mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
30 lines
1.3 KiB
YAML
30 lines
1.3 KiB
YAML
name: Suspicious Cloud Authentication Activities
|
|
id: 6380ebbb-55c5-4fce-b754-01fd565fb73c
|
|
version: 1
|
|
date: '2020-06-04'
|
|
author: Rico Valdez, Splunk
|
|
description: 'Monitor your cloud authentication events. Searches within this Analytic
|
|
Story leverage the recent cloud updates to the Authentication data model to help
|
|
you stay aware of and investigate suspicious login activity. '
|
|
narrative: 'It is important to monitor and control who has access to your cloud infrastructure.
|
|
Detecting suspicious logins will provide good starting points for investigations.
|
|
Abusive behaviors caused by compromised credentials can lead to direct monetary
|
|
costs, as you will be billed for any compute activity whether legitimate or otherwise.\
|
|
|
|
This Analytic Story has data model versions of cloud searches leveraging Authentication
|
|
data, including those looking for suspicious login activity, and cross-account activity
|
|
for AWS.'
|
|
references:
|
|
- https://aws.amazon.com/blogs/security/aws-cloudtrail-now-tracks-cross-account-activity-to-its-origin/
|
|
- https://docs.aws.amazon.com/IAM/latest/UserGuide/cloudtrail-integration.html
|
|
tags:
|
|
analytic_story: Suspicious Cloud Authentication Activities
|
|
category:
|
|
- Cloud Security
|
|
product:
|
|
- Splunk Security Analytics for AWS
|
|
- Splunk Enterprise
|
|
- Splunk Enterprise Security
|
|
- Splunk Cloud
|
|
usecase: Security Monitoring
|