Detection: Previously Seen AWS Cross Account Activity - Initial

REMOVED DETECTION

This detection has been removed from the Splunk Threat Research content library and is no longer maintained or supported.

Reason: All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.

Removed in version: 5.4.0

If you have any questions or concerns, please reach out to us at research@splunk.com.

Description

This search looks for AssumeRole events where the requesting account differs from the requested account, then writes these relationships to a lookup file.

1
2| tstats earliest(_time) as firstTime latest(_time) as lastTime from datamodel=Authentication where Authentication.signature=AssumeRole by Authentication.vendor_account Authentication.user Authentication.src Authentication.user_role 
3|  `drop_dm_object_name(Authentication)` 
4| rex field=user_role "arn:aws:sts:*:(?<dest_account>.*):" 
5|  where  vendor_account != dest_account 
6| rename vendor_account as requestingAccountId dest_account as requestedAccountId 
7| table requestingAccountId requestedAccountId firstTime lastTime 
8| outputlookup previously_seen_aws_cross_account_activity

Data Source

No data sources specified for this detection.

Macros Used

Name Value
drop_dm_object_name ``

Annotations

- MITRE ATT&CK
+ Kill Chain Phases
+ NIST
+ CIS
- Threat Actors
ID Technique Tactic

Default Configuration

This detection is configured by default in Splunk Enterprise Security to run with the following settings:

Setting Value
Disabled true
Cron Schedule N/A
Earliest Time N/A
Latest Time N/A
Schedule Window N/A
Creates Finding (Notable) No
Creates Intermediate Finding (Risk Event) No

Implementation

You must install and configure the Splunk Add-on for AWS (version 5.1.0 or later)and Enterprise Security 6.2, which contains the required updates to the Authentication data model for cloud use cases. Validate the user name entries in previously_seen_aws_cross_account_activity.csv, a lookup file created by this support search.

Known False Positives

none

Associated Analytic Story

Detection Testing

Test Type Status Dataset Source Sourcetype
Validation Not Applicable N/A N/A N/A
Unit Not Applicable N/A N/A N/A
Integration Not Applicable N/A N/A N/A

Replay any dataset to Splunk Enterprise by using our replay.py tool or the UI. Alternatively you can replay a dataset into a Splunk Attack Range


Source: GitHub |

Version: 1