Files
splunk-security_content/docs/_stories/dev_sec_ops.md
T
2021-09-27 13:16:04 -04:00

4.1 KiB

title, last_modified_at, toc, tags
title last_modified_at toc tags
Dev Sec Ops 2021-08-18 true
Splunk Enterprise
Splunk Enterprise Security
Splunk Cloud
Dev Sec Ops Analytics

Try in Splunk Security Cloud{: .btn .btn--success}

Description

This story is focused around detecting attacks on a DevSecOps lifeccycle which consists of the phases plan, code, build, test, release, deploy, operate and monitor.

  • Product: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud, Dev Sec Ops Analytics
  • Datamodel:
  • Last Updated: 2021-08-18
  • Author: Patrick Bareiss, Splunk
  • ID: 0ca8c38e-631e-4b81-940c-f9c5450ce41e

Narrative

DevSecOps is a collaborative framework, which thinks about application and infrastructure security from the start. This means that security tools are part of the continuous integration and continuous deployment pipeline. In this analytics story, we focused on detections around the tools used in this framework such as GitHub as a version control system, GDrive for the documentation, CircleCI as the CI/CD pipeline, Kubernetes as the container execution engine and multiple security tools such as Semgrep and Kube-Hunter.

Detections

Name Technique Type
AWS ECR Container Scanning Findings High Malicious Image, Compromise Client Software Binary, Compromise Software Dependencies and Development Tools, Exploitation for Credential Access, Cloud Service Discovery TTP
AWS ECR Container Scanning Findings Low Informational Unknown Malicious Image Hunting
AWS ECR Container Scanning Findings Medium Malicious Image Anomaly
AWS ECR Container Upload Outside Business Hours Malicious Image Anomaly
AWS ECR Container Upload Unknown User Malicious Image Anomaly
Circle CI Disable Security Job Compromise Client Software Binary Anomaly
Circle CI Disable Security Step Compromise Client Software Binary Anomaly
Correlation by Repository and Risk Malicious Image Correlation
Correlation by User and Risk Malicious Image Correlation
GitHub Dependabot Alert Compromise Software Dependencies and Development Tools Anomaly
GitHub Pull Request from Unknown User Compromise Software Dependencies and Development Tools Anomaly
Kubernetes Nginx Ingress LFI Exploitation for Credential Access TTP
Kubernetes Nginx Ingress RFI Exploitation for Credential Access TTP
Kubernetes Scanner Image Pulling Cloud Service Discovery TTP

Reference

source | version: 1