Files
splunk-security_content/detections/users_without_mfa.yml

112 lines
4.5 KiB
YAML

asset_type: AWS Instance
confidence: medium
creation_date: '2018-05-17'
data_metadata:
data_source:
- AWS CloudTrail logs
data_sourcetypes:
- aws:cloudtrail
providing_technologies:
- AWS
description: This search looks for CloudTrail events where a user logged into the
AWS account, is making API calls and has not enabled Multi Factor authentication.
Multi factor authentication adds a layer of security by forcing the users to type
a unique authentication code from an approved authentication device when they access
AWS websites or services. AWS Best Practices recommend that you enable MFA for privileged
IAM users.
detect:
splunk:
correlation_rule:
notable:
nes_fields: user
rule_description: API Activity detected from $user$ without MFA enabled.
rule_title: API Activity detected from $user$ without MFA enabled
risk:
risk_object: user
risk_object_type:
- user
risk_score: 30
schedule:
cron_schedule: 0 8 * * *
earliest_time: -1d@d
latest_time: -10m@m
search: sourcetype=aws:cloudtrail userIdentity.sessionContext.attributes.mfaAuthenticated=false
| search NOT [| inputlookup aws_service_accounts | fields identity | rename
identity as user]| stats count min(_time) as firstTime max(_time) as lastTime
values(eventName) as eventName by userIdentity.arn userIdentity.type user
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
suppress:
suppress_fields: user
suppress_period: 84600s
eli5: ' In this search, we query CloudTrail logs and specifically look for events
where the multi factor authentication context of the user''s session is false which
basically means, that the user does not have MFA enabled on AWS. We then filter
out all the known AWS service accounts since service accounts typically do not have
MFA enabled. The search then creates a table of the first and last time a user without
MFA was detected, the values and count of the API calls made, the type of user identity,
ARN and the name of the user.'
entities:
- user
how_to_implement: 'You must install the AWS App for Splunk (version 5.1.0 or later)
and Splunk Add-on for AWS (version 4.4.0 or later), then configure your CloudTrail
inputs. Leverage the support search `Create a list of approved AWS service accounts`:
run it once every 30 days to create a list of service accounts and validate them.\
This search produces fields (`eventName`,`userIdentity.type`,`userIdentity.arn`)
that are not yet supported by ES Incident Review and therefore cannot be viewed
when a notable event is raised. These fields contribute additional context to the
notable. To see the additional metadata, add the following fields, if not already
present, to Incident Review - Event Attributes (Configure > Incident Management
> Incident Review Settings > Add New Entry):\\n1. **Label:** AWS Event Name, **Field:**
eventName\
1. \
1. **Label:** AWS User ARN, **Field:** userIdentity.arn\
1. \
1. **Label:** AWS User Type, **Field:** userIdentity.type\
Detailed documentation on how to create a new field within Incident Review may be
found here: `https://docs.splunk.com/Documentation/ES/5.3.0/Admin/Customizenotables#Add_a_field_to_the_notable_event_details`'
id: 2a9b80d3-6340-4345-w5ad-212bf5d1dac4
investigations:
- id: 3d6c3213-5fff-4a1e-b57d-b24c262171e7
name: Get Notable History
type: splunk
- id: f3fb4d1b-5f33-4b01-b541-c7af9534c242
name: Get Notable Info
type: splunk
- id: bc91a8cd-35e7-4bb2-6140-e756cc46fd76
name: Investigate AWS User Activities by user field
type: splunk
known_false_positives: Many service accounts configured within an AWS infrastructure
do not have multi factor authentication enabled. Please ignore the service accounts,
if triggered and instead add them to the aws_service_accounts.csv file to fine tune
the detection. It is also possible that the search detects users in your environment
using Single Sign-On systems, since the MFA is not handled by AWS.
maintainers:
- company: Splunk
email: bpatel@splunk.com
name: Bhavin Patel
mappings:
cis20:
- CIS 16
mitre_attack:
- Execution
nist:
- DE.DP
- PR.AC
modification_date: '2018-05-17'
name: Detect API activity from users without MFA
original_authors:
- company: Splunk
email: bpatel@splunk.com
name: Bhavin Patel
references: []
security_domain: network
spec_version: 2
type: splunk
version: '1.0'