/asl_aws_defense_evasion_putbucketlifecycle.yml index 4b7c0b67a0..2b843cd24f 100644 --- a/detections/cloud/asl_aws_defense_evasion_putbucketlifecycle.yml +++ b/detections/cloud/asl_aws_defense_evasion_putbucketlifecycle.yml @@ -13,21 +13,10 @@ how_to_implement: The detection is based on Amazon Security Lake events from Ama known_false_positives: While this search has no known false positives, it is possible that it is a legitimate admin activity. Please consider filtering out these noisy events using userAgent, user_arn field names. references: - https://stratus-red-team.cloud/attack-techniques/AWS/aws.defense-evasion.cloudtrail-lifecycle-rule/ -rba: - message: User $user$ has created a new rule to on an S3 bucket $bucketName$ with short expiration days - risk_objects: - - field: user - type: user - score: 20 - threat_objects: - - field: src_ip - type: ip_address tags: analytic_story: - AWS Defense Evasion asset_type: AWS Account - confidence: 40 - impact: 50 mitre_attack_id: - T1562.008 - T1562 @@ -37,15 +26,6 @@ tags: - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud - required_fields: - - api.operation - - api.request.data - - actor.user.uid - - actor.user.account.uid - - http_request.user_agent - - src_endpoint.ip - - src_endpoint.domain - - cloud.region security_domain: threat tests: - name: True Positive Test diff --git a/detections/cloud/asl_aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml b/detections/cloud/asl_aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml index 2da368a653..41ee11048f 100644 --- a/detections/cloud/asl_aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml +++ b/detections/cloud/asl_aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml @@ -48,24 +48,12 @@ tags: analytic_story: - Ransomware Cloud asset_type: AWS Account - confidence: 50 - impact: 50 - message: AWS account is potentially compromised and user $user$ is trying to compromise other accounts. mitre_attack_id: - T1486 product: - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud - required_fields: - - api.operation - - actor.user.uid - - actor.user.account.uid - - api.request.data - - http_request.user_agent - - src_endpoint.ip - - src_endpoint.domain - - cloud.region security_domain: threat tests: - name: True Positive Test diff --git a/detections/cloud/asl_aws_disable_bucket_versioning.yml b/detections/cloud/asl_aws_disable_bucket_versioning.yml index 66232a2458..b475b18556 100644 --- a/detections/cloud/asl_aws_disable_bucket_versioning.yml +++ b/detections/cloud/asl_aws_disable_bucket_versioning.yml @@ -44,23 +44,12 @@ tags: - Suspicious AWS S3 Activities - Data Exfiltration asset_type: AWS Account - confidence: 80 - impact: 80 mitre_attack_id: - T1490 product: - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud - required_fields: - - api.operation - - actor.user.uid - - actor.user.account.uid - - api.request.data - - http_request.user_agent - - src_endpoint.ip - - src_endpoint.domain - - cloud.region security_domain: threat tests: - name: True Positive Test diff --git a/detections/cloud/asl_aws_ec2_snapshot_shared_externally.yml b/detections/cloud/asl_aws_ec2_snapshot_shared_externally.yml index 4cc3a9b44f..baeb005631 100644 --- a/detections/cloud/asl_aws_ec2_snapshot_shared_externally.yml +++ b/detections/cloud/asl_aws_ec2_snapshot_shared_externally.yml @@ -44,23 +44,12 @@ tags: - Suspicious Cloud Instance Activities - Data Exfiltration asset_type: EC2 Snapshot - confidence: 80 - impact: 60 mitre_attack_id: - T1537 product: - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud - required_fields: - - api.operation - - actor.user.uid - - actor.user.account.uid - - api.request.data - - http_request.user_agent - - src_endpoint.ip - - src_endpoint.domain - - cloud.region security_domain: threat tests: - name: True Positive Test diff --git a/detections/cloud/asl_aws_iam_accessdenied_discovery_events.yml b/detections/cloud/asl_aws_iam_accessdenied_discovery_events.yml index b0ea311339..c4c121d8b5 100644 --- a/detections/cloud/asl_aws_iam_accessdenied_discovery_events.yml +++ b/detections/cloud/asl_aws_iam_accessdenied_discovery_events.yml @@ -41,19 +41,12 @@ tags: analytic_story: - Suspicious Cloud User Activities asset_type: AWS Account - confidence: 50 - impact: 20 mitre_attack_id: - T1580 product: - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud - required_fields: - - api.operation - - actor.user.uid - - src_endpoint.ip - - cloud.region security_domain: access tests: - name: True Positive Test diff --git a/detections/cloud/asl_aws_iam_assume_role_policy_brute_force.yml b/detections/cloud/asl_aws_iam_assume_role_policy_brute_force.yml index b7c11aee4c..3eab43490b 100644 --- a/detections/cloud/asl_aws_iam_assume_role_policy_brute_force.yml +++ b/detections/cloud/asl_aws_iam_assume_role_policy_brute_force.yml @@ -42,8 +42,6 @@ tags: analytic_story: - AWS IAM Privilege Escalation asset_type: AWS Account - confidence: 70 - impact: 40 mitre_attack_id: - T1580 - T1110 @@ -51,12 +49,6 @@ tags: - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud - required_fields: - - _time - - api.operation - - actor.user.uid - - src_endpoint.ip - - cloud.region security_domain: access tests: - name: True Positive Test diff --git a/detections/cloud/asl_aws_network_access_control_list_created_with_all_open_ports.yml b/detections/cloud/asl_aws_network_access_control_list_created_with_all_open_ports.yml index 3e036cdc04..d6bef2c61e 100644 --- a/detections/cloud/asl_aws_network_access_control_list_created_with_all_open_ports.yml +++ b/detections/cloud/asl_aws_network_access_control_list_created_with_all_open_ports.yml @@ -44,8 +44,6 @@ tags: analytic_story: - AWS Network ACL Activity asset_type: AWS Instance - confidence: 80 - impact: 60 mitre_attack_id: - T1562.007 - T1562 @@ -53,14 +51,6 @@ tags: - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud - required_fields: - - api.operation - - api.request.data - - actor.user.uid - - actor.user.account.uid - - http_request.user_agent - - src_endpoint.ip - - cloud.region security_domain: network tests: - name: True Positive Test diff --git a/detections/cloud/asl_aws_network_access_control_list_deleted.yml b/detections/cloud/asl_aws_network_access_control_list_deleted.yml index 493551fb3d..067e4b543f 100644 --- a/detections/cloud/asl_aws_network_access_control_list_deleted.yml +++ b/detections/cloud/asl_aws_network_access_control_list_deleted.yml @@ -41,8 +41,6 @@ tags: analytic_story: - AWS Network ACL Activity asset_type: AWS Instance - confidence: 50 - impact: 10 mitre_attack_id: - T1562.007 - T1562 @@ -50,14 +48,6 @@ tags: - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud - required_fields: - - api.operation - - api.request.data - - actor.user.uid - - actor.user.account.uid - - http_request.user_agent - - src_endpoint.ip - - cloud.region security_domain: network tests: - name: True Positive Test diff --git a/detections/cloud/asl_aws_saml_update_identity_provider.yml b/detections/cloud/asl_aws_saml_update_identity_provider.yml index e34853ed72..a33f61d9ed 100644 --- a/detections/cloud/asl_aws_saml_update_identity_provider.yml +++ b/detections/cloud/asl_aws_saml_update_identity_provider.yml @@ -42,22 +42,12 @@ tags: analytic_story: - Cloud Federated Credential Abuse asset_type: AWS Federated Account - confidence: 80 - impact: 80 - message: User $user$ from IP address $src_ip$ updated the SAML provider mitre_attack_id: - T1078 product: - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud - required_fields: - - api.operation - - actor.user.uid - - actor.user.account.uid - - http_request.user_agent - - src_endpoint.ip - - cloud.region security_domain: threat tests: - name: True Positive Test diff --git a/detections/cloud/asl_aws_updateloginprofile.yml b/detections/cloud/asl_aws_updateloginprofile.yml index c8ced55fc9..eab3050952 100644 --- a/detections/cloud/asl_aws_updateloginprofile.yml +++ b/detections/cloud/asl_aws_updateloginprofile.yml @@ -40,8 +40,6 @@ tags: analytic_story: - AWS IAM Privilege Escalation asset_type: AWS Account - confidence: 60 - impact: 50 mitre_attack_id: - T1136.003 - T1136 @@ -49,13 +47,6 @@ tags: - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud - required_fields: - - api.operation - - actor.user.uid - - actor.user.account.uid - - http_request.user_agent - - src_endpoint.ip - - cloud.region security_domain: threat tests: - name: True Positive Test diff --git a/detections/cloud/azure_ad_azurehound_useragent_detected.yml b/detections/cloud/azure_ad_azurehound_useragent_detected.yml index b194270d52..12b044f4c3 100644 --- a/detections/cloud/azure_ad_azurehound_useragent_detected.yml +++ b/detections/cloud/azure_ad_azurehound_useragent_detected.yml @@ -3,7 +3,7 @@ id: d62852db-a1f1-40db-a7fc-c3d56fa8bda3 version: 1 date: '2025-01-06' author: Dean Luxton -data_sources: +data_source: - Azure Active Directory NonInteractiveUserSignInLogs - Azure Active Directory MicrosoftGraphActivityLogs type: TTP @@ -35,7 +35,7 @@ rba: message: AzureHound UserAgent String $user_agent$ Detected on Tenant $tenantId$ risk_objects: - field: tenantId - type: Other + type: other score: 80 threat_objects: - field: src @@ -47,9 +47,6 @@ tags: - Azure Active Directory Privilege Escalation - Compromised User Account asset_type: Azure Tenant - confidence: 100 - impact: 80 - message: AzureHound UserAgent String $user_agent$ Detected on Tenant $tenantId$ mitre_attack_id: - T1087.004 - T1526 @@ -57,11 +54,6 @@ tags: - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud - required_fields: - - src - - category - - properties.userAgent - - tenantId security_domain: identity tests: - name: True Positive Test diff --git a/detections/cloud/azure_ad_service_principal_enumeration.yml b/detections/cloud/azure_ad_service_principal_enumeration.yml index 15d8e1c24c..0b2628a773 100644 --- a/detections/cloud/azure_ad_service_principal_enumeration.yml +++ b/detections/cloud/azure_ad_service_principal_enumeration.yml @@ -39,7 +39,7 @@ rba: message: $spn_count$ Service Principals have been enumerated by $user$ from IP $src$ risk_objects: - field: tenantId - type: Other + type: other score: 80 threat_objects: - field: src @@ -51,8 +51,6 @@ tags: - Azure Active Directory Privilege Escalation - Compromised User Account asset_type: Azure Tenant - confidence: 100 - impact: 80 mitre_attack_id: - T1087.004 - T1526 @@ -60,11 +58,6 @@ tags: - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud - required_fields: - - category - - properties.requestUri - - src - - user security_domain: identity tests: - name: True Positive Test diff --git a/detections/cloud/azure_ad_service_principal_privilege_escalation.yml b/detections/cloud/azure_ad_service_principal_privilege_escalation.yml index 732641f3cc..29720e929f 100644 --- a/detections/cloud/azure_ad_service_principal_privilege_escalation.yml +++ b/detections/cloud/azure_ad_service_principal_privilege_escalation.yml @@ -3,7 +3,7 @@ id: 29eb39d3-2bc8-49cc-99b3-35593191a588 version: 1 date: '2025-01-06' author: Dean Luxton -data_sources: +data_source: - Azure Active Directory Add app role assignment to service principal type: TTP status: production @@ -48,8 +48,6 @@ tags: analytic_story: - Azure Active Directory Privilege Escalation asset_type: Azure Tenant - confidence: 100 - impact: 100 mitre_attack_id: - T1098.003 - T1098 @@ -57,18 +55,6 @@ tags: - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud - required_fields: - - user_agent - - identity - - properties.initiatedBy.app.servicePrincipalId - - operationName - - tenantId - - correlationId - - category - - properties.initiatedBy.app.displayName - - properties.result - - properties{}.targetResources{}.modifiedProperties{} - - properties.targetResources{}.displayName security_domain: identity tests: - name: True Positive Test diff --git a/detections/cloud/microsoft_intune_device_health_scripts.yml b/detections/cloud/microsoft_intune_device_health_scripts.yml index 3797691df4..26a8429bfa 100644 --- a/detections/cloud/microsoft_intune_device_health_scripts.yml +++ b/detections/cloud/microsoft_intune_device_health_scripts.yml @@ -3,7 +3,7 @@ id: 6fe42e07-15b1-4caa-b547-7885666cb1bd version: 1 date: '2025-01-06' author: Dean Luxton -data_sources: +data_source: - Azure Monitor Activity type: Hunting status: production @@ -29,8 +29,6 @@ tags: analytic_story: - Azure Active Directory Account Takeover asset_type: Azure Tenant - confidence: 40 - impact: 100 mitre_attack_id: - T1072 - T1021.007 @@ -40,10 +38,6 @@ tags: - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud - required_fields: - - operationName - - identity - - properties.TargetObjectIds{} security_domain: audit tests: - name: True Positive Test diff --git a/detections/cloud/microsoft_intune_devicemanagementconfigurationpolicies.yml b/detections/cloud/microsoft_intune_devicemanagementconfigurationpolicies.yml index 133cfdf875..4e8114911d 100644 --- a/detections/cloud/microsoft_intune_devicemanagementconfigurationpolicies.yml +++ b/detections/cloud/microsoft_intune_devicemanagementconfigurationpolicies.yml @@ -3,7 +3,7 @@ id: 3c49e5ed-625c-408c-a2c7-8e2b524efb2c version: 1 date: '2025-01-07' author: Dean Luxton -data_sources: +data_source: - Azure Monitor Activity type: Hunting status: production @@ -31,8 +31,6 @@ tags: analytic_story: - Azure Active Directory Account Takeover asset_type: Azure Tenant - confidence: 40 - impact: 100 mitre_attack_id: - T1072 - T1484 @@ -43,10 +41,6 @@ tags: - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud - required_fields: - - operationName - - identity - - properties.TargetObjectIds{} security_domain: audit tests: - name: True Positive Test diff --git a/detections/cloud/microsoft_intune_manual_device_management.yml b/detections/cloud/microsoft_intune_manual_device_management.yml index ebff4fa243..d152bb5d9d 100644 --- a/detections/cloud/microsoft_intune_manual_device_management.yml +++ b/detections/cloud/microsoft_intune_manual_device_management.yml @@ -3,7 +3,7 @@ id: 5ca7ebee-4ee7-4cf2-b3be-0ea26a00d822 version: 1 date: '2025-01-07' author: Dean Luxton -data_sources: +data_source: - Azure Monitor Activity type: Hunting status: production @@ -31,8 +31,6 @@ tags: analytic_story: - Azure Active Directory Account Takeover asset_type: Azure Tenant - confidence: 70 - impact: 20 mitre_attack_id: - T1021.007 - T1072 @@ -41,10 +39,6 @@ tags: - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud - required_fields: - - operationName - - identity - - properties.TargetObjectIds{} security_domain: audit tests: - name: True Positive Test diff --git a/detections/cloud/microsoft_intune_mobile_apps.yml b/detections/cloud/microsoft_intune_mobile_apps.yml index 07efc2b22a..807c515f26 100644 --- a/detections/cloud/microsoft_intune_mobile_apps.yml +++ b/detections/cloud/microsoft_intune_mobile_apps.yml @@ -3,7 +3,7 @@ id: 98e6b389-2806-4426-a580-8a92cb0d9710 version: 1 date: '2025-01-07' author: Dean Luxton -data_sources: +data_source: - Azure Monitor Activity type: Hunting status: experimental @@ -29,8 +29,6 @@ tags: analytic_story: - Azure Active Directory Account Takeover asset_type: Azure Tenant - confidence: 40 - impact: 100 mitre_attack_id: - T1072 - T1021.007 @@ -40,10 +38,6 @@ tags: - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud - required_fields: - - operationName - - identity - - properties.TargetObjectIds{} security_domain: audit tests: - name: True Positive Test diff --git a/detections/cloud/o365_service_principal_privilege_escalation.yml b/detections/cloud/o365_service_principal_privilege_escalation.yml index 2ff8e59180..ee93c75401 100644 --- a/detections/cloud/o365_service_principal_privilege_escalation.yml +++ b/detections/cloud/o365_service_principal_privilege_escalation.yml @@ -3,7 +3,7 @@ id: b686d0bd-cca7-44ca-ae07-87f6465131d9 version: 1 date: '2025-01-06' author: Dean Luxton -data_sources: +data_source: - O365 Add app role assignment grant to user type: TTP status: production @@ -47,8 +47,6 @@ tags: - Azure Active Directory Privilege Escalation - Office 365 Account Takeover asset_type: Azure Tenant - confidence: 100 - impact: 100 mitre_attack_id: - T1098.003 - T1098 @@ -56,15 +54,6 @@ tags: - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud - required_fields: - - user_agent - - Actor{}.ID - - ResultStatus - - Operation - - ModifiedProperties{} - - user - - InterSystemsId - - tenant_id security_domain: identity tests: - name: True Positive Test