Files
splunk-security_content/stories/suspicious_cloud_authentication_activities.yml
2020-06-09 10:54:30 -07:00

28 lines
1.2 KiB
YAML

name: Suspicious Cloud Authentication Activities
id: 6380ebbb-55c5-4fce-b754-01fd565fb73c
version: 1
date: '2020-06-04'
description: 'Monitor your cloud authentication events. Searches within this Analytic Story leverage
the recent cloud updates to the Authentication data model to help you stay aware of and investigate
suspicious login activity. '
narrative: 'It is important to monitor and control who has access to your cloud infrastructure.
Detecting suspicious logins will provide good starting points for investigations. Abusive behaviors
caused by compromised credentials can lead to direct monetary costs, as you will be billed for any
compute activity whether legitimate or otherwise.\
This Analytic Story has data model versions of cloud searches leveraging Authentication data,
including those looking for suspicious login activity, and cross-account activity for AWS.'
author: Rico Valdez, Splunk
type: ESCU
references:
- https://aws.amazon.com/blogs/security/aws-cloudtrail-now-tracks-cross-account-activity-to-its-origin/
- https://docs.aws.amazon.com/IAM/latest/UserGuide/cloudtrail-integration.html
tags:
analytics_story: Suspicious Cloud Authentication Activities
usecase: Security Monitoring
category:
- Cloud Security