mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
update and pull in all the latest changes from
develop branch
This commit is contained in:
@@ -1,7 +1,7 @@
|
||||
name: Detect Distributed Password Spray Attempts
|
||||
id: b1a82fc8-8a9f-4344-9ec2-bde5c5331b57
|
||||
version: 3
|
||||
date: '2025-01-21'
|
||||
version: 4
|
||||
date: '2025-02-10'
|
||||
author: Dean Luxton
|
||||
status: production
|
||||
type: Hunting
|
||||
@@ -65,7 +65,6 @@ tags:
|
||||
- 90bc2e54-6c84-47a5-9439-0a2a92b4b175
|
||||
mitre_attack_id:
|
||||
- T1110.003
|
||||
- T1110
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Detect Password Spray Attempts
|
||||
id: 086ab581-8877-42b3-9aee-4a7ecb0923af
|
||||
version: 5
|
||||
date: '2025-01-21'
|
||||
version: 6
|
||||
date: '2025-02-10'
|
||||
author: Dean Luxton
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -83,7 +83,6 @@ tags:
|
||||
- 90bc2e54-6c84-47a5-9439-0a2a92b4b175
|
||||
mitre_attack_id:
|
||||
- T1110.003
|
||||
- T1110
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Email files written outside of the Outlook directory
|
||||
id: 8d52cf03-ba25-4101-aa78-07994aed4f74
|
||||
version: 6
|
||||
date: '2025-01-21'
|
||||
version: 7
|
||||
date: '2025-02-10'
|
||||
author: Bhavin Patel, Splunk
|
||||
status: experimental
|
||||
type: TTP
|
||||
@@ -44,7 +44,6 @@ tags:
|
||||
- Collection and Staging
|
||||
asset_type: Endpoint
|
||||
mitre_attack_id:
|
||||
- T1114
|
||||
- T1114.001
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Email servers sending high volume traffic to hosts
|
||||
id: 7f5fb3e1-4209-4914-90db-0ec21b556378
|
||||
version: 5
|
||||
date: '2025-01-21'
|
||||
version: 6
|
||||
date: '2025-02-10'
|
||||
author: Bhavin Patel, Splunk
|
||||
status: experimental
|
||||
type: Anomaly
|
||||
@@ -51,7 +51,6 @@ tags:
|
||||
- HAFNIUM Group
|
||||
asset_type: Endpoint
|
||||
mitre_attack_id:
|
||||
- T1114
|
||||
- T1114.002
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Okta Authentication Failed During MFA Challenge
|
||||
id: e2b99e7d-d956-411a-a120-2b14adfdde93
|
||||
version: 4
|
||||
date: '2025-01-21'
|
||||
version: 5
|
||||
date: '2025-02-10'
|
||||
author: Bhavin Patel, Splunk
|
||||
data_source:
|
||||
- Okta
|
||||
@@ -59,10 +59,8 @@ tags:
|
||||
- Okta Account Takeover
|
||||
asset_type: Okta Tenant
|
||||
mitre_attack_id:
|
||||
- T1586
|
||||
- T1586.003
|
||||
- T1078
|
||||
- T1078.004
|
||||
- T1586.003
|
||||
- T1621
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Okta Multi-Factor Authentication Disabled
|
||||
id: 7c0348ce-bdf9-45f6-8a57-c18b5976f00a
|
||||
version: 5
|
||||
date: '2025-01-21'
|
||||
version: 6
|
||||
date: '2025-02-10'
|
||||
author: Mauricio Velazco, Splunk
|
||||
data_source:
|
||||
- Okta
|
||||
@@ -57,7 +57,6 @@ tags:
|
||||
- Okta Account Takeover
|
||||
asset_type: Okta Tenant
|
||||
mitre_attack_id:
|
||||
- T1556
|
||||
- T1556.006
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Okta New API Token Created
|
||||
id: c3d22720-35d3-4da4-bd0a-740d37192bd4
|
||||
version: 6
|
||||
date: '2025-01-21'
|
||||
version: 7
|
||||
date: '2025-02-10'
|
||||
author: Michael Haag, Mauricio Velazco, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -54,7 +54,6 @@ tags:
|
||||
- Okta Account Takeover
|
||||
asset_type: Okta Tenant
|
||||
mitre_attack_id:
|
||||
- T1078
|
||||
- T1078.001
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Okta New Device Enrolled on Account
|
||||
id: bb27cbce-d4de-432c-932f-2e206e9130fb
|
||||
version: 6
|
||||
date: '2025-01-21'
|
||||
version: 7
|
||||
date: '2025-02-10'
|
||||
author: Michael Haag, Mauricio Velazco, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -54,7 +54,6 @@ tags:
|
||||
- Okta Account Takeover
|
||||
asset_type: Okta Tenant
|
||||
mitre_attack_id:
|
||||
- T1098
|
||||
- T1098.005
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Okta Phishing Detection with FastPass Origin Check
|
||||
id: f4ca0057-cbf3-44f8-82ea-4e330ee901d3
|
||||
version: 4
|
||||
date: '2025-01-21'
|
||||
version: 5
|
||||
date: '2025-02-10'
|
||||
author: Okta, Inc, Michael Haag, Splunk
|
||||
type: TTP
|
||||
status: experimental
|
||||
@@ -38,7 +38,6 @@ tags:
|
||||
- Okta Account Takeover
|
||||
asset_type: Infrastructure
|
||||
mitre_attack_id:
|
||||
- T1078
|
||||
- T1078.001
|
||||
- T1556
|
||||
product:
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Okta Successful Single Factor Authentication
|
||||
id: 98f6ad4f-4325-4096-9d69-45dc8e638e82
|
||||
version: 4
|
||||
date: '2025-01-21'
|
||||
version: 5
|
||||
date: '2025-02-10'
|
||||
author: Bhavin Patel, Splunk
|
||||
data_source:
|
||||
- Okta
|
||||
@@ -55,10 +55,8 @@ tags:
|
||||
- Okta Account Takeover
|
||||
asset_type: Okta Tenant
|
||||
mitre_attack_id:
|
||||
- T1586
|
||||
- T1586.003
|
||||
- T1078
|
||||
- T1078.004
|
||||
- T1586.003
|
||||
- T1621
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Okta Suspicious Activity Reported
|
||||
id: bfc840f5-c9c6-454c-aa13-b46fd0bf1e79
|
||||
version: 5
|
||||
date: '2025-01-21'
|
||||
version: 6
|
||||
date: '2025-02-10'
|
||||
author: Michael Haag, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -55,7 +55,6 @@ tags:
|
||||
- Okta Account Takeover
|
||||
asset_type: Okta Tenant
|
||||
mitre_attack_id:
|
||||
- T1078
|
||||
- T1078.001
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Okta ThreatInsight Threat Detected
|
||||
id: 140504ae-5fe2-4d65-b2bc-a211813fbca6
|
||||
version: 5
|
||||
date: '2025-01-21'
|
||||
version: 6
|
||||
date: '2025-02-10'
|
||||
author: Michael Haag, Mauricio Velazco, Splunk
|
||||
status: production
|
||||
type: Anomaly
|
||||
@@ -56,7 +56,6 @@ tags:
|
||||
- Okta Account Takeover
|
||||
asset_type: Infrastructure
|
||||
mitre_attack_id:
|
||||
- T1078
|
||||
- T1078.004
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: PingID Mismatch Auth Source and Verification Response
|
||||
id: 15b0694e-caa2-4009-8d83-a1f98b86d086
|
||||
version: 4
|
||||
version: 5
|
||||
date: '2025-01-21'
|
||||
author: Steven Dick
|
||||
status: production
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Suspicious Email Attachment Extensions
|
||||
id: 473bd65f-06ca-4dfe-a2b8-ba04ab4a0084
|
||||
version: 6
|
||||
date: '2025-01-21'
|
||||
version: 7
|
||||
date: '2025-02-10'
|
||||
author: David Dorsey, Splunk
|
||||
status: experimental
|
||||
type: Anomaly
|
||||
@@ -48,7 +48,6 @@ tags:
|
||||
asset_type: Endpoint
|
||||
mitre_attack_id:
|
||||
- T1566.001
|
||||
- T1566
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Windows AD Dangerous Deny ACL Modification
|
||||
id: 8e897153-2ebd-4cb2-85d3-09ad57db2fb7
|
||||
version: 3
|
||||
date: '2025-01-21'
|
||||
version: 4
|
||||
date: '2025-02-10'
|
||||
author: Dean Luxton
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -76,9 +76,8 @@ tags:
|
||||
- Sneaky Active Directory Persistence Tricks
|
||||
asset_type: Endpoint
|
||||
mitre_attack_id:
|
||||
- T1484
|
||||
- T1222
|
||||
- T1222.001
|
||||
- T1484
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Windows AD Dangerous Group ACL Modification
|
||||
id: 59b0fc85-7a0d-4585-97ec-06a382801990
|
||||
version: 3
|
||||
date: '2025-01-21'
|
||||
version: 4
|
||||
date: '2025-02-10'
|
||||
author: Dean Luxton
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -85,9 +85,8 @@ tags:
|
||||
- Sneaky Active Directory Persistence Tricks
|
||||
asset_type: Endpoint
|
||||
mitre_attack_id:
|
||||
- T1484
|
||||
- T1222
|
||||
- T1222.001
|
||||
- T1484
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Windows AD Dangerous User ACL Modification
|
||||
id: ec5b6790-595a-4fb8-ad43-56e5b55a9617
|
||||
version: 3
|
||||
date: '2025-01-21'
|
||||
version: 4
|
||||
date: '2025-02-10'
|
||||
author: Dean Luxton
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -82,9 +82,8 @@ tags:
|
||||
- Sneaky Active Directory Persistence Tricks
|
||||
asset_type: Endpoint
|
||||
mitre_attack_id:
|
||||
- T1484
|
||||
- T1222
|
||||
- T1222.001
|
||||
- T1484
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Windows AD Domain Root ACL Deletion
|
||||
id: 3cb56e57-5642-4638-907f-8dfde9afb889
|
||||
version: 3
|
||||
date: '2025-01-21'
|
||||
version: 4
|
||||
date: '2025-02-10'
|
||||
author: Dean Luxton
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -75,9 +75,8 @@ tags:
|
||||
- Sneaky Active Directory Persistence Tricks
|
||||
asset_type: Endpoint
|
||||
mitre_attack_id:
|
||||
- T1484
|
||||
- T1222
|
||||
- T1222.001
|
||||
- T1484
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Windows AD Domain Root ACL Modification
|
||||
id: 4981e2db-1372-440d-816e-3e7e2ed74433
|
||||
version: 3
|
||||
date: '2025-01-21'
|
||||
version: 4
|
||||
date: '2025-02-10'
|
||||
author: Dean Luxton
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -75,9 +75,8 @@ tags:
|
||||
- Sneaky Active Directory Persistence Tricks
|
||||
asset_type: Endpoint
|
||||
mitre_attack_id:
|
||||
- T1484
|
||||
- T1222
|
||||
- T1222.001
|
||||
- T1484
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Windows AD GPO New CSE Addition
|
||||
id: 700c11d1-da09-47b2-81aa-358c143c7986
|
||||
version: 3
|
||||
date: '2025-01-21'
|
||||
version: 4
|
||||
date: '2025-02-10'
|
||||
author: Dean Luxton
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -64,10 +64,8 @@ tags:
|
||||
- Sneaky Active Directory Persistence Tricks
|
||||
asset_type: Endpoint
|
||||
mitre_attack_id:
|
||||
- T1484
|
||||
- T1484.001
|
||||
- T1222
|
||||
- T1222.001
|
||||
- T1484.001
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Windows AD Hidden OU Creation
|
||||
id: 66b6ad5e-339a-40af-b721-dacefc7bdb75
|
||||
version: 3
|
||||
date: '2025-01-21'
|
||||
version: 4
|
||||
date: '2025-02-10'
|
||||
author: Dean Luxton
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -74,9 +74,8 @@ tags:
|
||||
- Sneaky Active Directory Persistence Tricks
|
||||
asset_type: Endpoint
|
||||
mitre_attack_id:
|
||||
- T1484
|
||||
- T1222
|
||||
- T1222.001
|
||||
- T1484
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Windows AD Object Owner Updated
|
||||
id: 4af01f6b-d8d4-4f96-8635-758a01557130
|
||||
version: 4
|
||||
date: '2025-01-21'
|
||||
version: 5
|
||||
date: '2025-02-10'
|
||||
author: Dean Luxton
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -66,9 +66,8 @@ tags:
|
||||
- Sneaky Active Directory Persistence Tricks
|
||||
asset_type: Endpoint
|
||||
mitre_attack_id:
|
||||
- T1484
|
||||
- T1222
|
||||
- T1222.001
|
||||
- T1484
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Windows AD Suspicious Attribute Modification
|
||||
id: 5682052e-ce55-4f9f-8d28-59191420b7e0
|
||||
version: 3
|
||||
date: '2025-01-21'
|
||||
version: 5
|
||||
date: '2025-02-10'
|
||||
author: Dean Luxton
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -62,9 +62,8 @@ tags:
|
||||
- Sneaky Active Directory Persistence Tricks
|
||||
asset_type: Endpoint
|
||||
mitre_attack_id:
|
||||
- T1550
|
||||
- T1222
|
||||
- T1222.001
|
||||
- T1550
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Windows AD Suspicious GPO Modification
|
||||
id: 0a2afc18-a3b5-4452-b60a-2e774214f9bf
|
||||
version: 3
|
||||
date: '2025-01-21'
|
||||
version: 5
|
||||
date: '2025-02-10'
|
||||
author: Dean Luxton
|
||||
status: experimental
|
||||
type: TTP
|
||||
@@ -70,10 +70,8 @@ tags:
|
||||
- Sneaky Active Directory Persistence Tricks
|
||||
asset_type: Endpoint
|
||||
mitre_attack_id:
|
||||
- T1484
|
||||
- T1484.001
|
||||
- T1222
|
||||
- T1222.001
|
||||
- T1484.001
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Abnormally High Number Of Cloud Infrastructure API Calls
|
||||
id: 0840ddf1-8c89-46ff-b730-c8d6722478c0
|
||||
version: 5
|
||||
date: '2024-11-14'
|
||||
version: 6
|
||||
date: '2025-02-10'
|
||||
author: David Dorsey, Splunk
|
||||
status: experimental
|
||||
type: Anomaly
|
||||
@@ -46,7 +46,6 @@ tags:
|
||||
asset_type: AWS Instance
|
||||
mitre_attack_id:
|
||||
- T1078.004
|
||||
- T1078
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Abnormally High Number Of Cloud Instances Destroyed
|
||||
id: ef629fc9-1583-4590-b62a-f2247fbf7bbf
|
||||
version: 5
|
||||
date: '2024-11-14'
|
||||
version: 6
|
||||
date: '2025-02-10'
|
||||
author: David Dorsey, Splunk
|
||||
status: experimental
|
||||
type: Anomaly
|
||||
@@ -48,7 +48,6 @@ tags:
|
||||
asset_type: Cloud Instance
|
||||
mitre_attack_id:
|
||||
- T1078.004
|
||||
- T1078
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Abnormally High Number Of Cloud Instances Launched
|
||||
id: f2361e9f-3928-496c-a556-120cd4223a65
|
||||
version: 6
|
||||
date: '2024-11-14'
|
||||
version: 7
|
||||
date: '2025-02-10'
|
||||
author: David Dorsey, Splunk
|
||||
status: experimental
|
||||
type: Anomaly
|
||||
@@ -48,7 +48,6 @@ tags:
|
||||
asset_type: Cloud Instance
|
||||
mitre_attack_id:
|
||||
- T1078.004
|
||||
- T1078
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Abnormally High Number Of Cloud Security Group API Calls
|
||||
id: d4dfb7f3-7a37-498a-b5df-f19334e871af
|
||||
version: 5
|
||||
date: '2024-11-14'
|
||||
version: 6
|
||||
date: '2025-02-10'
|
||||
author: David Dorsey, Splunk
|
||||
status: experimental
|
||||
type: Anomaly
|
||||
@@ -46,7 +46,6 @@ tags:
|
||||
asset_type: AWS Instance
|
||||
mitre_attack_id:
|
||||
- T1078.004
|
||||
- T1078
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -1,16 +1,33 @@
|
||||
name: ASL AWS Create Access Key
|
||||
id: 81a9f2fe-1697-473c-af1d-086b0d8b63c8
|
||||
version: 1
|
||||
date: '2024-12-12'
|
||||
version: 2
|
||||
date: '2025-02-10'
|
||||
author: Patrick Bareiss, Splunk
|
||||
status: production
|
||||
type: Hunting
|
||||
description: The following analytic identifies the creation of AWS IAM access keys by a user for another user, which can indicate privilege escalation. It leverages AWS CloudTrail logs to detect instances where the user creating the access key is different from the user for whom the key is created. This activity is significant because unauthorized access key creation can allow attackers to establish persistence or exfiltrate data via AWS APIs. If confirmed malicious, this could lead to unauthorized access to AWS services, data exfiltration, and long-term persistence in the environment.
|
||||
data_source:
|
||||
description: The following analytic identifies the creation of AWS IAM access keys
|
||||
by a user for another user, which can indicate privilege escalation. It leverages
|
||||
AWS CloudTrail logs to detect instances where the user creating the access key is
|
||||
different from the user for whom the key is created. This activity is significant
|
||||
because unauthorized access key creation can allow attackers to establish persistence
|
||||
or exfiltrate data via AWS APIs. If confirmed malicious, this could lead to unauthorized
|
||||
access to AWS services, data exfiltration, and long-term persistence in the environment.
|
||||
data_source:
|
||||
- ASL AWS CloudTrail
|
||||
search: '`amazon_security_lake` api.operation=CreateAccessKey | fillnull | stats count min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region | rename actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent as user_agent | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` |`asl_aws_create_access_key_filter`'
|
||||
how_to_implement: The detection is based on Amazon Security Lake events from Amazon Web Services (AWS), which is a centralized data lake that provides security-related data from AWS services. To use this detection, you must ingest CloudTrail logs from Amazon Security Lake into Splunk. To run this search, ensure that you ingest events using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876) or the Federated Analytics App.
|
||||
known_false_positives: While this search has no known false positives, it is possible that an AWS admin has legitimately created keys for another user.
|
||||
search: '`amazon_security_lake` api.operation=CreateAccessKey | fillnull | stats count
|
||||
min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid
|
||||
http_request.user_agent src_endpoint.ip cloud.region | rename actor.user.uid as
|
||||
user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent
|
||||
as user_agent | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
|
||||
|`asl_aws_create_access_key_filter`'
|
||||
how_to_implement: The detection is based on Amazon Security Lake events from Amazon
|
||||
Web Services (AWS), which is a centralized data lake that provides security-related
|
||||
data from AWS services. To use this detection, you must ingest CloudTrail logs from
|
||||
Amazon Security Lake into Splunk. To run this search, ensure that you ingest events
|
||||
using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876)
|
||||
or the Federated Analytics App.
|
||||
known_false_positives: While this search has no known false positives, it is possible
|
||||
that an AWS admin has legitimately created keys for another user.
|
||||
references:
|
||||
- https://bishopfox.com/blog/privilege-escalation-in-aws
|
||||
- https://rhinosecuritylabs.com/aws/aws-privilege-escalation-methods-mitigation-part-2/
|
||||
@@ -20,7 +37,6 @@ tags:
|
||||
asset_type: AWS Account
|
||||
mitre_attack_id:
|
||||
- T1136.003
|
||||
- T1136
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
@@ -29,6 +45,7 @@ tags:
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078/aws_createaccesskey/asl_ocsf_cloudtrail.json
|
||||
- data:
|
||||
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078/aws_createaccesskey/asl_ocsf_cloudtrail.json
|
||||
sourcetype: aws:asl
|
||||
source: aws_asl
|
||||
|
||||
@@ -1,16 +1,36 @@
|
||||
name: ASL AWS Create Policy Version to allow all resources
|
||||
id: 22cc7a62-3884-48c4-82da-592b8199b72f
|
||||
version: 1
|
||||
date: '2024-12-12'
|
||||
version: 2
|
||||
date: '2025-02-10'
|
||||
author: Patrick Bareiss, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
description: The following analytic identifies the creation of a new AWS IAM policy version that allows access to all resources. It detects this activity by analyzing AWS CloudTrail logs for the CreatePolicyVersion event with a policy document that grants broad permissions. This behavior is significant because it violates the principle of least privilege, potentially exposing the environment to misuse or abuse. If confirmed malicious, an attacker could gain extensive access to AWS resources, leading to unauthorized actions, data exfiltration, or further compromise of the AWS environment.
|
||||
data_source:
|
||||
description: The following analytic identifies the creation of a new AWS IAM policy
|
||||
version that allows access to all resources. It detects this activity by analyzing
|
||||
AWS CloudTrail logs for the CreatePolicyVersion event with a policy document that
|
||||
grants broad permissions. This behavior is significant because it violates the principle
|
||||
of least privilege, potentially exposing the environment to misuse or abuse. If
|
||||
confirmed malicious, an attacker could gain extensive access to AWS resources, leading
|
||||
to unauthorized actions, data exfiltration, or further compromise of the AWS environment.
|
||||
data_source:
|
||||
- ASL AWS CloudTrail
|
||||
search: '`amazon_security_lake` api.operation=CreatePolicy | spath input=api.request.data | spath input=policyDocument | regex Statement{}.Action="\*" | regex Statement{}.Resource="\*" | fillnull | stats count min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region api.request.data | rename actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent as user_agent | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`|`asl_aws_create_policy_version_to_allow_all_resources_filter`'
|
||||
how_to_implement: The detection is based on Amazon Security Lake events from Amazon Web Services (AWS), which is a centralized data lake that provides security-related data from AWS services. To use this detection, you must ingest CloudTrail logs from Amazon Security Lake into Splunk. To run this search, ensure that you ingest events using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876) or the Federated Analytics App.
|
||||
known_false_positives: While this search has no known false positives, it is possible that an AWS admin has legitimately created a policy to allow a user to access all resources. That said, AWS strongly advises against granting full control to all AWS resources and you must verify this activity.
|
||||
search: '`amazon_security_lake` api.operation=CreatePolicy | spath input=api.request.data
|
||||
| spath input=policyDocument | regex Statement{}.Action="\*" | regex Statement{}.Resource="\*"
|
||||
| fillnull | stats count min(_time) as firstTime max(_time) as lastTime by api.operation
|
||||
actor.user.uid actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region
|
||||
api.request.data | rename actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region
|
||||
as region, http_request.user_agent as user_agent | `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)`|`asl_aws_create_policy_version_to_allow_all_resources_filter`'
|
||||
how_to_implement: The detection is based on Amazon Security Lake events from Amazon
|
||||
Web Services (AWS), which is a centralized data lake that provides security-related
|
||||
data from AWS services. To use this detection, you must ingest CloudTrail logs from
|
||||
Amazon Security Lake into Splunk. To run this search, ensure that you ingest events
|
||||
using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876)
|
||||
or the Federated Analytics App.
|
||||
known_false_positives: While this search has no known false positives, it is possible
|
||||
that an AWS admin has legitimately created a policy to allow a user to access all
|
||||
resources. That said, AWS strongly advises against granting full control to all
|
||||
AWS resources and you must verify this activity.
|
||||
references:
|
||||
- https://bishopfox.com/blog/privilege-escalation-in-aws
|
||||
- https://rhinosecuritylabs.com/aws/aws-privilege-escalation-methods-mitigation-part-2/
|
||||
@@ -20,11 +40,17 @@ drilldown_searches:
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
- name: View risk events for the last 7 days for - "$user$"
|
||||
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
|
||||
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$")
|
||||
starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime
|
||||
values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories)
|
||||
as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic)
|
||||
as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)`'
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
rba:
|
||||
message: User $user$ created a policy version that allows them to access any resource in their account
|
||||
message: User $user$ created a policy version that allows them to access any resource
|
||||
in their account
|
||||
risk_objects:
|
||||
- field: user
|
||||
type: user
|
||||
@@ -36,7 +62,6 @@ tags:
|
||||
asset_type: AWS Account
|
||||
mitre_attack_id:
|
||||
- T1078.004
|
||||
- T1078
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
@@ -45,6 +70,7 @@ tags:
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078/aws_create_policy_version/asl_ocsf_cloudtrail.json
|
||||
- data:
|
||||
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078/aws_create_policy_version/asl_ocsf_cloudtrail.json
|
||||
sourcetype: aws:asl
|
||||
source: aws_asl
|
||||
|
||||
@@ -1,16 +1,34 @@
|
||||
name: ASL AWS Credential Access GetPasswordData
|
||||
id: a79b607a-50cc-4704-bb9d-eff280cb78c2
|
||||
version: 1
|
||||
date: '2024-12-12'
|
||||
version: 2
|
||||
date: '2025-02-10'
|
||||
author: Patrick Bareiss, Splunk
|
||||
status: production
|
||||
type: Anomaly
|
||||
description: The following analytic identifiesGetPasswordData API calls in your AWS account. It leverages CloudTrail logs from Amazon Security Lake to detect this activity by counting the distinct instance IDs accessed. This behavior is significant as it may indicate an attempt to retrieve encrypted administrator passwords for running Windows instances, which is a critical security concern. If confirmed malicious, attackers could gain unauthorized access to administrative credentials, potentially leading to full control over the affected instances and further compromise of the AWS environment.
|
||||
data_source:
|
||||
description: The following analytic identifiesGetPasswordData API calls in your AWS
|
||||
account. It leverages CloudTrail logs from Amazon Security Lake to detect this
|
||||
activity by counting the distinct instance IDs accessed. This behavior is significant
|
||||
as it may indicate an attempt to retrieve encrypted administrator passwords for
|
||||
running Windows instances, which is a critical security concern. If confirmed malicious,
|
||||
attackers could gain unauthorized access to administrative credentials, potentially
|
||||
leading to full control over the affected instances and further compromise of the
|
||||
AWS environment.
|
||||
data_source:
|
||||
- ASL AWS CloudTrail
|
||||
search: '`amazon_security_lake` api.operation=GetPasswordData | spath input=api.request.data | fillnull | stats count min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region instanceId | rename actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent as user_agent | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` |`asl_aws_credential_access_getpassworddata_filter`'
|
||||
how_to_implement: The detection is based on Amazon Security Lake events from Amazon Web Services (AWS), which is a centralized data lake that provides security-related data from AWS services. To use this detection, you must ingest CloudTrail logs from Amazon Security Lake into Splunk. To run this search, ensure that you ingest events using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876) or the Federated Analytics App.
|
||||
known_false_positives: Administrator tooling or automated scripts may make these calls but it is highly unlikely to make several calls in a short period of time.
|
||||
search: '`amazon_security_lake` api.operation=GetPasswordData | spath input=api.request.data
|
||||
| fillnull | stats count min(_time) as firstTime max(_time) as lastTime by api.operation
|
||||
actor.user.uid actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region
|
||||
instanceId | rename actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region
|
||||
as region, http_request.user_agent as user_agent | `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)` |`asl_aws_credential_access_getpassworddata_filter`'
|
||||
how_to_implement: The detection is based on Amazon Security Lake events from Amazon
|
||||
Web Services (AWS), which is a centralized data lake that provides security-related
|
||||
data from AWS services. To use this detection, you must ingest CloudTrail logs from
|
||||
Amazon Security Lake into Splunk. To run this search, ensure that you ingest events
|
||||
using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876)
|
||||
or the Federated Analytics App.
|
||||
known_false_positives: Administrator tooling or automated scripts may make these calls
|
||||
but it is highly unlikely to make several calls in a short period of time.
|
||||
references:
|
||||
- https://attack.mitre.org/techniques/T1552/
|
||||
- https://stratus-red-team.cloud/attack-techniques/AWS/aws.credential-access.ec2-get-password-data/
|
||||
@@ -20,7 +38,12 @@ drilldown_searches:
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
- name: View risk events for the last 7 days for - "$user$"
|
||||
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
|
||||
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$")
|
||||
starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime
|
||||
values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories)
|
||||
as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic)
|
||||
as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)`'
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
rba:
|
||||
@@ -37,10 +60,8 @@ tags:
|
||||
- AWS Identity and Access Management Account Takeover
|
||||
asset_type: AWS Account
|
||||
mitre_attack_id:
|
||||
- T1586
|
||||
- T1586.003
|
||||
- T1110
|
||||
- T1110.001
|
||||
- T1586.003
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
@@ -49,6 +70,7 @@ tags:
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1552/aws_getpassworddata/asl_ocsf_cloudtrail.json
|
||||
- data:
|
||||
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1552/aws_getpassworddata/asl_ocsf_cloudtrail.json
|
||||
sourcetype: aws:asl
|
||||
source: aws_asl
|
||||
|
||||
@@ -1,15 +1,34 @@
|
||||
name: ASL AWS Credential Access RDS Password reset
|
||||
id: d15e9bd9-ef64-4d84-bc04-f62955a9fee8
|
||||
version: 1
|
||||
date: '2024-12-12'
|
||||
version: 2
|
||||
date: '2025-02-10'
|
||||
author: Patrick Bareiss, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
description: The following analytic detects the resetting of the master user password for an Amazon RDS DB instance. It leverages AWS CloudTrail logs from Amazon Security Lake to identify events where the `ModifyDBInstance` API call includes a new `masterUserPassword` parameter. This activity is significant because unauthorized password resets can grant attackers access to sensitive data stored in production databases, such as credit card information, PII, and healthcare data. If confirmed malicious, this could lead to data breaches, regulatory non-compliance, and significant reputational damage. Immediate investigation is required to determine the legitimacy of the password reset.
|
||||
data_source:
|
||||
description: The following analytic detects the resetting of the master user password
|
||||
for an Amazon RDS DB instance. It leverages AWS CloudTrail logs from Amazon Security
|
||||
Lake to identify events where the `ModifyDBInstance` API call includes a new `masterUserPassword`
|
||||
parameter. This activity is significant because unauthorized password resets can
|
||||
grant attackers access to sensitive data stored in production databases, such as
|
||||
credit card information, PII, and healthcare data. If confirmed malicious, this
|
||||
could lead to data breaches, regulatory non-compliance, and significant reputational
|
||||
damage. Immediate investigation is required to determine the legitimacy of the password
|
||||
reset.
|
||||
data_source:
|
||||
- ASL AWS CloudTrail
|
||||
search: '`amazon_security_lake` api.operation=ModifyDBInstance OR api.operation=ModifyDBCluster | spath input=api.request.data | search masterUserPassword=* | fillnull | stats count min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region api.request.data | rename actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent as user_agent | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` |`asl_aws_credential_access_rds_password_reset_filter`'
|
||||
how_to_implement: The detection is based on Amazon Security Lake events from Amazon Web Services (AWS), which is a centralized data lake that provides security-related data from AWS services. To use this detection, you must ingest CloudTrail logs from Amazon Security Lake into Splunk. To run this search, ensure that you ingest events using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876) or the Federated Analytics App.
|
||||
search: '`amazon_security_lake` api.operation=ModifyDBInstance OR api.operation=ModifyDBCluster
|
||||
| spath input=api.request.data | search masterUserPassword=* | fillnull | stats
|
||||
count min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid
|
||||
actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region api.request.data
|
||||
| rename actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region as region,
|
||||
http_request.user_agent as user_agent | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
|
||||
|`asl_aws_credential_access_rds_password_reset_filter`'
|
||||
how_to_implement: The detection is based on Amazon Security Lake events from Amazon
|
||||
Web Services (AWS), which is a centralized data lake that provides security-related
|
||||
data from AWS services. To use this detection, you must ingest CloudTrail logs from
|
||||
Amazon Security Lake into Splunk. To run this search, ensure that you ingest events
|
||||
using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876)
|
||||
or the Federated Analytics App.
|
||||
known_false_positives: Users may genuinely reset the RDS password.
|
||||
references:
|
||||
- https://aws.amazon.com/premiumsupport/knowledge-center/reset-master-user-password-rds
|
||||
@@ -19,7 +38,12 @@ drilldown_searches:
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
- name: View risk events for the last 7 days for - "$user$"
|
||||
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
|
||||
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$")
|
||||
starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime
|
||||
values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories)
|
||||
as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic)
|
||||
as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)`'
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
rba:
|
||||
@@ -36,9 +60,8 @@ tags:
|
||||
- AWS Identity and Access Management Account Takeover
|
||||
asset_type: AWS Account
|
||||
mitre_attack_id:
|
||||
- T1586
|
||||
- T1586.003
|
||||
- T1110
|
||||
- T1586.003
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
@@ -47,6 +70,7 @@ tags:
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.002/aws_rds_password_reset/asl_ocsf_cloudtrail.json
|
||||
- data:
|
||||
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.002/aws_rds_password_reset/asl_ocsf_cloudtrail.json
|
||||
sourcetype: aws:asl
|
||||
source: aws_asl
|
||||
|
||||
@@ -1,16 +1,33 @@
|
||||
name: ASL AWS Defense Evasion Delete Cloudtrail
|
||||
id: 1f0b47e5-0134-43eb-851c-e3258638945e
|
||||
version: 6
|
||||
date: '2024-11-14'
|
||||
version: 7
|
||||
date: '2025-02-10'
|
||||
author: Patrick Bareiss, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
description: The following analytic detects AWS `DeleteTrail` events within CloudTrail logs. It leverages Amazon Security Lake logs parsed in the Open Cybersecurity Schema Framework (OCSF) format to identify when a CloudTrail is deleted. This activity is significant because adversaries may delete CloudTrail logs to evade detection and operate with stealth. If confirmed malicious, this action could allow attackers to cover their tracks, making it difficult to trace their activities and investigate other potential compromises within the AWS environment.
|
||||
data_source:
|
||||
description: The following analytic detects AWS `DeleteTrail` events within CloudTrail
|
||||
logs. It leverages Amazon Security Lake logs parsed in the Open Cybersecurity Schema
|
||||
Framework (OCSF) format to identify when a CloudTrail is deleted. This activity
|
||||
is significant because adversaries may delete CloudTrail logs to evade detection
|
||||
and operate with stealth. If confirmed malicious, this action could allow attackers
|
||||
to cover their tracks, making it difficult to trace their activities and investigate
|
||||
other potential compromises within the AWS environment.
|
||||
data_source:
|
||||
- ASL AWS CloudTrail
|
||||
search: '`amazon_security_lake` api.operation=DeleteTrail | fillnull | stats count min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region | rename actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent as user_agent | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)`| `asl_aws_defense_evasion_delete_cloudtrail_filter`'
|
||||
how_to_implement: The detection is based on Amazon Security Lake events from Amazon Web Services (AWS), which is a centralized data lake that provides security-related data from AWS services. To use this detection, you must ingest CloudTrail logs from Amazon Security Lake into Splunk. To run this search, ensure that you ingest events using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876) or the Federated Analytics App.
|
||||
known_false_positives: While this search has no known false positives, it is possible that an AWS admin has stopped cloudTrail logging. Please investigate this activity.
|
||||
search: '`amazon_security_lake` api.operation=DeleteTrail | fillnull | stats count
|
||||
min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid
|
||||
http_request.user_agent src_endpoint.ip cloud.region | rename actor.user.uid as
|
||||
user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent
|
||||
as user_agent | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)`|
|
||||
`asl_aws_defense_evasion_delete_cloudtrail_filter`'
|
||||
how_to_implement: The detection is based on Amazon Security Lake events from Amazon
|
||||
Web Services (AWS), which is a centralized data lake that provides security-related
|
||||
data from AWS services. To use this detection, you must ingest CloudTrail logs from
|
||||
Amazon Security Lake into Splunk. To run this search, ensure that you ingest events
|
||||
using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876)
|
||||
or the Federated Analytics App.
|
||||
known_false_positives: While this search has no known false positives, it is possible
|
||||
that an AWS admin has stopped cloudTrail logging. Please investigate this activity.
|
||||
references:
|
||||
- https://attack.mitre.org/techniques/T1562/008/
|
||||
drilldown_searches:
|
||||
@@ -42,7 +59,6 @@ tags:
|
||||
asset_type: AWS Account
|
||||
mitre_attack_id:
|
||||
- T1562.008
|
||||
- T1562
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
@@ -51,6 +67,7 @@ tags:
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.008/stop_delete_cloudtrail/asl_ocsf_cloudtrail.json
|
||||
- data:
|
||||
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.008/stop_delete_cloudtrail/asl_ocsf_cloudtrail.json
|
||||
sourcetype: aws:asl
|
||||
source: aws_asl
|
||||
|
||||
@@ -1,16 +1,34 @@
|
||||
name: ASL AWS Defense Evasion Delete CloudWatch Log Group
|
||||
id: 0f701b38-a0fb-43fd-a83d-d12265f71f33
|
||||
version: 5
|
||||
date: '2024-11-14'
|
||||
version: 6
|
||||
date: '2025-02-10'
|
||||
author: Patrick Bareiss, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
description: The following analytic detects the deletion of CloudWatch log groups in AWS, identified through `DeleteLogGroup` events in CloudTrail logs. This method leverages Amazon Security Lake logs parsed in the OCSF format. The activity is significant because attackers may delete log groups to evade detection and disrupt logging capabilities, hindering incident response efforts. If confirmed malicious, this action could allow attackers to cover their tracks, making it difficult to trace their activities and potentially leading to undetected data breaches or further malicious actions within the compromised AWS environment.
|
||||
data_source:
|
||||
description: The following analytic detects the deletion of CloudWatch log groups
|
||||
in AWS, identified through `DeleteLogGroup` events in CloudTrail logs. This method
|
||||
leverages Amazon Security Lake logs parsed in the OCSF format. The activity is significant
|
||||
because attackers may delete log groups to evade detection and disrupt logging capabilities,
|
||||
hindering incident response efforts. If confirmed malicious, this action could allow
|
||||
attackers to cover their tracks, making it difficult to trace their activities and
|
||||
potentially leading to undetected data breaches or further malicious actions within
|
||||
the compromised AWS environment.
|
||||
data_source:
|
||||
- ASL AWS CloudTrail
|
||||
search: '`amazon_security_lake` api.operation=DeleteLogGroup | fillnull | stats count min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region | rename actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent as user_agent | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)`| `asl_aws_defense_evasion_delete_cloudwatch_log_group_filter`'
|
||||
how_to_implement: The detection is based on Amazon Security Lake events from Amazon Web Services (AWS), which is a centralized data lake that provides security-related data from AWS services. To use this detection, you must ingest CloudTrail logs from Amazon Security Lake into Splunk. To run this search, ensure that you ingest events using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876) or the Federated Analytics App.
|
||||
known_false_positives: While this search has no known false positives, it is possible that an AWS admin has deleted CloudWatch logging. Please investigate this activity.
|
||||
search: '`amazon_security_lake` api.operation=DeleteLogGroup | fillnull | stats count
|
||||
min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid
|
||||
http_request.user_agent src_endpoint.ip cloud.region | rename actor.user.uid as
|
||||
user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent
|
||||
as user_agent | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)`|
|
||||
`asl_aws_defense_evasion_delete_cloudwatch_log_group_filter`'
|
||||
how_to_implement: The detection is based on Amazon Security Lake events from Amazon
|
||||
Web Services (AWS), which is a centralized data lake that provides security-related
|
||||
data from AWS services. To use this detection, you must ingest CloudTrail logs from
|
||||
Amazon Security Lake into Splunk. To run this search, ensure that you ingest events
|
||||
using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876)
|
||||
or the Federated Analytics App.
|
||||
known_false_positives: While this search has no known false positives, it is possible
|
||||
that an AWS admin has deleted CloudWatch logging. Please investigate this activity.
|
||||
references:
|
||||
- https://attack.mitre.org/techniques/T1562/008/
|
||||
drilldown_searches:
|
||||
@@ -41,7 +59,6 @@ tags:
|
||||
- AWS Defense Evasion
|
||||
asset_type: AWS Account
|
||||
mitre_attack_id:
|
||||
- T1562
|
||||
- T1562.008
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
|
||||
@@ -1,16 +1,35 @@
|
||||
name: ASL AWS Defense Evasion Impair Security Services
|
||||
id: 5029b681-0462-47b7-82e7-f7e3d37f5a2d
|
||||
version: 5
|
||||
date: '2024-11-14'
|
||||
version: 6
|
||||
date: '2025-02-10'
|
||||
author: Patrick Bareiss, Bhavin Patel, Gowthamaraj Rajendran, Splunk
|
||||
status: production
|
||||
type: Hunting
|
||||
description: The following analytic detects the deletion of critical AWS Security Services configurations, such as CloudWatch alarms, GuardDuty detectors, and Web Application Firewall rules. It leverages Amazon Security Lake logs to identify specific API calls like "DeleteLogStream" and "DeleteDetector." This activity is significant because adversaries often use these actions to disable security monitoring and evade detection. If confirmed malicious, this could allow attackers to operate undetected, leading to potential data breaches, unauthorized access, and prolonged persistence within the AWS environment.
|
||||
data_source:
|
||||
description: The following analytic detects the deletion of critical AWS Security
|
||||
Services configurations, such as CloudWatch alarms, GuardDuty detectors, and Web
|
||||
Application Firewall rules. It leverages Amazon Security Lake logs to identify specific
|
||||
API calls like "DeleteLogStream" and "DeleteDetector." This activity is significant
|
||||
because adversaries often use these actions to disable security monitoring and evade
|
||||
detection. If confirmed malicious, this could allow attackers to operate undetected,
|
||||
leading to potential data breaches, unauthorized access, and prolonged persistence
|
||||
within the AWS environment.
|
||||
data_source:
|
||||
- ASL AWS CloudTrail
|
||||
search: '`amazon_security_lake` api.operation IN ("DeleteLogStream","DeleteDetector","DeleteIPSet","DeleteWebACL","DeleteRule","DeleteRuleGroup","DeleteLoggingConfiguration","DeleteAlarms") | fillnull | stats count min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region | rename actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent as user_agent, actor.user.account_uid as aws_account_id | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `asl_aws_defense_evasion_impair_security_services_filter`'
|
||||
how_to_implement: The detection is based on Amazon Security Lake events from Amazon Web Services (AWS), which is a centralized data lake that provides security-related data from AWS services. To use this detection, you must ingest CloudTrail logs from Amazon Security Lake into Splunk. To run this search, ensure that you ingest events using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876) or the Federated Analytics App.
|
||||
known_false_positives: While this search has no known false positives, it is possible that it is a legitimate admin activity. Please consider filtering out these noisy events using userAgent, user_arn field names.
|
||||
search: '`amazon_security_lake` api.operation IN ("DeleteLogStream","DeleteDetector","DeleteIPSet","DeleteWebACL","DeleteRule","DeleteRuleGroup","DeleteLoggingConfiguration","DeleteAlarms")
|
||||
| fillnull | stats count min(_time) as firstTime max(_time) as lastTime by api.operation
|
||||
actor.user.uid actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region
|
||||
| rename actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region as region,
|
||||
http_request.user_agent as user_agent, actor.user.account_uid as aws_account_id
|
||||
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `asl_aws_defense_evasion_impair_security_services_filter`'
|
||||
how_to_implement: The detection is based on Amazon Security Lake events from Amazon
|
||||
Web Services (AWS), which is a centralized data lake that provides security-related
|
||||
data from AWS services. To use this detection, you must ingest CloudTrail logs from
|
||||
Amazon Security Lake into Splunk. To run this search, ensure that you ingest events
|
||||
using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876)
|
||||
or the Federated Analytics App.
|
||||
known_false_positives: While this search has no known false positives, it is possible
|
||||
that it is a legitimate admin activity. Please consider filtering out these noisy
|
||||
events using userAgent, user_arn field names.
|
||||
references:
|
||||
- https://docs.aws.amazon.com/cli/latest/reference/guardduty/index.html
|
||||
- https://docs.aws.amazon.com/cli/latest/reference/waf/index.html
|
||||
@@ -21,7 +40,6 @@ tags:
|
||||
asset_type: AWS Account
|
||||
mitre_attack_id:
|
||||
- T1562.008
|
||||
- T1562
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
@@ -30,6 +48,7 @@ tags:
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.008/aws_delete_security_services/asl_ocsf_cloudtrail.json
|
||||
- data:
|
||||
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.008/aws_delete_security_services/asl_ocsf_cloudtrail.json
|
||||
sourcetype: aws:asl
|
||||
source: aws_asl
|
||||
|
||||
@@ -1,16 +1,36 @@
|
||||
name: ASL AWS Defense Evasion PutBucketLifecycle
|
||||
id: 986565a2-7707-48ea-9590-37929cebc938
|
||||
version: 1
|
||||
date: '2024-12-16'
|
||||
version: 2
|
||||
date: '2025-02-10'
|
||||
author: Patrick Bareiss, Splunk
|
||||
status: production
|
||||
type: Hunting
|
||||
description: The following analytic detects `PutBucketLifecycle` events in AWS CloudTrail logs where a user sets a lifecycle rule for an S3 bucket with an expiration period of fewer than three days. This detection leverages CloudTrail logs to identify suspicious lifecycle configurations. This activity is significant because attackers may use it to delete CloudTrail logs quickly, thereby evading detection and impairing forensic investigations. If confirmed malicious, this could allow attackers to cover their tracks, making it difficult to trace their actions and respond to the breach effectively.
|
||||
description: The following analytic detects `PutBucketLifecycle` events in AWS CloudTrail
|
||||
logs where a user sets a lifecycle rule for an S3 bucket with an expiration period
|
||||
of fewer than three days. This detection leverages CloudTrail logs to identify suspicious
|
||||
lifecycle configurations. This activity is significant because attackers may use
|
||||
it to delete CloudTrail logs quickly, thereby evading detection and impairing forensic
|
||||
investigations. If confirmed malicious, this could allow attackers to cover their
|
||||
tracks, making it difficult to trace their actions and respond to the breach effectively.
|
||||
data_source:
|
||||
- ASL AWS CloudTrail
|
||||
search: '`amazon_security_lake` api.operation=PutBucketLifecycle | spath input=api.request.data path=LifecycleConfiguration.Rule.NoncurrentVersionExpiration.NoncurrentDays output=NoncurrentDays | where NoncurrentDays < 3 | spath input=api.request.data | fillnull | stats count min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region NoncurrentDays bucketName | rename actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent as user_agent | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `asl_aws_defense_evasion_putbucketlifecycle_filter`'
|
||||
how_to_implement: The detection is based on Amazon Security Lake events from Amazon Web Services (AWS), which is a centralized data lake that provides security-related data from AWS services. To use this detection, you must ingest CloudTrail logs from Amazon Security Lake into Splunk. To run this search, ensure that you ingest events using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876) or the Federated Analytics App.
|
||||
known_false_positives: While this search has no known false positives, it is possible that it is a legitimate admin activity. Please consider filtering out these noisy events using userAgent, user_arn field names.
|
||||
search: '`amazon_security_lake` api.operation=PutBucketLifecycle | spath input=api.request.data
|
||||
path=LifecycleConfiguration.Rule.NoncurrentVersionExpiration.NoncurrentDays output=NoncurrentDays
|
||||
| where NoncurrentDays < 3 | spath input=api.request.data | fillnull | stats count
|
||||
min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid
|
||||
http_request.user_agent src_endpoint.ip cloud.region NoncurrentDays bucketName |
|
||||
rename actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region as region,
|
||||
http_request.user_agent as user_agent | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
|
||||
| `asl_aws_defense_evasion_putbucketlifecycle_filter`'
|
||||
how_to_implement: The detection is based on Amazon Security Lake events from Amazon
|
||||
Web Services (AWS), which is a centralized data lake that provides security-related
|
||||
data from AWS services. To use this detection, you must ingest CloudTrail logs from
|
||||
Amazon Security Lake into Splunk. To run this search, ensure that you ingest events
|
||||
using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876)
|
||||
or the Federated Analytics App.
|
||||
known_false_positives: While this search has no known false positives, it is possible
|
||||
that it is a legitimate admin activity. Please consider filtering out these noisy
|
||||
events using userAgent, user_arn field names.
|
||||
references:
|
||||
- https://stratus-red-team.cloud/attack-techniques/AWS/aws.defense-evasion.cloudtrail-lifecycle-rule/
|
||||
tags:
|
||||
@@ -18,10 +38,8 @@ tags:
|
||||
- AWS Defense Evasion
|
||||
asset_type: AWS Account
|
||||
mitre_attack_id:
|
||||
- T1562.008
|
||||
- T1562
|
||||
- T1485.001
|
||||
- T1485
|
||||
- T1562.008
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
@@ -30,6 +48,7 @@ tags:
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.008/put_bucketlifecycle/asl_ocsf_cloudtrail.json
|
||||
- data:
|
||||
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.008/put_bucketlifecycle/asl_ocsf_cloudtrail.json
|
||||
sourcetype: aws:asl
|
||||
source: aws_asl
|
||||
|
||||
@@ -1,17 +1,36 @@
|
||||
name: ASL AWS Defense Evasion Stop Logging Cloudtrail
|
||||
id: 0b78a8f9-1d31-4d23-85c8-56ad13d5b4c1
|
||||
version: 4
|
||||
date: '2024-11-14'
|
||||
version: 5
|
||||
date: '2025-02-10'
|
||||
author: Patrick Bareiss, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
description: The following analytic detects `StopLogging` events within AWS CloudTrail logs, a critical action that adversaries may use to evade detection. By halting the logging of their malicious activities, attackers aim to operate undetected within a compromised AWS environment. This detection is achieved by monitoring for specific CloudTrail log entries that indicate the cessation of logging activities. Identifying such behavior is crucial for a Security Operations Center (SOC), as it signals an attempt to undermine the integrity of logging mechanisms, potentially allowing malicious activities to proceed without observation. The impact of this evasion tactic is significant, as it can severely hamper incident response and forensic investigations by obscuring the attacker's actions.
|
||||
data_source:
|
||||
description: The following analytic detects `StopLogging` events within AWS CloudTrail
|
||||
logs, a critical action that adversaries may use to evade detection. By halting
|
||||
the logging of their malicious activities, attackers aim to operate undetected within
|
||||
a compromised AWS environment. This detection is achieved by monitoring for specific
|
||||
CloudTrail log entries that indicate the cessation of logging activities. Identifying
|
||||
such behavior is crucial for a Security Operations Center (SOC), as it signals an
|
||||
attempt to undermine the integrity of logging mechanisms, potentially allowing malicious
|
||||
activities to proceed without observation. The impact of this evasion tactic is
|
||||
significant, as it can severely hamper incident response and forensic investigations
|
||||
by obscuring the attacker's actions.
|
||||
data_source:
|
||||
- ASL AWS CloudTrail
|
||||
search: '`amazon_security_lake` api.operation=StopLogging | fillnull | stats count min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region | rename actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent as user_agent, actor.user.account.uid
|
||||
as aws_account_id | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `asl_aws_defense_evasion_stop_logging_cloudtrail_filter`'
|
||||
how_to_implement: The detection is based on Amazon Security Lake events from Amazon Web Services (AWS), which is a centralized data lake that provides security-related data from AWS services. To use this detection, you must ingest CloudTrail logs from Amazon Security Lake into Splunk. To run this search, ensure that you ingest events using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876) or the Federated Analytics App.
|
||||
known_false_positives: While this search has no known false positives, it is possible that an AWS admin has stopped cloudtrail logging. Please investigate this activity.
|
||||
search: '`amazon_security_lake` api.operation=StopLogging | fillnull | stats count
|
||||
min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid
|
||||
http_request.user_agent src_endpoint.ip cloud.region | rename actor.user.uid as
|
||||
user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent
|
||||
as user_agent, actor.user.account.uid as aws_account_id | `security_content_ctime(firstTime)`|
|
||||
`security_content_ctime(lastTime)` | `asl_aws_defense_evasion_stop_logging_cloudtrail_filter`'
|
||||
how_to_implement: The detection is based on Amazon Security Lake events from Amazon
|
||||
Web Services (AWS), which is a centralized data lake that provides security-related
|
||||
data from AWS services. To use this detection, you must ingest CloudTrail logs from
|
||||
Amazon Security Lake into Splunk. To run this search, ensure that you ingest events
|
||||
using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876)
|
||||
or the Federated Analytics App.
|
||||
known_false_positives: While this search has no known false positives, it is possible
|
||||
that an AWS admin has stopped cloudtrail logging. Please investigate this activity.
|
||||
references:
|
||||
- https://attack.mitre.org/techniques/T1562/008/
|
||||
drilldown_searches:
|
||||
@@ -44,7 +63,6 @@ tags:
|
||||
asset_type: AWS Account
|
||||
mitre_attack_id:
|
||||
- T1562.008
|
||||
- T1562
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
@@ -53,6 +71,7 @@ tags:
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.008/stop_delete_cloudtrail/asl_ocsf_cloudtrail_2.json
|
||||
- data:
|
||||
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.008/stop_delete_cloudtrail/asl_ocsf_cloudtrail_2.json
|
||||
sourcetype: aws:asl
|
||||
source: aws_asl
|
||||
|
||||
@@ -1,16 +1,35 @@
|
||||
name: ASL AWS Defense Evasion Update Cloudtrail
|
||||
id: f3eb471c-16d0-404d-897c-7653f0a78cba
|
||||
version: 4
|
||||
date: '2024-11-14'
|
||||
version: 5
|
||||
date: '2025-02-10'
|
||||
author: Patrick Bareiss, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
description: The following analytic detects `UpdateTrail` events within AWS CloudTrail logs, aiming to identify attempts by attackers to evade detection by altering logging configurations. By updating CloudTrail settings with incorrect parameters, such as changing multi-regional logging to a single region, attackers can impair the logging of their activities across other regions. This behavior is crucial for Security Operations Centers (SOCs) to identify, as it indicates an adversary's intent to operate undetected within a compromised AWS environment. The impact of such evasion tactics is significant, potentially allowing malicious activities to proceed without being logged, thereby hindering incident response and forensic investigations.
|
||||
data_source:
|
||||
description: The following analytic detects `UpdateTrail` events within AWS CloudTrail
|
||||
logs, aiming to identify attempts by attackers to evade detection by altering logging
|
||||
configurations. By updating CloudTrail settings with incorrect parameters, such
|
||||
as changing multi-regional logging to a single region, attackers can impair the
|
||||
logging of their activities across other regions. This behavior is crucial for Security
|
||||
Operations Centers (SOCs) to identify, as it indicates an adversary's intent to
|
||||
operate undetected within a compromised AWS environment. The impact of such evasion
|
||||
tactics is significant, potentially allowing malicious activities to proceed without
|
||||
being logged, thereby hindering incident response and forensic investigations.
|
||||
data_source:
|
||||
- ASL AWS CloudTrail
|
||||
search: '`amazon_security_lake` api.operation=UpdateTrail | fillnull | stats count min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region | rename actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent as user_agent, actor.user.account.uid as aws_account_id | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `asl_aws_defense_evasion_update_cloudtrail_filter`'
|
||||
how_to_implement: The detection is based on Amazon Security Lake events from Amazon Web Services (AWS), which is a centralized data lake that provides security-related data from AWS services. To use this detection, you must ingest CloudTrail logs from Amazon Security Lake into Splunk. To run this search, ensure that you ingest events using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876) or the Federated Analytics App.
|
||||
known_false_positives: While this search has no known false positives, it is possible that an AWS admin has updated cloudtrail logging. Please investigate this activity.
|
||||
search: '`amazon_security_lake` api.operation=UpdateTrail | fillnull | stats count
|
||||
min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid
|
||||
http_request.user_agent src_endpoint.ip cloud.region | rename actor.user.uid as
|
||||
user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent
|
||||
as user_agent, actor.user.account.uid as aws_account_id | `security_content_ctime(firstTime)`|
|
||||
`security_content_ctime(lastTime)` | `asl_aws_defense_evasion_update_cloudtrail_filter`'
|
||||
how_to_implement: The detection is based on Amazon Security Lake events from Amazon
|
||||
Web Services (AWS), which is a centralized data lake that provides security-related
|
||||
data from AWS services. To use this detection, you must ingest CloudTrail logs from
|
||||
Amazon Security Lake into Splunk. To run this search, ensure that you ingest events
|
||||
using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876)
|
||||
or the Federated Analytics App.
|
||||
known_false_positives: While this search has no known false positives, it is possible
|
||||
that an AWS admin has updated cloudtrail logging. Please investigate this activity.
|
||||
references:
|
||||
- https://attack.mitre.org/techniques/T1562/008/
|
||||
drilldown_searches:
|
||||
@@ -42,7 +61,6 @@ tags:
|
||||
- AWS Defense Evasion
|
||||
asset_type: AWS Account
|
||||
mitre_attack_id:
|
||||
- T1562
|
||||
- T1562.008
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
@@ -52,6 +70,7 @@ tags:
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.008/update_cloudtrail/asl_ocsf_cloudtrail.json
|
||||
- data:
|
||||
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.008/update_cloudtrail/asl_ocsf_cloudtrail.json
|
||||
sourcetype: aws:asl
|
||||
source: aws_asl
|
||||
|
||||
@@ -1,16 +1,35 @@
|
||||
name: ASL AWS ECR Container Upload Outside Business Hours
|
||||
id: 739ed682-27e9-4ba0-80e5-a91b97698213
|
||||
version: 5
|
||||
date: '2024-11-14'
|
||||
version: 6
|
||||
date: '2025-02-10'
|
||||
author: Patrick Bareiss, Splunk
|
||||
status: production
|
||||
type: Anomaly
|
||||
description: The following analytic detects the upload of new containers to AWS Elastic Container Service (ECR) outside of standard business hours through AWS CloudTrail events. It identifies this behavior by monitoring for `PutImage` events occurring before 8 AM or after 8 PM, as well as any uploads on weekends. This activity is significant for a SOC to investigate as it may indicate unauthorized access or malicious deployments, potentially leading to compromised services or data breaches. Identifying and addressing such uploads promptly can mitigate the risk of security incidents and their associated impacts.
|
||||
data_source:
|
||||
description: The following analytic detects the upload of new containers to AWS Elastic
|
||||
Container Service (ECR) outside of standard business hours through AWS CloudTrail
|
||||
events. It identifies this behavior by monitoring for `PutImage` events occurring
|
||||
before 8 AM or after 8 PM, as well as any uploads on weekends. This activity is
|
||||
significant for a SOC to investigate as it may indicate unauthorized access or malicious
|
||||
deployments, potentially leading to compromised services or data breaches. Identifying
|
||||
and addressing such uploads promptly can mitigate the risk of security incidents
|
||||
and their associated impacts.
|
||||
data_source:
|
||||
- ASL AWS CloudTrail
|
||||
search: '`amazon_security_lake` api.operation=PutImage | eval hour=strftime(time/pow(10,3), "%H"), weekday=strftime(time/pow(10,3), "%A") | where hour >= 20 OR hour < 8 OR weekday=Saturday OR weekday=Sunday | fillnull | stats count min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid http_request.user_agent cloud.region | rename actor.user.uid as user, cloud.region as region, http_request.user_agent as user_agent | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `asl_aws_ecr_container_upload_outside_business_hours_filter`'
|
||||
how_to_implement: The detection is based on Amazon Security Lake events from Amazon Web Services (AWS), which is a centralized data lake that provides security-related data from AWS services. To use this detection, you must ingest CloudTrail logs from Amazon Security Lake into Splunk. To run this search, ensure that you ingest events using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876) or the Federated Analytics App.
|
||||
known_false_positives: When your development is spreaded in different time zones, applying this rule can be difficult.
|
||||
search: '`amazon_security_lake` api.operation=PutImage | eval hour=strftime(time/pow(10,3),
|
||||
"%H"), weekday=strftime(time/pow(10,3), "%A") | where hour >= 20 OR hour < 8 OR
|
||||
weekday=Saturday OR weekday=Sunday | fillnull | stats count min(_time) as firstTime
|
||||
max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid http_request.user_agent
|
||||
cloud.region | rename actor.user.uid as user, cloud.region as region, http_request.user_agent
|
||||
as user_agent | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
|
||||
| `asl_aws_ecr_container_upload_outside_business_hours_filter`'
|
||||
how_to_implement: The detection is based on Amazon Security Lake events from Amazon
|
||||
Web Services (AWS), which is a centralized data lake that provides security-related
|
||||
data from AWS services. To use this detection, you must ingest CloudTrail logs from
|
||||
Amazon Security Lake into Splunk. To run this search, ensure that you ingest events
|
||||
using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876)
|
||||
or the Federated Analytics App.
|
||||
known_false_positives: When your development is spreaded in different time zones,
|
||||
applying this rule can be difficult.
|
||||
references:
|
||||
- https://attack.mitre.org/techniques/T1204/003/
|
||||
drilldown_searches:
|
||||
@@ -40,16 +59,17 @@ tags:
|
||||
asset_type: AWS Account
|
||||
mitre_attack_id:
|
||||
- T1204.003
|
||||
- T1204
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
security_domain: network
|
||||
manual_test: Can't be tested automatically because of outside of business hours time
|
||||
manual_test: Can't be tested automatically because of outside of business hours
|
||||
time
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1204.003/aws_ecr_container_upload/asl_ocsf_cloudtrail.json
|
||||
- data:
|
||||
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1204.003/aws_ecr_container_upload/asl_ocsf_cloudtrail.json
|
||||
sourcetype: aws:asl
|
||||
source: aws_asl
|
||||
|
||||
@@ -1,15 +1,34 @@
|
||||
name: ASL AWS ECR Container Upload Unknown User
|
||||
id: 886a8f46-d7e2-4439-b9ba-aec238e31732
|
||||
version: 4
|
||||
date: '2024-11-14'
|
||||
version: 5
|
||||
date: '2025-02-10'
|
||||
author: Patrick Bareiss, Splunk
|
||||
status: production
|
||||
type: Anomaly
|
||||
description: The following analytic detects unauthorized container uploads to AWS Elastic Container Service (ECR) by monitoring AWS CloudTrail events. It identifies instances where a new container is uploaded by a user not previously recognized as authorized. This detection is crucial for a SOC as it can indicate a potential compromise or misuse of AWS ECR, which could lead to unauthorized access to sensitive data or the deployment of malicious containers. By identifying and investigating these events, organizations can mitigate the risk of data breaches or other security incidents resulting from unauthorized container uploads. The impact of such an attack could be significant, compromising the integrity and security of the organization's cloud environment.
|
||||
data_source:
|
||||
description: The following analytic detects unauthorized container uploads to AWS
|
||||
Elastic Container Service (ECR) by monitoring AWS CloudTrail events. It identifies
|
||||
instances where a new container is uploaded by a user not previously recognized
|
||||
as authorized. This detection is crucial for a SOC as it can indicate a potential
|
||||
compromise or misuse of AWS ECR, which could lead to unauthorized access to sensitive
|
||||
data or the deployment of malicious containers. By identifying and investigating
|
||||
these events, organizations can mitigate the risk of data breaches or other security
|
||||
incidents resulting from unauthorized container uploads. The impact of such an attack
|
||||
could be significant, compromising the integrity and security of the organization's
|
||||
cloud environment.
|
||||
data_source:
|
||||
- ASL AWS CloudTrail
|
||||
search: '`amazon_security_lake` api.operation=PutImage NOT `aws_ecr_users_asl` | stats count min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region | rename actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent as user_agent | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `asl_aws_ecr_container_upload_unknown_user_filter`'
|
||||
how_to_implement: The detection is based on Amazon Security Lake events from Amazon Web Services (AWS), which is a centralized data lake that provides security-related data from AWS services. To use this detection, you must ingest CloudTrail logs from Amazon Security Lake into Splunk. To run this search, ensure that you ingest events using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876) or the Federated Analytics App.
|
||||
search: '`amazon_security_lake` api.operation=PutImage NOT `aws_ecr_users_asl` | stats
|
||||
count min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid
|
||||
actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region | rename
|
||||
actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent
|
||||
as user_agent | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
|
||||
| `asl_aws_ecr_container_upload_unknown_user_filter`'
|
||||
how_to_implement: The detection is based on Amazon Security Lake events from Amazon
|
||||
Web Services (AWS), which is a centralized data lake that provides security-related
|
||||
data from AWS services. To use this detection, you must ingest CloudTrail logs from
|
||||
Amazon Security Lake into Splunk. To run this search, ensure that you ingest events
|
||||
using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876)
|
||||
or the Federated Analytics App.
|
||||
known_false_positives: unknown
|
||||
references:
|
||||
- https://attack.mitre.org/techniques/T1204/003/
|
||||
@@ -42,7 +61,6 @@ tags:
|
||||
asset_type: AWS Account
|
||||
mitre_attack_id:
|
||||
- T1204.003
|
||||
- T1204
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
@@ -51,6 +69,7 @@ tags:
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1204.003/aws_ecr_container_upload/asl_ocsf_cloudtrail.json
|
||||
- data:
|
||||
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1204.003/aws_ecr_container_upload/asl_ocsf_cloudtrail.json
|
||||
sourcetype: aws:asl
|
||||
source: aws_asl
|
||||
|
||||
@@ -1,16 +1,32 @@
|
||||
name: ASL AWS IAM Successful Group Deletion
|
||||
id: 1bbe54f1-93d7-4764-8a01-ddaa12ece7ac
|
||||
version: 5
|
||||
date: '2024-11-14'
|
||||
version: 6
|
||||
date: '2025-02-10'
|
||||
author: Patrick Bareiss, Splunk
|
||||
status: production
|
||||
type: Hunting
|
||||
description: The following analytic detects the successful deletion of a group within AWS IAM, leveraging CloudTrail IAM events. This action, while not inherently malicious, can serve as a precursor to more sinister activities, such as unauthorized access or privilege escalation attempts. By monitoring for such deletions, the analytic aids in identifying potential preparatory steps towards an attack, allowing for early detection and mitigation. The identification of this behavior is crucial for a SOC to prevent the potential impact of an attack, which could include unauthorized access to sensitive resources or disruption of AWS environment operations.
|
||||
data_source:
|
||||
description: The following analytic detects the successful deletion of a group within
|
||||
AWS IAM, leveraging CloudTrail IAM events. This action, while not inherently malicious,
|
||||
can serve as a precursor to more sinister activities, such as unauthorized access
|
||||
or privilege escalation attempts. By monitoring for such deletions, the analytic
|
||||
aids in identifying potential preparatory steps towards an attack, allowing for
|
||||
early detection and mitigation. The identification of this behavior is crucial for
|
||||
a SOC to prevent the potential impact of an attack, which could include unauthorized
|
||||
access to sensitive resources or disruption of AWS environment operations.
|
||||
data_source:
|
||||
- ASL AWS CloudTrail
|
||||
search: '`amazon_security_lake` api.operation=DeleteGroup status=Success | fillnull | stats count min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region | rename actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent as user_agent | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `asl_aws_iam_successful_group_deletion_filter`'
|
||||
how_to_implement: You must install the Data Lake Federated Analytics App and ingest the logs into Splunk.
|
||||
known_false_positives: This detection will require tuning to provide high fidelity detection capabilties. Tune based on src addresses (corporate offices, VPN terminations) or by groups of users. Not every user with AWS access should have permission to delete groups (least privilege).
|
||||
search: '`amazon_security_lake` api.operation=DeleteGroup status=Success | fillnull
|
||||
| stats count min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid
|
||||
actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region | rename
|
||||
actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent
|
||||
as user_agent | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
|
||||
| `asl_aws_iam_successful_group_deletion_filter`'
|
||||
how_to_implement: You must install the Data Lake Federated Analytics App and ingest
|
||||
the logs into Splunk.
|
||||
known_false_positives: This detection will require tuning to provide high fidelity
|
||||
detection capabilties. Tune based on src addresses (corporate offices, VPN terminations)
|
||||
or by groups of users. Not every user with AWS access should have permission to
|
||||
delete groups (least privilege).
|
||||
references:
|
||||
- https://awscli.amazonaws.com/v2/documentation/api/latest/reference/iam/delete-group.html
|
||||
- https://docs.aws.amazon.com/IAM/latest/APIReference/API_DeleteGroup.html
|
||||
@@ -21,7 +37,6 @@ tags:
|
||||
mitre_attack_id:
|
||||
- T1069.003
|
||||
- T1098
|
||||
- T1069
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
@@ -30,6 +45,7 @@ tags:
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1098/aws_iam_successful_group_deletion/asl_ocsf_cloudtrail.json
|
||||
- data:
|
||||
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1098/aws_iam_successful_group_deletion/asl_ocsf_cloudtrail.json
|
||||
sourcetype: aws:asl
|
||||
source: aws_asl
|
||||
|
||||
@@ -1,16 +1,34 @@
|
||||
name: ASL AWS Multi-Factor Authentication Disabled
|
||||
id: 4d2df5e0-1092-4817-88a8-79c7fa054668
|
||||
version: 5
|
||||
date: '2024-11-14'
|
||||
version: 6
|
||||
date: '2025-02-10'
|
||||
author: Patrick Bareiss, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
description: The following analytic detects attempts to disable multi-factor authentication (MFA) for an AWS IAM user. It leverages Amazon Security Lake logs, specifically monitoring for `DeleteVirtualMFADevice` or `DeactivateMFADevice` API operations. This activity is significant as disabling MFA can indicate an adversary attempting to weaken account security to maintain persistence using a compromised account. If confirmed malicious, this action could allow attackers to retain access to the AWS environment without detection, potentially leading to unauthorized access to sensitive resources and prolonged compromise.
|
||||
data_source:
|
||||
description: The following analytic detects attempts to disable multi-factor authentication
|
||||
(MFA) for an AWS IAM user. It leverages Amazon Security Lake logs, specifically
|
||||
monitoring for `DeleteVirtualMFADevice` or `DeactivateMFADevice` API operations.
|
||||
This activity is significant as disabling MFA can indicate an adversary attempting
|
||||
to weaken account security to maintain persistence using a compromised account.
|
||||
If confirmed malicious, this action could allow attackers to retain access to the
|
||||
AWS environment without detection, potentially leading to unauthorized access to
|
||||
sensitive resources and prolonged compromise.
|
||||
data_source:
|
||||
- ASL AWS CloudTrail
|
||||
search: '`amazon_security_lake` (api.operation=DeleteVirtualMFADevice OR api.operation=DeactivateMFADevice) | fillnull | stats count min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region | rename actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent as user_agent | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `asl_aws_multi_factor_authentication_disabled_filter`'
|
||||
how_to_implement: The detection is based on Amazon Security Lake events from Amazon Web Services (AWS), which is a centralized data lake that provides security-related data from AWS services. To use this detection, you must ingest CloudTrail logs from Amazon Security Lake into Splunk. To run this search, ensure that you ingest events using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876) or the Federated Analytics App.
|
||||
known_false_positives: AWS Administrators may disable MFA but it is highly unlikely for this event to occur without prior notice to the company
|
||||
search: '`amazon_security_lake` (api.operation=DeleteVirtualMFADevice OR api.operation=DeactivateMFADevice)
|
||||
| fillnull | stats count min(_time) as firstTime max(_time) as lastTime by api.operation
|
||||
actor.user.uid actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region
|
||||
| rename actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region as region,
|
||||
http_request.user_agent as user_agent | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
|
||||
| `asl_aws_multi_factor_authentication_disabled_filter`'
|
||||
how_to_implement: The detection is based on Amazon Security Lake events from Amazon
|
||||
Web Services (AWS), which is a centralized data lake that provides security-related
|
||||
data from AWS services. To use this detection, you must ingest CloudTrail logs from
|
||||
Amazon Security Lake into Splunk. To run this search, ensure that you ingest events
|
||||
using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876)
|
||||
or the Federated Analytics App.
|
||||
known_false_positives: AWS Administrators may disable MFA but it is highly unlikely
|
||||
for this event to occur without prior notice to the company
|
||||
references:
|
||||
- https://attack.mitre.org/techniques/T1621/
|
||||
- https://aws.amazon.com/what-is/mfa/
|
||||
@@ -42,11 +60,9 @@ tags:
|
||||
- AWS Identity and Access Management Account Takeover
|
||||
asset_type: AWS Account
|
||||
mitre_attack_id:
|
||||
- T1586
|
||||
- T1556.006
|
||||
- T1586.003
|
||||
- T1621
|
||||
- T1556
|
||||
- T1556.006
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
@@ -55,6 +71,7 @@ tags:
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1621/aws_mfa_disabled/asl_ocsf_cloudtrail.json
|
||||
- data:
|
||||
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1621/aws_mfa_disabled/asl_ocsf_cloudtrail.json
|
||||
sourcetype: aws:asl
|
||||
source: aws_asl
|
||||
|
||||
+39
-19
@@ -1,26 +1,41 @@
|
||||
name: ASL AWS Network Access Control List Created with All Open Ports
|
||||
id: a2625034-c2de-44fc-b45c-7bac9c4a7974
|
||||
version: 1
|
||||
date: '2025-01-09'
|
||||
version: 2
|
||||
date: '2025-02-10'
|
||||
author: Patrick Bareiss, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
description: The following analytic detects the creation of AWS Network Access Control Lists (ACLs) with all ports open to a specified CIDR. It leverages AWS CloudTrail events, specifically monitoring for `CreateNetworkAclEntry` or `ReplaceNetworkAclEntry` actions with rules allowing all traffic. This activity is significant because it can expose the network to unauthorized access, increasing the risk of data breaches and other malicious activities. If confirmed malicious, an attacker could exploit this misconfiguration to gain unrestricted access to the network, potentially leading to data exfiltration, service disruption, or further compromise of the AWS environment.
|
||||
data_source:
|
||||
description: The following analytic detects the creation of AWS Network Access Control
|
||||
Lists (ACLs) with all ports open to a specified CIDR. It leverages AWS CloudTrail
|
||||
events, specifically monitoring for `CreateNetworkAclEntry` or `ReplaceNetworkAclEntry`
|
||||
actions with rules allowing all traffic. This activity is significant because it
|
||||
can expose the network to unauthorized access, increasing the risk of data breaches
|
||||
and other malicious activities. If confirmed malicious, an attacker could exploit
|
||||
this misconfiguration to gain unrestricted access to the network, potentially leading
|
||||
to data exfiltration, service disruption, or further compromise of the AWS environment.
|
||||
data_source:
|
||||
- ASL AWS CloudTrail
|
||||
search: '`amazon_security_lake` api.operation=CreateNetworkAclEntry OR api.operation=ReplaceNetworkAclEntry status=Success
|
||||
| spath input=api.request.data path=ruleAction output=ruleAction
|
||||
| spath input=api.request.data path=egress output=egress
|
||||
| spath input=api.request.data path=aclProtocol output=aclProtocol
|
||||
| spath input=api.request.data path=cidrBlock output=cidrBlock
|
||||
| spath input=api.request.data path=networkAclId output=networkAclId
|
||||
search: '`amazon_security_lake` api.operation=CreateNetworkAclEntry OR api.operation=ReplaceNetworkAclEntry
|
||||
status=Success | spath input=api.request.data path=ruleAction output=ruleAction
|
||||
| spath input=api.request.data path=egress output=egress | spath input=api.request.data
|
||||
path=aclProtocol output=aclProtocol | spath input=api.request.data path=cidrBlock
|
||||
output=cidrBlock | spath input=api.request.data path=networkAclId output=networkAclId
|
||||
| search ruleAction=allow AND egress=false AND aclProtocol=-1 AND cidrBlock=0.0.0.0/0
|
||||
| fillnull
|
||||
| stats count min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region networkAclId cidrBlock
|
||||
| rename actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent as user_agent, actor.user.account.uid as aws_account_id
|
||||
| `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `asl_aws_network_access_control_list_created_with_all_open_ports_filter`'
|
||||
how_to_implement: The detection is based on Amazon Security Lake events from Amazon Web Services (AWS), which is a centralized data lake that provides security-related data from AWS services. To use this detection, you must ingest CloudTrail logs from Amazon Security Lake into Splunk. To run this search, ensure that you ingest events using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876) or the Federated Analytics App.
|
||||
known_false_positives: It's possible that an admin has created this ACL with all ports open for some legitimate purpose however, this should be scoped and not allowed in production environment.
|
||||
| fillnull | stats count min(_time) as firstTime max(_time) as lastTime by api.operation
|
||||
actor.user.uid actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region
|
||||
networkAclId cidrBlock | rename actor.user.uid as user, src_endpoint.ip as src_ip,
|
||||
cloud.region as region, http_request.user_agent as user_agent, actor.user.account.uid
|
||||
as aws_account_id | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)`
|
||||
| `asl_aws_network_access_control_list_created_with_all_open_ports_filter`'
|
||||
how_to_implement: The detection is based on Amazon Security Lake events from Amazon
|
||||
Web Services (AWS), which is a centralized data lake that provides security-related
|
||||
data from AWS services. To use this detection, you must ingest CloudTrail logs from
|
||||
Amazon Security Lake into Splunk. To run this search, ensure that you ingest events
|
||||
using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876)
|
||||
or the Federated Analytics App.
|
||||
known_false_positives: It's possible that an admin has created this ACL with all ports
|
||||
open for some legitimate purpose however, this should be scoped and not allowed
|
||||
in production environment.
|
||||
references: []
|
||||
drilldown_searches:
|
||||
- name: View the detection results for - "$user$"
|
||||
@@ -28,7 +43,12 @@ drilldown_searches:
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
- name: View risk events for the last 7 days for - "$user$"
|
||||
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
|
||||
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$")
|
||||
starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime
|
||||
values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories)
|
||||
as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic)
|
||||
as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)`'
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
rba:
|
||||
@@ -46,7 +66,6 @@ tags:
|
||||
asset_type: AWS Instance
|
||||
mitre_attack_id:
|
||||
- T1562.007
|
||||
- T1562
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
@@ -55,6 +74,7 @@ tags:
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.007/aws_create_acl/asl_ocsf_cloudtrail.json
|
||||
- data:
|
||||
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.007/aws_create_acl/asl_ocsf_cloudtrail.json
|
||||
sourcetype: aws:asl
|
||||
source: aws_asl
|
||||
|
||||
@@ -1,23 +1,35 @@
|
||||
name: ASL AWS Network Access Control List Deleted
|
||||
id: e010ddf5-e9a5-44e5-bdd6-0c919ba8fc8b
|
||||
version: 1
|
||||
date: '2025-01-09'
|
||||
version: 2
|
||||
date: '2025-02-10'
|
||||
author: Patrick Bareiss, Splunk
|
||||
status: production
|
||||
type: Anomaly
|
||||
description: The following analytic detects the deletion of AWS Network Access Control Lists (ACLs). It leverages AWS CloudTrail logs to identify events where a user deletes a network ACL entry. This activity is significant because deleting a network ACL can remove critical access restrictions, potentially allowing unauthorized access to cloud instances. If confirmed malicious, this action could enable attackers to bypass network security controls, leading to unauthorized access, data exfiltration, or further compromise of the cloud environment.
|
||||
data_source:
|
||||
description: The following analytic detects the deletion of AWS Network Access Control
|
||||
Lists (ACLs). It leverages AWS CloudTrail logs to identify events where a user deletes
|
||||
a network ACL entry. This activity is significant because deleting a network ACL
|
||||
can remove critical access restrictions, potentially allowing unauthorized access
|
||||
to cloud instances. If confirmed malicious, this action could enable attackers to
|
||||
bypass network security controls, leading to unauthorized access, data exfiltration,
|
||||
or further compromise of the cloud environment.
|
||||
data_source:
|
||||
- ASL AWS CloudTrail
|
||||
search: '`amazon_security_lake` api.operation=DeleteNetworkAclEntry status=Success
|
||||
| spath input=api.request.data path=egress output=egress
|
||||
| spath input=api.request.data path=networkAclId output=networkAclId
|
||||
| search egress=false
|
||||
| fillnull
|
||||
| stats count min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region networkAclId
|
||||
| rename actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent as user_agent, actor.user.account_uid as aws_account_id
|
||||
| `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `asl_aws_network_access_control_list_deleted_filter`'
|
||||
how_to_implement: The detection is based on Amazon Security Lake events from Amazon Web Services (AWS), which is a centralized data lake that provides security-related data from AWS services. To use this detection, you must ingest CloudTrail logs from Amazon Security Lake into Splunk. To run this search, ensure that you ingest events using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876) or the Federated Analytics App.
|
||||
known_false_positives: It's possible that a user has legitimately deleted a network ACL.
|
||||
| spath input=api.request.data path=egress output=egress | spath input=api.request.data
|
||||
path=networkAclId output=networkAclId | search egress=false | fillnull | stats count
|
||||
min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid
|
||||
http_request.user_agent src_endpoint.ip cloud.region networkAclId | rename actor.user.uid
|
||||
as user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent
|
||||
as user_agent, actor.user.account_uid as aws_account_id | `security_content_ctime(firstTime)`|
|
||||
`security_content_ctime(lastTime)` | `asl_aws_network_access_control_list_deleted_filter`'
|
||||
how_to_implement: The detection is based on Amazon Security Lake events from Amazon
|
||||
Web Services (AWS), which is a centralized data lake that provides security-related
|
||||
data from AWS services. To use this detection, you must ingest CloudTrail logs from
|
||||
Amazon Security Lake into Splunk. To run this search, ensure that you ingest events
|
||||
using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876)
|
||||
or the Federated Analytics App.
|
||||
known_false_positives: It's possible that a user has legitimately deleted a network
|
||||
ACL.
|
||||
references: []
|
||||
drilldown_searches:
|
||||
- name: View the detection results for - "$user$"
|
||||
@@ -25,7 +37,12 @@ drilldown_searches:
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
- name: View risk events for the last 7 days for - "$user$"
|
||||
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
|
||||
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$")
|
||||
starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime
|
||||
values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories)
|
||||
as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic)
|
||||
as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)`'
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
rba:
|
||||
@@ -43,7 +60,6 @@ tags:
|
||||
asset_type: AWS Instance
|
||||
mitre_attack_id:
|
||||
- T1562.007
|
||||
- T1562
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
@@ -52,6 +68,7 @@ tags:
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.007/aws_delete_acl/asl_ocsf_cloudtrail.json
|
||||
- data:
|
||||
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.007/aws_delete_acl/asl_ocsf_cloudtrail.json
|
||||
sourcetype: aws:asl
|
||||
source: aws_asl
|
||||
|
||||
@@ -1,16 +1,34 @@
|
||||
name: ASL AWS New MFA Method Registered For User
|
||||
id: 33ae0931-2a03-456b-b1d7-b016c5557fbd
|
||||
version: 6
|
||||
date: '2024-11-14'
|
||||
version: 7
|
||||
date: '2025-02-10'
|
||||
author: Patrick Bareiss, Splunk
|
||||
status: experimental
|
||||
type: TTP
|
||||
description: The following analytic identifies the registration of a new Multi-Factor Authentication (MFA) method for an AWS account, as logged through Amazon Security Lake (ASL). It detects this activity by monitoring the `CreateVirtualMFADevice` API operation within ASL logs. This behavior is significant because adversaries who gain unauthorized access to an AWS account may register a new MFA method to maintain persistence. If confirmed malicious, this activity could allow attackers to secure their access, making it harder to detect and remove their presence from the compromised environment.
|
||||
data_source:
|
||||
description: The following analytic identifies the registration of a new Multi-Factor
|
||||
Authentication (MFA) method for an AWS account, as logged through Amazon Security
|
||||
Lake (ASL). It detects this activity by monitoring the `CreateVirtualMFADevice`
|
||||
API operation within ASL logs. This behavior is significant because adversaries
|
||||
who gain unauthorized access to an AWS account may register a new MFA method to
|
||||
maintain persistence. If confirmed malicious, this activity could allow attackers
|
||||
to secure their access, making it harder to detect and remove their presence from
|
||||
the compromised environment.
|
||||
data_source:
|
||||
- ASL AWS CloudTrail
|
||||
search: '`amazon_security_lake` api.operation=CreateVirtualMFADevice | fillnull | stats count min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region | rename actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent as user_agent | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `asl_aws_new_mfa_method_registered_for_user_filter`'
|
||||
how_to_implement: The detection is based on Amazon Security Lake events from Amazon Web Services (AWS), which is a centralized data lake that provides security-related data from AWS services. To use this detection, you must ingest CloudTrail logs from Amazon Security Lake into Splunk. To run this search, ensure that you ingest events using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876) or the Federated Analytics App.
|
||||
known_false_positives: Newly onboarded users who are registering an MFA method for the first time will also trigger this detection.
|
||||
search: '`amazon_security_lake` api.operation=CreateVirtualMFADevice | fillnull |
|
||||
stats count min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid
|
||||
actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region | rename
|
||||
actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent
|
||||
as user_agent | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
|
||||
| `asl_aws_new_mfa_method_registered_for_user_filter`'
|
||||
how_to_implement: The detection is based on Amazon Security Lake events from Amazon
|
||||
Web Services (AWS), which is a centralized data lake that provides security-related
|
||||
data from AWS services. To use this detection, you must ingest CloudTrail logs from
|
||||
Amazon Security Lake into Splunk. To run this search, ensure that you ingest events
|
||||
using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876)
|
||||
or the Federated Analytics App.
|
||||
known_false_positives: Newly onboarded users who are registering an MFA method for
|
||||
the first time will also trigger this detection.
|
||||
references:
|
||||
- https://aws.amazon.com/blogs/security/you-can-now-assign-multiple-mfa-devices-in-iam/
|
||||
- https://attack.mitre.org/techniques/T1556/
|
||||
@@ -30,7 +48,6 @@ tags:
|
||||
- AWS Identity and Access Management Account Takeover
|
||||
asset_type: AWS Account
|
||||
mitre_attack_id:
|
||||
- T1556
|
||||
- T1556.006
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
@@ -40,6 +57,7 @@ tags:
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1556.006/aws_new_mfa_method_registered_for_user/asl_ocsf_cloudtrail.json
|
||||
- data:
|
||||
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1556.006/aws_new_mfa_method_registered_for_user/asl_ocsf_cloudtrail.json
|
||||
sourcetype: aws:asl
|
||||
source: aws_asl
|
||||
|
||||
@@ -1,20 +1,34 @@
|
||||
name: ASL AWS UpdateLoginProfile
|
||||
id: 5b3f63a3-865b-4637-9941-f98bd1a50c0d
|
||||
version: 1
|
||||
date: '2025-01-09'
|
||||
version: 2
|
||||
date: '2025-02-10'
|
||||
author: Patrick Bareiss, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
description: The following analytic detects an AWS CloudTrail event where a user with permissions updates the login profile of another user. It leverages CloudTrail logs to identify instances where the user making the change is different from the user whose profile is being updated. This activity is significant because it can indicate privilege escalation attempts, where an attacker uses a compromised account to gain higher privileges. If confirmed malicious, this could allow the attacker to escalate their privileges, potentially leading to unauthorized access and control over sensitive resources within the AWS environment.
|
||||
data_source:
|
||||
description: The following analytic detects an AWS CloudTrail event where a user with
|
||||
permissions updates the login profile of another user. It leverages CloudTrail logs
|
||||
to identify instances where the user making the change is different from the user
|
||||
whose profile is being updated. This activity is significant because it can indicate
|
||||
privilege escalation attempts, where an attacker uses a compromised account to gain
|
||||
higher privileges. If confirmed malicious, this could allow the attacker to escalate
|
||||
their privileges, potentially leading to unauthorized access and control over sensitive
|
||||
resources within the AWS environment.
|
||||
data_source:
|
||||
- ASL AWS CloudTrail
|
||||
search: '`amazon_security_lake` api.operation=UpdateLoginProfile
|
||||
| fillnull
|
||||
| stats count min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region
|
||||
| rename actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent as user_agent
|
||||
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `asl_aws_updateloginprofile_filter`'
|
||||
how_to_implement: The detection is based on Amazon Security Lake events from Amazon Web Services (AWS), which is a centralized data lake that provides security-related data from AWS services. To use this detection, you must ingest CloudTrail logs from Amazon Security Lake into Splunk. To run this search, ensure that you ingest events using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876) or the Federated Analytics App.
|
||||
known_false_positives: While this search has no known false positives, it is possible that an AWS admin has legitimately created keys for another user.
|
||||
search: '`amazon_security_lake` api.operation=UpdateLoginProfile | fillnull | stats
|
||||
count min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid
|
||||
actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region | rename
|
||||
actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent
|
||||
as user_agent | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
|
||||
| `asl_aws_updateloginprofile_filter`'
|
||||
how_to_implement: The detection is based on Amazon Security Lake events from Amazon
|
||||
Web Services (AWS), which is a centralized data lake that provides security-related
|
||||
data from AWS services. To use this detection, you must ingest CloudTrail logs from
|
||||
Amazon Security Lake into Splunk. To run this search, ensure that you ingest events
|
||||
using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876)
|
||||
or the Federated Analytics App.
|
||||
known_false_positives: While this search has no known false positives, it is possible
|
||||
that an AWS admin has legitimately created keys for another user.
|
||||
references:
|
||||
- https://bishopfox.com/blog/privilege-escalation-in-aws
|
||||
- https://rhinosecuritylabs.com/aws/aws-privilege-escalation-methods-mitigation-part-2/
|
||||
@@ -24,12 +38,18 @@ drilldown_searches:
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
- name: View risk events for the last 7 days for - "$user$"
|
||||
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
|
||||
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$")
|
||||
starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime
|
||||
values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories)
|
||||
as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic)
|
||||
as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)`'
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
rba:
|
||||
message: User $user$ from IP address $src_ip$ updated the login profile of another user
|
||||
risk_objects:
|
||||
message: User $user$ from IP address $src_ip$ updated the login profile of another
|
||||
user
|
||||
risk_objects:
|
||||
- field: user
|
||||
type: user
|
||||
score: 30
|
||||
@@ -42,7 +62,6 @@ tags:
|
||||
asset_type: AWS Account
|
||||
mitre_attack_id:
|
||||
- T1136.003
|
||||
- T1136
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
@@ -51,6 +70,7 @@ tags:
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078/aws_updateloginprofile/asl_ocsf_cloudtrail.json
|
||||
- data:
|
||||
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078/aws_updateloginprofile/asl_ocsf_cloudtrail.json
|
||||
sourcetype: aws:asl
|
||||
source: aws_asl
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: AWS Console Login Failed During MFA Challenge
|
||||
id: 55349868-5583-466f-98ab-d3beb321961e
|
||||
version: 4
|
||||
date: '2024-11-14'
|
||||
version: 5
|
||||
date: '2025-02-10'
|
||||
author: Bhavin Patel, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -57,7 +57,6 @@ tags:
|
||||
- Compromised User Account
|
||||
asset_type: AWS Account
|
||||
mitre_attack_id:
|
||||
- T1586
|
||||
- T1586.003
|
||||
- T1621
|
||||
product:
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: AWS Create Policy Version to allow all resources
|
||||
id: 2a9b80d3-6340-4345-b5ad-212bf3d0dac4
|
||||
version: 7
|
||||
date: '2024-11-14'
|
||||
version: 8
|
||||
date: '2025-02-10'
|
||||
author: Bhavin Patel, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -58,7 +58,6 @@ tags:
|
||||
asset_type: AWS Account
|
||||
mitre_attack_id:
|
||||
- T1078.004
|
||||
- T1078
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: AWS CreateAccessKey
|
||||
id: 2a9b80d3-6340-4345-11ad-212bf3d0d111
|
||||
version: 6
|
||||
date: '2024-11-14'
|
||||
version: 7
|
||||
date: '2025-02-10'
|
||||
author: Bhavin Patel, Splunk
|
||||
status: production
|
||||
type: Hunting
|
||||
@@ -33,7 +33,6 @@ tags:
|
||||
asset_type: AWS Account
|
||||
mitre_attack_id:
|
||||
- T1136.003
|
||||
- T1136
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: AWS CreateLoginProfile
|
||||
id: 2a9b80d3-6340-4345-11ad-212bf444d111
|
||||
version: 5
|
||||
date: '2024-11-14'
|
||||
version: 6
|
||||
date: '2025-02-10'
|
||||
author: Bhavin Patel, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -59,7 +59,6 @@ tags:
|
||||
asset_type: AWS Account
|
||||
mitre_attack_id:
|
||||
- T1136.003
|
||||
- T1136
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: AWS Credential Access Failed Login
|
||||
id: a19b354d-0d7f-47f3-8ea6-1a7c36434968
|
||||
version: 4
|
||||
date: '2024-11-14'
|
||||
version: 5
|
||||
date: '2025-02-10'
|
||||
author: Gowthamaraj Rajendran, Bhavin Patel, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -54,10 +54,8 @@ tags:
|
||||
- AWS Identity and Access Management Account Takeover
|
||||
asset_type: AWS Account
|
||||
mitre_attack_id:
|
||||
- T1586
|
||||
- T1586.003
|
||||
- T1110
|
||||
- T1110.001
|
||||
- T1586.003
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: AWS Credential Access GetPasswordData
|
||||
id: 4d347c4a-306e-41db-8d10-b46baf71b3e2
|
||||
version: 4
|
||||
date: '2024-11-14'
|
||||
version: 5
|
||||
date: '2025-02-10'
|
||||
author: Bhavin Patel, Splunk
|
||||
status: production
|
||||
type: Anomaly
|
||||
@@ -57,10 +57,8 @@ tags:
|
||||
- AWS Identity and Access Management Account Takeover
|
||||
asset_type: AWS Account
|
||||
mitre_attack_id:
|
||||
- T1586
|
||||
- T1586.003
|
||||
- T1110
|
||||
- T1110.001
|
||||
- T1586.003
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: AWS Credential Access RDS Password reset
|
||||
id: 6153c5ea-ed30-4878-81e6-21ecdb198189
|
||||
version: 5
|
||||
date: '2024-11-14'
|
||||
version: 6
|
||||
date: '2025-02-10'
|
||||
author: Gowthamaraj Rajendran, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -52,9 +52,8 @@ tags:
|
||||
- AWS Identity and Access Management Account Takeover
|
||||
asset_type: AWS Account
|
||||
mitre_attack_id:
|
||||
- T1586
|
||||
- T1586.003
|
||||
- T1110
|
||||
- T1586.003
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: AWS Defense Evasion Delete Cloudtrail
|
||||
id: 82092925-9ca1-4e06-98b8-85a2d3889552
|
||||
version: 4
|
||||
date: '2024-11-14'
|
||||
version: 5
|
||||
date: '2025-02-10'
|
||||
author: Bhavin Patel, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -56,7 +56,6 @@ tags:
|
||||
asset_type: AWS Account
|
||||
mitre_attack_id:
|
||||
- T1562.008
|
||||
- T1562
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: AWS Defense Evasion Delete CloudWatch Log Group
|
||||
id: d308b0f1-edb7-4a62-a614-af321160710f
|
||||
version: 4
|
||||
date: '2024-11-14'
|
||||
version: 5
|
||||
date: '2025-02-10'
|
||||
author: Gowthamaraj Rajendran, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -55,7 +55,6 @@ tags:
|
||||
- AWS Defense Evasion
|
||||
asset_type: AWS Account
|
||||
mitre_attack_id:
|
||||
- T1562
|
||||
- T1562.008
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: AWS Defense Evasion Impair Security Services
|
||||
id: b28c4957-96a6-47e0-a965-6c767aac1458
|
||||
version: 4
|
||||
date: '2024-11-14'
|
||||
version: 5
|
||||
date: '2025-02-10'
|
||||
author: Bhavin Patel, Gowthamaraj Rajendran, Splunk
|
||||
status: production
|
||||
type: Hunting
|
||||
@@ -42,7 +42,6 @@ tags:
|
||||
asset_type: AWS Account
|
||||
mitre_attack_id:
|
||||
- T1562.008
|
||||
- T1562
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: AWS Defense Evasion PutBucketLifecycle
|
||||
id: ce1c0e2b-9303-4903-818b-0d9002fc6ea4
|
||||
version: 4
|
||||
date: '2024-11-14'
|
||||
version: 5
|
||||
date: '2025-02-10'
|
||||
author: Bhavin Patel
|
||||
status: production
|
||||
type: Hunting
|
||||
@@ -33,10 +33,8 @@ tags:
|
||||
- AWS Defense Evasion
|
||||
asset_type: AWS Account
|
||||
mitre_attack_id:
|
||||
- T1562.008
|
||||
- T1562
|
||||
- T1485.001
|
||||
- T1485
|
||||
- T1562.008
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: AWS Defense Evasion Stop Logging Cloudtrail
|
||||
id: 8a2f3ca2-4eb5-4389-a549-14063882e537
|
||||
version: 4
|
||||
date: '2024-11-14'
|
||||
version: 5
|
||||
date: '2025-02-10'
|
||||
author: Bhavin Patel, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -56,7 +56,6 @@ tags:
|
||||
asset_type: AWS Account
|
||||
mitre_attack_id:
|
||||
- T1562.008
|
||||
- T1562
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: AWS Defense Evasion Update Cloudtrail
|
||||
id: 7c921d28-ef48-4f1b-85b3-0af8af7697db
|
||||
version: 4
|
||||
date: '2024-11-14'
|
||||
version: 5
|
||||
date: '2025-02-10'
|
||||
author: Gowthamaraj Rajendran, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -55,7 +55,6 @@ tags:
|
||||
- AWS Defense Evasion
|
||||
asset_type: AWS Account
|
||||
mitre_attack_id:
|
||||
- T1562
|
||||
- T1562.008
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: AWS ECR Container Scanning Findings High
|
||||
id: 30a0e9f8-f1dd-4f9d-8fc2-c622461d781c
|
||||
version: 5
|
||||
date: '2024-11-14'
|
||||
version: 6
|
||||
date: '2025-02-10'
|
||||
author: Patrick Bareiss, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -57,7 +57,6 @@ tags:
|
||||
asset_type: AWS Account
|
||||
mitre_attack_id:
|
||||
- T1204.003
|
||||
- T1204
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: AWS ECR Container Scanning Findings Low Informational Unknown
|
||||
id: cbc95e44-7c22-443f-88fd-0424478f5589
|
||||
version: 5
|
||||
date: '2024-11-14'
|
||||
version: 6
|
||||
date: '2025-02-10'
|
||||
author: Patrick Bareiss, Eric McGinnis Splunk
|
||||
status: production
|
||||
type: Anomaly
|
||||
@@ -57,7 +57,6 @@ tags:
|
||||
asset_type: AWS Account
|
||||
mitre_attack_id:
|
||||
- T1204.003
|
||||
- T1204
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: AWS ECR Container Scanning Findings Medium
|
||||
id: 0b80e2c8-c746-4ddb-89eb-9efd892220cf
|
||||
version: 5
|
||||
date: '2024-11-14'
|
||||
version: 6
|
||||
date: '2025-02-10'
|
||||
author: Patrick Bareiss, Splunk
|
||||
status: production
|
||||
type: Anomaly
|
||||
@@ -56,7 +56,6 @@ tags:
|
||||
asset_type: AWS Account
|
||||
mitre_attack_id:
|
||||
- T1204.003
|
||||
- T1204
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: AWS ECR Container Upload Outside Business Hours
|
||||
id: d4c4d4eb-3994-41ca-a25e-a82d64e125bb
|
||||
version: 5
|
||||
date: '2024-11-14'
|
||||
version: 6
|
||||
date: '2025-02-10'
|
||||
author: Patrick Bareiss, Splunk
|
||||
status: production
|
||||
type: Anomaly
|
||||
@@ -56,7 +56,6 @@ tags:
|
||||
asset_type: AWS Account
|
||||
mitre_attack_id:
|
||||
- T1204.003
|
||||
- T1204
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: AWS ECR Container Upload Unknown User
|
||||
id: 300688e4-365c-4486-a065-7c884462b31d
|
||||
version: 4
|
||||
date: '2024-11-14'
|
||||
version: 5
|
||||
date: '2025-02-10'
|
||||
author: Patrick Bareiss, Splunk
|
||||
status: production
|
||||
type: Anomaly
|
||||
@@ -54,7 +54,6 @@ tags:
|
||||
asset_type: AWS Account
|
||||
mitre_attack_id:
|
||||
- T1204.003
|
||||
- T1204
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: AWS High Number Of Failed Authentications From Ip
|
||||
id: f75b7f1a-b8eb-4975-a214-ff3e0a944757
|
||||
version: 4
|
||||
date: '2024-11-14'
|
||||
version: 5
|
||||
date: '2025-02-10'
|
||||
author: Bhavin Patel, Splunk
|
||||
status: production
|
||||
type: Anomaly
|
||||
@@ -55,7 +55,6 @@ tags:
|
||||
- Compromised User Account
|
||||
asset_type: AWS Account
|
||||
mitre_attack_id:
|
||||
- T1110
|
||||
- T1110.003
|
||||
- T1110.004
|
||||
product:
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: AWS IAM Successful Group Deletion
|
||||
id: e776d06c-9267-11eb-819b-acde48001122
|
||||
version: 5
|
||||
date: '2024-11-14'
|
||||
version: 6
|
||||
date: '2025-02-10'
|
||||
author: Michael Haag, Splunk
|
||||
status: production
|
||||
type: Hunting
|
||||
@@ -36,7 +36,6 @@ tags:
|
||||
mitre_attack_id:
|
||||
- T1069.003
|
||||
- T1098
|
||||
- T1069
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: AWS Multi-Factor Authentication Disabled
|
||||
id: 374832b1-3603-420c-b456-b373e24d34c0
|
||||
version: 4
|
||||
date: '2024-11-14'
|
||||
version: 5
|
||||
date: '2025-02-10'
|
||||
author: Bhavin Patel, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -56,11 +56,9 @@ tags:
|
||||
- AWS Identity and Access Management Account Takeover
|
||||
asset_type: AWS Account
|
||||
mitre_attack_id:
|
||||
- T1586
|
||||
- T1556.006
|
||||
- T1586.003
|
||||
- T1621
|
||||
- T1556
|
||||
- T1556.006
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: AWS Multiple Failed MFA Requests For User
|
||||
id: 1fece617-e614-4329-9e61-3ba228c0f353
|
||||
version: 4
|
||||
date: '2024-11-14'
|
||||
version: 5
|
||||
date: '2025-02-10'
|
||||
author: Bhavin Patel
|
||||
status: production
|
||||
type: Anomaly
|
||||
@@ -54,7 +54,6 @@ tags:
|
||||
- AWS Identity and Access Management Account Takeover
|
||||
asset_type: AWS Account
|
||||
mitre_attack_id:
|
||||
- T1586
|
||||
- T1586.003
|
||||
- T1621
|
||||
product:
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: AWS Multiple Users Failing To Authenticate From Ip
|
||||
id: 71e1fb89-dd5f-4691-8523-575420de4630
|
||||
version: 4
|
||||
date: '2024-11-14'
|
||||
version: 5
|
||||
date: '2025-02-10'
|
||||
author: Bhavin Patel
|
||||
status: production
|
||||
type: Anomaly
|
||||
@@ -57,7 +57,6 @@ tags:
|
||||
- Compromised User Account
|
||||
asset_type: AWS Account
|
||||
mitre_attack_id:
|
||||
- T1110
|
||||
- T1110.003
|
||||
- T1110.004
|
||||
product:
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: AWS Network Access Control List Created with All Open Ports
|
||||
id: ada0f478-84a8-4641-a3f1-d82362d6bd75
|
||||
version: 5
|
||||
date: '2024-11-14'
|
||||
version: 6
|
||||
date: '2025-02-10'
|
||||
author: Bhavin Patel, Patrick Bareiss, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -63,7 +63,6 @@ tags:
|
||||
asset_type: AWS Instance
|
||||
mitre_attack_id:
|
||||
- T1562.007
|
||||
- T1562
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: AWS Network Access Control List Deleted
|
||||
id: ada0f478-84a8-4641-a3f1-d82362d6fd75
|
||||
version: 5
|
||||
date: '2024-11-14'
|
||||
version: 6
|
||||
date: '2025-02-10'
|
||||
author: Bhavin Patel, Patrick Bareiss, Splunk
|
||||
status: production
|
||||
type: Anomaly
|
||||
@@ -54,7 +54,6 @@ tags:
|
||||
asset_type: AWS Instance
|
||||
mitre_attack_id:
|
||||
- T1562.007
|
||||
- T1562
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: AWS New MFA Method Registered For User
|
||||
id: 4e3c26f2-4fb9-4bd7-ab46-1b76ffa2a23b
|
||||
version: 5
|
||||
date: '2024-11-14'
|
||||
version: 6
|
||||
date: '2025-02-10'
|
||||
author: Bhavin Patel, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -56,7 +56,6 @@ tags:
|
||||
- AWS Identity and Access Management Account Takeover
|
||||
asset_type: AWS Account
|
||||
mitre_attack_id:
|
||||
- T1556
|
||||
- T1556.006
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: AWS SetDefaultPolicyVersion
|
||||
id: 2a9b80d3-6340-4345-11ad-212bf3d0dac4
|
||||
version: 4
|
||||
date: '2024-11-14'
|
||||
version: 5
|
||||
date: '2025-02-10'
|
||||
author: Bhavin Patel, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -58,7 +58,6 @@ tags:
|
||||
asset_type: AWS Account
|
||||
mitre_attack_id:
|
||||
- T1078.004
|
||||
- T1078
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: AWS Successful Single-Factor Authentication
|
||||
id: a520b1fe-cc9e-4f56-b762-18354594c52f
|
||||
version: 4
|
||||
date: '2024-11-14'
|
||||
version: 5
|
||||
date: '2025-02-10'
|
||||
author: Bhavin Patel, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -56,10 +56,8 @@ tags:
|
||||
- AWS Identity and Access Management Account Takeover
|
||||
asset_type: AWS Account
|
||||
mitre_attack_id:
|
||||
- T1586
|
||||
- T1586.003
|
||||
- T1078
|
||||
- T1078.004
|
||||
- T1586.003
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: AWS Unusual Number of Failed Authentications From Ip
|
||||
id: 0b5c9c2b-e2cb-4831-b4f1-af125ceb1386
|
||||
version: 5
|
||||
date: '2024-11-14'
|
||||
version: 6
|
||||
date: '2025-02-10'
|
||||
author: Bhavin Patel, Splunk
|
||||
status: production
|
||||
type: Anomaly
|
||||
@@ -57,11 +57,9 @@ tags:
|
||||
- AWS Identity and Access Management Account Takeover
|
||||
asset_type: AWS Account
|
||||
mitre_attack_id:
|
||||
- T1586
|
||||
- T1586.003
|
||||
- T1110
|
||||
- T1110.003
|
||||
- T1110.004
|
||||
- T1586.003
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: AWS UpdateLoginProfile
|
||||
id: 2a9b80d3-6a40-4115-11ad-212bf3d0d111
|
||||
version: 7
|
||||
date: '2024-11-14'
|
||||
version: 8
|
||||
date: '2025-02-10'
|
||||
author: Bhavin Patel, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -59,7 +59,6 @@ tags:
|
||||
asset_type: AWS Account
|
||||
mitre_attack_id:
|
||||
- T1136.003
|
||||
- T1136
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Azure Active Directory High Risk Sign-in
|
||||
id: 1ecff169-26d7-4161-9a7b-2ac4c8e61bea
|
||||
version: 6
|
||||
date: '2024-11-14'
|
||||
version: 7
|
||||
date: '2025-02-10'
|
||||
author: Mauricio Velazco, Gowthamaraj Rajendran, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -58,10 +58,8 @@ tags:
|
||||
- Azure Active Directory Account Takeover
|
||||
asset_type: Azure Active Directory
|
||||
mitre_attack_id:
|
||||
- T1586
|
||||
- T1586.003
|
||||
- T1110
|
||||
- T1110.003
|
||||
- T1586.003
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Azure AD Application Administrator Role Assigned
|
||||
id: eac4de87-7a56-4538-a21b-277897af6d8d
|
||||
version: 6
|
||||
date: '2024-11-14'
|
||||
version: 8
|
||||
date: '2025-02-10'
|
||||
author: Mauricio Velazco, Gowthamaraj Rajendran, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -64,7 +64,6 @@ tags:
|
||||
asset_type: Azure Active Directory
|
||||
atomic_guid: []
|
||||
mitre_attack_id:
|
||||
- T1098
|
||||
- T1098.003
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Azure AD Authentication Failed During MFA Challenge
|
||||
id: e62c9c2e-bf51-4719-906c-3074618fcc1c
|
||||
version: 7
|
||||
date: '2024-11-14'
|
||||
version: 8
|
||||
date: '2025-02-10'
|
||||
author: Mauricio Velazco, Gowthamaraj Rajendran, Splunk, 0xC0FFEEEE
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -70,10 +70,8 @@ tags:
|
||||
- Azure Active Directory Account Takeover
|
||||
asset_type: Azure Active Directory
|
||||
mitre_attack_id:
|
||||
- T1586
|
||||
- T1586.003
|
||||
- T1078
|
||||
- T1078.004
|
||||
- T1586.003
|
||||
- T1621
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: Azure AD AzureHound UserAgent Detected
|
||||
id: d62852db-a1f1-40db-a7fc-c3d56fa8bda3
|
||||
version: 1
|
||||
version: 2
|
||||
date: '2025-01-06'
|
||||
author: Dean Luxton
|
||||
data_source:
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Azure AD Device Code Authentication
|
||||
id: d68d8732-6f7e-4ee5-a6eb-737f2b990b91
|
||||
version: 5
|
||||
date: '2024-11-14'
|
||||
version: 6
|
||||
date: '2025-02-10'
|
||||
author: Mauricio Velazco, Gowthamaraj Rajendran, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -62,7 +62,6 @@ tags:
|
||||
asset_type: Azure Tenant
|
||||
mitre_attack_id:
|
||||
- T1528
|
||||
- T1566
|
||||
- T1566.002
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: Azure AD External Guest User Invited
|
||||
id: c1fb4edb-cab1-4359-9b40-925ffd797fb5
|
||||
version: 5
|
||||
version: 6
|
||||
date: '2024-11-14'
|
||||
author: Gowthamaraj Rajendran, Mauricio Velazco, Splunk
|
||||
status: production
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Azure AD High Number Of Failed Authentications For User
|
||||
id: 630b1694-210a-48ee-a450-6f79e7679f2c
|
||||
version: 6
|
||||
date: '2024-11-14'
|
||||
version: 7
|
||||
date: '2025-02-10'
|
||||
author: Mauricio Velazco, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -58,7 +58,6 @@ tags:
|
||||
- Azure Active Directory Account Takeover
|
||||
asset_type: Azure Tenant
|
||||
mitre_attack_id:
|
||||
- T1110
|
||||
- T1110.001
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Azure AD High Number Of Failed Authentications From Ip
|
||||
id: e5ab41bf-745d-4f72-a393-2611151afd8e
|
||||
version: 7
|
||||
date: '2024-11-14'
|
||||
version: 8
|
||||
date: '2025-02-10'
|
||||
author: Mauricio Velazco, Bhavin Patel, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -62,7 +62,6 @@ tags:
|
||||
- NOBELIUM Group
|
||||
asset_type: Azure Tenant
|
||||
mitre_attack_id:
|
||||
- T1110
|
||||
- T1110.001
|
||||
- T1110.003
|
||||
product:
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Azure AD Multi-Factor Authentication Disabled
|
||||
id: 482dd42a-acfa-486b-a0bb-d6fcda27318e
|
||||
version: 5
|
||||
date: '2024-11-14'
|
||||
version: 7
|
||||
date: '2025-02-10'
|
||||
author: Mauricio Velazco, Gowthamaraj Rajendran, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -60,10 +60,8 @@ tags:
|
||||
- Azure Active Directory Account Takeover
|
||||
asset_type: Azure Active Directory
|
||||
mitre_attack_id:
|
||||
- T1586
|
||||
- T1586.003
|
||||
- T1556
|
||||
- T1556.006
|
||||
- T1586.003
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Azure AD Multi-Source Failed Authentications Spike
|
||||
id: 116e11a9-63ea-41eb-a66a-6a13bdc7d2c7
|
||||
version: 6
|
||||
date: '2024-11-14'
|
||||
version: 7
|
||||
date: '2025-02-10'
|
||||
author: Mauricio Velazco, Splunk
|
||||
status: production
|
||||
type: Hunting
|
||||
@@ -53,11 +53,9 @@ tags:
|
||||
asset_type: Azure Tenant
|
||||
atomic_guid: []
|
||||
mitre_attack_id:
|
||||
- T1586
|
||||
- T1586.003
|
||||
- T1110
|
||||
- T1110.003
|
||||
- T1110.004
|
||||
- T1586.003
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Azure AD Multiple Failed MFA Requests For User
|
||||
id: 264ea131-ab1f-41b8-90e0-33ad1a1888ea
|
||||
version: 7
|
||||
date: '2024-11-14'
|
||||
version: 8
|
||||
date: '2025-02-10'
|
||||
author: Mauricio Velazco, Gowthamaraj Rajendran, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -62,11 +62,9 @@ tags:
|
||||
- Azure Active Directory Account Takeover
|
||||
asset_type: Azure Active Directory
|
||||
mitre_attack_id:
|
||||
- T1586
|
||||
- T1078.004
|
||||
- T1586.003
|
||||
- T1621
|
||||
- T1078
|
||||
- T1078.004
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Azure AD Multiple Users Failing To Authenticate From Ip
|
||||
id: 94481a6a-8f59-4c86-957f-55a71e3612a6
|
||||
version: 6
|
||||
date: '2024-11-14'
|
||||
version: 7
|
||||
date: '2025-02-10'
|
||||
author: Mauricio Velazco, Gowthamaraj Rajendran, Splunk
|
||||
status: production
|
||||
type: Anomaly
|
||||
@@ -60,11 +60,9 @@ tags:
|
||||
- Azure Active Directory Account Takeover
|
||||
asset_type: Azure Active Directory
|
||||
mitre_attack_id:
|
||||
- T1586
|
||||
- T1586.003
|
||||
- T1110
|
||||
- T1110.003
|
||||
- T1110.004
|
||||
- T1586.003
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Azure AD New Custom Domain Added
|
||||
id: 30c47f45-dd6a-4720-9963-0bca6c8686ef
|
||||
version: 6
|
||||
date: '2024-11-14'
|
||||
version: 7
|
||||
date: '2025-02-10'
|
||||
author: Mauricio Velazco, Gowthamaraj Rajendran, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -60,7 +60,6 @@ tags:
|
||||
- Azure Active Directory Persistence
|
||||
asset_type: Azure Active Directory
|
||||
mitre_attack_id:
|
||||
- T1484
|
||||
- T1484.002
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Azure AD New Federated Domain Added
|
||||
id: a87cd633-076d-4ab2-9047-977751a3c1a0
|
||||
version: 6
|
||||
date: '2024-11-14'
|
||||
version: 7
|
||||
date: '2025-02-10'
|
||||
author: Mauricio Velazco, Gowthamaraj Rajendran, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -58,7 +58,6 @@ tags:
|
||||
- Azure Active Directory Persistence
|
||||
asset_type: Azure Active Directory
|
||||
mitre_attack_id:
|
||||
- T1484
|
||||
- T1484.002
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Azure AD New MFA Method Registered
|
||||
id: 0488e814-eb81-42c3-9f1f-b2244973e3a3
|
||||
version: 5
|
||||
date: '2024-11-14'
|
||||
version: 6
|
||||
date: '2025-02-10'
|
||||
author: Mauricio Velazco, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -62,7 +62,6 @@ tags:
|
||||
- Azure Active Directory Persistence
|
||||
asset_type: Azure Tenant
|
||||
mitre_attack_id:
|
||||
- T1098
|
||||
- T1098.005
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Azure AD New MFA Method Registered For User
|
||||
id: 2628b087-4189-403f-9044-87403f777a1b
|
||||
version: 6
|
||||
date: '2024-11-14'
|
||||
version: 7
|
||||
date: '2025-02-10'
|
||||
author: Mauricio Velazco, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -60,7 +60,6 @@ tags:
|
||||
- Azure Active Directory Account Takeover
|
||||
asset_type: Azure Active Directory
|
||||
mitre_attack_id:
|
||||
- T1556
|
||||
- T1556.006
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Azure AD PIM Role Assigned
|
||||
id: fcd6dfeb-191c-46a0-a29c-c306382145ab
|
||||
version: 6
|
||||
date: '2024-11-14'
|
||||
version: 7
|
||||
date: '2025-02-10'
|
||||
author: Mauricio Velazco, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -57,7 +57,6 @@ tags:
|
||||
- Azure Active Directory Persistence
|
||||
asset_type: Azure Active Directory
|
||||
mitre_attack_id:
|
||||
- T1098
|
||||
- T1098.003
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Azure AD PIM Role Assignment Activated
|
||||
id: 952e80d0-e343-439b-83f4-808c3e6fbf2e
|
||||
version: 7
|
||||
date: '2024-11-14'
|
||||
version: 8
|
||||
date: '2025-02-10'
|
||||
author: Mauricio Velazco, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -58,7 +58,6 @@ tags:
|
||||
- Azure Active Directory Persistence
|
||||
asset_type: Azure Active Directory
|
||||
mitre_attack_id:
|
||||
- T1098
|
||||
- T1098.003
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Azure AD Privileged Role Assigned
|
||||
id: a28f0bc3-3400-4a6e-a2da-89b9e95f0d2a
|
||||
version: 6
|
||||
date: '2024-11-14'
|
||||
version: 8
|
||||
date: '2025-02-10'
|
||||
author: Mauricio Velazco, Gowthamaraj Rajendran, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -65,7 +65,6 @@ tags:
|
||||
- NOBELIUM Group
|
||||
asset_type: Azure Active Directory
|
||||
mitre_attack_id:
|
||||
- T1098
|
||||
- T1098.003
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Azure AD Privileged Role Assigned to Service Principal
|
||||
id: 5dfaa3d3-e2e4-4053-8252-16d9ee528c41
|
||||
version: 6
|
||||
date: '2024-11-14'
|
||||
version: 7
|
||||
date: '2025-02-10'
|
||||
author: Mauricio Velazco, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -61,7 +61,6 @@ tags:
|
||||
- NOBELIUM Group
|
||||
asset_type: Azure Active Directory
|
||||
mitre_attack_id:
|
||||
- T1098
|
||||
- T1098.003
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: Azure AD Service Principal Enumeration
|
||||
id: 3f0647ce-add5-4436-8039-cbd1abe74563
|
||||
version: 1
|
||||
version: 2
|
||||
date: '2025-01-06'
|
||||
author: Dean Luxton
|
||||
data_source:
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Azure AD Service Principal New Client Credentials
|
||||
id: e3adc0d3-9e4b-4b5d-b662-12cec1adff2a
|
||||
version: 6
|
||||
date: '2024-11-14'
|
||||
version: 7
|
||||
date: '2025-02-10'
|
||||
author: Mauricio Velazco, Gowthamaraj Rajendran, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -62,7 +62,6 @@ tags:
|
||||
- NOBELIUM Group
|
||||
asset_type: Azure Active Directory
|
||||
mitre_attack_id:
|
||||
- T1098
|
||||
- T1098.001
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: Azure AD Service Principal Owner Added
|
||||
id: 7ddf2084-6cf3-4a44-be83-474f7b73c701
|
||||
version: 7
|
||||
version: 8
|
||||
date: '2024-11-14'
|
||||
author: Mauricio Velazco, Gowthamaraj Rajendran, Splunk
|
||||
status: production
|
||||
|
||||
@@ -1,24 +1,35 @@
|
||||
name: Azure AD Service Principal Privilege Escalation
|
||||
id: 29eb39d3-2bc8-49cc-99b3-35593191a588
|
||||
version: 1
|
||||
date: '2025-01-06'
|
||||
version: 2
|
||||
date: '2025-02-10'
|
||||
author: Dean Luxton
|
||||
data_source:
|
||||
- Azure Active Directory Add app role assignment to service principal
|
||||
type: TTP
|
||||
status: production
|
||||
description: This detection identifies when an Azure Service Principal elevates privileges by adding themself to a new app role assignment.
|
||||
description: This detection identifies when an Azure Service Principal elevates privileges
|
||||
by adding themself to a new app role assignment.
|
||||
search: >-
|
||||
`azure_monitor_aad` category=AuditLogs operationName="Add app role assignment to service principal" properties.initiatedBy.app.displayName=* properties.result=Success
|
||||
| spath path=properties{}.targetResources{}.modifiedProperties{} output=targetResources
|
||||
| stats min(_time) as _time values(eval(mvfilter(match(targetResources, "AppRole.Value")))) as appRole, values(eval(mvfilter(match(targetResources, "ServicePrincipal.DisplayName")))) as targetServicePrincipal values(eval(mvindex('properties.targetResources{}.displayName',0))) as targetAppContext values(user_agent) as user_agent values(identity) as servicePrincipal values(properties.initiatedBy.app.servicePrincipalId) as servicePrincipalId by operationName tenantId correlationId
|
||||
`azure_monitor_aad` category=AuditLogs operationName="Add app role assignment to
|
||||
service principal" properties.initiatedBy.app.displayName=* properties.result=Success |
|
||||
spath path=properties{}.targetResources{}.modifiedProperties{} output=targetResources
|
||||
| stats min(_time) as _time values(eval(mvfilter(match(targetResources, "AppRole.Value"))))
|
||||
as appRole, values(eval(mvfilter(match(targetResources, "ServicePrincipal.DisplayName"))))
|
||||
as targetServicePrincipal values(eval(mvindex('properties.targetResources{}.displayName',0)))
|
||||
as targetAppContext values(user_agent) as user_agent values(identity) as servicePrincipal
|
||||
values(properties.initiatedBy.app.servicePrincipalId) as servicePrincipalId by operationName
|
||||
tenantId correlationId
|
||||
| spath input=appRole path=newValue output=appRole
|
||||
| spath input=targetServicePrincipal path=newValue output=targetServicePrincipal
|
||||
| eval appRole=trim(replace(appRole, "\"", "")), targetServicePrincipal=trim(replace(targetServicePrincipal, "\"", ""))
|
||||
| eval appRole=trim(replace(appRole, "\"", "")), targetServicePrincipal=trim(replace(targetServicePrincipal,
|
||||
"\"", ""))
|
||||
| where servicePrincipal=targetServicePrincipal
|
||||
| table _time operationName servicePrincipal servicePrincipalId appRole targetAppContext user_agent tenantId correlationId
|
||||
| table _time operationName servicePrincipal servicePrincipalId appRole targetAppContext
|
||||
user_agent tenantId correlationId
|
||||
| `azure_ad_service_principal_privilege_escalation_filter`
|
||||
how_to_implement: The Splunk Add-on for Microsoft Cloud Services add-on is required to ingest EntraID audit logs via Azure EventHub. See reference for links for further details on how to onboard this log source.
|
||||
how_to_implement: The Splunk Add-on for Microsoft Cloud Services add-on is required
|
||||
to ingest EntraID audit logs via Azure EventHub. See reference for links for further
|
||||
details on how to onboard this log source.
|
||||
known_false_positives: Unknown
|
||||
references:
|
||||
- https://splunkbase.splunk.com/app/3110
|
||||
@@ -32,11 +43,17 @@ drilldown_searches:
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
- name: View risk events for the last 7 days for - "$servicePrincipal$"
|
||||
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$servicePrincipal$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
|
||||
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$servicePrincipal$")
|
||||
starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime
|
||||
values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories)
|
||||
as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic)
|
||||
as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)`
|
||||
| `security_content_ctime(lastTime)`'
|
||||
earliest_offset: $info_min_time$
|
||||
latest_offset: $info_max_time$
|
||||
rba:
|
||||
message: Service Principal $servicePrincipal$ has elevated privileges by adding themself to app role $appRole$
|
||||
rba:
|
||||
message: Service Principal $servicePrincipal$ has elevated privileges by adding
|
||||
themself to app role $appRole$
|
||||
risk_objects:
|
||||
- field: servicePrincipal
|
||||
type: user
|
||||
@@ -50,7 +67,6 @@ tags:
|
||||
asset_type: Azure Tenant
|
||||
mitre_attack_id:
|
||||
- T1098.003
|
||||
- T1098
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
@@ -59,6 +75,7 @@ tags:
|
||||
tests:
|
||||
- name: True Positive Test
|
||||
attack_data:
|
||||
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1098.003/azure_ad_spn_privesc/azure_ad_spn_privesc.log
|
||||
- data:
|
||||
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1098.003/azure_ad_spn_privesc/azure_ad_spn_privesc.log
|
||||
sourcetype: azure:monitor:aad
|
||||
source: Azure AD
|
||||
|
||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user