mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
112 lines
4.5 KiB
YAML
112 lines
4.5 KiB
YAML
asset_type: AWS Instance
|
|
confidence: medium
|
|
creation_date: '2018-05-17'
|
|
data_metadata:
|
|
data_source:
|
|
- AWS CloudTrail logs
|
|
data_sourcetypes:
|
|
- aws:cloudtrail
|
|
providing_technologies:
|
|
- AWS
|
|
description: This search looks for CloudTrail events where a user logged into the
|
|
AWS account, is making API calls and has not enabled Multi Factor authentication.
|
|
Multi factor authentication adds a layer of security by forcing the users to type
|
|
a unique authentication code from an approved authentication device when they access
|
|
AWS websites or services. AWS Best Practices recommend that you enable MFA for privileged
|
|
IAM users.
|
|
detect:
|
|
splunk:
|
|
correlation_rule:
|
|
notable:
|
|
nes_fields: user
|
|
rule_description: API Activity detected from $user$ without MFA enabled.
|
|
rule_title: API Activity detected from $user$ without MFA enabled
|
|
risk:
|
|
risk_object: user
|
|
risk_object_type:
|
|
- user
|
|
risk_score: 30
|
|
schedule:
|
|
cron_schedule: 0 8 * * *
|
|
earliest_time: -1d@d
|
|
latest_time: -10m@m
|
|
search: sourcetype=aws:cloudtrail userIdentity.sessionContext.attributes.mfaAuthenticated=false
|
|
| search NOT [| inputlookup aws_service_accounts | fields identity | rename
|
|
identity as user]| stats count min(_time) as firstTime max(_time) as lastTime
|
|
values(eventName) as eventName by userIdentity.arn userIdentity.type user
|
|
| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`
|
|
suppress:
|
|
suppress_fields: user
|
|
suppress_period: 84600s
|
|
eli5: ' In this search, we query CloudTrail logs and specifically look for events
|
|
where the multi factor authentication context of the user''s session is false which
|
|
basically means, that the user does not have MFA enabled on AWS. We then filter
|
|
out all the known AWS service accounts since service accounts typically do not have
|
|
MFA enabled. The search then creates a table of the first and last time a user without
|
|
MFA was detected, the values and count of the API calls made, the type of user identity,
|
|
ARN and the name of the user.'
|
|
entities:
|
|
- user
|
|
how_to_implement: 'You must install the AWS App for Splunk (version 5.1.0 or later)
|
|
and Splunk Add-on for AWS (version 4.4.0 or later), then configure your CloudTrail
|
|
inputs. Leverage the support search `Create a list of approved AWS service accounts`:
|
|
run it once every 30 days to create a list of service accounts and validate them.\
|
|
|
|
This search produces fields (`eventName`,`userIdentity.type`,`userIdentity.arn`)
|
|
that are not yet supported by ES Incident Review and therefore cannot be viewed
|
|
when a notable event is raised. These fields contribute additional context to the
|
|
notable. To see the additional metadata, add the following fields, if not already
|
|
present, to Incident Review - Event Attributes (Configure > Incident Management
|
|
> Incident Review Settings > Add New Entry):\\n1. **Label:** AWS Event Name, **Field:**
|
|
eventName\
|
|
|
|
1. \
|
|
|
|
1. **Label:** AWS User ARN, **Field:** userIdentity.arn\
|
|
|
|
1. \
|
|
|
|
1. **Label:** AWS User Type, **Field:** userIdentity.type\
|
|
|
|
Detailed documentation on how to create a new field within Incident Review may be
|
|
found here: `https://docs.splunk.com/Documentation/ES/5.3.0/Admin/Customizenotables#Add_a_field_to_the_notable_event_details`'
|
|
id: 2a9b80d3-6340-4345-w5ad-212bf5d1dac4
|
|
investigations:
|
|
- id: 3d6c3213-5fff-4a1e-b57d-b24c262171e7
|
|
name: Get Notable History
|
|
type: splunk
|
|
- id: f3fb4d1b-5f33-4b01-b541-c7af9534c242
|
|
name: Get Notable Info
|
|
type: splunk
|
|
- id: bc91a8cd-35e7-4bb2-6140-e756cc46fd76
|
|
name: Investigate AWS User Activities by user field
|
|
type: splunk
|
|
known_false_positives: Many service accounts configured within an AWS infrastructure
|
|
do not have multi factor authentication enabled. Please ignore the service accounts,
|
|
if triggered and instead add them to the aws_service_accounts.csv file to fine tune
|
|
the detection. It is also possible that the search detects users in your environment
|
|
using Single Sign-On systems, since the MFA is not handled by AWS.
|
|
maintainers:
|
|
- company: Splunk
|
|
email: bpatel@splunk.com
|
|
name: Bhavin Patel
|
|
mappings:
|
|
cis20:
|
|
- CIS 16
|
|
mitre_attack:
|
|
- Execution
|
|
nist:
|
|
- DE.DP
|
|
- PR.AC
|
|
modification_date: '2018-05-17'
|
|
name: Detect API activity from users without MFA
|
|
original_authors:
|
|
- company: Splunk
|
|
email: bpatel@splunk.com
|
|
name: Bhavin Patel
|
|
references: []
|
|
security_domain: network
|
|
spec_version: 2
|
|
type: splunk
|
|
version: '1.0'
|