mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
28 lines
1.2 KiB
YAML
28 lines
1.2 KiB
YAML
|
|
name: Suspicious Cloud Authentication Activities
|
|
id: 6380ebbb-55c5-4fce-b754-01fd565fb73c
|
|
version: 1
|
|
date: '2020-06-04'
|
|
description: 'Monitor your cloud authentication events. Searches within this Analytic Story leverage
|
|
the recent cloud updates to the Authentication data model to help you stay aware of and investigate
|
|
suspicious login activity. '
|
|
narrative: 'It is important to monitor and control who has access to your cloud infrastructure.
|
|
Detecting suspicious logins will provide good starting points for investigations. Abusive behaviors
|
|
caused by compromised credentials can lead to direct monetary costs, as you will be billed for any
|
|
compute activity whether legitimate or otherwise.\
|
|
|
|
This Analytic Story has data model versions of cloud searches leveraging Authentication data,
|
|
including those looking for suspicious login activity, and cross-account activity for AWS.'
|
|
author: Rico Valdez, Splunk
|
|
type: ESCU
|
|
references:
|
|
- https://aws.amazon.com/blogs/security/aws-cloudtrail-now-tracks-cross-account-activity-to-its-origin/
|
|
- https://docs.aws.amazon.com/IAM/latest/UserGuide/cloudtrail-integration.html
|
|
tags:
|
|
analytics_story: Suspicious Cloud Authentication Activities
|
|
usecase: Security Monitoring
|
|
category:
|
|
- Cloud Security
|
|
|
|
|