mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
69 lines
3.1 KiB
YAML
69 lines
3.1 KiB
YAML
name: Cloud Security Groups Modifications by User
|
|
id: cfe7cca7-2746-4bdf-b712-b01ed819b9de
|
|
version: 2
|
|
date: '2024-05-18'
|
|
author: Bhavin Patel, Splunk
|
|
data_source:
|
|
- AWS CloudTrail
|
|
type: Anomaly
|
|
status: production
|
|
description: The following analytic identifies unusual modifications to security groups
|
|
in your cloud environment by users, focusing on actions such as modifications, deletions,
|
|
or creations over 30-minute intervals. It leverages cloud infrastructure logs and
|
|
calculates the standard deviation for each user, using the 3-sigma rule to detect
|
|
anomalies. This activity is significant as it may indicate a compromised account
|
|
or insider threat. If confirmed malicious, attackers could alter security group
|
|
configurations, potentially exposing sensitive resources or disrupting services.
|
|
search: '| tstats dc(All_Changes.object) as unique_security_groups values(All_Changes.src)
|
|
as src values(All_Changes.user_type) as user_type values(All_Changes.object_category)
|
|
as object_category values(All_Changes.object) as objects values(All_Changes.action)
|
|
as action values(All_Changes.user_agent) as user_agent values(All_Changes.command)
|
|
as command from datamodel=Change WHERE All_Changes.object_category = "security_group"
|
|
(All_Changes.action = modified OR All_Changes.action = deleted OR All_Changes.action
|
|
= created) by All_Changes.user _time span=30m | `drop_dm_object_name("All_Changes")`
|
|
| eventstats avg(unique_security_groups) as avg_changes , stdev(unique_security_groups)
|
|
as std_changes by user | eval upperBound=(avg_changes+std_changes*3) | eval isOutlier=if(unique_security_groups
|
|
> 2 and unique_security_groups >= upperBound, 1, 0) | where isOutlier=1| `cloud_security_groups_modifications_by_user_filter`'
|
|
how_to_implement: This search requries the Cloud infrastructure logs such as AWS Cloudtrail,
|
|
GCP Pubsub Message logs, Azure Audit logs to be ingested into an accelerated Change
|
|
datamodel. It is also recommended that users can try different combinations of the
|
|
`bucket` span time and outlier conditions to better suit with their environment.
|
|
known_false_positives: It is possible that legitimate user/admin may modify a number
|
|
of security groups
|
|
references:
|
|
- https://attack.mitre.org/techniques/T1578/005/
|
|
tags:
|
|
analytic_story:
|
|
- Suspicious Cloud User Activities
|
|
asset_type: Cloud Instance
|
|
confidence: 50
|
|
impact: 70
|
|
message: Unsual number cloud security group modifications detected by user - $user$
|
|
mitre_attack_id:
|
|
- T1578.005
|
|
observable:
|
|
- name: user
|
|
type: User
|
|
role:
|
|
- Victim
|
|
product:
|
|
- Splunk Enterprise
|
|
- Splunk Enterprise Security
|
|
- Splunk Cloud
|
|
required_fields:
|
|
- _time
|
|
- All_Changes.object_id
|
|
- All_Changes.action
|
|
- All_Changes.status
|
|
- All_Changes.object_category
|
|
- All_Changes.user
|
|
risk_score: 35
|
|
security_domain: threat
|
|
tests:
|
|
- name: True Positive Test
|
|
attack_data:
|
|
- data:
|
|
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1578.005/aws_authorize_security_group/aws_authorize_security_group.json
|
|
sourcetype: aws:cloudtrail
|
|
source: aws_cloudtrail
|