mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
30 lines
1.2 KiB
YAML
30 lines
1.2 KiB
YAML
name: Suspicious Cloud User Activities
|
|
id: 1ed5ce7d-5469-4232-92af-89d1a3595b39
|
|
version: 1
|
|
date: '2020-09-04'
|
|
author: David Dorsey, Splunk
|
|
description: Detect and investigate suspicious activities by users and roles in your
|
|
cloud environments.
|
|
narrative: 'It seems obvious that it is critical to monitor and control the users
|
|
who have access to your cloud infrastructure. Nevertheless, it''s all too common
|
|
for enterprises to lose track of ad-hoc accounts, leaving their servers vulnerable
|
|
to attack. In fact, this was the very oversight that led to Tesla''s cryptojacking
|
|
attack in February, 2018.\
|
|
|
|
In addition to compromising the security of your data, when bad actors leverage
|
|
your compute resources, it can incur monumental costs, since you will be billed
|
|
for any new instances and increased bandwidth usage.'
|
|
references:
|
|
- https://d0.awsstatic.com/whitepapers/aws-security-best-practices.pdf
|
|
- https://redlock.io/blog/cryptojacking-tesla
|
|
tags:
|
|
analytic_story: Suspicious Cloud User Activities
|
|
category:
|
|
- Cloud Security
|
|
product:
|
|
- Splunk Security Analytics for AWS
|
|
- Splunk Enterprise
|
|
- Splunk Enterprise Security
|
|
- Splunk Cloud
|
|
usecase: Security Monitoring
|