mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
54 lines
1.8 KiB
YAML
54 lines
1.8 KiB
YAML
name: GCP Detect gcploit framework
|
|
id: a1c5a85e-a162-410c-a5d9-99ff639e5a52
|
|
version: 1
|
|
date: '2020-10-08'
|
|
author: Rod Soto, Splunk
|
|
status: experimental
|
|
type: TTP
|
|
description: This search provides detection of GCPloit exploitation framework. This
|
|
framework can be used to escalate privileges and move laterally from compromised
|
|
high privilege accounts.
|
|
data_source: []
|
|
search: '`google_gcp_pubsub_message` data.protoPayload.request.function.timeout=539s
|
|
| table src src_user data.resource.labels.project_id data.protoPayload.request.function.serviceAccountEmail
|
|
data.protoPayload.authorizationInfo{}.permission data.protoPayload.request.location
|
|
http_user_agent | `gcp_detect_gcploit_framework_filter`'
|
|
how_to_implement: You must install splunk GCP add-on. This search works with gcp:pubsub:message
|
|
logs
|
|
known_false_positives: Payload.request.function.timeout value can possibly be match
|
|
with other functions or requests however the source user and target request account
|
|
may indicate an attempt to move laterally accross acounts or projects
|
|
references:
|
|
- https://github.com/dxa4481/gcploit
|
|
- https://www.youtube.com/watch?v=Ml09R38jpok
|
|
tags:
|
|
analytic_story:
|
|
- GCP Cross Account Activity
|
|
asset_type: GCP Account
|
|
confidence: 50
|
|
impact: 50
|
|
message: tbd
|
|
mitre_attack_id:
|
|
- T1078
|
|
observable:
|
|
- name: user
|
|
type: User
|
|
role:
|
|
- Victim
|
|
product:
|
|
- Splunk Enterprise
|
|
- Splunk Enterprise Security
|
|
- Splunk Cloud
|
|
required_fields:
|
|
- _time
|
|
- data.protoPayload.request.function.timeout
|
|
- src
|
|
- src_user
|
|
- data.resource.labels.project_id
|
|
- data.protoPayload.request.function.serviceAccountEmail
|
|
- data.protoPayload.authorizationInfo{}.permission
|
|
- data.protoPayload.request.location
|
|
- http_user_agent
|
|
risk_score: 25
|
|
security_domain: threat
|