| ID | Technique | Tactic |
|---|
Detection: Previously Seen AWS Cross Account Activity - Initial
REMOVED DETECTION
This detection has been removed from the Splunk Threat Research content library and is no longer maintained or supported.
Reason: All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.
Removed in version: 5.4.0
If you have any questions or concerns, please reach out to us at research@splunk.com.
Description
This search looks for AssumeRole events where the requesting account differs from the requested account, then writes these relationships to a lookup file.
Search
1
2| tstats earliest(_time) as firstTime latest(_time) as lastTime from datamodel=Authentication where Authentication.signature=AssumeRole by Authentication.vendor_account Authentication.user Authentication.src Authentication.user_role
3| `drop_dm_object_name(Authentication)`
4| rex field=user_role "arn:aws:sts:*:(?<dest_account>.*):"
5| where vendor_account != dest_account
6| rename vendor_account as requestingAccountId dest_account as requestedAccountId
7| table requestingAccountId requestedAccountId firstTime lastTime
8| outputlookup previously_seen_aws_cross_account_activity
Data Source
No data sources specified for this detection.
Macros Used
| Name | Value |
|---|---|
| drop_dm_object_name | `` |
Annotations
Default Configuration
This detection is configured by default in Splunk Enterprise Security to run with the following settings:
| Setting | Value |
|---|---|
| Disabled | true |
| Cron Schedule | N/A |
| Earliest Time | N/A |
| Latest Time | N/A |
| Schedule Window | N/A |
| Creates Finding (Notable) | No |
| Creates Intermediate Finding (Risk Event) | No |
Implementation
You must install and configure the Splunk Add-on for AWS (version 5.1.0 or later)and Enterprise Security 6.2, which contains the required updates to the Authentication data model for cloud use cases. Validate the user name entries in previously_seen_aws_cross_account_activity.csv, a lookup file created by this support search.
Known False Positives
none
Associated Analytic Story
Detection Testing
| Test Type | Status | Dataset | Source | Sourcetype |
|---|---|---|---|---|
| Validation | Not Applicable | N/A | N/A | N/A |
| Unit | Not Applicable | N/A | N/A |
N/A |
| Integration | Not Applicable | N/A | N/A |
N/A |
Replay any dataset to Splunk Enterprise by using our replay.py tool or the UI.
Alternatively you can replay a dataset into a Splunk Attack Range
Source: GitHub |
Version: 1