| ID | Technique | Tactic |
|---|
Detection: Baseline Of Cloud Instances Launched
REMOVED DETECTION
This detection has been removed from the Splunk Threat Research content library and is no longer maintained or supported.
Reason: All detection(s) which leverage this baseline have been deprecated. As such, this baseline has been deprecated as well.
Removed in version: 5.26.0
If you have any questions or concerns, please reach out to us at research@splunk.com.
Description
This search is used to build a Machine Learning Toolkit (MLTK) model for how many instances are created in the environment. By default, the search uses the last 90 days of data to build the model and the model is rebuilt weekly. The model created by this search is then used in the corresponding detection search, which identifies subsequent outliers in the number of instances created in a small time window.
Search
1
2| tstats count as instances_launched from datamodel=Change where (All_Changes.action=created) AND All_Changes.status=success AND All_Changes.object_category=instance by _time span=1h
3| makecontinuous span=1h _time
4| eval instances_launched=coalesce(instances_launched, (random()%2)*0.0000000001)
5| eval HourOfDay=strftime(_time, "%H")
6| eval HourOfDay=floor(HourOfDay/4)*4
7| eval DayOfWeek=strftime(_time, "%w")
8| eval isWeekend=if(DayOfWeek >= 1 AND DayOfWeek <= 5, 0, 1)
9| table _time instances_launched, HourOfDay, isWeekend
10| fit DensityFunction instances_launched by "HourOfDay,isWeekend" into cloud_excessive_instances_created_v1 dist=expon show_density=true
Data Source
No data sources specified for this detection.
Macros Used
| Name | Value |
|---|
Annotations
Default Configuration
This detection is configured by default in Splunk Enterprise Security to run with the following settings:
| Setting | Value |
|---|---|
| Disabled | true |
| Cron Schedule | N/A |
| Earliest Time | N/A |
| Latest Time | N/A |
| Schedule Window | N/A |
| Creates Finding (Notable) | No |
| Creates Intermediate Finding (Risk Event) | No |
Implementation
You must have Enterprise Security 6.0 or later, if not you will need to verify that the Machine Learning Toolkit (MLTK) version 4.2 or later is installed, along with any required dependencies. Depending on the number of users in your environment, you may also need to adjust the value for max_inputs in the MLTK settings for the DensityFunction algorithm, then ensure that the search completes in a reasonable timeframe. By default, the search builds the model using the past 90 days of data. You can modify the search window to build the model over a longer period of time, which may give you better results. You may also want to periodically re-run this search to rebuild the model with the latest data.
More information on the algorithm used in the search can be found at https://help.splunk.com/en/splunk-enterprise/apply-machine-learning/use-splunk-machine-learning-toolkit/5.5.0/algorithms-and-scoring-metrics-in-mltk/algorithms-in-the-splunk-machine-learning-toolkit#densityfunction-0.
Known False Positives
No false positives have been identified at this time.
Associated Analytic Story
Detection Testing
| Test Type | Status | Dataset | Source | Sourcetype |
|---|---|---|---|---|
| Validation | Not Applicable | N/A | N/A | N/A |
| Unit | Not Applicable | N/A | N/A |
N/A |
| Integration | Not Applicable | N/A | N/A |
N/A |
Replay any dataset to Splunk Enterprise by using our replay.py tool or the UI.
Alternatively you can replay a dataset into a Splunk Attack Range
Source: GitHub |
Version: 3