Files
splunk-security_content/docs/_stories/dev_sec_ops.md
T
2021-09-20 21:23:13 -04:00

2.6 KiB

title, last_modified_at, toc, tags
title last_modified_at toc tags
Dev Sec Ops 2021-08-18 true
Splunk Enterprise
Splunk Enterprise Security
Splunk Cloud

Description

This story is focused around detecting attacks on a DevSecOps lifeccycle which consists of the phases plan, code, build, test, release, deploy, operate and monitor.

  • ID: 0ca8c38e-631e-4b81-940c-f9c5450ce41e
  • Product: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud
  • Datamodel:
  • Last Updated: 2021-08-18
  • Author: Patrick Bareiss, Splunk

Narrative

DevSecOps is a collaborative framework, which thinks about application and infrastructure security from the start. This means that security tools are part of the continuous integration and continuous deployment pipeline. In this analytics story, we focused on detections around the tools used in this framework such as GitHub as a version control system, GDrive for the documentation, CircleCI as the CI/CD pipeline, Kubernetes as the container execution engine and multiple security tools such as Semgrep and Kube-Hunter.

Detections

Name Technique Type
AWS ECR Container Scanning Findings High None TTP
AWS ECR Container Scanning Findings Low Informational Unknown None Hunting
AWS ECR Container Scanning Findings Medium None Anomaly
AWS ECR Container Upload Outside Business Hours None Anomaly
AWS ECR Container Upload Unknown User None Anomaly
Circle CI Disable Security Job None Anomaly
Circle CI Disable Security Step None Anomaly
GitHub Dependabot Alert None Anomaly
GitHub Pull Request from Unknown User None Anomaly
Kubernetes Nginx Ingress LFI None TTP
Kubernetes Nginx Ingress RFI None TTP
Kubernetes Scanner Image Pulling None TTP

Reference

source | version: 1