Files
splunk-security_content/detections/cloud/cloud_security_groups_modifications_by_user.yml
2024-06-26 14:41:53 +00:00

69 lines
3.1 KiB
YAML

name: Cloud Security Groups Modifications by User
id: cfe7cca7-2746-4bdf-b712-b01ed819b9de
version: 2
date: '2024-05-18'
author: Bhavin Patel, Splunk
data_source:
- AWS CloudTrail
type: Anomaly
status: production
description: The following analytic identifies unusual modifications to security groups
in your cloud environment by users, focusing on actions such as modifications, deletions,
or creations over 30-minute intervals. It leverages cloud infrastructure logs and
calculates the standard deviation for each user, using the 3-sigma rule to detect
anomalies. This activity is significant as it may indicate a compromised account
or insider threat. If confirmed malicious, attackers could alter security group
configurations, potentially exposing sensitive resources or disrupting services.
search: '| tstats dc(All_Changes.object) as unique_security_groups values(All_Changes.src)
as src values(All_Changes.user_type) as user_type values(All_Changes.object_category)
as object_category values(All_Changes.object) as objects values(All_Changes.action)
as action values(All_Changes.user_agent) as user_agent values(All_Changes.command)
as command from datamodel=Change WHERE All_Changes.object_category = "security_group"
(All_Changes.action = modified OR All_Changes.action = deleted OR All_Changes.action
= created) by All_Changes.user _time span=30m | `drop_dm_object_name("All_Changes")`
| eventstats avg(unique_security_groups) as avg_changes , stdev(unique_security_groups)
as std_changes by user | eval upperBound=(avg_changes+std_changes*3) | eval isOutlier=if(unique_security_groups
> 2 and unique_security_groups >= upperBound, 1, 0) | where isOutlier=1| `cloud_security_groups_modifications_by_user_filter`'
how_to_implement: This search requries the Cloud infrastructure logs such as AWS Cloudtrail,
GCP Pubsub Message logs, Azure Audit logs to be ingested into an accelerated Change
datamodel. It is also recommended that users can try different combinations of the
`bucket` span time and outlier conditions to better suit with their environment.
known_false_positives: It is possible that legitimate user/admin may modify a number
of security groups
references:
- https://attack.mitre.org/techniques/T1578/005/
tags:
analytic_story:
- Suspicious Cloud User Activities
asset_type: Cloud Instance
confidence: 50
impact: 70
message: Unsual number cloud security group modifications detected by user - $user$
mitre_attack_id:
- T1578.005
observable:
- name: user
type: User
role:
- Victim
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
required_fields:
- _time
- All_Changes.object_id
- All_Changes.action
- All_Changes.status
- All_Changes.object_category
- All_Changes.user
risk_score: 35
security_domain: threat
tests:
- name: True Positive Test
attack_data:
- data:
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1578.005/aws_authorize_security_group/aws_authorize_security_group.json
sourcetype: aws:cloudtrail
source: aws_cloudtrail