mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
67 lines
2.3 KiB
YAML
67 lines
2.3 KiB
YAML
name: AWS Excessive Security Scanning
|
|
id: 1fdd164a-def8-4762-83a9-9ffe24e74d5a
|
|
version: 2
|
|
date: '2024-05-08'
|
|
author: Patrick Bareiss, Splunk
|
|
status: production
|
|
type: TTP
|
|
description: The following analytic identifies excessive security scanning activities
|
|
in AWS by detecting a high number of Describe, List, or Get API calls from a single
|
|
user. It leverages AWS CloudTrail logs to count distinct event names and flags users
|
|
with more than 50 such events. This behavior is significant as it may indicate reconnaissance
|
|
activities by an attacker attempting to map out your AWS environment. If confirmed
|
|
malicious, this could lead to unauthorized access, data exfiltration, or further
|
|
exploitation of your cloud infrastructure.
|
|
data_source:
|
|
- AWS CloudTrail
|
|
search: '`cloudtrail` eventName=Describe* OR eventName=List* OR eventName=Get* |
|
|
stats dc(eventName) as dc_events min(_time) as firstTime max(_time) as lastTime
|
|
values(eventName) as command values(src) as src values(userAgent) as userAgent by
|
|
user userIdentity.arn | where dc_events > 50 | `security_content_ctime(firstTime)`
|
|
| `security_content_ctime(lastTime)`|`aws_excessive_security_scanning_filter`'
|
|
how_to_implement: You must install splunk AWS add on and Splunk App for AWS. This
|
|
search works with AWS CloudTrail logs.
|
|
known_false_positives: While this search has no known false positives.
|
|
references:
|
|
- https://github.com/aquasecurity/cloudsploit
|
|
tags:
|
|
analytic_story:
|
|
- AWS User Monitoring
|
|
asset_type: AWS Account
|
|
confidence: 60
|
|
impact: 30
|
|
message: User $user$ has excessive number of api calls $dc_events$ from these IP
|
|
addresses $src$, violating the threshold of 50, using the following commands $command$.
|
|
mitre_attack_id:
|
|
- T1526
|
|
observable:
|
|
- name: src
|
|
type: IP Address
|
|
role:
|
|
- Attacker
|
|
- name: user
|
|
type: User
|
|
role:
|
|
- Victim
|
|
product:
|
|
- Splunk Enterprise
|
|
- Splunk Enterprise Security
|
|
- Splunk Cloud
|
|
required_fields:
|
|
- _time
|
|
- eventName
|
|
- src
|
|
- userAgent
|
|
- user
|
|
- userIdentity.arn
|
|
risk_score: 18
|
|
security_domain: network
|
|
tests:
|
|
- name: True Positive Test
|
|
attack_data:
|
|
- data:
|
|
https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1526/aws_security_scanner/aws_security_scanner.json
|
|
sourcetype: aws:cloudtrail
|
|
source: aws_cloudtrail
|
|
update_timestamp: true
|