mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
32 lines
1.6 KiB
YAML
32 lines
1.6 KiB
YAML
name: Cloud Federated Credential Abuse
|
|
id: cecdc1e7-0af2-4a55-8967-b9ea62c0317d
|
|
version: 1
|
|
date: '2021-01-26'
|
|
author: Rod Soto, Splunk
|
|
description: This analytical story addresses events that indicate abuse of cloud federated
|
|
credentials. These credentials are usually extracted from endpoint desktop or servers
|
|
specially those servers that provide federation services such as Windows Active
|
|
Directory Federation Services. Identity Federation relies on objects such as Oauth2
|
|
tokens, cookies or SAML assertions in order to provide seamless access between cloud
|
|
and perimeter environments. If these objects are either hijacked or forged then
|
|
attackers will be able to pivot into victim's cloud environements.
|
|
narrative: This story is composed of detection searches based on endpoint that addresses
|
|
the use of Mimikatz, Escalation of Privileges and Abnormal processes that may indicate
|
|
the extraction of Federated directory objects such as passwords, Oauth2 tokens,
|
|
certificates and keys. Cloud environment (AWS, Azure) related events are also addressed
|
|
in specific cloud environment detection searches.
|
|
references:
|
|
- https://www.cyberark.com/resources/threat-research-blog/golden-saml-newly-discovered-attack-technique-forges-authentication-to-cloud-apps
|
|
- https://www.fireeye.com/content/dam/fireeye-www/blog/pdfs/wp-m-unc2452-2021-000343-01.pdf
|
|
- https://us-cert.cisa.gov/ncas/alerts/aa21-008a
|
|
tags:
|
|
analytic_story: Cloud Federated Credential Abuse
|
|
category:
|
|
- Cloud Security
|
|
usecase: Security Monitoring
|
|
product:
|
|
- Splunk Security Analytics for AWS
|
|
- Splunk Enterprise
|
|
- Splunk Enterprise Security
|
|
- Splunk Cloud
|