update and pull in all the latest changes from

develop branch
This commit is contained in:
pyth0n1c
2025-02-14 10:22:46 -08:00
parent ebc1d84058
commit f1dd70da1e
1033 changed files with 4864 additions and 3734 deletions
@@ -1,7 +1,7 @@
name: Detect Distributed Password Spray Attempts
id: b1a82fc8-8a9f-4344-9ec2-bde5c5331b57
version: 3
date: '2025-01-21'
version: 4
date: '2025-02-10'
author: Dean Luxton
status: production
type: Hunting
@@ -65,7 +65,6 @@ tags:
- 90bc2e54-6c84-47a5-9439-0a2a92b4b175
mitre_attack_id:
- T1110.003
- T1110
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Detect Password Spray Attempts
id: 086ab581-8877-42b3-9aee-4a7ecb0923af
version: 5
date: '2025-01-21'
version: 6
date: '2025-02-10'
author: Dean Luxton
status: production
type: TTP
@@ -83,7 +83,6 @@ tags:
- 90bc2e54-6c84-47a5-9439-0a2a92b4b175
mitre_attack_id:
- T1110.003
- T1110
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Email files written outside of the Outlook directory
id: 8d52cf03-ba25-4101-aa78-07994aed4f74
version: 6
date: '2025-01-21'
version: 7
date: '2025-02-10'
author: Bhavin Patel, Splunk
status: experimental
type: TTP
@@ -44,7 +44,6 @@ tags:
- Collection and Staging
asset_type: Endpoint
mitre_attack_id:
- T1114
- T1114.001
product:
- Splunk Enterprise
@@ -1,7 +1,7 @@
name: Email servers sending high volume traffic to hosts
id: 7f5fb3e1-4209-4914-90db-0ec21b556378
version: 5
date: '2025-01-21'
version: 6
date: '2025-02-10'
author: Bhavin Patel, Splunk
status: experimental
type: Anomaly
@@ -51,7 +51,6 @@ tags:
- HAFNIUM Group
asset_type: Endpoint
mitre_attack_id:
- T1114
- T1114.002
product:
- Splunk Enterprise
@@ -1,7 +1,7 @@
name: Okta Authentication Failed During MFA Challenge
id: e2b99e7d-d956-411a-a120-2b14adfdde93
version: 4
date: '2025-01-21'
version: 5
date: '2025-02-10'
author: Bhavin Patel, Splunk
data_source:
- Okta
@@ -59,10 +59,8 @@ tags:
- Okta Account Takeover
asset_type: Okta Tenant
mitre_attack_id:
- T1586
- T1586.003
- T1078
- T1078.004
- T1586.003
- T1621
product:
- Splunk Enterprise
@@ -1,7 +1,7 @@
name: Okta Multi-Factor Authentication Disabled
id: 7c0348ce-bdf9-45f6-8a57-c18b5976f00a
version: 5
date: '2025-01-21'
version: 6
date: '2025-02-10'
author: Mauricio Velazco, Splunk
data_source:
- Okta
@@ -57,7 +57,6 @@ tags:
- Okta Account Takeover
asset_type: Okta Tenant
mitre_attack_id:
- T1556
- T1556.006
product:
- Splunk Enterprise
@@ -1,7 +1,7 @@
name: Okta New API Token Created
id: c3d22720-35d3-4da4-bd0a-740d37192bd4
version: 6
date: '2025-01-21'
version: 7
date: '2025-02-10'
author: Michael Haag, Mauricio Velazco, Splunk
status: production
type: TTP
@@ -54,7 +54,6 @@ tags:
- Okta Account Takeover
asset_type: Okta Tenant
mitre_attack_id:
- T1078
- T1078.001
product:
- Splunk Enterprise
@@ -1,7 +1,7 @@
name: Okta New Device Enrolled on Account
id: bb27cbce-d4de-432c-932f-2e206e9130fb
version: 6
date: '2025-01-21'
version: 7
date: '2025-02-10'
author: Michael Haag, Mauricio Velazco, Splunk
status: production
type: TTP
@@ -54,7 +54,6 @@ tags:
- Okta Account Takeover
asset_type: Okta Tenant
mitre_attack_id:
- T1098
- T1098.005
product:
- Splunk Enterprise
@@ -1,7 +1,7 @@
name: Okta Phishing Detection with FastPass Origin Check
id: f4ca0057-cbf3-44f8-82ea-4e330ee901d3
version: 4
date: '2025-01-21'
version: 5
date: '2025-02-10'
author: Okta, Inc, Michael Haag, Splunk
type: TTP
status: experimental
@@ -38,7 +38,6 @@ tags:
- Okta Account Takeover
asset_type: Infrastructure
mitre_attack_id:
- T1078
- T1078.001
- T1556
product:
@@ -1,7 +1,7 @@
name: Okta Successful Single Factor Authentication
id: 98f6ad4f-4325-4096-9d69-45dc8e638e82
version: 4
date: '2025-01-21'
version: 5
date: '2025-02-10'
author: Bhavin Patel, Splunk
data_source:
- Okta
@@ -55,10 +55,8 @@ tags:
- Okta Account Takeover
asset_type: Okta Tenant
mitre_attack_id:
- T1586
- T1586.003
- T1078
- T1078.004
- T1586.003
- T1621
product:
- Splunk Enterprise
@@ -1,7 +1,7 @@
name: Okta Suspicious Activity Reported
id: bfc840f5-c9c6-454c-aa13-b46fd0bf1e79
version: 5
date: '2025-01-21'
version: 6
date: '2025-02-10'
author: Michael Haag, Splunk
status: production
type: TTP
@@ -55,7 +55,6 @@ tags:
- Okta Account Takeover
asset_type: Okta Tenant
mitre_attack_id:
- T1078
- T1078.001
product:
- Splunk Enterprise
@@ -1,7 +1,7 @@
name: Okta ThreatInsight Threat Detected
id: 140504ae-5fe2-4d65-b2bc-a211813fbca6
version: 5
date: '2025-01-21'
version: 6
date: '2025-02-10'
author: Michael Haag, Mauricio Velazco, Splunk
status: production
type: Anomaly
@@ -56,7 +56,6 @@ tags:
- Okta Account Takeover
asset_type: Infrastructure
mitre_attack_id:
- T1078
- T1078.004
product:
- Splunk Enterprise
@@ -1,6 +1,6 @@
name: PingID Mismatch Auth Source and Verification Response
id: 15b0694e-caa2-4009-8d83-a1f98b86d086
version: 4
version: 5
date: '2025-01-21'
author: Steven Dick
status: production
@@ -1,7 +1,7 @@
name: Suspicious Email Attachment Extensions
id: 473bd65f-06ca-4dfe-a2b8-ba04ab4a0084
version: 6
date: '2025-01-21'
version: 7
date: '2025-02-10'
author: David Dorsey, Splunk
status: experimental
type: Anomaly
@@ -48,7 +48,6 @@ tags:
asset_type: Endpoint
mitre_attack_id:
- T1566.001
- T1566
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Windows AD Dangerous Deny ACL Modification
id: 8e897153-2ebd-4cb2-85d3-09ad57db2fb7
version: 3
date: '2025-01-21'
version: 4
date: '2025-02-10'
author: Dean Luxton
status: production
type: TTP
@@ -76,9 +76,8 @@ tags:
- Sneaky Active Directory Persistence Tricks
asset_type: Endpoint
mitre_attack_id:
- T1484
- T1222
- T1222.001
- T1484
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Windows AD Dangerous Group ACL Modification
id: 59b0fc85-7a0d-4585-97ec-06a382801990
version: 3
date: '2025-01-21'
version: 4
date: '2025-02-10'
author: Dean Luxton
status: production
type: TTP
@@ -85,9 +85,8 @@ tags:
- Sneaky Active Directory Persistence Tricks
asset_type: Endpoint
mitre_attack_id:
- T1484
- T1222
- T1222.001
- T1484
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Windows AD Dangerous User ACL Modification
id: ec5b6790-595a-4fb8-ad43-56e5b55a9617
version: 3
date: '2025-01-21'
version: 4
date: '2025-02-10'
author: Dean Luxton
status: production
type: TTP
@@ -82,9 +82,8 @@ tags:
- Sneaky Active Directory Persistence Tricks
asset_type: Endpoint
mitre_attack_id:
- T1484
- T1222
- T1222.001
- T1484
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Windows AD Domain Root ACL Deletion
id: 3cb56e57-5642-4638-907f-8dfde9afb889
version: 3
date: '2025-01-21'
version: 4
date: '2025-02-10'
author: Dean Luxton
status: production
type: TTP
@@ -75,9 +75,8 @@ tags:
- Sneaky Active Directory Persistence Tricks
asset_type: Endpoint
mitre_attack_id:
- T1484
- T1222
- T1222.001
- T1484
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Windows AD Domain Root ACL Modification
id: 4981e2db-1372-440d-816e-3e7e2ed74433
version: 3
date: '2025-01-21'
version: 4
date: '2025-02-10'
author: Dean Luxton
status: production
type: TTP
@@ -75,9 +75,8 @@ tags:
- Sneaky Active Directory Persistence Tricks
asset_type: Endpoint
mitre_attack_id:
- T1484
- T1222
- T1222.001
- T1484
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Windows AD GPO New CSE Addition
id: 700c11d1-da09-47b2-81aa-358c143c7986
version: 3
date: '2025-01-21'
version: 4
date: '2025-02-10'
author: Dean Luxton
status: production
type: TTP
@@ -64,10 +64,8 @@ tags:
- Sneaky Active Directory Persistence Tricks
asset_type: Endpoint
mitre_attack_id:
- T1484
- T1484.001
- T1222
- T1222.001
- T1484.001
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Windows AD Hidden OU Creation
id: 66b6ad5e-339a-40af-b721-dacefc7bdb75
version: 3
date: '2025-01-21'
version: 4
date: '2025-02-10'
author: Dean Luxton
status: production
type: TTP
@@ -74,9 +74,8 @@ tags:
- Sneaky Active Directory Persistence Tricks
asset_type: Endpoint
mitre_attack_id:
- T1484
- T1222
- T1222.001
- T1484
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Windows AD Object Owner Updated
id: 4af01f6b-d8d4-4f96-8635-758a01557130
version: 4
date: '2025-01-21'
version: 5
date: '2025-02-10'
author: Dean Luxton
status: production
type: TTP
@@ -66,9 +66,8 @@ tags:
- Sneaky Active Directory Persistence Tricks
asset_type: Endpoint
mitre_attack_id:
- T1484
- T1222
- T1222.001
- T1484
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Windows AD Suspicious Attribute Modification
id: 5682052e-ce55-4f9f-8d28-59191420b7e0
version: 3
date: '2025-01-21'
version: 5
date: '2025-02-10'
author: Dean Luxton
status: production
type: TTP
@@ -62,9 +62,8 @@ tags:
- Sneaky Active Directory Persistence Tricks
asset_type: Endpoint
mitre_attack_id:
- T1550
- T1222
- T1222.001
- T1550
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Windows AD Suspicious GPO Modification
id: 0a2afc18-a3b5-4452-b60a-2e774214f9bf
version: 3
date: '2025-01-21'
version: 5
date: '2025-02-10'
author: Dean Luxton
status: experimental
type: TTP
@@ -70,10 +70,8 @@ tags:
- Sneaky Active Directory Persistence Tricks
asset_type: Endpoint
mitre_attack_id:
- T1484
- T1484.001
- T1222
- T1222.001
- T1484.001
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Abnormally High Number Of Cloud Infrastructure API Calls
id: 0840ddf1-8c89-46ff-b730-c8d6722478c0
version: 5
date: '2024-11-14'
version: 6
date: '2025-02-10'
author: David Dorsey, Splunk
status: experimental
type: Anomaly
@@ -46,7 +46,6 @@ tags:
asset_type: AWS Instance
mitre_attack_id:
- T1078.004
- T1078
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Abnormally High Number Of Cloud Instances Destroyed
id: ef629fc9-1583-4590-b62a-f2247fbf7bbf
version: 5
date: '2024-11-14'
version: 6
date: '2025-02-10'
author: David Dorsey, Splunk
status: experimental
type: Anomaly
@@ -48,7 +48,6 @@ tags:
asset_type: Cloud Instance
mitre_attack_id:
- T1078.004
- T1078
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Abnormally High Number Of Cloud Instances Launched
id: f2361e9f-3928-496c-a556-120cd4223a65
version: 6
date: '2024-11-14'
version: 7
date: '2025-02-10'
author: David Dorsey, Splunk
status: experimental
type: Anomaly
@@ -48,7 +48,6 @@ tags:
asset_type: Cloud Instance
mitre_attack_id:
- T1078.004
- T1078
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Abnormally High Number Of Cloud Security Group API Calls
id: d4dfb7f3-7a37-498a-b5df-f19334e871af
version: 5
date: '2024-11-14'
version: 6
date: '2025-02-10'
author: David Dorsey, Splunk
status: experimental
type: Anomaly
@@ -46,7 +46,6 @@ tags:
asset_type: AWS Instance
mitre_attack_id:
- T1078.004
- T1078
product:
- Splunk Enterprise
- Splunk Enterprise Security
+26 -9
View File
@@ -1,16 +1,33 @@
name: ASL AWS Create Access Key
id: 81a9f2fe-1697-473c-af1d-086b0d8b63c8
version: 1
date: '2024-12-12'
version: 2
date: '2025-02-10'
author: Patrick Bareiss, Splunk
status: production
type: Hunting
description: The following analytic identifies the creation of AWS IAM access keys by a user for another user, which can indicate privilege escalation. It leverages AWS CloudTrail logs to detect instances where the user creating the access key is different from the user for whom the key is created. This activity is significant because unauthorized access key creation can allow attackers to establish persistence or exfiltrate data via AWS APIs. If confirmed malicious, this could lead to unauthorized access to AWS services, data exfiltration, and long-term persistence in the environment.
data_source:
description: The following analytic identifies the creation of AWS IAM access keys
by a user for another user, which can indicate privilege escalation. It leverages
AWS CloudTrail logs to detect instances where the user creating the access key is
different from the user for whom the key is created. This activity is significant
because unauthorized access key creation can allow attackers to establish persistence
or exfiltrate data via AWS APIs. If confirmed malicious, this could lead to unauthorized
access to AWS services, data exfiltration, and long-term persistence in the environment.
data_source:
- ASL AWS CloudTrail
search: '`amazon_security_lake` api.operation=CreateAccessKey | fillnull | stats count min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region | rename actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent as user_agent | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` |`asl_aws_create_access_key_filter`'
how_to_implement: The detection is based on Amazon Security Lake events from Amazon Web Services (AWS), which is a centralized data lake that provides security-related data from AWS services. To use this detection, you must ingest CloudTrail logs from Amazon Security Lake into Splunk. To run this search, ensure that you ingest events using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876) or the Federated Analytics App.
known_false_positives: While this search has no known false positives, it is possible that an AWS admin has legitimately created keys for another user.
search: '`amazon_security_lake` api.operation=CreateAccessKey | fillnull | stats count
min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid
http_request.user_agent src_endpoint.ip cloud.region | rename actor.user.uid as
user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent
as user_agent | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
|`asl_aws_create_access_key_filter`'
how_to_implement: The detection is based on Amazon Security Lake events from Amazon
Web Services (AWS), which is a centralized data lake that provides security-related
data from AWS services. To use this detection, you must ingest CloudTrail logs from
Amazon Security Lake into Splunk. To run this search, ensure that you ingest events
using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876)
or the Federated Analytics App.
known_false_positives: While this search has no known false positives, it is possible
that an AWS admin has legitimately created keys for another user.
references:
- https://bishopfox.com/blog/privilege-escalation-in-aws
- https://rhinosecuritylabs.com/aws/aws-privilege-escalation-methods-mitigation-part-2/
@@ -20,7 +37,6 @@ tags:
asset_type: AWS Account
mitre_attack_id:
- T1136.003
- T1136
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -29,6 +45,7 @@ tags:
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078/aws_createaccesskey/asl_ocsf_cloudtrail.json
- data:
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078/aws_createaccesskey/asl_ocsf_cloudtrail.json
sourcetype: aws:asl
source: aws_asl
@@ -1,16 +1,36 @@
name: ASL AWS Create Policy Version to allow all resources
id: 22cc7a62-3884-48c4-82da-592b8199b72f
version: 1
date: '2024-12-12'
version: 2
date: '2025-02-10'
author: Patrick Bareiss, Splunk
status: production
type: TTP
description: The following analytic identifies the creation of a new AWS IAM policy version that allows access to all resources. It detects this activity by analyzing AWS CloudTrail logs for the CreatePolicyVersion event with a policy document that grants broad permissions. This behavior is significant because it violates the principle of least privilege, potentially exposing the environment to misuse or abuse. If confirmed malicious, an attacker could gain extensive access to AWS resources, leading to unauthorized actions, data exfiltration, or further compromise of the AWS environment.
data_source:
description: The following analytic identifies the creation of a new AWS IAM policy
version that allows access to all resources. It detects this activity by analyzing
AWS CloudTrail logs for the CreatePolicyVersion event with a policy document that
grants broad permissions. This behavior is significant because it violates the principle
of least privilege, potentially exposing the environment to misuse or abuse. If
confirmed malicious, an attacker could gain extensive access to AWS resources, leading
to unauthorized actions, data exfiltration, or further compromise of the AWS environment.
data_source:
- ASL AWS CloudTrail
search: '`amazon_security_lake` api.operation=CreatePolicy | spath input=api.request.data | spath input=policyDocument | regex Statement{}.Action="\*" | regex Statement{}.Resource="\*" | fillnull | stats count min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region api.request.data | rename actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent as user_agent | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`|`asl_aws_create_policy_version_to_allow_all_resources_filter`'
how_to_implement: The detection is based on Amazon Security Lake events from Amazon Web Services (AWS), which is a centralized data lake that provides security-related data from AWS services. To use this detection, you must ingest CloudTrail logs from Amazon Security Lake into Splunk. To run this search, ensure that you ingest events using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876) or the Federated Analytics App.
known_false_positives: While this search has no known false positives, it is possible that an AWS admin has legitimately created a policy to allow a user to access all resources. That said, AWS strongly advises against granting full control to all AWS resources and you must verify this activity.
search: '`amazon_security_lake` api.operation=CreatePolicy | spath input=api.request.data
| spath input=policyDocument | regex Statement{}.Action="\*" | regex Statement{}.Resource="\*"
| fillnull | stats count min(_time) as firstTime max(_time) as lastTime by api.operation
actor.user.uid actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region
api.request.data | rename actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region
as region, http_request.user_agent as user_agent | `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`|`asl_aws_create_policy_version_to_allow_all_resources_filter`'
how_to_implement: The detection is based on Amazon Security Lake events from Amazon
Web Services (AWS), which is a centralized data lake that provides security-related
data from AWS services. To use this detection, you must ingest CloudTrail logs from
Amazon Security Lake into Splunk. To run this search, ensure that you ingest events
using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876)
or the Federated Analytics App.
known_false_positives: While this search has no known false positives, it is possible
that an AWS admin has legitimately created a policy to allow a user to access all
resources. That said, AWS strongly advises against granting full control to all
AWS resources and you must verify this activity.
references:
- https://bishopfox.com/blog/privilege-escalation-in-aws
- https://rhinosecuritylabs.com/aws/aws-privilege-escalation-methods-mitigation-part-2/
@@ -20,11 +40,17 @@ drilldown_searches:
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
- name: View risk events for the last 7 days for - "$user$"
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$")
starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime
values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories)
as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic)
as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`'
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
rba:
message: User $user$ created a policy version that allows them to access any resource in their account
message: User $user$ created a policy version that allows them to access any resource
in their account
risk_objects:
- field: user
type: user
@@ -36,7 +62,6 @@ tags:
asset_type: AWS Account
mitre_attack_id:
- T1078.004
- T1078
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -45,6 +70,7 @@ tags:
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078/aws_create_policy_version/asl_ocsf_cloudtrail.json
- data:
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078/aws_create_policy_version/asl_ocsf_cloudtrail.json
sourcetype: aws:asl
source: aws_asl
@@ -1,16 +1,34 @@
name: ASL AWS Credential Access GetPasswordData
id: a79b607a-50cc-4704-bb9d-eff280cb78c2
version: 1
date: '2024-12-12'
version: 2
date: '2025-02-10'
author: Patrick Bareiss, Splunk
status: production
type: Anomaly
description: The following analytic identifiesGetPasswordData API calls in your AWS account. It leverages CloudTrail logs from Amazon Security Lake to detect this activity by counting the distinct instance IDs accessed. This behavior is significant as it may indicate an attempt to retrieve encrypted administrator passwords for running Windows instances, which is a critical security concern. If confirmed malicious, attackers could gain unauthorized access to administrative credentials, potentially leading to full control over the affected instances and further compromise of the AWS environment.
data_source:
description: The following analytic identifiesGetPasswordData API calls in your AWS
account. It leverages CloudTrail logs from Amazon Security Lake to detect this
activity by counting the distinct instance IDs accessed. This behavior is significant
as it may indicate an attempt to retrieve encrypted administrator passwords for
running Windows instances, which is a critical security concern. If confirmed malicious,
attackers could gain unauthorized access to administrative credentials, potentially
leading to full control over the affected instances and further compromise of the
AWS environment.
data_source:
- ASL AWS CloudTrail
search: '`amazon_security_lake` api.operation=GetPasswordData | spath input=api.request.data | fillnull | stats count min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region instanceId | rename actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent as user_agent | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` |`asl_aws_credential_access_getpassworddata_filter`'
how_to_implement: The detection is based on Amazon Security Lake events from Amazon Web Services (AWS), which is a centralized data lake that provides security-related data from AWS services. To use this detection, you must ingest CloudTrail logs from Amazon Security Lake into Splunk. To run this search, ensure that you ingest events using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876) or the Federated Analytics App.
known_false_positives: Administrator tooling or automated scripts may make these calls but it is highly unlikely to make several calls in a short period of time.
search: '`amazon_security_lake` api.operation=GetPasswordData | spath input=api.request.data
| fillnull | stats count min(_time) as firstTime max(_time) as lastTime by api.operation
actor.user.uid actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region
instanceId | rename actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region
as region, http_request.user_agent as user_agent | `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)` |`asl_aws_credential_access_getpassworddata_filter`'
how_to_implement: The detection is based on Amazon Security Lake events from Amazon
Web Services (AWS), which is a centralized data lake that provides security-related
data from AWS services. To use this detection, you must ingest CloudTrail logs from
Amazon Security Lake into Splunk. To run this search, ensure that you ingest events
using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876)
or the Federated Analytics App.
known_false_positives: Administrator tooling or automated scripts may make these calls
but it is highly unlikely to make several calls in a short period of time.
references:
- https://attack.mitre.org/techniques/T1552/
- https://stratus-red-team.cloud/attack-techniques/AWS/aws.credential-access.ec2-get-password-data/
@@ -20,7 +38,12 @@ drilldown_searches:
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
- name: View risk events for the last 7 days for - "$user$"
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$")
starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime
values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories)
as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic)
as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`'
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
rba:
@@ -37,10 +60,8 @@ tags:
- AWS Identity and Access Management Account Takeover
asset_type: AWS Account
mitre_attack_id:
- T1586
- T1586.003
- T1110
- T1110.001
- T1586.003
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -49,6 +70,7 @@ tags:
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1552/aws_getpassworddata/asl_ocsf_cloudtrail.json
- data:
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1552/aws_getpassworddata/asl_ocsf_cloudtrail.json
sourcetype: aws:asl
source: aws_asl
@@ -1,15 +1,34 @@
name: ASL AWS Credential Access RDS Password reset
id: d15e9bd9-ef64-4d84-bc04-f62955a9fee8
version: 1
date: '2024-12-12'
version: 2
date: '2025-02-10'
author: Patrick Bareiss, Splunk
status: production
type: TTP
description: The following analytic detects the resetting of the master user password for an Amazon RDS DB instance. It leverages AWS CloudTrail logs from Amazon Security Lake to identify events where the `ModifyDBInstance` API call includes a new `masterUserPassword` parameter. This activity is significant because unauthorized password resets can grant attackers access to sensitive data stored in production databases, such as credit card information, PII, and healthcare data. If confirmed malicious, this could lead to data breaches, regulatory non-compliance, and significant reputational damage. Immediate investigation is required to determine the legitimacy of the password reset.
data_source:
description: The following analytic detects the resetting of the master user password
for an Amazon RDS DB instance. It leverages AWS CloudTrail logs from Amazon Security
Lake to identify events where the `ModifyDBInstance` API call includes a new `masterUserPassword`
parameter. This activity is significant because unauthorized password resets can
grant attackers access to sensitive data stored in production databases, such as
credit card information, PII, and healthcare data. If confirmed malicious, this
could lead to data breaches, regulatory non-compliance, and significant reputational
damage. Immediate investigation is required to determine the legitimacy of the password
reset.
data_source:
- ASL AWS CloudTrail
search: '`amazon_security_lake` api.operation=ModifyDBInstance OR api.operation=ModifyDBCluster | spath input=api.request.data | search masterUserPassword=* | fillnull | stats count min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region api.request.data | rename actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent as user_agent | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` |`asl_aws_credential_access_rds_password_reset_filter`'
how_to_implement: The detection is based on Amazon Security Lake events from Amazon Web Services (AWS), which is a centralized data lake that provides security-related data from AWS services. To use this detection, you must ingest CloudTrail logs from Amazon Security Lake into Splunk. To run this search, ensure that you ingest events using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876) or the Federated Analytics App.
search: '`amazon_security_lake` api.operation=ModifyDBInstance OR api.operation=ModifyDBCluster
| spath input=api.request.data | search masterUserPassword=* | fillnull | stats
count min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid
actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region api.request.data
| rename actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region as region,
http_request.user_agent as user_agent | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
|`asl_aws_credential_access_rds_password_reset_filter`'
how_to_implement: The detection is based on Amazon Security Lake events from Amazon
Web Services (AWS), which is a centralized data lake that provides security-related
data from AWS services. To use this detection, you must ingest CloudTrail logs from
Amazon Security Lake into Splunk. To run this search, ensure that you ingest events
using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876)
or the Federated Analytics App.
known_false_positives: Users may genuinely reset the RDS password.
references:
- https://aws.amazon.com/premiumsupport/knowledge-center/reset-master-user-password-rds
@@ -19,7 +38,12 @@ drilldown_searches:
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
- name: View risk events for the last 7 days for - "$user$"
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$")
starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime
values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories)
as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic)
as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`'
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
rba:
@@ -36,9 +60,8 @@ tags:
- AWS Identity and Access Management Account Takeover
asset_type: AWS Account
mitre_attack_id:
- T1586
- T1586.003
- T1110
- T1586.003
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -47,6 +70,7 @@ tags:
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.002/aws_rds_password_reset/asl_ocsf_cloudtrail.json
- data:
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.002/aws_rds_password_reset/asl_ocsf_cloudtrail.json
sourcetype: aws:asl
source: aws_asl
@@ -1,16 +1,33 @@
name: ASL AWS Defense Evasion Delete Cloudtrail
id: 1f0b47e5-0134-43eb-851c-e3258638945e
version: 6
date: '2024-11-14'
version: 7
date: '2025-02-10'
author: Patrick Bareiss, Splunk
status: production
type: TTP
description: The following analytic detects AWS `DeleteTrail` events within CloudTrail logs. It leverages Amazon Security Lake logs parsed in the Open Cybersecurity Schema Framework (OCSF) format to identify when a CloudTrail is deleted. This activity is significant because adversaries may delete CloudTrail logs to evade detection and operate with stealth. If confirmed malicious, this action could allow attackers to cover their tracks, making it difficult to trace their activities and investigate other potential compromises within the AWS environment.
data_source:
description: The following analytic detects AWS `DeleteTrail` events within CloudTrail
logs. It leverages Amazon Security Lake logs parsed in the Open Cybersecurity Schema
Framework (OCSF) format to identify when a CloudTrail is deleted. This activity
is significant because adversaries may delete CloudTrail logs to evade detection
and operate with stealth. If confirmed malicious, this action could allow attackers
to cover their tracks, making it difficult to trace their activities and investigate
other potential compromises within the AWS environment.
data_source:
- ASL AWS CloudTrail
search: '`amazon_security_lake` api.operation=DeleteTrail | fillnull | stats count min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region | rename actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent as user_agent | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)`| `asl_aws_defense_evasion_delete_cloudtrail_filter`'
how_to_implement: The detection is based on Amazon Security Lake events from Amazon Web Services (AWS), which is a centralized data lake that provides security-related data from AWS services. To use this detection, you must ingest CloudTrail logs from Amazon Security Lake into Splunk. To run this search, ensure that you ingest events using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876) or the Federated Analytics App.
known_false_positives: While this search has no known false positives, it is possible that an AWS admin has stopped cloudTrail logging. Please investigate this activity.
search: '`amazon_security_lake` api.operation=DeleteTrail | fillnull | stats count
min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid
http_request.user_agent src_endpoint.ip cloud.region | rename actor.user.uid as
user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent
as user_agent | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)`|
`asl_aws_defense_evasion_delete_cloudtrail_filter`'
how_to_implement: The detection is based on Amazon Security Lake events from Amazon
Web Services (AWS), which is a centralized data lake that provides security-related
data from AWS services. To use this detection, you must ingest CloudTrail logs from
Amazon Security Lake into Splunk. To run this search, ensure that you ingest events
using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876)
or the Federated Analytics App.
known_false_positives: While this search has no known false positives, it is possible
that an AWS admin has stopped cloudTrail logging. Please investigate this activity.
references:
- https://attack.mitre.org/techniques/T1562/008/
drilldown_searches:
@@ -42,7 +59,6 @@ tags:
asset_type: AWS Account
mitre_attack_id:
- T1562.008
- T1562
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -51,6 +67,7 @@ tags:
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.008/stop_delete_cloudtrail/asl_ocsf_cloudtrail.json
- data:
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.008/stop_delete_cloudtrail/asl_ocsf_cloudtrail.json
sourcetype: aws:asl
source: aws_asl
@@ -1,16 +1,34 @@
name: ASL AWS Defense Evasion Delete CloudWatch Log Group
id: 0f701b38-a0fb-43fd-a83d-d12265f71f33
version: 5
date: '2024-11-14'
version: 6
date: '2025-02-10'
author: Patrick Bareiss, Splunk
status: production
type: TTP
description: The following analytic detects the deletion of CloudWatch log groups in AWS, identified through `DeleteLogGroup` events in CloudTrail logs. This method leverages Amazon Security Lake logs parsed in the OCSF format. The activity is significant because attackers may delete log groups to evade detection and disrupt logging capabilities, hindering incident response efforts. If confirmed malicious, this action could allow attackers to cover their tracks, making it difficult to trace their activities and potentially leading to undetected data breaches or further malicious actions within the compromised AWS environment.
data_source:
description: The following analytic detects the deletion of CloudWatch log groups
in AWS, identified through `DeleteLogGroup` events in CloudTrail logs. This method
leverages Amazon Security Lake logs parsed in the OCSF format. The activity is significant
because attackers may delete log groups to evade detection and disrupt logging capabilities,
hindering incident response efforts. If confirmed malicious, this action could allow
attackers to cover their tracks, making it difficult to trace their activities and
potentially leading to undetected data breaches or further malicious actions within
the compromised AWS environment.
data_source:
- ASL AWS CloudTrail
search: '`amazon_security_lake` api.operation=DeleteLogGroup | fillnull | stats count min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region | rename actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent as user_agent | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)`| `asl_aws_defense_evasion_delete_cloudwatch_log_group_filter`'
how_to_implement: The detection is based on Amazon Security Lake events from Amazon Web Services (AWS), which is a centralized data lake that provides security-related data from AWS services. To use this detection, you must ingest CloudTrail logs from Amazon Security Lake into Splunk. To run this search, ensure that you ingest events using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876) or the Federated Analytics App.
known_false_positives: While this search has no known false positives, it is possible that an AWS admin has deleted CloudWatch logging. Please investigate this activity.
search: '`amazon_security_lake` api.operation=DeleteLogGroup | fillnull | stats count
min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid
http_request.user_agent src_endpoint.ip cloud.region | rename actor.user.uid as
user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent
as user_agent | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)`|
`asl_aws_defense_evasion_delete_cloudwatch_log_group_filter`'
how_to_implement: The detection is based on Amazon Security Lake events from Amazon
Web Services (AWS), which is a centralized data lake that provides security-related
data from AWS services. To use this detection, you must ingest CloudTrail logs from
Amazon Security Lake into Splunk. To run this search, ensure that you ingest events
using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876)
or the Federated Analytics App.
known_false_positives: While this search has no known false positives, it is possible
that an AWS admin has deleted CloudWatch logging. Please investigate this activity.
references:
- https://attack.mitre.org/techniques/T1562/008/
drilldown_searches:
@@ -41,7 +59,6 @@ tags:
- AWS Defense Evasion
asset_type: AWS Account
mitre_attack_id:
- T1562
- T1562.008
product:
- Splunk Enterprise
@@ -1,16 +1,35 @@
name: ASL AWS Defense Evasion Impair Security Services
id: 5029b681-0462-47b7-82e7-f7e3d37f5a2d
version: 5
date: '2024-11-14'
version: 6
date: '2025-02-10'
author: Patrick Bareiss, Bhavin Patel, Gowthamaraj Rajendran, Splunk
status: production
type: Hunting
description: The following analytic detects the deletion of critical AWS Security Services configurations, such as CloudWatch alarms, GuardDuty detectors, and Web Application Firewall rules. It leverages Amazon Security Lake logs to identify specific API calls like "DeleteLogStream" and "DeleteDetector." This activity is significant because adversaries often use these actions to disable security monitoring and evade detection. If confirmed malicious, this could allow attackers to operate undetected, leading to potential data breaches, unauthorized access, and prolonged persistence within the AWS environment.
data_source:
description: The following analytic detects the deletion of critical AWS Security
Services configurations, such as CloudWatch alarms, GuardDuty detectors, and Web
Application Firewall rules. It leverages Amazon Security Lake logs to identify specific
API calls like "DeleteLogStream" and "DeleteDetector." This activity is significant
because adversaries often use these actions to disable security monitoring and evade
detection. If confirmed malicious, this could allow attackers to operate undetected,
leading to potential data breaches, unauthorized access, and prolonged persistence
within the AWS environment.
data_source:
- ASL AWS CloudTrail
search: '`amazon_security_lake` api.operation IN ("DeleteLogStream","DeleteDetector","DeleteIPSet","DeleteWebACL","DeleteRule","DeleteRuleGroup","DeleteLoggingConfiguration","DeleteAlarms") | fillnull | stats count min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region | rename actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent as user_agent, actor.user.account_uid as aws_account_id | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `asl_aws_defense_evasion_impair_security_services_filter`'
how_to_implement: The detection is based on Amazon Security Lake events from Amazon Web Services (AWS), which is a centralized data lake that provides security-related data from AWS services. To use this detection, you must ingest CloudTrail logs from Amazon Security Lake into Splunk. To run this search, ensure that you ingest events using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876) or the Federated Analytics App.
known_false_positives: While this search has no known false positives, it is possible that it is a legitimate admin activity. Please consider filtering out these noisy events using userAgent, user_arn field names.
search: '`amazon_security_lake` api.operation IN ("DeleteLogStream","DeleteDetector","DeleteIPSet","DeleteWebACL","DeleteRule","DeleteRuleGroup","DeleteLoggingConfiguration","DeleteAlarms")
| fillnull | stats count min(_time) as firstTime max(_time) as lastTime by api.operation
actor.user.uid actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region
| rename actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region as region,
http_request.user_agent as user_agent, actor.user.account_uid as aws_account_id
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `asl_aws_defense_evasion_impair_security_services_filter`'
how_to_implement: The detection is based on Amazon Security Lake events from Amazon
Web Services (AWS), which is a centralized data lake that provides security-related
data from AWS services. To use this detection, you must ingest CloudTrail logs from
Amazon Security Lake into Splunk. To run this search, ensure that you ingest events
using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876)
or the Federated Analytics App.
known_false_positives: While this search has no known false positives, it is possible
that it is a legitimate admin activity. Please consider filtering out these noisy
events using userAgent, user_arn field names.
references:
- https://docs.aws.amazon.com/cli/latest/reference/guardduty/index.html
- https://docs.aws.amazon.com/cli/latest/reference/waf/index.html
@@ -21,7 +40,6 @@ tags:
asset_type: AWS Account
mitre_attack_id:
- T1562.008
- T1562
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -30,6 +48,7 @@ tags:
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.008/aws_delete_security_services/asl_ocsf_cloudtrail.json
- data:
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.008/aws_delete_security_services/asl_ocsf_cloudtrail.json
sourcetype: aws:asl
source: aws_asl
@@ -1,16 +1,36 @@
name: ASL AWS Defense Evasion PutBucketLifecycle
id: 986565a2-7707-48ea-9590-37929cebc938
version: 1
date: '2024-12-16'
version: 2
date: '2025-02-10'
author: Patrick Bareiss, Splunk
status: production
type: Hunting
description: The following analytic detects `PutBucketLifecycle` events in AWS CloudTrail logs where a user sets a lifecycle rule for an S3 bucket with an expiration period of fewer than three days. This detection leverages CloudTrail logs to identify suspicious lifecycle configurations. This activity is significant because attackers may use it to delete CloudTrail logs quickly, thereby evading detection and impairing forensic investigations. If confirmed malicious, this could allow attackers to cover their tracks, making it difficult to trace their actions and respond to the breach effectively.
description: The following analytic detects `PutBucketLifecycle` events in AWS CloudTrail
logs where a user sets a lifecycle rule for an S3 bucket with an expiration period
of fewer than three days. This detection leverages CloudTrail logs to identify suspicious
lifecycle configurations. This activity is significant because attackers may use
it to delete CloudTrail logs quickly, thereby evading detection and impairing forensic
investigations. If confirmed malicious, this could allow attackers to cover their
tracks, making it difficult to trace their actions and respond to the breach effectively.
data_source:
- ASL AWS CloudTrail
search: '`amazon_security_lake` api.operation=PutBucketLifecycle | spath input=api.request.data path=LifecycleConfiguration.Rule.NoncurrentVersionExpiration.NoncurrentDays output=NoncurrentDays | where NoncurrentDays < 3 | spath input=api.request.data | fillnull | stats count min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region NoncurrentDays bucketName | rename actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent as user_agent | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `asl_aws_defense_evasion_putbucketlifecycle_filter`'
how_to_implement: The detection is based on Amazon Security Lake events from Amazon Web Services (AWS), which is a centralized data lake that provides security-related data from AWS services. To use this detection, you must ingest CloudTrail logs from Amazon Security Lake into Splunk. To run this search, ensure that you ingest events using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876) or the Federated Analytics App.
known_false_positives: While this search has no known false positives, it is possible that it is a legitimate admin activity. Please consider filtering out these noisy events using userAgent, user_arn field names.
search: '`amazon_security_lake` api.operation=PutBucketLifecycle | spath input=api.request.data
path=LifecycleConfiguration.Rule.NoncurrentVersionExpiration.NoncurrentDays output=NoncurrentDays
| where NoncurrentDays < 3 | spath input=api.request.data | fillnull | stats count
min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid
http_request.user_agent src_endpoint.ip cloud.region NoncurrentDays bucketName |
rename actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region as region,
http_request.user_agent as user_agent | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
| `asl_aws_defense_evasion_putbucketlifecycle_filter`'
how_to_implement: The detection is based on Amazon Security Lake events from Amazon
Web Services (AWS), which is a centralized data lake that provides security-related
data from AWS services. To use this detection, you must ingest CloudTrail logs from
Amazon Security Lake into Splunk. To run this search, ensure that you ingest events
using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876)
or the Federated Analytics App.
known_false_positives: While this search has no known false positives, it is possible
that it is a legitimate admin activity. Please consider filtering out these noisy
events using userAgent, user_arn field names.
references:
- https://stratus-red-team.cloud/attack-techniques/AWS/aws.defense-evasion.cloudtrail-lifecycle-rule/
tags:
@@ -18,10 +38,8 @@ tags:
- AWS Defense Evasion
asset_type: AWS Account
mitre_attack_id:
- T1562.008
- T1562
- T1485.001
- T1485
- T1562.008
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -30,6 +48,7 @@ tags:
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.008/put_bucketlifecycle/asl_ocsf_cloudtrail.json
- data:
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.008/put_bucketlifecycle/asl_ocsf_cloudtrail.json
sourcetype: aws:asl
source: aws_asl
@@ -1,17 +1,36 @@
name: ASL AWS Defense Evasion Stop Logging Cloudtrail
id: 0b78a8f9-1d31-4d23-85c8-56ad13d5b4c1
version: 4
date: '2024-11-14'
version: 5
date: '2025-02-10'
author: Patrick Bareiss, Splunk
status: production
type: TTP
description: The following analytic detects `StopLogging` events within AWS CloudTrail logs, a critical action that adversaries may use to evade detection. By halting the logging of their malicious activities, attackers aim to operate undetected within a compromised AWS environment. This detection is achieved by monitoring for specific CloudTrail log entries that indicate the cessation of logging activities. Identifying such behavior is crucial for a Security Operations Center (SOC), as it signals an attempt to undermine the integrity of logging mechanisms, potentially allowing malicious activities to proceed without observation. The impact of this evasion tactic is significant, as it can severely hamper incident response and forensic investigations by obscuring the attacker's actions.
data_source:
description: The following analytic detects `StopLogging` events within AWS CloudTrail
logs, a critical action that adversaries may use to evade detection. By halting
the logging of their malicious activities, attackers aim to operate undetected within
a compromised AWS environment. This detection is achieved by monitoring for specific
CloudTrail log entries that indicate the cessation of logging activities. Identifying
such behavior is crucial for a Security Operations Center (SOC), as it signals an
attempt to undermine the integrity of logging mechanisms, potentially allowing malicious
activities to proceed without observation. The impact of this evasion tactic is
significant, as it can severely hamper incident response and forensic investigations
by obscuring the attacker's actions.
data_source:
- ASL AWS CloudTrail
search: '`amazon_security_lake` api.operation=StopLogging | fillnull | stats count min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region | rename actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent as user_agent, actor.user.account.uid
as aws_account_id | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `asl_aws_defense_evasion_stop_logging_cloudtrail_filter`'
how_to_implement: The detection is based on Amazon Security Lake events from Amazon Web Services (AWS), which is a centralized data lake that provides security-related data from AWS services. To use this detection, you must ingest CloudTrail logs from Amazon Security Lake into Splunk. To run this search, ensure that you ingest events using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876) or the Federated Analytics App.
known_false_positives: While this search has no known false positives, it is possible that an AWS admin has stopped cloudtrail logging. Please investigate this activity.
search: '`amazon_security_lake` api.operation=StopLogging | fillnull | stats count
min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid
http_request.user_agent src_endpoint.ip cloud.region | rename actor.user.uid as
user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent
as user_agent, actor.user.account.uid as aws_account_id | `security_content_ctime(firstTime)`|
`security_content_ctime(lastTime)` | `asl_aws_defense_evasion_stop_logging_cloudtrail_filter`'
how_to_implement: The detection is based on Amazon Security Lake events from Amazon
Web Services (AWS), which is a centralized data lake that provides security-related
data from AWS services. To use this detection, you must ingest CloudTrail logs from
Amazon Security Lake into Splunk. To run this search, ensure that you ingest events
using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876)
or the Federated Analytics App.
known_false_positives: While this search has no known false positives, it is possible
that an AWS admin has stopped cloudtrail logging. Please investigate this activity.
references:
- https://attack.mitre.org/techniques/T1562/008/
drilldown_searches:
@@ -44,7 +63,6 @@ tags:
asset_type: AWS Account
mitre_attack_id:
- T1562.008
- T1562
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -53,6 +71,7 @@ tags:
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.008/stop_delete_cloudtrail/asl_ocsf_cloudtrail_2.json
- data:
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.008/stop_delete_cloudtrail/asl_ocsf_cloudtrail_2.json
sourcetype: aws:asl
source: aws_asl
@@ -1,16 +1,35 @@
name: ASL AWS Defense Evasion Update Cloudtrail
id: f3eb471c-16d0-404d-897c-7653f0a78cba
version: 4
date: '2024-11-14'
version: 5
date: '2025-02-10'
author: Patrick Bareiss, Splunk
status: production
type: TTP
description: The following analytic detects `UpdateTrail` events within AWS CloudTrail logs, aiming to identify attempts by attackers to evade detection by altering logging configurations. By updating CloudTrail settings with incorrect parameters, such as changing multi-regional logging to a single region, attackers can impair the logging of their activities across other regions. This behavior is crucial for Security Operations Centers (SOCs) to identify, as it indicates an adversary's intent to operate undetected within a compromised AWS environment. The impact of such evasion tactics is significant, potentially allowing malicious activities to proceed without being logged, thereby hindering incident response and forensic investigations.
data_source:
description: The following analytic detects `UpdateTrail` events within AWS CloudTrail
logs, aiming to identify attempts by attackers to evade detection by altering logging
configurations. By updating CloudTrail settings with incorrect parameters, such
as changing multi-regional logging to a single region, attackers can impair the
logging of their activities across other regions. This behavior is crucial for Security
Operations Centers (SOCs) to identify, as it indicates an adversary's intent to
operate undetected within a compromised AWS environment. The impact of such evasion
tactics is significant, potentially allowing malicious activities to proceed without
being logged, thereby hindering incident response and forensic investigations.
data_source:
- ASL AWS CloudTrail
search: '`amazon_security_lake` api.operation=UpdateTrail | fillnull | stats count min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region | rename actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent as user_agent, actor.user.account.uid as aws_account_id | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `asl_aws_defense_evasion_update_cloudtrail_filter`'
how_to_implement: The detection is based on Amazon Security Lake events from Amazon Web Services (AWS), which is a centralized data lake that provides security-related data from AWS services. To use this detection, you must ingest CloudTrail logs from Amazon Security Lake into Splunk. To run this search, ensure that you ingest events using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876) or the Federated Analytics App.
known_false_positives: While this search has no known false positives, it is possible that an AWS admin has updated cloudtrail logging. Please investigate this activity.
search: '`amazon_security_lake` api.operation=UpdateTrail | fillnull | stats count
min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid
http_request.user_agent src_endpoint.ip cloud.region | rename actor.user.uid as
user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent
as user_agent, actor.user.account.uid as aws_account_id | `security_content_ctime(firstTime)`|
`security_content_ctime(lastTime)` | `asl_aws_defense_evasion_update_cloudtrail_filter`'
how_to_implement: The detection is based on Amazon Security Lake events from Amazon
Web Services (AWS), which is a centralized data lake that provides security-related
data from AWS services. To use this detection, you must ingest CloudTrail logs from
Amazon Security Lake into Splunk. To run this search, ensure that you ingest events
using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876)
or the Federated Analytics App.
known_false_positives: While this search has no known false positives, it is possible
that an AWS admin has updated cloudtrail logging. Please investigate this activity.
references:
- https://attack.mitre.org/techniques/T1562/008/
drilldown_searches:
@@ -42,7 +61,6 @@ tags:
- AWS Defense Evasion
asset_type: AWS Account
mitre_attack_id:
- T1562
- T1562.008
product:
- Splunk Enterprise
@@ -52,6 +70,7 @@ tags:
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.008/update_cloudtrail/asl_ocsf_cloudtrail.json
- data:
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.008/update_cloudtrail/asl_ocsf_cloudtrail.json
sourcetype: aws:asl
source: aws_asl
@@ -1,16 +1,35 @@
name: ASL AWS ECR Container Upload Outside Business Hours
id: 739ed682-27e9-4ba0-80e5-a91b97698213
version: 5
date: '2024-11-14'
version: 6
date: '2025-02-10'
author: Patrick Bareiss, Splunk
status: production
type: Anomaly
description: The following analytic detects the upload of new containers to AWS Elastic Container Service (ECR) outside of standard business hours through AWS CloudTrail events. It identifies this behavior by monitoring for `PutImage` events occurring before 8 AM or after 8 PM, as well as any uploads on weekends. This activity is significant for a SOC to investigate as it may indicate unauthorized access or malicious deployments, potentially leading to compromised services or data breaches. Identifying and addressing such uploads promptly can mitigate the risk of security incidents and their associated impacts.
data_source:
description: The following analytic detects the upload of new containers to AWS Elastic
Container Service (ECR) outside of standard business hours through AWS CloudTrail
events. It identifies this behavior by monitoring for `PutImage` events occurring
before 8 AM or after 8 PM, as well as any uploads on weekends. This activity is
significant for a SOC to investigate as it may indicate unauthorized access or malicious
deployments, potentially leading to compromised services or data breaches. Identifying
and addressing such uploads promptly can mitigate the risk of security incidents
and their associated impacts.
data_source:
- ASL AWS CloudTrail
search: '`amazon_security_lake` api.operation=PutImage | eval hour=strftime(time/pow(10,3), "%H"), weekday=strftime(time/pow(10,3), "%A") | where hour >= 20 OR hour < 8 OR weekday=Saturday OR weekday=Sunday | fillnull | stats count min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid http_request.user_agent cloud.region | rename actor.user.uid as user, cloud.region as region, http_request.user_agent as user_agent | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `asl_aws_ecr_container_upload_outside_business_hours_filter`'
how_to_implement: The detection is based on Amazon Security Lake events from Amazon Web Services (AWS), which is a centralized data lake that provides security-related data from AWS services. To use this detection, you must ingest CloudTrail logs from Amazon Security Lake into Splunk. To run this search, ensure that you ingest events using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876) or the Federated Analytics App.
known_false_positives: When your development is spreaded in different time zones, applying this rule can be difficult.
search: '`amazon_security_lake` api.operation=PutImage | eval hour=strftime(time/pow(10,3),
"%H"), weekday=strftime(time/pow(10,3), "%A") | where hour >= 20 OR hour < 8 OR
weekday=Saturday OR weekday=Sunday | fillnull | stats count min(_time) as firstTime
max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid http_request.user_agent
cloud.region | rename actor.user.uid as user, cloud.region as region, http_request.user_agent
as user_agent | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
| `asl_aws_ecr_container_upload_outside_business_hours_filter`'
how_to_implement: The detection is based on Amazon Security Lake events from Amazon
Web Services (AWS), which is a centralized data lake that provides security-related
data from AWS services. To use this detection, you must ingest CloudTrail logs from
Amazon Security Lake into Splunk. To run this search, ensure that you ingest events
using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876)
or the Federated Analytics App.
known_false_positives: When your development is spreaded in different time zones,
applying this rule can be difficult.
references:
- https://attack.mitre.org/techniques/T1204/003/
drilldown_searches:
@@ -40,16 +59,17 @@ tags:
asset_type: AWS Account
mitre_attack_id:
- T1204.003
- T1204
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
security_domain: network
manual_test: Can't be tested automatically because of outside of business hours time
manual_test: Can't be tested automatically because of outside of business hours
time
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1204.003/aws_ecr_container_upload/asl_ocsf_cloudtrail.json
- data:
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1204.003/aws_ecr_container_upload/asl_ocsf_cloudtrail.json
sourcetype: aws:asl
source: aws_asl
@@ -1,15 +1,34 @@
name: ASL AWS ECR Container Upload Unknown User
id: 886a8f46-d7e2-4439-b9ba-aec238e31732
version: 4
date: '2024-11-14'
version: 5
date: '2025-02-10'
author: Patrick Bareiss, Splunk
status: production
type: Anomaly
description: The following analytic detects unauthorized container uploads to AWS Elastic Container Service (ECR) by monitoring AWS CloudTrail events. It identifies instances where a new container is uploaded by a user not previously recognized as authorized. This detection is crucial for a SOC as it can indicate a potential compromise or misuse of AWS ECR, which could lead to unauthorized access to sensitive data or the deployment of malicious containers. By identifying and investigating these events, organizations can mitigate the risk of data breaches or other security incidents resulting from unauthorized container uploads. The impact of such an attack could be significant, compromising the integrity and security of the organization's cloud environment.
data_source:
description: The following analytic detects unauthorized container uploads to AWS
Elastic Container Service (ECR) by monitoring AWS CloudTrail events. It identifies
instances where a new container is uploaded by a user not previously recognized
as authorized. This detection is crucial for a SOC as it can indicate a potential
compromise or misuse of AWS ECR, which could lead to unauthorized access to sensitive
data or the deployment of malicious containers. By identifying and investigating
these events, organizations can mitigate the risk of data breaches or other security
incidents resulting from unauthorized container uploads. The impact of such an attack
could be significant, compromising the integrity and security of the organization's
cloud environment.
data_source:
- ASL AWS CloudTrail
search: '`amazon_security_lake` api.operation=PutImage NOT `aws_ecr_users_asl` | stats count min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region | rename actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent as user_agent | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `asl_aws_ecr_container_upload_unknown_user_filter`'
how_to_implement: The detection is based on Amazon Security Lake events from Amazon Web Services (AWS), which is a centralized data lake that provides security-related data from AWS services. To use this detection, you must ingest CloudTrail logs from Amazon Security Lake into Splunk. To run this search, ensure that you ingest events using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876) or the Federated Analytics App.
search: '`amazon_security_lake` api.operation=PutImage NOT `aws_ecr_users_asl` | stats
count min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid
actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region | rename
actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent
as user_agent | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
| `asl_aws_ecr_container_upload_unknown_user_filter`'
how_to_implement: The detection is based on Amazon Security Lake events from Amazon
Web Services (AWS), which is a centralized data lake that provides security-related
data from AWS services. To use this detection, you must ingest CloudTrail logs from
Amazon Security Lake into Splunk. To run this search, ensure that you ingest events
using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876)
or the Federated Analytics App.
known_false_positives: unknown
references:
- https://attack.mitre.org/techniques/T1204/003/
@@ -42,7 +61,6 @@ tags:
asset_type: AWS Account
mitre_attack_id:
- T1204.003
- T1204
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -51,6 +69,7 @@ tags:
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1204.003/aws_ecr_container_upload/asl_ocsf_cloudtrail.json
- data:
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1204.003/aws_ecr_container_upload/asl_ocsf_cloudtrail.json
sourcetype: aws:asl
source: aws_asl
@@ -1,16 +1,32 @@
name: ASL AWS IAM Successful Group Deletion
id: 1bbe54f1-93d7-4764-8a01-ddaa12ece7ac
version: 5
date: '2024-11-14'
version: 6
date: '2025-02-10'
author: Patrick Bareiss, Splunk
status: production
type: Hunting
description: The following analytic detects the successful deletion of a group within AWS IAM, leveraging CloudTrail IAM events. This action, while not inherently malicious, can serve as a precursor to more sinister activities, such as unauthorized access or privilege escalation attempts. By monitoring for such deletions, the analytic aids in identifying potential preparatory steps towards an attack, allowing for early detection and mitigation. The identification of this behavior is crucial for a SOC to prevent the potential impact of an attack, which could include unauthorized access to sensitive resources or disruption of AWS environment operations.
data_source:
description: The following analytic detects the successful deletion of a group within
AWS IAM, leveraging CloudTrail IAM events. This action, while not inherently malicious,
can serve as a precursor to more sinister activities, such as unauthorized access
or privilege escalation attempts. By monitoring for such deletions, the analytic
aids in identifying potential preparatory steps towards an attack, allowing for
early detection and mitigation. The identification of this behavior is crucial for
a SOC to prevent the potential impact of an attack, which could include unauthorized
access to sensitive resources or disruption of AWS environment operations.
data_source:
- ASL AWS CloudTrail
search: '`amazon_security_lake` api.operation=DeleteGroup status=Success | fillnull | stats count min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region | rename actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent as user_agent | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `asl_aws_iam_successful_group_deletion_filter`'
how_to_implement: You must install the Data Lake Federated Analytics App and ingest the logs into Splunk.
known_false_positives: This detection will require tuning to provide high fidelity detection capabilties. Tune based on src addresses (corporate offices, VPN terminations) or by groups of users. Not every user with AWS access should have permission to delete groups (least privilege).
search: '`amazon_security_lake` api.operation=DeleteGroup status=Success | fillnull
| stats count min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid
actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region | rename
actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent
as user_agent | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
| `asl_aws_iam_successful_group_deletion_filter`'
how_to_implement: You must install the Data Lake Federated Analytics App and ingest
the logs into Splunk.
known_false_positives: This detection will require tuning to provide high fidelity
detection capabilties. Tune based on src addresses (corporate offices, VPN terminations)
or by groups of users. Not every user with AWS access should have permission to
delete groups (least privilege).
references:
- https://awscli.amazonaws.com/v2/documentation/api/latest/reference/iam/delete-group.html
- https://docs.aws.amazon.com/IAM/latest/APIReference/API_DeleteGroup.html
@@ -21,7 +37,6 @@ tags:
mitre_attack_id:
- T1069.003
- T1098
- T1069
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -30,6 +45,7 @@ tags:
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1098/aws_iam_successful_group_deletion/asl_ocsf_cloudtrail.json
- data:
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1098/aws_iam_successful_group_deletion/asl_ocsf_cloudtrail.json
sourcetype: aws:asl
source: aws_asl
@@ -1,16 +1,34 @@
name: ASL AWS Multi-Factor Authentication Disabled
id: 4d2df5e0-1092-4817-88a8-79c7fa054668
version: 5
date: '2024-11-14'
version: 6
date: '2025-02-10'
author: Patrick Bareiss, Splunk
status: production
type: TTP
description: The following analytic detects attempts to disable multi-factor authentication (MFA) for an AWS IAM user. It leverages Amazon Security Lake logs, specifically monitoring for `DeleteVirtualMFADevice` or `DeactivateMFADevice` API operations. This activity is significant as disabling MFA can indicate an adversary attempting to weaken account security to maintain persistence using a compromised account. If confirmed malicious, this action could allow attackers to retain access to the AWS environment without detection, potentially leading to unauthorized access to sensitive resources and prolonged compromise.
data_source:
description: The following analytic detects attempts to disable multi-factor authentication
(MFA) for an AWS IAM user. It leverages Amazon Security Lake logs, specifically
monitoring for `DeleteVirtualMFADevice` or `DeactivateMFADevice` API operations.
This activity is significant as disabling MFA can indicate an adversary attempting
to weaken account security to maintain persistence using a compromised account.
If confirmed malicious, this action could allow attackers to retain access to the
AWS environment without detection, potentially leading to unauthorized access to
sensitive resources and prolonged compromise.
data_source:
- ASL AWS CloudTrail
search: '`amazon_security_lake` (api.operation=DeleteVirtualMFADevice OR api.operation=DeactivateMFADevice) | fillnull | stats count min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region | rename actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent as user_agent | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `asl_aws_multi_factor_authentication_disabled_filter`'
how_to_implement: The detection is based on Amazon Security Lake events from Amazon Web Services (AWS), which is a centralized data lake that provides security-related data from AWS services. To use this detection, you must ingest CloudTrail logs from Amazon Security Lake into Splunk. To run this search, ensure that you ingest events using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876) or the Federated Analytics App.
known_false_positives: AWS Administrators may disable MFA but it is highly unlikely for this event to occur without prior notice to the company
search: '`amazon_security_lake` (api.operation=DeleteVirtualMFADevice OR api.operation=DeactivateMFADevice)
| fillnull | stats count min(_time) as firstTime max(_time) as lastTime by api.operation
actor.user.uid actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region
| rename actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region as region,
http_request.user_agent as user_agent | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
| `asl_aws_multi_factor_authentication_disabled_filter`'
how_to_implement: The detection is based on Amazon Security Lake events from Amazon
Web Services (AWS), which is a centralized data lake that provides security-related
data from AWS services. To use this detection, you must ingest CloudTrail logs from
Amazon Security Lake into Splunk. To run this search, ensure that you ingest events
using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876)
or the Federated Analytics App.
known_false_positives: AWS Administrators may disable MFA but it is highly unlikely
for this event to occur without prior notice to the company
references:
- https://attack.mitre.org/techniques/T1621/
- https://aws.amazon.com/what-is/mfa/
@@ -42,11 +60,9 @@ tags:
- AWS Identity and Access Management Account Takeover
asset_type: AWS Account
mitre_attack_id:
- T1586
- T1556.006
- T1586.003
- T1621
- T1556
- T1556.006
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -55,6 +71,7 @@ tags:
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1621/aws_mfa_disabled/asl_ocsf_cloudtrail.json
- data:
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1621/aws_mfa_disabled/asl_ocsf_cloudtrail.json
sourcetype: aws:asl
source: aws_asl
@@ -1,26 +1,41 @@
name: ASL AWS Network Access Control List Created with All Open Ports
id: a2625034-c2de-44fc-b45c-7bac9c4a7974
version: 1
date: '2025-01-09'
version: 2
date: '2025-02-10'
author: Patrick Bareiss, Splunk
status: production
type: TTP
description: The following analytic detects the creation of AWS Network Access Control Lists (ACLs) with all ports open to a specified CIDR. It leverages AWS CloudTrail events, specifically monitoring for `CreateNetworkAclEntry` or `ReplaceNetworkAclEntry` actions with rules allowing all traffic. This activity is significant because it can expose the network to unauthorized access, increasing the risk of data breaches and other malicious activities. If confirmed malicious, an attacker could exploit this misconfiguration to gain unrestricted access to the network, potentially leading to data exfiltration, service disruption, or further compromise of the AWS environment.
data_source:
description: The following analytic detects the creation of AWS Network Access Control
Lists (ACLs) with all ports open to a specified CIDR. It leverages AWS CloudTrail
events, specifically monitoring for `CreateNetworkAclEntry` or `ReplaceNetworkAclEntry`
actions with rules allowing all traffic. This activity is significant because it
can expose the network to unauthorized access, increasing the risk of data breaches
and other malicious activities. If confirmed malicious, an attacker could exploit
this misconfiguration to gain unrestricted access to the network, potentially leading
to data exfiltration, service disruption, or further compromise of the AWS environment.
data_source:
- ASL AWS CloudTrail
search: '`amazon_security_lake` api.operation=CreateNetworkAclEntry OR api.operation=ReplaceNetworkAclEntry status=Success
| spath input=api.request.data path=ruleAction output=ruleAction
| spath input=api.request.data path=egress output=egress
| spath input=api.request.data path=aclProtocol output=aclProtocol
| spath input=api.request.data path=cidrBlock output=cidrBlock
| spath input=api.request.data path=networkAclId output=networkAclId
search: '`amazon_security_lake` api.operation=CreateNetworkAclEntry OR api.operation=ReplaceNetworkAclEntry
status=Success | spath input=api.request.data path=ruleAction output=ruleAction
| spath input=api.request.data path=egress output=egress | spath input=api.request.data
path=aclProtocol output=aclProtocol | spath input=api.request.data path=cidrBlock
output=cidrBlock | spath input=api.request.data path=networkAclId output=networkAclId
| search ruleAction=allow AND egress=false AND aclProtocol=-1 AND cidrBlock=0.0.0.0/0
| fillnull
| stats count min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region networkAclId cidrBlock
| rename actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent as user_agent, actor.user.account.uid as aws_account_id
| `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `asl_aws_network_access_control_list_created_with_all_open_ports_filter`'
how_to_implement: The detection is based on Amazon Security Lake events from Amazon Web Services (AWS), which is a centralized data lake that provides security-related data from AWS services. To use this detection, you must ingest CloudTrail logs from Amazon Security Lake into Splunk. To run this search, ensure that you ingest events using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876) or the Federated Analytics App.
known_false_positives: It's possible that an admin has created this ACL with all ports open for some legitimate purpose however, this should be scoped and not allowed in production environment.
| fillnull | stats count min(_time) as firstTime max(_time) as lastTime by api.operation
actor.user.uid actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region
networkAclId cidrBlock | rename actor.user.uid as user, src_endpoint.ip as src_ip,
cloud.region as region, http_request.user_agent as user_agent, actor.user.account.uid
as aws_account_id | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)`
| `asl_aws_network_access_control_list_created_with_all_open_ports_filter`'
how_to_implement: The detection is based on Amazon Security Lake events from Amazon
Web Services (AWS), which is a centralized data lake that provides security-related
data from AWS services. To use this detection, you must ingest CloudTrail logs from
Amazon Security Lake into Splunk. To run this search, ensure that you ingest events
using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876)
or the Federated Analytics App.
known_false_positives: It's possible that an admin has created this ACL with all ports
open for some legitimate purpose however, this should be scoped and not allowed
in production environment.
references: []
drilldown_searches:
- name: View the detection results for - "$user$"
@@ -28,7 +43,12 @@ drilldown_searches:
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
- name: View risk events for the last 7 days for - "$user$"
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$")
starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime
values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories)
as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic)
as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`'
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
rba:
@@ -46,7 +66,6 @@ tags:
asset_type: AWS Instance
mitre_attack_id:
- T1562.007
- T1562
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -55,6 +74,7 @@ tags:
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.007/aws_create_acl/asl_ocsf_cloudtrail.json
- data:
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.007/aws_create_acl/asl_ocsf_cloudtrail.json
sourcetype: aws:asl
source: aws_asl
@@ -1,23 +1,35 @@
name: ASL AWS Network Access Control List Deleted
id: e010ddf5-e9a5-44e5-bdd6-0c919ba8fc8b
version: 1
date: '2025-01-09'
version: 2
date: '2025-02-10'
author: Patrick Bareiss, Splunk
status: production
type: Anomaly
description: The following analytic detects the deletion of AWS Network Access Control Lists (ACLs). It leverages AWS CloudTrail logs to identify events where a user deletes a network ACL entry. This activity is significant because deleting a network ACL can remove critical access restrictions, potentially allowing unauthorized access to cloud instances. If confirmed malicious, this action could enable attackers to bypass network security controls, leading to unauthorized access, data exfiltration, or further compromise of the cloud environment.
data_source:
description: The following analytic detects the deletion of AWS Network Access Control
Lists (ACLs). It leverages AWS CloudTrail logs to identify events where a user deletes
a network ACL entry. This activity is significant because deleting a network ACL
can remove critical access restrictions, potentially allowing unauthorized access
to cloud instances. If confirmed malicious, this action could enable attackers to
bypass network security controls, leading to unauthorized access, data exfiltration,
or further compromise of the cloud environment.
data_source:
- ASL AWS CloudTrail
search: '`amazon_security_lake` api.operation=DeleteNetworkAclEntry status=Success
| spath input=api.request.data path=egress output=egress
| spath input=api.request.data path=networkAclId output=networkAclId
| search egress=false
| fillnull
| stats count min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region networkAclId
| rename actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent as user_agent, actor.user.account_uid as aws_account_id
| `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `asl_aws_network_access_control_list_deleted_filter`'
how_to_implement: The detection is based on Amazon Security Lake events from Amazon Web Services (AWS), which is a centralized data lake that provides security-related data from AWS services. To use this detection, you must ingest CloudTrail logs from Amazon Security Lake into Splunk. To run this search, ensure that you ingest events using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876) or the Federated Analytics App.
known_false_positives: It's possible that a user has legitimately deleted a network ACL.
| spath input=api.request.data path=egress output=egress | spath input=api.request.data
path=networkAclId output=networkAclId | search egress=false | fillnull | stats count
min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid
http_request.user_agent src_endpoint.ip cloud.region networkAclId | rename actor.user.uid
as user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent
as user_agent, actor.user.account_uid as aws_account_id | `security_content_ctime(firstTime)`|
`security_content_ctime(lastTime)` | `asl_aws_network_access_control_list_deleted_filter`'
how_to_implement: The detection is based on Amazon Security Lake events from Amazon
Web Services (AWS), which is a centralized data lake that provides security-related
data from AWS services. To use this detection, you must ingest CloudTrail logs from
Amazon Security Lake into Splunk. To run this search, ensure that you ingest events
using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876)
or the Federated Analytics App.
known_false_positives: It's possible that a user has legitimately deleted a network
ACL.
references: []
drilldown_searches:
- name: View the detection results for - "$user$"
@@ -25,7 +37,12 @@ drilldown_searches:
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
- name: View risk events for the last 7 days for - "$user$"
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$")
starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime
values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories)
as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic)
as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`'
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
rba:
@@ -43,7 +60,6 @@ tags:
asset_type: AWS Instance
mitre_attack_id:
- T1562.007
- T1562
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -52,6 +68,7 @@ tags:
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.007/aws_delete_acl/asl_ocsf_cloudtrail.json
- data:
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.007/aws_delete_acl/asl_ocsf_cloudtrail.json
sourcetype: aws:asl
source: aws_asl
@@ -1,16 +1,34 @@
name: ASL AWS New MFA Method Registered For User
id: 33ae0931-2a03-456b-b1d7-b016c5557fbd
version: 6
date: '2024-11-14'
version: 7
date: '2025-02-10'
author: Patrick Bareiss, Splunk
status: experimental
type: TTP
description: The following analytic identifies the registration of a new Multi-Factor Authentication (MFA) method for an AWS account, as logged through Amazon Security Lake (ASL). It detects this activity by monitoring the `CreateVirtualMFADevice` API operation within ASL logs. This behavior is significant because adversaries who gain unauthorized access to an AWS account may register a new MFA method to maintain persistence. If confirmed malicious, this activity could allow attackers to secure their access, making it harder to detect and remove their presence from the compromised environment.
data_source:
description: The following analytic identifies the registration of a new Multi-Factor
Authentication (MFA) method for an AWS account, as logged through Amazon Security
Lake (ASL). It detects this activity by monitoring the `CreateVirtualMFADevice`
API operation within ASL logs. This behavior is significant because adversaries
who gain unauthorized access to an AWS account may register a new MFA method to
maintain persistence. If confirmed malicious, this activity could allow attackers
to secure their access, making it harder to detect and remove their presence from
the compromised environment.
data_source:
- ASL AWS CloudTrail
search: '`amazon_security_lake` api.operation=CreateVirtualMFADevice | fillnull | stats count min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region | rename actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent as user_agent | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `asl_aws_new_mfa_method_registered_for_user_filter`'
how_to_implement: The detection is based on Amazon Security Lake events from Amazon Web Services (AWS), which is a centralized data lake that provides security-related data from AWS services. To use this detection, you must ingest CloudTrail logs from Amazon Security Lake into Splunk. To run this search, ensure that you ingest events using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876) or the Federated Analytics App.
known_false_positives: Newly onboarded users who are registering an MFA method for the first time will also trigger this detection.
search: '`amazon_security_lake` api.operation=CreateVirtualMFADevice | fillnull |
stats count min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid
actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region | rename
actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent
as user_agent | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
| `asl_aws_new_mfa_method_registered_for_user_filter`'
how_to_implement: The detection is based on Amazon Security Lake events from Amazon
Web Services (AWS), which is a centralized data lake that provides security-related
data from AWS services. To use this detection, you must ingest CloudTrail logs from
Amazon Security Lake into Splunk. To run this search, ensure that you ingest events
using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876)
or the Federated Analytics App.
known_false_positives: Newly onboarded users who are registering an MFA method for
the first time will also trigger this detection.
references:
- https://aws.amazon.com/blogs/security/you-can-now-assign-multiple-mfa-devices-in-iam/
- https://attack.mitre.org/techniques/T1556/
@@ -30,7 +48,6 @@ tags:
- AWS Identity and Access Management Account Takeover
asset_type: AWS Account
mitre_attack_id:
- T1556
- T1556.006
product:
- Splunk Enterprise
@@ -40,6 +57,7 @@ tags:
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1556.006/aws_new_mfa_method_registered_for_user/asl_ocsf_cloudtrail.json
- data:
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1556.006/aws_new_mfa_method_registered_for_user/asl_ocsf_cloudtrail.json
sourcetype: aws:asl
source: aws_asl
+36 -16
View File
@@ -1,20 +1,34 @@
name: ASL AWS UpdateLoginProfile
id: 5b3f63a3-865b-4637-9941-f98bd1a50c0d
version: 1
date: '2025-01-09'
version: 2
date: '2025-02-10'
author: Patrick Bareiss, Splunk
status: production
type: TTP
description: The following analytic detects an AWS CloudTrail event where a user with permissions updates the login profile of another user. It leverages CloudTrail logs to identify instances where the user making the change is different from the user whose profile is being updated. This activity is significant because it can indicate privilege escalation attempts, where an attacker uses a compromised account to gain higher privileges. If confirmed malicious, this could allow the attacker to escalate their privileges, potentially leading to unauthorized access and control over sensitive resources within the AWS environment.
data_source:
description: The following analytic detects an AWS CloudTrail event where a user with
permissions updates the login profile of another user. It leverages CloudTrail logs
to identify instances where the user making the change is different from the user
whose profile is being updated. This activity is significant because it can indicate
privilege escalation attempts, where an attacker uses a compromised account to gain
higher privileges. If confirmed malicious, this could allow the attacker to escalate
their privileges, potentially leading to unauthorized access and control over sensitive
resources within the AWS environment.
data_source:
- ASL AWS CloudTrail
search: '`amazon_security_lake` api.operation=UpdateLoginProfile
| fillnull
| stats count min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region
| rename actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent as user_agent
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `asl_aws_updateloginprofile_filter`'
how_to_implement: The detection is based on Amazon Security Lake events from Amazon Web Services (AWS), which is a centralized data lake that provides security-related data from AWS services. To use this detection, you must ingest CloudTrail logs from Amazon Security Lake into Splunk. To run this search, ensure that you ingest events using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876) or the Federated Analytics App.
known_false_positives: While this search has no known false positives, it is possible that an AWS admin has legitimately created keys for another user.
search: '`amazon_security_lake` api.operation=UpdateLoginProfile | fillnull | stats
count min(_time) as firstTime max(_time) as lastTime by api.operation actor.user.uid
actor.user.account.uid http_request.user_agent src_endpoint.ip cloud.region | rename
actor.user.uid as user, src_endpoint.ip as src_ip, cloud.region as region, http_request.user_agent
as user_agent | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
| `asl_aws_updateloginprofile_filter`'
how_to_implement: The detection is based on Amazon Security Lake events from Amazon
Web Services (AWS), which is a centralized data lake that provides security-related
data from AWS services. To use this detection, you must ingest CloudTrail logs from
Amazon Security Lake into Splunk. To run this search, ensure that you ingest events
using the latest version of Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876)
or the Federated Analytics App.
known_false_positives: While this search has no known false positives, it is possible
that an AWS admin has legitimately created keys for another user.
references:
- https://bishopfox.com/blog/privilege-escalation-in-aws
- https://rhinosecuritylabs.com/aws/aws-privilege-escalation-methods-mitigation-part-2/
@@ -24,12 +38,18 @@ drilldown_searches:
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
- name: View risk events for the last 7 days for - "$user$"
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$")
starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime
values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories)
as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic)
as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`'
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
rba:
message: User $user$ from IP address $src_ip$ updated the login profile of another user
risk_objects:
message: User $user$ from IP address $src_ip$ updated the login profile of another
user
risk_objects:
- field: user
type: user
score: 30
@@ -42,7 +62,6 @@ tags:
asset_type: AWS Account
mitre_attack_id:
- T1136.003
- T1136
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -51,6 +70,7 @@ tags:
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078/aws_updateloginprofile/asl_ocsf_cloudtrail.json
- data:
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078/aws_updateloginprofile/asl_ocsf_cloudtrail.json
sourcetype: aws:asl
source: aws_asl
@@ -1,7 +1,7 @@
name: AWS Console Login Failed During MFA Challenge
id: 55349868-5583-466f-98ab-d3beb321961e
version: 4
date: '2024-11-14'
version: 5
date: '2025-02-10'
author: Bhavin Patel, Splunk
status: production
type: TTP
@@ -57,7 +57,6 @@ tags:
- Compromised User Account
asset_type: AWS Account
mitre_attack_id:
- T1586
- T1586.003
- T1621
product:
@@ -1,7 +1,7 @@
name: AWS Create Policy Version to allow all resources
id: 2a9b80d3-6340-4345-b5ad-212bf3d0dac4
version: 7
date: '2024-11-14'
version: 8
date: '2025-02-10'
author: Bhavin Patel, Splunk
status: production
type: TTP
@@ -58,7 +58,6 @@ tags:
asset_type: AWS Account
mitre_attack_id:
- T1078.004
- T1078
product:
- Splunk Enterprise
- Splunk Enterprise Security
+2 -3
View File
@@ -1,7 +1,7 @@
name: AWS CreateAccessKey
id: 2a9b80d3-6340-4345-11ad-212bf3d0d111
version: 6
date: '2024-11-14'
version: 7
date: '2025-02-10'
author: Bhavin Patel, Splunk
status: production
type: Hunting
@@ -33,7 +33,6 @@ tags:
asset_type: AWS Account
mitre_attack_id:
- T1136.003
- T1136
product:
- Splunk Enterprise
- Splunk Enterprise Security
+2 -3
View File
@@ -1,7 +1,7 @@
name: AWS CreateLoginProfile
id: 2a9b80d3-6340-4345-11ad-212bf444d111
version: 5
date: '2024-11-14'
version: 6
date: '2025-02-10'
author: Bhavin Patel, Splunk
status: production
type: TTP
@@ -59,7 +59,6 @@ tags:
asset_type: AWS Account
mitre_attack_id:
- T1136.003
- T1136
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: AWS Credential Access Failed Login
id: a19b354d-0d7f-47f3-8ea6-1a7c36434968
version: 4
date: '2024-11-14'
version: 5
date: '2025-02-10'
author: Gowthamaraj Rajendran, Bhavin Patel, Splunk
status: production
type: TTP
@@ -54,10 +54,8 @@ tags:
- AWS Identity and Access Management Account Takeover
asset_type: AWS Account
mitre_attack_id:
- T1586
- T1586.003
- T1110
- T1110.001
- T1586.003
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: AWS Credential Access GetPasswordData
id: 4d347c4a-306e-41db-8d10-b46baf71b3e2
version: 4
date: '2024-11-14'
version: 5
date: '2025-02-10'
author: Bhavin Patel, Splunk
status: production
type: Anomaly
@@ -57,10 +57,8 @@ tags:
- AWS Identity and Access Management Account Takeover
asset_type: AWS Account
mitre_attack_id:
- T1586
- T1586.003
- T1110
- T1110.001
- T1586.003
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: AWS Credential Access RDS Password reset
id: 6153c5ea-ed30-4878-81e6-21ecdb198189
version: 5
date: '2024-11-14'
version: 6
date: '2025-02-10'
author: Gowthamaraj Rajendran, Splunk
status: production
type: TTP
@@ -52,9 +52,8 @@ tags:
- AWS Identity and Access Management Account Takeover
asset_type: AWS Account
mitre_attack_id:
- T1586
- T1586.003
- T1110
- T1586.003
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: AWS Defense Evasion Delete Cloudtrail
id: 82092925-9ca1-4e06-98b8-85a2d3889552
version: 4
date: '2024-11-14'
version: 5
date: '2025-02-10'
author: Bhavin Patel, Splunk
status: production
type: TTP
@@ -56,7 +56,6 @@ tags:
asset_type: AWS Account
mitre_attack_id:
- T1562.008
- T1562
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: AWS Defense Evasion Delete CloudWatch Log Group
id: d308b0f1-edb7-4a62-a614-af321160710f
version: 4
date: '2024-11-14'
version: 5
date: '2025-02-10'
author: Gowthamaraj Rajendran, Splunk
status: production
type: TTP
@@ -55,7 +55,6 @@ tags:
- AWS Defense Evasion
asset_type: AWS Account
mitre_attack_id:
- T1562
- T1562.008
product:
- Splunk Enterprise
@@ -1,7 +1,7 @@
name: AWS Defense Evasion Impair Security Services
id: b28c4957-96a6-47e0-a965-6c767aac1458
version: 4
date: '2024-11-14'
version: 5
date: '2025-02-10'
author: Bhavin Patel, Gowthamaraj Rajendran, Splunk
status: production
type: Hunting
@@ -42,7 +42,6 @@ tags:
asset_type: AWS Account
mitre_attack_id:
- T1562.008
- T1562
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: AWS Defense Evasion PutBucketLifecycle
id: ce1c0e2b-9303-4903-818b-0d9002fc6ea4
version: 4
date: '2024-11-14'
version: 5
date: '2025-02-10'
author: Bhavin Patel
status: production
type: Hunting
@@ -33,10 +33,8 @@ tags:
- AWS Defense Evasion
asset_type: AWS Account
mitre_attack_id:
- T1562.008
- T1562
- T1485.001
- T1485
- T1562.008
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: AWS Defense Evasion Stop Logging Cloudtrail
id: 8a2f3ca2-4eb5-4389-a549-14063882e537
version: 4
date: '2024-11-14'
version: 5
date: '2025-02-10'
author: Bhavin Patel, Splunk
status: production
type: TTP
@@ -56,7 +56,6 @@ tags:
asset_type: AWS Account
mitre_attack_id:
- T1562.008
- T1562
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: AWS Defense Evasion Update Cloudtrail
id: 7c921d28-ef48-4f1b-85b3-0af8af7697db
version: 4
date: '2024-11-14'
version: 5
date: '2025-02-10'
author: Gowthamaraj Rajendran, Splunk
status: production
type: TTP
@@ -55,7 +55,6 @@ tags:
- AWS Defense Evasion
asset_type: AWS Account
mitre_attack_id:
- T1562
- T1562.008
product:
- Splunk Enterprise
@@ -1,7 +1,7 @@
name: AWS ECR Container Scanning Findings High
id: 30a0e9f8-f1dd-4f9d-8fc2-c622461d781c
version: 5
date: '2024-11-14'
version: 6
date: '2025-02-10'
author: Patrick Bareiss, Splunk
status: production
type: TTP
@@ -57,7 +57,6 @@ tags:
asset_type: AWS Account
mitre_attack_id:
- T1204.003
- T1204
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: AWS ECR Container Scanning Findings Low Informational Unknown
id: cbc95e44-7c22-443f-88fd-0424478f5589
version: 5
date: '2024-11-14'
version: 6
date: '2025-02-10'
author: Patrick Bareiss, Eric McGinnis Splunk
status: production
type: Anomaly
@@ -57,7 +57,6 @@ tags:
asset_type: AWS Account
mitre_attack_id:
- T1204.003
- T1204
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: AWS ECR Container Scanning Findings Medium
id: 0b80e2c8-c746-4ddb-89eb-9efd892220cf
version: 5
date: '2024-11-14'
version: 6
date: '2025-02-10'
author: Patrick Bareiss, Splunk
status: production
type: Anomaly
@@ -56,7 +56,6 @@ tags:
asset_type: AWS Account
mitre_attack_id:
- T1204.003
- T1204
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: AWS ECR Container Upload Outside Business Hours
id: d4c4d4eb-3994-41ca-a25e-a82d64e125bb
version: 5
date: '2024-11-14'
version: 6
date: '2025-02-10'
author: Patrick Bareiss, Splunk
status: production
type: Anomaly
@@ -56,7 +56,6 @@ tags:
asset_type: AWS Account
mitre_attack_id:
- T1204.003
- T1204
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: AWS ECR Container Upload Unknown User
id: 300688e4-365c-4486-a065-7c884462b31d
version: 4
date: '2024-11-14'
version: 5
date: '2025-02-10'
author: Patrick Bareiss, Splunk
status: production
type: Anomaly
@@ -54,7 +54,6 @@ tags:
asset_type: AWS Account
mitre_attack_id:
- T1204.003
- T1204
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: AWS High Number Of Failed Authentications From Ip
id: f75b7f1a-b8eb-4975-a214-ff3e0a944757
version: 4
date: '2024-11-14'
version: 5
date: '2025-02-10'
author: Bhavin Patel, Splunk
status: production
type: Anomaly
@@ -55,7 +55,6 @@ tags:
- Compromised User Account
asset_type: AWS Account
mitre_attack_id:
- T1110
- T1110.003
- T1110.004
product:
@@ -1,7 +1,7 @@
name: AWS IAM Successful Group Deletion
id: e776d06c-9267-11eb-819b-acde48001122
version: 5
date: '2024-11-14'
version: 6
date: '2025-02-10'
author: Michael Haag, Splunk
status: production
type: Hunting
@@ -36,7 +36,6 @@ tags:
mitre_attack_id:
- T1069.003
- T1098
- T1069
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: AWS Multi-Factor Authentication Disabled
id: 374832b1-3603-420c-b456-b373e24d34c0
version: 4
date: '2024-11-14'
version: 5
date: '2025-02-10'
author: Bhavin Patel, Splunk
status: production
type: TTP
@@ -56,11 +56,9 @@ tags:
- AWS Identity and Access Management Account Takeover
asset_type: AWS Account
mitre_attack_id:
- T1586
- T1556.006
- T1586.003
- T1621
- T1556
- T1556.006
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: AWS Multiple Failed MFA Requests For User
id: 1fece617-e614-4329-9e61-3ba228c0f353
version: 4
date: '2024-11-14'
version: 5
date: '2025-02-10'
author: Bhavin Patel
status: production
type: Anomaly
@@ -54,7 +54,6 @@ tags:
- AWS Identity and Access Management Account Takeover
asset_type: AWS Account
mitre_attack_id:
- T1586
- T1586.003
- T1621
product:
@@ -1,7 +1,7 @@
name: AWS Multiple Users Failing To Authenticate From Ip
id: 71e1fb89-dd5f-4691-8523-575420de4630
version: 4
date: '2024-11-14'
version: 5
date: '2025-02-10'
author: Bhavin Patel
status: production
type: Anomaly
@@ -57,7 +57,6 @@ tags:
- Compromised User Account
asset_type: AWS Account
mitre_attack_id:
- T1110
- T1110.003
- T1110.004
product:
@@ -1,7 +1,7 @@
name: AWS Network Access Control List Created with All Open Ports
id: ada0f478-84a8-4641-a3f1-d82362d6bd75
version: 5
date: '2024-11-14'
version: 6
date: '2025-02-10'
author: Bhavin Patel, Patrick Bareiss, Splunk
status: production
type: TTP
@@ -63,7 +63,6 @@ tags:
asset_type: AWS Instance
mitre_attack_id:
- T1562.007
- T1562
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: AWS Network Access Control List Deleted
id: ada0f478-84a8-4641-a3f1-d82362d6fd75
version: 5
date: '2024-11-14'
version: 6
date: '2025-02-10'
author: Bhavin Patel, Patrick Bareiss, Splunk
status: production
type: Anomaly
@@ -54,7 +54,6 @@ tags:
asset_type: AWS Instance
mitre_attack_id:
- T1562.007
- T1562
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: AWS New MFA Method Registered For User
id: 4e3c26f2-4fb9-4bd7-ab46-1b76ffa2a23b
version: 5
date: '2024-11-14'
version: 6
date: '2025-02-10'
author: Bhavin Patel, Splunk
status: production
type: TTP
@@ -56,7 +56,6 @@ tags:
- AWS Identity and Access Management Account Takeover
asset_type: AWS Account
mitre_attack_id:
- T1556
- T1556.006
product:
- Splunk Enterprise
@@ -1,7 +1,7 @@
name: AWS SetDefaultPolicyVersion
id: 2a9b80d3-6340-4345-11ad-212bf3d0dac4
version: 4
date: '2024-11-14'
version: 5
date: '2025-02-10'
author: Bhavin Patel, Splunk
status: production
type: TTP
@@ -58,7 +58,6 @@ tags:
asset_type: AWS Account
mitre_attack_id:
- T1078.004
- T1078
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: AWS Successful Single-Factor Authentication
id: a520b1fe-cc9e-4f56-b762-18354594c52f
version: 4
date: '2024-11-14'
version: 5
date: '2025-02-10'
author: Bhavin Patel, Splunk
status: production
type: TTP
@@ -56,10 +56,8 @@ tags:
- AWS Identity and Access Management Account Takeover
asset_type: AWS Account
mitre_attack_id:
- T1586
- T1586.003
- T1078
- T1078.004
- T1586.003
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: AWS Unusual Number of Failed Authentications From Ip
id: 0b5c9c2b-e2cb-4831-b4f1-af125ceb1386
version: 5
date: '2024-11-14'
version: 6
date: '2025-02-10'
author: Bhavin Patel, Splunk
status: production
type: Anomaly
@@ -57,11 +57,9 @@ tags:
- AWS Identity and Access Management Account Takeover
asset_type: AWS Account
mitre_attack_id:
- T1586
- T1586.003
- T1110
- T1110.003
- T1110.004
- T1586.003
product:
- Splunk Enterprise
- Splunk Enterprise Security
+2 -3
View File
@@ -1,7 +1,7 @@
name: AWS UpdateLoginProfile
id: 2a9b80d3-6a40-4115-11ad-212bf3d0d111
version: 7
date: '2024-11-14'
version: 8
date: '2025-02-10'
author: Bhavin Patel, Splunk
status: production
type: TTP
@@ -59,7 +59,6 @@ tags:
asset_type: AWS Account
mitre_attack_id:
- T1136.003
- T1136
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Azure Active Directory High Risk Sign-in
id: 1ecff169-26d7-4161-9a7b-2ac4c8e61bea
version: 6
date: '2024-11-14'
version: 7
date: '2025-02-10'
author: Mauricio Velazco, Gowthamaraj Rajendran, Splunk
status: production
type: TTP
@@ -58,10 +58,8 @@ tags:
- Azure Active Directory Account Takeover
asset_type: Azure Active Directory
mitre_attack_id:
- T1586
- T1586.003
- T1110
- T1110.003
- T1586.003
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Azure AD Application Administrator Role Assigned
id: eac4de87-7a56-4538-a21b-277897af6d8d
version: 6
date: '2024-11-14'
version: 8
date: '2025-02-10'
author: Mauricio Velazco, Gowthamaraj Rajendran, Splunk
status: production
type: TTP
@@ -64,7 +64,6 @@ tags:
asset_type: Azure Active Directory
atomic_guid: []
mitre_attack_id:
- T1098
- T1098.003
product:
- Splunk Enterprise
@@ -1,7 +1,7 @@
name: Azure AD Authentication Failed During MFA Challenge
id: e62c9c2e-bf51-4719-906c-3074618fcc1c
version: 7
date: '2024-11-14'
version: 8
date: '2025-02-10'
author: Mauricio Velazco, Gowthamaraj Rajendran, Splunk, 0xC0FFEEEE
status: production
type: TTP
@@ -70,10 +70,8 @@ tags:
- Azure Active Directory Account Takeover
asset_type: Azure Active Directory
mitre_attack_id:
- T1586
- T1586.003
- T1078
- T1078.004
- T1586.003
- T1621
product:
- Splunk Enterprise
@@ -1,6 +1,6 @@
name: Azure AD AzureHound UserAgent Detected
id: d62852db-a1f1-40db-a7fc-c3d56fa8bda3
version: 1
version: 2
date: '2025-01-06'
author: Dean Luxton
data_source:
@@ -1,7 +1,7 @@
name: Azure AD Device Code Authentication
id: d68d8732-6f7e-4ee5-a6eb-737f2b990b91
version: 5
date: '2024-11-14'
version: 6
date: '2025-02-10'
author: Mauricio Velazco, Gowthamaraj Rajendran, Splunk
status: production
type: TTP
@@ -62,7 +62,6 @@ tags:
asset_type: Azure Tenant
mitre_attack_id:
- T1528
- T1566
- T1566.002
product:
- Splunk Enterprise
@@ -1,6 +1,6 @@
name: Azure AD External Guest User Invited
id: c1fb4edb-cab1-4359-9b40-925ffd797fb5
version: 5
version: 6
date: '2024-11-14'
author: Gowthamaraj Rajendran, Mauricio Velazco, Splunk
status: production
@@ -1,7 +1,7 @@
name: Azure AD High Number Of Failed Authentications For User
id: 630b1694-210a-48ee-a450-6f79e7679f2c
version: 6
date: '2024-11-14'
version: 7
date: '2025-02-10'
author: Mauricio Velazco, Splunk
status: production
type: TTP
@@ -58,7 +58,6 @@ tags:
- Azure Active Directory Account Takeover
asset_type: Azure Tenant
mitre_attack_id:
- T1110
- T1110.001
product:
- Splunk Enterprise
@@ -1,7 +1,7 @@
name: Azure AD High Number Of Failed Authentications From Ip
id: e5ab41bf-745d-4f72-a393-2611151afd8e
version: 7
date: '2024-11-14'
version: 8
date: '2025-02-10'
author: Mauricio Velazco, Bhavin Patel, Splunk
status: production
type: TTP
@@ -62,7 +62,6 @@ tags:
- NOBELIUM Group
asset_type: Azure Tenant
mitre_attack_id:
- T1110
- T1110.001
- T1110.003
product:
@@ -1,7 +1,7 @@
name: Azure AD Multi-Factor Authentication Disabled
id: 482dd42a-acfa-486b-a0bb-d6fcda27318e
version: 5
date: '2024-11-14'
version: 7
date: '2025-02-10'
author: Mauricio Velazco, Gowthamaraj Rajendran, Splunk
status: production
type: TTP
@@ -60,10 +60,8 @@ tags:
- Azure Active Directory Account Takeover
asset_type: Azure Active Directory
mitre_attack_id:
- T1586
- T1586.003
- T1556
- T1556.006
- T1586.003
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Azure AD Multi-Source Failed Authentications Spike
id: 116e11a9-63ea-41eb-a66a-6a13bdc7d2c7
version: 6
date: '2024-11-14'
version: 7
date: '2025-02-10'
author: Mauricio Velazco, Splunk
status: production
type: Hunting
@@ -53,11 +53,9 @@ tags:
asset_type: Azure Tenant
atomic_guid: []
mitre_attack_id:
- T1586
- T1586.003
- T1110
- T1110.003
- T1110.004
- T1586.003
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Azure AD Multiple Failed MFA Requests For User
id: 264ea131-ab1f-41b8-90e0-33ad1a1888ea
version: 7
date: '2024-11-14'
version: 8
date: '2025-02-10'
author: Mauricio Velazco, Gowthamaraj Rajendran, Splunk
status: production
type: TTP
@@ -62,11 +62,9 @@ tags:
- Azure Active Directory Account Takeover
asset_type: Azure Active Directory
mitre_attack_id:
- T1586
- T1078.004
- T1586.003
- T1621
- T1078
- T1078.004
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Azure AD Multiple Users Failing To Authenticate From Ip
id: 94481a6a-8f59-4c86-957f-55a71e3612a6
version: 6
date: '2024-11-14'
version: 7
date: '2025-02-10'
author: Mauricio Velazco, Gowthamaraj Rajendran, Splunk
status: production
type: Anomaly
@@ -60,11 +60,9 @@ tags:
- Azure Active Directory Account Takeover
asset_type: Azure Active Directory
mitre_attack_id:
- T1586
- T1586.003
- T1110
- T1110.003
- T1110.004
- T1586.003
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -1,7 +1,7 @@
name: Azure AD New Custom Domain Added
id: 30c47f45-dd6a-4720-9963-0bca6c8686ef
version: 6
date: '2024-11-14'
version: 7
date: '2025-02-10'
author: Mauricio Velazco, Gowthamaraj Rajendran, Splunk
status: production
type: TTP
@@ -60,7 +60,6 @@ tags:
- Azure Active Directory Persistence
asset_type: Azure Active Directory
mitre_attack_id:
- T1484
- T1484.002
product:
- Splunk Enterprise
@@ -1,7 +1,7 @@
name: Azure AD New Federated Domain Added
id: a87cd633-076d-4ab2-9047-977751a3c1a0
version: 6
date: '2024-11-14'
version: 7
date: '2025-02-10'
author: Mauricio Velazco, Gowthamaraj Rajendran, Splunk
status: production
type: TTP
@@ -58,7 +58,6 @@ tags:
- Azure Active Directory Persistence
asset_type: Azure Active Directory
mitre_attack_id:
- T1484
- T1484.002
product:
- Splunk Enterprise
@@ -1,7 +1,7 @@
name: Azure AD New MFA Method Registered
id: 0488e814-eb81-42c3-9f1f-b2244973e3a3
version: 5
date: '2024-11-14'
version: 6
date: '2025-02-10'
author: Mauricio Velazco, Splunk
status: production
type: TTP
@@ -62,7 +62,6 @@ tags:
- Azure Active Directory Persistence
asset_type: Azure Tenant
mitre_attack_id:
- T1098
- T1098.005
product:
- Splunk Enterprise
@@ -1,7 +1,7 @@
name: Azure AD New MFA Method Registered For User
id: 2628b087-4189-403f-9044-87403f777a1b
version: 6
date: '2024-11-14'
version: 7
date: '2025-02-10'
author: Mauricio Velazco, Splunk
status: production
type: TTP
@@ -60,7 +60,6 @@ tags:
- Azure Active Directory Account Takeover
asset_type: Azure Active Directory
mitre_attack_id:
- T1556
- T1556.006
product:
- Splunk Enterprise
@@ -1,7 +1,7 @@
name: Azure AD PIM Role Assigned
id: fcd6dfeb-191c-46a0-a29c-c306382145ab
version: 6
date: '2024-11-14'
version: 7
date: '2025-02-10'
author: Mauricio Velazco, Splunk
status: production
type: TTP
@@ -57,7 +57,6 @@ tags:
- Azure Active Directory Persistence
asset_type: Azure Active Directory
mitre_attack_id:
- T1098
- T1098.003
product:
- Splunk Enterprise
@@ -1,7 +1,7 @@
name: Azure AD PIM Role Assignment Activated
id: 952e80d0-e343-439b-83f4-808c3e6fbf2e
version: 7
date: '2024-11-14'
version: 8
date: '2025-02-10'
author: Mauricio Velazco, Splunk
status: production
type: TTP
@@ -58,7 +58,6 @@ tags:
- Azure Active Directory Persistence
asset_type: Azure Active Directory
mitre_attack_id:
- T1098
- T1098.003
product:
- Splunk Enterprise
@@ -1,7 +1,7 @@
name: Azure AD Privileged Role Assigned
id: a28f0bc3-3400-4a6e-a2da-89b9e95f0d2a
version: 6
date: '2024-11-14'
version: 8
date: '2025-02-10'
author: Mauricio Velazco, Gowthamaraj Rajendran, Splunk
status: production
type: TTP
@@ -65,7 +65,6 @@ tags:
- NOBELIUM Group
asset_type: Azure Active Directory
mitre_attack_id:
- T1098
- T1098.003
product:
- Splunk Enterprise
@@ -1,7 +1,7 @@
name: Azure AD Privileged Role Assigned to Service Principal
id: 5dfaa3d3-e2e4-4053-8252-16d9ee528c41
version: 6
date: '2024-11-14'
version: 7
date: '2025-02-10'
author: Mauricio Velazco, Splunk
status: production
type: TTP
@@ -61,7 +61,6 @@ tags:
- NOBELIUM Group
asset_type: Azure Active Directory
mitre_attack_id:
- T1098
- T1098.003
product:
- Splunk Enterprise
@@ -1,6 +1,6 @@
name: Azure AD Service Principal Enumeration
id: 3f0647ce-add5-4436-8039-cbd1abe74563
version: 1
version: 2
date: '2025-01-06'
author: Dean Luxton
data_source:
@@ -1,7 +1,7 @@
name: Azure AD Service Principal New Client Credentials
id: e3adc0d3-9e4b-4b5d-b662-12cec1adff2a
version: 6
date: '2024-11-14'
version: 7
date: '2025-02-10'
author: Mauricio Velazco, Gowthamaraj Rajendran, Splunk
status: production
type: TTP
@@ -62,7 +62,6 @@ tags:
- NOBELIUM Group
asset_type: Azure Active Directory
mitre_attack_id:
- T1098
- T1098.001
product:
- Splunk Enterprise
@@ -1,6 +1,6 @@
name: Azure AD Service Principal Owner Added
id: 7ddf2084-6cf3-4a44-be83-474f7b73c701
version: 7
version: 8
date: '2024-11-14'
author: Mauricio Velazco, Gowthamaraj Rajendran, Splunk
status: production
@@ -1,24 +1,35 @@
name: Azure AD Service Principal Privilege Escalation
id: 29eb39d3-2bc8-49cc-99b3-35593191a588
version: 1
date: '2025-01-06'
version: 2
date: '2025-02-10'
author: Dean Luxton
data_source:
- Azure Active Directory Add app role assignment to service principal
type: TTP
status: production
description: This detection identifies when an Azure Service Principal elevates privileges by adding themself to a new app role assignment.
description: This detection identifies when an Azure Service Principal elevates privileges
by adding themself to a new app role assignment.
search: >-
`azure_monitor_aad` category=AuditLogs operationName="Add app role assignment to service principal" properties.initiatedBy.app.displayName=* properties.result=Success
| spath path=properties{}.targetResources{}.modifiedProperties{} output=targetResources
| stats min(_time) as _time values(eval(mvfilter(match(targetResources, "AppRole.Value")))) as appRole, values(eval(mvfilter(match(targetResources, "ServicePrincipal.DisplayName")))) as targetServicePrincipal values(eval(mvindex('properties.targetResources{}.displayName',0))) as targetAppContext values(user_agent) as user_agent values(identity) as servicePrincipal values(properties.initiatedBy.app.servicePrincipalId) as servicePrincipalId by operationName tenantId correlationId
`azure_monitor_aad` category=AuditLogs operationName="Add app role assignment to
service principal" properties.initiatedBy.app.displayName=* properties.result=Success |
spath path=properties{}.targetResources{}.modifiedProperties{} output=targetResources
| stats min(_time) as _time values(eval(mvfilter(match(targetResources, "AppRole.Value"))))
as appRole, values(eval(mvfilter(match(targetResources, "ServicePrincipal.DisplayName"))))
as targetServicePrincipal values(eval(mvindex('properties.targetResources{}.displayName',0)))
as targetAppContext values(user_agent) as user_agent values(identity) as servicePrincipal
values(properties.initiatedBy.app.servicePrincipalId) as servicePrincipalId by operationName
tenantId correlationId
| spath input=appRole path=newValue output=appRole
| spath input=targetServicePrincipal path=newValue output=targetServicePrincipal
| eval appRole=trim(replace(appRole, "\"", "")), targetServicePrincipal=trim(replace(targetServicePrincipal, "\"", ""))
| eval appRole=trim(replace(appRole, "\"", "")), targetServicePrincipal=trim(replace(targetServicePrincipal,
"\"", ""))
| where servicePrincipal=targetServicePrincipal
| table _time operationName servicePrincipal servicePrincipalId appRole targetAppContext user_agent tenantId correlationId
| table _time operationName servicePrincipal servicePrincipalId appRole targetAppContext
user_agent tenantId correlationId
| `azure_ad_service_principal_privilege_escalation_filter`
how_to_implement: The Splunk Add-on for Microsoft Cloud Services add-on is required to ingest EntraID audit logs via Azure EventHub. See reference for links for further details on how to onboard this log source.
how_to_implement: The Splunk Add-on for Microsoft Cloud Services add-on is required
to ingest EntraID audit logs via Azure EventHub. See reference for links for further
details on how to onboard this log source.
known_false_positives: Unknown
references:
- https://splunkbase.splunk.com/app/3110
@@ -32,11 +43,17 @@ drilldown_searches:
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
- name: View risk events for the last 7 days for - "$servicePrincipal$"
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$servicePrincipal$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$servicePrincipal$")
starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime
values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories)
as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic)
as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`'
earliest_offset: $info_min_time$
latest_offset: $info_max_time$
rba:
message: Service Principal $servicePrincipal$ has elevated privileges by adding themself to app role $appRole$
rba:
message: Service Principal $servicePrincipal$ has elevated privileges by adding
themself to app role $appRole$
risk_objects:
- field: servicePrincipal
type: user
@@ -50,7 +67,6 @@ tags:
asset_type: Azure Tenant
mitre_attack_id:
- T1098.003
- T1098
product:
- Splunk Enterprise
- Splunk Enterprise Security
@@ -59,6 +75,7 @@ tags:
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1098.003/azure_ad_spn_privesc/azure_ad_spn_privesc.log
- data:
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1098.003/azure_ad_spn_privesc/azure_ad_spn_privesc.log
sourcetype: azure:monitor:aad
source: Azure AD

Some files were not shown because too many files have changed in this diff Show More