mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
64 lines
3.9 KiB
YAML
64 lines
3.9 KiB
YAML
name: Cloud Security Groups Modifications by User
|
|
id: cfe7cca7-2746-4bdf-b712-b01ed819b9de
|
|
version: 9
|
|
creation_date: '2024-03-06'
|
|
modification_date: '2026-05-13'
|
|
author: Bhavin Patel, Splunk
|
|
status: production
|
|
type: Anomaly
|
|
description: The following analytic identifies unusual modifications to security groups in your cloud environment by users, focusing on actions such as modifications, deletions, or creations over 30-minute intervals. It leverages cloud infrastructure logs and calculates the standard deviation for each user, using the 3-sigma rule to detect anomalies. This activity is significant as it may indicate a compromised account or insider threat. If confirmed malicious, attackers could alter security group configurations, potentially exposing sensitive resources or disrupting services.
|
|
data_source:
|
|
- AWS CloudTrail
|
|
search: |-
|
|
| tstats dc(All_Changes.object) as unique_security_groups values(All_Changes.src) as src values(All_Changes.user_type) as user_type values(All_Changes.object_category) as object_category values(All_Changes.object) as objects values(All_Changes.action) as action values(All_Changes.user_agent) as user_agent values(All_Changes.command) as command FROM datamodel=Change
|
|
WHERE All_Changes.object_category = "security_group" (All_Changes.action = modified
|
|
OR
|
|
All_Changes.action = deleted
|
|
OR
|
|
All_Changes.action = created)
|
|
BY All_Changes.user _time span=30m
|
|
| `drop_dm_object_name("All_Changes")`
|
|
| eventstats avg(unique_security_groups) as avg_changes , stdev(unique_security_groups) as std_changes
|
|
BY user
|
|
| eval upperBound=(avg_changes+std_changes*3)
|
|
| eval isOutlier=if(unique_security_groups > 2 and unique_security_groups >= upperBound, 1, 0)
|
|
| where isOutlier=1
|
|
| `cloud_security_groups_modifications_by_user_filter`
|
|
how_to_implement: This search requries the Cloud infrastructure logs such as AWS Cloudtrail, GCP Pubsub Message logs, Azure Audit logs to be ingested into an accelerated Change datamodel. It is also recommended that users can try different combinations of the `bucket` span time and outlier conditions to better suit with their environment.
|
|
known_false_positives: It is possible that legitimate user/admin may modify a number of security groups
|
|
references:
|
|
- https://attack.mitre.org/techniques/T1578/005/
|
|
drilldown_searches:
|
|
- name: View the detection results for - "$user$"
|
|
search: '%original_detection_search% | search user = "$user$"'
|
|
earliest_offset: $info_min_time$
|
|
latest_offset: $info_max_time$
|
|
- name: View risk events for the last 7 days for - "$user$"
|
|
search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$user$") | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`'
|
|
earliest_offset: 7d
|
|
latest_offset: "0"
|
|
intermediate_findings:
|
|
entities:
|
|
- field: user
|
|
type: user
|
|
score: 20
|
|
message: Unsual number cloud security group modifications detected by user - $user$
|
|
analytic_story:
|
|
- Suspicious Cloud User Activities
|
|
asset_type: Cloud Instance
|
|
mitre_attack_id:
|
|
- T1578.005
|
|
product:
|
|
- Splunk Enterprise
|
|
- Splunk Enterprise Security
|
|
- Splunk Cloud
|
|
category: cloud
|
|
security_domain: threat
|
|
tests:
|
|
- name: True Positive Test
|
|
attack_data:
|
|
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1578.005/aws_authorize_security_group/aws_authorize_security_group.json
|
|
sourcetype: aws:cloudtrail
|
|
source: aws_cloudtrail
|
|
test_type: unit
|