mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
2.6 KiB
2.6 KiB
title, last_modified_at, toc, tags
| title | last_modified_at | toc | tags | |||
|---|---|---|---|---|---|---|
| Dev Sec Ops | 2021-08-18 | true |
|
Description
This story is focused around detecting attacks on a DevSecOps lifeccycle which consists of the phases plan, code, build, test, release, deploy, operate and monitor.
- ID: 0ca8c38e-631e-4b81-940c-f9c5450ce41e
- Product: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud
- Datamodel:
- Last Updated: 2021-08-18
- Author: Patrick Bareiss, Splunk
Narrative
DevSecOps is a collaborative framework, which thinks about application and infrastructure security from the start. This means that security tools are part of the continuous integration and continuous deployment pipeline. In this analytics story, we focused on detections around the tools used in this framework such as GitHub as a version control system, GDrive for the documentation, CircleCI as the CI/CD pipeline, Kubernetes as the container execution engine and multiple security tools such as Semgrep and Kube-Hunter.
Detections
| Name | Technique | Type |
|---|---|---|
| AWS ECR Container Scanning Findings High | None | TTP |
| AWS ECR Container Scanning Findings Low Informational Unknown | None | Hunting |
| AWS ECR Container Scanning Findings Medium | None | Anomaly |
| AWS ECR Container Upload Outside Business Hours | None | Anomaly |
| AWS ECR Container Upload Unknown User | None | Anomaly |
| Circle CI Disable Security Job | None | Anomaly |
| Circle CI Disable Security Step | None | Anomaly |
| GitHub Dependabot Alert | None | Anomaly |
| GitHub Pull Request from Unknown User | None | Anomaly |
| Kubernetes Nginx Ingress LFI | None | TTP |
| Kubernetes Nginx Ingress RFI | None | TTP |
| Kubernetes Scanner Image Pulling | None | TTP |
Reference
source | version: 1