2.9 KiB
title, excerpt, categories, last_modified_at, toc, toc_label, tags
| title | excerpt | categories | last_modified_at | toc | toc_label | tags | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| aws detect permanent key creation | Valid Accounts |
|
2020-07-27 | true |
|
⚠️ WARNING THIS IS A EXPERIMENTAL DETECTION
We have not been able to test, simulate, or build datasets for this detection. Use at your own risk. This analytic is NOT supported.
Try in Splunk Security Cloud{: .btn .btn--success}
Description
This search provides detection of accounts creating permanent keys. Permanent keys are not created by default and they are only needed for programmatic calls. Creation of Permanent key is an important event to monitor.
- Type: Hunting
- Product: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud
- Datamodel:
- Last Updated: 2020-07-27
- Author: Rod Soto, Splunk
- ID: 12d6d713-3cb4-4ffc-a064-1dca3d1cca01
ATT&CK
| ID | Technique | Tactic |
|---|---|---|
| T1078 | Valid Accounts | Defense Evasion, Persistence, Privilege Escalation, Initial Access |
Search
`aws_cloudwatchlogs_eks` CreateAccessKey
| spath eventName
| search eventName=CreateAccessKey "userIdentity.type"=IAMUser
| table sourceIPAddress userName userIdentity.type userAgent action status responseElements.accessKey.createDate responseElements.accessKey.status responseElements.accessKey.accessKeyId
|`aws_detect_permanent_key_creation_filter`
Associated Analytic Story
How To Implement
You must install splunk AWS add on and Splunk App for AWS. This search works with cloudwatch logs
Required field
- _time
- eventName
- userIdentity.type
- sourceIPAddress
- userName userIdentity.type
- userAgent
- action
- status
- responseElements.accessKey.createDate
- esponseElements.accessKey.status
- responseElements.accessKey.accessKeyId
Kill Chain Phase
- Lateral Movement
Known False Positives
Not all permanent key creations are malicious. If there is a policy of rotating keys this search can be adjusted to provide better context.
Reference
Test Dataset
Replay any dataset to Splunk Enterprise by using our replay.py tool or the UI.
Alternatively you can replay a dataset into a Splunk Attack Range
source | version: 1